Aggregator

mongo-c-driver-2.5.6-1.fc45

19 minutes 4 seconds ago
FEDORA-2026-54d95e524b Packages in this update:
  • mongo-c-driver-2.5.6-1.fc45
Update description: libbson 2.5.6
  • Fix edge case in Decimal128 parsing. CVE-2026-106438
  • Enforce minimum size in bson_reserve_buffer. CVE-2026-106437
  • Fix bson_writer_new when writing empty documents. CVE-2026-106431

mongo-c-driver-2.5.6-1.el10_3

19 minutes 5 seconds ago
FEDORA-EPEL-2026-062cb358f2 Packages in this update:
  • mongo-c-driver-2.5.6-1.el10_3
Update description: libbson 2.5.6
  • Fix edge case in Decimal128 parsing. CVE-2026-106438
  • Enforce minimum size in bson_reserve_buffer. CVE-2026-106437
  • Fix bson_writer_new when writing empty documents. CVE-2026-106431

mongo-c-driver-2.5.6-1.el10_4

19 minutes 5 seconds ago
FEDORA-EPEL-2026-2ce5f50239 Packages in this update:
  • mongo-c-driver-2.5.6-1.el10_4
Update description: libbson 2.5.6
  • Fix edge case in Decimal128 parsing. CVE-2026-106438
  • Enforce minimum size in bson_reserve_buffer. CVE-2026-106437
  • Fix bson_writer_new when writing empty documents. CVE-2026-106431

docker-buildx-0.38.0-1.fc43

10 hours 20 minutes ago
FEDORA-2026-60dcacbb4f Packages in this update:
  • docker-buildx-0.38.0-1.fc43
Update description:
  • Update to release v0.38.0
  • Resolves: rhbz#2544412
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

USN-8910-1: libxml2 vulnerabilities

11 hours 55 minutes ago
Yirou Yang discovered that libxml2 incorrectly handled certain XML catalogs. If a user or automated system was tricked into processing a specially crafted XML catalog, an attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service. (CVE-2026-76781) It was discovered that libxml2 incorrectly handled certain large qualified names, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86138) It was discovered that libxml2 incorrectly handled escaping certain large URI strings. An attacker could possibly use this issue to cause libxml2 to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-86139) Xudong Cao and Meng Xu discovered that libxml2 incorrectly handled certain large XPointer expressions, leading to a heap-based buffer overflow. An attacker could possibly use this issue to cause libxml2 to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-86142) Xudong Cao and Meng Xu discovered that libxml2 did not check for integer overflows before passing output lengths to write callbacks. An attacker could possibly use this issue to cause an application using libxml2 to crash, resulting in a denial of service. (CVE-2026-86143) It was discovered that libxml2 did not apply parser options, such as disabling network access, when processing XInclude directives under certain circumstances. An attacker could possibly use this issue to perform XML external entity injection or server-side request forgery attacks, or cause a denial of service. (CVE-2026-86144)

docker-buildx-0.38.0-1.fc45

12 hours 47 minutes ago
FEDORA-2026-61b59254db Packages in this update:
  • docker-buildx-0.38.0-1.fc45
Update description:
  • Update to release v0.38.0
  • Resolves: rhbz#2544412
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

USN-8909-1: libde265 vulnerability

14 hours 49 minutes ago
It was discovered that libde265 did not properly validate certain crafted H.265 bitstreams, leading to a NULL pointer dereference. An attacker could possibly use this issue to cause libde265 to crash, resulting in a denial of service.

hamlib-4.5.5-2.el8

18 hours 4 minutes ago
FEDORA-EPEL-2026-9219ea595c Packages in this update:
  • hamlib-4.5.5-2.el8
Update description:

This is an update fixing stack out-of-bounds write and uninitialized memory disclosure (CVE-2026-54634).

hamlib-4.5.5-2.el9

18 hours 6 minutes ago
FEDORA-EPEL-2026-fe6a64f63f Packages in this update:
  • hamlib-4.5.5-2.el9
Update description:

This is an update fixing stack out-of-bounds write and uninitialized memory disclosure (CVE-2026-54634).

USN-8907-1: libgit2 vulnerability

18 hours 20 minutes ago
It was discovered that libgit2 incorrectly handled IP address SubjectAltName verification in TLS certificate validation. A remote attacker with a CA-trusted certificate could possibly use this issue to perform a machine-in-the-middle attack, leading to the exposure of sensitive information.

USN-8902-1: libarchive vulnerability

18 hours 47 minutes ago
It was discovered that libarchive had a signed integer overflow in its ZIP writer when handling encrypted entries with sizes near the maximum value. An attacker could possibly use this issue to cause libarchive to crash or execute arbitrary code.

python-django5-5.2.18-1.fc44

18 hours 54 minutes ago
FEDORA-2026-8a0e918188 Packages in this update:
  • python-django5-5.2.18-1.fc44
Update description:

Update Django 5 to version 5.2.18

  • Fixes CVE-2026-77050 [low]: Potential denial-of-service vulnerability in get_supported_language_variant()
  • Fixes CVE-2026-84429 [moderate]: Potential denial-of-service vulnerability in HTTP header parsing
  • Fixes CVE-2026-87890 [moderate]: Potential request forgery via spatial lookup byte values
  • Fixes CVE-2026-87975 [moderate]: Privilege abuse in model formsets with editable primary keys

See https://docs.djangoproject.com/en/dev/releases/5.2.18/ for more details

python-django5-5.2.18-1.fc45

18 hours 54 minutes ago
FEDORA-2026-36373ca634 Packages in this update:
  • python-django5-5.2.18-1.fc45
Update description:

Update Django 5 to version 5.2.18

  • Fixes CVE-2026-77050 [low]: Potential denial-of-service vulnerability in get_supported_language_variant()
  • Fixes CVE-2026-84429 [moderate]: Potential denial-of-service vulnerability in HTTP header parsing
  • Fixes CVE-2026-87890 [moderate]: Potential request forgery via spatial lookup byte values
  • Fixes CVE-2026-87975 [moderate]: Privilege abuse in model formsets with editable primary keys

See https://docs.djangoproject.com/en/dev/releases/5.2.18/ for more details

python-django5-5.2.18-1.fc43

18 hours 54 minutes ago
FEDORA-2026-a7b8ff851a Packages in this update:
  • python-django5-5.2.18-1.fc43
Update description:

Update Django 5 to version 5.2.18

  • Fixes CVE-2026-77050 [low]: Potential denial-of-service vulnerability in get_supported_language_variant()
  • Fixes CVE-2026-84429 [moderate]: Potential denial-of-service vulnerability in HTTP header parsing
  • Fixes CVE-2026-87890 [moderate]: Potential request forgery via spatial lookup byte values
  • Fixes CVE-2026-87975 [moderate]: Privilege abuse in model formsets with editable primary keys

See https://docs.djangoproject.com/en/dev/releases/5.2.18/ for more details