Aggregator

USN-8857-1: KCoreAddons vulnerability

6 days 9 hours ago
It was discovered that KCoreAddons incorrectly handled shell argument quoting in KShell::quoteArgs. The parsing did not adequately handle shell metacharacters, which could lead to a shell escape. An attacker could possibly use this issue to execute arbitrary commands in applications that relied on this method to handle user input.

php-getid3-1.9.27-1.fc44

6 days 10 hours ago
FEDORA-2026-71df118e18 Packages in this update:
  • php-getid3-1.9.27-1.fc44
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

php-getid3-1.9.27-1.fc45

6 days 10 hours ago
FEDORA-2026-6ef35023a5 Packages in this update:
  • php-getid3-1.9.27-1.fc45
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

php-getid3-1.9.27-1.fc43

6 days 10 hours ago
FEDORA-2026-b9ef1180ce Packages in this update:
  • php-getid3-1.9.27-1.fc43
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

GitPython-3.2.0-1.el9

6 days 11 hours ago
FEDORA-EPEL-2026-e0e0737425 Packages in this update:
  • GitPython-3.2.0-1.el9
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.

docker-buildx-0.37.2-1.fc45

6 days 16 hours ago
FEDORA-2026-59c42d53ab Packages in this update:
  • docker-buildx-0.37.2-1.fc45
Update description:
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

docker-buildx-0.37.2-1.fc46

6 days 19 hours ago
FEDORA-2026-934d570022 Packages in this update:
  • docker-buildx-0.37.2-1.fc46
Update description:

Automatic update for docker-buildx-0.37.2-1.fc46.

Changelog * Wed Sep 30 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 0.37.2-1 - Update to release v0.37.2 - Resolves: rhbz#2544198 - Resolves CVE-2026-56855: rhbz#2530594 - resolves CVE-2026-78662: rhbz#2530802 - Upstream fix

GitPython-3.2.0-1.el10_2

6 days 23 hours ago
FEDORA-EPEL-2026-c3ee85c015 Packages in this update:
  • GitPython-3.2.0-1.el10_2
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.

GitPython-3.2.0-1.el10_3

1 week ago
FEDORA-EPEL-2026-b8f0b437b3 Packages in this update:
  • GitPython-3.2.0-1.el10_3
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.

GitPython-3.2.0-1.el10_4

1 week ago
FEDORA-EPEL-2026-58b3caf388 Packages in this update:
  • GitPython-3.2.0-1.el10_4
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.