6 days 1 hour ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64018, CVE-2026-64025, CVE-2026-64029, CVE-2026-64032,
CVE-2026-64033, CVE-2026-64034, CVE-2026-64039, CVE-2026-64046,
CVE-2026-64047, CVE-2026-64048, CVE-2026-64051, CVE-2026-64055,
CVE-2026-64056, CVE-2026-64064, CVE-2026-64073, CVE-2026-64083,
CVE-2026-64084, CVE-2026-64085, CVE-2026-64086, CVE-2026-64087,
CVE-2026-64088, CVE-2026-64089, CVE-2026-64092, CVE-2026-64096,
CVE-2026-64097, CVE-2026-64098, CVE-2026-64102, CVE-2026-64103,
CVE-2026-64106, CVE-2026-64108, CVE-2026-64109, CVE-2026-64111,
CVE-2026-64113, CVE-2026-64114, CVE-2026-64115, CVE-2026-64116,
CVE-2026-64118, CVE-2026-64121, CVE-2026-64125, CVE-2026-64126,
CVE-2026-64127, CVE-2026-64128, CVE-2026-64133, CVE-2026-64134,
CVE-2026-64135, CVE-2026-64136, CVE-2026-64137, CVE-2026-64138,
CVE-2026-64144, CVE-2026-64147, CVE-2026-64148, CVE-2026-64153,
CVE-2026-64155, CVE-2026-64163, CVE-2026-64165, CVE-2026-64166,
CVE-2026-64168, CVE-2026-64170, CVE-2026-64173, CVE-2026-64174,
CVE-2026-64177, CVE-2026-64178, CVE-2026-64179, CVE-2026-64180,
CVE-2026-64182, CVE-2026-64183, CVE-2026-64184, CVE-2026-64185,
CVE-2026-64214, CVE-2026-64217, CVE-2026-64218, CVE-2026-64219,
CVE-2026-64220, CVE-2026-64221, CVE-2026-64225, CVE-2026-64231,
CVE-2026-64518)
6 days 1 hour ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033,
CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048,
CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064,
CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085,
CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089,
CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098,
CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108,
CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114,
CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121,
CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128,
CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136,
CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147,
CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163,
CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170,
CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178,
CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183,
CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217,
CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221,
CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)
6 days 1 hour ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
6 days 1 hour ago
6 days 1 hour ago
It was discovered that Memcached incorrectly handled ASCII
authentication. A remote attacker could possibly use this issue to
cause Memcached to crash, resulting in a denial of service.
6 days 1 hour ago
It was discovered that Ghostscript incorrectly handled JPEG 2000 image
components with mismatched subsampling factors. An attacker could
possibly use this issue to cause Ghostscript to crash or execute
arbitrary code if it opened a specially crafted file.
6 days 1 hour ago
It was discovered that libxml2 incorrectly handled certain XML elements
under certain circumstances. An attacker could possibly use this issue to
cause libxml2 to crash or execute arbitrary code. (CVE-2026-86140)
It was discovered that libxml2 incorrectly handled certain XML documents
when used with Python bindings. A remote attacker could possibly use this
issue to cause applications using libxml2 to crash, resulting in a denial
of service. (CVE-2026-74860)
6 days 1 hour ago
It was discovered that rsyslog incorrectly calculated buffer sizes when
replacing strings. A remote attacker could possibly use this issue to cause
rsyslog to crash, resulting in a denial of service.
6 days 2 hours ago
It was discovered that strongSwan incorrectly handled PKCS#7 containers
in the openssl plugin. A remote attacker could possibly use this issue
to cause strongSwan to crash, resulting in a denial of service.
(CVE-2026-78123)
It was discovered that strongSwan incorrectly handled memory when
enumerating certificates in PKCS#7 containers in the openssl plugin.
A remote attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-78124)
It was discovered that strongSwan incorrectly handled
AKA-Synchronization-Failure messages in the eap-aka plugin. A remote
attacker could possibly use this issue to cause strongSwan to crash,
resulting in a denial of service. (CVE-2026-78126)
It was discovered that strongSwan incorrectly handled memory when
stringifying IKE messages. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2026-78127)
It was discovered that strongSwan incorrectly handled PKCS#5 decryption.
A remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78129)
It was discovered that strongSwan incorrectly handled attribute
certificates in the x509 plugin when the issuer name was missing. A
remote attacker could possibly use this issue to cause strongSwan to
crash, resulting in a denial of service. (CVE-2026-78130)
It was discovered that strongSwan incorrectly handled memory when
parsing attribute certificates in the x509 plugin. A remote attacker
could possibly use this issue to obtain sensitive information.
(CVE-2026-78131)
It was discovered that strongSwan incorrectly handled attribute
certificates containing ietfAttrSyntax values in the x509 plugin. A
remote attacker could possibly use this issue to cause strongSwan to
consume excessive resources, leading to a denial of service.
(CVE-2026-78132)
It was discovered that strongSwan incorrectly handled IKEv2 rekeying
collisions with multi-key exchange. A remote attacker could possibly
use this issue to execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-78133)
It was discovered that strongSwan incorrectly validated inner EAP
method authentication details in the eap-ttls and eap-peap plugins.
An authenticated user could possibly use this issue to bypass
authentication. (CVE-2026-78134)
It was discovered that strongSwan incorrectly handled CREATE_CHILD_SA
requests on unestablished IKE_SAs. A remote attacker could possibly
use this issue to bypass authentication. (CVE-2026-78135)
6 days 2 hours ago
FEDORA-2026-9b73fdb8e6
Packages in this update:
- flatpak-builder-1.4.12-1.fc44
Update description:
Update to 1.4.12
6 days 2 hours ago
It was discovered that ClamAV incorrectly handled certain zip archive
files. A remote attacker could possibly use this issue to cause ClamAV
to crash, resulting in a denial of service. (CVE-2026-20337,
CVE-2026-20338)
It was discovered that ClamAV incorrectly handled certain PESpin files.
A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20339)
It was discovered that ClamAV incorrectly handled certain GPT files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20345)
It was discovered that ClamAV incorrectly handled certain PDF files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20346)
It was discovered that ClamAV incorrectly handled certain Mach-O files.
A remote attacker could possibly use this issue to cause ClamAV to
crash, resulting in a denial of service. (CVE-2026-20347)
It was discovered that ClamAV incorrectly handled certain XAR files. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service. (CVE-2026-20348)
6 days 3 hours ago
FEDORA-2026-8e3688d489
Packages in this update:
Update description:
1.036 bump
- Fix CVE-2026-93019 (TGA large color map size interpreted as negative)
- Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
6 days 3 hours ago
FEDORA-2026-12f0a70554
Packages in this update:
Update description:
1.036 bump
- Fix CVE-2026-93019 (TGA large color map size interpreted as negative)
- Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
6 days 3 hours ago
FEDORA-2026-625ab5c382
Packages in this update:
Update description:
1.036 bump
- Fix CVE-2026-93019 (TGA large color map size interpreted as negative)
- Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
6 days 5 hours ago
FEDORA-2026-fc27f09459
Packages in this update:
Update description:
Backport fixes for CVE-2026-{88047-88054}
6 days 5 hours ago
FEDORA-2026-4585aba520
Packages in this update:
Update description:
Backport fixes for CVE-2026-{88047-88054}
6 days 5 hours ago
FEDORA-2026-e3bf7f4ecb
Packages in this update:
Update description:
Backport fixes for CVE-2026-{88047-88054}
6 days 10 hours ago
FEDORA-2026-3e60aed77e
Packages in this update:
Update description:
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes
6 days 13 hours ago
FEDORA-2026-6b8872b8ac
Packages in this update:
Update description:
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes
6 days 16 hours ago
FEDORA-2026-ec725c24c1
Packages in this update:
Update description:
Automatic update for rootlesskit-3.2.0-1.fc46.
Changelog
* Sun Sep 20 2026 Bradley G Smith <
bradley.g.smith@gmail.com> - 3.2.0-1
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes