Aggregator

USN-5376-6: Git regression

3 hours 15 minutes ago
USN-5376-4 fixed a regression in Git. This update provides the corresponding update for Ubuntu 18.04 LTS. We apologize for the inconvenience. Original advisory details: 俞晨东 discovered that Git incorrectly handled certain repository paths in platforms with multiple users support. An attacker could possibly use this issue to run arbitrary commands.

perl-Crypt-SysRandom-XS-0.011-1.fc42

8 hours 2 minutes ago
FEDORA-2026-c0123ede74 Packages in this update:
  • perl-Crypt-SysRandom-XS-0.011-1.fc42
Update description:

0.011 - Update data pointer on resize for rdrand; Clean up string length handling 0.010 - Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

perl-Crypt-SysRandom-XS-0.011-1.fc43

8 hours 2 minutes ago
FEDORA-2026-7b9874a01f Packages in this update:
  • perl-Crypt-SysRandom-XS-0.011-1.fc43
Update description:

0.011 - Update data pointer on resize for rdrand; Clean up string length handling 0.010 - Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS

perl-Net-CIDR-0.27-1.el9

1 day 5 hours ago
FEDORA-EPEL-2026-19279ff82c Packages in this update:
  • perl-Net-CIDR-0.27-1.el9
Update description:

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

perl-Net-CIDR-0.27-1.el10_1

1 day 5 hours ago
FEDORA-EPEL-2026-c2d409a4ce Packages in this update:
  • perl-Net-CIDR-0.27-1.el10_1
Update description:

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

perl-Net-CIDR-0.27-1.el8

1 day 5 hours ago
FEDORA-EPEL-2026-39c5d63f42 Packages in this update:
  • perl-Net-CIDR-0.27-1.el8
Update description:

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

perl-Net-CIDR-0.27-1.el10_3

1 day 5 hours ago
FEDORA-EPEL-2026-32a3851c80 Packages in this update:
  • perl-Net-CIDR-0.27-1.el10_3
Update description:

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

perl-Net-CIDR-0.27-1.el10_2

1 day 5 hours ago
FEDORA-EPEL-2026-36a72373e7 Packages in this update:
  • perl-Net-CIDR-0.27-1.el10_2
Update description:

This update fixes handling of leading zeroes.

The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users. In some cases an attacker may be able to leverage this to bypass access controls based on IP addresses.

perl-Net-CIDR-0.27-1.fc42

1 day 9 hours ago
FEDORA-2026-baf8782c7a Packages in this update:
  • perl-Net-CIDR-0.27-1.fc42
Update description:

Net::CIDR versions before 0.24 for Perl mishandle leading zeros in IP CIDR addresses, which may have unspecified impact. The functions addr2cidr and cidrlookup may return leading zeros in a CIDR string, which may in turn be parsed as octal numbers by subsequent users.

Current versions of the module strip leading zeros from octets.

chromium-145.0.7632.116-1.el10_3

2 days 11 hours ago
FEDORA-EPEL-2026-d6de408e6a Packages in this update:
  • chromium-145.0.7632.116-1.el10_3
Update description:

Update to 145.0.7632.116

  • CVE-2026-3061: Out of bounds read in Media
  • CVE-2026-3062: Out of bounds read and write in Tint
  • CVE-2026-3063: Inappropriate implementation in DevTools