Aggregator

bluez-5.87-5.fc43

1 hour 5 minutes ago
FEDORA-2026-432a1ef311 Packages in this update:
  • bluez-5.87-5.fc43
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc44

1 hour 6 minutes ago
FEDORA-2026-01488a5766 Packages in this update:
  • bluez-5.87-5.fc44
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc45

1 hour 8 minutes ago
FEDORA-2026-f4d10955d6 Packages in this update:
  • bluez-5.87-6.fc45
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bind-9.18.50-2.fc43

4 hours 23 minutes ago
FEDORA-2026-875d2a5154 Packages in this update:
  • bind-9.18.50-2.fc43
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-2.fc44

4 hours 48 minutes ago
FEDORA-2026-d87e7f498a Packages in this update:
  • bind-9.18.50-2.fc44
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-34.fc45

4 hours 49 minutes ago
FEDORA-2026-0adbf9c133 Packages in this update:
  • bind-9.18.50-34.fc45
Update description:

Fixes multiple CVEs, without a rebase to newer version

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

mrtg-2.17.10-15.fc45

6 hours 18 minutes ago
FEDORA-2026-c2dba9f29d Packages in this update:
  • mrtg-2.17.10-15.fc45
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-13.fc43

6 hours 58 minutes ago
FEDORA-2026-4522f50b2c Packages in this update:
  • mrtg-2.17.10-13.fc43
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-14.fc44

7 hours 29 minutes ago
FEDORA-2026-d05b77001f Packages in this update:
  • mrtg-2.17.10-14.fc44
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

USN-8681-1: OpenJDK 25 vulnerabilities

12 hours 37 minutes ago
It was discovered that the JSSE component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-46968) It was discovered that the JSSE component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-46917) It was discovered that the ImageIO component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47010) It was discovered that the 2D component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47021, CVE-2026-47059) It was discovered that the Libraries component of OpenJDK 25 did not correctly authorize users. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-47027) It was discovered that the Security component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-60147) It was discovered that the Libraries component of OpenJDK 25 did not correctly authenticate users. A remote attacker could possibly use this issue to read or modify sensitive data. (CVE-2026-47063) Lian Owen discovered that the 2D (Little CMS) component of OpenJDK 25 did not correctly handle certain integer arithmetic. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41254)

USN-8666-2: Linux kernel (Azure) vulnerabilities

17 hours 2 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; - TIPC protocol; (CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986, CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)

USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities

17 hours 5 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)