Aggregator
chromium-151.0.7922.137-1.el10_2
- chromium-151.0.7922.137-1.el10_2
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blinkchromium-151.0.7922.137-1.fc43
- chromium-151.0.7922.137-1.fc43
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blinkchromium-151.0.7922.137-1.fc44
- chromium-151.0.7922.137-1.fc44
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blinkchromium-151.0.7922.137-1.el9
- chromium-151.0.7922.137-1.el9
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blinkchromium-151.0.7922.137-1.el10_3
- chromium-151.0.7922.137-1.el10_3
chromium security release 151.0.7922.137 inludes fixes for:
* CVE-2026-19556: Use after free in V8 * CVE-2026-19557: Use after free in TabStrip * CVE-2026-19558: Use after free in Extensions * CVE-2026-19559: Use after free in HTML * CVE-2026-19560: Use after free in Blinkdotnet8.0-8.0.130-1.fc44
- dotnet8.0-8.0.130-1.fc44
Update to .NET SDK 8.0.130 and Runtime 8.0.30
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
dotnet8.0-8.0.130-1.fc43
- dotnet8.0-8.0.130-1.fc43
Update to .NET SDK 8.0.130 and Runtime 8.0.30
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
dotnet10.0-10.0.111-1.fc44
- dotnet10.0-10.0.111-1.fc44
Update to .NET SDK 10.0.111 and Runtime 10.0.11
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
dotnet10.0-10.0.111-1.fc43
- dotnet10.0-10.0.111-1.fc43
Update to .NET SDK 10.0.111 and Runtime 10.0.11
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
wordpress-6.9.7-1.fc43
- wordpress-6.9.7-1.fc43
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
wordpress-6.9.7-1.el9
- wordpress-6.9.7-1.el9
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
wordpress-6.9.7-1.fc44
- wordpress-6.9.7-1.fc44
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
wordpress-7.0.4-1.el10_3
- wordpress-7.0.4-1.el10_3
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
wordpress-6.9.7-1.el10_2
- wordpress-6.9.7-1.el10_2
Security update included in this release
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript. CVE-2026-65640
Security update included in this release
- Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
- Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
- Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
- Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
- Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
- A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
- An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
- Enumeration of post slugs reported by HDWSec
- Disclosure of notes in comment feeds reported by Elio Gubser
- Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
- Bypass of the email address confirmation flow reported by 0ways
- A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
trafficserver-10.2.0-1.fc43
- trafficserver-10.2.0-1.fc43
Update to upstream 10.2.0.
trafficserver-10.2.0-1.fc44
- trafficserver-10.2.0-1.fc44
Update to upstream 10.2.0.
libnfs-5.0.3-3.el10_3
- libnfs-5.0.3-3.el10_3
Fixes CVE-2026-53689
libnfs-4.0.0-2.el8
- libnfs-4.0.0-2.el8
Fixes CVE-2026-53689
libnfs-5.0.3-3.el9
- libnfs-5.0.3-3.el9
Fixes CVE-2026-53689