Aggregator

linux-firmware-20260810-1.fc43

8 hours 51 minutes ago
FEDORA-2026-e82e06fcae Packages in this update:
  • linux-firmware-20260810-1.fc43
Update description:

Update to 20260810:

  • amdgpu: numerous firmware updates
  • update firmware for MT7922 WiFi device
  • morsemicro: add firmware for mm8108 support
  • ath10k: WCN3990 hw1.0: update board-2.bin
  • Update firmware for an8811hb 2.5G ethernet phy
  • xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S
  • mediatek MT7922: update bluetooth firmware to 20260724143815
  • airoha: update AN7583 NPU firmwares to version 0.5
  • qcom: Add gpu firmwares for Eliza chipset
  • cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
  • rtw89: 8922d: add fw 0.35.113.2
  • qcom: venus-5.4: fix vp9 decoder assertion failure
  • qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
  • qcom: Update qdsp6sw firmware for shikra platform
  • amdgpu: DMCUB updates for various ASICs
  • intel_vpu: Update NPU firmware
  • qcom: Update DSP firmware for qcs8300 platform
  • tas2783: Add firmware for new soundwire devices
  • rtw88: add firmware v41.0.0 for RTL8723B
  • Update AMD cpu microcode
  • Add firmware file for Intel BlazarIW
  • Update firmware file for Intel BlazarI/BlazarU/Scorpius core
  • amdgpu: DMCUB updates for various ASICs
  • qcom: add ADSP firmware for hawi platform
  • powervr: add firmware for Imagination Technologies BXM-4-64 GPU
  • qcom: Update DSP firmware for sa8775p platform
  • xe: Release GuC firmware for NVL-S
  • cirrus: cs35l56: Update firmware for the ASUS UX5406SA
  • qcom: vpu: add Gen2 firmware binary for Purwa
  • cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
  • QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
  • iwlwifi: add Bz/Sc/Hr/Gf FW for core24.60-33 release
  • iwlwifi: update ty/So/Ma/cc/Qu/QuZ firmwares for core24.60-33 release
  • cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
  • ueagle-atm: sadly drop unlicensed files
  • qcom: sync audioreach firmwares from v1.0.4 build
  • QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
  • amdgpu: DMCUB updates for various ASICs
  • tas2781: Add firmware for new HP projects
  • rtw89: 8852a: add TX power track R34
  • Update AMD SEV firmware

linux-firmware-20260810-1.fc44

8 hours 51 minutes ago
FEDORA-2026-c53019ed4f Packages in this update:
  • linux-firmware-20260810-1.fc44
Update description:

Update to 20260810:

  • amdgpu: numerous firmware updates
  • update firmware for MT7922 WiFi device
  • morsemicro: add firmware for mm8108 support
  • ath10k: WCN3990 hw1.0: update board-2.bin
  • Update firmware for an8811hb 2.5G ethernet phy
  • xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S
  • mediatek MT7922: update bluetooth firmware to 20260724143815
  • airoha: update AN7583 NPU firmwares to version 0.5
  • qcom: Add gpu firmwares for Eliza chipset
  • cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
  • rtw89: 8922d: add fw 0.35.113.2
  • qcom: venus-5.4: fix vp9 decoder assertion failure
  • qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
  • qcom: Update qdsp6sw firmware for shikra platform
  • amdgpu: DMCUB updates for various ASICs
  • intel_vpu: Update NPU firmware
  • qcom: Update DSP firmware for qcs8300 platform
  • tas2783: Add firmware for new soundwire devices
  • rtw88: add firmware v41.0.0 for RTL8723B
  • Update AMD cpu microcode
  • Add firmware file for Intel BlazarIW
  • Update firmware file for Intel BlazarI/BlazarU/Scorpius core
  • amdgpu: DMCUB updates for various ASICs
  • qcom: add ADSP firmware for hawi platform
  • powervr: add firmware for Imagination Technologies BXM-4-64 GPU
  • qcom: Update DSP firmware for sa8775p platform
  • xe: Release GuC firmware for NVL-S
  • cirrus: cs35l56: Update firmware for the ASUS UX5406SA
  • qcom: vpu: add Gen2 firmware binary for Purwa
  • cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
  • QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
  • iwlwifi: add Bz/Sc/Hr/Gf FW for core24.60-33 release
  • iwlwifi: update ty/So/Ma/cc/Qu/QuZ firmwares for core24.60-33 release
  • cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
  • ueagle-atm: sadly drop unlicensed files
  • qcom: sync audioreach firmwares from v1.0.4 build
  • QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
  • amdgpu: DMCUB updates for various ASICs
  • tas2781: Add firmware for new HP projects
  • rtw89: 8852a: add TX power track R34
  • Update AMD SEV firmware

roundcubemail-1.6.18-1.el10_2

15 hours 20 minutes ago
FEDORA-EPEL-2026-4e7b9eeb2b Packages in this update:
  • roundcubemail-1.6.18-1.el10_2
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.6.18-1.el10_3

15 hours 20 minutes ago
FEDORA-EPEL-2026-c09c342945 Packages in this update:
  • roundcubemail-1.6.18-1.el10_3
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.6.18-1.fc43

15 hours 20 minutes ago
FEDORA-2026-914a40b4fd Packages in this update:
  • roundcubemail-1.6.18-1.fc43
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.7.3-1.fc44

15 hours 34 minutes ago
FEDORA-2026-2aa96a9ce5 Packages in this update:
  • roundcubemail-1.7.3-1.fc44
Update description: Release 1.7.3
  • OAuth: Don't log an error when a refreshed token's TTL is below refresh_interval (#10213)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Fix bug where searching in example_addressbook plugin was reporting zero results despite matches (#9022)
  • Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593)
  • Fix bug where the php session driver practically disabled session.lazy_write optimization (#9885, #10248)
  • Fix bug where dates could get displayed shifted back one day in some places (#9403)
  • Fix regression where it wasn't possible to hide a skin logo image anymore (#10254)
  • Fix decoding of multi-segment RFC2231 extended attachment filenames (#10268)
  • Fix vCard import silently dropping properties with a non-item group prefix (#10271)
  • Fix so REQUEST_URI is used as a fallback if PATH_INFO is empty in static.php (#10181)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

USN-8592-1: ImageMagick vulnerabilities

23 hours 32 minutes ago
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-30936) It was discovered that ImageMagick incorrectly handled extremely large XWD images. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. (CVE-2026-30937) It was discovered that ImageMagick incorrectly handled extremely large SFW images on 32-bit systems. An attacker could possibly use this issue to trigger an integer overflow, resulting in a denial of service. (CVE-2026-31853) It was discovered that ImageMagick incorrectly handled memory allocation failures in the sixel encoder. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-32259)