1 hour 59 minutes ago
FEDORA-2026-d2a288c8eb
Packages in this update:
Update description:
Update to 3.31.1
Update to 3.31.0
2 hours 3 minutes ago
FEDORA-2026-f33ade2ba6
Packages in this update:
Update description:
This update aligns the package to the latest Upstream release, which is also the first stable version of complyctl.
It introduced the core redesign from OSCAL to Gemara. The project has gone through three pre-release milestones (alpha, beta, RC) with contributions from 11 people across 200+ commits. This release marks the point where the CLI surface, configuration format, provider gRPC API, and output formats are considered stable under semantic versioning.
More information in https://github.com/complytime/complyctl/releases/tag/v1.0.0
The providers, formerly plugins, were also moved to their own repository and are no longer delivered in the same package of complyctl. A new package called complytime-providers is being introduced to Fedora repositories via https://bugzilla.redhat.com/show_bug.cgi?id=2526823
2 hours 59 minutes ago
FEDORA-2026-fc26634b91
Packages in this update:
Update description:
Update to 1.9.4
2 hours 59 minutes ago
FEDORA-2026-275646ea83
Packages in this update:
Update description:
Update to 1.9.4
2 hours 59 minutes ago
FEDORA-2026-ce70c33170
Packages in this update:
Update description:
Update to 1.9.4
11 hours 15 minutes ago
FEDORA-2026-571b7e1505
Packages in this update:
Update description:
Fix CVE-2026-84267, CVE-2026-84268, CVE-2026-84269, and CVE-2026-84270
13 hours 32 minutes ago
FEDORA-2026-c33332bcf7
Packages in this update:
Update description:
2.1.3, fix for CVE-2026-40898
13 hours 32 minutes ago
FEDORA-2026-bd6debcfb6
Packages in this update:
Update description:
2.1.3, fix for CVE-2026-40898
16 hours 15 minutes ago
FEDORA-2026-6d094c5360
Packages in this update:
- python-jwcrypto-1.6.0-1.fc45
Update description:
Low severity security fixes
16 hours 15 minutes ago
FEDORA-2026-8caad572b0
Packages in this update:
- python-jwcrypto-1.6.0-1.fc44
Update description:
Low severity security fixes
18 hours 27 minutes ago
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (CVE-2026-59884)
It was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID
values in quadratic time relative to the number of arcs. An attacker could
possibly use this issue to cause applications decoding untrusted ASN.1 data
to consume excessive CPU resources, resulting in a denial of service.
(CVE-2026-59885)
It was discovered that pyasn1 incorrectly handled conversion of decoded
REAL values to Python float types. An attacker could possibly use this
issue to cause applications decoding untrusted ASN.1 data to consume
excessive CPU and memory resources, resulting in a denial of service.
(CVE-2026-59886)
18 hours 33 minutes ago
It was discovered that Libgcrypt had a timing-based side-channel flaw in
its RSA implementation. A remote attacker could possibly use this issue to
obtain sensitive information.
19 hours 3 minutes ago
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
19 hours 7 minutes ago
Version:next-20260901 (linux-next)
Released:2026-09-01
19 hours 15 minutes ago
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu
14.04 LTS only, it was discovered that some machines were unable to
enable esm-infra-legacy due to a preemptive apt-helper check. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer
token in command-line arguments when validating APT credentials. A local
attacker could possibly use this issue to obtain sensitive information
and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)
Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly
validate data received from the contract server when writing APT source
files. An attacker could possibly use this issue to inject arbitrary APT
configuration and execute arbitrary code. (CVE-2026-11386)
Mateusz Gierblinski discovered that Ubuntu Advantage Tools did not
properly handle symbolic links when collecting diagnostic logs. A local
attacker could possibly use this issue to obtain sensitive information
from files owned by the administrator. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-12391)
19 hours 20 minutes ago
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-63381)
Rajat Raghav discovered that libevent incorrectly handled certain HTTP
requests. An attacker could possibly use this issue to desynchronize
HTTP request boundaries, resulting in HTTP request smuggling.
(CVE-2026-63382)
Qiu Sihao discovered that libevent incorrectly handled certain malformed
tagged RPC data. An attacker could possibly use this issue to trigger an
out-of-bounds read, resulting in a denial of service. (CVE-2026-63383)
Qiu Sihao discovered that libevent incorrectly handled certain large
payload lengths in tagged RPC data. An attacker could possibly use this
issue to consume excessive system resources, resulting in a denial of
service. (CVE-2026-63384)
Asaf Meizner discovered that libevent incorrectly handled certain HTTP
URIs and header values. An attacker could possibly use this issue to
cause HTTP messages to be interpreted inconsistently, resulting in
security restrictions being bypassed. (CVE-2026-63385)
19 hours 23 minutes ago
It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.
19 hours 43 minutes ago
FEDORA-2026-2719c6cac1
Packages in this update:
Update description:
5.6.1 release
19 hours 43 minutes ago
FEDORA-2026-8a0b0bba30
Packages in this update:
Update description:
5.6.1 release
5.6.1 release
21 hours 19 minutes ago
FEDORA-EPEL-2026-0563db3f0c
Packages in this update:
Update description:
Backport several CVE fixes