Aggregator

chromium-150.0.7871.128-1.el10_3

1 week ago
FEDORA-EPEL-2026-80f5d69973 Packages in this update:
  • chromium-150.0.7871.128-1.el10_3
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.fc44

1 week ago
FEDORA-2026-310f620a68 Packages in this update:
  • chromium-150.0.7871.128-1.fc44
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.el9

1 week ago
FEDORA-EPEL-2026-a72ac31b48 Packages in this update:
  • chromium-150.0.7871.128-1.el9
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.el10_2

1 week ago
FEDORA-EPEL-2026-81064cea8f Packages in this update:
  • chromium-150.0.7871.128-1.el10_2
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.fc43

1 week ago
FEDORA-2026-ac712bf651 Packages in this update:
  • chromium-150.0.7871.128-1.fc43
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

wordpress-6.9.5-1.el9

1 week ago
FEDORA-EPEL-2026-b847a0b309 Packages in this update:
  • wordpress-6.9.5-1.el9
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.el10_2

1 week ago
FEDORA-EPEL-2026-224c06e2c7 Packages in this update:
  • wordpress-6.9.5-1.el10_2
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.fc43

1 week ago
FEDORA-2026-46346e9637 Packages in this update:
  • wordpress-6.9.5-1.fc43
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.fc44

1 week ago
FEDORA-2026-2b8250197a Packages in this update:
  • wordpress-6.9.5-1.fc44
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-7.0.2-1.el10_3

1 week ago
FEDORA-EPEL-2026-604236f7b8 Packages in this update:
  • wordpress-7.0.2-1.el10_3
Update description: Version 7.0.2

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

kernel-7.1.4-101.fc43

1 week 1 day ago
FEDORA-2026-336f10ee31 Packages in this update:
  • kernel-7.1.4-101.fc43
Update description:

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

kernel-7.1.4-201.fc44

1 week 1 day ago
FEDORA-2026-eb0b86b6f9 Packages in this update:
  • kernel-7.1.4-201.fc44
Update description:

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

USN-8558-1: ImageMagick vulnerabilities

1 week 1 day ago
It was discovered that ImageMagick did not limit mutual references between MVG files. An attacker could possibly use this issue to cause a stack overflow, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-68950) It was discovered that the ImageMagick MSL coder destroyed a cloned image twice when an MSL script failed. An attacker could possibly use this issue to cause a use-after-free, resulting in a denial of service, or arbitrary code execution. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-28688) It was discovered that the ImageMagick VIFF image encoder did not properly validate the packet count, leading to an integer overflow on 32-bit systems. An attacker could possibly use this issue to cause an out-of- bounds heap write, resulting in a denial of service. (CVE-2026-33900) It was discovered that ImageMagick did not properly handle the column offset when sampling an image. An attacker could possibly use this issue to cause ImageMagick to read out of bounds, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-33905)

USN-8563-2: nginx regression

1 week 1 day ago
USN-8563-1 fixed vulnerabilities in nginx. One of the fixes introduced ABI changes that could cause issues with external modules. This update reverts the fix for CVE-2026-42533 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

nginx-1.30.4-1.fc45 nginx-mod-brotli-1.0.0~rc-13.fc45 nginx-mod-fancyindex-0.6.0-8.fc45 nginx-mod-headers-more-0.40-3.fc45 nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc45 nginx-mod-modsecurity-1.0.4-16.fc45 nginx-mod-naxsi-1.6-21.fc45 nginx-mod-vts…

1 week 1 day ago
FEDORA-2026-d1cd8e3d25 Packages in this update:
  • nginx-1.30.4-1.fc45
  • nginx-mod-brotli-1.0.0~rc-13.fc45
  • nginx-mod-fancyindex-0.6.0-8.fc45
  • nginx-mod-headers-more-0.40-3.fc45
  • nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc45
  • nginx-mod-modsecurity-1.0.4-16.fc45
  • nginx-mod-naxsi-1.6-21.fc45
  • nginx-mod-vts-0.2.4-13.fc45
Update description:

nginx-mod-fancyindex:

Rebuild for 1.30.4

nginx-mod-modsecurity:

Rebuild for 1.30.4

nginx-mod-naxsi:

Rebuild for 1.30.4

nginx-mod-headers-more:

Rebuild for 1.30.4

nginx-mod-brotli:

Rebuild for 1.30.4

nginx-mod-js-challenge:

Rebuild for 1.30.4

nginx-mod-vts:

Rebuild for 1.30.4

nginx:

update to 1.30.4 fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434