Aggregator

USN-8287-2: XDG Desktop Portal regression

1 week 3 days ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8808-1: SQL parse vulnerabilities

1 week 3 days ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.

cockpit-368-1.fc44

1 week 3 days ago
FEDORA-2026-61b2a3477a Packages in this update:
  • cockpit-368-1.fc44
Update description:

Automatic update for cockpit-368-1.fc44.

Changelog for cockpit * Wed Sep 23 2026 Packit <hello@packit.dev> - 368-1 - Limit concurrent connections CVE-2026-91149 - Harden cockpit-ws against trailing slash CVE-2026-91147 - Sanitize URLs from PackageKit CVE-2026-91148 - Interactive file chooser for SSH keys - Bug fixes and translation updates - Resolves RHEL-263070, RHEL-262891, RHEL-253609 for rhel-10.4 - Resolves RHEL-263066 for rhel-9.10

cockpit-368-1.fc45

1 week 3 days ago
FEDORA-2026-d375ea9e79 Packages in this update:
  • cockpit-368-1.fc45
Update description:

Automatic update for cockpit-368-1.fc45.

Changelog for cockpit * Wed Sep 23 2026 Packit <hello@packit.dev> - 368-1 - Limit concurrent connections CVE-2026-91149 - Harden cockpit-ws against trailing slash CVE-2026-91147 - Sanitize URLs from PackageKit CVE-2026-91148 - Interactive file chooser for SSH keys - Bug fixes and translation updates - Resolves RHEL-263070, RHEL-262891, RHEL-253609 for rhel-10.4 - Resolves RHEL-263066 for rhel-9.10