Aggregator

freeipmi-1.6.19-1.fc45

3 days 15 hours ago
FEDORA-2026-abe39f1809 Packages in this update:
  • freeipmi-1.6.19-1.fc45
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

perl-Net-DNS-1.57-1.el10_4

3 days 16 hours ago
FEDORA-EPEL-2026-0f5b361fa5 Packages in this update:
  • perl-Net-DNS-1.57-1.el10_4
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.el10_3

3 days 16 hours ago
FEDORA-EPEL-2026-8a37d4d02f Packages in this update:
  • perl-Net-DNS-1.57-1.el10_3
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc44

3 days 16 hours ago
FEDORA-2026-57f107ed83 Packages in this update:
  • perl-Net-DNS-1.57-1.fc44
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc43

3 days 16 hours ago
FEDORA-2026-48a4531e02 Packages in this update:
  • perl-Net-DNS-1.57-1.fc43
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

evolution-3.62.0-1.fc45 evolution-data-server-3.62.0-1.fc45 evolution-ews-3.62.0-1.fc45

3 days 17 hours ago
FEDORA-2026-5debc0de2b Packages in this update:
  • evolution-3.62.0-1.fc45
  • evolution-data-server-3.62.0-1.fc45
  • evolution-ews-3.62.0-1.fc45
Update description:

Update to 3.62.0

evolution-data-server

Bug Fixes:

  • I#660 - GOA EWS: Do not require OABUrl in autodiscover
  • I#662 - EBackend: Document how OAuth2 sources should ask to be authenticated (Tobias Mueller)
  • I#665 - CalDAV: Ignore Bad Request (400) on overwrite
  • M!243 - ESourceRegistry: Name the credentials source in failed-lookup debug message (Tobias Mueller)

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • Emin Tufan Çetin (tr)
  • Juliano de Souza Camargo (pt_BR)
  • Kjartan Maraas (nb)
evolution

Bug Fixes:

  • I#3381 - Composer: De-duplicate inline images before send
  • I#3383 - junk-filters: Do not leak the child stdin pipe into concurrent spawns (Benjamin Herrenschmidt)
  • I#3386 - Default to not use read-only calendars for reminders and conflict search
  • I#3387 - EUIParser: Notify about accelerators moved by an action rename (Martin Monperrus (AI-assisted))
  • I#3388 - Mail: Validate clickable preview elements are generated by Evolution
  • M!235 - Mail: Remove deprecated SHA1 signature algorithm (Robin Haberkorn)

Miscellaneous:

  • docs: Add API index for newly added symbols in 3.62 for e-util

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • burns (pt_BR)
  • Emin Tufan Çetin (tr)
  • Guillaume Bernard (fr)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)
evolution-ews

Bug Fixes:

  • M!18 - Add a per-folder coalescing gate for sync and refresh (Benjamin Herrenschmidt)
  • M!19 - camel: Do not save the folder summary in the subclass dispose (David Woodhouse)

Translations:

  • Alan Mortensen (da)
  • Balázs Úr (hu)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)

USN-8750-1: FFmpeg vulnerabilities

3 days 23 hours ago
Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-12706) Xinghang Lv discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-30999) It was discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a denial of service. (CVE-2026-58049) Adrian Junge discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could leak sensitive information. (CVE-2026-70629, CVE-2026-70630, CVE-2026-70631) Ori Hollander discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly cause a denial of service or execute arbitrary code. (CVE-2026-8461)

USN-8749-1: CivetWeb vulnerabilities

4 days 1 hour ago
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-55763) It was discovered that CivetWeb did not correctly handle parsing certain HTTP requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2025-9648)

perl-HTML-FormHandler-0.410002-1.fc44

4 days 16 hours ago
FEDORA-2026-21850d7df0 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc44
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc43

4 days 16 hours ago
FEDORA-2026-167a356523 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc43
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc45

4 days 16 hours ago
FEDORA-2026-406a152d49 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc45
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.