Aggregator

dotnet8.0-8.0.129-2.fc43

3 hours 26 minutes ago
FEDORA-2026-da44c3870f Packages in this update:
  • dotnet8.0-8.0.129-2.fc43
Update description:

Update to .NET SDK 8.0.129 and Runtime 8.0.29

Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108

Release Notes:

USN-8580-2: AccountsService vulnerabilities

3 hours 30 minutes ago
USN-8580-1 fixed vulnerabilities in AccountsService. This update provides the corresponding fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)

dotnet8.0-8.0.129-2.fc44

3 hours 35 minutes ago
FEDORA-2026-9aef53fa96 Packages in this update:
  • dotnet8.0-8.0.129-2.fc44
Update description:

Update to .NET SDK 8.0.129 and Runtime 8.0.29

Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108

Release Notes:

proftpd-1.3.9c-3.el10_3

5 hours 10 minutes ago
FEDORA-EPEL-2026-58bc6905cb Packages in this update:
  • proftpd-1.3.9c-3.el10_3
Update description:

This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.

proftpd-1.3.9c-3.el10_2

5 hours 10 minutes ago
FEDORA-EPEL-2026-8258136556 Packages in this update:
  • proftpd-1.3.9c-3.el10_2
Update description:

This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.

USN-8582-1: jbig2dec vulnerabilities

5 hours 12 minutes ago
Zeng Yunxiang and Song Jiaxuan discovered that jbig2dec had an out-of-bounds read vulnerability in its command-line tool. An attacker could possibly use this issue to cause jbig2dec to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-46361) It was discovered that jbig2dec had an integer overflow in the jbig2_arith_iaid_ctx_new() function. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-38076)

USN-8581-1: libarchive vulnerabilities

5 hours 19 minutes ago
It was discovered that libarchive did not properly manage memory when unpacking certain RAR5 archives, leading to a double free. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-14164) It was discovered that libarchive did not properly validate certain tar archives, leading to a buffer overflow. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15028) It was discovered that libarchive did not properly validate certain malformed ACL entries. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-5745)

kernel-7.1.4-102.fc43

5 hours 31 minutes ago
FEDORA-2026-f1fc7772c3 Packages in this update:
  • kernel-7.1.4-102.fc43
Update description:

The 7.1.4-102/202 stable kernel updates contain a few important fixes across the tree.

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

kernel-7.1.4-202.fc44

5 hours 31 minutes ago
FEDORA-2026-2dd8b600bb Packages in this update:
  • kernel-7.1.4-202.fc44
Update description:

The 7.1.4-102/202 stable kernel updates contain a few important fixes across the tree.

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

proftpd-1.3.9c-3.fc43

5 hours 47 minutes ago
FEDORA-2026-d314ce6051 Packages in this update:
  • proftpd-1.3.9c-3.fc43
Update description:

This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.

proftpd-1.3.9c-3.fc44

5 hours 47 minutes ago
FEDORA-2026-2994824419 Packages in this update:
  • proftpd-1.3.9c-3.fc44
Update description:

This update adds a new module, mod_procfs, which is enabled by default. It addressses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix), by disallowing any file accesses via procfs filesystems.

USN-8580-1: AccountsService vulnerabilities

5 hours 53 minutes ago
It was discovered that the Ubuntu-specific SetLanguage patch to AccountsService incorrectly handled dropping privileges. A local attacker could use this issue to execute arbitrary commands as an administrator. (CVE-2026-61897) It was discovered that the Ubuntu-specific SetLanguage helpers for AccountsService incorrectly handled parsing configuration files. A local attacker could use this issue to execute arbitrary commands. (CVE-2026-61898)

USN-8579-1: snapd vulnerabilities

8 hours 29 minutes ago
James Henstridge discovered that snapd's default apparmor template did not restrict access to systemd-userdbd varlink interface. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2024-5300) Qualys discovered that snap-confine can be tricked to create attacker-controlled files at certain privileged locations. A local attacker could possibly use this issue to bypass intended restrictions and escalate privileges to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-8933) Zygmunt Krynicki discovered that snapd's default seccomp template did not restrict the creation of executables with the set-user-ID attribute. A local attacker could possibly use this issue to create and execute setuid binaries. (CVE-2026-15226)

USN-8577-1: OpenSSH vulnerability

10 hours 36 minutes ago
USN-8222-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 16.04 LTS. Original advisory details: Vladimir Tokarev discovered that OpenSSH incorrectly handled certificates with the principal name containing a comma character when using user-trusted CA keys in authorized_keys and an authorized_keys principals="" option that lists more than one principal. This could result in inappropriate principal matching, contrary to expectations. (CVE-2026-35414)