Aggregator

pack-0.40.9-1.el8

1 week 1 day ago
FEDORA-EPEL-2026-df0e6e2699 Packages in this update:
  • pack-0.40.9-1.el8
Update description:

Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)

pack-0.40.9-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-0af8f5893c Packages in this update:
  • pack-0.40.9-1.el9
Update description:

Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)

pack-0.40.9-1.fc43

1 week 1 day ago
FEDORA-2026-70dd9b4fc0 Packages in this update:
  • pack-0.40.9-1.fc43
Update description:

Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)

pack-0.40.9-1.fc44

1 week 1 day ago
FEDORA-2026-14ebd38fea Packages in this update:
  • pack-0.40.9-1.fc44
Update description:

Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)

USN-8638-1: Axios vulnerabilities

1 week 1 day ago
Ameer Assadi discovered that Axios did not properly handle certain hostnames when applying NO_PROXY rules. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2025-62718) It was discovered that Axios did not properly protect certain HTTP header values from prototype pollution. An attacker could possibly use this issue to inject malicious values into outbound requests, resulting in HTTP header injection. (CVE-2026-40175) Sachin Patil and Amol Patil discovered that Axios did not properly apply NO_PROXY rules to certain loopback addresses. An attacker could possibly use this issue to bypass proxy restrictions and access internal services, resulting in server-side request forgery. (CVE-2026-42043) Yu Bao discovered that Axios did not properly protect JSON response processing from prototype pollution. An attacker could possibly use this issue to modify values in application responses, resulting in authorization bypass or privilege escalation. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-42044) It was discovered that Axios did not properly protect certain request configuration options from prototype pollution. An attacker could possibly use this issue to modify outbound HTTP requests, resulting in security restrictions being bypassed. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)

dotnet9.0-9.0.120-1.fc44

1 week 1 day ago
FEDORA-2026-7cfd54a4c1 Packages in this update:
  • dotnet9.0-9.0.120-1.fc44
Update description:

Update to .NET SDK 9.0.120 and Runtime 9.0.19

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet9.0-9.0.120-1.fc43

1 week 1 day ago
FEDORA-2026-9c8770dffb Packages in this update:
  • dotnet9.0-9.0.120-1.fc43
Update description:

Update to .NET SDK 9.0.120 and Runtime 9.0.19

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

USN-8637-1: Linux kernel (OEM) vulnerabilities

1 week 1 day ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Thunderbolt and USB4 drivers; - Network traffic control; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - SCTP protocol; (CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186, CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247, CVE-2026-53260, CVE-2026-53359)

USN-8631-2: Linux kernel (Oracle) vulnerabilities

1 week 1 day ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8630-2: Linux kernel vulnerabilities

1 week 1 day ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

chromium-151.0.7922.137-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-164ecb432d Packages in this update:
  • chromium-151.0.7922.137-1.el10_2
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.fc43

1 week 1 day ago
FEDORA-2026-51e9d3c767 Packages in this update:
  • chromium-151.0.7922.137-1.fc43
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.fc44

1 week 1 day ago
FEDORA-2026-c374680c6a Packages in this update:
  • chromium-151.0.7922.137-1.fc44
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-c2dac28c8c Packages in this update:
  • chromium-151.0.7922.137-1.el9
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

chromium-151.0.7922.137-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-40713968f8 Packages in this update:
  • chromium-151.0.7922.137-1.el10_3
Update description:

chromium security release 151.0.7922.137 inludes fixes for:

* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blink

dotnet8.0-8.0.130-1.fc44

1 week 1 day ago
FEDORA-2026-1397d83d94 Packages in this update:
  • dotnet8.0-8.0.130-1.fc44
Update description:

Update to .NET SDK 8.0.130 and Runtime 8.0.30

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet8.0-8.0.130-1.fc43

1 week 1 day ago
FEDORA-2026-0db5bf0aae Packages in this update:
  • dotnet8.0-8.0.130-1.fc43
Update description:

Update to .NET SDK 8.0.130 and Runtime 8.0.30

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes:

dotnet10.0-10.0.111-1.fc44

1 week 1 day ago
FEDORA-2026-8b4cb2340a Packages in this update:
  • dotnet10.0-10.0.111-1.fc44
Update description:

Update to .NET SDK 10.0.111 and Runtime 10.0.11

Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354

Release Notes: