Aggregator
USN-8112-1: Linux kernel vulnerabilities
python-ujson-5.8.0-2.el9
- python-ujson-5.8.0-2.el9
Backport fixes for CVE-2026-32874 and CVE-2026-32875
rubygem-json-2.13.2-2.fc43
- rubygem-json-2.13.2-2.fc43
This new updates backports a fix for a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210
bcftools-1.23.1-1.el8 htslib-1.23.1-1.el8 samtools-1.23.1-1.el8
- bcftools-1.23.1-1.el8
- htslib-1.23.1-1.el8
- samtools-1.23.1-1.el8
Update to 1.23.1
perl-YAML-Syck-1.37-1.el9
- perl-YAML-Syck-1.37-1.el9
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
perl-YAML-Syck-1.37-1.el10_2
- perl-YAML-Syck-1.37-1.el10_2
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
perl-YAML-Syck-1.37-1.el10_3
- perl-YAML-Syck-1.37-1.el10_3
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
perl-YAML-Syck-1.37-1.fc43
- perl-YAML-Syck-1.37-1.fc43
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
perl-YAML-Syck-1.37-1.fc44
- perl-YAML-Syck-1.37-1.fc44
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
perl-YAML-Syck-1.37-1.fc42
- perl-YAML-Syck-1.37-1.fc42
YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.
USN-8105-2: FreeRDP regression
bcftools-1.23.1-1.fc44 htslib-1.23.1-1.fc44 samtools-1.23.1-1.fc44
- bcftools-1.23.1-1.fc44
- htslib-1.23.1-1.fc44
- samtools-1.23.1-1.fc44
Update to 1.23.1
bcftools-1.23.1-1.fc43 htslib-1.23.1-1.fc43 samtools-1.23.1-1.fc43
- bcftools-1.23.1-1.fc43
- htslib-1.23.1-1.fc43
- samtools-1.23.1-1.fc43
Update to 1.23.1
bcftools-1.23.1-1.fc42 htslib-1.23.1-1.fc42 samtools-1.23.1-1.fc42
- bcftools-1.23.1-1.fc42
- htslib-1.23.1-1.fc42
- samtools-1.23.1-1.fc42
Update to 1.23.1
USN-8111-1: OpenStack Glance vulnerability
6.19.9: stable
libsoup3-3.6.6-2.fc43
- libsoup3-3.6.6-2.fc43
Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)
libsoup3-3.6.6-6.fc44
- libsoup3-3.6.6-6.fc44
Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)