4 days 22 hours ago
It was discovered that Flatpak did not properly validate paths in
sandbox-expose options. A malicious or compromised Flatpak app could
use app-controlled symlinks to access arbitrary host files and gain
code execution in the host context. This issue was addressed in Ubuntu
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078)
It was discovered that Flatpak did not properly validate paths when
removing outdated ld.so cache files. A malicious or compromised Flatpak
app could use this issue to delete arbitrary files on the host.
(CVE-2026-34079)
4 days 23 hours ago
FEDORA-2026-2857104379
Packages in this update:
Update description:
Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.
4 days 23 hours ago
FEDORA-2026-9831a751e2
Packages in this update:
Update description:
Update rubygems to 4.0.20. Additionally, several security issues were found in resolv gem bundled in rubygems. This update resolves these issues by updating resolv to 0.7.2.
5 days ago
FEDORA-2026-c77b963cc9
Packages in this update:
Update description:
Automatic update for rubygems-4.0.20-1.fc46.
Changelog
* Thu Sep 3 2026 Mamoru TASAKA <
mtasaka@fedoraproject.org> - 4.0.20-1
- Update to RubyGems 4.0.20
- Backport ruby upstream patch to update resolv to 0.7.2
- Resolves: CVE-2026-80212 (rhbz#2527309)
- Resolves: CVE-2026-80213 (rhbz#2527311)
5 days ago
Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did
not properly validate cross-origin WebSocket connections. An attacker could
possibly use this issue to expose sensitive information. (CVE-2026-58649)
Rajesh Chada discovered that the .NET watch AspireServerService improperly
exposed information through the use of certain arguments. An attacker could
possibly use this issue to elevate privileges and execute arbitrary code.
(CVE-2026-69806)
5 days 1 hour ago
FEDORA-2026-8b8efbd2b8
Packages in this update:
Update description:
- updated to 2.4.5, many security fixes
5 days 1 hour ago
FEDORA-2026-2e6b786570
Packages in this update:
Update description:
- updated to 2.4.5, many security fixes
5 days 1 hour ago
FEDORA-2026-e8a6485109
Packages in this update:
Update description:
- updated to 2.4.5, many security fixes
5 days 3 hours ago
5 days 12 hours ago
FEDORA-EPEL-2026-d8f2957095
Packages in this update:
Update description:
Update to 3.1.62 (close RHBZ#2529282)
5 days 13 hours ago
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides
the corresponding fix for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that FFmpeg incorrectly handled certain crafted media
files in the VobSub subtitle demuxer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-64830)
It was discovered that FFmpeg incorrectly handled certain crafted HEVC
bitstreams in the Vulkan HEVC hardware decoder. An attacker could
possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-64831)
It was discovered that FFmpeg incorrectly handled certain crafted video
files in the NVDEC hardware decoder. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-64832)
It was discovered that FFmpeg incorrectly handled certain crafted DTS
audio streams in the S/PDIF muxer. An attacker could possibly use this
issue to cause a denial of service or expose sensitive information.
(CVE-2026-64833)
It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF
streams. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-64834)
It was discovered that FFmpeg incorrectly handled certain crafted ADX
audio files. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-64835)
It was discovered that FFmpeg incorrectly handled certain crafted AVI
files in the TDSC video decoder. An attacker could possibly use this
issue to cause a denial of service or execute arbitrary code.
(CVE-2026-65703)
It was discovered that FFmpeg incorrectly handled certain crafted
ffconcat files processed via the TY demuxer. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-65704)
It was discovered that FFmpeg incorrectly handled certain crafted video
streams in the vf_floodfill video filter. An attacker could possibly
use this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-65705)
It was discovered that FFmpeg incorrectly handled certain crafted NV12
video frames in the vf_swaprect video filter. An attacker could
possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-65706)
It was discovered that FFmpeg incorrectly handled certain crafted hvcC
NAL arrays in the HEVC parser. An attacker could possibly use this
issue to cause a denial of service or execute arbitrary code.
(CVE-2026-75141)
It was discovered that FFmpeg incorrectly handled certain crafted MPEG
system headers. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-75142)
It was discovered that FFmpeg incorrectly handled certain crafted
network input in the librist protocol handler. An attacker could
possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-75143)
It was discovered that FFmpeg incorrectly handled certain crafted Dirac
data units in the VC2 HQ RTP packetizer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-75144)
It was discovered that FFmpeg incorrectly handled certain crafted DASH
manifests. An attacker could possibly use this issue to cause a denial
of service or expose sensitive information. (CVE-2026-75146)
5 days 13 hours ago
FEDORA-2026-301e6e2983
Packages in this update:
- python-django5-5.2.17-2.fc44
Update description:
Update python-django5 to the latest 5.x release (5.2.17)
- Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
- Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
- Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
- Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin
5 days 13 hours ago
FEDORA-2026-6b28b4e483
Packages in this update:
- python-django5-5.2.17-2.fc43
Update description:
Update python-django5 to the latest 5.x release (5.2.17)
- Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
- Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
- Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
- Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin
5 days 13 hours ago
FEDORA-2026-950089270f
Packages in this update:
- python-django5-5.2.17-2.fc45
Update description:
Update python-django5 to the latest 5.x release (5.2.17)
- Fixes CVE-2026-15307 [high]: Server-side file-write and request forgery via spatial lookups
- Fixes CVE-2026-15337 [low]: Potential denial-of-service vulnerability in check_for_language()
- Fixes CVE-2026-15830 [moderate]: Potential denial-of-service vulnerability via nested geometry collections
- Fixes CVE-2026-15920 [moderate]: Potential cross-site scripting via URLField values in the admin
5 days 16 hours ago
Version:next-20260909 (linux-next)
Released:2026-09-09
5 days 17 hours ago
USN-8675-1 fixed vulnerabilities in Perl. This update provides the
corresponding fix for Perl on Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that Perl incorrectly handled short source addresses
in the Socket module. An attacker could possibly use this issue to
trigger an out-of-bounds heap read, resulting in information disclosure.
(CVE-2026-12087)
It was discovered that Perl incorrectly handled regular expressions
containing a large number of fixed string alternatives. An attacker
could possibly use this issue to cause incorrect regular expression
matches, resulting in security restrictions being bypassed.
(CVE-2026-13221)
It was discovered that Perl incorrectly handled certain large repeat
counts when processing pack and unpack templates. An attacker could
possibly use this issue to trigger an out-of-bounds heap read, resulting
in information disclosure. (CVE-2026-57432)
It was discovered that Perl incorrectly handled certain crafted data
when deserializing with the Storable module. An attacker could possibly
use this issue to trigger an integer overflow and application
termination, resulting in a denial of service. (CVE-2026-57433)
5 days 17 hours ago
FEDORA-2026-ee1eb89e7b
Packages in this update:
Update description:
Fix CVE-2026-5704, CVE-2026-18508, CVE-2026-18477, and a regression in the fix for CVE-2025-45582.
5 days 17 hours ago
FEDORA-2026-c8b1bb0c97
Packages in this update:
Update description:
Patched the vulnerabilities GNATCOLL-CORE-0162 and GNATCOLL-CORE-0164 in a way that avoids interface changes.
5 days 18 hours ago
FEDORA-2026-6ed52ea50e
Packages in this update:
- bluez-5.87+1.git8750129efca8-1.fc43
Update description:
This update fixes a number of security issues.
5 days 18 hours ago
FEDORA-2026-d4156b5fc5
Packages in this update:
- bluez-5.87+1.git8750129efca8-1.fc44
Update description:
This update fixes a number of security issues.