2 hours 21 minutes ago
FEDORA-2026-bcfa11cd3b
Packages in this update:
- mingw-gstreamer1-plugins-base-1.26.11-2.fc43
- mingw-gstreamer1-plugins-good-1.26.11-3.fc43
Update description:
Backport multiple security fixes.
2 hours 21 minutes ago
FEDORA-2026-e6ca27403f
Packages in this update:
- mingw-gstreamer1-1.28.6-1.fc44
- mingw-gstreamer1-plugins-bad-free-1.28.6-1.fc44
- mingw-gstreamer1-plugins-base-1.28.6-1.fc44
- mingw-gstreamer1-plugins-good-1.28.6-1.fc44
Update description:
Update to 1.28.6.
3 hours 20 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
3 hours 23 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
3 hours 36 minutes ago
FEDORA-2026-6d1e651eb5
Packages in this update:
Update description:
Update to expat-2.8.3.
3 hours 36 minutes ago
FEDORA-2026-43f21f29dc
Packages in this update:
Update description:
Update to expat-2.8.3.
3 hours 36 minutes ago
FEDORA-2026-f5e2a6b9b5
Packages in this update:
Update description:
Update to expat-2.8.3.
3 hours 36 minutes ago
FEDORA-2026-94344a87fb
Packages in this update:
- mingw-openexr-3.4.15-1.fc45
Update description:
Update to openexr 3.4.15 resp 3.3.14.
3 hours 36 minutes ago
FEDORA-2026-54d00b8af5
Packages in this update:
- mingw-openexr-3.4.15-1.fc44
Update description:
Update to openexr 3.4.15 resp 3.3.14.
3 hours 36 minutes ago
FEDORA-2026-bcc9ac580d
Packages in this update:
- mingw-openexr-3.3.14-1.fc43
Update description:
Update to openexr 3.4.15 resp 3.3.14.
3 hours 37 minutes ago
3 hours 37 minutes ago
4 hours 8 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
4 hours 14 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
4 hours 21 minutes ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
4 hours 34 minutes ago
Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
data. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)
Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-70632)
5 hours 6 minutes ago
It was discovered that Vim incorrectly handled certain tags files. An
attacker could possibly use this issue to execute arbitrary code.
6 hours 56 minutes ago
It was discovered that OpenSSL incorrectly handled the QUIC server incoming
channel queue. A remote attacker could possibly use this issue to cause
OpenSSL to use excessive resources, leading to a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)
It was discovered that OpenSSL incorrectly handled signature algorithm
selection when using Raw Public Keys. A remote attacker could possibly use
this issue to cause OpenSSL to crash, resulting in a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)
It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet
processing. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-18798)
It was discovered that OpenSSL incorrectly handled buffering of DTLS
records for a future epoch. A remote attacker could possibly use this issue
to cause OpenSSL to use excessive resources, leading to a denial of
service. (CVE-2026-54874)
It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A
remote attacker could possibly use this issue to cause a heap buffer
overflow, leading to a denial of service or arbitrary code execution.
(CVE-2026-63072)
It was discovered that OpenSSL incorrectly validated the sender
distinguished name in CMP response messages. A remote attacker could
possibly use this issue to cause OpenSSL to crash, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)
It was discovered that OpenSSL incorrectly limited the growth of an
internal certificate cache used during CMP operations. A remote attacker
could possibly use this issue to cause OpenSSL to use excessive resources,
leading to a denial of service. (CVE-2026-63074)
It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet
retention. A remote attacker could possibly use this issue to cause OpenSSL
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-63075)
It was discovered that OpenSSL incorrectly handled CMP protection algorithm
validation. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)
It was discovered that OpenSSL incorrectly verified authentication tags
when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker
could possibly use this issue to perform AEAD forgery attacks.
(CVE-2026-75803)
8 hours 5 minutes ago
USN-8670-1 fixed a vulnerability in curl. This update provides the
corresponding update for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
22.04 LTS.
Original advisory details:
Joshua Rogers discovered that curl incorrectly handled reusing
connections when client certificate settings changed. This could result
in the wrong client certificates being used, contrary to expectations.
9 hours 40 minutes ago
It was discovered that Perl incorrectly handled short source addresses
in the Socket module. An attacker could possibly use this issue to
trigger an out-of-bounds heap read, resulting in information disclosure.
(CVE-2026-12087)
It was discovered that Perl incorrectly handled regular expressions
containing a large number of fixed string alternatives. An attacker
could possibly use this issue to cause incorrect regular expression
matches, resulting in security restrictions being bypassed.
(CVE-2026-13221)
It was discovered that Perl incorrectly handled certain large repeat
counts when processing pack and unpack templates. An attacker could
possibly use this issue to trigger an out-of-bounds heap read, resulting
in information disclosure. (CVE-2026-57432)
It was discovered that Perl incorrectly handled certain crafted data
when deserializing with the Storable module. An attacker could possibly
use this issue to trigger an integer overflow and application
termination, resulting in a denial of service. (CVE-2026-57433)