Aggregator

xorg-x11-server-Xwayland-24.1.14-1.fc43

1 hour 56 minutes ago
FEDORA-2026-112c430ffc Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc43
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

xorg-x11-server-Xwayland-24.1.14-1.fc44

2 hours 10 minutes ago
FEDORA-2026-2448dda850 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc44
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

xorg-x11-server-Xwayland-24.1.14-1.fc45

2 hours 22 minutes ago
FEDORA-2026-2460ebb288 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc45
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

curl-8.15.0-11.fc43

3 hours 4 minutes ago
FEDORA-2026-3ea898ea77 Packages in this update:
  • curl-8.15.0-11.fc43
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

USN-8893-1: Libwebsockets vulnerabilities

5 hours 1 minute ago
It was discovered that libwebsockets did not properly validate user-supplied data when parsing HTTP/2 HPACK path headers, which could result in a write past the end of an allocated buffer. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-19773) It was discovered that libwebsockets did not properly handle CBOR recording in the LECP parser, which could result in a write past the end of an allocated buffer. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2026-78161)

wordpress-6.9.10-1.el9

5 hours 34 minutes ago
FEDORA-EPEL-2026-15d6637cee Packages in this update:
  • wordpress-6.9.10-1.el9
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.fc44

5 hours 34 minutes ago
FEDORA-2026-5ada1f2961 Packages in this update:
  • wordpress-6.9.10-1.fc44
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team