Aggregator

USN-7950-1: Tornado vulnerabilities

9 hours 22 minutes ago
It was discovered that Tornado incorrectly handled special characters in HTTP headers. An attacker could possibly use this issue to execute a cross- site scripting (XSS) attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10. (CVE-2025-67724) It was discovered that Tornado incorrectly handled repeated HTTP headers. An attacker could possibly use this issue to cause Tornado to use excessive resources, causing a denial of service. (CVE-2025-67725) It was discovered that Tornado incorrectly handled parsing of certain HTTP header values. An attacker could possibly use this issue to cause Tornado to use excessive resources, causing a denial of service. (CVE-2025-67726)

chromium-143.0.7499.192-1.fc44

11 hours 12 minutes ago
FEDORA-2026-5551bc920f Packages in this update:
  • chromium-143.0.7499.192-1.fc44
Update description:

Automatic update for chromium-143.0.7499.192-1.fc44.

Changelog * Wed Jan 7 2026 Than Ngo <than@redhat.com> - 143.0.7499.192-1 - Update tp 143.0.7499.192 * High CVE-2026-0628: Insufficient policy enforcement in WebView tag - Fix rhbz#2425338, Enable control flow integrity support for x86_64/aarch64 - Enable build for epel10.1

USN-7946-2: GnuPG vulnerability

12 hours 7 minutes ago
USN-7946-1 fixed vulnerabilities in GnuPG 2.x. This update provides the corresponding updates for GnuPG 1.x. Original advisory details: It was discovered that GnuPG incorrectly handled crafted input. A remote attacker could possibly use this issue to crash the program, or execute arbitrary code.

USN-7948-1: GPSd vulnerabilities

13 hours 28 minutes ago
It was discovered that GPSd incorrectly handled processing NMEA2000 packets. An attacker could use this issue to cause GPSd to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-67268) It was discovered that GPSd incorrectly handled processing NAVCOM packets. An attacker could possibly use this issue to cause GPSd to consume resources, resulting in a denial of service. (CVE-2025-67269)

USN-7047-1: libvirt vulnerabilities

15 hours 3 minutes ago
It was discovered that libvirt parsed user-provided XML files before performing ACL checks. An attacker could possibly use this issue to cause libvirt to consume memory, resulting in a denial of service. (CVE-2025-12748) It was discovered that libvirt incorrectly handled permissions on external inactive snapshots. A local attacker could possibly use this issue to obtain sensitive guest contents. (CVE-2025-13193)

chromium-143.0.7499.192-1.el10_1

19 hours 27 minutes ago
FEDORA-EPEL-2026-2f73131e02 Packages in this update:
  • chromium-143.0.7499.192-1.el10_1
Update description:

Update to 143.0.7499.192

* High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

chromium-143.0.7499.192-1.fc42

19 hours 27 minutes ago
FEDORA-2026-540f5a89d1 Packages in this update:
  • chromium-143.0.7499.192-1.fc42
Update description:

Update to 143.0.7499.192

* High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

chromium-143.0.7499.192-1.el10_2

19 hours 27 minutes ago
FEDORA-EPEL-2026-7101d35773 Packages in this update:
  • chromium-143.0.7499.192-1.el10_2
Update description:

Update to 143.0.7499.192

* High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

chromium-143.0.7499.192-1.el9

19 hours 27 minutes ago
FEDORA-EPEL-2026-1e6d3d4287 Packages in this update:
  • chromium-143.0.7499.192-1.el9
Update description:

Update to 143.0.7499.192

* High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1

chromium-143.0.7499.192-1.fc43

19 hours 27 minutes ago
FEDORA-2026-66162d01ae Packages in this update:
  • chromium-143.0.7499.192-1.fc43
Update description:

Update to 143.0.7499.192

* High CVE-2026-0628: Insufficient policy enforcement in WebView tag * Enable control flow integrity support for x86_64/aarch64 * Enable build for epel10.1