Aggregator

mongo-c-driver-1.30.11-1.el9

3 hours 41 minutes ago
FEDORA-EPEL-2026-f3189ad8bc Packages in this update:
  • mongo-c-driver-1.30.11-1.el9
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.fc43

3 hours 41 minutes ago
FEDORA-2026-b4c749cdd2 Packages in this update:
  • mongo-c-driver-1.30.11-1.fc43
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.el10_2

3 hours 41 minutes ago
FEDORA-EPEL-2026-a7a6a60c98 Packages in this update:
  • mongo-c-driver-1.30.11-1.el10_2
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.el8

3 hours 41 minutes ago
FEDORA-EPEL-2026-633d87af00 Packages in this update:
  • mongo-c-driver-1.30.11-1.el8
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-1.30.11-1.fc44

3 hours 41 minutes ago
FEDORA-2026-4286ff2dfd Packages in this update:
  • mongo-c-driver-1.30.11-1.fc44
Update description: libbson 1.30.11

Fixes

  • Fix length check in bson_new_from_buffer.
libmongoc 1.30.11

Fixes

  • Fix allocation in Windows Secure Channel.
  • Fix error handling in SCRAM authentication.
libmongoc 1.30.10

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.fc45

4 hours 4 minutes ago
FEDORA-2026-0fcc2d09c6 Packages in this update:
  • mongo-c-driver-2.5.4-1.fc45
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.el10_3

4 hours 4 minutes ago
FEDORA-EPEL-2026-8775c68ed7 Packages in this update:
  • mongo-c-driver-2.5.4-1.el10_3
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

mongo-c-driver-2.5.4-1.el10_4

4 hours 4 minutes ago
FEDORA-EPEL-2026-aa805ed951 Packages in this update:
  • mongo-c-driver-2.5.4-1.el10_4
Update description: libmongoc 2.5.4

Fixes

  • Fix allocation in Windows Secure Channel.
libmongoc 2.5.3

Fixes

  • Use exact match for file ID in GridFS methods CVE-2026-88036
  • Validate SASL username CVE-2026-88035

wordpress-6.9.8-1.el9

4 hours 20 minutes ago
FEDORA-EPEL-2026-30ba647e0d Packages in this update:
  • wordpress-6.9.8-1.el9
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.fc43

4 hours 20 minutes ago
FEDORA-2026-03794a8ad4 Packages in this update:
  • wordpress-6.9.8-1.fc43
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.el10_2

4 hours 20 minutes ago
FEDORA-EPEL-2026-92398592b0 Packages in this update:
  • wordpress-6.9.8-1.el10_2
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.8-1.fc44

4 hours 20 minutes ago
FEDORA-2026-1811aa4e7c Packages in this update:
  • wordpress-6.9.8-1.fc44
Update description: WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.el10_3

4 hours 31 minutes ago
FEDORA-EPEL-2026-d3f5e5502d Packages in this update:
  • wordpress-7.1.1-1.el10_3
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.fc45

4 hours 31 minutes ago
FEDORA-2026-4b2be5b3a2 Packages in this update:
  • wordpress-7.1.1-1.fc45
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-7.1.1-1.el10_4

4 hours 31 minutes ago
FEDORA-EPEL-2026-86738cd79a Packages in this update:
  • wordpress-7.1.1-1.el10_4
Update description: WordPress 7.1.1 Maintenance and Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

USN-8779-2: Bubblewrap regression

12 hours 23 minutes ago
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This update reverts that fix until a complete fix is available. We apologize for the inconvenience. Original advisory details: It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-12439) It was discovered that Bubblewrap incorrectly handled certain symlinks during sandbox setup. A local attacker could possibly use this issue to create files outside of the sandbox. (CVE-2026-87766)

xen-4.20.4-2.fc43

14 hours 24 minutes ago
FEDORA-2026-a9ea805bc1 Packages in this update:
  • xen-4.20.4-2.fc43
Update description:

x86: DMs may cause mem leak by IRQ binding [XSA-509, CVE-2026-62437] x86: improper handling of HVM emulation return codes [XSA-510, CVE-2026-79602] Unconditionally do TLB flushing ahead of page scrubbing [XSA-511, CVE-2026-79603] oxenstored: Unbounded accumulation of watches [XSA-512, CVE-2026-79604]