Aggregator

openbao-2.6.4-1.fc44

2 hours 25 minutes ago
FEDORA-2026-c079fc3c0b Packages in this update:
  • openbao-2.6.4-1.fc44
Update description:

Update to upstream 2.6.4. Includes multiple GHSA security notices, see https://github.com/openbao/openbao/releases/tag/v2.6.4

Update to 2.6.3-2. Fixes privilege problem in the service file and cleans up default configuration file.

Update to 2.6.3. Includes fixes to multiple GHSAs listed at https://github.com/openbao/openbao/releases/tag/v2.6.3.

openbao-2.6.4-1.fc45

2 hours 25 minutes ago
FEDORA-2026-c0f7a19ee3 Packages in this update:
  • openbao-2.6.4-1.fc45
Update description:

Update to upstream 2.6.4. Includes multiple GHSA security notices, see https://github.com/openbao/openbao/releases/tag/v2.6.4

Update to 2.6.3-2. Fixes privilege problem in the service file and cleans up default configuration file.

Update to 2.6.3. Includes fixes to multiple GHSAs listed at https://github.com/openbao/openbao/releases/tag/v2.6.3.

USN-8863-1: GStreamer Good Plugins vulnerabilities

12 hours 54 minutes ago
Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-17072) Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed certain AVI files. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-73433) Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse certain AVI files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-73434) Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled certain closed caption data. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88914)

docker-buildx-0.37.2-1.fc43

14 hours 46 minutes ago
FEDORA-2026-d1b26c4745 Packages in this update:
  • docker-buildx-0.37.2-1.fc43
Update description:
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

docker-buildx-0.37.2-1.fc44

15 hours 24 minutes ago
FEDORA-2026-af9902ab5e Packages in this update:
  • docker-buildx-0.37.2-1.fc44
Update description:
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

USN-8862-1: libXpm vulnerability

16 hours 50 minutes ago
It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service.

USN-8861-1: OpenSSL vulnerabilities

17 hours 39 minutes ago
It was discovered that OpenSSL had an inefficient algorithm in its QUIC stream reassembly implementation. A remote attacker could possibly use this issue to cause OpenSSL to use excessive CPU resources, leading to a denial of service. (CVE-2026-42772) It was discovered that OpenSSL did not properly limit memory allocated for QUIC packet buffers. A remote attacker could possibly use this issue to cause OpenSSL to use excessive memory resources, leading to a denial of service. (CVE-2026-54873)

USN-8857-1: KCoreAddons vulnerability

18 hours 52 minutes ago
It was discovered that KCoreAddons incorrectly handled shell argument quoting in KShell::quoteArgs. The parsing did not adequately handle shell metacharacters, which could lead to a shell escape. An attacker could possibly use this issue to execute arbitrary commands in applications that relied on this method to handle user input.