Aggregator
DSA-6325-1 chromium - security update
DSA-6326-1 nginx - security update
python-django4.2-4.2.30-2.el9
- python-django4.2-4.2.30-2.el9
- Backport fix for CVE-2026-35192 (low): Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST
- Django 4.2.30 fixes one security issue with severity “moderate” and four security issues with severity “low” in 4.2.29
- CVE-2026-33033: Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload [moderate]
- CVE-2026-3902: ASGI header spoofing via underscore/hyphen conflation
- CVE-2026-4277: Privilege abuse in GenericInlineModelAdmin
- CVE-2026-4292: Privilege abuse in ModelAdmin.list_editable
- CVE-2026-33034: Potential denial-of-service vulnerability in ASGI requests via memory upload limit bypass
- Django 4.2.29 fixes a security issue with severity “moderate” and a security issue with severity “low” in 4.2.28
- CVE-2026-25673: Potential denial-of-service vulnerability in URLField via Unicode normalization on Windows [moderate]
- CVE-2026-25674: Potential incorrect permissions on newly created file system objects
chromium-149.0.7827.53-1.el10_2
- chromium-149.0.7827.53-1.el10_2
Update to 149.0.7827.53
- fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)
chromium-149.0.7827.53-1.fc43
- chromium-149.0.7827.53-1.fc43
Update to 149.0.7827.53
- fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)
chromium-149.0.7827.53-1.el10_3
- chromium-149.0.7827.53-1.el10_3
Update to 149.0.7827.53
- fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)
chromium-149.0.7827.53-1.el9
- chromium-149.0.7827.53-1.el9
Update to 149.0.7827.53
- fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)
chromium-149.0.7827.53-1.fc44
- chromium-149.0.7827.53-1.fc44
Update to 149.0.7827.53
- fix 429 CVEs ( CVE-2026-10881 through CVE-2026-11309)
transmission-flatpak-4.1.2-2
- transmission-flatpak-4.1.2-2
4.1.2
DSA-6323-1 apache2 - security update
DSA-6324-1 request-tracker5 - security update
dnsdist-2.0.6-1.el10_2
- dnsdist-2.0.6-1.el10_2
Bug Fixes:
CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default
CVE-2026-33257: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default
CVE-2026-33260: An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The web server is disabled and restricted by an ACL by default
CVE-2026-33593: A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query
CVE-2026-33595: A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection. DOQ and DoH3 are disabled by default
CVE-2026-33596: A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend
CVE-2026-33597: A crafted query containing an invalid DNS label can prevent the PRSD detection algorithm executed via DynBlockRulesGroup:setSuffixMatchRule or DynBlockRulesGroup:setSuffixMatchRuleFFI from being executed
CVE-2026-33598: A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache
CVE-2026-33599: A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default
CVE-2026-33602: A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service
CVE-2026-33594: A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection. Outgoing DoH is disabled by default
python-django5-5.2.15-1.fc44
- python-django5-5.2.15-1.fc44
Fixes five low-severity CVEs
- CVE-2026-6873: Signed cookie salt namespace collision
- CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend
- CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives
- CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization
- CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header
python-django5-5.2.15-1.fc43
- python-django5-5.2.15-1.fc43
Fixes five low-severity CVEs
- CVE-2026-6873: Signed cookie salt namespace collision
- CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend
- CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-Control directives
- CVE-2026-35193: Potential exposure of private data via missing Vary: Authorization
- CVE-2026-48587: Potential exposure of private data via whitespace padding in Vary header
bind9-next-9.21.22-2.fc43
- bind9-next-9.21.22-2.fc43
- Limit resolver server list size. (CVE-2026-3592)
- Fix GSS-API resource leak. (CVE-2026-3039)
- Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
- Avoid unbounded recursion loop. (CVE-2026-5950)
- Fix crash in resolver when SIG(0)-signed responses are received under load. (CVE-2026-5947)
- Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. (CVE-2026-3593)
- Fix outgoing zone transfers' quota issue.
- Fix CPU spikes and slow queries when cache approaches memory limit.
- Implement RFC 3645 Section 4.1.1 key expiry check in TKEY.
- Reduce memory footprint by actively returning unused memory to the OS.
multiple bugfixes.
Source: https://downloads.isc.org/isc/bind9/9.21.22/doc/arm/html/notes.html#notes-for-bind-9-21-22
next-20260605: linux-next
nasm-3.01-3.fc44
- nasm-3.01-3.fc44
Fix for CVE-2026-6067 .
bind9-next-9.21.22-2.fc44
- bind9-next-9.21.22-2.fc44
- Limit resolver server list size. (CVE-2026-3592)
- Fix GSS-API resource leak. (CVE-2026-3039)
- Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
- Avoid unbounded recursion loop. (CVE-2026-5950)
- Fix crash in resolver when SIG(0)-signed responses are received under load. (CVE-2026-5947)
- Fix use-after-free error in DNS-over-HTTPS when processing HTTP/2 SETTINGS frames. (CVE-2026-3593)
- Fix outgoing zone transfers' quota issue.
- Fix CPU spikes and slow queries when cache approaches memory limit.
- Implement RFC 3645 Section 4.1.1 key expiry check in TKEY.
- Reduce memory footprint by actively returning unused memory to the OS.
multiple bugfixes.
Source: https://downloads.isc.org/isc/bind9/9.21.22/doc/arm/html/notes.html#notes-for-bind-9-21-22
python-python-multipart-0.0.32-1.el10_2
- python-python-multipart-0.0.32-1.el10_2
- Speed up partial-boundary scanning for CR/LF-dense part data.
- Speed up multipart header parsing and callback dispatch.
- Bound header field name size before validating.
- Validate Content-Length is non-negative in parse_form.
Fixes security issues GHSA-v9pg-7xvm-68hf, GHSA-5rvq-cxj2-64vf, GHSA-6jv3-5f52-599m, and GHSA-vffw-93wf-4j4q.
0.0.30 (2026-05-31)- Parse application/x-www-form-urlencoded bodies per the WHATWG URL standard, treating only & as a field separator.
- Ignore RFC 2231/5987 extended parameters (name*, filename*) in parse_options_header, keeping the plain parameter authoritative per RFC 7578 §4.2.