Aggregator
openvpn-2.7.8-1.el10_3
- openvpn-2.7.8-1.el10_3
Update to upstream 2.7.8 release
xorg-x11-server-Xwayland-24.1.14-1.fc43
- xorg-x11-server-Xwayland-24.1.14-1.fc43
Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536
sudo-1.9.17-10.p2.fc44
- sudo-1.9.17-10.p2.fc44
Fix for CVE-2026-96512
sudo-1.9.17-18.p2.fc45
- sudo-1.9.17-18.p2.fc45
Fix for CVE-2026-96512
openvpn-2.7.8-1.el10_4
- openvpn-2.7.8-1.el10_4
Update to upstream 2.7.8 release
xorg-x11-server-Xwayland-24.1.14-1.fc44
- xorg-x11-server-Xwayland-24.1.14-1.fc44
Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536
xorg-x11-server-Xwayland-24.1.14-1.fc45
- xorg-x11-server-Xwayland-24.1.14-1.fc45
Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536
jfrog-cli-2.126.0-1.el9
- jfrog-cli-2.126.0-1.el9
Update to 2.126.0.
jfrog-cli-2.126.0-1.el10_2
- jfrog-cli-2.126.0-1.el10_2
Update to 2.126.0.
jfrog-cli-2.126.0-1.el10_3
- jfrog-cli-2.126.0-1.el10_3
Update to 2.126.0.
jfrog-cli-2.126.0-1.el10_4
- jfrog-cli-2.126.0-1.el10_4
Update to 2.126.0.
jfrog-cli-2.126.0-1.fc45
- jfrog-cli-2.126.0-1.fc45
Update to 2.126.0.
jfrog-cli-2.126.0-1.fc44
- jfrog-cli-2.126.0-1.fc44
Update to 2.126.0.
openvpn-2.7.8-1.fc45
- openvpn-2.7.8-1.fc45
Update to upstream 2.7.8 release
openvpn-2.7.8-1.fc44
- openvpn-2.7.8-1.fc44
Update to upstream 2.7.8 release
curl-8.15.0-11.fc43
- curl-8.15.0-11.fc43
- fix secure cookie attribute bypass with tab (CVE-2026-80255)
- fix OpenSSL provider use-after-free (CVE-2026-80229)
USN-8893-1: Libwebsockets vulnerabilities
wordpress-6.9.10-1.el9
- wordpress-6.9.10-1.el9
Security updates included in this release
- A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
- A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
- A second-Order SQL injection in WordPress WXR export, reported by Anthropic
- A weakness allowing Author role users to sticky posts, reported by Anthropic
- Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
- Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
- Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team
wordpress-6.9.10-1.fc44
- wordpress-6.9.10-1.fc44
Security updates included in this release
- A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
- A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
- A second-Order SQL injection in WordPress WXR export, reported by Anthropic
- A weakness allowing Author role users to sticky posts, reported by Anthropic
- Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
- Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
- Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team