Aggregator
DSA-6311-1 php-twig - security update
USN-8347-1: QT WebEngine vulnerability
It was discovered that the vendored LibTIFF in QT WebEngine incorrectly
handled memory when parsing malformed TIFF image metadata. An attacker
could possibly use this issue to cause a denial of service, obtain
sensitive information, or execute arbitrary code.
USN-8346-1: Texmaker vulnerabilities
It was discovered that the vendored LibTIFF in Texmaker incorrectly
handled memory when parsing malformed TIFF image metadata. An attacker
could possibly use this issue to cause a denial of service, obtain
sensitive information, or execute arbitrary code.
USN-8345-1: GDAL vulnerability
It was discovered that the vendored LibTIFF in GDAL incorrectly handled
memory when parsing malformed TIFF image metadata. An attacker could
possibly use this issue to cause a denial of service, obtain sensitive
information, or execute arbitrary code.
libre-4.8.1-1.el10_3
FEDORA-EPEL-2026-39d9295352
Packages in this update:
- libre-4.8.1-1.el10_3
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
libre-4.8.1-1.fc43
FEDORA-2026-bfba5a213d
Packages in this update:
- libre-4.8.1-1.fc43
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
libre-4.8.1-1.el9
FEDORA-EPEL-2026-e3f844d4d5
Packages in this update:
- libre-4.8.1-1.el9
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
libre-4.8.1-1.el8
FEDORA-EPEL-2026-035f48b183
Packages in this update:
- libre-4.8.1-1.el8
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
libre-4.8.1-1.el10_2
FEDORA-EPEL-2026-fdfd52de3c
Packages in this update:
- libre-4.8.1-1.el10_2
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
libre-4.8.1-1.fc44
FEDORA-2026-837d6ef455
Packages in this update:
- libre-4.8.1-1.fc44
- fmt/pl: add pl_strip_html()
- sys/fs: add getpwuid fallback for fs_gethome
- tls: remove unused include rsa.h
- ice: check source address of incoming application packets
- websock: Fix integer overflow in websock_decode() masked frame check
python-starlette-0.52.1-2.fc43
FEDORA-2026-e0f378428e
Packages in this update:
- python-starlette-0.52.1-2.fc43
Backport fix for CVE-2026-48710
USN-8341-1: OpenJDK 26 vulnerabilities
Thomas Beckers discovered that the JAXP component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the Networking component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-34282)
It was discovered that the JSSE component of OpenJDK 26 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could
possibly use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that the JGSS component of OpenJDK 26 did not correctly
authenticate certain APIs. A remote attacker could possibly use this issue
to obtain sensitive information. (CVE-2026-22013)
It was discovered that the 2D component of OpenJDK 26 did not correctly
handle certain integer arithmetic. If a user or automated system were
tricked into opening a specially crafted file, an attacker could
possibly use this issue to obtain sensitive information. (CVE-2026-23865)
It was discovered that the Libraries component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to modify data. (CVE-2026-22008)
It was discovered that the Libraries component of OpenJDK 26 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-22018)
Ken Pyle discovered that the Security component of OpenJDK 26 did not
correctly authenticate certain APIs. A local attacker could possibly
use this issue to obtain sensitive information.
(CVE-2026-22007, CVE-2026-34268)
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Please see the following for more information:
https://openjdk.org/groups/vulnerability/advisories/2026-04-21
USN-8344-1: pip vulnerabilities
It was discovered that pip incorrectly handled TLS certificate
verification in session connections. If a session was first used with
certificate verification disabled, subsequent requests to the same host
would also skip verification regardless of the session's current settings.
A remote attacker could possibly use this issue to perform a machine-in-the-middle
attack and expose sensitive information. (CVE-2024-35195)
It was discovered that pip's bundled urllib3 library did not limit the
number of decompression steps when processing HTTP responses. A remote
attacker could possibly use this issue to cause pip to consume excessive resources,
leading to a denial of service. (CVE-2025-66418)
It was discovered that pip's bundled urllib3 library improperly
handled streaming decompression of highly compressed data. A remote
attacker could possibly use this issue to cause pip to consume excessive resources,
leading to a denial of service. (CVE-2025-66471)
python-starlette-0.52.1-2.fc44
FEDORA-2026-3bce8d3f11
Packages in this update:
- python-starlette-0.52.1-2.fc44
Backport fix for CVE-2026-48710
nextcloud-33.0.4-1.el10_2
FEDORA-EPEL-2026-688571a474
Packages in this update:
- nextcloud-33.0.4-1.el10_2
33.0.4 Release
nextcloud-33.0.4-1.fc43
FEDORA-2026-e187104307
Packages in this update:
- nextcloud-33.0.4-1.fc43
33.0.4 Release
nextcloud-33.0.4-1.el10_3
FEDORA-EPEL-2026-a0b50bf0a0
Packages in this update:
- nextcloud-33.0.4-1.el10_3
33.0.4 Release
nextcloud-33.0.4-1.fc44
FEDORA-2026-30881a5be7
Packages in this update:
- nextcloud-33.0.4-1.fc44
33.0.4 Release
USN-8229-2: sed vulnerability
USN-8229-1 fixed a vulnerability in sed. This update provides the
corresponding update for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
Michał Majchrowicz and Marcin Wyczechowski discovered that sed
incorrectly handled symbolic links when performing in-place edits.
A local attacker could possibly use this issue to overwrite
arbitrary files.