Aggregator
gvfs-1.58.4-4.fc43
FEDORA-2026-571b7e1505
Packages in this update:
- gvfs-1.58.4-4.fc43
Fix CVE-2026-84267, CVE-2026-84268, CVE-2026-84269, and CVE-2026-84270
syncthing-2.1.3-1.fc44
FEDORA-2026-c33332bcf7
Packages in this update:
- syncthing-2.1.3-1.fc44
2.1.3, fix for CVE-2026-40898
syncthing-2.1.3-1.fc45
FEDORA-2026-bd6debcfb6
Packages in this update:
- syncthing-2.1.3-1.fc45
2.1.3, fix for CVE-2026-40898
python-jwcrypto-1.6.0-1.fc45
FEDORA-2026-6d094c5360
Packages in this update:
- python-jwcrypto-1.6.0-1.fc45
Low severity security fixes
python-jwcrypto-1.6.0-1.fc44
FEDORA-2026-8caad572b0
Packages in this update:
- python-jwcrypto-1.6.0-1.fc44
Low severity security fixes
USN-8712-1: pyasn1 vulnerabilities
It was discovered that pyasn1 did not properly bound the size of long-form
tag identifiers when parsing BER, CER, or DER encoded data. An attacker
could possibly use this issue to cause applications decoding untrusted
ASN.1 data to consume excessive CPU resources, resulting in a denial of
service. (CVE-2026-59884)
It was discovered that pyasn1 processed OBJECT IDENTIFIER and RELATIVE-OID
values in quadratic time relative to the number of arcs. An attacker could
possibly use this issue to cause applications decoding untrusted ASN.1 data
to consume excessive CPU resources, resulting in a denial of service.
(CVE-2026-59885)
It was discovered that pyasn1 incorrectly handled conversion of decoded
REAL values to Python float types. An attacker could possibly use this
issue to cause applications decoding untrusted ASN.1 data to consume
excessive CPU and memory resources, resulting in a denial of service.
(CVE-2026-59886)
USN-8711-1: Libgcrypt vulnerability
It was discovered that Libgcrypt had a timing-based side-channel flaw in
its RSA implementation. A remote attacker could possibly use this issue to
obtain sensitive information.
USN-8688-2: PAM vulnerability
USN-8688-1 fixed a vulnerability in PAM. This update provides the
corresponding fix for PAM on Ubuntu 26.04 LTS.
Original advisory details:
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
next-20260901: linux-next
Version:next-20260901 (linux-next)
Released:2026-09-01
USN-8555-2: Ubuntu Advantage Tools (pro client) regression
USN-8555-1 fixed vulnerabilities in Ubuntu Advantage Tools. On Ubuntu
14.04 LTS only, it was discovered that some machines were unable to
enable esm-infra-legacy due to a preemptive apt-helper check. This
update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Bilal Teke discovered that Ubuntu Advantage Tools exposed the Pro bearer
token in command-line arguments when validating APT credentials. A local
attacker could possibly use this issue to obtain sensitive information
and gain unauthorized access to Ubuntu Pro repositories. (CVE-2026-9494)
Frederick Jerusha discovered that Ubuntu Advantage Tools did not properly
validate data received from the contract server when writing APT source
files. An attacker could possibly use this issue to inject arbitrary APT
configuration and execute arbitrary code. (CVE-2026-11386)
Mateusz Gierblinski discovered that Ubuntu Advantage Tools did not
properly handle symbolic links when collecting diagnostic logs. A local
attacker could possibly use this issue to obtain sensitive information
from files owned by the administrator. This issue only affected Ubuntu
16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-12391)
USN-8710-1: libevent vulnerabilities
Alexis Challande discovered that libevent incorrectly handled certain
empty output buffers. An attacker could possibly use this issue to
trigger a use-after-free, resulting in a denial of service or arbitrary
code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04
LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-63381)
Rajat Raghav discovered that libevent incorrectly handled certain HTTP
requests. An attacker could possibly use this issue to desynchronize
HTTP request boundaries, resulting in HTTP request smuggling.
(CVE-2026-63382)
Qiu Sihao discovered that libevent incorrectly handled certain malformed
tagged RPC data. An attacker could possibly use this issue to trigger an
out-of-bounds read, resulting in a denial of service. (CVE-2026-63383)
Qiu Sihao discovered that libevent incorrectly handled certain large
payload lengths in tagged RPC data. An attacker could possibly use this
issue to consume excessive system resources, resulting in a denial of
service. (CVE-2026-63384)
Asaf Meizner discovered that libevent incorrectly handled certain HTTP
URIs and header values. An attacker could possibly use this issue to
cause HTTP messages to be interpreted inconsistently, resulting in
security restrictions being bypassed. (CVE-2026-63385)
USN-8709-1: ncurses vulnerability
It was discovered that ncurses incorrectly handled specially crafted
terminfo database entries. A local attacker could possibly use this issue
to cause applications using ncurses to crash, resulting in a denial of
service.
darktable-5.6.1-2.fc44
FEDORA-2026-2719c6cac1
Packages in this update:
- darktable-5.6.1-2.fc44
5.6.1 release
darktable-5.6.1-2.fc45
FEDORA-2026-8a0b0bba30
Packages in this update:
- darktable-5.6.1-2.fc45
5.6.1 release
5.6.1 release
freerdp2-2.11.7-7.el10_2
FEDORA-EPEL-2026-0563db3f0c
Packages in this update:
- freerdp2-2.11.7-7.el10_2
Backport several CVE fixes
freerdp2-2.11.7-7.el10_3
FEDORA-EPEL-2026-aa30a19f4c
Packages in this update:
- freerdp2-2.11.7-7.el10_3
Backport several CVE fixes
freerdp2-2.11.7-7.el10_4
FEDORA-EPEL-2026-1c4570b861
Packages in this update:
- freerdp2-2.11.7-7.el10_4
Backport several CVE fixes
freerdp2-2.11.7-16.fc43
FEDORA-2026-3fe3e3ae10
Packages in this update:
- freerdp2-2.11.7-16.fc43
Backport several CVE fixes
freerdp2-2.11.7-16.fc44
FEDORA-2026-d91338eea8
Packages in this update:
- freerdp2-2.11.7-16.fc44
Backport several CVE fixes