Aggregator

USN-8682-1: Bind vulnerabilities

4 days 6 hours ago
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zhang discovered that Bind incorrectly handled self-pointed glue records. A remote attacker could possibly use this issue to use Bind in denial of service amplification attacks against other systems. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-3592) It was discovered that Bind incorrectly handled DNS messages whose class was not IN. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5946)

GitPython-3.1.60-1.fc45

4 days 8 hours ago
FEDORA-2026-63e7132525 Packages in this update:
  • GitPython-3.1.60-1.fc45
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

bluez-5.87-6.fc43

4 days 8 hours ago
FEDORA-2026-d4eec45564 Packages in this update:
  • bluez-5.87-6.fc43
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc44

4 days 8 hours ago
FEDORA-2026-1fba3f22c9 Packages in this update:
  • bluez-5.87-6.fc44
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-7.fc45

4 days 8 hours ago
FEDORA-2026-84b4f1c43a Packages in this update:
  • bluez-5.87-7.fc45
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc43

4 days 10 hours ago
FEDORA-2026-432a1ef311 Packages in this update:
  • bluez-5.87-5.fc43
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc44

4 days 10 hours ago
FEDORA-2026-01488a5766 Packages in this update:
  • bluez-5.87-5.fc44
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc45

4 days 10 hours ago
FEDORA-2026-f4d10955d6 Packages in this update:
  • bluez-5.87-6.fc45
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bind-9.18.50-2.fc43

4 days 13 hours ago
FEDORA-2026-875d2a5154 Packages in this update:
  • bind-9.18.50-2.fc43
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-2.fc44

4 days 14 hours ago
FEDORA-2026-d87e7f498a Packages in this update:
  • bind-9.18.50-2.fc44
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-34.fc45

4 days 14 hours ago
FEDORA-2026-0adbf9c133 Packages in this update:
  • bind-9.18.50-34.fc45
Update description:

Fixes multiple CVEs, without a rebase to newer version

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

mrtg-2.17.10-15.fc45

4 days 15 hours ago
FEDORA-2026-c2dba9f29d Packages in this update:
  • mrtg-2.17.10-15.fc45
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-13.fc43

4 days 16 hours ago
FEDORA-2026-4522f50b2c Packages in this update:
  • mrtg-2.17.10-13.fc43
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-14.fc44

4 days 16 hours ago
FEDORA-2026-d05b77001f Packages in this update:
  • mrtg-2.17.10-14.fc44
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling