Aggregator

python-linkify-it-py-2.1.1-1.fc44

2 hours 43 minutes ago
FEDORA-2026-7c23b06d74 Packages in this update:
  • python-linkify-it-py-2.1.1-1.fc44
Update description:

Security release: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8).

  • Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82)
  • Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82)
  • Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
  • Update port.yml (linkify-it v5.0.2) (#82)

USN-8671-1: FFmpeg vulnerabilities

4 hours 17 minutes ago
Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-66038)

USN-8670-1: curl vulnerability

5 hours 2 minutes ago
Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

perl-DBD-Pg-3.21.1-2.fc44

7 hours 39 minutes ago
FEDORA-2026-bef4b3d7a3 Packages in this update:
  • perl-DBD-Pg-3.21.1-2.fc44
Update description:

Fix missing closing double-quote in su -c commands in dbdpg_test_setup.pl

3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183

chromium-151.0.7922.173-1.el10_2

8 hours 2 minutes ago
FEDORA-EPEL-2026-9264cd8a7d Packages in this update:
  • chromium-151.0.7922.173-1.el10_2
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.fc43

8 hours 2 minutes ago
FEDORA-2026-129176284e Packages in this update:
  • chromium-151.0.7922.173-1.fc43
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.el9

8 hours 2 minutes ago
FEDORA-EPEL-2026-62d65c771f Packages in this update:
  • chromium-151.0.7922.173-1.el9
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.fc44

8 hours 2 minutes ago
FEDORA-2026-7cee1b8755 Packages in this update:
  • chromium-151.0.7922.173-1.fc44
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.el10_3

8 hours 2 minutes ago
FEDORA-EPEL-2026-69c4d34cdb Packages in this update:
  • chromium-151.0.7922.173-1.el10_3
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

perl-DBD-Pg-3.21.1-1.fc44

10 hours 25 minutes ago
FEDORA-2026-fa463c2a7d Packages in this update:
  • perl-DBD-Pg-3.21.1-1.fc44
Update description:

3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183

python-aiohttp-3.14.3-3.fc45

13 hours 8 minutes ago
FEDORA-2026-e76e1f737b Packages in this update:
  • python-aiohttp-3.14.3-3.fc45
Update description:

Automatic update for python-aiohttp-3.14.3-3.fc45.

Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystem

python-aiohttp-3.14.3-3.fc46

13 hours 29 minutes ago
FEDORA-2026-84f7af8f97 Packages in this update:
  • python-aiohttp-3.14.3-3.fc46
Update description:

Automatic update for python-aiohttp-3.14.3-3.fc46.

Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystem

rpki-client-9.9-1.el10_2

22 hours 1 minute ago
FEDORA-EPEL-2026-f7b19f60e3 Packages in this update:
  • rpki-client-9.9-1.el10_2
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.