Aggregator

USN-8656-1: Linux kernel (HWE) vulnerabilities

5 days 11 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - Open vSwitch; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247, CVE-2026-53359, CVE-2026-64531)

USN-8543-2: Wget regression

5 days 12 hours ago
USN-8543-1 fixed vulnerabilities in Wget. The update for CVE-2026-58472 was incomplete and could introduce a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that Wget mishandled semicolons in the userinfo subcomponent of a URL. A remote attacker could possibly use this issue to trick a user into connecting to a different host than intended. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38428) It was discovered that Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58469) It was discovered that Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. (CVE-2026-58470) It was discovered that Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58471) It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58472)

rust-anstyle-hyperlink-1.0.2-1.fc43 rust-anstyle-progress-0.1.4-1.fc43 rust-cargo-0.98.0-1.fc43 rust-cargo-c-0.10.24-2.fc43 rust-cargo-credential-libsecret-0.5.8-1.fc43 rust-cargo-util-0.2.30-1.fc43 rust-cargo-util-schemas-0.14.1-1.fc43 rust-cargo-util…

5 days 15 hours ago
FEDORA-2026-ce685f40fe Packages in this update:
  • rust-anstyle-hyperlink-1.0.2-1.fc43
  • rust-anstyle-progress-0.1.4-1.fc43
  • rust-cargo-0.98.0-1.fc43
  • rust-cargo-c-0.10.24-2.fc43
  • rust-cargo-credential-libsecret-0.5.8-1.fc43
  • rust-cargo-util-0.2.30-1.fc43
  • rust-cargo-util-schemas-0.14.1-1.fc43
  • rust-cargo-util-terminal-0.1.0-1.fc43
  • rust-crates-io-0.41.0-1.fc43
  • rust-rustfix-0.9.7-1.fc43
Update description:
  • Update cargo-c to version 0.10.24 (plus dependency updates).
  • Initial packaging of the anstyle-hyperlink, anstyle-progress, and cargo-util-terminal crates.

yt-dlp-2026.08.19-1.fc45

5 days 17 hours ago
FEDORA-2026-c0410a0829 Packages in this update:
  • yt-dlp-2026.08.19-1.fc45
Update description:

Automatic update for yt-dlp-2026.08.19-1.fc45.

Changelog * Thu Aug 20 2026 Mikel Olasagasti Uranga <mikel@olasagasti.info> - 2026.08.19-1 - Update to 2026.08.19 - Closes rhbz#2497100 rhbz#2505367 rhbz#2491888 rhbz#2491889 rhbz#2491890 rhbz#2499189 * Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2026.06.09-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

yt-dlp-2026.08.19-1.fc46

5 days 17 hours ago
FEDORA-2026-139d3aad5f Packages in this update:
  • yt-dlp-2026.08.19-1.fc46
Update description:

Automatic update for yt-dlp-2026.08.19-1.fc46.

Changelog * Thu Aug 20 2026 Mikel Olasagasti Uranga <mikel@olasagasti.info> - 2026.08.19-1 - Update to 2026.08.19 - Closes rhbz#2497100 rhbz#2505367 rhbz#2491888 rhbz#2491889 rhbz#2491890 rhbz#2499189 * Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2026.06.09-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

USN-8654-1: Netty vulnerabilities

5 days 18 hours ago
It was discovered that Netty did not properly handle malformed HTTP/2 control frames. An attacker could use this to cause a denial of service via resource exhaustion. This issue only affects Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-55163) It was discovered that Netty did not properly validate the request URI for line-break characters. An attacker could use this to perform CRLF injection and request smuggling. (CVE-2025-67735)

kernel-7.1.9-200.fc44

5 days 19 hours ago
FEDORA-2026-e57251bf72 Packages in this update:
  • kernel-7.1.9-200.fc44
Update description:

The 7.1.9 stable kernel update contains a number of important updates across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.9-100.fc43

5 days 19 hours ago
FEDORA-2026-1eb1157853 Packages in this update:
  • kernel-7.1.9-100.fc43
Update description:

The 7.1.9 stable kernel update contains a number of important updates across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

libkcapi-1.5.1-2.fc46

5 days 19 hours ago
FEDORA-2026-e3ee465ab3 Packages in this update:
  • libkcapi-1.5.1-2.fc46
Update description:

Automatic update for libkcapi-1.5.1-2.fc46.

Changelog * Thu Aug 20 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-2 - Apply pending upstream patch to fix the auxiliary test * Tue Aug 18 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-1 - Update to version 1.5.1 (fedora#2512793) - Fix CVE-2026-71225 (fedora#2511445) - Fix CVE-2026-71226 (fedora#2511484) - Fix CVE-2026-71227 (fedora#2511487)

Automatic update for libkcapi-1.5.1-1.fc46.

libkcapi-1.5.1-2.fc45

5 days 19 hours ago
FEDORA-2026-1a1eac3dfb Packages in this update:
  • libkcapi-1.5.1-2.fc45
Update description:

Automatic update for libkcapi-1.5.1-2.fc45.

Changelog * Thu Aug 20 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-2 - Apply pending upstream patch to fix the auxiliary test * Tue Aug 18 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-1 - Update to version 1.5.1 (fedora#2512793) - Fix CVE-2026-71225 (fedora#2511445) - Fix CVE-2026-71226 (fedora#2511484) - Fix CVE-2026-71227 (fedora#2511487)

Automatic update for libkcapi-1.5.1-1.fc45.

rust-anstyle-hyperlink-1.0.2-1.el10_3 rust-anstyle-progress-0.1.4-1.el10_3 rust-cargo-0.98.0-1.el10_3 rust-cargo-c-0.10.24-1.el10_3 rust-cargo-credential-libsecret-0.5.8-1.el10_3 rust-cargo-util-0.2.30-1.el10_3 rust-cargo-util-schemas-0.14.1-1.el10_3…

5 days 19 hours ago
FEDORA-EPEL-2026-ae89cbbac2 Packages in this update:
  • rust-anstyle-hyperlink-1.0.2-1.el10_3
  • rust-anstyle-progress-0.1.4-1.el10_3
  • rust-cargo-0.98.0-1.el10_3
  • rust-cargo-c-0.10.24-1.el10_3
  • rust-cargo-credential-libsecret-0.5.8-1.el10_3
  • rust-cargo-util-0.2.30-1.el10_3
  • rust-cargo-util-schemas-0.14.1-1.el10_3
  • rust-cargo-util-terminal-0.1.0-1.el10_3
  • rust-crates-io-0.41.0-1.el10_3
  • rust-rustfix-0.9.7-1.el10_3
Update description:
  • Update cargo-c to version 0.10.24 (plus dependency updates).
  • Initial packaging of the anstyle-hyperlink, anstyle-progress, and cargo-util-terminal crates.