1 week 1 day ago
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was
backed out in USN-8563-2 because it could cause a regression. This update
includes a better fix for CVE-2026-42533.
We apologize for the inconvenience.
Original advisory details:
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the
ngx_http_ssi_module module when configured with Server-Side Includes,
proxy_pass, and proxy buffering disabled directives. An attacker able to
intercept traffic and control responses from an upstream server could
possibly use this issue to cause nginx to crash, resulting in a denial of
service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the
ngx_http_slice_module module. A remote attacker could possibly use this
issue to obtain sensitive information or cause nginx to crash, resulting
in a denial of service. (CVE-2026-60005)
1 week 1 day ago
1 week 1 day ago
1 week 1 day ago
1 week 1 day ago
1 week 2 days ago
1 week 2 days ago
FEDORA-2026-abe39f1809
Packages in this update:
Update description:
Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode
1 week 2 days ago
FEDORA-EPEL-2026-0f5b361fa5
Packages in this update:
- perl-Net-DNS-1.57-1.el10_4
Update description:
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
1 week 2 days ago
FEDORA-EPEL-2026-8a37d4d02f
Packages in this update:
- perl-Net-DNS-1.57-1.el10_3
Update description:
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
1 week 2 days ago
FEDORA-2026-57f107ed83
Packages in this update:
Update description:
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
1 week 2 days ago
FEDORA-2026-48a4531e02
Packages in this update:
Update description:
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
1 week 2 days ago
FEDORA-2026-5debc0de2b
Packages in this update:
- evolution-3.62.0-1.fc45
- evolution-data-server-3.62.0-1.fc45
- evolution-ews-3.62.0-1.fc45
Update description:
Update to 3.62.0
evolution-data-server
Bug Fixes:
- I#660 - GOA EWS: Do not require OABUrl in autodiscover
- I#662 - EBackend: Document how OAuth2 sources should ask to be authenticated (Tobias Mueller)
- I#665 - CalDAV: Ignore Bad Request (400) on overwrite
- M!243 - ESourceRegistry: Name the credentials source in failed-lookup debug message (Tobias Mueller)
Translations:
- Alan Mortensen (da)
- Aurimas Černius (lt)
- Balázs Úr (hu)
- Baurzhan Muftakhidinov (kk)
- Emin Tufan Çetin (tr)
- Juliano de Souza Camargo (pt_BR)
- Kjartan Maraas (nb)
evolution
Bug Fixes:
- I#3381 - Composer: De-duplicate inline images before send
- I#3383 - junk-filters: Do not leak the child stdin pipe into concurrent spawns (Benjamin Herrenschmidt)
- I#3386 - Default to not use read-only calendars for reminders and conflict search
- I#3387 - EUIParser: Notify about accelerators moved by an action rename (Martin Monperrus (AI-assisted))
- I#3388 - Mail: Validate clickable preview elements are generated by Evolution
- M!235 - Mail: Remove deprecated SHA1 signature algorithm (Robin Haberkorn)
Miscellaneous:
- docs: Add API index for newly added symbols in 3.62 for e-util
Translations:
- Alan Mortensen (da)
- Aurimas Černius (lt)
- Balázs Úr (hu)
- Baurzhan Muftakhidinov (kk)
- burns (pt_BR)
- Emin Tufan Çetin (tr)
- Guillaume Bernard (fr)
- Jiri Eischmann (cs)
- Kjartan Maraas (nb)
evolution-ews
Bug Fixes:
- M!18 - Add a per-folder coalescing gate for sync and refresh (Benjamin Herrenschmidt)
- M!19 - camel: Do not save the folder summary in the subclass dispose (David Woodhouse)
Translations:
- Alan Mortensen (da)
- Balázs Úr (hu)
- Jiri Eischmann (cs)
- Kjartan Maraas (nb)
1 week 2 days ago
FEDORA-2026-97a7ec5786
Packages in this update:
- cyrus-imapd-3.10.4-1.fc43
Update description:
- New version 3.10.4 (rhbz#2500822)
1 week 2 days ago
FEDORA-2026-740bc1c6fa
Packages in this update:
- cyrus-imapd-3.12.4-1.fc44
Update description:
- New version 3.12.4 (rhbz#2500822)
1 week 2 days ago
FEDORA-2026-3bf3e31ef4
Packages in this update:
- cyrus-imapd-3.12.4-1.fc45
Update description:
- New version 3.12.4 (rhbz#2500822)
1 week 2 days ago
1 week 2 days ago
Katriel Moses discovered that Urwid used a weak PRNG. A local attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code.
1 week 2 days ago
Seung Min Shin discovered that FFmpeg did not correctly handle certain
memory operations. If a user or automated system were tricked into
opening a specially crafted file, an attacker could cause a denial of
service. (CVE-2026-12706)
Xinghang Lv discovered that FFmpeg did not correctly handle certain
memory operations. If a user or automated system were tricked into
opening a specially crafted file, an attacker could cause a denial of
service. (CVE-2026-30999)
It was discovered that FFmpeg did not correctly handle certain memory
operations. If a user or automated system were tricked into opening a
specially crafted file, an attacker could cause a denial of service.
(CVE-2026-58049)
Adrian Junge discovered that FFmpeg did not correctly handle certain
memory operations. If a user or automated system were tricked into
opening a specially crafted file, an attacker could leak sensitive
information. (CVE-2026-70629, CVE-2026-70630, CVE-2026-70631)
Ori Hollander discovered that FFmpeg did not correctly handle certain
memory operations. If a user or automated system were tricked into
opening a specially crafted file, an attacker could possibly cause a
denial of service or execute arbitrary code. (CVE-2026-8461)
1 week 2 days ago
It was discovered that CivetWeb did not correctly handle parsing certain
URIs. A remote attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763)
It was discovered that CivetWeb did not correctly handle parsing certain
HTTP requests. A remote attacker could possibly use this issue to cause
a denial of service. (CVE-2025-9648)
1 week 2 days ago