Aggregator
USN-8675-1: Perl vulnerabilities
neovim-0.12.5-1.fc46 tree-sitter-0.26.13-1.fc46
- neovim-0.12.5-1.fc46
- tree-sitter-0.26.13-1.fc46
Update neovim and tree-sitter
next-20260825: linux-next
emacs-30.2-28.fc44
- emacs-30.2-28.fc44
Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.
emacs-30.2-10.fc43
- emacs-30.2-10.fc43
Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.
golang-1.26.7-1.fc44
- golang-1.26.7-1.fc44
Update to 1.26.7 upstream release
curl-8.18.0-9.fc44
- curl-8.18.0-9.fc44
- Fix QUIC zero-length UDP datagrams busy-loop (CVE-2026-11352)
- Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
- Fix proto-default skips SSH verification (CVE-2026-12064)
- Fix wrong STARTTLS connection reuse (CVE-2026-8286)
- Fix SASL double-free (CVE-2026-8925)
- Fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
- Fix sending old referer (CVE-2026-9546)
- Fix exposing HTTP/3 early data (CVE-2026-9545)
- Fix UAF after pause in socket callback (CVE-2026-9080)
proftpd-1.3.9d-2.el10_4
- proftpd-1.3.9d-2.el10_4
Current upstream maintenance release, with a handful of potentially security-related bugfixes.
DSA-6466-1 linux - security update
DSA-6465-1 openssl - security update
DSA-6464-1 erlang - security update
gum-2.0.0-1.el10_4
- gum-2.0.0-1.el10_4
Update to version 2.0.0 and override bundled golang.org/x/net to v0.55.0. The latter fixes CVE-2026-25680, CVE-2026-25681, and CVE-2026-42506.
python-linkify-it-py-2.1.1-1.fc44
- python-linkify-it-py-2.1.1-1.fc44
Security release: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8).
- Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82)
- Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82)
- Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
- Update port.yml (linkify-it v5.0.2) (#82)
USN-8671-1: FFmpeg vulnerabilities
python-llm-0.33-2.fc44
- python-llm-0.33-2.fc44
Update to latest upstream release python llm 0.33
USN-8670-1: curl vulnerability
perl-DBD-Pg-3.21.1-2.fc44
- perl-DBD-Pg-3.21.1-2.fc44
Fix missing closing double-quote in su -c commands in dbdpg_test_setup.pl
3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183
chromium-151.0.7922.173-1.el10_2
- chromium-151.0.7922.173-1.el10_2
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Themingchromium-151.0.7922.173-1.fc43
- chromium-151.0.7922.173-1.fc43
Update to 151.0.7922.173
* CVE-2026-76017: Use after free in Chromoting * CVE-2026-76018: Privilege elevation in Import * CVE-2026-76019: Incorrect authorization in Workers * CVE-2026-76020: Race condition in V8 * CVE-2026-76021: Use after free in DOM * CVE-2026-76022: Buffer overflow in Network * CVE-2026-76023: Improper resource control in Linux Toolkit Theming