6 days 22 hours ago
FEDORA-2026-bcfa11cd3b
Packages in this update:
- mingw-gstreamer1-plugins-base-1.26.11-2.fc43
- mingw-gstreamer1-plugins-good-1.26.11-3.fc43
Update description:
Backport multiple security fixes.
6 days 22 hours ago
FEDORA-2026-e6ca27403f
Packages in this update:
- mingw-gstreamer1-1.28.6-1.fc44
- mingw-gstreamer1-plugins-bad-free-1.28.6-1.fc44
- mingw-gstreamer1-plugins-base-1.28.6-1.fc44
- mingw-gstreamer1-plugins-good-1.28.6-1.fc44
Update description:
Update to 1.28.6.
6 days 23 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
6 days 23 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
6 days 23 hours ago
FEDORA-2026-6d1e651eb5
Packages in this update:
Update description:
Update to expat-2.8.3.
6 days 23 hours ago
FEDORA-2026-43f21f29dc
Packages in this update:
Update description:
Update to expat-2.8.3.
6 days 23 hours ago
FEDORA-2026-f5e2a6b9b5
Packages in this update:
Update description:
Update to expat-2.8.3.
6 days 23 hours ago
FEDORA-2026-94344a87fb
Packages in this update:
- mingw-openexr-3.4.15-1.fc45
Update description:
Update to openexr 3.4.15 resp 3.3.14.
6 days 23 hours ago
FEDORA-2026-54d00b8af5
Packages in this update:
- mingw-openexr-3.4.15-1.fc44
Update description:
Update to openexr 3.4.15 resp 3.3.14.
6 days 23 hours ago
FEDORA-2026-bcc9ac580d
Packages in this update:
- mingw-openexr-3.3.14-1.fc43
Update description:
Update to openexr 3.4.15 resp 3.3.14.
6 days 23 hours ago
6 days 23 hours ago
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
1 week ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
1 week ago
Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)
Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-70632)
1 week ago
It was discovered that Vim incorrectly handled certain tags files. An
attacker could possibly use this issue to execute arbitrary code.
1 week ago
USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,
Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
In addition, this update also fixes the following issues that were
not previously addressed in those releases:
It was discovered that OpenSSL incorrectly handled TLS handshake
message buffering. A remote attacker could possibly use this issue to
cause OpenSSL to consume excessive memory, leading to a denial of
service. (LP: #2161371)
It was discovered that OpenSSL incorrectly handled session cache
management when processing TLSv1.3 sessions. A remote attacker could
possibly use this issue to cause OpenSSL to consume excessive memory,
leading to a denial of service. This issue only affected OpenSSL 1.1.1
on Ubuntu 18.04 LTS. (CVE-2024-2511)
It was discovered that OpenSSL incorrectly handled the SSL_select_next_proto
function when called with an empty client protocol list. A remote attacker
could possibly use this issue to cause OpenSSL to disclose private memory
contents to the peer, leading to a loss of confidentiality. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)
Original advisory details:
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
1 week ago
It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)
It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)
It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)
It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)
It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)
It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)
It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)
1 week ago
USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS.
Original advisory details:
Joshua Rogers discovered that curl incorrectly handled reusing
connections when client certificate settings changed. This could result
in the wrong client certificates being used, contrary to expectations.