6 days 13 hours ago
FEDORA-2026-f4563b100f
Packages in this update:
Update description:
patchlevel 2146
Security fix for CVE-2026-25749
6 days 14 hours ago
FEDORA-2026-7eda235f65
Packages in this update:
Update description:
patchlevel 2146
Security fix for CVE-2026-25749
6 days 15 hours ago
FEDORA-2026-6ee987bce2
Packages in this update:
- python3.13-3.13.12-1.fc43
Update description:
Update to 3.13.12
6 days 15 hours ago
FEDORA-EPEL-2026-e148a6bb84
Packages in this update:
- python3.13-3.13.12-1.el10_1
Update description:
Update to 3.13.12
6 days 16 hours ago
6 days 17 hours ago
Charles Chan discovered that AIOHTTP incorrectly handled the decompression
of compressed requests. A remote attacker could possibly use this issue to
cause a denial of service. This issue was only addressed in Ubuntu 25.10.
(CVE-2025-69223)
Thomas Rinsma discovered that AIOHTTP incorrectly handled non-ASCII
characters in HTTP headers. A remote attacker could possibly use this issue
to perform a request smuggling attack to bypass certain proxy protections.
This issue was only addressed in Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and
Ubuntu 25.10. (CVE-2025-69224)
Thomas Rinsma discovered that AIOHTTP incorrectly handled non-ASCII
characters in the Range header. A remote attacker could possibly use this
issue to perform a request smuggling attack. (CVE-2025-69225)
Thomas Rinsma discovered that AIOHTTP incorrectly handled path
normalization when serving static files. A remote attacker could possibly
use this issue to obtain sensitive information. (CVE-2025-69226)
Thomas Rinsma discovered that AIOHTTP incorrectly handled certain POST
request bodies. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2025-69227)
Thomas Rinsma discovered that AIOHTTP incorrectly handled large POST
request payloads. A remote attacker could possibly use this issue to cause
a denial of service. (CVE-2025-69228)
It was discovered that AIOHTTP incorrectly handled chunked messages. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2025-69229)
1 week ago
Yuhan Gao and Peng Zhou discovered that Dottie was vulnerable to prototype
pollution when altering the __proto__ magical attribute. An attacker could
possibly use this issue to achieve remote code execution.
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Padata parallel execution mechanism;
- Netfilter;
(CVE-2022-49698, CVE-2025-21726, CVE-2025-40019)
1 week ago
Titouan Lazard discovered that MUNGE contained an exploitable buffer
overflow in munged (the MUNGE authentication daemon). A local attacker
could possibly use this issue to forge MUNGE credentials, leading to
arbitrary code execution.
1 week ago
It was discovered that the libpng simplified API incorrectly handled
quantizing RGB images. If a user or automated system were tricked into
opening a specially crafted PNG file, an attacker could use this issue to
cause libpng to crash, resulting in a denial of service.
1 week ago
It was discovered that nginx incorrectly handled proxying to upstream TLS
servers. An attacker could possibly use this issue to insert plain text
data into the response from an upstream proxied server.
1 week ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Media drivers;
- NVME drivers;
- File systems infrastructure;
- Timer subsystem;
- Memory management;
- Packet sockets;
(CVE-2022-48986, CVE-2024-27078, CVE-2024-49959, CVE-2024-50195,
CVE-2024-56606, CVE-2024-56756, CVE-2025-39993)
1 week ago
FEDORA-2026-b1b37b00ef
Packages in this update:
- python3.13-3.13.12-1.fc42
- python3-docs-3.13.12-1.fc42
Update description:
Update to 3.13.12
1 week ago
It was discovered that HTTP/2, which is used/vendored by DNSdist, did not
properly account for resources when handling client-triggered stream
resets. An attacker could possibly use this issue to cause a
denial of service. (CVE-2025-8671)
It was discovered that DNSdist did not properly manage memory limits when
handling an unlimited number of queries on a single TCP connection. An
attacker could possibly use this issue to cause a denial of service.
(CVE-2025-30193)
It was discovered that DNSdist, when configured with the nghttp2 library,
did not correctly process certain DNS over HTTPS queries. An attacker
could possibly use this cause a denial of service. (CVE-2025-30187)
1 week ago
FEDORA-EPEL-2026-2fbc90c446
Packages in this update:
- python3.13-3.13.12-1.el10_2
Update description:
Update to 3.13.12
1 week ago
FEDORA-EPEL-2026-7e7682c00c
Packages in this update:
Update description:
Update to 3.13.12
1 week ago
Asim Viladi Oglu Manizada discovered that HAProxy incorrectly handled
certain INITIAL packets. A remote attacker could possibly use this issue
to cause HAProxy to crash, resulting in a denial of service.
1 week ago
Version:next-20260212 (linux-next)
Released:2026-02-12
1 week ago
It was discovered that the libpng simplified API incorrectly processed
palette PNG images with partial transparency and gamma correction. If a
user or automated system were tricked into opening a specially crafted PNG
file, an attacker could use this issue to cause libpng to crash, resulting
in a denial of service. (CVE-2025-66293)
Petr Simecek, Stanislav Fort and Pavel Kohout discovered that the libpng
simplified API incorrectly processed interlaced 16-bit PNGs with 8-bit
output format and non-minimal row strides. If a user or automated system
were tricked into opening a specially crafted PNG file, an attacker could
use this issue to cause libpng to crash, resulting in a denial of service.
(CVE-2026-22695)
Cosmin Truta discovered that the libpng simplified API incorrectly handled
invalid row strides. If a user or automated system were tricked into
opening a specially crafted PNG file, an attacker could use this issue to
cause libpng to crash, resulting in a denial of service. This issue only
affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-22801)
It was discovered that the libpng simplified API incorrectly handled
quantizing RGB images. If a user or automated system were tricked into
opening a specially crafted PNG file, an attacker could use this issue to
cause libpng to crash, resulting in a denial of service. (CVE-2026-25646)
1 week ago
FEDORA-2026-2af2f2fa9d
Packages in this update:
- mingw-libpng-1.6.55-1.fc42
Update description:
Update to libpng-1.6.55.