Aggregator

chromium-142.0.7444.175-2.fc43

7 hours 3 minutes ago
FEDORA-2025-d41f5f4a2a Packages in this update:
  • chromium-142.0.7444.175-2.fc43
Update description:

Update to 142.0.7444.175

* High CVE-2025-13223: Type Confusion in V8 * High CVE-2025-13224: Type Confusion in V8

chromium-142.0.7444.175-2.el9

7 hours 3 minutes ago
FEDORA-EPEL-2025-cdf5100498 Packages in this update:
  • chromium-142.0.7444.175-2.el9
Update description:

Update to 142.0.7444.175

* High CVE-2025-13223: Type Confusion in V8 * High CVE-2025-13224: Type Confusion in V8

Update to 142.0.7444.162

* High CVE-2025-13042: Inappropriate implementation in V8

chromium-142.0.7444.175-2.fc41

7 hours 3 minutes ago
FEDORA-2025-ee528a170d Packages in this update:
  • chromium-142.0.7444.175-2.fc41
Update description:

Update to 142.0.7444.175

* High CVE-2025-13223: Type Confusion in V8 * High CVE-2025-13224: Type Confusion in V8

chromium-142.0.7444.175-2.el10_2

7 hours 3 minutes ago
FEDORA-EPEL-2025-62f79f7f05 Packages in this update:
  • chromium-142.0.7444.175-2.el10_2
Update description:

Update to 142.0.7444.175

* High CVE-2025-13223: Type Confusion in V8 * High CVE-2025-13224: Type Confusion in V8

chromium-142.0.7444.175-2.fc42

7 hours 3 minutes ago
FEDORA-2025-54b43715b6 Packages in this update:
  • chromium-142.0.7444.175-2.fc42
Update description:

Update to 142.0.7444.175

* High CVE-2025-13223: Type Confusion in V8 * High CVE-2025-13224: Type Confusion in V8

gnutls-3.8.11-1.fc43

12 hours 21 minutes ago
FEDORA-2025-45b1844342 Packages in this update:
  • gnutls-3.8.11-1.fc43
Update description:

Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements.

USN-7876-1: ImageMagick vulnerability

21 hours 5 minutes ago
It was discovered that ImageMagick did not properly handle memory when encoding BMP images. An attacker could possibly use this issue to cause ImageMagick to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue exists due to an incomplete fix for CVE-2025-57803.

USN-7878-1: cups-filters vulnerabilities

22 hours 46 minutes ago
It was discovered that cups-filters incorrectly handled certain malformed TIFF image files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2025-57812) It was discovered that cups-filters incorrectly handled certain malformed PDF document files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2025-64503) It was discovered that cups-filters incorrectly handled certain malformed CUPS Raster files. A remote attacker could use this issue to cause cups-filters to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-64524)

USN-7877-1: libcupsfilters vulnerabilities

23 hours ago
It was discovered that libcupsfilters incorrectly handled certain malformed TIFF image files. A remote attacker could use this issue to cause libcupsfilters to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-57812) It was discovered that libcupsfilters incorrectly handled certain malformed PDF document files. A remote attacker could use this issue to cause libcupsfilters to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2025-64503)

USN-7861-4: Linux kernel (AWS) vulnerabilities

1 day 17 hours ago
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HSI subsystem; - Bluetooth subsystem; - Timer subsystem; (CVE-2025-37838, CVE-2025-38118, CVE-2025-38352)

USN-7875-1: Linux kernel (Oracle) vulnerabilities

1 day 17 hours ago
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - DMA engine subsystem; - GPU drivers; - HSI subsystem; - Media drivers; - Ethernet team driver; - SPI subsystem; - USB core drivers; - Framebuffer layer; - BTRFS file system; - Ext4 file system; - Network file system (NFS) server daemon; - NILFS2 file system; - Timer subsystem; - DCCP (Datagram Congestion Control Protocol); - IPv6 networking; - NET/ROM layer; - Packet sockets; - Network traffic control; - SCTP protocol; - VMware vSockets driver; - USB sound devices; (CVE-2023-52477, CVE-2023-52574, CVE-2023-52650, CVE-2024-27074, CVE-2024-35849, CVE-2024-41006, CVE-2024-47685, CVE-2024-49924, CVE-2024-50006, CVE-2024-50051, CVE-2024-50202, CVE-2024-50299, CVE-2024-53124, CVE-2024-53130, CVE-2024-53131, CVE-2024-53150, CVE-2024-56767, CVE-2024-57996, CVE-2025-21796, CVE-2025-37752, CVE-2025-37785, CVE-2025-37838, CVE-2025-38350, CVE-2025-38352, CVE-2025-38477, CVE-2025-38617, CVE-2025-38618)

drupal7-7.103-1.fc43

1 day 17 hours ago

drupal7-7.103-1.fc42

1 day 17 hours ago

drupal7-7.103-1.fc41

1 day 17 hours ago

USN-7874-2: Linux kernel (FIPS) vulnerabilities

1 day 21 hours ago
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HSI subsystem; - I3C subsystem; - SMB network file system; - Padata parallel execution mechanism; - Timer subsystem; - Networking core; (CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-56664, CVE-2025-21727, CVE-2025-37838, CVE-2025-38352)

USN-7874-1: Linux kernel vulnerabilities

1 day 21 hours ago
Jean-Claude Graf, Sandro Rüegge, Ali Hajiabadi, and Kaveh Razavi discovered that the Linux kernel contained insufficient branch predictor isolation between a guest and a userspace hypervisor for certain processors. This flaw is known as VMSCAPE. An attacker in a guest VM could possibly use this to expose sensitive information from the host OS. (CVE-2025-40300) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HSI subsystem; - I3C subsystem; - SMB network file system; - Padata parallel execution mechanism; - Timer subsystem; - Networking core; (CVE-2023-52854, CVE-2024-35867, CVE-2024-50061, CVE-2024-56664, CVE-2025-21727, CVE-2025-37838, CVE-2025-38352)