gegl04-0.4.70-5.fc43
- gegl04-0.4.70-5.fc43
This update fixes an overflow in parsing RGBE/HDR image files.
This update fixes an overflow in parsing RGBE/HDR image files.
This update fixes an overflow in parsing RGBE/HDR image files.
This update fixes an overflow in parsing RGBE/HDR image files.
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.
Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.
Fixes CVE-2026-57074 and CVE-2026-13401.
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.
Fixes CVE-2026-57074 and CVE-2026-13401.
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.
Fixes CVE-2026-57074 and CVE-2026-13401.
XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.
Fixes CVE-2026-57074 and CVE-2026-13401.
Fix CVE-2026-79992: Local shell command injection through the user field in emacs tramp
The 7.2.2 stable kernel update contains a single fix for CVE-2026-80590
The 7.1.12 stable kernel update contains a single fix for CVE-2026-80590.
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
The 7.1.12 stable kernel update contains a single fix for CVE-2026-80590.
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
Fix CVE-2026-79992: Local shell command injection through the user field in emacs tramp
Rebase to OpenSSL 4.0.2
Rebase to OpenSSL 3.5.8
Rebase to OpenSSL 3.5.8
Update to 1.75.0
BUG FIXES:
Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt