Aggregator

USN-8739-2: ImageMagick vulnerabilities

6 days 20 hours ago
USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368, CVE-2026-56371, CVE-2026-56373) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-56370) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56378) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379) It was discovered that ImageMagick incorrectly handled memory allocation in certain operations. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61465) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61857) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870) It was discovered that ImageMagick incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866) It was discovered that ImageMagick incorrectly handled certain images on 32-bit systems. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-62946)

dotnet10.0-10.0.112-1.fc44

6 days 20 hours ago
FEDORA-2026-a5c27e8727 Packages in this update:
  • dotnet10.0-10.0.112-1.fc44
Update description:

Update to .NET SDK 10.0.112 and Runtime 10.0.12

Fixes: CVE-2026-58649,CVE-2026-69304,CVE-2026-69439,CVE-2026-69522,CVE-2026-69806,CVE-2026-71328

Release Notes:

dotnet10.0-10.0.112-1.fc43

6 days 20 hours ago
FEDORA-2026-04a0116777 Packages in this update:
  • dotnet10.0-10.0.112-1.fc43
Update description:

Update to .NET SDK 10.0.112 and Runtime 10.0.12

Fixes: CVE-2026-58649,CVE-2026-69304,CVE-2026-69439,CVE-2026-69522,CVE-2026-69806,CVE-2026-71328

Release Notes:

dotnet10.0-10.0.112-1.fc45

6 days 20 hours ago
FEDORA-2026-fa6de37202 Packages in this update:
  • dotnet10.0-10.0.112-1.fc45
Update description:

Update to .NET SDK 10.0.112 and Runtime 10.0.12

Fixes: CVE-2026-58649,CVE-2026-69304,CVE-2026-69439,CVE-2026-69522,CVE-2026-69806,CVE-2026-71328

Release Notes:

USN-8757-1: cgit vulnerability

1 week ago
It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensitive information.

USN-8756-1: Yelp vulnerability

1 week ago
It was discovered that Yelp allowed help documents to execute arbitrary scripts. An attacker could possibly use this issue to trick a user into opening a specially crafted help document and obtain sensitive information.

USN-8754-1: Freeciv vulnerability

1 week ago
It was discovered that Freeciv incorrectly handled certain network packets, resulting in a stack overflow. A remote attacker could possibly use this issue to cause Freeciv clients or servers to crash, resulting in a denial of service.

freeipmi-1.6.19-1.fc44

1 week ago
FEDORA-2026-febfd10293 Packages in this update:
  • freeipmi-1.6.19-1.fc44
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

postgresql16-anonymizer-3.2.2-1.fc45

1 week ago
FEDORA-2026-bc7408de42 Packages in this update:
  • postgresql16-anonymizer-3.2.2-1.fc45
Update description:

Upstream changelog: https://gitlab.com/dalibo/postgresql_anonymizer/-/releases

  • [core] CVE-2026-19633: Escalation via custom types, operators and rangevars
  • [core] update dependencies
  • [static] Define masking policy with parallel static masking
  • [pseudo] Add seeded_street_name
  • [static] CVE-2026-83534: Elevation in parallel masking
  • [make] call extension+install before regress
  • [pseudo] new panel of seeded_* functions
  • [impexp] CVE-2026-19634: SQL injection via import functions
  • [partial] Add anon.array_remove_regex()
  • [static] Ignore a TABLESAMPLE sampling ratio on non-plain-table relations
  • [parallel] Reject a materialized view before parallel masking
  • [dynamic] Proper error message on write operations
  • [static] Optionally drop indexes during static masking (beta)
  • [doc] update the permission matrix
  • [tests] Gate the impexp unit tests on cfg(test) only
  • [doc] split Load and Support out of the Install page
  • [docker] make the image ready for replica masking
  • [tests] Introduce cargo pgrx regress
  • [core] Upgrade dependencies
  • [core] Remove useless compatibility function
  • [image] Define a default value for the sigma parameter
  • [doc] Add the "Anonymized Replica" tutorial
  • [docker] disable fsync during initdb
  • [static] Improve performance and correctness for parallel masking
  • [doc] how to fix cargo audit warnings
  • [doc] Install on Fedora
  • [core] Support PostgreSQL 19 (beta)
  • [core] Upgrade to PGRX 0.19

postgresql16-anonymizer-3.2.2-1.fc44

1 week ago
FEDORA-2026-58a319c686 Packages in this update:
  • postgresql16-anonymizer-3.2.2-1.fc44
Update description:

Upstream changelog: https://gitlab.com/dalibo/postgresql_anonymizer/-/releases

  • [core] CVE-2026-19633: Escalation via custom types, operators and rangevars
  • [core] update dependencies
  • [static] Define masking policy with parallel static masking
  • [pseudo] Add seeded_street_name
  • [static] CVE-2026-83534: Elevation in parallel masking
  • [make] call extension+install before regress
  • [pseudo] new panel of seeded_* functions
  • [impexp] CVE-2026-19634: SQL injection via import functions
  • [partial] Add anon.array_remove_regex()
  • [static] Ignore a TABLESAMPLE sampling ratio on non-plain-table relations
  • [parallel] Reject a materialized view before parallel masking
  • [dynamic] Proper error message on write operations
  • [static] Optionally drop indexes during static masking (beta)
  • [doc] update the permission matrix
  • [tests] Gate the impexp unit tests on cfg(test) only
  • [doc] split Load and Support out of the Install page
  • [docker] make the image ready for replica masking
  • [tests] Introduce cargo pgrx regress
  • [core] Upgrade dependencies
  • [core] Remove useless compatibility function
  • [image] Define a default value for the sigma parameter
  • [doc] Add the "Anonymized Replica" tutorial
  • [docker] disable fsync during initdb
  • [static] Improve performance and correctness for parallel masking
  • [doc] how to fix cargo audit warnings
  • [doc] Install on Fedora
  • [core] Support PostgreSQL 19 (beta)
  • [core] Upgrade to PGRX 0.19