Aggregator

python-jupytext-1.19.6-1.fc43

2 hours 43 minutes ago
FEDORA-2026-3942ab86fd Packages in this update:
  • python-jupytext-1.19.6-1.fc43
Update description:

See https://github.com/jupytext/jupytext/blob/main/CHANGELOG.md for changes in versions 1.19.5 and 1.19.6. For this update, a patch has been applied that reverses the jupyterlab → jupyter-builder change for Fedora releases ≤ 45, since jupyter-builder is only available in F46 and later. Many CVEs have been fixed in this release.

USN-8870-1: OpenStack Aodh and Watcher vulnerability

7 hours 23 minutes ago
Chen YuXiang discovered that OpenStack Aodh did not correctly enforce project scoping in its alarm list API and that the OpenStack Watcher webhook trigger endpoint did not apply authorization. An attacker could possibly use this issue to access sensitive alarm metadata or trigger unauthorized action plans.

USN-8871-1: Linux kernel (Raspberry Pi) vulnerabilities

7 hours 40 minutes ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

USN-8851-3: Linux kernel (Azure) vulnerabilities

7 hours 44 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network file system (NFS) server daemon; - IPv6 networking; - Netfilter; (CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)

aegisub-3.5.0-1.fc43

7 hours 57 minutes ago
FEDORA-2026-78a11da997 Packages in this update:
  • aegisub-3.5.0-1.fc43
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-2.fc44

7 hours 58 minutes ago
FEDORA-2026-0c6d4471fc Packages in this update:
  • aegisub-3.5.0-2.fc44
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-1.fc45

7 hours 58 minutes ago
FEDORA-2026-d296db490c Packages in this update:
  • aegisub-3.5.0-1.fc45
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

zabbix7.0-7.0.31-1.el10_3

7 hours 58 minutes ago
FEDORA-EPEL-2026-042a8bf4e4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_3
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el10_4

7 hours 58 minutes ago
FEDORA-EPEL-2026-3e248bfcbd Packages in this update:
  • zabbix7.0-7.0.31-1.el10_4
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el9

7 hours 59 minutes ago
FEDORA-EPEL-2026-0879abafaa Packages in this update:
  • zabbix7.0-7.0.31-1.el9
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el8

7 hours 59 minutes ago
FEDORA-EPEL-2026-367fe24aeb Packages in this update:
  • zabbix7.0-7.0.31-1.el8
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

Update to 7.0.28

zabbix7.0-7.0.31-1.el10_2

7 hours 59 minutes ago
FEDORA-EPEL-2026-6aaa054bb4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_2
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

USN-8868-1: LibreOffice vulnerabilities

9 hours 13 minutes ago
It was discovered that LibreOffice incorrectly handled WMF image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63272) It was discovered that LibreOffice incorrectly handled PDF document imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63273, CVE-2026-63274) It was discovered that LibreOffice incorrectly handled CFF fonts embedded in documents. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-63275, CVE-2026-63276) It was discovered that LibreOffice incorrectly validated package URLs. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-63278) It was discovered that LibreOffice incorrectly handled PICT image imports. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or obtain sensitive information. (CVE-2026-63279) It was discovered that LibreOffice incorrectly mitigated out-of-bounds writes via Graphite font actions. An attacker could possibly use this issue to cause LibreOffice to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-50593)