Aggregator

USN-8900-1: Go Networking vulnerabilities

3 hours 43 minutes ago
It was discovered that Go Networking did not properly handle server errors after sending a GOAWAY frame during HTTP/2 connection shutdown, which could cause the connection to hang. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-27664) It was discovered that Go Networking had quadratic complexity when decoding HPACK headers in HTTP/2 streams. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2022-41723) It was discovered that Go Networking incorrectly rendered text nodes outside of the HTML namespace literally, causing text that should be escaped to not be escaped. A remote attacker could possibly use this issue to perform cross-site scripting attacks. (CVE-2023-3978) Guido Vranken discovered that Go Networking processed certain inputs to the HTML parsing functions non-linearly with respect to their length. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2024-45338) Sean Ng discovered that Go Networking incorrectly interpreted tags in foreign content with unquoted attribute values ending with a solidus character as self-closing, which could result in content being placed in the wrong scope during DOM construction. A remote attacker could possibly use this issue to perform cross-site scripting attacks. (CVE-2025-22872) It was discovered that Go Networking had quadratic parsing complexity when processing certain HTML inputs. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2025-47911) It was discovered that Go Networking could enter an infinite loop when parsing certain HTML inputs. A remote attacker could possibly use this issue to cause Go Networking to use excessive resources, leading to a denial of service. (CVE-2025-58190) It was discovered that Go Networking incorrectly accepted Punycode-encoded labels that decoded to ASCII-only labels when processing internationalized domain names. A remote attacker could possibly use this issue to bypass access control restrictions and escalate privileges. (CVE-2026-39821)

USN-8895-1: Sudo vulnerability

9 hours 40 minutes ago
It was discovered that Sudo did not properly handle time-based access restrictions when sudoers rules used NOTBEFORE or NOTAFTER with timestamps omitting the trailing timezone indicator. A local attacker could possibly use this issue to execute commands outside the intended time window by manipulating the TZ environment variable.

xorg-x11-server-Xwayland-24.1.14-1.fc43

9 hours 41 minutes ago
FEDORA-2026-112c430ffc Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc43
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

USN-8894-1: poppler vulnerabilities

9 hours 51 minutes ago
It was discovered that Poppler had an integer overflow in FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102620) It was discovered that Poppler had an integer overflow in SplashClip::clipToPath. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102621) It was discovered that Poppler had a null pointer dereference in JBIG2Stream. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service. (CVE-2026-93312) It was discovered that Poppler had an integer overflow in JBIG2Stream::readCodeTableSeg. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93313) It was discovered that Poppler had an integer overflow in FoFiTrueType::mapCodeToGID. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93314)