44 minutes 56 seconds ago
FEDORA-2026-663a2d0ba4
Packages in this update:
Update description:
- fix HTTP/2 server push UAF (CVE-2026-18924)
- fix Negotiate ambient user conn reuse (CVE-2026-19931)
- remove test1701 - HTTP/2 Upgrade in a HTTP/1.1 POST request is no longer supported
1 hour 17 minutes ago
FEDORA-2026-7a31054ed6
Packages in this update:
Update description:
Update to 1.18.4
1 hour 31 minutes ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
1 hour 31 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
1 hour 31 minutes ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
3 hours 10 minutes ago
FEDORA-EPEL-2026-6867b104b2
Packages in this update:
Update description:
Update to 3.20.1.
3 hours 10 minutes ago
FEDORA-2026-82691b59d6
Packages in this update:
Update description:
Update to 3.20.1.
3 hours 10 minutes ago
FEDORA-2026-0b3030633b
Packages in this update:
Update description:
Update to 3.20.1.
3 hours 10 minutes ago
FEDORA-EPEL-2026-bc47388d91
Packages in this update:
Update description:
Update to 3.20.1.
3 hours 10 minutes ago
FEDORA-2026-cffd5fed1f
Packages in this update:
Update description:
Update to 3.20.1.
5 hours 31 minutes ago
15 hours 11 minutes ago
It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly handled QUIC unvalidated
amplification credit accounting. An attacker could possibly use this
issue to cause a denial of service. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35191)
It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly
use this issue to perform a timing side-channel attack and obtain
sensitive information. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 scalar
multiplication on ARM64 and RISC-V architectures. An attacker could
possibly use this issue to perform a timing side-channel attack and
obtain sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-54875)
It was discovered that OpenSSL incorrectly handled SSL context switching
during a TLS handshake. An attacker could possibly use this issue to
cause an out-of-bounds read, resulting in a denial of service or
obtaining sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-72897)
It was discovered that OpenSSL incorrectly enforced QUIC connection-
level flow control for streams. An attacker could possibly use this
issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-75804)
It was discovered that OpenSSL incorrectly handled a NULL pointer in
CMP client revocation response processing. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-75805)
It was discovered that OpenSSL incorrectly handled undersized DTLS 1.2
AEAD records before authentication. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-75806)
It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information.
(CVE-2026-77696)
It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)
It was discovered that OpenSSL incorrectly handled QUIC
RETIRE_CONNECTION_ID frames. An attacker could possibly use this issue
to cause OpenSSL to consume excessive memory, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84784)
17 hours 12 minutes ago
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
compressed metadata. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 26.04 LTS. (CVE-2026-84384)
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
HEIF sequence data. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84446)
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
image references. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84447)
It was discovered that libheif incorrectly handled certain region masks.
A local attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448)
It was discovered that libheif incorrectly handled certain images. A
remote attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)
18 hours 16 minutes ago
It was discovered that c-ares incorrectly handled certain query completion
callbacks. An attacker could possibly use this issue to trigger a use-
after-free or double-free, resulting in a denial of service or arbitrary
code execution.
18 hours 37 minutes ago
Version:next-20260929 (linux-next)
Released:2026-09-29
19 hours 15 minutes ago
It was discovered that FreeIPMI incorrectly handled certain malformed
Fujitsu SEL long-text responses, leading to a stack-based buffer
overflow. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2026-85504)
It was discovered that FreeIPMI incorrectly handled short responses when
retrieving Fujitsu SEL entries, leading to a stack-based buffer
over-read. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service. (CVE-2026-85505)
It was discovered that FreeIPMI incorrectly handled certain Dell iDRAC
and CMC IPv6 system information responses, leading to a stack-based
buffer overflow. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2026-85506,
CVE-2026-85508)
It was discovered that FreeIPMI incorrectly handled certain Dell CMC
system information responses, leading to a stack-based buffer overflow.
An attacker in control of a malicious IPMI device could possibly use this
issue to cause FreeIPMI to crash, resulting in a denial of service, or
possibly execute arbitrary code. This issue only affected Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-85507)
It was discovered that FreeIPMI incorrectly handled FRU data responses
that were larger than requested, leading to a stack-based buffer
overflow. An attacker in control of a malicious IPMI device could
possibly use this issue to cause FreeIPMI to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2026-85509)
1 day ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
1 day ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
1 day ago
FEDORA-2026-e39b376e66
Packages in this update:
Update description:
1.654 bump
Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV)
Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)
1 day ago
FEDORA-2026-dc85e47244
Packages in this update:
Update description:
1.654 bump
Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV)
Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)