2 days 23 hours ago
2 days 23 hours ago
2 days 23 hours ago
2 days 23 hours ago
3 days ago
FEDORA-2026-5db1745c4f
Packages in this update:
Update description:
- Update to 6.1.0 for CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134 and CVE-2026-78135
3 days 1 hour ago
It was discovered that GStreamer Good Plugins incorrectly parsed certain
MRF files. A remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2026-18295, CVE-2026-18296)
It was discovered that GStreamer Good Plugins incorrectly parsed certain
PNG files. A remote attacker could possibly use this issue to execute
arbitrary code. (CVE-2026-18298)
DongHyeon Hwang discovered that GStreamer Good Plugins incorrectly
handled certain RTP packets. A remote attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-18299)
3 days 1 hour ago
It was discovered that GStreamer Base Plugins incorrectly handled certain
OGG media files. A remote attacker could possibly use this issue to
execute arbitrary code if it opened a specially crafted file.
3 days 1 hour ago
FEDORA-2026-a387125860
Packages in this update:
Update description:
Update to latest upstream version.
Update to latest stable upstream version.
3 days 3 hours ago
It was discovered that GLib's GDBus authentication mechanism failed to
enforce length limitations on data lines read from a client. An
unauthenticated attacker could exploit this to cause a denial of service
via resource exhaustion. (CVE-2026-15588)
It was discovered that the xdgmime library in GLib had a heap-based
buffer overflow. An attacker-controlled MIME magic file could cause an
out-of-bounds write on little-endian systems. (CVE-2026-16118)
It was discovered that GLib had an off-by-one error in the GVariant
serialiser. An attacker could use this to cause an out-of-bounds read,
leading to information disclosure or a denial of service.
(CVE-2026-58010)
It was discovered that GLib had an out-of-bounds read in GDateTime. An
attacker could use this to corrupt date output and cause a denial of
service. (CVE-2026-58011)
It was discovered that GLib's g_regex_replace() function had a buffer
over-read when used with the G_REGEX_RAW flag. An attacker could use
this to cause information disclosure or a denial of service.
(CVE-2026-58012)
It was discovered that GLib's GIOChannel had a buffer over-read when
using a custom line terminator. An attacker could use this to cause
information disclosure or a denial of service. (CVE-2026-58013)
It was discovered that GLib's GKeyFile had an off-by-one error when
loading a key file with an empty value. An attacker could use this to
cause an out-of-bounds access or a denial of service. (CVE-2026-58014)
It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism
failed to validate the cookie_context parameter. A malicious D-Bus
server could use this to read arbitrary files from the client.
(CVE-2026-58015)
It was discovered that GLib's D-Bus introspection XML parser had a
state confusion issue. An attacker could use this to cause an
out-of-bounds read and denial of service. (CVE-2026-58016)
3 days 3 hours ago
Kai Aizen discovered that the Networking component of OpenJDK 21 did not
correctly handle user authentication. A remote attacker could possibly use
this issue to leak sensitive information. (CVE-2026-61308)
It was discovered that the JSSE component of OpenJDK 21 did not correctly
handle user authentication. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-70907)
It was discovered that the Security component of OpenJDK 21 did not
correctly handle user authentication. A remote attacker could possibly use
this issue to leak sensitive information. (CVE-2026-60589)
3 days 3 hours ago
Kai Aizen discovered that the Networking component of OpenJDK 17 did not
correctly handle user authentication. A remote attacker could possibly use
this issue to leak sensitive information. (CVE-2026-61308)
It was discovered that the JSSE component of OpenJDK 17 did not correctly
handle user authentication. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-70907)
It was discovered that the Security component of OpenJDK 17 did not
correctly handle user authentication. A remote attacker could possibly use
this issue to leak sensitive information. (CVE-2026-60589)
3 days 5 hours ago
Version:next-20260921 (linux-next)
Released:2026-09-21
3 days 5 hours ago
It was discovered that Expat could be made to allocate large amounts of
memory when parsing a small crafted document. An attacker could possibly
use this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 24.04 LTS.
(CVE-2025-59375)
It was discovered that Expat incorrectly handled empty external parameter
entity content. An attacker could possibly use this issue to cause Expat to
crash, resulting in a denial of service. (CVE-2026-32776)
It was discovered that Expat incorrectly handled certain DTD content. An
attacker could possibly use this issue to cause Expat to enter an infinite
loop, resulting in a denial of service. (CVE-2026-32777)
It was discovered that Expat incorrectly handled memory when retrying after
an earlier out-of-memory condition. An attacker could possibly use this
issue to cause Expat to crash, resulting in a denial of service.
(CVE-2026-32778)
It was discovered that Expat performed attribute name collision checks
inefficiently. An attacker could possibly use this issue to cause Expat to
consume resources when processing a moderately sized crafted XML document,
resulting in a denial of service. This issue was only addressed in Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-45186)
It was discovered that Expat used insufficient entropy, allowing hash
flooding through a crafted XML document. An attacker could possibly use
this issue to cause Expat to consume resources, leading to a denial of
service. This issue was only addressed in Ubuntu 14.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-41080)
It was discovered that Expat did not track handler call depth for certain
functions called from within handlers, leading to a use-after-free. An
attacker could possibly use this issue to cause Expat to crash, resulting
in a denial of service, or possibly execute arbitrary code.
(CVE-2026-50219, CVE-2026-56412)
It was discovered that Expat incorrectly handled certain values, leading to
integer overflows. An attacker could possibly use this issue to cause Expat
to crash, resulting in a denial of service. (CVE-2026-56403,
CVE-2026-56404, CVE-2026-56405)
It was discovered that Expat incorrectly handled certain values, leading to
an integer overflow. An attacker could possibly use this issue to cause
Expat to crash, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and
Ubuntu 26.04 LTS. (CVE-2026-56408)
3 days 5 hours ago
FEDORA-2026-f5733c1dd0
Packages in this update:
Update description:
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes
3 days 5 hours ago
FEDORA-2026-019108693f
Packages in this update:
Update description:
Fixed CVE-2026-90558
3 days 5 hours ago
FEDORA-2026-e5174fc4cf
Packages in this update:
Update description:
Fixed CVE-2026-90558
3 days 5 hours ago
FEDORA-2026-3ff086aa2a
Packages in this update:
Update description:
Fixed CVE-2026-90558
3 days 6 hours ago
3 days 6 hours ago
3 days 6 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Bluetooth drivers;
- GPU drivers;
- Hardware monitoring drivers;
- SPI subsystem;
- NTFS3 file system;
- io_uring subsystem;
- Ethernet bridge;
- Multipath TCP;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315)