asterisk-23.5.0-4.fc45
- asterisk-23.5.0-4.fc45
Disable outdated functionality which requires outdated SDL1.
Fix for CVE-2026-57160
Disable outdated functionality which requires outdated SDL1.
Fix for CVE-2026-57160
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).
opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).
Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9
Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9
Update to version 2.1.3.
Update to version 2.1.3.
Update to version 2.1.3.
The 7.2.5 stable kernel update contains a number of important fixes across the tree.
The 7.2.5 stable kernel update contains a number of important fixes across the tree.
The 7.2.5 stable kernel update contains a number of important fixes across the tree.
Fix for CVE-2026-57160
This update contains new upstream releases containing bugfixes and improvements. Notably, it fixes an overflow in parsing RGBE/HDR image files.
For more information, please consult the GIMP 3.2.6 release announcement and the more detailed changelogs of gimp and gegl04.
Patch stb_sprintf: security fix for CVE-2026-79516
Patch stb_sprintf: security fix for CVE-2026-79516
Patch stb_sprintf: security fix for CVE-2026-79516
This is an upstream bug and security fix release.
Please consult the upstream release notes for more details.