Aggregator

openssh-10.0p1-12.fc43

4 days 21 hours ago
FEDORA-2026-535a408db5 Packages in this update:
  • openssh-10.0p1-12.fc43
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

USN-8563-3: nginx vulnerability

4 days 21 hours ago
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533. We apologize for the inconvenience. Original advisory details: It was discovered that nginx incorrectly handled certain map directives using regex matching and capture variables. A remote attacker could use this issue to cause nginx to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-42533) It was discovered that nginx had a use-after-free vulnerability in the ngx_http_ssi_module module when configured with Server-Side Includes, proxy_pass, and proxy buffering disabled directives. An attacker able to intercept traffic and control responses from an upstream server could possibly use this issue to cause nginx to crash, resulting in a denial of service. (CVE-2026-56434) It was discovered that nginx incorrectly handled certain requests in the ngx_http_slice_module module. A remote attacker could possibly use this issue to obtain sensitive information or cause nginx to crash, resulting in a denial of service. (CVE-2026-60005)

USN-8648-1: Bind vulnerabilities

4 days 21 hours ago
It was discovered that Bind incorrectly accepted NSEC3 records whose signer name did not match the owning zone. A remote attacker could possibly use this issue to perform NSEC3 impersonation attacks, bypassing DNSSEC validation. (CVE-2026-10723) It was discovered that Bind incorrectly handled Key Records using the PRIVATEDNS algorithm. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2026-10822) It was discovered that Bind incorrectly handled wildcard CNAME expansion in Response Policy Zones. A remote attacker could possibly use this issue to bypass configured RPZ policies. (CVE-2026-11331) It was discovered that Bind performed unnecessary validation of DNSSEC signed records. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-11605) It was discovered that Bind incorrectly tracked memory usage in the DNS cache. A remote attacker could possibly use this issue to cause Bind to use memory beyond configured limits, leading to a denial of service. (CVE-2026-11622) It was discovered that Bind incorrectly handled signed wildcard records with label count discrepancies and RRSIG validation. A remote attacker could possibly use this issue to perform cache poisoning attacks. (CVE-2026-11721) It was discovered that Bind incorrectly handled certain CNAME and DNAME record orderings in the resolver. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. (CVE-2026-12617) It was discovered that Bind incorrectly validated out-of-zone NSEC next owner names during DNSSEC validation. A remote attacker could possibly use this issue to bypass DNSSEC validation. (CVE-2026-13321)

opkssh-0.16.0-2.el10_3

5 days ago
FEDORA-EPEL-2026-f45034028f Packages in this update:
  • opkssh-0.16.0-2.el10_3
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.el10_2

5 days ago
FEDORA-EPEL-2026-8d8aa891da Packages in this update:
  • opkssh-0.16.0-2.el10_2
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc43

5 days ago
FEDORA-2026-8d9ba295e0 Packages in this update:
  • opkssh-0.16.0-2.fc43
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc44

5 days ago
FEDORA-2026-f5a5073561 Packages in this update:
  • opkssh-0.16.0-2.fc44
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

USN-8093-2: libssh vulnerability

5 days 1 hour ago
USN-8093-1 fixed a vulnerability in libssh. This update provides the corresponsing fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that libssh incorrectly performed bounds checking when processing SFTP extensions. If a client application queried extension data out of bounds, it could cause the application to crash, resulting in a denial of service, or exhibit unintended behavior.

USN-8113-2: LibTIFF vulnerabilities

5 days 1 hour ago
USN 8113-1 fixed vulnerabilities in tiff. This update provides the corresponding fixes for Ubuntu 26.04 LTS. Original advisory details: It was discovered that LibTIFF did not properly handle memory when processing certain images. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61143) It was discovered that LibTIFF did not properly handle memory when processing malformed TIFF directories. An attacker could possibly use this issue to cause LibTIFF to crash, resulting in a denial of service. (CVE-2025-61144)

firefox-154.0-3.fc44

5 days 2 hours ago
FEDORA-2026-fc11919789 Packages in this update:
  • firefox-154.0-3.fc44
Update description:

Implement buffer stride support for PipeWire camera.

  • Update to latest upstream (154.0)
  • Enabled Wayland session restore on KDE.

openbao-2.6.2-1.el8

5 days 10 hours ago
FEDORA-EPEL-2026-f78a6b3cf2 Packages in this update:
  • openbao-2.6.2-1.el8
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_3

5 days 10 hours ago
FEDORA-EPEL-2026-0194a75a00 Packages in this update:
  • openbao-2.6.2-1.el10_3
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc44

5 days 10 hours ago
FEDORA-2026-73f5dc988f Packages in this update:
  • openbao-2.6.2-1.fc44
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_2

5 days 10 hours ago
FEDORA-EPEL-2026-56bfe89982 Packages in this update:
  • openbao-2.6.2-1.el10_2
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc43

5 days 10 hours ago
FEDORA-2026-ba51600ab3 Packages in this update:
  • openbao-2.6.2-1.fc43
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el9

5 days 10 hours ago
FEDORA-EPEL-2026-cba2df79a1 Packages in this update:
  • openbao-2.6.2-1.el9
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

USN-8630-3: Linux kernel (Oracle) vulnerabilities

5 days 12 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)