Aggregator

USN-8827-1: Erlang vulnerabilities

3 days 4 hours ago
It was discovered that the Erlang Port Mapper Daemon did not properly handle slow connections. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-42792) It was discovered that Erlang incorrectly handled certain external term format data, leading to heap corruption. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-55737) It was discovered that Erlang incorrectly handled invalid external term format data. An attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-54890) It was discovered that Erlang incorrectly handled certain packet lengths, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538) It was discovered that the Erlang Megaco flex scanner incorrectly handled certain input, leading to a buffer overflow. A remote attacker could possibly use this issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-59250) It was discovered that Erlang TLS clients incorrectly accepted cipher suites that they had not offered. A remote attacker could possibly use this issue to intercept and modify TLS communications. (CVE-2026-55953) It was discovered that Erlang incorrectly handled certain certificate chains. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-58227) It was discovered that Erlang incorrectly handled certain certificate policies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-59251) It was discovered that the Erlang HTTP server incorrectly handled certain conflicting HTTP framing headers. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812) It was discovered that the Erlang HTTP server incorrectly handled certain malformed chunk sizes. A remote attacker could possibly use this issue to cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664) It was discovered that the Erlang HTTP server did not properly limit the size of chunked request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-74835) It was discovered that the Erlang HTTP server incorrectly handled certain equivalent request paths and differences in character case. A remote attacker could possibly use this issue to bypass authentication and gain unauthorized access. (CVE-2026-66835, CVE-2026-73270) It was discovered that the Erlang HTTP server did not properly limit simultaneous connections. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-70399) It was discovered that the Erlang HTTP server incorrectly handled header continuation lines. A remote attacker could possibly use this issue to smuggle HTTP requests. (CVE-2026-66357) It was discovered that the Erlang HTTP server incorrectly handled certain malformed header names. A remote attacker could possibly use this issue to smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-73276) It was discovered that the Erlang HTTP server incorrectly handled incomplete request bodies. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-71380) It was discovered that the Erlang HTTP client did not properly limit the size of HTTP response headers. A malicious HTTP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-55951) It was discovered that Erlang did not properly limit the length of port numbers when parsing URIs. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696) It was discovered that the Erlang SNMP application did not properly limit the size of certain integer values. A remote attacker could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70405) It was discovered that the Erlang LDAP client did not properly limit the length of port numbers in referral URLs. A malicious LDAP server could possibly use this issue to cause Erlang to use excessive resources, leading to a denial of service. (CVE-2026-70409)

USN-8836-1: FreeRDP vulnerabilities

3 days 5 hours ago
It was discovered that FreeRDP contained multiple security issues. An attacker could possibly use these issues to obtain sensitive information, cause FreeRDP to crash, resulting in a denial of service, or execute arbitrary code.

USN-8834-1: Exim vulnerabilities

3 days 5 hours ago
It was discovered that Exim had an out-of-bounds write when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-94054) It was discovered that Exim had a use-after-free when certain non-default TLS settings were used with GnuTLS. A remote attacker could possibly use this issue to cause Exim to crash, resulting in a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-94055) It was discovered that Exim allowed attackers to read uninitialized data from stack memory when Proxy-Protocol was used with an attacker-controlled proxy. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-94056) It was discovered that Exim allowed SMTP smuggling via crafted data sent after a rejection during DATA processing. A remote attacker could possibly use this issue to inject arbitrary email messages. (CVE-2026-94057)

