Aggregator

pack-0.40.8-1.el9

4 hours 23 minutes ago
FEDORA-EPEL-2026-75bd5ec746 Packages in this update:
  • pack-0.40.8-1.el9
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.el10_2

4 hours 23 minutes ago
FEDORA-EPEL-2026-394b18b263 Packages in this update:
  • pack-0.40.8-1.el10_2
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc43

4 hours 24 minutes ago
FEDORA-2026-e6e0368149 Packages in this update:
  • pack-0.40.8-1.fc43
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc44

4 hours 24 minutes ago
FEDORA-2026-8729dce4b8 Packages in this update:
  • pack-0.40.8-1.fc44
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

skopeo-1.22.2-2.fc44

5 hours 38 minutes ago
FEDORA-2026-9b2e56edf5 Packages in this update:
  • skopeo-1.22.2-2.fc44
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.26.5 which includes the fix.

skopeo-1.22.2-2.fc43

5 hours 38 minutes ago
FEDORA-2026-4d9a2870e5 Packages in this update:
  • skopeo-1.22.2-2.fc43
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.25.12 which includes the fix.

kernel-7.1.4-204.fc44

6 hours 19 minutes ago
FEDORA-2026-2b94d8d05c Packages in this update:
  • kernel-7.1.4-204.fc44
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

kernel-7.1.4-104.fc43

6 hours 19 minutes ago
FEDORA-2026-6503a6a639 Packages in this update:
  • kernel-7.1.4-104.fc43
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

USN-8591-1: AIOHTTP vulnerabilities

6 hours 41 minutes ago
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

USN-8590-1: Exim vulnerabilities

10 hours 20 minutes ago
It was discovered that Exim incorrectly handled certain command line options. A local attacker could possibly use this issue to access files outside of the spool area. It was discovered that Exim incorrectly handled string expansion in .local files. A local attacker could possibly use this issue to escalate privileges.

USN-8589-1: Apache HTTP Server vulnerabilities

10 hours 36 minutes ago
It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-29167) It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled HTML generation for FTP directory listings. A remote attacker could possibly use this issue to inject arbitrary web script or HTML. (CVE-2026-29170) Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module was vulnerable to a timing attack. A remote attacker could possibly use this issue to bypass Digest authentication. (CVE-2026-33006)

USN-8588-1: Gawk vulnerabilities

10 hours 48 minutes ago
It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It was discovered that Gawk incorrectly handled certain integer calculations when allocating memory. An attacker could possibly use this issue to cause a denial of service or overwrite heap memory with attacker-controlled data. (CVE-2026-40468) It was discovered that Gawk incorrectly handled certain integer calculations when performing substitutions. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40469) It was discovered that Gawk incorrectly handled memory when reading directory entries. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-40553)

bpfman-0.5.4-13.fc45

11 hours 25 minutes ago
FEDORA-2026-fa34dc95e6 Packages in this update:
  • bpfman-0.5.4-13.fc45
Update description:

Automatic update for bpfman-0.5.4-13.fc45.

Changelog * Wed Jul 22 2026 Daniel Mellado <dmellado@fedoraproject.org> - 0.5.4-13 - Bump vendored openssl to 0.10.78 / openssl-sys to 0.9.117 for OpenSSL 4.0 support * Wed Jul 15 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.5.4-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 12 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 0.5.4-11 - Rebuilt for openssl 4.0 * Tue Apr 28 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-10 - update sources and spec * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-9 - add source vendor * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-8 - Fix CVE-2026-25727: Bump time to 0.3.47 - closes rhbz#2438107

USN-8477-3: tar regression

12 hours 15 minutes ago
USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could cause tar to fail to extract old archives that recorded a nonzero size for directory entries, resulting in a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms.