53 minutes 6 seconds ago
Version:next-20260701 (linux-next)
Released:2026-07-01
54 minutes 19 seconds ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- DMA engine subsystem;
- InfiniBand drivers;
- STMicroelectronics network drivers;
- Network drivers;
- NVME drivers;
- SCSI subsystem;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Kernel thread helper (kthread);
- IPv6 networking;
- Tracing infrastructure;
- Kernel exit() syscall;
- Scatterlist API;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- IPv4 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SMC sockets;
- X.25 network layer;
(CVE-2026-22984, CVE-2026-23272, CVE-2026-23278, CVE-2026-23392,
CVE-2026-23427, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31418, CVE-2026-31436, CVE-2026-31448,
CVE-2026-31478, CVE-2026-31607, CVE-2026-31635, CVE-2026-31637,
CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668,
CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-31718,
CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071,
CVE-2026-43083, CVE-2026-43114, CVE-2026-43117, CVE-2026-43125,
CVE-2026-43186, CVE-2026-43197, CVE-2026-43304, CVE-2026-43341,
CVE-2026-43376, CVE-2026-43378, CVE-2026-43383, CVE-2026-43384,
CVE-2026-43402, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414,
CVE-2026-43493, CVE-2026-43501, CVE-2026-45898, CVE-2026-45988,
CVE-2026-46039, CVE-2026-46043, CVE-2026-46115, CVE-2026-46119,
CVE-2026-46135, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243,
CVE-2026-46244, CVE-2026-46266, CVE-2026-46289, CVE-2026-46290,
CVE-2026-46316, CVE-2026-46325)
1 hour ago
FEDORA-2026-7ae597d1d2
Packages in this update:
Update description:
The 7.0.14-101/201 kernel builds contain a fix for an unprivileged container / jail escape. This has not been assigned a CVE number yet, but a POC is in the wild.
The 7.0.14 stable kernel update contains a number of important fixes across the tree.
1 hour 2 minutes ago
FEDORA-2026-35e2185559
Packages in this update:
Update description:
The 7.0.14-101/201 kernel builds contain a fix for an unprivileged container / jail escape. This has not been assigned a CVE number yet, but a POC is in the wild.
The 7.0.14 stable kernel update contains a number of important fixes across the tree.
1 hour 3 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- Block layer subsystem;
- Cryptographic API;
- DMA engine subsystem;
- InfiniBand drivers;
- STMicroelectronics network drivers;
- Network drivers;
- NVME drivers;
- SCSI subsystem;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Kernel thread helper (kthread);
- IPv6 networking;
- Tracing infrastructure;
- Kernel exit() syscall;
- Scatterlist API;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- IPv4 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SMC sockets;
- X.25 network layer;
(CVE-2026-22984, CVE-2026-23272, CVE-2026-23278, CVE-2026-23392,
CVE-2026-23427, CVE-2026-23428, CVE-2026-23450, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31418, CVE-2026-31436, CVE-2026-31448,
CVE-2026-31478, CVE-2026-31607, CVE-2026-31635, CVE-2026-31637,
CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668,
CVE-2026-31669, CVE-2026-31682, CVE-2026-31685, CVE-2026-31718,
CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43071,
CVE-2026-43083, CVE-2026-43114, CVE-2026-43117, CVE-2026-43125,
CVE-2026-43186, CVE-2026-43197, CVE-2026-43304, CVE-2026-43341,
CVE-2026-43376, CVE-2026-43378, CVE-2026-43383, CVE-2026-43384,
CVE-2026-43402, CVE-2026-43406, CVE-2026-43407, CVE-2026-43414,
CVE-2026-43493, CVE-2026-43501, CVE-2026-45898, CVE-2026-45988,
CVE-2026-46039, CVE-2026-46043, CVE-2026-46115, CVE-2026-46119,
CVE-2026-46135, CVE-2026-46185, CVE-2026-46195, CVE-2026-46243,
CVE-2026-46244, CVE-2026-46266, CVE-2026-46289, CVE-2026-46316,
CVE-2026-46325)
1 hour 35 minutes ago
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284, CVE-2026-43500, CVE-2026-45998, CVE-2026-46000)
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503,
CVE-2026-46300)
Qualys discovered that a race condition existed in the ptrace subsystem of
the Linux kernel when privileged processes are exiting. An unprivileged
local attacker could use this issue to expose sensitive information.
(CVE-2026-46333)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a memory leak when handling AppArmor notifications. A local
attacker could use this to cause resource exhaustion. (CVE-2026-47326)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contain a NULL pointer dereference when handling AppArmor notifications. A
local attacker could use this to cause a kernel oops. (CVE-2026-47327)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an invalid free when handling AppArmor notifications. A local
attacker could use this to corrupt kernel memory. (CVE-2026-47328)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained insufficient validation of AppArmor notification responses. A
local attacker could use this to allow crafted responses to be processed.
(CVE-2026-47329)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0 used
an uninitialized variable when handling AppArmor notifications. A local
attacker could use this to cause incorrect caching of data.
(CVE-2026-47330)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained an out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause information disclosure of kernel
memory. (CVE-2026-47332)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained a out-of-bounds (OOB) read when handling AppArmor notifications.
A local attacker could use this to cause kernel memory corruption and,
theoretically, influence processing of AppArmor policies. (CVE-2026-47333)
Tristan Madani discovered that Ubuntu Linux kernel 6.8, 6.17 and 7.0
contained incorrect holding of locks when handling AppArmor notifications.
A local attacker could use this to cause a kernel panic or deadlock.
(CVE-2026-47334)
Tristan Madani and Trevor Lawrence have each independently discovered that
Ubuntu Linux kernel 6.8, 6.17 and 7.0 contained a NULL pointer dereference
when handling AppArmor network socket mediation. A local attacker could use
this to cause a kernel oops. (CVE-2026-47337)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drivers;
- Hardware monitoring drivers;
- IIO subsystem;
- InfiniBand drivers;
- Input Device core drivers;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- IBM Advanced System Management driver;
- MTD block device drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- NVME drivers;
- Device tree and open firmware driver;
- PCI subsystem;
- Remote Processor subsystem;
- SCSI subsystem;
- SPI subsystem;
- Thermal drivers;
- VFIO drivers;
- Framebuffer layer;
- 9P distributed file system;
- AFS file system;
- Ceph distributed file system;
- EROFS file system;
- File systems infrastructure;
- Ext4 file system;
- Journaling layer for block devices (JBD2);
- File system notification infrastructure;
- NTFS3 file system;
- OCFS2 file system;
- Overlay file system;
- SMB network file system;
- UDF file system;
- XFS file system;
- Codetag library;
- Memory management;
- Tracing infrastructure;
- io_uring subsystem;
- Locking primitives;
- Scatterlist API;
- Heterogeneous memory management;
- Bluetooth subsystem;
- Ethernet bridge;
- CAIF protocol;
- Ceph Core library;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- Qualcomm IPC Router (QRTR);
- RDS protocol;
- RxRPC session sockets;
- SMC sockets;
