Aggregator

cef-145.0.25^chromium145.0.7632.75-4.fc44

1 week 5 days ago
FEDORA-2026-376794abc1 Packages in this update:
  • cef-145.0.25^chromium145.0.7632.75-4.fc44
Update description:

Update to cef-145.0.25 + chromium 145.0.7632.75

  • CVE-2026-1861: Heap buffer overflow in libvpx
  • CVE-2026-1862: Type Confusion in V8
  • CVE-2026-2313: Use after free in CSS
  • CVE-2026-2314: Heap buffer overflow in Codecs
  • CVE-2026-2315: Inappropriate implementation in WebGPU
  • CVE-2026-2316: Insufficient policy enforcement in Frames
  • CVE-2026-2317: Inappropriate implementation in Animation
  • CVE-2026-2318: Inappropriate implementation in PictureInPicture
  • CVE-2026-2319: Race in DevTools
  • CVE-2026-2320: Inappropriate implementation in File input
  • CVE-2026-2321: Use after free in Ozone
  • CVE-2026-2322: Inappropriate implementation in File input
  • CVE-2026-2323: Inappropriate implementation in Downloads
  • CVE-2026-2441: Use after free in CSS

cef-145.0.25^chromium145.0.7632.75-4.fc42

1 week 5 days ago
FEDORA-2026-a48b5f36ec Packages in this update:
  • cef-145.0.25^chromium145.0.7632.75-4.fc42
Update description:

Update to cef-145.0.25 + chromium 145.0.7632.75

  • CVE-2026-1861: Heap buffer overflow in libvpx
  • CVE-2026-1862: Type Confusion in V8
  • CVE-2026-2313: Use after free in CSS
  • CVE-2026-2314: Heap buffer overflow in Codecs
  • CVE-2026-2315: Inappropriate implementation in WebGPU
  • CVE-2026-2316: Insufficient policy enforcement in Frames
  • CVE-2026-2317: Inappropriate implementation in Animation
  • CVE-2026-2318: Inappropriate implementation in PictureInPicture
  • CVE-2026-2319: Race in DevTools
  • CVE-2026-2320: Inappropriate implementation in File input
  • CVE-2026-2321: Use after free in Ozone
  • CVE-2026-2322: Inappropriate implementation in File input
  • CVE-2026-2323: Inappropriate implementation in Downloads
  • CVE-2026-2441: Use after free in CSS

cef-145.0.25^chromium145.0.7632.75-4.fc43

1 week 5 days ago
FEDORA-2026-0bced5158d Packages in this update:
  • cef-145.0.25^chromium145.0.7632.75-4.fc43
Update description:

Update to cef-145.0.25 + chromium 145.0.7632.75

  • CVE-2026-1861: Heap buffer overflow in libvpx
  • CVE-2026-1862: Type Confusion in V8
  • CVE-2026-2313: Use after free in CSS
  • CVE-2026-2314: Heap buffer overflow in Codecs
  • CVE-2026-2315: Inappropriate implementation in WebGPU
  • CVE-2026-2316: Insufficient policy enforcement in Frames
  • CVE-2026-2317: Inappropriate implementation in Animation
  • CVE-2026-2318: Inappropriate implementation in PictureInPicture
  • CVE-2026-2319: Race in DevTools
  • CVE-2026-2320: Inappropriate implementation in File input
  • CVE-2026-2321: Use after free in Ozone
  • CVE-2026-2322: Inappropriate implementation in File input
  • CVE-2026-2323: Inappropriate implementation in Downloads
  • CVE-2026-2441: Use after free in CSS

USN-8015-5: Linux kernel vulnerabilities

1 week 6 days ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - SMB network file system; - io_uring subsystem; (CVE-2025-38561, CVE-2025-39698, CVE-2025-40019)

python-django4.2-4.2.28-1.el9

1 week 6 days ago
FEDORA-EPEL-2026-e4c468db6d Packages in this update:
  • python-django4.2-4.2.28-1.el9
Update description:
  • Fixes CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler
  • Fixes CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI
  • Fixes CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS
  • Fixes CVE-2026-1285: Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
  • Fixes CVE-2026-1287: Potential SQL injection in column aliases via control characters
  • Fixes CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation

python-django4.2-4.2.28-1.fc42

1 week 6 days ago
FEDORA-2026-ca3d81129a Packages in this update:
  • python-django4.2-4.2.28-1.fc42
Update description:
  • Fixes CVE-2025-13473: Username enumeration through timing difference in mod_wsgi authentication handler
  • Fixes CVE-2025-14550: Potential denial-of-service vulnerability via repeated headers when using ASGI
  • Fixes CVE-2026-1207: Potential SQL injection via raster lookups on PostGIS
  • Fixes CVE-2026-1285: Potential denial-of-service vulnerability in django.utils.text.Truncator HTML methods
  • Fixes CVE-2026-1287: Potential SQL injection in column aliases via control characters
  • Fixes CVE-2026-1312: Potential SQL injection via QuerySet.order_by and FilteredRelation

USN-7990-5: Linux kernel (Azure) vulnerabilities

1 week 6 days ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Padata parallel execution mechanism; - Netfilter; (CVE-2022-49698, CVE-2025-21726, CVE-2025-40019)