Aggregator

pcs-0.12.3-1.fc44

2 hours 44 minutes ago
FEDORA-2026-ee77e0c099 Packages in this update:
  • pcs-0.12.3-1.fc44
Update description:
  • Rebased pcs to the newest major version (see CHANGELOG.md) - includes fix for CVE-2026-84828
  • Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.25 (see CHANGELOG_WUI.md)
  • pcs no longer depends on rubygems ethon and ffi, rubygem curb is used instead

pcs-0.12.3-1.fc43

2 hours 44 minutes ago
FEDORA-2026-96efddc493 Packages in this update:
  • pcs-0.12.3-1.fc43
Update description:
  • Rebased pcs to the newest major version (see CHANGELOG.md) - includes fix for CVE-2026-84828
  • Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.25 (see CHANGELOG_WUI.md)
  • pcs no longer depends on rubygems ethon and ffi, rubygem curb is used instead

unbound-1.26.1-1.fc43

3 hours 12 minutes ago
FEDORA-2026-41f949afc4 Packages in this update:
  • unbound-1.26.1-1.fc43
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.

unbound-1.26.1-1.fc44

3 hours 29 minutes ago
FEDORA-2026-996b326401 Packages in this update:
  • unbound-1.26.1-1.fc44
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.

unbound-1.26.1-1.fc45

4 hours 16 minutes ago
FEDORA-2026-3baacede89 Packages in this update:
  • unbound-1.26.1-1.fc45
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.

USN-8772-1: AOM vulnerabilities

5 hours 56 minutes ago
It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use this issue to cause a heap buffer overflow, leading to a denial of service or possibly execute arbitrary code. (CVE-2026-56208) It was discovered that AOM incorrectly validated spatial and temporal layer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker could possibly use this issue to write to an arbitrary memory address, read out-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209, CVE-2026-56210, CVE-2026-56211)

USN-8514-2: OpenSSH vulnerability

6 hours 39 minutes ago
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation.

USN-8770-1: SimpleSAMLphp vulnerabilities

23 hours 9 minutes ago
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596) It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use this issue to bypass authentication and impersonate users. (CVE-2025-27773)

USN-8769-1: phpseclib vulnerability

23 hours 26 minutes ago
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing attack and obtain sensitive information.