Aggregator
DSA-6502-1 mkvtoolnix - security update
DSA-6503-1 thunderbird - security update
DSA-6496-2 nginx - regression update
mingw-pcre2-10.48-1.fc45
FEDORA-2026-68e2c40a81
Packages in this update:
- mingw-pcre2-10.48-1.fc45
Update to pcre-10.48
mingw-pcre2-10.48-1.fc43
FEDORA-2026-98f3f016c4
Packages in this update:
- mingw-pcre2-10.48-1.fc43
Update to pcre-10.48
mingw-pcre2-10.48-1.fc44
FEDORA-2026-e9c6062c07
Packages in this update:
- mingw-pcre2-10.48-1.fc44
Update to pcre-10.48
next-20260915: linux-next
Version:next-20260915 (linux-next)
Released:2026-09-15
USN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic
signatures in XML messages. An authenticated attacker could possibly use
this issue to impersonate users or gain elevated privileges. This issue
only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465)
It was discovered that SimpleSAMLphp incorrectly handled external entities
when parsing untrusted XML documents. A remote attacker could possibly use
this issue to obtain sensitive information. This issue did not affect
Ubuntu 24.04 LTS. (CVE-2024-52596)
It was discovered that SimpleSAMLphp incorrectly verified signatures in
SAML messages using the HTTP-Redirect binding. A remote attacker could
possibly use this issue to bypass authentication and impersonate users.
(CVE-2025-27773)
USN-8769-1: phpseclib vulnerability
It was discovered that phpseclib did not perform padding validation in
constant time when using AES in CBC mode. A remote attacker could possibly
use this issue to conduct a padding oracle timing attack and obtain
sensitive information.
USN-8768-1: Shibboleth vulnerability
Florian Stuhlmann discovered that Shibboleth incorrectly escaped input
when using the ODBC storage plugin. A remote attacker could possibly use
this issue to perform SQL injection attacks and obtain sensitive
information.
USN-8767-1: Snapcast vulnerability
It was discovered that Snapcast incorrectly handled crafted JSON-RPC
requests. A remote attacker could possibly use this issue to execute
arbitrary code or obtain sensitive information.
USN-8766-1: Suricata-Update vulnerability
Guillem Lefait discovered that Suricata-Update did not properly validate
destination paths when extracting files referenced by downloaded rule
archives. An attacker could possibly use this issue to write arbitrary
files outside the configured rules directory.
USN-8765-1: python-sql vulnerability
Cédric Krier discovered that python-sql incorrectly escaped values passed
to unary operators. An attacker could possibly use this issue to perform
SQL injection attacks.
USN-8762-1: polkit vulnerability
It was discovered that polkit incorrectly handled cookie input.
A local
attacker could possibly use this issue to cause polkit
to crash, resulting
in a denial of service, or execute arbitrary code.
USN-8764-1: SRT vulnerabilities
It was discovered that SRT did not authenticate certain encryption control
messages. A remote attacker could possibly use this issue to downgrade an
encrypted connection and inject arbitrary content or interrupt a media
stream. (CVE-2026-55868)
It was discovered that SRT did not properly validate certain control
packets during connection setup and key refresh operations. A remote
attacker could possibly use this issue to cause SRT to crash, resulting in
a denial of service. (CVE-2026-55869)
USN-8763-1: kitty vulnerabilities
It was discovered that kitty incorrectly escaped error messages when
handling specially crafted terminal escape sequences. A remote attacker
could possibly use this issue to execute arbitrary commands.
(CVE-2026-42850)
It was discovered that kitty incorrectly handled remote edit requests in
terminal output. An attacker could possibly use this issue to execute
arbitrary code with the user's privileges.
(CVE-2026-42851)
Thai Son Dinh and Nguyen Huy Vu Dung discovered that kitty incorrectly
handled destination paths in its file transmission protocol. A local
attacker could possibly use this issue to overwrite arbitrary files with
the user's privileges.
(CVE-2026-54055)
It was discovered that kitty incorrectly sanitized responses to color
queries. An attacker could possibly use this issue to execute arbitrary
commands with the user's privileges. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54057)
USN-8761-1: Linux kernel (Azure) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- PowerPC architecture;
- Compute Acceleration Framework;
- Drivers core;
- Bluetooth drivers;
- Arm Firmware Framework for ARMv8-A(FFA);
- EFI core;
- GPU drivers;
- Hardware monitoring drivers;
- InfiniBand drivers;
- Network drivers;
- SCSI subsystem;
- SPI subsystem;
- Network file systems library;
- NTFS3 file system;
- SMB network file system;
- File systems infrastructure;
- Software nodes and device properties;
- Bluetooth subsystem;
- Netfilter;
- Tracing infrastructure;
- io_uring subsystem;
- IRQ subsystem;
- KProbes tracing;
- Memory management;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- Phonet protocol;
- SMC sockets;
- TLS protocol;
- Unix domain sockets;
- VMware vSockets driver;
- Wireless networking;
- Key management;
- Linux Security Modules (LSM) Framework;
- ALSA framework;
- AudioScience HPI driver;
(CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486,
CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275,
CVE-2026-46315, CVE-2026-52912, CVE-2026-52915, CVE-2026-52916,
CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922,
CVE-2026-52926, CVE-2026-52941, CVE-2026-53357, CVE-2026-64015,
CVE-2026-64025, CVE-2026-64029, CVE-2026-64032, CVE-2026-64033,
CVE-2026-64039, CVE-2026-64046, CVE-2026-64047, CVE-2026-64048,
CVE-2026-64051, CVE-2026-64055, CVE-2026-64056, CVE-2026-64064,
CVE-2026-64073, CVE-2026-64083, CVE-2026-64084, CVE-2026-64085,
CVE-2026-64086, CVE-2026-64087, CVE-2026-64088, CVE-2026-64089,
CVE-2026-64092, CVE-2026-64096, CVE-2026-64097, CVE-2026-64098,
CVE-2026-64102, CVE-2026-64103, CVE-2026-64106, CVE-2026-64108,
CVE-2026-64109, CVE-2026-64111, CVE-2026-64113, CVE-2026-64114,
CVE-2026-64115, CVE-2026-64116, CVE-2026-64118, CVE-2026-64121,
CVE-2026-64125, CVE-2026-64126, CVE-2026-64127, CVE-2026-64128,
CVE-2026-64133, CVE-2026-64134, CVE-2026-64135, CVE-2026-64136,
CVE-2026-64137, CVE-2026-64138, CVE-2026-64144, CVE-2026-64147,
CVE-2026-64148, CVE-2026-64153, CVE-2026-64155, CVE-2026-64163,
CVE-2026-64165, CVE-2026-64166, CVE-2026-64168, CVE-2026-64170,
CVE-2026-64173, CVE-2026-64174, CVE-2026-64177, CVE-2026-64178,
CVE-2026-64179, CVE-2026-64180, CVE-2026-64182, CVE-2026-64183,
CVE-2026-64184, CVE-2026-64185, CVE-2026-64214, CVE-2026-64217,
CVE-2026-64218, CVE-2026-64219, CVE-2026-64220, CVE-2026-64221,
CVE-2026-64225, CVE-2026-64231, CVE-2026-64518)
USN-8730-2: Linux kernel (Azure) vulnerability
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
slurm-26.05.4-2.el10_3
FEDORA-EPEL-2026-08168503f3
Packages in this update:
- slurm-26.05.4-2.el10_3
Merge rawhide into epel10 to reconcile diverged history