Aggregator

wordpress-7.1.3-1.el10_4

2 days 16 hours ago
FEDORA-EPEL-2026-0d5bab9c2d Packages in this update:
  • wordpress-7.1.3-1.el10_4
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.el10_3

2 days 16 hours ago
FEDORA-EPEL-2026-98aa985c34 Packages in this update:
  • wordpress-7.1.3-1.el10_3
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

xorg-x11-server-21.1.25-1.fc44

2 days 16 hours ago
FEDORA-2026-013922e1cc Packages in this update:
  • xorg-x11-server-21.1.25-1.fc44
Update description:

Update to xserver 21.1.24, Security fixes for CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

socat-1.8.1.3-1.fc46

2 days 17 hours ago
FEDORA-2026-3bb7b0bc5a Packages in this update:
  • socat-1.8.1.3-1.fc46
Update description:

Automatic update for socat-1.8.1.3-1.fc46.

Changelog * Tue Oct 6 2026 Martin Osvald <mosvald@redhat.com> - 1.8.1.3-1 - Update to 1.8.1.3 (rhbz#2492929) - Fix for CVE-2026-56123 (rhbz#2535043)

xorg-x11-server-21.1.25-1.fc45

2 days 18 hours ago
FEDORA-2026-11378d4ce0 Packages in this update:
  • xorg-x11-server-21.1.25-1.fc45
Update description:

Update to xserver 21.1.24, Security fixes for CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

sudo-1.9.17-17.p2.fc46

2 days 18 hours ago
FEDORA-2026-da6797fbc8 Packages in this update:
  • sudo-1.9.17-17.p2.fc46
Update description:

Automatic update for sudo-1.9.17-17.p2.fc46.

Changelog * Tue Oct 6 2026 Alejandro López <allopez@redhat.com> - 1.9.17-17.p2 - Fix CVE-2026-96512 - Resolves: rhbz#2539401

USN-8892-1: Ubuntu Pro for WSL vulnerability

3 days 5 hours ago
Darshan U discovered that Ubuntu Pro for WSL exposed the attach token in command-line arguments when enabling a subscription on a WSL instance. An attacker could possibly use this issue to obtain sensitive information and gain unauthorized access to Ubuntu Pro repositories.

7zip-26.04-1.el9

3 days 5 hours ago
FEDORA-EPEL-2026-29947f7caa Packages in this update:
  • 7zip-26.04-1.el9
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_3

3 days 5 hours ago
FEDORA-EPEL-2026-e527d77d36 Packages in this update:
  • 7zip-26.04-1.el10_3
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_4

3 days 5 hours ago
FEDORA-EPEL-2026-7b07dd12c9 Packages in this update:
  • 7zip-26.04-1.el10_4
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

USN-8891-1: librsvg vulnerability

3 days 8 hours ago
It was discovered that librsvg incorrectly handled duplicate XML entity declarations while processing SVG documents containing nested XML inclusions. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.

USN-8890-1: libsoup vulnerabilities

3 days 9 hours ago
It was discovered that libsoup incorrectly handled certain HTTP/2 requests. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-4271) It was discovered that libsoup incorrectly handled certain HTTPS proxy connections. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-5119) It was discovered that libsoup incorrectly parsed certain chunked HTTP requests. A remote attacker could possibly use this issue to bypass security controls. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-6324) It was discovered that libsoup incorrectly handled proxy authentication credentials. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-66339) It was discovered that libsoup incorrectly handled certain HTTP Range headers. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-77014, CVE-2026-77680) It was discovered that libsoup incorrectly handled certain HTTP/2 connections. A remote attacker could possibly use this issue to obtain sensitive information or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-85197) It was discovered that libsoup incorrectly handled certain HTTP/2 transfers. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-85534)