Aggregator

USN-8287-2: XDG Desktop Portal regression

5 hours 8 minutes ago
USN-8287-1 fixed a vulnerability in XDG Desktop Portal. Unfortunately the fix for CVE-2026-40354 was incomplete and introduced a regression when trashing files. This update fixes the problem and provides the corresponding update for Ubuntu 26.04 LTS. We apologize for the inconvenience. Original advisory details: It was discovered that XDG Desktop Portal incorrectly handled trashing files. A local attacker could possibly use this issue to delete arbitrary files on the host file system via a symlink attack.

USN-8809-1: libgit2 vulnerability

5 hours 19 minutes ago
Kazuma Matsumoto and Isabel Mill discovered that libgit2 incorrectly handled certain repository URLs when using the SSH transport. A remote attacker could possibly use this issue to execute arbitrary commands.

USN-8808-1: SQL parse vulnerabilities

5 hours 29 minutes ago
It was discovered that SQL parse contained multiple algorithmic complexity flaws when parsing SQL statements with deeply nested parentheses, comments, or dollar-quoted string literals. An attacker could use this issue to cause SQL parse to consume excessive CPU resources, resulting in a denial of service.

emacs-31.1-4.fc46

9 hours 13 minutes ago
FEDORA-2026-b3367f2111 Packages in this update:
  • emacs-31.1-4.fc46
Update description:

Automatic update for emacs-31.1-4.fc46.

Changelog * Wed Sep 23 2026 Peter Oliver <git@mavit.org.uk> - 1:31.1-4 - Prevent arbitrary code execution in flymake (rhbz#2537390).

hplip-3.26.6-1.fc43

10 hours 19 minutes ago
FEDORA-2026-59a4f90bc0 Packages in this update:
  • hplip-3.26.6-1.fc43
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097