1 hour 54 minutes ago
Version:next-20260119 (linux-next)
Released:2026-01-19
9 hours 14 minutes ago
It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)
Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
programs. (CVE-2025-65082)
Mattias Åsander discovered that the Apache HTTP Server incorrectly
handled AllowOverride FileInfo configurations when using mod_userdir with
suexec. An attacker with access to use the RequestHeader directive in
htaccess can cause some CGI scripts to run under an unexpected userid.
(CVE-2025-66200)
11 hours 31 minutes ago
USN-7966-1 fixed vulnerabilities in Snowflake. This update provides the
corresponding updates for Telegraf.
Original advisory details:
It was discovered that Pion DTLS, vendored in Telegraf, did not impose a limit
on the amount of data that was buffered during the handshake. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29189)
It was discovered that Pion DTLS, vendored in Telegraf, did not prevent the
fragmentBuffer from processing zero length fragments. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29190)
It was discovered that Pion DTLS, vendored in Telegraf, did not require
CertificateVerify when Client Cert was sent. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29222)
11 hours 43 minutes ago
It was discovered that Avahi incorrectly terminated when processing browser
records with wide-area disabled. An attacker could possibly use this issue
to cause Avahi to crash, resulting in a denial of service. (CVE-2025-68276)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records pointing to resource records with short TTLs. An
attacker could possibly use this issue to cause Avahi to crash, resulting
in a denial of service. (CVE-2025-68468)
It was discovered that Avahi incorrectly terminated when processing
unsolicited CNAME records in quick succession. An attacker could possibly
use this issue to cause Avahi to crash, resulting in a denial of service.
(CVE-2025-68471)
12 hours ago
12 hours 3 minutes ago
12 hours 16 minutes ago
USN-7955-1 fixed vulnerabilities in urllib3. The update introduced a
regression in response streaming on Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that urllib3 incorrectly handled decompression during
HTTP redirects. An attacker could possibly use this issue to cause urllib3
to use excessive resources, causing a denial of service.
13 hours 38 minutes ago
It was discovered that Pion DTLS, vendored in Snowflake, did not impose a limit
on the amount of data that was buffered during the handshake. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29189)
It was discovered that Pion DTLS, vendored in Snowflake, did not prevent the
fragmentBuffer from processing zero length fragments. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29190)
It was discovered that Pion DTLS, vendored in Snowflake, did not require
CertificateVerify when Client Cert was sent. An attacker could
possibly use the issue to cause a denial of service. (CVE-2022-29222)
1 day ago
1 day 15 hours ago
FEDORA-EPEL-2026-825e0cae21
Packages in this update:
- qownnotes-26.1.7-4.el10_2
Update description:
See commit history
1 day 15 hours ago
FEDORA-2026-4ea96a154e
Packages in this update:
Update description:
See commit history
2 days ago
FEDORA-EPEL-2026-7d20038bca
Packages in this update:
Update description:
See commit history
2 days 1 hour ago
FEDORA-2026-00a6b7589c
Packages in this update:
Update description:
See commit history
Automatic update for qownnotes-26.1.7-2.fc43.
Changelog for qownnotes
* Fri Jan 16 2026 Artem Polishchuk <
ego.cordatus@gmail.com> - 26.1.7-2
- Mask BR: botan-3 temporary
* Thu Jan 15 2026 Artem Polishchuk <
ego.cordatus@gmail.com> - 26.1.7-1
- 26.1.7
- Bundle Botan 2 for now
2 days 8 hours ago
2 days 8 hours ago
2 days 8 hours ago
2 days 8 hours ago
2 days 13 hours ago
FEDORA-2026-0e8fe3c8a3
Packages in this update:
- mingw-openexr-3.3.6-1.fc42
Update description:
Update to openexr-3.3.6, fixes multiple security issues.
2 days 13 hours ago
FEDORA-2026-1fbf91067c
Packages in this update:
- mingw-openexr-3.3.6-1.fc43
Update description:
Update to openexr-3.3.6, fixes multiple security issues.
2 days 13 hours ago
FEDORA-2026-20b533bbc7
Packages in this update:
- mingw-libsoup-2.74.3-16.fc43
Update description:
Backport fix for CVE-2025-14523