Aggregator

opkssh-0.15.0-2.el10_2

5 hours 12 minutes ago
FEDORA-EPEL-2026-2dad2b9f74 Packages in this update:
  • opkssh-0.15.0-2.el10_2
Update description:

Update to opkssh 0.15.0.

This release fixes several CVEs in bundled/vendored dependencies:

  • CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
  • CVE-2026-39833: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
  • CVE-2026-27145: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (fixed via the Go toolchain used to build this package)

opkssh-0.15.0-2.el10_3

5 hours 15 minutes ago
FEDORA-EPEL-2026-229e7ad5a2 Packages in this update:
  • opkssh-0.15.0-2.el10_3
Update description:

Update to opkssh 0.15.0.

This release fixes several CVEs in bundled/vendored dependencies:

  • CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
  • CVE-2026-39833: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
  • CVE-2026-27145: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (fixed via the Go toolchain used to build this package)

opkssh-0.15.0-2.fc44

5 hours 15 minutes ago
FEDORA-2026-a7570524a7 Packages in this update:
  • opkssh-0.15.0-2.fc44
Update description:

Update to opkssh 0.15.0.

This release fixes several CVEs in bundled/vendored dependencies:

  • CVE-2026-39829: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
  • CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
  • CVE-2026-39833: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
  • CVE-2026-27145: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (fixed via the Go toolchain used to build this package)

opkssh-0.15.0-2.fc43

5 hours 22 minutes ago
FEDORA-2026-387cf555e7 Packages in this update:
  • opkssh-0.15.0-2.fc43
Update description:

Update to opkssh 0.15.0.

This release fixes several CVEs in bundled/vendored dependencies:

  • CVE-2026-39829: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters
  • CVE-2026-39835: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate
  • CVE-2026-39833: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation
  • CVE-2026-27145: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (fixed via the Go toolchain used to build this package)

perl-HTML-Gumbo-0.19-1.fc44

5 hours 24 minutes ago
FEDORA-2026-75010c7f44 Packages in this update:
  • perl-HTML-Gumbo-0.19-1.fc44
Update description:

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion.

Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses.</template>

perl-HTML-Gumbo-0.19-1.fc43

5 hours 24 minutes ago
FEDORA-2026-a457bf78b4 Packages in this update:
  • perl-HTML-Gumbo-0.19-1.fc43
Update description:

This package provides the Perl module HTML::Gumbo. Versions before 0.19 disclose heap memory via type confusion.

Support for the <template> element was added to libgumbo 0.10.0 in 2015, but the walk_tree function in lib/HTML/Gumbo.xs was not updated to support it. The element was treated as a text-node, where strlen() over-reads the heap block that the pointer addresses.</template>

docker-compose-5.3.0-1.fc45

6 hours 33 minutes ago
FEDORA-2026-caecf8f2d7 Packages in this update:
  • docker-compose-5.3.0-1.fc45
Update description:

Automatic update for docker-compose-5.3.0-1.fc45.

Changelog * Thu Jul 2 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 5.3.0-1 - Update to release v5.3.0 - Resolves: rhbz#2496535 - Resolves CVE-2026-53492: rhbz#2496550 - Resolves CVE-2026-47262: rhbz#2496433 - Upstream note: This release introduces native support for init containers. - Additional upstream fixes and new features

USN-8500-1: Vim vulnerabilities

9 hours 42 minutes ago
It was discovered that Vim incorrectly handled path traversal in the zip.vim plugin. An attacker could possibly use this issue to overwrite arbitrary files. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-35177) It was discovered that Vim incorrectly handled depth tracking when processing spell files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-55693, CVE-2026-55892) It was discovered that Vim incorrectly handled filename escaping in the netrw plugin. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-55895) It was discovered that Vim incorrectly handled length calculations when opening encrypted files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-57452) Dhruv Vishesh Gupta discovered that Vim incorrectly handled quoting of archive entry names. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-57453) It was discovered that Vim incorrectly handled bounds checking when translating words through a byte map. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-57455) Chenyuan Mi discovered that Vim incorrectly handled docstring escaping during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-57456)