Aggregator

avr-binutils-2.45-8.fc45

2 days 14 hours ago
FEDORA-2026-220bbf27df Packages in this update:
  • avr-binutils-2.45-8.fc45
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

avr-binutils-2.45-8.fc44

2 days 14 hours ago
FEDORA-2026-bd6b3ee737 Packages in this update:
  • avr-binutils-2.45-8.fc44
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

avr-binutils-2.45-8.fc43

2 days 14 hours ago
FEDORA-2026-5a5f49bc55 Packages in this update:
  • avr-binutils-2.45-8.fc43
Update description:
  • fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)

USN-8867-1: Ceph vulnerability

2 days 15 hours ago
It was discovered that the Ceph Object Gateway (RGW) SigV4 handler did not reject requests carrying x-amz-* headers that were absent from the signed header set. An attacker holding a presigned URL could possibly use this issue to attach arbitrary unsigned x-amz-* headers that RGW would honor, allowing them to escalate their privileges beyond what the URL's signer intended.

USN-8865-1: EDK II vulnerabilities

2 days 15 hours ago
It was discovered that EDK II incorrectly handled CMS key unwrapping in the embedded OpenSSL library. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-63072) It was discovered that EDK II incorrectly handled CMP protection verification in the embedded OpenSSL library. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-63076) It was discovered that EDK II incorrectly buffered DTLS records in the embedded OpenSSL library. A remote attacker could possibly use this issue to cause EDK II to consume excessive memory, resulting in a denial of service. (CVE-2026-54874) It was discovered that EDK II incorrectly verified AEAD tags in the embedded OpenSSL library. An attacker could possibly use this issue to cause EDK II to accept forged messages. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-75803)

arm-none-eabi-binutils-cs-2.45-5.fc46

2 days 16 hours ago
FEDORA-2026-96f6bd1144 Packages in this update:
  • arm-none-eabi-binutils-cs-2.45-5.fc46
Update description:

Automatic update for arm-none-eabi-binutils-cs-2.45-5.fc46.

Changelog * Mon Oct 5 2026 Michal Hlavinka <mhlavink@redhat.com> - 1:2.45-5 - fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519352)

avr-binutils-2.45-8.fc46

2 days 17 hours ago
FEDORA-2026-0c04027565 Packages in this update:
  • avr-binutils-2.45-8.fc46
Update description:

Automatic update for avr-binutils-2.45-8.fc46.

Changelog * Mon Oct 5 2026 Michal Hlavinka <mhlavink@redhat.com> - 1:2.45-8 - fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519351)