3 hours 26 minutes ago
FEDORA-2026-da44c3870f
Packages in this update:
Update description:
Update to .NET SDK 8.0.129 and Runtime 8.0.29
Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108
Release Notes:
3 hours 30 minutes ago
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides
the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that the Ubuntu-specific SetLanguage patch to
AccountsService incorrectly handled dropping privileges. A local attacker
could use this issue to execute arbitrary commands as an administrator.
(CVE-2026-61897)
It was discovered that the Ubuntu-specific SetLanguage helpers for
AccountsService incorrectly handled parsing configuration files. A local
attacker could use this issue to execute arbitrary commands.
(CVE-2026-61898)
3 hours 35 minutes ago
FEDORA-2026-9aef53fa96
Packages in this update:
Update description:
Update to .NET SDK 8.0.129 and Runtime 8.0.29
Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108
Release Notes:
5 hours 10 minutes ago
FEDORA-EPEL-2026-58bc6905cb
Packages in this update:
Update description:
This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.
5 hours 10 minutes ago
FEDORA-EPEL-2026-8258136556
Packages in this update:
Update description:
This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.
5 hours 12 minutes ago
Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an
out-of-bounds read vulnerability in its command-line tool. An attacker
could possibly use this issue to cause jbig2dec to crash, resulting in a
denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-46361)
It was discovered that jbig2dec had an integer overflow in the
jbig2_arith_iaid_ctx_new() function. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-38076)
5 hours 19 minutes ago
It was discovered that libarchive did not properly manage memory when
unpacking certain RAR5 archives, leading to a double free. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-14164)
It was discovered that libarchive did not properly validate certain tar
archives, leading to a buffer overflow. A remote attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028)
It was discovered that libarchive did not properly validate certain
malformed ACL entries. An attacker could possibly use this issue to cause a
denial of service. (CVE-2026-5745)
5 hours 31 minutes ago
FEDORA-2026-f1fc7772c3
Packages in this update:
Update description:
The 7.1.4-102/202 stable kernel updates contain a few important fixes across the tree.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
5 hours 31 minutes ago
FEDORA-2026-2dd8b600bb
Packages in this update:
Update description:
The 7.1.4-102/202 stable kernel updates contain a few important fixes across the tree.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
5 hours 47 minutes ago
FEDORA-2026-d314ce6051
Packages in this update:
Update description:
This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.
5 hours 47 minutes ago
FEDORA-2026-2994824419
Packages in this update:
Update description:
This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.
5 hours 53 minutes ago
It was discovered that the Ubuntu-specific SetLanguage patch to
AccountsService incorrectly handled dropping privileges. A local attacker
could use this issue to execute arbitrary commands as an administrator.
(CVE-2026-61897)
It was discovered that the Ubuntu-specific SetLanguage helpers for
AccountsService incorrectly handled parsing configuration files. A local
attacker could use this issue to execute arbitrary commands.
(CVE-2026-61898)
6 hours 27 minutes ago
Version:next-20260721 (linux-next)
Released:2026-07-21
8 hours 20 minutes ago
FEDORA-2026-e6bbab8aa8
Packages in this update:
Update description:
8 hours 29 minutes ago
James Henstridge discovered that snapd's default apparmor template did
not restrict access to systemd-userdbd varlink interface. A local
attacker could possibly use this issue to obtain sensitive information.
(CVE-2024-5300)
Qualys discovered that snap-confine can be tricked to create
attacker-controlled files at certain privileged locations. A local
attacker could possibly use this issue to bypass intended restrictions
and escalate privileges to root. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-8933)
Zygmunt Krynicki discovered that snapd's default seccomp template
did not restrict the creation of executables with the set-user-ID
attribute. A local attacker could possibly use this issue to create
and execute setuid binaries. (CVE-2026-15226)
8 hours 37 minutes ago
FEDORA-2026-600530ae91
Packages in this update:
Update description:
14.1
8 hours 37 minutes ago
FEDORA-2026-9630be304f
Packages in this update:
Update description:
14.1
9 hours 56 minutes ago
It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.
10 hours 19 minutes ago
FEDORA-2026-51628b98a8
Packages in this update:
Update description:
Update to 1.5.6
10 hours 36 minutes ago
USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the
corresponding fix for Ubuntu 16.04 LTS.
Original advisory details:
Vladimir Tokarev discovered that OpenSSH incorrectly handled certificates
with the principal name containing a comma character when using user-trusted
CA keys in authorized_keys and an authorized_keys principals="" option
that lists more than one principal. This could result in inappropriate
principal matching, contrary to expectations. (CVE-2026-35414)