Aggregator
bluez-5.87-5.fc43
- bluez-5.87-5.fc43
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-5.fc44
- bluez-5.87-5.fc44
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-6.fc45
- bluez-5.87-6.fc45
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bind-9.18.50-2.fc43
- bind-9.18.50-2.fc43
Fixes multiple CVEs
- Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
- Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
- Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
- Potential memory usage beyond configured limits (CVE-2026-11622)
- Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
- Incorrect acceptance of NSEC3 records (CVE-2026-10723)
- Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
- DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
bind-9.18.50-2.fc44
- bind-9.18.50-2.fc44
Fixes multiple CVEs
- Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
- Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
- Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
- Potential memory usage beyond configured limits (CVE-2026-11622)
- Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
- Incorrect acceptance of NSEC3 records (CVE-2026-10723)
- Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
- DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
bind-9.18.50-34.fc45
- bind-9.18.50-34.fc45
Fixes multiple CVEs, without a rebase to newer version
- Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
- Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
- Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
- Potential memory usage beyond configured limits (CVE-2026-11622)
- Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
- Incorrect acceptance of NSEC3 records (CVE-2026-10723)
- Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
- DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
mrtg-2.17.10-15.fc45
- mrtg-2.17.10-15.fc45
Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling
mrtg-2.17.10-13.fc43
- mrtg-2.17.10-13.fc43
Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling
mrtg-2.17.10-14.fc44
- mrtg-2.17.10-14.fc44
Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling
rest-0.10.2-9.fc44
- rest-0.10.2-9.fc44
Fix for https://access.redhat.com/security/cve/cve-2026-16615
rest-0.10.2-12.fc45
- rest-0.10.2-12.fc45
Fix for https://access.redhat.com/security/cve/cve-2026-16615
rest-0.10.2-5.fc43
- rest-0.10.2-5.fc43
Fix for https://access.redhat.com/security/cve/cve-2026-16615
USN-8681-1: OpenJDK 25 vulnerabilities
USN-8659-4: Linux kernel (Oracle) vulnerability
mingw-gstreamer1-plugins-base-1.26.11-2.fc43 mingw-gstreamer1-plugins-good-1.26.11-3.fc43
- mingw-gstreamer1-plugins-base-1.26.11-2.fc43
- mingw-gstreamer1-plugins-good-1.26.11-3.fc43
Backport multiple security fixes.
mingw-gstreamer1-1.28.6-1.fc44 mingw-gstreamer1-plugins-bad-free-1.28.6-1.fc44 mingw-gstreamer1-plugins-base-1.28.6-1.fc44 mingw-gstreamer1-plugins-good-1.28.6-1.fc44
- mingw-gstreamer1-1.28.6-1.fc44
- mingw-gstreamer1-plugins-bad-free-1.28.6-1.fc44
- mingw-gstreamer1-plugins-base-1.28.6-1.fc44
- mingw-gstreamer1-plugins-good-1.28.6-1.fc44
Update to 1.28.6.
USN-8666-2: Linux kernel (Azure) vulnerabilities
USN-8630-5: Linux kernel (Raspberry Pi) vulnerabilities
mingw-expat-2.8.3-1.fc45
- mingw-expat-2.8.3-1.fc45
Update to expat-2.8.3.