1 week 1 day ago
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Packet sockets;
- RDS protocol;
- TLS protocol;
(CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077,
CVE-2026-43078, CVE-2026-43494, CVE-2026-46028)
1 week 1 day ago
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Network drivers;
- NVME drivers;
- IPv4 networking;
- Packet sockets;
- RDS protocol;
- TLS protocol;
(CVE-2024-50304, CVE-2026-23112, CVE-2026-23209, CVE-2026-31504,
CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078,
CVE-2026-43494, CVE-2026-46028)
1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container.
1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- RDS protocol;
(CVE-2026-43494)
1 week 1 day ago
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500)
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)
Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- RDS protocol;
(CVE-2026-43494)
1 week 1 day ago
FEDORA-EPEL-2026-6821fe2971
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
FEDORA-2026-ff5370cd61
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
FEDORA-EPEL-2026-78c9d246b0
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
FEDORA-EPEL-2026-5afb48ca9e
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
FEDORA-EPEL-2026-c26294a28d
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
FEDORA-2026-77b4ea4fb8
Packages in this update:
Update description:
Update to upstream 1.5.1. Fixes CVE-2026-48785
1 week 1 day ago
Michał Majchrowicz and Marcin Wyczechowski discovered that Nano created
the ~/.local directory with incorrect permissions. In environments with
permissive umask settings, a local attacker could possibly use this
issue to inject a malicious launcher file, resulting in information
disclosure or other unintended actions. (CVE-2026-6842)
Michał Majchrowicz and Marcin Wyczechowski discovered that Nano
incorrectly handled directory names when updating the status line. A
local attacker could possibly use this issue to cause Nano to crash,
resulting in a denial of service. This issue only affected Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.
(CVE-2026-6843)
1 week 1 day ago
FEDORA-2026-4280f7beb8
Packages in this update:
Update description:
Automatic update for systemd-261~rc3-1.fc45.
Changelog
* Thu Jun 4 2026 Zbigniew Jędrzejewski-Szmek <
zbyszek@amutable.com> - 261~rc3-1
- Version 261~rc3
- Various smaller and larger fixes
- A hint is emitted if init is called with the legacy telinit args
(rhbz#2479961)
- Various messages for missing dlopened libraries have been downgraded
(rhbz#2463540)
1 week 1 day ago
Version:next-20260604 (linux-next)
Released:2026-06-04
1 week 1 day ago
It was discovered that Robocode could be tricked into making network
requests to attacker-controlled systems. An attacker could possibly use
this issue to cause external service interaction, resulting in
information disclosure. This issue only affected Ubuntu 16.04 LTS and
Ubuntu 18.04 LTS. (CVE-2019-10648)
Lim Sim Yee discovered that Robocode did not properly validate file
paths in the CacheCleaner component. An attacker could possibly use this
issue to delete arbitrary files. (CVE-2025-14306)
Lim Sim Yee discovered that Robocode did not securely create temporary
files in the AutoExtract component. An attacker could possibly use this
issue to manipulate temporary files, resulting in arbitrary code
execution. (CVE-2025-14307)
Lim Sim Yee discovered that Robocode did not properly validate data
lengths in the Buffer class. An attacker could possibly use this issue
to trigger an integer overflow, resulting in arbitrary code execution.
(CVE-2025-14308)
1 week 2 days ago
FEDORA-EPEL-2026-4dc7d2c6bb
Packages in this update:
- python-python-multipart-0.0.31-1.el10_2
Update description:
0.0.31 (2026-06-04)
- Speed up multipart header parsing and callback dispatch.
- Bound header field name size before validating.
- Validate Content-Length is non-negative in parse_form.
Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.
0.0.30 (2026-05-31)
- Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
- Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.
1 week 2 days ago
FEDORA-EPEL-2026-63f4d4a3b2
Packages in this update:
- python-python-multipart-0.0.31-1.el10_3
Update description:
0.0.31 (2026-06-04)
0.0.30 (2026-05-31)
- Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
- Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.
1 week 2 days ago
FEDORA-2026-4d81c2ff49
Packages in this update:
- python-python-multipart-0.0.31-1.fc43
Update description:
0.0.31 (2026-06-04)
- Speed up multipart header parsing and callback dispatch.
- Bound header field name size before validating.
- Validate Content-Length is non-negative in parse_form.
Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.
0.0.30 (2026-05-31)
- Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
- Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.
1 week 2 days ago
FEDORA-2026-c7869a8216
Packages in this update:
- python-python-multipart-0.0.31-1.fc44
Update description:
0.0.31 (2026-06-04)
- Speed up multipart header parsing and callback dispatch.
- Bound header field name size before validating.
- Validate Content-Length is non-negative in parse_form.
Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.
0.0.30 (2026-05-31)
- Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
- Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.
1 week 2 days ago
FEDORA-2026-a63aad0224
Packages in this update:
Update description:
- Add support for half-width fonts.
- Improve content filter compilation by avoiding file copies.
- Improve handling of out of disk space conditions when the NetworkProcess tried to write data in caches.
- Fix painting scrollbars when their width changes.
- Fix playback of certain YouTube videos with low frame rates.
- Fix webkit://gpu not working in systems where neither libGL.so.1 nor libOpenGL.so.0 are available.
- Fix several crashes and rendering issues.
- Security fixes: CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-43658, CVE-2026-43660