3 days 12 hours ago
FEDORA-2026-7a31054ed6
Packages in this update:
Update description:
Update to 1.18.4
3 days 12 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- OCFS2 file system;
- IPv6 networking;
- Netfilter;
- SCTP protocol;
(CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)
3 days 12 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888,
CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984,
CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007,
CVE-2026-64091)
3 days 13 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
3 days 13 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
3 days 13 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
3 days 13 hours ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystems:
- IPv6 networking;
- Netfilter;
3 days 14 hours ago
FEDORA-EPEL-2026-6867b104b2
Packages in this update:
Update description:
Update to 3.20.1.
3 days 14 hours ago
FEDORA-2026-82691b59d6
Packages in this update:
Update description:
Update to 3.20.1.
3 days 14 hours ago
FEDORA-2026-0b3030633b
Packages in this update:
Update description:
Update to 3.20.1.
3 days 14 hours ago
FEDORA-EPEL-2026-bc47388d91
Packages in this update:
Update description:
Update to 3.20.1.
3 days 14 hours ago
FEDORA-2026-cffd5fed1f
Packages in this update:
Update description:
Update to 3.20.1.
3 days 17 hours ago
3 days 17 hours ago
3 days 17 hours ago
3 days 21 hours ago
USN-8847-1 fixed vulnerabilities in OpenSSL. This update provides the
corresponding fix for OpenSSL on Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly use
this issue to perform a timing side-channel attack and obtain
sensitive information. This issue only affected Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-77696)
It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)
4 days 2 hours ago
It was discovered that OpenSSL incorrectly handled certain certificate
revocation list distribution point names. An attacker could possibly use
this issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. (CVE-2026-35189)
It was discovered that OpenSSL incorrectly handled QUIC unvalidated
amplification credit accounting. An attacker could possibly use this
issue to cause a denial of service. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35191)
It was discovered that OpenSSL incorrectly implemented scalar
multiplication for non-NIST elliptic curves. An attacker could possibly
use this issue to perform a timing side-channel attack and obtain
sensitive information. (CVE-2026-54872)
It was discovered that OpenSSL incorrectly implemented SM2 scalar
multiplication on ARM64 and RISC-V architectures. An attacker could
possibly use this issue to perform a timing side-channel attack and
obtain sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-54875)
It was discovered that OpenSSL incorrectly handled SSL context switching
during a TLS handshake. An attacker could possibly use this issue to
cause an out-of-bounds read, resulting in a denial of service or
obtaining sensitive information. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-72897)
It was discovered that OpenSSL incorrectly enforced QUIC connection-
level flow control for streams. An attacker could possibly use this
issue to cause OpenSSL to consume excessive memory, resulting in a
denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-75804)
It was discovered that OpenSSL incorrectly handled a NULL pointer in
CMP client revocation response processing. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-75805)
It was discovered that OpenSSL incorrectly handled undersized DTLS 1.2
AEAD records before authentication. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-75806)
It was discovered that OpenSSL incorrectly implemented SM2 signature
generation. An attacker could possibly use this issue to perform a
timing side-channel attack and obtain sensitive information.
(CVE-2026-77696)
It was discovered that OpenSSL incorrectly handled DTLS retransmission
of handshake messages. An attacker could possibly use this issue to
cause incorrect handshake behavior or a denial of service.
(CVE-2026-84782)
It was discovered that OpenSSL incorrectly handled QUIC
RETIRE_CONNECTION_ID frames. An attacker could possibly use this issue
to cause OpenSSL to consume excessive memory, resulting in a denial of
service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-84784)
4 days 4 hours ago
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
compressed metadata. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 26.04 LTS. (CVE-2026-84384)
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
HEIF sequence data. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84446)
Yuqi Qiu and Xiang Li discovered that libheif incorrectly handled certain
image references. A remote attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-84447)
It was discovered that libheif incorrectly handled certain region masks.
A local attacker could possibly use this issue to obtain sensitive
information or cause a denial of service. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-84448)
It was discovered that libheif incorrectly handled certain images. A
remote attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-84449)
4 days 5 hours ago
It was discovered that c-ares incorrectly handled certain query completion
callbacks. An attacker could possibly use this issue to trigger a use-
after-free or double-free, resulting in a denial of service or arbitrary
code execution.
4 days 6 hours ago
Version:next-20260929 (linux-next)
Released:2026-09-29