- Stream parser;
- Landlock security;
- SELinux security module;
- ALSA framework;
- Generic PCM loopback sound driver;
- Creative Sound Blaster X-Fi driver;
- USB sound devices;
(CVE-2026-43491, CVE-2026-43493, CVE-2026-43494, CVE-2026-43499,
CVE-2026-43501, CVE-2026-45986, CVE-2026-45987, CVE-2026-45988,
CVE-2026-45989, CVE-2026-45990, CVE-2026-45991, CVE-2026-45994,
CVE-2026-45995, CVE-2026-45996, CVE-2026-45997, CVE-2026-45999,
CVE-2026-46001, CVE-2026-46002, CVE-2026-46003, CVE-2026-46004,
CVE-2026-46005, CVE-2026-46006, CVE-2026-46007, CVE-2026-46008,
CVE-2026-46009, CVE-2026-46010, CVE-2026-46011, CVE-2026-46012,
CVE-2026-46013, CVE-2026-46014, CVE-2026-46015, CVE-2026-46016,
CVE-2026-46018, CVE-2026-46019, CVE-2026-46020, CVE-2026-46021,
CVE-2026-46022, CVE-2026-46023, CVE-2026-46024, CVE-2026-46025,
CVE-2026-46026, CVE-2026-46027, CVE-2026-46028, CVE-2026-46029,
CVE-2026-46030, CVE-2026-46031, CVE-2026-46032, CVE-2026-46033,
CVE-2026-46034, CVE-2026-46035, CVE-2026-46036, CVE-2026-46037,
CVE-2026-46038, CVE-2026-46039, CVE-2026-46040, CVE-2026-46041,
CVE-2026-46042, CVE-2026-46043, CVE-2026-46044, CVE-2026-46045,
CVE-2026-46046, CVE-2026-46047, CVE-2026-46048, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46323, CVE-2026-46332, CVE-2026-52904,
CVE-2026-52905, CVE-2026-52906, CVE-2026-52907, CVE-2026-52933,
CVE-2026-53174)
1 hour 48 minutes ago
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drivers;
- HID subsystem;
- Microsoft Hyper-V drivers;
- Hardware monitoring drivers;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- Input Device core drivers;
- LED subsystem;
- Multiple devices driver;
- Media drivers;
- IBM Advanced System Management driver;
- MTD block device drivers;
- Network drivers;
- Microsoft Azure Network Adapter (MANA) driver;
- NTB driver;
- NVME drivers;
- Device tree and open firmware driver;
- PCI subsystem;
- Remote Processor subsystem;
- SCSI subsystem;
- SPI subsystem;
- Realtek RTL8723BS SDIO drivers;
- SM750 framebuffer staging driver;
- Thermal drivers;
- USB Gadget drivers;
- USB over IP driver;
- VFIO drivers;
- Framebuffer layer;
- 9P distributed file system;
- AFS file system;
- Ceph distributed file system;
- File systems infrastructure;
- EROFS file system;
- Ext4 file system;
- F2FS file system;
- FUSE (File system in Userspace);
- Journaling layer for block devices (JBD2);
- NILFS2 file system;
- File system notification infrastructure;
- NTFS3 file system;
- OCFS2 file system;
- SMB network file system;
- UDF file system;
- XFS file system;
- Codetag library;
- Memory management;
- Memory Management;
- KVM subsystem;
- Tracing infrastructure;
- User-space API (UAPI);
- io_uring subsystem;
- Locking primitives;
- Timer subsystem;
- Scatterlist API;
- Heterogeneous memory management;
- KASAN memory debugging framework;
- Bluetooth subsystem;
- Ethernet bridge;
- CAIF protocol;
- CAN network layer;
- Ceph Core library;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- NFC subsystem;
- Packet sockets;
- Qualcomm IPC Router (QRTR);
- RDS protocol;
- RxRPC session sockets;
- SMC sockets;
- Stream parser;
- Landlock security;
- SELinux security module;
- ALSA framework;
- Generic PCM loopback sound driver;
- FireWire sound drivers;
- Creative Sound Blaster X-Fi driver;
- QCOM ASoC drivers;
- USB sound devices;
- Objtool;
(CVE-2026-31532, CVE-2026-31574, CVE-2026-31575, CVE-2026-31576,
CVE-2026-31577, CVE-2026-31578, CVE-2026-31579, CVE-2026-31580,
CVE-2026-31581, CVE-2026-31582, CVE-2026-31583, CVE-2026-31584,
CVE-2026-31585, CVE-2026-31586, CVE-2026-31587, CVE-2026-31588,
CVE-2026-31589, CVE-2026-31590, CVE-2026-31591, CVE-2026-31592,
CVE-2026-31593, CVE-2026-31594, CVE-2026-31595, CVE-2026-31596,
CVE-2026-31597, CVE-2026-31598, CVE-2026-31599, CVE-2026-31600,
CVE-2026-31601, CVE-2026-31602, CVE-2026-31603, CVE-2026-31604,
CVE-2026-31605, CVE-2026-31606, CVE-2026-31607, CVE-2026-31608,
CVE-2026-31609, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612,
CVE-2026-31613, CVE-2026-31614, CVE-2026-31615, CVE-2026-31616,
CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620,
CVE-2026-31621, CVE-2026-31622, CVE-2026-31623, CVE-2026-31624,
CVE-2026-31625, CVE-2026-31626, CVE-2026-31627, CVE-2026-31628,
CVE-2026-31629, CVE-2026-31686, CVE-2026-31694, CVE-2026-31696,
CVE-2026-31697, CVE-2026-31698, CVE-2026-31699, CVE-2026-31700,
CVE-2026-31701, CVE-2026-31702, CVE-2026-31703, CVE-2026-31704,
CVE-2026-31705, CVE-2026-31706, CVE-2026-31707, CVE-2026-31708,
CVE-2026-31709, CVE-2026-31710, CVE-2026-31711, CVE-2026-31712,
CVE-2026-31713, CVE-2026-31714, CVE-2026-31715, CVE-2026-31716,
CVE-2026-31717, CVE-2026-31718, CVE-2026-31719, CVE-2026-43058,
CVE-2026-43071, CVE-2026-43072, CVE-2026-43073, CVE-2026-43348,
CVE-2026-43349, CVE-2026-43350, CVE-2026-43491, CVE-2026-43493,
CVE-2026-43499, CVE-2026-43501, CVE-2026-45986, CVE-2026-45987,
CVE-2026-45988, CVE-2026-45989, CVE-2026-45990, CVE-2026-45991,
CVE-2026-45994, CVE-2026-45995, CVE-2026-45996, CVE-2026-45997,
CVE-2026-45999, CVE-2026-46001, CVE-2026-46002, CVE-2026-46003,
CVE-2026-46004, CVE-2026-46005, CVE-2026-46006, CVE-2026-46007,
CVE-2026-46008, CVE-2026-46009, CVE-2026-46010, CVE-2026-46011,
CVE-2026-46012, CVE-2026-46013, CVE-2026-46014, CVE-2026-46015,
CVE-2026-46016, CVE-2026-46018, CVE-2026-46019, CVE-2026-46020,
CVE-2026-46021, CVE-2026-46022, CVE-2026-46023, CVE-2026-46024,
CVE-2026-46025, CVE-2026-46026, CVE-2026-46027, CVE-2026-46028,
CVE-2026-46029, CVE-2026-46030, CVE-2026-46031, CVE-2026-46032,
CVE-2026-46033, CVE-2026-46034, CVE-2026-46035, CVE-2026-46036,
CVE-2026-46037, CVE-2026-46038, CVE-2026-46039, CVE-2026-46040,
CVE-2026-46041, CVE-2026-46042, CVE-2026-46043, CVE-2026-46044,
CVE-2026-46045, CVE-2026-46046, CVE-2026-46047, CVE-2026-46049,
CVE-2026-46050, CVE-2026-46051, CVE-2026-46052, CVE-2026-46053,
CVE-2026-46054, CVE-2026-46056, CVE-2026-46057, CVE-2026-46058,
CVE-2026-46059, CVE-2026-46060, CVE-2026-46061, CVE-2026-46062,
CVE-2026-46063, CVE-2026-46064, CVE-2026-46065, CVE-2026-46066,
CVE-2026-46067, CVE-2026-46068, CVE-2026-46069, CVE-2026-46070,
CVE-2026-46071, CVE-2026-46072, CVE-2026-46073, CVE-2026-46074,
CVE-2026-46075, CVE-2026-46076, CVE-2026-46077, CVE-2026-46078,
CVE-2026-46079, CVE-2026-46080, CVE-2026-46081, CVE-2026-46082,
CVE-2026-46083, CVE-2026-46084, CVE-2026-46085, CVE-2026-46086,
CVE-2026-46087, CVE-2026-46088, CVE-2026-46089, CVE-2026-46090,
CVE-2026-46091, CVE-2026-46092, CVE-2026-46093, CVE-2026-46094,
