Aggregator

squidclamav-7.5-1.el9

4 days 19 hours ago
FEDORA-EPEL-2026-1bc4040b98 Packages in this update:
  • squidclamav-7.5-1.el9
Update description:

Upgrade to new upstream version CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability

squidclamav-7.5-1.el8

4 days 19 hours ago
FEDORA-EPEL-2026-31efc13ba7 Packages in this update:
  • squidclamav-7.5-1.el8
Update description:

Upgrade to new upstream version CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability

USN-8666-3: Linux kernel (GCP FIPS) vulnerabilities

5 days 2 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - NVME drivers; - File systems infrastructure; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; - TIPC protocol; (CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986, CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)

USN-8644-3: Linux kernel (Azure) vulnerabilities

5 days 2 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - File systems infrastructure; - OCFS2 file system; - B.A.T.M.A.N. meshing protocol; - SCTP protocol; - TIPC protocol; (CVE-2026-43071, CVE-2026-52914, CVE-2026-52993, CVE-2026-53043, CVE-2026-53224, CVE-2026-53246, CVE-2026-53309)

USN-8661-3: Linux kernel vulnerabilities

5 days 3 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - IPv6 networking; - Multipath TCP; - Netfilter; - Open vSwitch; - SCTP protocol; - SMC sockets; (CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53359, CVE-2026-64531)

USN-8643-5: Linux kernel vulnerabilities

5 days 3 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - Open vSwitch; - SCTP protocol; (CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)

kernel-7.2.1-300.fc45

5 days 3 hours ago
FEDORA-2026-b02404c8c0 Packages in this update:
  • kernel-7.2.1-300.fc45
Update description:

The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.11-200.fc44

5 days 3 hours ago
FEDORA-2026-fd4ffe7527 Packages in this update:
  • kernel-7.1.11-200.fc44
Update description:

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.11-100.fc43

5 days 3 hours ago
FEDORA-2026-25d7c1eb61 Packages in this update:
  • kernel-7.1.11-100.fc43
Update description:

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

USN-8688-1: PAM vulnerability

5 days 4 hours ago
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed login attempt records when certain services invoked the account phase without first performing authentication. An attacker could possibly use this issue to reset failed login counters, resulting in authentication lockout restrictions being bypassed.

curl-8.15.0-9.fc43

5 days 8 hours ago
FEDORA-2026-f903f9ff11 Packages in this update:
  • curl-8.15.0-9.fc43
Update description:
  • fix proto-default skips SSH verification (CVE-2026-12064)
  • fix wrong STARTTLS connection reuse (CVE-2026-8286)
  • fix SASL double-free (CVE-2026-8925)
  • fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
  • fix exposing HTTP/3 early data (CVE-2026-9545)
  • fix UAF after pause in socket callback (CVE-2026-9080)

USN-8687-1: p11-kit vulnerabilities

5 days 9 hours ago
It was discovered that p11-kit incorrectly handled certain RPC messages. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-13757) It was discovered that p11-kit incorrectly handled nested attribute decoding on 32-bit systems. A local attacker could use this issue to cause p11-kit to crash, resulting in a denial of service. (CVE-2026-18938)

USN-8686-1: openCryptoki vulnerabilities

5 days 9 hours ago
It was discovered that primitive decoders in openCryptoki produced integer underflows when the encoded length was zero. An attacker could possibly use this issue to trigger out-of-bounds reads. (CVE-2026-40253) It was discovered that openCryptoki incorrectly handled symlinks. An attacker in the token-group could possibly use this issue to achieve privilege escalation or access sensitive information. (CVE-2026-23893)

composer-2.10.3-1.el10_3

5 days 11 hours ago
FEDORA-EPEL-2026-9a4c6ee5c5 Packages in this update:
  • composer-2.10.3-1.el10_3
Update description: Version 2.10.3 - 2026-08-27
  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)

composer-2.10.3-1.el9

5 days 11 hours ago
FEDORA-EPEL-2026-bf7afd5dc2 Packages in this update:
  • composer-2.10.3-1.el9
Update description: Version 2.10.3 - 2026-08-27
  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)