Aggregator

chromium-150.0.7871.124-1.el10_3

5 days 6 hours ago
FEDORA-EPEL-2026-012b021e70 Packages in this update:
  • chromium-150.0.7871.124-1.el10_3
Update description:

Update to 150.0.7871.124

* CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation

chromium-150.0.7871.124-1.el10_2

5 days 6 hours ago
FEDORA-EPEL-2026-3bd3da0297 Packages in this update:
  • chromium-150.0.7871.124-1.el10_2
Update description:

Update to 150.0.7871.124

* CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation

chromium-150.0.7871.124-1.fc43

5 days 6 hours ago
FEDORA-2026-32e3e23696 Packages in this update:
  • chromium-150.0.7871.124-1.fc43
Update description:

Update to 150.0.7871.124

* CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation

chromium-150.0.7871.124-1.el9

5 days 6 hours ago
FEDORA-EPEL-2026-72397f334b Packages in this update:
  • chromium-150.0.7871.124-1.el9
Update description:

Update to 150.0.7871.124

* CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation

chromium-150.0.7871.124-1.fc44

5 days 6 hours ago
FEDORA-2026-7437330b17 Packages in this update:
  • chromium-150.0.7871.124-1.fc44
Update description:

Update to 150.0.7871.124

* CVE-2026-15764: Use after free in Ozone * CVE-2026-15765: Use after free in Ozone * CVE-2026-15766: Uninitialized Use in Skia * CVE-2026-15767: Heap buffer overflow in libyuv * CVE-2026-15768: Insufficient policy enforcement in HTML-in-Canvas * CVE-2026-15769: Insufficient validation of untrusted input in Linux Toolkit Theming * CVE-2026-15770: Uninitialized Use in V8 * CVE-2026-15771: Insufficient validation of untrusted input in Media * CVE-2026-15772: Use after free in GPU * CVE-2026-15773: Use after free in Core * CVE-2026-15774: Use after free in Skia * CVE-2026-15775: Insufficient policy enforcement in V8 * CVE-2026-15776: Type Confusion in V8 * CVE-2026-15777: Use after free in UI * CVE-2026-15778: Insufficient validation of untrusted input in Navigation

moby-engine-29.6.2-1.fc44

5 days 9 hours ago
FEDORA-2026-70a4eeeab8 Packages in this update:
  • moby-engine-29.6.2-1.fc44
Update description:
  • Update to release v29.6.2
  • Resolves: rhbz#2496437
  • Upstream security fixes
    • GHSA-hw3h-2gp9-cxpv
    • GHSA-qx3x-mv6r-52p6
    • GHSA-32pv-7hq5-qhwq
    • GHSA-g2h8-426c-7976
    • GHSA-388v-wmr2-g2v2

python-django5-5.2.16-1.fc43

5 days 15 hours ago
FEDORA-2026-fbb9501b22 Packages in this update:
  • python-django5-5.2.16-1.fc43
Update description:

Update python-django5 to version 5.2.16

Fixes three low-severity CVEs

  • CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response
  • CVE-2026-53877: Heap buffer over-read in GDALRaster
  • CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input

python-django5-5.2.16-1.fc44

5 days 15 hours ago
FEDORA-2026-595d35a4d1 Packages in this update:
  • python-django5-5.2.16-1.fc44
Update description:

Update python-django5 to version 5.2.16

Fixes three low-severity CVEs

  • CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response
  • CVE-2026-53877: Heap buffer over-read in GDALRaster
  • CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input

moby-engine-29.6.2-1.fc45

5 days 15 hours ago
FEDORA-2026-3a690a88c2 Packages in this update:
  • moby-engine-29.6.2-1.fc45
Update description:

Automatic update for moby-engine-29.6.2-1.fc45.

Changelog * Thu Jul 16 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 29.6.2-1 - Update to release v29.6.2 - Resolves: rhbz#2496437 - Upstream security fixes - - GHSA-hw3h-2gp9-cxpv - - GHSA-qx3x-mv6r-52p6 - - GHSA-32pv-7hq5-qhwq - - GHSA-g2h8-426c-7976 - - GHSA-388v-wmr2-g2v2 * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 29.6.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

dotnet10.0-10.0.110-1.fc44

5 days 16 hours ago
FEDORA-2026-f738966fc9 Packages in this update:
  • dotnet10.0-10.0.110-1.fc44
Update description:

Update to .NET SDK 10.0.110 and Runtime 10.0.10

Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108

Release Notes:

dotnet10.0-10.0.110-1.fc43

5 days 16 hours ago
FEDORA-2026-d9817786d6 Packages in this update:
  • dotnet10.0-10.0.110-1.fc43
Update description:

Update to .NET SDK 10.0.110 and Runtime 10.0.10

Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-50659,CVE-2026-56158,CVE-2026-57108

Release Notes:

USN-8477-2: tar regression

5 days 17 hours ago
USN-8477-1 fixed a vulnerability in tar. The update introduced a regression that could cause tar to fail to extract certain valid files. This update fixes the problem. Original advisory details: It was discovered that tar incorrectly handled certain crafted archive files. An attacker could possibly use this to inject hidden files with attacker-controlled content, bypassing pre-extraction inspection mechanisms.

USN-8557-1: Authlib vulnerabilities

5 days 19 hours ago
Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting in authentication and authorization bypass. (CVE-2026-27962) Jay Neiva and Mauro Carrillo discovered that Authlib incorrectly handled RSA1_5 encrypted tokens. An attacker could possibly use this issue to recover sensitive encrypted information, resulting in information disclosure. (CVE-2026-28490) Jay Neiva and Mauro Carrillo discovered that Authlib did not properly reject unsupported cryptographic algorithms when validating OpenID Connect ID tokens. An attacker could possibly use this issue to bypass token integrity checks, resulting in authentication bypass. (CVE-2026-28498) Johnny Deuss discovered that Authlib did not provide cross-site request forgery protection for the OAuth cache feature in its Starlette integration. An attacker could possibly use this issue to perform unauthorized OAuth actions, resulting in cross-site request forgery. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41425)

USN-8556-1: Ruby vulnerabilities

5 days 23 hours ago
It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject arbitrary IMAP commands via CRLF sequences. (CVE-2026-42258) It was discovered that the Zlib::GzipReader in Ruby did not correctly ensure sufficient buffer capacity in the zstream_buffer_ungets function. An attacker could use this to craft a gzip stream that, when processed, could cause a buffer overflow, resulting in memory corruption and possibly arbitrary code execution. (CVE-2026-27820)