CVE-2026-46095, CVE-2026-46096, CVE-2026-46097, CVE-2026-46098,
CVE-2026-46099, CVE-2026-46100, CVE-2026-46101, CVE-2026-46102,
CVE-2026-46103, CVE-2026-46115, CVE-2026-46119, CVE-2026-46135,
CVE-2026-46137, CVE-2026-46155, CVE-2026-46185, CVE-2026-46195,
CVE-2026-46243, CVE-2026-46244, CVE-2026-46276, CVE-2026-46277,
CVE-2026-46278, CVE-2026-46279, CVE-2026-46280, CVE-2026-46281,
CVE-2026-46282, CVE-2026-46283, CVE-2026-46284, CVE-2026-46285,
CVE-2026-46286, CVE-2026-46287, CVE-2026-46288, CVE-2026-46289,
CVE-2026-46316, CVE-2026-46332, CVE-2026-52904, CVE-2026-52905,
CVE-2026-52906, CVE-2026-52907, CVE-2026-52933)
3 hours 16 minutes ago
FEDORA-2026-602d919dbc
Packages in this update:
Update description:
- Fix CVE-2026-58058 (rhbz#2494410)
3 hours 17 minutes ago
FEDORA-2026-3b30fa1da4
Packages in this update:
Update description:
- Fix CVE-2026-58058 (rhbz#2494410)
3 hours 20 minutes ago
FEDORA-2026-0245fd9f84
Packages in this update:
Update description:
Automatic update for nmap-7.92-11.fc45.
Changelog
* Tue Jun 30 2026 Martin Osvald <
mosvald@redhat.com> - 4:7.92-11
- Fix CVE-2026-58058 (rhbz#2494410)
6 hours 55 minutes ago
FEDORA-2026-e55bcd0c54
Packages in this update:
- python-pendulum-3.2.0-1.fc43
Update description:
Update to 3.2.0 (final). Update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177.
10 hours 13 minutes ago
FEDORA-2026-f4272d87ef
Packages in this update:
Update description:
PHP version 8.4.23 (03 Jul 2026)
Core:
- Fixed bug GH-22280 (Incorrect compile error for goto to label preceding try/finally block). (Pratik Bhujel)
BCMath:
- Fixed issues with oversized allocations and signed overflow in bcround() and BcMath\Number::round(). (edorian)
Date:
- Fix incorrect recurrence check of DatePeriod::createFromISO8601String(). (ndossche)
DOM:
- Fix GH-22219 (Dom\XMLDocument::schemaValidate fails to resolve xs:QName with prefix from imported schema). (David Carlier)
Exif:
- Read correct value for single and double tags. (ndossche)
GD:
- Fixed bug GH-22121 (Double free in gdImageSetStyle() after overflow-triggered early return). (iliaal)
- Fixed bug GH-19666 (imageconvolution() unexpected nan filter value). (David Carlier)
- Fixed bug GH-19739 (imageellipse/imagefilledellipse overflow). (David Carlier)
- Fixed bug GH-19730 (imageaffine overflow). (David Carlier)
Intl:
- Fix incorrect argument positions for uninitialized calendar arguments in IntlCalendar::equals(), ::before(), ::after(), and ::isEquivalentTo(), and for invalid start/end arguments in transliterator_transliterate(). (Weilin Du)
- Fixed IntlTimeZone::getDisplayName() to synchronize object error state for invalid display types. (Weilin Du)
- Fixed Spoofchecker restriction-level APIs to only be exposed with ICU 53 and later. (Graham Campbell)
mysqli:
- Fix stmt->query leak in mysqli_execute_query() validation errors. (David Carlier)
Opcache:
- Fixed bug GH-20469 (Unsafe inheritance cache replay with reentrant autoloading). (Levi Morrison)
OpenSSL:
- Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD). (David Carlier)
Phar:
- Fixed a bypass of the magic ".phar" directory protection in Phar::addEmptyDir() for paths starting with "/.phar", while allowing non-magic directory names that merely share the ".phar" prefix. (Weilin Du)
