Aggregator

USN-8328-1: OpenJDK 21 vulnerabilities

4 days 16 hours ago
Thomas Beckers discovered that the JAXP component of OpenJDK 21 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to gain unauthorized access to sensitive information. (CVE-2026-22016) It was discovered that the Networking component of OpenJDK 21 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-34282) It was discovered that the JSSE component of OpenJDK 21 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22021) It was discovered that the JGSS component of OpenJDK 21 did not correctly authenticate certain APIs. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-22013) It was discovered that the 2D component of OpenJDK 21 did not correctly handle certain integer arithmetic. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to leak sensitive information. (CVE-2026-23865) It was discovered that the Libraries component of OpenJDK 21 did not correctly authenticate certain APIs. A remote unauthenticated attacker could possibly use this issue to cause a denial of service. (CVE-2026-22018) Ken Pyle discovered that the Security component of OpenJDK 21 did not correctly authenticate certain APIs. A local attacker could possibly use this issue to leak sensitive information. (CVE-2026-22007, CVE-2026-34268) In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://openjdk.org/groups/vulnerability/advisories/2026-04-21

strongswan-6.0.6-1.el9

4 days 22 hours ago
FEDORA-EPEL-2026-ea9af18b11 Packages in this update:
  • strongswan-6.0.6-1.el9
Update description:

Update to 6.0.6 to fix CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291

rust-sequoia-cert-store-0.7.3-1.fc43 rust-sequoia-chameleon-gnupg-0.13.1-13.fc43 rust-sequoia-octopus-librnp-1.11.1-7.fc43 rust-sequoia-sop-0.37.3-4.fc43 rust-sequoia-sq-1.3.1-12.fc43 rust-sequoia-wot-0.15.2-1.fc43

5 days ago
FEDORA-2026-ecfadb29a1 Packages in this update:
  • rust-sequoia-cert-store-0.7.3-1.fc43
  • rust-sequoia-chameleon-gnupg-0.13.1-13.fc43
  • rust-sequoia-octopus-librnp-1.11.1-7.fc43
  • rust-sequoia-sop-0.37.3-4.fc43
  • rust-sequoia-sq-1.3.1-12.fc43
  • rust-sequoia-wot-0.15.2-1.fc43
Update description:
  • Update the sequoia-wot crate to version 0.15.2.
  • Update the sequoia-keystore crate to version 0.7.3.

This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:

rust-sequoia-cert-store-0.7.3-1.fc44 rust-sequoia-chameleon-gnupg-0.13.1-13.fc44 rust-sequoia-octopus-librnp-1.11.1-7.fc44 rust-sequoia-sop-0.37.3-4.fc44 rust-sequoia-sq-1.3.1-12.fc44 rust-sequoia-wot-0.15.2-1.fc44

5 days ago
FEDORA-2026-5c5f4f40a4 Packages in this update:
  • rust-sequoia-cert-store-0.7.3-1.fc44
  • rust-sequoia-chameleon-gnupg-0.13.1-13.fc44
  • rust-sequoia-octopus-librnp-1.11.1-7.fc44
  • rust-sequoia-sop-0.37.3-4.fc44
  • rust-sequoia-sq-1.3.1-12.fc44
  • rust-sequoia-wot-0.15.2-1.fc44
Update description:
  • Update the sequoia-wot crate to version 0.15.2.
  • Update the sequoia-keystore crate to version 0.7.3.

This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:

strongswan-6.0.6-1.el10_3

5 days 2 hours ago
FEDORA-EPEL-2026-9b6d13e4b9 Packages in this update:
  • strongswan-6.0.6-1.el10_3
Update description:

Fixes CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291

USN-8326-1: Foomuuri vulnerabilities

5 days 5 hours ago
Matthias Gerstner discovered that Foomuuri's D-Bus service did not properly enforce authorization. An unprivileged local attacker could possibly use this issue to manipulate the firewall configuration, contrary to expectations. (CVE-2025-67603) Matthias Gerstner discovered that Foomuuri's D-Bus service did not properly validate interface names. A local attacker could possibly use this issue to manipulate the firewall configuration in unintended ways. (CVE-2025-67858)

kernel-7.0.10-201.fc44

5 days 6 hours ago
FEDORA-2026-bc20b091a8 Packages in this update:
  • kernel-7.0.10-201.fc44
Update description:

The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.

kernel-7.0.10-101.fc43

5 days 6 hours ago
FEDORA-2026-146d86eefc Packages in this update:
  • kernel-7.0.10-101.fc43
Update description:

The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.

USN-8325-1: tgt vulnerability

5 days 7 hours ago
It was discovered that tgt incorrectly tried to achieve entropy by calling rand without srand. An attacker could possibly use this issue to make tgt generate an identical sequence of challenges, resulting in authentication bypass.

USN-8324-1: Apache Tika vulnerabilities

5 days 8 hours ago
It was discovered that Apache Tika incorrectly handled XML external entities when parsing XFA content in PDF files. An attacker could possibly use this issue to obtain sensitive information or send malicious requests to internal resources or third-party servers.

USN-8323-1: Postorius vulnerability

5 days 9 hours ago
It was discovered that Postorius did not properly escape HTML in message subjects when rendering the Held messages pop-up. An attacker could possibly use this issue to inject arbitrary HTML, resulting in exposure of sensitive information.