Aggregator

chromium-154.0.8037.57-1.el10_2

1 hour 2 minutes ago
FEDORA-EPEL-2026-c4d340d432 Packages in this update:
  • chromium-154.0.8037.57-1.el10_2
Update description:

Update to 154.0.8037.57

CVE-2026-95274: Improper output encoding in DevTools CVE-2026-95275: Incorrect reference resolution in MediaStream CVE-2026-95276: Improper input validation in Themes CVE-2026-95277: Use after free in Views CVE-2026-95278: Missing authorization in WakeLock CVE-2026-95279: UI misrepresentation in Omnibox CVE-2026-95280: Race condition in V8 CVE-2026-95281: Buffer overflow in ANGLE CVE-2026-95282: Use after free in Platform CVE-2026-95283: Buffer overflow in Tint CVE-2026-95284: Buffer overflow in ANGLE CVE-2026-95285: Missing authorization in WebView CVE-2026-95286: Type confusion in Bindings CVE-2026-95287: Missing authorization in Navigation CVE-2026-95288: UI misrepresentation in Mobile CVE-2026-95289: Incorrect authorization in Scroll CVE-2026-95290: Missing authorization in NFC CVE-2026-95291: UI misrepresentation in SecurityIndicators CVE-2026-95292: Incorrect authorization in Safebrowsing CVE-2026-95293: Uninitialized resource in GPU CVE-2026-95294: UI misrepresentation in Browser CVE-2026-95295: Information leak in Mobile CVE-2026-95296: Missing authorization in Core CVE-2026-95297: Missing authorization in Contextual Tasks CVE-2026-95298: Use after free in Browser CVE-2026-95299: Use after free in GPU CVE-2026-95300: Missing authorization in DevTools CVE-2026-95301: Missing authorization in Extensions CVE-2026-95302: Incorrect authorization in WebAPKs CVE-2026-95303: Incomplete cleanup in SmartCard CVE-2026-95304: Out of bounds write in V8 CVE-2026-95305: UI misrepresentation in Chromoting CVE-2026-95306: Type confusion in V8 CVE-2026-95307: UI misrepresentation in ExtensionsMenu CVE-2026-95308: Integer overflow in Metrics CVE-2026-95309: UI misrepresentation in Mobile CVE-2026-95310: Use after free in AdFilter CVE-2026-95311: Free of non-heap memory in Fonts CVE-2026-95312: Information leak in Passwords CVE-2026-95313: Use after free in Fullscreen CVE-2026-95314: Incorrect authorization in HID CVE-2026-95315: Use after free in Aura CVE-2026-95316: Unchecked return value in Performance CVE-2026-95317: Incorrect authorization in MediaCapture CVE-2026-95318: Buffer overflow in Video CVE-2026-95319: Use after free in Printing CVE-2026-95320: Missing authorization in Navigation CVE-2026-95321: UI misrepresentation in Payments CVE-2026-95322: Out of bounds write in GPU CVE-2026-95323: UI misrepresentation in Chromium CVE-2026-95324: Uninitialized resource in GPU CVE-2026-95325: Use after free in ANGLE CVE-2026-95326: Incomplete cleanup in Bluetooth CVE-2026-95327: Information leak in Networking CVE-2026-95328: Confused deputy in Mobile CVE-2026-95329: Out of bounds write in WebGL CVE-2026-95330: Improper state validation in Downloads CVE-2026-95331: Out of bounds write in ANGLE CVE-2026-95332: Use of uninitialized variable in Tint CVE-2026-95333: Use after free in Metrics CVE-2026-95334: Incorrect reference resolution in WebProtect CVE-2026-95335: Use after free in HID CVE-2026-95336: Information leak in Transactions Platform CVE-2026-95337: UI misrepresentation in Messages CVE-2026-95338: Use after free in PDFium CVE-2026-95339: Use after free in ServiceWorker CVE-2026-95340: Incorrect authorization in PictureInPicture CVE-2026-95341: Improper input validation in Desktop CVE-2026-95342: Missing authorization in V8 CVE-2026-95343: Use after free in WebAudio CVE-2026-95344: Race condition in DevTools CVE-2026-95345: Use after free in Actor CVE-2026-95346: UI misrepresentation in Chromoting CVE-2026-95347: Use after free in Updater CVE-2026-95348: Use after free in Bluetooth CVE-2026-95349: Buffer overflow in WebGL CVE-2026-95350: Buffer overflow in ANGLE CVE-2026-95351: Use after free in Views CVE-2026-95352: Incorrect authorization in DevTools CVE-2026-95353: Use after free in Bindings CVE-2026-95354: Use after free in Verifier CVE-2026-95355: Incorrect authorization in Navigation CVE-2026-95356: Use after free in WindowDialog CVE-2026-95357: Out of bounds write in GPU CVE-2026-95358: Incorrect authorization in Mobile CVE-2026-95359: Uninitialized resource in GPU CVE-2026-95360: Race condition in Editing CVE-2026-95361: Confused deputy in DevTools CVE-2026-95362: Cross-site request forgery in DevTools CVE-2026-95363: UI misrepresentation in FileSystem CVE-2026-95364: Improper input validation in Passwords CVE-2026-95365: Type confusion in IndexedDB CVE-2026-95366: Use of released resource in Core CVE-2026-95367: Information leak in DataTransfer CVE-2026-95368: Incorrect authorization in DevTools CVE-2026-95369: Inappropriate implementation in XML CVE-2026-95370: Inappropriate implementation in NFC CVE-2026-95371: Missing authorization in Views CVE-2026-95372: Use after free in Chromecast CVE-2026-95373: Use after free in DevTools CVE-2026-95374: Incorrect authorization in Network CVE-2026-95375: Incorrect authorization in BrowserTag CVE-2026-95376: Externally controlled reference in DevTools CVE-2026-95380: Type confusion in V8 CVE-2026-95381: Improper input validation in Printing CVE-2026-95382: Improper input validation in Auth CVE-2026-95384: Race condition in Transactions Platform CVE-2026-95385: Inappropriate implementation in PlatformIntegration

