2 weeks 3 days ago
Thomas Beckers discovered that the JAXP component of OpenJDK 8 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the JSSE component of OpenJDK 8 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could possibly
use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that the JGSS component of OpenJDK 8 did not correctly
authenticate certain APIs. A remote attacker could possibly use this issue
to obtain sensitive information. (CVE-2026-22013)
It was discovered that the 2D component of OpenJDK 8 did not correctly
handle certain integer arithmetic. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive information. (CVE-2026-23865)
It was discovered that the Libraries component of OpenJDK 8 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-22018)
Ken Pyle discovered that the Security component of OpenJDK 8 did not
correctly authenticate certain APIs. A local attacker could possibly use
this issue to leak sensitive information. (CVE-2026-22007, CVE-2026-34268)
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://openjdk.org/groups/vulnerability/advisories/2026-04-21
2 weeks 3 days ago
FEDORA-2026-2d0a32ddc0
Packages in this update:
- rubygem-yard-0.9.37-5.fc43
Update description:
Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues
2 weeks 3 days ago
FEDORA-2026-acefc1fe48
Packages in this update:
- rubygem-yard-0.9.40-2.fc44
Update description:
Backport 0.9.41 / 0.9.44 fixes for possible path traversal issues
2 weeks 3 days ago
It was discovered that the FFmpeg CAF decoder incorrectly handled certain
file size calculations. An attacker could possibly use this issue to cause
FFmpeg to crash, resulting in a denial of service.
2 weeks 3 days ago
Thomas Beckers discovered that the JAXP component of OpenJDK 21 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to gain unauthorized access to sensitive
information. (CVE-2026-22016)
It was discovered that the Networking component of OpenJDK 21 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-34282)
It was discovered that the JSSE component of OpenJDK 21 did not correctly
authenticate certain APIs. A remote unauthenticated attacker could possibly
use this issue to cause a denial of service. (CVE-2026-22021)
It was discovered that the JGSS component of OpenJDK 21 did not correctly
authenticate certain APIs. A remote attacker could possibly use this issue
to obtain sensitive information. (CVE-2026-22013)
It was discovered that the 2D component of OpenJDK 21 did not correctly
handle certain integer arithmetic. If a user or automated system were
tricked into opening a specially crafted file, an attacker could possibly
use this issue to leak sensitive information. (CVE-2026-23865)
It was discovered that the Libraries component of OpenJDK 21 did not
correctly authenticate certain APIs. A remote unauthenticated attacker
could possibly use this issue to cause a denial of service.
(CVE-2026-22018)
Ken Pyle discovered that the Security component of OpenJDK 21 did not
correctly authenticate certain APIs. A local attacker could possibly use
this issue to leak sensitive information. (CVE-2026-22007, CVE-2026-34268)
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://openjdk.org/groups/vulnerability/advisories/2026-04-21
2 weeks 3 days ago
2 weeks 3 days ago
2 weeks 3 days ago
2 weeks 3 days ago
2 weeks 3 days ago
FEDORA-EPEL-2026-ea9af18b11
Packages in this update:
Update description:
Update to 6.0.6 to fix CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291
2 weeks 3 days ago
FEDORA-2026-ecfadb29a1
Packages in this update:
- rust-sequoia-cert-store-0.7.3-1.fc43
- rust-sequoia-chameleon-gnupg-0.13.1-13.fc43
- rust-sequoia-octopus-librnp-1.11.1-7.fc43
- rust-sequoia-sop-0.37.3-4.fc43
- rust-sequoia-sq-1.3.1-12.fc43
- rust-sequoia-wot-0.15.2-1.fc43
Update description:
- Update the sequoia-wot crate to version 0.15.2.
- Update the sequoia-keystore crate to version 0.7.3.
This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:
2 weeks 3 days ago
FEDORA-2026-5c5f4f40a4
Packages in this update:
- rust-sequoia-cert-store-0.7.3-1.fc44
- rust-sequoia-chameleon-gnupg-0.13.1-13.fc44
- rust-sequoia-octopus-librnp-1.11.1-7.fc44
- rust-sequoia-sop-0.37.3-4.fc44
- rust-sequoia-sq-1.3.1-12.fc44
- rust-sequoia-wot-0.15.2-1.fc44
Update description:
- Update the sequoia-wot crate to version 0.15.2.
- Update the sequoia-keystore crate to version 0.7.3.
This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:
2 weeks 4 days ago
FEDORA-2026-4a6b728056
Packages in this update:
- dolphin-emu-2503a-16.fc45
Update description:
Automatic update for dolphin-emu-2503a-16.fc45.
Changelog
* Wed May 27 2026 Jeremy Newton <
alexjnewt@hotmail.com> - 2503a-16
- Fix RHBZ#2454084
2 weeks 4 days ago
FEDORA-EPEL-2026-9b6d13e4b9
Packages in this update:
- strongswan-6.0.6-1.el10_3
Update description:
Fixes CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291
2 weeks 4 days ago
Matthias Gerstner discovered that Foomuuri's D-Bus service did not properly
enforce authorization. An unprivileged local attacker could possibly use
this issue to manipulate the firewall configuration, contrary to
expectations. (CVE-2025-67603)
Matthias Gerstner discovered that Foomuuri's D-Bus service did not properly
validate interface names. A local attacker could possibly use this issue to
manipulate the firewall configuration in unintended ways. (CVE-2025-67858)
2 weeks 4 days ago
FEDORA-2026-bc20b091a8
Packages in this update:
Update description:
The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.
2 weeks 4 days ago
FEDORA-2026-146d86eefc
Packages in this update:
Update description:
The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.
2 weeks 4 days ago
Version:next-20260527 (linux-next)
Released:2026-05-27
2 weeks 4 days ago
It was discovered that tgt incorrectly tried to achieve entropy by calling
rand without srand. An attacker could possibly use this issue to make tgt
generate an identical sequence of challenges, resulting in authentication
bypass.
2 weeks 4 days ago
It was discovered that Apache Tika incorrectly handled XML external
entities when parsing XFA content in PDF files. An attacker could possibly
use this issue to obtain sensitive information or send malicious requests
to internal resources or third-party servers.