1 week 1 day ago
Grzegorz Grasza discovered that OpenStack Keystone did not consistently
enforce restrictions for delegated authentication tokens. An authenticated
attacker could possibly use this issue to create credentials or delegations
that outlasted the delegated token. (CVE-2026-80182)
It was discovered that OpenStack Keystone incorrectly handled role
assignment queries under certain circumstances. An authenticated attacker
could possibly use this issue to obtain sensitive information. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183)
Tim Shephard discovered that OpenStack Keystone did not properly
restrict reauthentication using delegated tokens. An authenticated
attacker could possibly use this issue to escape their intended
project scope and obtain unauthorized access. (CVE-2026-80184)
1 week 1 day ago
FEDORA-2026-12f3f3d569
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.9
1 week 1 day ago
It was discovered that OpenSBI did not properly validate the counter index
mask in SBI PMU extension requests. An attacker could use this issue to
cause a denial of service.
1 week 1 day ago
FEDORA-2026-93eed17997
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.9
1 week 1 day ago
FEDORA-2026-b7ad280cc1
Packages in this update:
- mstflint-4.37.0_1.1-2.fc45
Update description:
Update to upstream release v4.37.0-1.1.
Fix licensing issues.
For upstream release information, see:
https://github.com/Mellanox/mstflint/releases
1 week 1 day ago
It was discovered that OpenVPN had a use-after-free vulnerability in
its TLS session handling. An attacker could possibly use this issue
to cause OpenVPN to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-84471)
It was discovered that OpenVPN incorrectly handled retransmissions of
ACK packet IDs, which could trigger a timeout integer overflow. A
remote attacker could possibly use this issue to cause a denial of
service. (CVE-2026-84732)
1 week 1 day ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
1 week 1 day ago
FEDORA-2026-0072911d9d
Packages in this update:
Update description:
xkb: Check the keysym range in _XkbReadKeyActions (CVE-2026-88806)
1 week 1 day ago
FEDORA-2026-663a2d0ba4
Packages in this update:
Update description:
- fix HTTP/2 server push UAF (CVE-2026-18924)
- fix Negotiate ambient user conn reuse (CVE-2026-19931)
- remove test1701 - HTTP/2 Upgrade in a HTTP/1.1 POST request is no longer supported
1 week 2 days ago
FEDORA-2026-7a31054ed6
Packages in this update:
Update description:
Update to 1.18.4
1 week 2 days ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- OCFS2 file system;
- IPv6 networking;
- Netfilter;
- SCTP protocol;
(CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)
1 week 2 days ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888,
CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984,
CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007,
CVE-2026-64091)
1 week 2 days ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
1 week 2 days ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
1 week 2 days ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
1 week 2 days ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
1 week 2 days ago
FEDORA-EPEL-2026-6867b104b2
Packages in this update:
Update description:
Update to 3.20.1.
1 week 2 days ago
FEDORA-2026-82691b59d6
Packages in this update:
Update description:
Update to 3.20.1.
1 week 2 days ago
FEDORA-2026-0b3030633b
Packages in this update:
Update description:
Update to 3.20.1.
1 week 2 days ago
FEDORA-EPEL-2026-bc47388d91
Packages in this update:
Update description:
Update to 3.20.1.