Aggregator

xen-4.21.2-2.fc44

17 hours ago
FEDORA-2026-1d448c1d40 Packages in this update:
  • xen-4.21.2-2.fc44
Update description:

x86: DMs may cause mem leak by IRQ binding [XSA-509, CVE-2026-62437] x86: improper handling of HVM emulation return codes [XSA-510, CVE-2026-79602] Unconditionally do TLB flushing ahead of page scrubbing [XSA-511, CVE-2026-79603] oxenstored: Unbounded accumulation of watches [XSA-512, CVE-2026-79604]

USN-8776-1: python-cryptography vulnerabilities

18 hours 15 minutes ago
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with observable timing differences. A remote attacker could possibly use this issue to recover the key used to encrypt the message contents, and obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69247) Jack Lloyd discovered that python-cryptography incorrectly handled wildcard DNS names when enforcing the name constraints of a certificate authority. A remote attacker could possibly use this issue to have an invalid certificate chain accepted, and use names outside of the permitted ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69248) Samuel Judson discovered that python-cryptography incorrectly handled certificate chains that contained duplicate certificates. A remote attacker could possibly use this issue to cause python-cryptography to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-69249)

USN-8775-1: SQLite vulnerability

21 hours 39 minutes ago
It was discovered that SQLite was vulnerable to a buffer overflow in the sqlar extension. If a user were tricked into opening a specially crafted SQLar archive, an attacker could cause a denial of service.

USN-8774-1: libheif vulnerabilities

21 hours 52 minutes ago
Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62377)