Aggregator

wordpress-6.9.7-1.fc43

39 minutes ago
FEDORA-2026-61704c09ea Packages in this update:
  • wordpress-6.9.7-1.fc43
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.el9

39 minutes ago
FEDORA-EPEL-2026-96feebe88a Packages in this update:
  • wordpress-6.9.7-1.el9
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.fc44

39 minutes 1 second ago
FEDORA-2026-dc0ff85b8b Packages in this update:
  • wordpress-6.9.7-1.fc44
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-7.0.4-1.el10_3

39 minutes 3 seconds ago
FEDORA-EPEL-2026-c91a425a57 Packages in this update:
  • wordpress-7.0.4-1.el10_3
Update description: WordPress 7.0.4 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 7.0.3 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

wordpress-6.9.7-1.el10_2

39 minutes 3 seconds ago
FEDORA-EPEL-2026-4f38e2a6eb Packages in this update:
  • wordpress-6.9.7-1.el10_2
Update description: WordPress 6.9.7 Release

Security update included in this release

  • Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
WordPress 6.9.6 Release

Security update included in this release

  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters

python-alembic-1.19.1-1.fc43 python-asyncmy-0.2.14-1.fc43 python-sqlalchemy-2.0.52-1.fc43

6 hours 57 minutes ago
FEDORA-2026-7d816931eb Packages in this update:
  • python-alembic-1.19.1-1.fc43
  • python-asyncmy-0.2.14-1.fc43
  • python-sqlalchemy-2.0.52-1.fc43
Update description:

This update contains new upstream releases for python-sqlalchemy (bugfixes), python-alembic (bugfixes) and python-asyncmy (bugfixes, security fixes and enhancements).

Please refer to upstream release notes and changelogs for details:

python-alembic-1.19.1-1.fc44 python-asyncmy-0.2.14-1.fc44 python-sqlalchemy-2.0.52-1.fc44

6 hours 57 minutes ago
FEDORA-2026-6f7b906353 Packages in this update:
  • python-alembic-1.19.1-1.fc44
  • python-asyncmy-0.2.14-1.fc44
  • python-sqlalchemy-2.0.52-1.fc44
Update description:

This update contains new upstream releases for python-sqlalchemy (bugfixes), python-alembic (bugfixes) and python-asyncmy (bugfixes, security fixes and enhancements).

Please refer to upstream release notes and changelogs for details:

USN-8632-1: follow-redirects vulnerability

8 hours 41 minutes ago
Dennis Sepede discovered that follow-redirects did not properly remove custom authentication headers when following cross-domain redirects. An attacker could possibly use this issue to obtain sensitive authentication information, resulting in credential disclosure.

USN-8636-1: Linux kernel vulnerabilities

9 hours 1 minute ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Media drivers; - Network drivers; - Mellanox network drivers; - Texas Instruments network drivers; - NVME drivers; - File systems infrastructure; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - Memory management; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-31405, CVE-2026-31414, CVE-2026-31501, CVE-2026-31589, CVE-2026-31633, CVE-2026-31636, CVE-2026-31705, CVE-2026-43198, CVE-2026-43379, CVE-2026-43465, CVE-2026-43499, CVE-2026-46113, CVE-2026-46137, CVE-2026-46242, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53131, CVE-2026-53176, CVE-2026-53212, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8635-1: Linux kernel (Azure) vulnerabilities

9 hours 6 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Tracing infrastructure; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - X.25 network layer; (CVE-2021-47202, CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43198, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43499, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8634-1: Linux kernel vulnerabilities

9 hours 13 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - STMicroelectronics network drivers; - Network drivers; - Ext4 file system; - IPv4 networking; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31659, CVE-2026-31685, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53176, CVE-2026-53225, CVE-2026-53359)

USN-8633-1: Linux kernel vulnerabilities

9 hours 13 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657, CVE-2026-31668, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8631-1: Linux kernel vulnerabilities

9 hours 18 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8630-1: Linux kernel vulnerabilities

9 hours 25 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)