USN-8833-1: libvirt vulnerabilities

3 days 5 hours ago
It was discovered that libvirt did not properly validate newline characters in DNS TXT record values and SRV record attributes in its virtual network driver. A local attacker with permission to define virtual networks could possibly use this issue to inject arbitrary dnsmasq configuration directives, leading to arbitrary command execution as root. (CVE-2026-61477) It was discovered that libvirt did not properly handle errors during XML context parsing. An attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. (CVE-2026-61478) He Wei discovered that libvirt had a symlink-following vulnerability in the file ownership change function used for virtual TPM state directories. A local attacker running as the swtpm user could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-63622) It was discovered that libvirt created storage volume images with overly permissive permissions during clone or convert operations. A local attacker could possibly use this issue to read guest disk contents, resulting in information disclosure. (CVE-2026-63623) It was discovered that libvirt had an integer overflow in the NodeGetFreePages RPC handler. A local attacker could possibly use this issue to cause libvirt to crash or execute arbitrary code. (CVE-2026-18917) It was discovered that libvirt had a symlink-following flaw in the virtual TPM emulator setup function. A local attacker with access to the swtpm account could possibly use this issue to cause libvirt to change the ownership of an arbitrary file, leading to privilege escalation. (CVE-2026-77159)

USN-8831-1: libvirt vulnerabilities

3 days 5 hours ago
It was discovered that libvirt had an integer overflow vulnerability in the NodeGetFreePages RPC handler. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-18917) It was discovered that libvirt did not correctly handle symbolic links when changing ownership of the TPM emulator log file. A local attacker with access to the swtpm account could possibly use this issue to cause libvirt to change the ownership of an arbitrary file. (CVE-2026-77159)

chromium-154.0.8037.57-1.el10_2

3 days 10 hours ago
FEDORA-EPEL-2026-c4d340d432 Packages in this update:
  • chromium-154.0.8037.57-1.el10_2
Update description:

