3 hours 55 minutes ago
FEDORA-2026-571b7e1505
Packages in this update:
Update description:
Fix CVE-2026-84267, CVE-2026-84268, CVE-2026-84269, and CVE-2026-84270
6 hours 12 minutes ago
FEDORA-2026-c33332bcf7
Packages in this update:
Update description:
2.1.3, fix for CVE-2026-40898
6 hours 12 minutes ago
FEDORA-2026-bd6debcfb6
Packages in this update:
Update description:
2.1.3, fix for CVE-2026-40898
8 hours 55 minutes ago
FEDORA-2026-6d094c5360
Packages in this update:
- python-jwcrypto-1.6.0-1.fc45
Update description:
Low severity security fixes
8 hours 55 minutes ago
FEDORA-2026-8caad572b0
Packages in this update:
- python-jwcrypto-1.6.0-1.fc44
Update description:
Low severity security fixes
11 hours 7 minutes ago
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (CVE-2026-59884)
It was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID
values in quadratic time relative to the number of arcs. An attacker could
possibly use this issue to cause applications decoding untrusted ASN.1 data
to consume excessive CPU resources, resulting in a denial of service.
(CVE-2026-59885)
It was discovered that pyasn1 incorrectly handled conversion of decoded
REAL values to Python float types. An attacker could possibly use this
issue to cause applications decoding untrusted ASN.1 data to consume
excessive CPU and memory resources, resulting in a denial of service.
(CVE-2026-59886)
11 hours 13 minutes ago
It was discovered that Libgcrypt had a timing-based side-channel flaw in
its RSA implementation. A remote attacker could possibly use this issue to
obtain sensitive information.
11 hours 43 minutes ago
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
11 hours 47 minutes ago
Version:next-20260901 (linux-next)
Released:2026-09-01
11 hours 54 minutes ago
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu
14.04 LTS only, it was discovered that some machines were unable to
enable esm-infra-legacy due to a preemptive apt-helper check. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer
token in command-line arguments when validating APT credentials. A local
attacker could possibly use this issue to obtain sensitive information
and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)
Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly
validate data received from the contract server when writing APT source
files. An attacker could possibly use this issue to inject arbitrary APT
configuration and execute arbitrary code. (CVE-2026-11386)
Mateusz Gierblinski discovered that Ubuntu Advantage Tools did not
properly handle symbolic links when collecting diagnostic logs. A local
attacker could possibly use this issue to obtain sensitive information
from files owned by the administrator. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-12391)
11 hours 59 minutes ago
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-63381)
Rajat Raghav discovered that libevent incorrectly handled certain HTTP
requests. An attacker could possibly use this issue to desynchronize
HTTP request boundaries, resulting in HTTP request smuggling.
(CVE-2026-63382)
Qiu Sihao discovered that libevent incorrectly handled certain malformed
tagged RPC data. An attacker could possibly use this issue to trigger an
out-of-bounds read, resulting in a denial of service. (CVE-2026-63383)
Qiu Sihao discovered that libevent incorrectly handled certain large
payload lengths in tagged RPC data. An attacker could possibly use this
issue to consume excessive system resources, resulting in a denial of
service. (CVE-2026-63384)
Asaf Meizner discovered that libevent incorrectly handled certain HTTP
URIs and header values. An attacker could possibly use this issue to
cause HTTP messages to be interpreted inconsistently, resulting in
security restrictions being bypassed. (CVE-2026-63385)
12 hours 3 minutes ago
It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.
12 hours 23 minutes ago
FEDORA-2026-2719c6cac1
Packages in this update:
Update description:
5.6.1 release
12 hours 23 minutes ago
FEDORA-2026-8a0b0bba30
Packages in this update:
Update description:
5.6.1 release
5.6.1 release
13 hours 59 minutes ago
FEDORA-EPEL-2026-0563db3f0c
Packages in this update:
Update description:
Backport several CVE fixes
13 hours 59 minutes ago
FEDORA-EPEL-2026-aa30a19f4c
Packages in this update:
Update description:
Backport several CVE fixes
14 hours ago
FEDORA-EPEL-2026-1c4570b861
Packages in this update:
Update description:
Backport several CVE fixes
14 hours 1 minute ago
FEDORA-2026-3fe3e3ae10
Packages in this update:
Update description:
Backport several CVE fixes
14 hours 1 minute ago
FEDORA-2026-d91338eea8
Packages in this update:
Update description:
Backport several CVE fixes
14 hours 2 minutes ago
FEDORA-2026-20b7d49f70
Packages in this update:
Update description:
Backport several CVE fixes