4 days 6 hours ago
4 days 6 hours ago
4 days 6 hours ago
4 days 10 hours ago
USN-8369-1 fixed a vulnerability in mod_jk. It was discovered that for
Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for
CVE-2023-41081 was incorrectly dropped. This update reintroduces the fix
for CVE-2023-41081.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache Tomcat Connectors used incorrect default
permissions for shared memory on Unix-like systems. A local attacker could
possibly use this issue to view or modify mod_jk configuration data in
shared memory, resulting in sensitive information exposure or a denial of
service.
4 days 10 hours ago
FEDORA-2026-ff2a96c8de
Packages in this update:
- rabbitmq-server-4.2.9-1.fc44
Update description:
RabbitMQ ver. 4.2.9
4 days 11 hours ago
FEDORA-EPEL-2026-75bd5ec746
Packages in this update:
Update description:
Security update to pack 0.40.8
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions
Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package
Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls
4 days 11 hours ago
FEDORA-EPEL-2026-394b18b263
Packages in this update:
Update description:
Security update to pack 0.40.8
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions
Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package
Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls
4 days 11 hours ago
FEDORA-2026-e6e0368149
Packages in this update:
Update description:
Security update to pack 0.40.8
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions
Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package
Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls
4 days 11 hours ago
FEDORA-2026-8729dce4b8
Packages in this update:
Update description:
Security update to pack 0.40.8
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions
Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package
Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls
4 days 13 hours ago
FEDORA-2026-9b2e56edf5
Packages in this update:
Update description:
Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.26.5 which includes the fix.
4 days 13 hours ago
FEDORA-2026-4d9a2870e5
Packages in this update:
Update description:
Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.25.12 which includes the fix.
4 days 13 hours ago
FEDORA-2026-2b94d8d05c
Packages in this update:
Update description:
The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.
4 days 13 hours ago
FEDORA-2026-6503a6a639
Packages in this update:
Update description:
The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.
4 days 14 hours ago
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly limit the size of its
DNS cache. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service.
(CVE-2026-34513)
Mingi Jung discovered that AIOHTTP did not properly sanitize the
content_type parameter. An attacker could possibly use this issue to
inject malicious HTTP headers, resulting in HTTP response splitting.
(CVE-2026-34514)
It was discovered that AIOHTTP did not properly limit memory usage when
processing multipart headers. An attacker could possibly use this issue
to consume excessive system resources, resulting in a denial of service.
(CVE-2026-34516)
4 days 14 hours ago
FEDORA-2026-68853bb50c
Packages in this update:
- dokuwiki-20250514b-4.fc43
Update description:
Backport some security fixes
4 days 14 hours ago
FEDORA-2026-d37b1b981a
Packages in this update:
- dokuwiki-20250514b-6.fc44
Update description:
Backport some security fixes
4 days 15 hours ago
FEDORA-2026-9af234bcd6
Packages in this update:
Update description:
Fixes for CVE-2026-6067 and CVE-2026-6068.
4 days 17 hours ago
It was discovered that Exim incorrectly handled certain command line
options. A local attacker could possibly use this issue to access files
outside of the spool area.
It was discovered that Exim incorrectly handled string expansion in
.local files. A local attacker could possibly use this issue to escalate
privileges.
4 days 18 hours ago
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)
4 days 18 hours ago
It was discovered that Gawk incorrectly handled memory when processing
input using the getline redirection. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-40467)
It was discovered that Gawk incorrectly handled certain integer
calculations when allocating memory. An attacker could possibly use
this issue to cause a denial of service or overwrite heap memory with
attacker-controlled data. (CVE-2026-40468)
It was discovered that Gawk incorrectly handled certain integer
calculations when performing substitutions. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-40469)
It was discovered that Gawk incorrectly handled memory when reading
directory entries. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-40553)