Update to 154.0.8037.57

CVE-2026-95274: Improper output encoding in DevTools CVE-2026-95275: Incorrect reference resolution in MediaStream CVE-2026-95276: Improper input validation in Themes CVE-2026-95277: Use after free in Views CVE-2026-95278: Missing authorization in WakeLock CVE-2026-95279: UI misrepresentation in Omnibox CVE-2026-95280: Race condition in V8 CVE-2026-95281: Buffer overflow in ANGLE CVE-2026-95282: Use after free in Platform CVE-2026-95283: Buffer overflow in Tint CVE-2026-95284: Buffer overflow in ANGLE CVE-2026-95285: Missing authorization in WebView CVE-2026-95286: Type confusion in Bindings CVE-2026-95287: Missing authorization in Navigation CVE-2026-95288: UI misrepresentation in Mobile CVE-2026-95289: Incorrect authorization in Scroll CVE-2026-95290: Missing authorization in NFC CVE-2026-95291: UI misrepresentation in SecurityIndicators CVE-2026-95292: Incorrect authorization in Safebrowsing CVE-2026-95293: Uninitialized resource in GPU CVE-2026-95294: UI misrepresentation in Browser CVE-2026-95295: Information leak in Mobile CVE-2026-95296: Missing authorization in Core CVE-2026-95297: Missing authorization in Contextual Tasks CVE-2026-95298: Use after free in Browser CVE-2026-95299: Use after free in GPU CVE-2026-95300: Missing authorization in DevTools CVE-2026-95301: Missing authorization in Extensions CVE-2026-95302: Incorrect authorization in WebAPKs CVE-2026-95303: Incomplete cleanup in SmartCard CVE-2026-95304: Out of bounds write in V8 CVE-2026-95305: UI misrepresentation in Chromoting CVE-2026-95306: Type confusion in V8 CVE-2026-95307: UI misrepresentation in ExtensionsMenu CVE-2026-95308: Integer overflow in Metrics CVE-2026-95309: UI misrepresentation in Mobile CVE-2026-95310: Use after free in AdFilter CVE-2026-95311: Free of non-heap memory in Fonts CVE-2026-95312: Information leak in Passwords CVE-2026-95313: Use after free in Fullscreen CVE-2026-95314: Incorrect authorization in HID CVE-2026-95315: Use after free in Aura CVE-2026-95316: Unchecked return value in Performance CVE-2026-95317: Incorrect authorization in MediaCapture CVE-2026-95318: Buffer overflow in Video CVE-2026-95319: Use after free in Printing CVE-2026-95320: Missing authorization in Navigation CVE-2026-95321: UI misrepresentation in Payments CVE-2026-95322: Out of bounds write in GPU CVE-2026-95323: UI misrepresentation in Chromium CVE-2026-95324: Uninitialized resource in GPU CVE-2026-95325: Use after free in ANGLE CVE-2026-95326: Incomplete cleanup in Bluetooth CVE-2026-95327: Information leak in Networking CVE-2026-95328: Confused deputy in Mobile CVE-2026-95329: Out of bounds write in WebGL CVE-2026-95330: Improper state validation in Downloads CVE-2026-95331: Out of bounds write in ANGLE CVE-2026-95332: Use of uninitialized variable in Tint CVE-2026-95333: Use after free in Metrics CVE-2026-95334: Incorrect reference resolution in WebProtect CVE-2026-95335: Use after free in HID CVE-2026-95336: Information leak in Transactions Platform CVE-2026-95337: UI misrepresentation in Messages CVE-2026-95338: Use after free in PDFium CVE-2026-95339: Use after free in ServiceWorker CVE-2026-95340: Incorrect authorization in PictureInPicture CVE-2026-95341: Improper input validation in Desktop CVE-2026-95342: Missing authorization in V8 CVE-2026-95343: Use after free in WebAudio CVE-2026-95344: Race condition in DevTools CVE-2026-95345: Use after free in Actor CVE-2026-95346: UI misrepresentation in Chromoting CVE-2026-95347: Use after free in Updater CVE-2026-95348: Use after free in Bluetooth CVE-2026-95349: Buffer overflow in WebGL CVE-2026-95350: Buffer overflow in ANGLE CVE-2026-95351: Use after free in Views CVE-2026-95352: Incorrect authorization in DevTools CVE-2026-95353: Use after free in Bindings CVE-2026-95354: Use after free in Verifier CVE-2026-95355: Incorrect authorization in Navigation CVE-2026-95356: Use after free in WindowDialog CVE-2026-95357: Out of bounds write in GPU CVE-2026-95358: Incorrect authorization in Mobile CVE-2026-95359: Uninitialized resource in GPU CVE-2026-95360: Race condition in Editing CVE-2026-95361: Confused deputy in DevTools CVE-2026-95362: Cross-site request forgery in DevTools CVE-2026-95363: UI misrepresentation in FileSystem CVE-2026-95364: Improper input validation in Passwords CVE-2026-95365: Type confusion in IndexedDB CVE-2026-95366: Use of released resource in Core CVE-2026-95367: Information leak in DataTransfer CVE-2026-95368: Incorrect authorization in DevTools CVE-2026-95369: Inappropriate implementation in XML CVE-2026-95370: Inappropriate implementation in NFC CVE-2026-95371: Missing authorization in Views CVE-2026-95372: Use after free in Chromecast CVE-2026-95373: Use after free in DevTools CVE-2026-95374: Incorrect authorization in Network CVE-2026-95375: Incorrect authorization in BrowserTag CVE-2026-95376: Externally controlled reference in DevTools CVE-2026-95380: Type confusion in V8 CVE-2026-95381: Improper input validation in Printing CVE-2026-95382: Improper input validation in Auth CVE-2026-95384: Race condition in Transactions Platform CVE-2026-95385: Inappropriate implementation in PlatformIntegration

python-engineio-4.12.3-2.el9 python-simple-websocket-1.0.0-8.el9

3 days 10 hours ago
FEDORA-EPEL-2026-e47857b934 Packages in this update:
  • python-engineio-4.12.3-2.el9
  • python-simple-websocket-1.0.0-8.el9
Update description:

Update python-engineio to 4.12.3, which is not the latest version but is the latest version that could be reasonably backported to EPEL9. This required branching a new package for python-simple-websocket 1.0.0 – again, not quite the latest version. Furthermore, this update includes a backport from versions 4.13.2 and 4.13.5 of the fixes for CVE-2026-48802 and CVE-2026-48809.

USN-8826-1: LXC vulnerabilities

3 days 11 hours ago
Maher Azzouzi discovered that LXC did not correctly handle logging certain failure messages. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2022-47952) Sam Sanoop discovered that LXC did not correctly handle certain forms of user authorization. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-39402)