Aggregator

USN-8897-1: lxml vulnerabilities

3 days 23 hours ago
Guillem Lefait discovered that lxml incorrectly handled certain URL attributes. A remote attacker could possibly use this issue to bypass URL sanitization, leading to a cross-site scripting attack. (CVE-2026-49825) Qiu Sihao discovered that lxml incorrectly handled untrusted XML input. A remote attacker could possibly use this issue to read local files and expose sensitive information. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41066)

USN-8895-1: Sudo vulnerability

4 days 2 hours ago
It was discovered that Sudo did not properly handle time-based access restrictions when sudoers rules used NOTBEFORE or NOTAFTER with timestamps omitting the trailing timezone indicator. A local attacker could possibly use this issue to execute commands outside the intended time window by manipulating the TZ environment variable.

xorg-x11-server-Xwayland-24.1.14-1.fc43

4 days 2 hours ago
FEDORA-2026-112c430ffc Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc43
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

USN-8894-1: poppler vulnerabilities

4 days 2 hours ago
It was discovered that Poppler had an integer overflow in FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102620) It was discovered that Poppler had an integer overflow in SplashClip::clipToPath. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-102621) It was discovered that Poppler had a null pointer dereference in JBIG2Stream. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service. (CVE-2026-93312) It was discovered that Poppler had an integer overflow in JBIG2Stream::readCodeTableSeg. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93313) It was discovered that Poppler had an integer overflow in FoFiTrueType::mapCodeToGID. An attacker could possibly use this issue to cause Poppler to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-93314)

xorg-x11-server-Xwayland-24.1.14-1.fc44

4 days 2 hours ago
FEDORA-2026-2448dda850 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc44
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

xorg-x11-server-Xwayland-24.1.14-1.fc45

4 days 3 hours ago
FEDORA-2026-2460ebb288 Packages in this update:
  • xorg-x11-server-Xwayland-24.1.14-1.fc45
Update description:

Update to xwayland 24.1.14 CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516 CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536