Aggregator

exim-4.99.5-1.fc44

5 days 18 hours ago
FEDORA-2026-94678c4b6e Packages in this update:
  • exim-4.99.5-1.fc44
Update description:

This is new version fixing command execution with alternate privilege.

libwignernj-0.7.0-6.fc45

5 days 19 hours ago
FEDORA-2026-8d270f3d39 Packages in this update:
  • libwignernj-0.7.0-6.fc45
Update description:

Automatic update for libwignernj-0.7.0-6.fc45.

Changelog * Thu Jul 23 2026 Susi Lehtola <jussilehtola@fedoraproject.org> - 0.7.0-6 - Fix gating on BR: libquadmath-devel. * Thu Jul 23 2026 Susi Lehtola <jussilehtola@fedoraproject.org> - 0.7.0-5 - Install the Fortran modules into %{_fmoddir} via CMake instead of moving them after the fact, fixing the non-existent include directory in the exported wignernj::wignernj_f03 target and in libwignernj_f03.pc. * Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 0.7.0-4 - Rebuilt for Python 3.15.0b4 ABI change

Automatic update for libwignernj-0.7.0-5.fc45.

chromium-150.0.7871.181-1.el10_3

5 days 19 hours ago
FEDORA-EPEL-2026-6d0ad13c41 Packages in this update:
  • chromium-150.0.7871.181-1.el10_3
Update description:

Update to 150.0.7871.181

* CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU

chromium-150.0.7871.181-1.fc44

5 days 19 hours ago
FEDORA-2026-4870f59184 Packages in this update:
  • chromium-150.0.7871.181-1.fc44
Update description:

Update to 150.0.7871.181

* CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU

chromium-150.0.7871.181-1.el10_2

5 days 19 hours ago
FEDORA-EPEL-2026-ba84dedb81 Packages in this update:
  • chromium-150.0.7871.181-1.el10_2
Update description:

Update to 150.0.7871.181

* CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU

chromium-150.0.7871.181-1.el9

5 days 19 hours ago
FEDORA-EPEL-2026-29920b487b Packages in this update:
  • chromium-150.0.7871.181-1.el9
Update description:

Update to 150.0.7871.181

* CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU

chromium-150.0.7871.181-1.fc43

5 days 19 hours ago
FEDORA-2026-acf674bc6a Packages in this update:
  • chromium-150.0.7871.181-1.fc43
Update description:

Update to 150.0.7871.181

* CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU

USN-8601-1: PAM vulnerability

5 days 20 hours ago
It was discovered that PAM had a timing discrepancy in the pam_userdb module when comparing plaintext passwords. An attacker could possibly use this issue to obtain sensitive information by measuring response-timing differences during repeated authentication attempts.

USN-8600-1: libXpm vulnerability

5 days 20 hours ago
Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.

postgresql16-16.14-1.fc45

5 days 20 hours ago
FEDORA-2026-5b2e6bf881 Packages in this update:
  • postgresql16-16.14-1.fc45
Update description:

Automatic update for postgresql16-16.14-1.fc45.

Changelog * Thu Jul 23 2026 Petr Khartskhaev <pkhartsk@redhat.com> - 16.14-1 - Update to version 16.14 - Resolves: rhbz#2477451 - Resolves: rhbz#2499964 - Resolves: rhbz#2499726 - Resolves: rhbz#2499705 - Resolves: rhbz#2489304 - Resolves: rhbz#2487460 - Resolves: rhbz#2484513 - Resolves: rhbz#2484512 - Resolves: rhbz#2484431 - Resolves: rhbz#2482515 - Resolves: rhbz#2499705 * Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 16.13-7 - Rebuilt for Python 3.15.0b4 ABI change

USN-8598-1: rsyslog vulnerabilities

5 days 21 hours ago
It was discovered that rsyslog incorrectly handled regex-based TCP framing in the imptcp module. A remote attacker could possibly use this issue to cause rsyslog to crash, resulting in a denial of service. It was discovered that rsyslog incorrectly handled oversized RFC5424 structured data in the mmpstrucdata module. A remote attacker could possibly use this issue to cause rsyslog to crash, resulting in a denial of service. (CVE-2026-61548)

GitPython-3.1.55-1.el9

5 days 21 hours ago
FEDORA-EPEL-2026-7c0d601022 Packages in this update:
  • GitPython-3.1.55-1.el9
Update description:

Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2, GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-94p4-4cq8-9g67.

GitPython-3.1.55-1.el10_2

5 days 21 hours ago
FEDORA-EPEL-2026-b0e9a07c5d Packages in this update:
  • GitPython-3.1.55-1.el10_2
Update description:

Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2, GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-94p4-4cq8-9g67.

GitPython-3.1.55-1.el10_3

5 days 22 hours ago
FEDORA-EPEL-2026-9998a1b64b Packages in this update:
  • GitPython-3.1.55-1.el10_3
Update description:

Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2, GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-94p4-4cq8-9g67.

postgresql16-16.14-1.fc44

5 days 23 hours ago
FEDORA-2026-f8ee1fd482 Packages in this update:
  • postgresql16-16.14-1.fc44
Update description:

Automatic update for postgresql16-16.14-1.fc44.

Changelog for postgresql16 * Thu May 14 2026 Packit <hello@packit.dev> - 16.14-1 - Update to version 16.14 - Resolves: rhbz#2477451

USN-8322-2: Apache Commons BeanUtils regression

6 days ago
USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was discovered that for Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was incorrectly dropped. This update reintroduces the fix for CVE-2014-0114 and CVE-2019-10086. We apologize for the inconvenience. Original advisory details: It was discovered that Apache Commons BeanUtils incorrectly allowed access to the declaredClass property of Java enum objects when handling externally supplied property paths. An attacker could possibly use this issue to execute arbitrary code.