Aggregator

USN-8082-1: GIMP vulnerabilities

2 hours 11 minutes ago
Michael Randrianantenaina discovered that GIMP incorrectly handled certain malformed ICO files. An attacker could possibly use this to cause a denial of service or execute arbitrary code. (CVE-2025-5473) Seungho Kim discovered that GIMP incorrectly handled certain memory operations when running the despeckle plugin. An attacker could possibly use this to cause a denial of service or execute arbitrary code. (CVE-2025-6035)

dnf5-5.2.18.0-2.fc42

4 hours 22 minutes ago
FEDORA-2026-beac8e1f11 Packages in this update:
  • dnf5-5.2.18.0-2.fc42
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

dnf5-5.2.18.0-2.fc43

4 hours 45 minutes ago
FEDORA-2026-4e264a94a4 Packages in this update:
  • dnf5-5.2.18.0-2.fc43
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

dnf5-5.4.0.0-2.fc44

5 hours 16 minutes ago
FEDORA-2026-6072c6888a Packages in this update:
  • dnf5-5.4.0.0-2.fc44
Update description:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client.

Update to upstream release 5.4.0.0. Full changelog.

cpp-httplib-0.37.0-1.el9

1 day 3 hours ago
FEDORA-EPEL-2026-53aded8e0e Packages in this update:
  • cpp-httplib-0.37.0-1.el9
Update description: Update to 0.37.0 (rhbz#2441656)
  • Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076, rhbz#2445663)
Update to 0.35.0
  • Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
  • Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, rhbz#2444636)

https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.0

cpp-httplib-0.37.0-1.fc44

1 day 3 hours ago
FEDORA-2026-2c2afa9f9e Packages in this update:
  • cpp-httplib-0.37.0-1.fc44
Update description: Update to 0.37.0 (rhbz#2441656)
  • Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076, rhbz#2445663)
Update to 0.35.0
  • Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
  • Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, rhbz#2444636)

https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.0

cpp-httplib-0.37.0-1.fc42

1 day 3 hours ago
FEDORA-2026-6ed9c65eaf Packages in this update:
  • cpp-httplib-0.37.0-1.fc42
Update description: Update to 0.37.0 (rhbz#2441656)
  • Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076, rhbz#2445663)
Update to 0.35.0
  • Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
  • Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, rhbz#2444636)

https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.0

cpp-httplib-0.37.0-1.fc43

1 day 3 hours ago
FEDORA-2026-c2049f7220 Packages in this update:
  • cpp-httplib-0.37.0-1.fc43
Update description: Update to 0.37.0 (rhbz#2441656)
  • Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076, rhbz#2445663)
Update to 0.35.0
  • Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
  • Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, rhbz#2444636)

https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.0

cpp-httplib-0.37.0-1.el10_3

1 day 3 hours ago
FEDORA-EPEL-2026-9612548dcf Packages in this update:
  • cpp-httplib-0.37.0-1.el10_3
Update description: Update to 0.37.0 (rhbz#2441656)
  • Fixes Denial of Service via crafted HTTP POST request (CVE-2026-29076, rhbz#2445663)
Update to 0.35.0
  • Payload size limit bypass via gzip decompression in ContentReader (streaming) allows oversized request bodies (CVE-2026-28435, rhbz#2444638)
  • Default exception handler leaks e.what() to clients via EXCEPTION_WHAT response header (CVE-2026-28434, rhbz#2444636)

https://github.com/yhirose/cpp-httplib/compare/v0.32.0...v0.37.0

USN-8080-1: YARA vulnerabilities

1 day 3 hours ago
Kamil Frankowicz discovered that a number of YARA's functions generated memory exceptions when processing specially crafted rules or files. A remote attacker could possibly use these issues to cause YARA to crash, resulting in a denial of service. These issues only affected Ubuntu 16.04 LTS. (CVE-2016-10211, CVE-2017-5923, CVE-2017-5924, CVE-2017-8294, CVE-2017-8929, CVE-2017-9304, CVE-2017-9438, CVE-2017-9465) Jurriaan Bremer discovered that YARA's yr_object_array_set_limit() function could result in a heap buffer overflow when scanning specially crafted .NET files. A remote attacker could possibly use this issue to cause YARA to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11328) It was discovered that YARA's yr_execute_code() function could cause an out-of-bounds read or write when parsing specially crafted compiled rule files. A remote attacker could possibly use these issues to cause YARA to crash, resulting in a denial of service. These issues only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-12034, CVE-2018-12035) It was discovered that YARA's virtual machine could be escaped in certain instances. A remote attacker could possibly use these issues to execute arbitrary code. These issues only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-19974, CVE-2018-19975, CVE-2018-19976) It was discovered that YARA's macho_parse_file() function would generate an out-of-bounds memory access error when parsing a specially crafted Mach-O file. A remote attacker could possibly use this issue to cause YARA to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2019-19648) It was discovered that YARA's macho.c implementation contained several overflow reads, which could be triggered when parsing specially crafted Mach-O files. A remote attacker could possibly use this issue to cause YARA to crash, resulting in a denial of service, or to learn sensitive information. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-3402) It was discovered that YARA's yr_set_configuration() function could trigger a buffer overflow when parsing specially crafted rules. A remote attacker could possibly use this issue to cause YARA to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-45429)

USN-7968-2: Apache HTTP Server regression

1 day 7 hours ago
USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update introduced a regression in mod_md where the MDStapleOthers setting was ignored which resulted in OCSP being broken for some domains. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that the Apache HTTP Server incorrectly handled failed ACME certificate renewals. This could result in renewal attempts to be repeated without delays, possibly leading to a denial of service. (CVE-2025-55753) Anthony Parfenov discovered that the Apache HTTP Server would pass the query string to cmd directives when configured with Server Side Includes (SSI) enabled and mod_cgid. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-58098) Mattias Åsander discovered that the Apache HTTP Server incorrectly neutralized certain environment variables. This could result in unexpectedly superseding variables calculated by the server for CGI programs. (CVE-2025-65082) Mattias Åsander discovered that the Apache HTTP Server incorrectly handled AllowOverride FileInfo configurations when using mod_userdir with suexec. An attacker with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. (CVE-2025-66200)

USN-8018-2: Python regression

1 day 10 hours ago
USN-8018-1 fixed vulnerabilities in python3. That update introduced regressions. The patches for CVE-2025-15366 and CVE-2025-15367 caused behavior regressions in IMAP and POP3 handling, which upstream chose to avoid by not backporting them. Additionally, the patch for CVE-2026-0865 incorrectly rejected horizontal tabs in wsgiref headers. This update fixes these problems. We apologize for the inconvenience. Original advisory details: Denis Ledoux discovered that Python incorrectly parsed email message headers. An attacker could possibly use this issue to inject arbitrary headers into email messages. This issue only affected python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-11468) Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python inefficiently parsed XML input with quadratic complexity. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-12084) It was discovered that Python incorrectly parsed malicious plist files. An attacker could possibly use this issue to cause Python to use excessive resources, leading to a denial of service. This issue only affected python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-13837) Omar Hasan discovered that Python incorrectly parsed URL mediatypes. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2025-15282) Omar Hasan discovered that Python incorrectly parsed malicious IMAP inputs. An attacker could possibly use this issue to inject arbitrary IMAP commands. (CVE-2025-15366) Omar Hasan discovered that Python incorrectly parsed malicious POP3 inputs. An attacker could possibly use this issue to inject arbitrary POP3 commands. (CVE-2025-15367) Omar Hasan discovered that Python incorrectly parsed malicious HTTP cookie headers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0672) Omar Hasan discovered that Python incorrectly parsed malicious HTTP header names and values. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0865)