Aggregator

USN-8563-4: nginx regression

5 days 11 hours ago
USN-8563-3 fixed a vulnerability in nginx. The fix introduced a regression in certain environments. This update reverts the fix for CVE-2026-42533 pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

USN-8650-1: Cap'n Proto vulnerabilities

5 days 14 hours ago
Chanho Kim and Jihyeok Han discovered that Cap'n Proto incorrectly handled negative Content-Length values or excessively large chunk sizes when processing HTTP messages. An attacker could possibly use these issues to cause HTTP messages to be interpreted inconsistently, resulting in HTTP request or response smuggling. (CVE-2026-32239, CVE-2026-32240)

bluez-5.87-4.fc43

5 days 16 hours ago
FEDORA-2026-a1cdcc1604 Packages in this update:
  • bluez-5.87-4.fc43
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

bluez-5.87-4.fc44

5 days 16 hours ago
FEDORA-2026-1bbec06c4d Packages in this update:
  • bluez-5.87-4.fc44
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

openssh-10.2p1-14.fc44

5 days 17 hours ago
FEDORA-2026-752aa3ff05 Packages in this update:
  • openssh-10.2p1-14.fc44
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

USN-8649-1: libheif vulnerabilities

5 days 18 hours ago
It was discovered that libheif had an integer underflow in the Fraction constructor when a clap transform was applied twice. An attacker could possibly use this issue to cause libheif to crash, resulting in a denial of service. (CVE-2026-62289) It was discovered that libheif had an out-of-bounds read in uncompressed tile range slicing. An attacker could possibly use this issue to cause libheif to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10. (CVE-2026-62292)

openssh-10.0p1-12.fc43

5 days 18 hours ago
FEDORA-2026-535a408db5 Packages in this update:
  • openssh-10.0p1-12.fc43
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

USN-8563-3: nginx vulnerability

5 days 18 hours ago
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

USN-8648-1: Bind vulnerabilities

5 days 19 hours ago
It was discovered that Bind incorrectly accepted NSEC3 records whose signer name did not match the owning zone. A remote attacker could possibly use this issue to perform NSEC3 impersonation attacks, bypassing DNSSEC validation. (CVE-2026-10723) It was discovered that Bind incorrectly handled Key Records using the PRIVATEDNS algorithm. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2026-10822) It was discovered that Bind incorrectly handled wildcard CNAME expansion in Response Policy Zones. A remote attacker could possibly use this issue to bypass configured RPZ policies. (CVE-2026-11331) It was discovered that Bind performed unnecessary validation of DNSSEC signed records. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-11605) It was discovered that Bind incorrectly tracked memory usage in the DNS cache. A remote attacker could possibly use this issue to cause Bind to use memory beyond configured limits, leading to a denial of service. (CVE-2026-11622) It was discovered that Bind incorrectly handled signed wildcard records with label count discrepancies and RRSIG validation. A remote attacker could possibly use this issue to perform cache poisoning attacks. (CVE-2026-11721) It was discovered that Bind incorrectly handled certain CNAME and DNAME record orderings in the resolver. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2026-12617) It was discovered that Bind incorrectly validated out-of-zone NSEC next owner names during DNSSEC validation. A remote attacker could possibly use this issue to bypass DNSSEC validation. (CVE-2026-13321)