Reflection:
- Preserve class-name case in ReflectionClass::getProperty() error messages and autoloading. (jorgsowa)
Sqlite:
- Fix error checks for column retrieval. (ndossche)
Zlib:
- Fixed memory leak if deflate initialization fails and there is a dict. (ndossche)
- Fixed memory leak in inflate_add(). (ndossche)
11 hours 25 minutes ago
FEDORA-2026-ec9cb4652f
Packages in this update:
Update description:
PHP version 8.5.8 (02 Jul 2026)
Core:
- Fixed bug GH-22280 (Incorrect compile error for goto to label preceding try/finally block). (Pratik Bhujel)
- Fixed bug GH-22112 (Assertion when error handler throws during NaN to bool/string coercion). (iliaal)
BCMath:
- Fixed issues with oversized allocations and signed overflow in bcround() and BcMath\Number::round(). (edorian)
Date:
- Fix incorrect recurrence check of DatePeriod::createFromISO8601String(). (ndossche)
Exif:
- Read correct value for single and double tags. (ndossche)
GD:
- Fixed bug GH-22121 (Double free in gdImageSetStyle() after overflow-triggered early return). (iliaal)
Intl:
- Fix incorrect argument positions for invalid start/end arguments in transliterator_transliterate(). (Weilin Du)
- Fixed IntlTimeZone::getDisplayName() to synchronize object error state for invalid display types. (Weilin Du)
Lexbor:
- Merge patch c3a6847. (ilutov, timwolla)
Opcache:
- Fixed bug GH-22265 (Another tailcall vm_interrupt bug). (Levi Morrison)
- Fixed bug GH-20469 (Unsafe inheritance cache replay with reentrant autoloading). (Levi Morrison)
- Fixed bug GH-21972 (Corrupted variable type when a typed by-value return contains a reference wrapper). (Weilin Du)
OpenSSL:
- Fixed bug GH-22187 (Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD). (David Carlier)
Phar:
- Fixed a bypass of the magic ".phar" directory protection in Phar::addEmptyDir() for paths starting with "/.phar", while allowing non-magic directory names that merely share the ".phar" prefix. (Weilin Du)
Reflection:
- Preserve class-name case in ReflectionClass::getProperty() error messages and autoloading. (jorgsowa)
SOAP:
- Fixed bug GH-22218 (SoapServer::handle() crash on $_SERVER not being an array). (David Carlier / Rex-Reynolds)
- Fixed bug GH-22285 (Soap server requires the raw input to be passed to $server->handle). (David Carlier / ndossche)
Sqlite:
- Fix error checks for column retrieval. (ndossche)
URI:
- Add LEXBOR_STATIC to CFLAGS_URI on Windows so ext/uri does not see LXB_API as __declspec(dllimport) when linked statically into PHP. (Luther Monson)
- Clean error logs before each Uri\WhatWg\Url wither call so that errors from previous wither calls are not returned the next time a UrlValidationError is thrown. (kocsismate)
Zlib:
- Fixed memory leak if deflate initialization fails and there is a dict. (ndossche)
- Fixed memory leak in inflate_add(). (ndossche)
17 hours 39 minutes ago
FEDORA-2026-abc468979d
Packages in this update:
- perl-CSS-Minifier-XS-0.15-1.fc43
Update description:
This package contains the Perl module CSS::Minifier::XS.
Versions of the module before 0.14 have a memory leak when the entire document is minified away (CVE-2026-13593).
This update brings version 0.15 which fixes this issue.
