Aggregator

emacs-30.2-28.fc44

4 hours 34 minutes ago
FEDORA-2026-60eff202e7 Packages in this update:
  • emacs-30.2-28.fc44
Update description:

Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.

emacs-30.2-10.fc43

4 hours 37 minutes ago
FEDORA-2026-8894da1406 Packages in this update:
  • emacs-30.2-10.fc43
Update description:

Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.

curl-8.18.0-9.fc44

8 hours 45 minutes ago
FEDORA-2026-2f88b83676 Packages in this update:
  • curl-8.18.0-9.fc44
Update description:
  • Fix QUIC zero-length UDP datagrams busy-loop (CVE-2026-11352)
  • Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
  • Fix proto-default skips SSH verification (CVE-2026-12064)
  • Fix wrong STARTTLS connection reuse (CVE-2026-8286)
  • Fix SASL double-free (CVE-2026-8925)
  • Fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
  • Fix sending old referer (CVE-2026-9546)
  • Fix exposing HTTP/3 early data (CVE-2026-9545)
  • Fix UAF after pause in socket callback (CVE-2026-9080)

proftpd-1.3.9d-2.el10_4

9 hours 54 minutes ago
FEDORA-EPEL-2026-37261f4ecd Packages in this update:
  • proftpd-1.3.9d-2.el10_4
Update description:

Current upstream maintenance release, with a handful of potentially security-related bugfixes.

python-linkify-it-py-2.1.1-1.fc44

22 hours 48 minutes ago
FEDORA-2026-7c23b06d74 Packages in this update:
  • python-linkify-it-py-2.1.1-1.fc44
Update description:

Security release: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8).

  • Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82)
  • Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82)
  • Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
  • Update port.yml (linkify-it v5.0.2) (#82)

USN-8671-1: FFmpeg vulnerabilities

1 day ago
Adrian Junge was discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-66036, CVE-2026-66039) Adrian Junge discovered that FFmpeg incorrectly handled certain media files. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-66038)

USN-8670-1: curl vulnerability

1 day 1 hour ago
Joshua Rogers discovered that curl incorrectly handled reusing connections when client certificate settings changed. This could result in the wrong client certificates being used, contrary to expectations.

perl-DBD-Pg-3.21.1-2.fc44

1 day 3 hours ago
FEDORA-2026-bef4b3d7a3 Packages in this update:
  • perl-DBD-Pg-3.21.1-2.fc44
Update description:

Fix missing closing double-quote in su -c commands in dbdpg_test_setup.pl

3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183

chromium-151.0.7922.173-1.el10_2

1 day 4 hours ago
FEDORA-EPEL-2026-9264cd8a7d Packages in this update:
  • chromium-151.0.7922.173-1.el10_2
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.fc43

1 day 4 hours ago
FEDORA-2026-129176284e Packages in this update:
  • chromium-151.0.7922.173-1.fc43
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.el9

1 day 4 hours ago
FEDORA-EPEL-2026-62d65c771f Packages in this update:
  • chromium-151.0.7922.173-1.el9
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.fc44

1 day 4 hours ago
FEDORA-2026-7cee1b8755 Packages in this update:
  • chromium-151.0.7922.173-1.fc44
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming

chromium-151.0.7922.173-1.el10_3

1 day 4 hours ago
FEDORA-EPEL-2026-69c4d34cdb Packages in this update:
  • chromium-151.0.7922.173-1.el10_3
Update description:

Update to 151.0.7922.173

* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming