Aggregator

USN-8863-1: GStreamer Good Plugins vulnerabilities

2 days 3 hours ago
Yazan Balawneh discovered that GStreamer Good Plugins incorrectly handled certain FLAC audio streams. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-17072) Seonwook Kim discovered that GStreamer Good Plugins incorrectly parsed certain AVI files. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. (CVE-2026-73433) Seonwook Kim discovered that GStreamer Good Plugins did not correctly parse certain AVI files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-73434) Seonwook Kim discovered that GStreamer Good Plugins incorrectly handled certain closed caption data. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88914)

docker-buildx-0.37.2-1.fc43

2 days 5 hours ago
FEDORA-2026-d1b26c4745 Packages in this update:
  • docker-buildx-0.37.2-1.fc43
Update description:
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

docker-buildx-0.37.2-1.fc44

2 days 6 hours ago
FEDORA-2026-af9902ab5e Packages in this update:
  • docker-buildx-0.37.2-1.fc44
Update description:
  • Update to release v0.37.2
  • Resolves: rhbz#2544198
  • Resolves CVE-2026-56855: rhbz#2530594
  • resolves CVE-2026-78662: rhbz#2530802
  • Upstream fix

USN-8862-1: libXpm vulnerability

2 days 7 hours ago
It was discovered that libXpm did not correctly handle XPM images with zero-dimension values. A local attacker could possibly use this issue to cause libXpm to use excessive resources, leading to a denial of service.

USN-8861-1: OpenSSL vulnerabilities

2 days 8 hours ago
It was discovered that OpenSSL had an inefficient algorithm in its QUIC stream reassembly implementation. A remote attacker could possibly use this issue to cause OpenSSL to use excessive CPU resources, leading to a denial of service. (CVE-2026-42772) It was discovered that OpenSSL did not properly limit memory allocated for QUIC packet buffers. A remote attacker could possibly use this issue to cause OpenSSL to use excessive memory resources, leading to a denial of service. (CVE-2026-54873)

USN-8857-1: KCoreAddons vulnerability

2 days 9 hours ago
It was discovered that KCoreAddons incorrectly handled shell argument quoting in KShell::quoteArgs. The parsing did not adequately handle shell metacharacters, which could lead to a shell escape. An attacker could possibly use this issue to execute arbitrary commands in applications that relied on this method to handle user input.

php-getid3-1.9.27-1.fc44

2 days 11 hours ago
FEDORA-2026-71df118e18 Packages in this update:
  • php-getid3-1.9.27-1.fc44
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

php-getid3-1.9.27-1.fc45

2 days 11 hours ago
FEDORA-2026-6ef35023a5 Packages in this update:
  • php-getid3-1.9.27-1.fc45
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

php-getid3-1.9.27-1.fc43

2 days 11 hours ago
FEDORA-2026-b9ef1180ce Packages in this update:
  • php-getid3-1.9.27-1.fc43
Update description: Version 1.9.27: [2026-09-22]
  • GHSA-c2xw-vp6w-gpph compressed ID3v2 frames max length
  • GHSA-j649-xr34-mmmh remove LIBXML_NOENT
  • embedded picture in WMA files is corrupt
  • silent failure of @libxml_disable_entity_loader() enables XXE

GitPython-3.2.0-1.el9

2 days 11 hours ago
FEDORA-EPEL-2026-e0e0737425 Packages in this update:
  • GitPython-3.2.0-1.el9
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.