2 hours 9 minutes ago
2 hours 9 minutes ago
2 hours 9 minutes ago
4 hours 33 minutes ago
FEDORA-2026-2a6ce5b288
Packages in this update:
Update description:
Update to upstream v1.4.2 (security release).
- Fix AudioBridge recordings bypassing protected folders (PR #3676)
- Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
- Better enforcement of max publishers in VideoRoom (PR #3678)
- Validate list of usernames in TextRoom batch message (PR #3679)
- Use size_t in strings replace helper (PR #3680)
- Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
- Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
- Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
- Fixed rare crash in AudioBridge plugin (PR #3664)
- Fixed one way audio after a long hold in the SIP plugin (PR #3640)
- Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)
4 hours 34 minutes ago
FEDORA-2026-256bf09e34
Packages in this update:
Update description:
Update to upstream v1.4.2 (security release).
- Fix AudioBridge recordings bypassing protected folders (PR #3676)
- Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
- Better enforcement of max publishers in VideoRoom (PR #3678)
- Validate list of usernames in TextRoom batch message (PR #3679)
- Use size_t in strings replace helper (PR #3680)
- Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
- Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
- Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
- Fixed rare crash in AudioBridge plugin (PR #3664)
- Fixed one way audio after a long hold in the SIP plugin (PR #3640)
- Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)
4 hours 34 minutes ago
FEDORA-2026-d58d30885a
Packages in this update:
Update description:
Update to upstream v1.4.2 (security release).
- Fix AudioBridge recordings bypassing protected folders (PR #3676)
- Fix missing protocol allowlist when using libcurl in Streaming/TextRoom plugins (PR #3677)
- Better enforcement of max publishers in VideoRoom (PR #3678)
- Validate list of usernames in TextRoom batch message (PR #3679)
- Use size_t in strings replace helper (PR #3680)
- Fix removal from wrong hashtable in SIP and NoSIP plugins (PR #3681)
- Add cap to helper threads in Streaming and VideoRoom plugins (PR #3682)
- Fixed memory leaks in loop allocation and ICE agent disposal (PR #3665, PR #3666)
- Fixed rare crash in AudioBridge plugin (PR #3664)
- Fixed one way audio after a long hold in the SIP plugin (PR #3640)
- Bumped API version patch to 11 (JANUS_VERSION_SO 2:11:0)
4 hours 55 minutes ago
FEDORA-2026-6debf34169
Packages in this update:
Update description:
This build adds a patch to fix CVE-2026-61714.
4 hours 55 minutes ago
FEDORA-2026-e5a087cb33
Packages in this update:
Update description:
This build adds a patch to fix CVE-2026-61714.
5 hours 25 minutes ago
FEDORA-EPEL-2026-d688c1b291
Packages in this update:
- djvulibre-3.5.29-1.el10_4
Update description:
Update to 3.5.29 to fix CVE-2025-53367.
7 hours 43 minutes ago
It was discovered that Atril did not properly sanitize command-line
arguments in PDF /GoToR actions. If a user opened a specially crafted PDF
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-46529)
It was discovered that Atril incorrectly handled certain PDF files. An
attacker could possibly use this issue to cause a denial of service or
to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-1010006)
Andy Nguyen discovered that Atril incorrectly handled certain images. An
attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS. (CVE-2019-11459)
7 hours 54 minutes ago
It was discovered that catdoc had an integer overflow when processing
shared string tables in malformed spreadsheet files. An attacker could
possibly use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-48877)
It was discovered that catdoc had an integer overflow when processing file
allocation tables in malformed document files. An attacker could possibly
use this issue to cause catdoc to crash or execute arbitrary code.
(CVE-2024-52035)
It was discovered that catdoc incorrectly validated sector sizes when
processing malformed document files, leading to an integer underflow. An
attacker could possibly use this issue to cause catdoc to crash or execute
arbitrary code. (CVE-2024-54028)
8 hours 12 minutes ago
It was discovered that pdfminer did not safely parse specially crafted
PDF files. An attacker could possibly use these issues to execute
arbitrary code. (CVE-2025-64512, CVE-2025-70559)
8 hours 22 minutes ago
It was discovered that Emacs improperly handled specially crafted SVG
images, resulting in memory corruption. An attacker could possibly use
this issue to cause Emacs to crash, resulting in a denial of service, or
obtain sensitive information.
8 hours 35 minutes ago
It was discovered that Booth did not properly validate message
authentication codes under certain circumstances. A remote attacker
could possibly use this issue to bypass authentication.
8 hours 43 minutes ago
Version:next-20260928 (linux-next)
Released:2026-09-28
9 hours ago
It was discovered that phpseclib did not perform constant-time padding
validation when using AES in CBC mode. A remote attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-32935)
It was discovered that phpseclib did not use a constant-time comparison
when validating SSH packet authentication codes. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2026-40194)
It was discovered that phpseclib did not properly limit object identifier
lengths when parsing ASN.1 data. An attacker could possibly use this issue
to cause phpseclib to use excessive resources, leading to a denial of
service. (CVE-2026-44167)
9 hours 13 minutes ago
Fabian Vogt discovered that Plasma Workspace did not properly authenticate
local clients connecting to the session manager. A local attacker could
possibly use this issue to execute arbitrary code as another user.
9 hours 22 minutes ago
It was discovered that dracut created initramfs images with overly
permissive permissions under certain circumstances. A local attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 16.04 LTS. (CVE-2016-8637)
It was discovered that dracut did not properly sanitize DHCP options
before writing them to shell scripts under certain circumstances. A remote
attacker controlling a DHCP server on the local network could possibly use
this issue to execute arbitrary code as root during system boot. This issue
only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-6893)
It was discovered that dracut did not properly quote error messages written
to shell scripts under certain circumstances. A remote attacker controlling
a DHCP server on the local network could possibly use this issue to execute
arbitrary code as root during system boot. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2026-15816)
It was discovered that dracut did not properly sanitize network
configuration data before writing it to a temporary shell script under
certain circumstances. A remote attacker controlling DHCP on the local
network could possibly use this issue to execute arbitrary code as root
during system boot. This issue only affected Ubuntu 22.04 LTS.
(CVE-2026-16445)
9 hours 34 minutes ago
It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)
It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)
It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)
It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)
It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)
It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)
It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)
It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)
It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)
It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)
It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)
It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)
It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)
It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)
It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)
It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)
It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)
It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)
9 hours 41 minutes ago
FEDORA-2026-203e30f5d8
Packages in this update:
- golang-x-mod-0.27.0-4.fc43
Update description:
Rebuild for security fixes