Aggregator

strongswan-6.1.0-1.fc45

3 days ago
FEDORA-2026-5db1745c4f Packages in this update:
  • strongswan-6.1.0-1.fc45
Update description:
  • Update to 6.1.0 for CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134 and CVE-2026-78135

USN-8798-1: GStreamer Good Plugins vulnerabilities

3 days 1 hour ago
It was discovered that GStreamer Good Plugins incorrectly parsed certain MRF files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18295, CVE-2026-18296) It was discovered that GStreamer Good Plugins incorrectly parsed certain PNG files. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18298) DongHyeon Hwang discovered that GStreamer Good Plugins incorrectly handled certain RTP packets. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-18299)

USN-8794-1: GLib vulnerabilities

3 days 3 hours ago
It was discovered that GLib's GDBus authentication mechanism failed to enforce length limitations on data lines read from a client. An unauthenticated attacker could exploit this to cause a denial of service via resource exhaustion. (CVE-2026-15588) It was discovered that the xdgmime library in GLib had a heap-based buffer overflow. An attacker-controlled MIME magic file could cause an out-of-bounds write on little-endian systems. (CVE-2026-16118) It was discovered that GLib had an off-by-one error in the GVariant serialiser. An attacker could use this to cause an out-of-bounds read, leading to information disclosure or a denial of service. (CVE-2026-58010) It was discovered that GLib had an out-of-bounds read in GDateTime. An attacker could use this to corrupt date output and cause a denial of service. (CVE-2026-58011) It was discovered that GLib's g_regex_replace() function had a buffer over-read when used with the G_REGEX_RAW flag. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58012) It was discovered that GLib's GIOChannel had a buffer over-read when using a custom line terminator. An attacker could use this to cause information disclosure or a denial of service. (CVE-2026-58013) It was discovered that GLib's GKeyFile had an off-by-one error when loading a key file with an empty value. An attacker could use this to cause an out-of-bounds access or a denial of service. (CVE-2026-58014) It was discovered that GLib's DBUS_COOKIE_SHA1 authentication mechanism failed to validate the cookie_context parameter. A malicious D-Bus server could use this to read arbitrary files from the client. (CVE-2026-58015) It was discovered that GLib's D-Bus introspection XML parser had a state confusion issue. An attacker could use this to cause an out-of-bounds read and denial of service. (CVE-2026-58016)

USN-8796-1: OpenJDK 21 vulnerabilities

3 days 3 hours ago
Kai Aizen discovered that the Networking component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-61308) It was discovered that the JSSE component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-70907) It was discovered that the Security component of OpenJDK 21 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-60589)

USN-8795-1: OpenJDK 17 vulnerabilities

3 days 3 hours ago
Kai Aizen discovered that the Networking component of OpenJDK 17 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-61308) It was discovered that the JSSE component of OpenJDK 17 did not correctly handle user authentication. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-70907) It was discovered that the Security component of OpenJDK 17 did not correctly handle user authentication. A remote attacker could possibly use this issue to leak sensitive information. (CVE-2026-60589)

USN-8790-1: Expat vulnerabilities

3 days 5 hours ago
It was discovered that Expat could be made to allocate large amounts of memory when parsing a small crafted document. An attacker could possibly use this issue to cause Expat to consume resources, leading to a denial of service. This issue was only addressed in Ubuntu 24.04 LTS. (CVE-2025-59375) It was discovered that Expat incorrectly handled empty external parameter entity content. An attacker could possibly use this issue to cause Expat to crash, resulting in a denial of service. (CVE-2026-32776) It was discovered that Expat incorrectly handled certain DTD content. An attacker could possibly use this issue to cause Expat to enter an infinite loop, resulting in a denial of service. (CVE-2026-32777) It was discovered that Expat incorrectly handled memory when retrying after an earlier out-of-memory condition. An attacker could possibly use this issue to cause Expat to crash, resulting in a denial of service. (CVE-2026-32778) It was discovered that Expat performed attribute name collision checks inefficiently. An attacker could possibly use this issue to cause Expat to consume resources when processing a moderately sized crafted XML document, resulting in a denial of service. This issue was only addressed in Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-45186) It was discovered that Expat used insufficient entropy, allowing hash flooding through a crafted XML document. An attacker could possibly use this issue to cause Expat to consume resources, leading to a denial of service. This issue was only addressed in Ubuntu 14.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-41080) It was discovered that Expat did not track handler call depth for certain functions called from within handlers, leading to a use-after-free. An attacker could possibly use this issue to cause Expat to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-50219, CVE-2026-56412) It was discovered that Expat incorrectly handled certain values, leading to integer overflows. An attacker could possibly use this issue to cause Expat to crash, resulting in a denial of service. (CVE-2026-56403, CVE-2026-56404, CVE-2026-56405) It was discovered that Expat incorrectly handled certain values, leading to an integer overflow. An attacker could possibly use this issue to cause Expat to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-56408)

rootlesskit-3.2.0-1.fc43

3 days 5 hours ago
FEDORA-2026-f5733c1dd0 Packages in this update:
  • rootlesskit-3.2.0-1.fc43
Update description:
  • Update to release v3.2.0
  • Resolves: rhbz#2530874
  • Resolves CVE-2026-56855: rhbz#2530631
  • Resolves CVE-2026-78662: rhbz#2530678
  • Upstream enhancements and fixes

USN-8793-1: Linux kernel (Azure CVM) vulnerabilities

3 days 6 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Bluetooth drivers; - GPU drivers; - Hardware monitoring drivers; - SPI subsystem; - NTFS3 file system; - io_uring subsystem; - Ethernet bridge; - Multipath TCP; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315)