python-engineio-4.12.3-2.el9 python-simple-websocket-1.0.0-8.el9

1 hour 51 minutes ago
FEDORA-EPEL-2026-e47857b934 Packages in this update:
  • python-engineio-4.12.3-2.el9
  • python-simple-websocket-1.0.0-8.el9
Update description:

Update python-engineio to 4.12.3, which is not the latest version but is the latest version that could be reasonably backported to EPEL9. This required branching a new package for python-simple-websocket 1.0.0 – again, not quite the latest version. Furthermore, this update includes a backport from versions 4.13.2 and 4.13.5 of the fixes for CVE-2026-48802 and CVE-2026-48809.

USN-8826-1: LXC vulnerabilities

2 hours 51 minutes ago
Maher Azzouzi discovered that LXC did not correctly handle logging certain failure messages. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2022-47952) Sam Sanoop discovered that LXC did not correctly handle certain forms of user authorization. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-39402)

cri-o1.36-1.36.6-1.fc43

10 hours 40 minutes ago
FEDORA-2026-0025579bc9 Packages in this update:
  • cri-o1.36-1.36.6-1.fc43
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc44

10 hours 55 minutes ago
FEDORA-2026-f5c88f763a Packages in this update:
  • cri-o1.36-1.36.6-1.fc44
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc45

11 hours 14 minutes ago
FEDORA-2026-77abfa2cdd Packages in this update:
  • cri-o1.36-1.36.6-1.fc45
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc46

11 hours 30 minutes ago
FEDORA-2026-05f65b07d7 Packages in this update:
  • cri-o1.36-1.36.6-1.fc46
Update description:

Automatic update for cri-o1.36-1.36.6-1.fc46.

Changelog * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.6-1 - Update to release v1.36.6 - Resolves: rhbz#2537559 - Resolves CVE-2026-17113: rhbz#2523493 - Resolves: rhbz#2540885 * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.5-2 - Define --pinns_path - pinns_path is set to the libexec path for pinns

ruff-0.16.9-1.fc46 rust-salsa-0.28.5-1.fc46 rust-salsa-macro-rules-0.28.5-1.fc46 rust-salsa-macros-0.28.5-1.fc46 ty-0.0.84-1.fc46

1 day 12 hours ago
FEDORA-2026-77f6cda09a Packages in this update:
  • ruff-0.16.9-1.fc46
  • rust-salsa-0.28.5-1.fc46
  • rust-salsa-macro-rules-0.28.5-1.fc46
  • rust-salsa-macros-0.28.5-1.fc46
  • ty-0.0.84-1.fc46
Update description:

Update the salsa/salsa-macros/salsa-macro-rules crates to 0.28.5, fixing a use-after-free bug, GHSA-xc3w-55vh-cw3w.

Update ruff to 0.16.9 and ty to 0.0.84, fixing GHSA-vxvm-j4xq-q7m4, which could result in arbitrary code execution when typechecking untrusted code.

nagios-plugins-2.5-2.fc45

1 day 14 hours ago
FEDORA-2026-c213ad9471 Packages in this update:
  • nagios-plugins-2.5-2.fc45
Update description:

Update to upstream (bz#2453492) check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

dnf5-5.4.6.0-2.fc45

1 day 14 hours ago
FEDORA-2026-4284af73e4 Packages in this update:
  • dnf5-5.4.6.0-2.fc45
Update description:
  • Update translations from weblate
  • spec: Symlink microdnf(8) and yum(8) manual pages to dnf5(8)
  • Update FSF's address in GPL-2.0 disclaimers
  • Update LGPL-2.1 and GPL-2.0 texts to current FSF's wording
  • fix: DNF5_FORCE_COLUMNS / non-TTY width in transaction table
  • progressbar: Report progress to terminal taskbar via OSC 9;4
  • Makefile: Add FEDORA_VERSION to unify defaults
  • spec: Require GCC ≥ 14.1 for std::chrono::parse()
  • dnf5daemon: Hide invalid offline transactions
  • Clarify plugin source language options
  • needs-restarting: Configure extra packages that require a reboot
  • VendorChangeManager: Allow empty vendor policies in compact format
  • manifest: Log before resolving & after writing files
  • manifest: Print transaction table on resolve