Aggregator

kernel-7.1.4-104.fc43

3 days 22 hours ago
FEDORA-2026-6503a6a639 Packages in this update:
  • kernel-7.1.4-104.fc43
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

USN-8591-1: AIOHTTP vulnerabilities

3 days 22 hours ago
Sean Gilligan discovered that AIOHTTP did not properly limit memory usage when processing HTTP headers and trailers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-22815) It was discovered that AIOHTTP did not properly limit the size of its DNS cache. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34513) Mingi Jung discovered that AIOHTTP did not properly sanitize the content_type parameter. An attacker could possibly use this issue to inject malicious HTTP headers, resulting in HTTP response splitting. (CVE-2026-34514) It was discovered that AIOHTTP did not properly limit memory usage when processing multipart headers. An attacker could possibly use this issue to consume excessive system resources, resulting in a denial of service. (CVE-2026-34516)

USN-8590-1: Exim vulnerabilities

4 days 2 hours ago
It was discovered that Exim incorrectly handled certain command line options. A local attacker could possibly use this issue to access files outside of the spool area. It was discovered that Exim incorrectly handled string expansion in .local files. A local attacker could possibly use this issue to escalate privileges.

USN-8589-1: Apache HTTP Server vulnerabilities

4 days 2 hours ago
It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-29167) It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled HTML generation for FTP directory listings. A remote attacker could possibly use this issue to inject arbitrary web script or HTML. (CVE-2026-29170) Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module was vulnerable to a timing attack. A remote attacker could possibly use this issue to bypass Digest authentication. (CVE-2026-33006)

USN-8588-1: Gawk vulnerabilities

4 days 3 hours ago
It was discovered that Gawk incorrectly handled memory when processing input using the getline redirection. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40467) It was discovered that Gawk incorrectly handled certain integer calculations when allocating memory. An attacker could possibly use this issue to cause a denial of service or overwrite heap memory with attacker-controlled data. (CVE-2026-40468) It was discovered that Gawk incorrectly handled certain integer calculations when performing substitutions. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-40469) It was discovered that Gawk incorrectly handled memory when reading directory entries. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-40553)

bpfman-0.5.4-13.fc45

4 days 3 hours ago
FEDORA-2026-fa34dc95e6 Packages in this update:
  • bpfman-0.5.4-13.fc45
Update description:

Automatic update for bpfman-0.5.4-13.fc45.

Changelog * Wed Jul 22 2026 Daniel Mellado <dmellado@fedoraproject.org> - 0.5.4-13 - Bump vendored openssl to 0.10.78 / openssl-sys to 0.9.117 for OpenSSL 4.0 support * Wed Jul 15 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.5.4-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 12 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 0.5.4-11 - Rebuilt for openssl 4.0 * Tue Apr 28 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-10 - update sources and spec * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-9 - add source vendor * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-8 - Fix CVE-2026-25727: Bump time to 0.3.47 - closes rhbz#2438107

USN-8477-3: tar regression

4 days 4 hours ago
USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could cause tar to fail to extract old archives that recorded a nonzero size for directory entries, resulting in a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms.

USN-8586-1: libgphoto2 vulnerabilities

4 days 6 hours ago
It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing EOS image format data. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40333) It was discovered that libgphoto2 did not properly null-terminate buffers when parsing Canon folder entries. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40334) It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing device property values. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40335) It was discovered that libgphoto2 had a memory leak when parsing Sony device property descriptors. An attacker with physical access could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-40336) It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing Sony device property enumeration data. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40338) It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing Sony device property form flags. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40339) It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing object information. An attacker with physical access could possibly use this issue to obtain sensitive information. (CVE-2026-40340) It was discovered that libgphoto2 did not properly validate buffer boundaries when parsing EOS focus information. An attacker with physical access could possibly use this issue to cause libgphoto2 to crash, resulting in a denial of service. (CVE-2026-40341)

USN-8585-1: Kerberos vulnerabilities

4 days 6 hours ago
It was discovered that Kerberos had an integer underflow vulnerability in the berval2tl_data() function. An attacker could possibly use this issue to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-11850) It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism parsing. A remote attacker could possibly use these issues to cause Kerberos to crash, resulting in a denial of service. (CVE-2026-40355, CVE-2026-40356)

USN-8584-1: GStreamer Good Plugins vulnerabilities

4 days 6 hours ago
It was discovered that GStreamer Good Plugins incorrectly handled certain Matroska files. An attacker could possibly use this issue to cause GStreamer Good Plugins to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39043) It was discovered that GStreamer Good Plugins incorrectly handled certain WAV files. An attacker could possibly use this issue to cause GStreamer Good Plugins to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39044) It was discovered that GStreamer Good Plugins incorrectly handled certain WavPack audio files. An attacker could use this issue to cause GStreamer Good Plugins to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-53705)

USN-8583-1: GIFLIB vulnerabilities

4 days 6 hours ago
It was discovered that GIFLIB incorrectly handled certain GIF image files. If a user or automated system were tricked into opening a specially crafted GIF file, a remote attacker could use this issue to cause GIFLIB to crash, resulting in a denial of service, or possibly execute arbitrary code.