3 days 12 hours ago
FEDORA-2026-96efddc493
Packages in this update:
Update description:
- Rebased pcs to the newest major version (see CHANGELOG.md) - includes fix for CVE-2026-84828
- Updated standalone web UI and HA Cluster Management Cockpit application to pcs-web-ui 0.1.25 (see CHANGELOG_WUI.md)
- pcs no longer depends on rubygems ethon and ffi, rubygem curb is used instead
3 days 13 hours ago
FEDORA-2026-41f949afc4
Packages in this update:
Update description:
Update to 1.26.1 (rhbz#2535076)
Security fix list from upstream:
- Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
- Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
- Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
- Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
- Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
- Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.
3 days 13 hours ago
FEDORA-2026-996b326401
Packages in this update:
Update description:
Update to 1.26.1 (rhbz#2535076)
Security fix list from upstream:
- Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
- Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
- Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
- Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
- Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
- Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.
3 days 13 hours ago
It was discovered that GNU Guix incorrectly made build outputs accessible
to local users before their file metadata was finalized. A local attacker
could possibly use this issue to gain elevated privileges.
3 days 14 hours ago
FEDORA-2026-3baacede89
Packages in this update:
Update description:
Update to 1.26.1 (rhbz#2535076)
Security fix list from upstream:
- Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC canonicalization. Thanks to Vlatko Kosturjak with Marlink Cyber for the report.
- Fix CVE-2026-82717, CNAME synthesis could lead to heap corruption. Thanks to Ben Morris from Anthropic for the report.
- Fix CVE-2026-77955, Possible ZONEMD verification bypass window. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab, In addition, thanks to Qifan Zhang from Palo Alto Networks for also reporting this issue.
- Fix CVE-2026-78227, Use-after-free in DoQ stream output buffer on reset re-transmission. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-80225, Possible degradation of service from continuous queries on the same TCP/DoT connection. Thanks to Qifan Zhang from Palo Alto Networks for the report.
- Fix CVE-2026-82720, Use-after-free in DoH stream cleanup code path. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report.
- Fix CVE-2026-85501, Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC. Thanks to Zuyao Xu and Xiang Li from Nankai University, AOSP Lab for report. In addition, thanks to Qifan Zhang from Palo Alto Networks for a complimentary report.
- Fix CVE-2026-77860, 'serve-expired' can bypass Unbound 'wait-limit'. Thanks to Xuanchao Xie, Lutong Chen, and Kaiping Xue from the University of Science and Technology of China (USTC) for the report.
3 days 14 hours ago
FEDORA-2026-9e6e8df67a
Packages in this update:
- bluez-5.87+1.git789f6e154-2.fc43
Update description:
Rebase to latest upstream. Fixes CVE-2026-19774 (rhbz:2535010)
3 days 14 hours ago
FEDORA-2026-f1ad071fb6
Packages in this update:
- bluez-5.87+1.git789f6e154-2.fc44
Update description:
Rebase to latest upstream. Fixes CVE-2026-19774 (rhbz:2535010)
3 days 14 hours ago
FEDORA-2026-b181e6352d
Packages in this update:
- bluez-5.87+1.git789f6e154-2.fc45
Update description:
Rebase to latest upstream. Fixes CVE-2026-19774 (rhbz:2535010)
3 days 15 hours ago
It was discovered that AOM incorrectly handled the first-pass statistics
buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use
this issue to cause a heap buffer overflow, leading to a denial of service
or possibly execute arbitrary code. (CVE-2026-56208)
It was discovered that AOM incorrectly validated spatial and temporal
layer IDs in the SVC (Scalable Video Coding) encoder controls. An attacker
could possibly use this issue to write to an arbitrary memory address, read
out-of-bounds heap memory, or execute arbitrary code. (CVE-2026-56209,
CVE-2026-56210, CVE-2026-56211)
3 days 16 hours ago
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides
the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that OpenSSH incorrectly handled file permissions when
downloading files as root using the legacy scp protocol without the
preserve-mode option. An attacker could use this to install setuid or setgid
files on a system, possibly leading to privilege escalation.
3 days 18 hours ago
FEDORA-2026-16f1152378
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc44
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
3 days 18 hours ago
FEDORA-2026-4e6575b35f
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc43
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
3 days 18 hours ago
FEDORA-2026-26573b6029
Packages in this update:
- mingw-gdk-pixbuf-2.44.8-2.fc45
Update description:
Backport fixes for CVE-2026-16768 and CVE-2026-81893.
3 days 20 hours ago
Madelyn Olson discovered that Valkey incorrectly handled TLS connections
under certain conditions. A remote attacker could possibly use this issue to
cause Valkey to crash, resulting in a denial of service, or execute arbitrary
code. (CVE-2026-56684)
It was discovered that Valkey incorrectly handled certain stream RDB payloads
when executing the RESTORE command. An authenticated remote attacker could
possibly use this issue to cause Valkey to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-63639)
It was discovered that Valkey incorrectly handled cluster slot migration
operations. A remote attacker could possibly use this issue to cause Valkey
to crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 26.04 LTS. (CVE-2026-85522)
3 days 21 hours ago
3 days 21 hours ago
3 days 21 hours ago
3 days 21 hours ago
3 days 21 hours ago
4 days 4 hours ago
FEDORA-2026-68e2c40a81
Packages in this update:
Update description:
Update to pcre-10.48