Aggregator

openqa-5^20260126git19189f0-1.fc43 os-autoinst-5^20260123git72cabd0-1.fc43

12 hours 13 minutes ago
FEDORA-2026-abd2d2d60c Packages in this update:
  • openqa-5^20260126git19189f0-1.fc43
  • os-autoinst-5^20260123git72cabd0-1.fc43
Update description:

This update provides new upstream snapshots of openQA and os-autoinst, with various fixes and enhancements. Please see upstream changelogs for details. They also address a CVE by updating a bundled javascript library, though we're fairly sure openQA didn't actually expose the vulnerability anyway.

USN-7978-1: GNU Screen vulnerabilities

19 hours 2 minutes ago
It was discovered that GNU Screen incorrectly handled signals when setuid or setgid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to send privileged signals, possibly leading to a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-24626) It was discovered that GNU Screen incorrectly handled PTY permissions. A local attacker could possibly use this issue to connect to an unauthorized screen session. (CVE-2025-46802) It was discovered that GNU Screen incorrectly handled file access when setuid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to deduce information about certain file paths. (CVE-2025-46804) It was discovered that GNU Screen incorrectly handled signals when setuid privileges were being used, which is not the default in Ubuntu. A local attacker could use this issue to send privileged signals, possibly leading to a denial of service. (CVE-2025-46805)

USN-7977-1: Git LFS vulnerabilities

23 hours 58 minutes ago
Ryota K discovered that Git LFS may leak login credentials in certain instances due to failing to check for URL-encoded characters. An attacker could possibly use this issue to learn sensitive information. (CVE-2024-53263) It was discovered that Git LFS could have its git lfs checkout and git lfs pull commands abused to write to any file on a user's system. An attacker could possibly use this issue to execute arbitrary code. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-26625)

USN-7976-1: Form-Data vulnerability

1 day 2 hours ago
Ben Shonaldmann discovered that Form-data incorrectly generated boundary values for multipart form-encoded data, leading to predictable values. A remote attacker could possibly use this issue to make arbitrary requests to internal systems.

gimp-3.0.8-4.fc43

1 day 14 hours ago
FEDORA-2026-ebabb127fb Packages in this update:
  • gimp-3.0.8-4.fc43
Update description:

This is an upstream bugfix and security update. Please refer to the upstream release notes for details about the changes in this version.

gimp-3.0.8-4.fc42

1 day 14 hours ago
FEDORA-2026-bda4a20a3c Packages in this update:
  • gimp-3.0.8-4.fc42
Update description:

This is an upstream bugfix and security update. Please refer to the upstream release notes for details about the changes in this version.