Aggregator
USN-8296-2: Linux kernel (NVIDIA Tegra) vulnerabilities
next-20260525: linux-next
USN-8302-1: NLTK vulnerabilities
USN-8301-1: SimpleEval vulnerability
USN-8300-1: ngtcp2 vulnerability
vim-9.2.530-1.fc43
- vim-9.2.530-1.fc43
keep GTK4 in rawhide for now
switch to GTK4 for GVim
Fix CVE-2026-46483
bind-9.18.49-1.fc42 bind-dyndb-ldap-11.11-12.fc42
- bind-9.18.49-1.fc42
- bind-dyndb-ldap-11.11-12.fc42
- Limit resolver server list size. (CVE-2026-3592)
- Fix GSS-API resource leak. (CVE-2026-3039)
- Disable recursion, UPDATE, and NOTIFY for non-IN views. (CVE-2026-5946)
- Avoid unbounded recursion loop. (CVE-2026-5950)
- Fix outgoing zone transfers' quota issue.
- Fix CPU spikes and slow queries when cache approaches memory limit.
- Fix named crash when processing SIG records in dynamic updates.
- Fix rndc modzone behavior for a zone in named.conf.
- Fix zone verification of NSEC3 signed zones.
- Prevent a crash when using both dns64 and filter-aaaa.
- Fixed an assertion failure when processing catalog zones.
- Prevent malicious DNSSEC zones from exhausting validator CPU.
- Fix rndc-confgen aborting on HMAC-SHA-384/512 keys above 512 bits.
- Prevent crafted queries from degrading RRL performance.
- Fix a bug in allow-query/allow-transfer catalog zone custom properties.
- Fix a memory leak issue in catalog zones.
- Fix suppressed missing-glue check in named-checkzone.
- Reject record sets too large to serve in DNS.
Source: https://downloads.isc.org/isc/bind9/9.18.49/doc/arm/html/notes.html#notes-for-bind-9-18-49
USN-8299-1: Rclone vulnerabilities
USN-8298-1: .NET vulnerability
python-wsgidav-4.3.4-1.el10_3
- python-wsgidav-4.3.4-1.el10_3
- Resolve security advisory CVE-2026-48099
python-wsgidav-4.3.4-1.fc43
- python-wsgidav-4.3.4-1.fc43
- Resolve security advisory CVE-2026-48099
python-wsgidav-4.3.4-1.fc44
- python-wsgidav-4.3.4-1.fc44
- Resolve security advisory CVE-2026-48099
nix-2.31.5-1.el10_2
- nix-2.31.5-1.el10_2
- Rebase nix to 2.31.5
- fixes https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368
roundcubemail-1.7.1-1.fc44
- roundcubemail-1.7.1-1.fc44
- Enigma: Support automatic public key lookup (import) using HKP v1 protocol (#5314)
- Managesieve: Fix error when a mail message contains duplicate List-Id header (#10186)
- Clarified Elastic installation instructions (#10163)
- Added HTMLFormElement.requestSubmit() polyfill for older browsers (#10179)
- Fix so "has:attachment" search uses $HasAttachment/$HasNoAttachment keywords (#10168)
- Fix potential too long value in IMAP ID command (#10136)
- Fix redis/memcache disconnection in rcube::sleep() (#10127)
- Fix so static resources, e.g. skin_logo can be put inside the public_html directory (#10160)
- Fix so REQUEST_URI is used as a fallback if PATH_INFO is not set in static.php (#10181)
- Fix assets_path feature and remove dependency on PATH_INFO (#10185)
- Fix MySQL upgrade on MySQL < 8.0 and MariaDB < 10.5.3 (#10188)
- Security: Fix stored XSS/HTML/CSS injection in subject field of the draft restore dialog
- Security: Fix CSS injection bypass in HTML sanitizer via SVG <animate attributeName="style">
- Security: Fix pre-auth SQL injection in virtuser_query plugin via preg_replace backslash escape bypass
- Security: Fix SSRF bypass via specific local address URLs
- Security: Fix bypass of remote image blocking via CSS var()
- Security: Fix local/private URL fetch bypass when remote resources were not allowed
- Security: Fix pre-auth arbitrary file delete via redis/memcache session poisoning bypass
- Security: Fix code injection vulnerability - remove support for code evaluation in LDAP autovalues option
DSA-6296-1 spip - security update
7.1-rc5: mainline
perl-Catalyst-Plugin-Authentication-0.10026-1.fc43
- perl-Catalyst-Plugin-Authentication-0.10026-1.fc43
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.
perl-Catalyst-Plugin-Authentication-0.10026-1.fc44
- perl-Catalyst-Plugin-Authentication-0.10026-1.fc44
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.
perl-Catalyst-Plugin-Authentication-0.10026-1.fc42
- perl-Catalyst-Plugin-Authentication-0.10026-1.fc42
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing attacks since these versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying hash or password. Version 0.10026 of the module fixes this issue.