erlang-26.2.5.21-5.fc44
- erlang-26.2.5.21-5.fc44
CVE-2026-55953
CVE-2026-55953
update to xen 4.21.2 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508]
More CVEs
Fixed CVE-2026-44839
Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.
Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.
Update to 2.88.3.
The update is required for update Perl to 5.42.3
Automatic update for docker-buildx-0.36.0-1.fc45.
Changelog * Wed Jul 29 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 0.36.0-1 - Update to release v0.36.0 - Resolves: rhbz#2506339 - Upstream new features and fixes - Resolves CVE-2026-53492 - rhbz#2496553 - Resolves CVE-2026-47262 - rhbz#2496436Automatic update for isns-utils-0.103-8.fc45.
Changelog * Wed Jul 29 2026 Chris Leech <cleech@redhat.com> - 0.103-8 - CVE-2026-55995: Denial of Service via double-free in iSNS attribute decoder (rhbz#2508456)Automatic update for iscsi-initiator-utils-6.2.1.12-1.fc45.
Changelog * Wed Jul 29 2026 Chris Leech <cleech@redhat.com> - 6.2.1.12-1 - rebase to Open-iSCSI 2.1.12 - CVE-2026-44943: Privilege Escalation via Path Traversal (rhbz#2508458) - CVE-2026-44944: Authentication bypass in iscsiuio control socket (rhbz#2508457)Automatic update for goss-0.4.10-1.fc45.
Changelog * Wed Jul 29 2026 Carlos Rodriguez-Fernandez <carlosrodrifernandez@gmail.com> - 0.4.10-1 - Update to 0.4.10 (rhbz#2494364,rhbz#2494459,rhbz#2494611,rhbz#2494911,rhbz#2495296)PHP version 8.4.24 (30 Jul 2026)
BCMath:
Calendar:
Date:
DBA:
DOM:
Exif:
Hash:
Intl:
ODBC:
OpenSSL:
PDO_ODBC:
PGSQL:
Phar:
PHPDBG:
Reflection:
Session:
SPL:
Standard:
Streams:
Update to upstream 10.1.4 Resolves: - CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy bypass - CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not stripped - CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling - CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the server - CVE-2026-58154 - Memory-safety errors in MIME and header parsing - CVE-2026-58155 - Header-name length truncation enables header aliasing and request smuggling - CVE-2026-58157 - Improper server-session reuse can expose data across client connections - CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the server - CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts framework - CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion - CVE-2026-24033 - Chunked extension quoted-string parsing allows request smuggling - CVE-2026-33930 - Buffer overflow via Host field that has a long string value - CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing host-SNI policy bypass - CVE-2026-57834 - Malformed chunked message body allows request smuggling - CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt memory - CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely - CVE-2026-58156 - URL and port parsing errors allow access-control bypass - CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack overflow - CVE-2026-58159 - Listener and ACL handling allow access-control bypass - CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses - CVE-2026-58162 - Certifier plugin trusts client SNI when generating certificates - CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state or crash the server - CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-after-free - CVE-2026-58175 - HostDB SRV handling leaks memory - CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side request forgery - CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input - CVE-2026-58180 - txn_box plugin overflows the stack from attacker input - CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or crash - CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors - CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input - CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory - CVE-2026-58185 - Use-after-free in the intercept plugin - CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded responses - CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service - CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental plugins - CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF amplification - CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed header encode - CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without certificate re-verification
Update to upstream 10.1.4 Resolves: - CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy bypass - CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not stripped - CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling - CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the server - CVE-2026-58154 - Memory-safety errors in MIME and header parsing - CVE-2026-58155 - Header-name length truncation enables header aliasing and request smuggling - CVE-2026-58157 - Improper server-session reuse can expose data across client connections - CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the server - CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts framework - CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion - CVE-2026-24033 - Chunked extension quoted-string parsing allows request smuggling - CVE-2026-33930 - Buffer overflow via Host field that has a long string value - CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing host-SNI policy bypass - CVE-2026-57834 - Malformed chunked message body allows request smuggling - CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt memory - CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely - CVE-2026-58156 - URL and port parsing errors allow access-control bypass - CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack overflow - CVE-2026-58159 - Listener and ACL handling allow access-control bypass - CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses - CVE-2026-58162 - Certifier plugin trusts client SNI when generating certificates - CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state or crash the server - CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-after-free - CVE-2026-58175 - HostDB SRV handling leaks memory - CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side request forgery - CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input - CVE-2026-58180 - txn_box plugin overflows the stack from attacker input - CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or crash - CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors - CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input - CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory - CVE-2026-58185 - Use-after-free in the intercept plugin - CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded responses - CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service - CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental plugins - CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF amplification - CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed header encode - CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without certificate re-verification
Update to upstream 9.2.15 Resolves: - CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy bypass - CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not stripped - CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling - CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the server - CVE-2026-58154 - Memory-safety errors in MIME and header parsing - CVE-2026-58155 - Header-name length truncation enables header aliasing and request smuggling - CVE-2026-58157 - Improper server-session reuse can expose data across client connections - CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the server - CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts framework - CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion - CVE-2026-24033 - Chunked extension quoted-string parsing allows request smuggling - CVE-2026-33930 - Buffer overflow via Host field that has a long string value - CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing host-SNI policy bypass - CVE-2026-57834 - Malformed chunked message body allows request smuggling - CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt memory - CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely - CVE-2026-58156 - URL and port parsing errors allow access-control bypass - CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack overflow - CVE-2026-58159 - Listener and ACL handling allow access-control bypass - CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses - CVE-2026-58162 - Certifier plugin trusts client SNI when generating certificates - CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state or crash the server - CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-after-free - CVE-2026-58175 - HostDB SRV handling leaks memory - CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side request forgery - CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input - CVE-2026-58180 - txn_box plugin overflows the stack from attacker input - CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or crash - CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors - CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input - CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory - CVE-2026-58185 - Use-after-free in the intercept plugin - CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded responses - CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service - CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental plugins - CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF amplification - CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed header encode - CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without certificate re-verification