3 hours 55 minutes ago
FEDORA-2026-59c42d53ab
Packages in this update:
- docker-buildx-0.37.2-1.fc45
Update description:
- Update to release v0.37.2
- Resolves: rhbz#2544198
- Resolves CVE-2026-56855: rhbz#2530594
- resolves CVE-2026-78662: rhbz#2530802
- Upstream fix
7 hours 30 minutes ago
FEDORA-2026-934d570022
Packages in this update:
- docker-buildx-0.37.2-1.fc46
Update description:
Automatic update for docker-buildx-0.37.2-1.fc46.
Changelog
* Wed Sep 30 2026 Bradley G Smith <
bradley.g.smith@gmail.com> - 0.37.2-1
- Update to release v0.37.2
- Resolves: rhbz#2544198
- Resolves CVE-2026-56855: rhbz#2530594
- resolves CVE-2026-78662: rhbz#2530802
- Upstream fix
8 hours 39 minutes ago
FEDORA-2026-0d57b0d529
Packages in this update:
Update description:
xkb: Check the keysym range in _XkbReadKeyActions (CVE-2026-88806)
11 hours 10 minutes ago
FEDORA-EPEL-2026-c3ee85c015
Packages in this update:
Update description:
Update to 3.2.0
Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239,
GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.
11 hours 37 minutes ago
FEDORA-EPEL-2026-b8f0b437b3
Packages in this update:
Update description:
Update to 3.2.0
Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239,
GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.
11 hours 53 minutes ago
FEDORA-EPEL-2026-58b3caf388
Packages in this update:
Update description:
Update to 3.2.0
Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239,
GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.
12 hours 27 minutes ago
FEDORA-2026-819ccf04d8
Packages in this update:
Update description:
Update to 1.69.0
12 hours 27 minutes ago
FEDORA-2026-6d4a64a6b0
Packages in this update:
Update description:
Update to 1.69.0
12 hours 27 minutes ago
FEDORA-2026-838b95d839
Packages in this update:
Update description:
Update to 1.69.0
15 hours 2 minutes ago
It was discovered that Authen::SASL, a Perl authentication library, did
not properly validate login attempts. An attacker could possibly use
this issue to gain unauthorized access.
15 hours 3 minutes ago
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service or
obtain sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-56367)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2026-93586)
It was discovered that ImageMagick did not correctly handle certain images.
A local attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589)
It was discovered that ImageMagick did not correctly handle certain images.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)
15 hours 37 minutes ago
It was discovered that GStreamer Bad Plugins incorrectly validated the size
of multi-channel audio blocks. An attacker could possibly use this issue
with a specially crafted WAV file to cause the program to crash, resulting
in a denial of service, or possibly execute arbitrary code.
15 hours 43 minutes ago
It was discovered that Kdenlive allowed dangerous proxy parameters when
processing attacker-controlled project files. An attacker could use this to
execute arbitrary commands via the MLT framework's ante/post consumer
properties.
15 hours 48 minutes ago
Keith Linneman discovered that GVfs did not properly validate data
received from SFTP servers. An attacker could possibly use this issue to
cause a heap buffer overflow, resulting in arbitrary code execution or a
denial of service. (CVE-2026-84268)
It was discovered that GVfs incorrectly handled file ownership when
creating private D-Bus sockets in the admin backend. A local attacker
could possibly use this issue to change the ownership of arbitrary
system files, resulting in privilege escalation to root. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88924)
15 hours 57 minutes ago
FEDORA-2026-06c29a2cb4
Packages in this update:
Update description:
Rebase to OpenSSL 4.0.3
15 hours 58 minutes ago
15 hours 58 minutes ago
16 hours 35 minutes ago
17 hours ago
FEDORA-2026-6d3a15e9c3
Packages in this update:
Update description:
1.655 - Fix for C89; Ignore invalid handles consistently
1.654 bump
Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV)
Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)
17 hours ago
FEDORA-2026-272f19f521
Packages in this update:
Update description:
1.655 - Fix for C89; Ignore invalid handles consistently
1.654 bump
Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV)
Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)