Aggregator

USN-8112-2: Linux kernel (FIPS) vulnerabilities

2 hours 12 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - MMC subsystem; - Network drivers; - USB Device Class drivers; - BTRFS file system; - HFS+ file system; - XFRM subsystem; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Simplified Mandatory Access Control Kernel framework; (CVE-2021-47599, CVE-2022-48875, CVE-2022-49267, CVE-2024-47659, CVE-2024-49927, CVE-2024-56548, CVE-2024-56581, CVE-2024-56593, CVE-2025-21704, CVE-2025-40215)

USN-8112-1: Linux kernel vulnerabilities

2 hours 26 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - MMC subsystem; - Network drivers; - USB Device Class drivers; - BTRFS file system; - HFS+ file system; - XFRM subsystem; - IPv4 networking; - IPv6 networking; - MAC80211 subsystem; - Simplified Mandatory Access Control Kernel framework; (CVE-2021-47599, CVE-2022-48875, CVE-2022-49267, CVE-2024-47659, CVE-2024-49927, CVE-2024-56548, CVE-2024-56581, CVE-2024-56593, CVE-2025-21704, CVE-2025-40215)

rubygem-json-2.13.2-2.fc43

7 hours 13 minutes ago
FEDORA-2026-8c07fcde49 Packages in this update:
  • rubygem-json-2.13.2-2.fc43
Update description:

This new updates backports a fix for a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210

perl-YAML-Syck-1.37-1.el9

17 hours 46 minutes ago
FEDORA-EPEL-2026-52be5354a0 Packages in this update:
  • perl-YAML-Syck-1.37-1.el9
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_2

17 hours 46 minutes ago
FEDORA-EPEL-2026-de60bba45b Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_2
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_3

17 hours 46 minutes ago
FEDORA-EPEL-2026-e7f8f46758 Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_3
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc43

18 hours 43 minutes ago
FEDORA-2026-3572f7e01c Packages in this update:
  • perl-YAML-Syck-1.37-1.fc43
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc44

18 hours 43 minutes ago
FEDORA-2026-a8d89d8ae2 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc44
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc42

18 hours 43 minutes ago
FEDORA-2026-d226775800 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc42
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

USN-8105-2: FreeRDP regression

19 hours 7 minutes ago
USN-8105-1 fixed vulnerabilities in FreeRDP. The update introduced a regression which could cause FreeRDP to crash. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that FreeRDP incorrectly handled certain RDP packets. A remote attacker could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8111-1: OpenStack Glance vulnerability

21 hours 16 minutes ago
It was discovered that OpenStack Glance was incorrectly validating the IP addresses and the redirect destination URL when downloading or importing images from a remote source. An attacker could possibly use this issue to perform server-side request forgery and obtain sensitive information.

libsoup3-3.6.6-2.fc43

21 hours 25 minutes ago
FEDORA-2026-f029d04054 Packages in this update:
  • libsoup3-3.6.6-2.fc43
Update description:

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

libsoup3-3.6.6-6.fc44

21 hours 26 minutes ago
FEDORA-2026-55dabf3975 Packages in this update:
  • libsoup3-3.6.6-6.fc44
Update description:

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)