wordpress-6.9.5-1.el9
- wordpress-6.9.5-1.el9
Security updates
- A facilitated SQL injection issue
- A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
Security updates
Security updates
Security updates
Security updates
Security updates
Backport upstream fixes for CVE-2023-52890 and CVE-2026-40706.
Backport upstream fix for CVE-2026-40706.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
nginx-mod-fancyindex:
Rebuild for 1.30.4nginx-mod-modsecurity:
Rebuild for 1.30.4nginx-mod-naxsi:
Rebuild for 1.30.4nginx-mod-headers-more:
Rebuild for 1.30.4nginx-mod-brotli:
Rebuild for 1.30.4nginx-mod-js-challenge:
Rebuild for 1.30.4nginx-mod-vts:
Rebuild for 1.30.4nginx:
update to 1.30.4 fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-564341.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
Update to 0.19.1
Update to 0.19.1
Update to 0.19.1
Automatic update for kronosnet-1.35-1.fc45.
Changelog * Mon Jul 20 2026 Fabio M. Di Nitto <fdinitto@redhat.com> - 1.35-1 - New upstream release - CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850) - CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852) - CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864) - tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets - libnozzle: Introduce test macros similar to libknet - docs: convert README to markdown format * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_RebuildUpdate to 0.19.1
Update to 0.19.1