Aggregator

chromium-154.0.8037.57-1.el10_2

3 days 3 hours ago
FEDORA-EPEL-2026-c4d340d432 Packages in this update:
  • chromium-154.0.8037.57-1.el10_2
Update description:

Update to 154.0.8037.57

CVE-2026-95274: Improper output encoding in DevTools CVE-2026-95275: Incorrect reference resolution in MediaStream CVE-2026-95276: Improper input validation in Themes CVE-2026-95277: Use after free in Views CVE-2026-95278: Missing authorization in WakeLock CVE-2026-95279: UI misrepresentation in Omnibox CVE-2026-95280: Race condition in V8 CVE-2026-95281: Buffer overflow in ANGLE CVE-2026-95282: Use after free in Platform CVE-2026-95283: Buffer overflow in Tint CVE-2026-95284: Buffer overflow in ANGLE CVE-2026-95285: Missing authorization in WebView CVE-2026-95286: Type confusion in Bindings CVE-2026-95287: Missing authorization in Navigation CVE-2026-95288: UI misrepresentation in Mobile CVE-2026-95289: Incorrect authorization in Scroll CVE-2026-95290: Missing authorization in NFC CVE-2026-95291: UI misrepresentation in SecurityIndicators CVE-2026-95292: Incorrect authorization in Safebrowsing CVE-2026-95293: Uninitialized resource in GPU CVE-2026-95294: UI misrepresentation in Browser CVE-2026-95295: Information leak in Mobile CVE-2026-95296: Missing authorization in Core CVE-2026-95297: Missing authorization in Contextual Tasks CVE-2026-95298: Use after free in Browser CVE-2026-95299: Use after free in GPU CVE-2026-95300: Missing authorization in DevTools CVE-2026-95301: Missing authorization in Extensions CVE-2026-95302: Incorrect authorization in WebAPKs CVE-2026-95303: Incomplete cleanup in SmartCard CVE-2026-95304: Out of bounds write in V8 CVE-2026-95305: UI misrepresentation in Chromoting CVE-2026-95306: Type confusion in V8 CVE-2026-95307: UI misrepresentation in ExtensionsMenu CVE-2026-95308: Integer overflow in Metrics CVE-2026-95309: UI misrepresentation in Mobile CVE-2026-95310: Use after free in AdFilter CVE-2026-95311: Free of non-heap memory in Fonts CVE-2026-95312: Information leak in Passwords CVE-2026-95313: Use after free in Fullscreen CVE-2026-95314: Incorrect authorization in HID CVE-2026-95315: Use after free in Aura CVE-2026-95316: Unchecked return value in Performance CVE-2026-95317: Incorrect authorization in MediaCapture CVE-2026-95318: Buffer overflow in Video CVE-2026-95319: Use after free in Printing CVE-2026-95320: Missing authorization in Navigation CVE-2026-95321: UI misrepresentation in Payments CVE-2026-95322: Out of bounds write in GPU CVE-2026-95323: UI misrepresentation in Chromium CVE-2026-95324: Uninitialized resource in GPU CVE-2026-95325: Use after free in ANGLE CVE-2026-95326: Incomplete cleanup in Bluetooth CVE-2026-95327: Information leak in Networking CVE-2026-95328: Confused deputy in Mobile CVE-2026-95329: Out of bounds write in WebGL CVE-2026-95330: Improper state validation in Downloads CVE-2026-95331: Out of bounds write in ANGLE CVE-2026-95332: Use of uninitialized variable in Tint CVE-2026-95333: Use after free in Metrics CVE-2026-95334: Incorrect reference resolution in WebProtect CVE-2026-95335: Use after free in HID CVE-2026-95336: Information leak in Transactions Platform CVE-2026-95337: UI misrepresentation in Messages CVE-2026-95338: Use after free in PDFium CVE-2026-95339: Use after free in ServiceWorker CVE-2026-95340: Incorrect authorization in PictureInPicture CVE-2026-95341: Improper input validation in Desktop CVE-2026-95342: Missing authorization in V8 CVE-2026-95343: Use after free in WebAudio CVE-2026-95344: Race condition in DevTools CVE-2026-95345: Use after free in Actor CVE-2026-95346: UI misrepresentation in Chromoting CVE-2026-95347: Use after free in Updater CVE-2026-95348: Use after free in Bluetooth CVE-2026-95349: Buffer overflow in WebGL CVE-2026-95350: Buffer overflow in ANGLE CVE-2026-95351: Use after free in Views CVE-2026-95352: Incorrect authorization in DevTools CVE-2026-95353: Use after free in Bindings CVE-2026-95354: Use after free in Verifier CVE-2026-95355: Incorrect authorization in Navigation CVE-2026-95356: Use after free in WindowDialog CVE-2026-95357: Out of bounds write in GPU CVE-2026-95358: Incorrect authorization in Mobile CVE-2026-95359: Uninitialized resource in GPU CVE-2026-95360: Race condition in Editing CVE-2026-95361: Confused deputy in DevTools CVE-2026-95362: Cross-site request forgery in DevTools CVE-2026-95363: UI misrepresentation in FileSystem CVE-2026-95364: Improper input validation in Passwords CVE-2026-95365: Type confusion in IndexedDB CVE-2026-95366: Use of released resource in Core CVE-2026-95367: Information leak in DataTransfer CVE-2026-95368: Incorrect authorization in DevTools CVE-2026-95369: Inappropriate implementation in XML CVE-2026-95370: Inappropriate implementation in NFC CVE-2026-95371: Missing authorization in Views CVE-2026-95372: Use after free in Chromecast CVE-2026-95373: Use after free in DevTools CVE-2026-95374: Incorrect authorization in Network CVE-2026-95375: Incorrect authorization in BrowserTag CVE-2026-95376: Externally controlled reference in DevTools CVE-2026-95380: Type confusion in V8 CVE-2026-95381: Improper input validation in Printing CVE-2026-95382: Improper input validation in Auth CVE-2026-95384: Race condition in Transactions Platform CVE-2026-95385: Inappropriate implementation in PlatformIntegration

python-engineio-4.12.3-2.el9 python-simple-websocket-1.0.0-8.el9

3 days 4 hours ago
FEDORA-EPEL-2026-e47857b934 Packages in this update:
  • python-engineio-4.12.3-2.el9
  • python-simple-websocket-1.0.0-8.el9
Update description:

Update python-engineio to 4.12.3, which is not the latest version but is the latest version that could be reasonably backported to EPEL9. This required branching a new package for python-simple-websocket 1.0.0 – again, not quite the latest version. Furthermore, this update includes a backport from versions 4.13.2 and 4.13.5 of the fixes for CVE-2026-48802 and CVE-2026-48809.

USN-8826-1: LXC vulnerabilities

3 days 5 hours ago
Maher Azzouzi discovered that LXC did not correctly handle logging certain failure messages. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2022-47952) Sam Sanoop discovered that LXC did not correctly handle certain forms of user authorization. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-39402)

cri-o1.36-1.36.6-1.fc43

3 days 13 hours ago
FEDORA-2026-0025579bc9 Packages in this update:
  • cri-o1.36-1.36.6-1.fc43
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc44

3 days 13 hours ago
FEDORA-2026-f5c88f763a Packages in this update:
  • cri-o1.36-1.36.6-1.fc44
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc45

3 days 14 hours ago
FEDORA-2026-77abfa2cdd Packages in this update:
  • cri-o1.36-1.36.6-1.fc45
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc46

3 days 14 hours ago
FEDORA-2026-05f65b07d7 Packages in this update:
  • cri-o1.36-1.36.6-1.fc46
Update description:

Automatic update for cri-o1.36-1.36.6-1.fc46.

Changelog * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.6-1 - Update to release v1.36.6 - Resolves: rhbz#2537559 - Resolves CVE-2026-17113: rhbz#2523493 - Resolves: rhbz#2540885 * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.5-2 - Define --pinns_path - pinns_path is set to the libexec path for pinns