Aggregator

USN-8859-1: ImageMagick vulnerabilities

4 days 19 hours ago
It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-56367) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-93586) It was discovered that ImageMagick did not correctly handle certain images. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93587, CVE-2026-93588) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-93589) It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-93590)

USN-8855-1: GStreamer Bad Plugins vulnerability

4 days 20 hours ago
It was discovered that GStreamer Bad Plugins incorrectly validated the size of multi-channel audio blocks. An attacker could possibly use this issue with a specially crafted WAV file to cause the program to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8845-1: GVfs vulnerabilities

4 days 20 hours ago
Keith Linneman discovered that GVfs did not properly validate data received from SFTP servers. An attacker could possibly use this issue to cause a heap buffer overflow, resulting in arbitrary code execution or a denial of service. (CVE-2026-84268) It was discovered that GVfs incorrectly handled file ownership when creating private D-Bus sockets in the admin backend. A local attacker could possibly use this issue to change the ownership of arbitrary system files, resulting in privilege escalation to root. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-88924)

perl-DBI-1.655-1.fc44

4 days 21 hours ago
FEDORA-2026-6d3a15e9c3 Packages in this update:
  • perl-DBI-1.655-1.fc44
Update description:

1.655 - Fix for C89; Ignore invalid handles consistently

1.654 bump

Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV) Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)

perl-DBI-1.655-1.fc43

4 days 21 hours ago
FEDORA-2026-272f19f521 Packages in this update:
  • perl-DBI-1.655-1.fc43
Update description:

1.655 - Fix for C89; Ignore invalid handles consistently

1.654 bump

Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV) Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)

perl-DBI-1.655-1.fc45

4 days 21 hours ago
FEDORA-2026-5fb5fb6508 Packages in this update:
  • perl-DBI-1.655-1.fc45
Update description:

1.655 - Fix for C89; Ignore invalid handles consistently

1.654 bump

Fix CVE-2026-88815 (DBI::sql_type_cast on IV/NV) Fix CVE-2026-88816 (FetchHashKeyName on IV/NV)

GitPython-3.2.0-1.fc43

4 days 22 hours ago
FEDORA-2026-c4dfd51df1 Packages in this update:
  • GitPython-3.2.0-1.fc43
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.

USN-8816-3: Linux kernel (Oracle) vulnerabilities

4 days 22 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - S390 architecture; - x86 architecture; - DRBD Distributed Replicated Block Device drivers; - InfiniBand drivers; - IOMMU subsystem; - Multiple devices driver; - Network drivers; - Microsoft Azure Network Adapter (MANA) driver; - NVME drivers; - TCM subsystem; - Virtio Host (VHOST) subsystem; - Xen hypervisor drivers; - AFS file system; - File systems infrastructure; - Network file systems library; - Network file system (NFS) client; - NTFS3 file system; - OCFS2 file system; - OrangeFS file system; - SMB network file system; - IPv4 networking; - Sun RPC protocol; - IPv6 networking; - IP tunnels definitions; - Netfilter; - TCP network protocol; - Locking primitives; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Networking core; - IFE protocol; - RxRPC session sockets; - Network traffic control; - SCTP protocol; - SMC sockets; - TIPC protocol; - XFRM subsystem; (CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, CVE-2026-64541, CVE-2026-64551, CVE-2026-68083, CVE-2026-68457, CVE-2026-68476, CVE-2026-68477, CVE-2026-72014, CVE-2026-72020, CVE-2026-72033, CVE-2026-72041, CVE-2026-72046, CVE-2026-72064, CVE-2026-72065, CVE-2026-72069, CVE-2026-72083, CVE-2026-72084, CVE-2026-72085, CVE-2026-72098, CVE-2026-72129, CVE-2026-72130, CVE-2026-72137, CVE-2026-72139, CVE-2026-72191, CVE-2026-72192, CVE-2026-72194, CVE-2026-72217, CVE-2026-72220, CVE-2026-72221, CVE-2026-72222, CVE-2026-72226, CVE-2026-72234, CVE-2026-72248, CVE-2026-72249, CVE-2026-72251, CVE-2026-72277, CVE-2026-72278, CVE-2026-72279, CVE-2026-72287, CVE-2026-72288, CVE-2026-72289, CVE-2026-72296, CVE-2026-72299, CVE-2026-72317, CVE-2026-72318, CVE-2026-72319, CVE-2026-72320, CVE-2026-72322, CVE-2026-72323, CVE-2026-72329, CVE-2026-72339, CVE-2026-72348, CVE-2026-72351, CVE-2026-72355, CVE-2026-72366, CVE-2026-72381, CVE-2026-72393, CVE-2026-72398, CVE-2026-72399, CVE-2026-72412, CVE-2026-72417, CVE-2026-72422, CVE-2026-72429, CVE-2026-72436, CVE-2026-72442, CVE-2026-72451, CVE-2026-72463, CVE-2026-72466, CVE-2026-72472, CVE-2026-72473, CVE-2026-72477, CVE-2026-72491, CVE-2026-72493, CVE-2026-72494, CVE-2026-72495, CVE-2026-72496, CVE-2026-72501, CVE-2026-74255, CVE-2026-74267, CVE-2026-74268, CVE-2026-74269, CVE-2026-74287, CVE-2026-74310, CVE-2026-74345, CVE-2026-74350, CVE-2026-74361, CVE-2026-74376, CVE-2026-74384, CVE-2026-74394, CVE-2026-74398, CVE-2026-74401, CVE-2026-74406, CVE-2026-74427, CVE-2026-74428, CVE-2026-74433, CVE-2026-74434, CVE-2026-74436, CVE-2026-74439, CVE-2026-80665)

USN-8817-3: Linux kernel (AWS) vulnerabilities

4 days 22 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - B.A.T.M.A.N. meshing protocol; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)

USN-8818-5: Linux kernel (NVIDIA Tegra) vulnerabilities

4 days 22 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - InfiniBand drivers; - Network drivers; - TCM subsystem; - exFAT file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - B.A.T.M.A.N. meshing protocol; - IPv4 networking; - IPv6 networking; - Netfilter; - RDS protocol; (CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)

GitPython-3.2.0-1.fc44

4 days 23 hours ago
FEDORA-2026-f2d13d09d7 Packages in this update:
  • GitPython-3.2.0-1.fc44
Update description:

Update to 3.2.0

Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239, GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.