Aggregator

USN-8592-1: ImageMagick vulnerabilities

4 days 21 hours ago
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-30936) It was discovered that ImageMagick incorrectly handled extremely large XWD images. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. (CVE-2026-30937) It was discovered that ImageMagick incorrectly handled extremely large SFW images on 32-bit systems. An attacker could possibly use this issue to trigger an integer overflow, resulting in a denial of service. (CVE-2026-31853) It was discovered that ImageMagick incorrectly handled memory allocation failures in the sixel encoder. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-32259)

GraphicsMagick-1.3.45-10.fc45 ImageMagick-7.1.2.29-2.fc45 OpenImageIO-3.1.15.0-4.fc45 OpenImageIO2.5-2.5.19.1-17.fc45 darktable-5.4.1-12.fc45 digikam-9.1.0-3.fc45 ffmpeg-8.1.2-10.fc45 geeqie-2.7-6.fc45 gimp-3.2.4-4.fc45 gthumb-4.0~beta-4.fc45 imlib2-1.12…

5 days ago
FEDORA-2026-26ae66c60f Packages in this update:
  • darktable-5.4.1-12.fc45
  • digikam-9.1.0-3.fc45
  • ffmpeg-8.1.2-10.fc45
  • geeqie-2.7-6.fc45
  • gimp-3.2.4-4.fc45
  • GraphicsMagick-1.3.45-10.fc45
  • gthumb-4.0~beta-4.fc45
  • ImageMagick-7.1.2.29-2.fc45
  • imlib2-1.12.5-4.fc45
  • imv-5.0.1-4.fc45
  • kf5-kimageformats-5.116.0-12.fc45
  • kf6-kimageformats-6.29.0-2.fc45
  • libheif-1.23.1-9.fc45
  • mingw-openexr-3.4.13-3.fc45
  • mpv-0.41.0-8.fc45
  • openapv-0.3.0.0-1.fc45
  • OpenImageIO2.5-2.5.19.1-17.fc45
  • OpenImageIO-3.1.15.0-4.fc45
  • openjph-0.31.0-1.fc45
  • perl-Prima-1.77-6.fc45
  • python-imagecodecs-2025.8.2-7.fc45
  • siril-1.4.4-3.fc45
  • swayimg-5.5-2.fc45
  • vapoursynth-79-3.fc45
  • vips-8.18.3-4.fc45
  • xevd-0.7.0-2.fc45
  • xeve-0.7.0-2.fc45
Update description:

Updated xeve/xevd, updated openapv and updated vapoursynth.

USN-8626-1: systemd vulnerabilities

5 days 4 hours ago
It was discovered that systemd-homed did not properly verify the signature of home records. A local attacker could possibly use this issue to add arbitrary system groups to a logged-in user and gain elevated privileges. (CVE-2026-16742) It was discovered that systemd-machined incorrectly handled certain polkit authorization checks. A local attacker could possibly use this issue to terminate arbitrary processes, including privileged ones. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15060) It was discovered that systemd-oomd did not properly validate certain IPC requests. A local attacker could possibly use this issue to terminate arbitrary processes. (CVE-2026-15059)

libcupsfilters-2.2.0-1.fc45

5 days 6 hours ago
FEDORA-2026-4acc8aafb3 Packages in this update:
  • libcupsfilters-2.2.0-1.fc45
Update description:

Automatic update for libcupsfilters-2.2.0-1.fc45.

Changelog * Thu Aug 6 2026 Zdenek Dohnal <zdohnal@redhat.com> - 1:2.2.0-1 - libcupsfilters-2.2.0 is available (fedora#2511889) * Wed Aug 5 2026 Zdenek Dohnal <zdohnal@redhat.com> - 1:2.1.1-9 - fixes CVE-2026-64611 and CVE-2026-64612 (fedora#2506364)

Automatic update for libcupsfilters-2.1.1-9.fc45.

perl-List-SomeUtils-XS-0.59-1.fc43

5 days 6 hours ago
FEDORA-2026-6217093b91 Packages in this update:
  • perl-List-SomeUtils-XS-0.59-1.fc43
Update description:

0.59 - Fix a heap buffer overflow in the pairwise function when it would return a very large list - CVE-2026-12844

perl-Imager-1.034-1.fc44

5 days 8 hours ago
FEDORA-2026-8a61adae6f Packages in this update:
  • perl-Imager-1.034-1.fc44
Update description:

Upstream changes (1.034): - Security fix: EXIF: fix decoding of ASCII fields with zero size (CVE-2026-19082, GHSA-hx46-55wp-hv6m) - JPEG: depend on Imager 1.034 for the EXIF decoding fix - Include bundled module Changes files in the main distribution - TIFF: fix potential seek error ignore in sizeproc

perl-Imager-1.034-1.fc43

5 days 8 hours ago
FEDORA-2026-4fb0f012fb Packages in this update:
  • perl-Imager-1.034-1.fc43
Update description:

Upstream changes (1.034): - Security fix: EXIF: fix decoding of ASCII fields with zero size (CVE-2026-19082, GHSA-hx46-55wp-hv6m) - JPEG: depend on Imager 1.034 for the EXIF decoding fix - Include bundled module Changes files in the main distribution - TIFF: fix potential seek error ignore in sizeproc

radsecproxy-1.11.4-1.fc43

5 days 8 hours ago
FEDORA-2026-057cd843d0 Packages in this update:
  • radsecproxy-1.11.4-1.fc43
Update description: radsecproxy 1.11.4 (2026-08-10) Bug Fixes
  • Fix potential crash when rewrite is too big
  • Fix Message-Authenticator verification for CoA/Disconnect-Request
  • Fix config check error message for rewrite in server block
  • Fix DtlsVersion config
  • Fix MS-MPPE size/alignment check (GHSA-wj29-mxmc-q98c)
Misc
  • Explain F-Ticks minimum requirements

radsecproxy-1.11.4-1.el10_3

5 days 8 hours ago
FEDORA-EPEL-2026-6ceff45673 Packages in this update:
  • radsecproxy-1.11.4-1.el10_3
Update description: radsecproxy 1.11.4 (2026-08-10) Bug Fixes
  • Fix potential crash when rewrite is too big
  • Fix Message-Authenticator verification for CoA/Disconnect-Request
  • Fix config check error message for rewrite in server block
  • Fix DtlsVersion config
  • Fix MS-MPPE size/alignment check (GHSA-wj29-mxmc-q98c)
Misc
  • Explain F-Ticks minimum requirements