Aggregator

bubblewrap-0.12.0-1.fc43

2 weeks 3 days ago
FEDORA-2026-96e0765328 Packages in this update:
  • bubblewrap-0.12.0-1.fc43
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

bubblewrap-0.12.0-1.fc44

2 weeks 3 days ago
FEDORA-2026-3d9bd126ce Packages in this update:
  • bubblewrap-0.12.0-1.fc44
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

GitPython-3.1.60-1.fc44

2 weeks 3 days ago
FEDORA-2026-32054fb87a Packages in this update:
  • GitPython-3.1.60-1.fc44
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

USN-8683-1: libheif vulnerabilities

2 weeks 3 days ago
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-62289) Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS. (CVE-2026-62291)

USN-8682-1: Bind vulnerabilities

2 weeks 3 days ago
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zhang discovered that Bind incorrectly handled self-pointed glue records. A remote attacker could possibly use this issue to use Bind in denial of service amplification attacks against other systems. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-3592) It was discovered that Bind incorrectly handled DNS messages whose class was not IN. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5946)