17 hours 39 minutes ago
FEDORA-2026-9f14575d85
Packages in this update:
- perl-CSS-Minifier-XS-0.15-1.fc44
Update description:
This package contains the Perl module CSS::Minifier::XS.
Versions of the module before 0.14 have a memory leak when the entire document is minified away (CVE-2026-13593).
This update brings version 0.15 which fixes this issue.
18 hours 12 minutes ago
FEDORA-2026-b43264dedb
Packages in this update:
Update description:
Automatic update for jq-1.8.2-4.fc45.
Changelog
* Sat Jun 20 2026 Filipe Rosset <
filiperosset@fedoraproject.org> - 1.8.2-4
- removed old upstreamed patches
* Sat Jun 20 2026 Filipe Rosset <
filiperosset@fedoraproject.org> - 1.8.2-3
- opt-in to packit for rawhide
* Sat Jun 20 2026 Filipe Rosset <
filiperosset@fedoraproject.org> - 1.8.2-2
- simplify .gitignore file
* Sat Jun 20 2026 Filipe Rosset <
filiperosset@fedoraproject.org> - 1.8.2-1
- update to 1.8.2 fixes rhbz#2458354 rhbz#2477179 rhbz#2477180 rhbz#2477235
rhbz#2477236 rhbz#2477522 rhbz#2477523
18 hours 41 minutes ago
FEDORA-2026-2559684e58
Packages in this update:
- python-pendulum-3.2.0-1.fc44
Update description:
Update to 3.2.0 (final). Update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177.
18 hours 48 minutes ago
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl incorrectly handled cookie parsing in
certain circumstances. A remote attacker could possibly use this issue
to set cookies that would be transmitted to unrelated third-party
domains. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and
Ubuntu 26.04 LTS. (CVE-2026-8924)
Joshua Rogers discovered that curl could double-free a GSASL context
when handling SASL authentication. A remote attacker could possibly use
this issue to cause a denial of service, or execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and
Ubuntu 26.04 LTS. (CVE-2026-8925)
Joshua Rogers discovered that curl could select the wrong password from
a .netrc file when a username was specified in the URL without a
password. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu
26.04 LTS. (CVE-2026-8926)
Ady Elouej discovered that curl did not clear proxy authentication
state between requests when reusing a handle with environment-variable
proxy configuration. A remote attacker could possibly use this issue to
obtain sensitive credentials. (CVE-2026-8927)
Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li discovered
that curl did not properly clear proxy authentication credentials when
instructed to do so. A remote attacker could possibly use this issue to
obtain sensitive credentials. This issue only affected Ubuntu 25.10 and
Ubuntu 26.04 LTS. (CVE-2026-9079)
Joshua Rogers discovered that curl contained a use-after-free when
curl_easy_pause() was called within the event-based socket callback. A
remote attacker could possibly use this issue to cause a denial of service
or possibly execute arbitrary code. This issue only affected Ubuntu 25.10
and Ubuntu 26.04 LTS. (CVE-2026-9080)
Eunsoo Kim discovered that curl could send early data on a resumed TLS
session before enforcing certificate verification failure. A
machine-in-the-middle attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu
26.04 LTS. (CVE-2026-9545)
Joshua Rogers discovered that curl did not properly reject host key
type mismatches when using the SSH key callback for SCP and SFTP
transfers. A machine-in-the-middle attacker could possibly use this
issue to impersonate a trusted server. This issue only affected Ubuntu
22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.
(CVE-2026-9547)
22 hours 50 minutes ago
Version:next-20260630 (linux-next)
Released:2026-06-30
1 day ago
FEDORA-2026-0ed2011b62
Packages in this update:
- transmission-4.1.3-1.fc43
Update description:
Fixed a CORS bug that leaked the anti-CSRF nonce. (#8938)
Fixed a use-after-free bug in peer code. (#8921)
Fixed build error when compiling with fmt 12.2.0. (#8942)
Fix qt icon