Aggregator

stb-0^20260802.2c980bb-2.fc46

5 days 4 hours ago
FEDORA-2026-ee846faf9d Packages in this update:
  • stb-0^20260802.2c980bb-2.fc46
Update description:

Automatic update for stb-0^20260802.2c980bb-2.fc46.

Changelog * Thu Sep 10 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0^20260802.2c980bb-2 - Patch stb_sprintf: security fix for CVE-2026-79516 - Fixes RHBZ#2531291; Fixes RHBZ#2531290 * Thu Sep 10 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0^20260802.2c980bb-1 - Update to 0^20260802.2c980bb

libpcap-1.10.7-1.fc43

5 days 5 hours ago
FEDORA-2026-4401b94ad0 Packages in this update:
  • libpcap-1.10.7-1.fc43
Update description:

New version 10.7.1 Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912

libpcap-1.10.7-1.fc45

5 days 5 hours ago
FEDORA-2026-c3fb234b87 Packages in this update:
  • libpcap-1.10.7-1.fc45
Update description:

New version 10.7.1 Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912

USN-8741-1: Flatpak vulnerabilities

5 days 5 hours ago
It was discovered that Flatpak did not properly validate paths in sandbox-expose options. A malicious or compromised Flatpak app could use app-controlled symlinks to access arbitrary host files and gain code execution in the host context. This issue was addressed in Ubuntu Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078) It was discovered that Flatpak did not properly validate paths when removing outdated ld.so cache files. A malicious or compromised Flatpak app could use this issue to delete arbitrary files on the host. (CVE-2026-34079)

rubygems-4.0.20-1.fc44

5 days 6 hours ago
FEDORA-2026-2857104379 Packages in this update:
  • rubygems-4.0.20-1.fc44
Update description:

Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.

rubygems-4.0.20-1.fc45

5 days 6 hours ago
FEDORA-2026-9831a751e2 Packages in this update:
  • rubygems-4.0.20-1.fc45
Update description:

Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.

rubygems-4.0.20-1.fc46

5 days 6 hours ago
FEDORA-2026-c77b963cc9 Packages in this update:
  • rubygems-4.0.20-1.fc46
Update description:

Automatic update for rubygems-4.0.20-1.fc46.

Changelog * Thu Sep 3 2026 Mamoru TASAKA <mtasaka@fedoraproject.org> - 4.0.20-1 - Update to RubyGems 4.0.20 - Backport ruby upstream patch to update resolv to 0.7.2 - Resolves: CVE-2026-80212 (rhbz#2527309) - Resolves: CVE-2026-80213 (rhbz#2527311)

USN-8740-1: .NET vulnerabilities

5 days 7 hours ago
Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did not properly validate cross-origin WebSocket connections. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-58649) Rajesh Chada discovered that the .NET watch AspireServerService improperly exposed information through the use of certain arguments. An attacker could possibly use this issue to elevate privileges and execute arbitrary code. (CVE-2026-69806)

USN-8716-2: FFmpeg vulnerabilities

5 days 20 hours ago
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64832) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65705) It was discovered that FFmpeg incorrectly handled certain crafted NV12 video frames in the vf_swaprect video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65706) It was discovered that FFmpeg incorrectly handled certain crafted hvcC NAL arrays in the HEVC parser. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75141) It was discovered that FFmpeg incorrectly handled certain crafted MPEG system headers. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75142) It was discovered that FFmpeg incorrectly handled certain crafted network input in the librist protocol handler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75143) It was discovered that FFmpeg incorrectly handled certain crafted Dirac data units in the VC2 HQ RTP packetizer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75144) It was discovered that FFmpeg incorrectly handled certain crafted DASH manifests. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-75146)

python-django5-5.2.17-2.fc44

5 days 20 hours ago
FEDORA-2026-301e6e2983 Packages in this update:
  • python-django5-5.2.17-2.fc44
Update description:

Update python-django5 to the latest 5.x release (5.2.17)

  • Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
  • Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
  • Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
  • Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin

python-django5-5.2.17-2.fc43

5 days 20 hours ago
FEDORA-2026-6b28b4e483 Packages in this update:
  • python-django5-5.2.17-2.fc43
Update description:

Update python-django5 to the latest 5.x release (5.2.17)

  • Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
  • Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
  • Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
  • Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin

python-django5-5.2.17-2.fc45

5 days 20 hours ago
FEDORA-2026-950089270f Packages in this update:
  • python-django5-5.2.17-2.fc45
Update description:

Update python-django5 to the latest 5.x release (5.2.17)

  • Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
  • Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
  • Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
  • Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin