Aggregator

USN-8081-1: libpng vulnerabilities

1 week 2 days ago
It was discovered that libpng did not properly handle memory when processing certain PNG files. An attacker could possibly use this issue to cause libpng to crash, resulting in a denial of service, or disclose sensitive information. (CVE-2025-64505) Joshua Inscoe discovered that libpng did not properly handle memory when processing certain PNG files. An attacker could possibly use this issue to cause libpng to crash, resulting in a denial of service, disclose sensitive information, or execute arbitrary code. (CVE-2026-25646)

USN-8082-1: GIMP vulnerabilities

1 week 3 days ago
Michael Randrianantenaina discovered that GIMP incorrectly handled certain malformed ICO files. An attacker could possibly use this to cause a denial of service or execute arbitrary code. (CVE-2025-5473) Seungho Kim discovered that GIMP incorrectly handled certain memory operations when running the despeckle plugin. An attacker could possibly use this to cause a denial of service or execute arbitrary code. (CVE-2025-6035)

dnf5-5.2.18.0-2.fc42

1 week 3 days ago
FEDORA-2026-beac8e1f11 Packages in this update:
  • dnf5-5.2.18.0-2.fc42
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

dnf5-5.2.18.0-2.fc43

1 week 3 days ago
FEDORA-2026-4e264a94a4 Packages in this update:
  • dnf5-5.2.18.0-2.fc43
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

dnf5-5.4.0.0-2.fc44

1 week 3 days ago
FEDORA-2026-6072c6888a Packages in this update:
  • dnf5-5.4.0.0-2.fc44
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

Update to upstream release 5.4.0.0. Full changelog.