Aggregator

xen-4.21.2-2.fc44

2 hours 34 minutes ago
FEDORA-2026-1d448c1d40 Packages in this update:
  • xen-4.21.2-2.fc44
Update description:

x86: DMs may cause mem leak by IRQ binding [XSA-509, CVE-2026-62437] x86: improper handling of HVM emulation return codes [XSA-510, CVE-2026-79602] Unconditionally do TLB flushing ahead of page scrubbing [XSA-511, CVE-2026-79603] oxenstored: Unbounded accumulation of watches [XSA-512, CVE-2026-79604]

USN-8776-1: python-cryptography vulnerabilities

3 hours 50 minutes ago
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247) Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248) Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)

USN-8774-1: libheif vulnerabilities

7 hours 26 minutes ago
Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62377)

USN-8736-2: Perl vulnerabilities

9 hours 25 minutes ago
USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (CVE-2026-15534) It was discovered that Perl incorrectly handled certain regular expression containing alternative matching branches. An attacker could possibly use this issue to cause incorrect regular expression matches, resulting in security restrictions being bypassed. (CVE-2026-19487)

pcs-0.12.3-1.fc44

11 hours 21 minutes ago
FEDORA-2026-ee77e0c099 Packages in this update:
  • pcs-0.12.3-1.fc44
Update description:
  • Rebased pcs to the newest major version (see CHANGELOG.md) - includes fix for CVE-2026-84828
  • Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.25 (see CHANGELOG_WUI.md)
  • pcs no longer depends on rubygems ethon and ffi, rubygem curb is used instead

pcs-0.12.3-1.fc43

11 hours 21 minutes ago
FEDORA-2026-96efddc493 Packages in this update:
  • pcs-0.12.3-1.fc43
Update description:
  • Rebased pcs to the newest major version (see CHANGELOG.md) - includes fix for CVE-2026-84828
  • Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.25 (see CHANGELOG_WUI.md)
  • pcs no longer depends on rubygems ethon and ffi, rubygem curb is used instead

unbound-1.26.1-1.fc43

11 hours 49 minutes ago
FEDORA-2026-41f949afc4 Packages in this update:
  • unbound-1.26.1-1.fc43
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.

unbound-1.26.1-1.fc44

12 hours 6 minutes ago
FEDORA-2026-996b326401 Packages in this update:
  • unbound-1.26.1-1.fc44
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.

unbound-1.26.1-1.fc45

12 hours 53 minutes ago
FEDORA-2026-3baacede89 Packages in this update:
  • unbound-1.26.1-1.fc45
Update description: Update to 1.26.1 (rhbz#2535076)

Security fix list from upstream:

  • Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
  • Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
  • Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
  • Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
  • Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
  • Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
  • Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.