Aggregator

USN-8793-2: Linux kernel (Azure CVM) vulnerabilities

2 days 19 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Bluetooth drivers; - GPU drivers; - Hardware monitoring drivers; - SPI subsystem; - NTFS3 file system; - io_uring subsystem; - Ethernet bridge; - Multipath TCP; (CVE-2025-71289, CVE-2026-23469, CVE-2026-31420, CVE-2026-31486, CVE-2026-31560, CVE-2026-46158, CVE-2026-46170, CVE-2026-46275, CVE-2026-46315)

USN-8661-5: Linux kernel (Raspberry Pi) vulnerabilities

2 days 21 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - IPv6 networking; - Multipath TCP; - Netfilter; - Open vSwitch; - SCTP protocol; - SMC sockets; (CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53359, CVE-2026-64531)

USN-8760-2: Linux kernel (NVIDIA) vulnerabilities

2 days 22 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - ARM64 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Drivers core; - Compressed RAM block device driver; - Bluetooth drivers; - Character device driver; - Hardware random number generator core; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - Intel Stratix 10 firmware drivers; - FPGA Framework; - GPIO subsystem; - GPU drivers; - HID subsystem; - CoreSight HW tracing drivers; - I2C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Fastrpc Driver; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - MediaTek network drivers; - NTB driver; - NVME drivers; - NVMEM (Non Volatile Memory) drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - System reset/shutdown drivers; - Power sequencing drivers; - PTP clock framework; - Voltage and Current Regulator drivers; - RPMSG subsystem; - SLIMbus drivers; - SPI subsystem; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - VME bus staging drivers; - Trusted Execution Environment drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - Cadence USB3 driver; - ULPI bus; - DesignWare USB3 driver; - Faraday FOTG210 USB2 dual-role controller driver; - USB Gadget drivers; - USB Host Controller drivers; - USB ChaosKey driver; - Siemens ID Mouse USB driver; - IOWarrior USB driver; - LD Didactic USB driver; - LEGO USB Tower driver; - Intel USBIO USB I/O expander driver; - USS720 USB parallel port adapter driver; - MediaTek USB3 DRD driver; - USB Serial drivers; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - USB over IP driver; - VFIO drivers; - Framebuffer layer; - Virtio drivers; - BTRFS file system; - EROFS file system; - exFAT file system; - F2FS file system; - File systems infrastructure; - FUSE (File system in Userspace); - GFS2 file system; - HFS file system; - HFS+ file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - OCFS2 file system; - Proc file system; - SMB network file system; - UDF file system; - XFS file system; - Key management; - BPF subsystem; - Memory management; - Software nodes and device properties; - Glob pattern matching library; - Memory Management; - KVM subsystem; - Mellanox drivers; - Restartable sequences system call mechanism; - Socket messages infrastructure; - Network traffic control; - Bluetooth subsystem; - Netfilter; - Networking core; - Network sockets; - TCP network protocol; - io_uring subsystem; - IPC subsystem; - Audit subsystem; - Perf events; - Kernel fork() syscall; - Locking primitives; - Kernel module support; - Scheduler infrastructure; - Signal handling mechanism; - Timer subsystem; - Tracing infrastructure; - Debug objects infrastructure; - 6LoWPAN network protocol; - IEEE 802 network protocols; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Devlink API; - HSR network protocol; - IEEE802154.4 network protocol; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NetLabel subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - SCTP protocol; - SMC sockets; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - eXpress Data Path; - AppArmor security module; - Linux Security Modules (LSM) Framework; - Apple Onboard Audio ALSA driver; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - Gravis UltraSound ALSA driver; - C-Media CMI8x38 ALSA driver; - ESS Solo-1 ALSA driver; - ICE1712/ICE1724 (Envy24) ALSA driver; - Yamaha YMFPCI ALSA driver; - Wolfson Microelectronics audio codecs; - SoundWire (SDCA) ASoC drivers; - USB sound devices; - Virtio sound driver; (CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52917, CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52938, CVE-2026-52939, CVE-2026-52940, CVE-2026-52942, CVE-2026-52947, CVE-2026-52948, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53139, CVE-2026-53140, CVE-2026-53141, CVE-2026-53142, CVE-2026-53143, CVE-2026-53144, CVE-2026-53145, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53152, CVE-2026-53153, CVE-2026-53154, CVE-2026-53155, CVE-2026-53156, CVE-2026-53157, CVE-2026-53158, CVE-2026-53159, CVE-2026-53160, CVE-2026-53161, CVE-2026-53162, CVE-2026-53163, CVE-2026-53164, CVE-2026-53165, CVE-2026-53167, CVE-2026-53168, CVE-2026-53169, CVE-2026-53170, CVE-2026-53171, CVE-2026-53172, CVE-2026-53173, CVE-2026-53177, CVE-2026-53178, CVE-2026-53179, CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183, CVE-2026-53184, CVE-2026-53185, CVE-2026-53187, CVE-2026-53188, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192, CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53197, CVE-2026-53198, CVE-2026-53199, CVE-2026-53200, CVE-2026-53201, CVE-2026-53202, CVE-2026-53203, CVE-2026-53204, CVE-2026-53205, CVE-2026-53206, CVE-2026-53207, CVE-2026-53208, CVE-2026-53209, CVE-2026-53210, CVE-2026-53211, CVE-2026-53213, CVE-2026-53214, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53222, CVE-2026-53223, CVE-2026-53226, CVE-2026-53227, CVE-2026-53229, CVE-2026-53230, CVE-2026-53231, CVE-2026-53232, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235, CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239, CVE-2026-53240, CVE-2026-53241, CVE-2026-53242, CVE-2026-53243, CVE-2026-53244, CVE-2026-53245, CVE-2026-53248, CVE-2026-53249, CVE-2026-53250, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53257, CVE-2026-53258, CVE-2026-53259, CVE-2026-53261, CVE-2026-53262, CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274, CVE-2026-53275, CVE-2026-53276, CVE-2026-53325, CVE-2026-53326, CVE-2026-53327, CVE-2026-53328, CVE-2026-53329, CVE-2026-53330, CVE-2026-53331, CVE-2026-53332, CVE-2026-53333, CVE-2026-53334, CVE-2026-53335, CVE-2026-53336, CVE-2026-53337, CVE-2026-53338, CVE-2026-53339, CVE-2026-53340, CVE-2026-53341, CVE-2026-53342, CVE-2026-53343, CVE-2026-53344, CVE-2026-53345, CVE-2026-53346, CVE-2026-53347, CVE-2026-53348, CVE-2026-53349, CVE-2026-53350, CVE-2026-53351, CVE-2026-53352, CVE-2026-53353, CVE-2026-53355, CVE-2026-53356, CVE-2026-53361, CVE-2026-53362, CVE-2026-53363, CVE-2026-53366, CVE-2026-53381, CVE-2026-53382, CVE-2026-53383, CVE-2026-53384, CVE-2026-53385, CVE-2026-53386, CVE-2026-53387, CVE-2026-53388, CVE-2026-53389, CVE-2026-53390, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53395, CVE-2026-53396, CVE-2026-53397, CVE-2026-53398, CVE-2026-53399, CVE-2026-53400, CVE-2026-53401, CVE-2026-53402, CVE-2026-53403, CVE-2026-63794, CVE-2026-63795, CVE-2026-63796, CVE-2026-63797, CVE-2026-63798, CVE-2026-63799, CVE-2026-63800, CVE-2026-63801, CVE-2026-63802, CVE-2026-63803, CVE-2026-63804, CVE-2026-63805, CVE-2026-63806, CVE-2026-63807, CVE-2026-63808, CVE-2026-63809, CVE-2026-63810, CVE-2026-63811, CVE-2026-63812, CVE-2026-63813, CVE-2026-63814, CVE-2026-63815, CVE-2026-63816, CVE-2026-63817, CVE-2026-63818, CVE-2026-63819, CVE-2026-63820, CVE-2026-63821, CVE-2026-63822, CVE-2026-63823, CVE-2026-63824, CVE-2026-63825, CVE-2026-63826, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63831, CVE-2026-63832, CVE-2026-63833, CVE-2026-63834, CVE-2026-63835, CVE-2026-63836, CVE-2026-63867, CVE-2026-63868, CVE-2026-63869, CVE-2026-63870, CVE-2026-63871, CVE-2026-63873, CVE-2026-63874, CVE-2026-64187, CVE-2026-64188, CVE-2026-64189, CVE-2026-64191, CVE-2026-64192, CVE-2026-64205, CVE-2026-64206, CVE-2026-64207, CVE-2026-64244, CVE-2026-64245, CVE-2026-64246, CVE-2026-64247, CVE-2026-64249, CVE-2026-64251, CVE-2026-64253, CVE-2026-64254, CVE-2026-64255, CVE-2026-64256, CVE-2026-64258, CVE-2026-64259, CVE-2026-64260, CVE-2026-64261, CVE-2026-64262, CVE-2026-64263, CVE-2026-64264, CVE-2026-64265, CVE-2026-64266, CVE-2026-64267, CVE-2026-64268, CVE-2026-64269, CVE-2026-64270, CVE-2026-64271, CVE-2026-64272, CVE-2026-64273, CVE-2026-64274, CVE-2026-64275, CVE-2026-64276, CVE-2026-64277, CVE-2026-64278, CVE-2026-64279, CVE-2026-64280, CVE-2026-64282, CVE-2026-64283, CVE-2026-64284, CVE-2026-64285, CVE-2026-64286, CVE-2026-64287, CVE-2026-64288, CVE-2026-64289, CVE-2026-64290, CVE-2026-64291, CVE-2026-64292, CVE-2026-64293, CVE-2026-64294, CVE-2026-64295, CVE-2026-64296, CVE-2026-64297, CVE-2026-64298, CVE-2026-64299, CVE-2026-64300, CVE-2026-64301, CVE-2026-64302, CVE-2026-64303, CVE-2026-64304, CVE-2026-64305, CVE-2026-64306, CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310, CVE-2026-64312, CVE-2026-64313, CVE-2026-64314, CVE-2026-64315, CVE-2026-64316, CVE-2026-64317, CVE-2026-64318, CVE-2026-64319, CVE-2026-64320, CVE-2026-64321, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64331, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347, CVE-2026-64348, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352, CVE-2026-64353, CVE-2026-64354, CVE-2026-64355, CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364, CVE-2026-64365, CVE-2026-64366, CVE-2026-64367, CVE-2026-64368, CVE-2026-64369, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64376, CVE-2026-64377, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64388, CVE-2026-64389, CVE-2026-64390, CVE-2026-64391, CVE-2026-64392, CVE-2026-64393, CVE-2026-64394, CVE-2026-64395, CVE-2026-64396, CVE-2026-64397, CVE-2026-64398, CVE-2026-64399, CVE-2026-64400, CVE-2026-64401, CVE-2026-64402, CVE-2026-64403, CVE-2026-64404, CVE-2026-64405, CVE-2026-64406, CVE-2026-64407, CVE-2026-64408, CVE-2026-64409, CVE-2026-64410, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64414, CVE-2026-64415, CVE-2026-64416, CVE-2026-64417, CVE-2026-64418, CVE-2026-64419, CVE-2026-64420, CVE-2026-64421, CVE-2026-64422, CVE-2026-64423, CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64428, CVE-2026-64429, CVE-2026-64430, CVE-2026-64432, CVE-2026-64433, CVE-2026-64434, CVE-2026-64435, CVE-2026-64436, CVE-2026-64438, CVE-2026-64439, CVE-2026-64440, CVE-2026-64441, CVE-2026-64442, CVE-2026-64443, CVE-2026-64444, CVE-2026-64445, CVE-2026-64446, CVE-2026-64447, CVE-2026-64448, CVE-2026-64449, CVE-2026-64450, CVE-2026-64451, CVE-2026-64452, CVE-2026-64453, CVE-2026-64454, CVE-2026-64455, CVE-2026-64456, CVE-2026-64457, CVE-2026-64458, CVE-2026-64459, CVE-2026-64460, CVE-2026-64461, CVE-2026-64462, CVE-2026-64463, CVE-2026-64464, CVE-2026-64465, CVE-2026-64466, CVE-2026-64467, CVE-2026-64468, CVE-2026-64469, CVE-2026-64470, CVE-2026-64471, CVE-2026-64472, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64476, CVE-2026-64477, CVE-2026-64478, CVE-2026-64479, CVE-2026-64480, CVE-2026-64481, CVE-2026-64482, CVE-2026-64483, CVE-2026-64484, CVE-2026-64485, CVE-2026-64486, CVE-2026-64487, CVE-2026-64488, CVE-2026-64489, CVE-2026-64490, CVE-2026-64491, CVE-2026-64492, CVE-2026-64493, CVE-2026-64494, CVE-2026-64495, CVE-2026-64496, CVE-2026-64497, CVE-2026-64499, CVE-2026-64500, CVE-2026-64501, CVE-2026-64502, CVE-2026-64503, CVE-2026-64504, CVE-2026-64505, CVE-2026-64507, CVE-2026-64508, CVE-2026-64509, CVE-2026-64510, CVE-2026-64511, CVE-2026-64512, CVE-2026-64513, CVE-2026-64514, CVE-2026-64529, CVE-2026-64531, CVE-2026-64536, CVE-2026-64556, CVE-2026-64588, CVE-2026-64589, CVE-2026-64590, CVE-2026-64591, CVE-2026-64592, CVE-2026-64593, CVE-2026-64594, CVE-2026-64596, CVE-2026-64597, CVE-2026-64598, CVE-2026-64599, CVE-2026-64600, CVE-2026-64601, CVE-2026-64602, CVE-2026-64603, CVE-2026-64604, CVE-2026-68084, CVE-2026-68085, CVE-2026-68087, CVE-2026-68088, CVE-2026-68089, CVE-2026-68090, CVE-2026-68091, CVE-2026-68092, CVE-2026-68459, CVE-2026-68460, CVE-2026-68461, CVE-2026-74584, CVE-2026-80591)

USN-8801-1: Linux kernel (Azure CVM) vulnerabilities

2 days 22 hours ago
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observed. A local attacker could possibly use this to write to memory after permission to do so had been revoked, bypassing memory protections or escalating privileges. (CVE-2025-10263) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Character device driver; - Networking core; - IPv6 networking; - Unix domain sockets; (CVE-2026-52938, CVE-2026-53325, CVE-2026-53361, CVE-2026-53362)

USN-8800-1: Linux kernel (NVIDIA BaseOS) vulnerabilities

2 days 23 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - User-space API (UAPI); - Kernel build system; - ARM32 architecture; - ARM64 architecture; - RISC-V architecture; - S390 architecture; - x86 architecture; - Block layer subsystem; - Cryptographic API; - Compute Acceleration Framework; - Intel NPU Driver; - ACPI drivers; - Android drivers; - Drivers core; - Compressed RAM block device driver; - Bluetooth drivers; - Character device driver; - Hardware random number generator core; - CPU frequency scaling framework; - Hardware crypto device drivers; - Buffer Sharing and Synchronization framework; - Intel Stratix 10 firmware drivers; - FPGA Framework; - GPIO subsystem; - GPU drivers; - HID subsystem; - CoreSight HW tracing drivers; - I2C subsystem; - I3C subsystem; - IIO subsystem; - IIO ADC drivers; - InfiniBand drivers; - Input Device core drivers; - Input Device (Mouse) drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Multifunction device drivers; - Fastrpc Driver; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - MediaTek network drivers; - NTB driver; - NVME drivers; - NVMEM (Non Volatile Memory) drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - System reset/shutdown drivers; - Power sequencing drivers; - PTP clock framework; - Voltage and Current Regulator drivers; - RPMSG subsystem; - SLIMbus drivers; - SPI subsystem; - Media staging drivers; - Realtek RTL8723BS SDIO drivers; - VME bus staging drivers; - Trusted Execution Environment drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - Cadence USB3 driver; - ULPI bus; - DesignWare USB3 driver; - Faraday FOTG210 USB2 dual-role controller driver; - USB Gadget drivers; - USB Host Controller drivers; - USB ChaosKey driver; - Siemens ID Mouse USB driver; - IOWarrior USB driver; - LD Didactic USB driver; - LEGO USB Tower driver; - Intel USBIO USB I/O expander driver; - USS720 USB parallel port adapter driver; - MediaTek USB3 DRD driver; - USB Serial drivers; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - USB over IP driver; - VFIO drivers; - Framebuffer layer; - Virtio drivers; - BTRFS file system; - EROFS file system; - exFAT file system; - F2FS file system; - File systems infrastructure; - FUSE (File system in Userspace); - GFS2 file system; - HFS file system; - HFS+ file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - NTFS3 file system; - OCFS2 file system; - Proc file system; - SMB network file system; - UDF file system; - XFS file system; - Key management; - BPF subsystem; - Memory management; - Software nodes and device properties; - Glob pattern matching library; - Memory Management; - KVM subsystem; - Mellanox drivers; - Restartable sequences system call mechanism; - Socket messages infrastructure; - Network traffic control; - Bluetooth subsystem; - Netfilter; - Networking core; - Network sockets; - TCP network protocol; - io_uring subsystem; - IPC subsystem; - Audit subsystem; - Perf events; - Kernel fork() syscall; - Locking primitives; - Kernel module support; - Scheduler infrastructure; - Signal handling mechanism; - Timer subsystem; - Tracing infrastructure; - Debug objects infrastructure; - 6LoWPAN network protocol; - IEEE 802 network protocols; - 9P file system network protocol; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Devlink API; - HSR network protocol; - IEEE802154.4 network protocol; - IPv4 networking; - IPv6 networking; - XFRM subsystem; - L2TP protocol; - MAC80211 subsystem; - IEEE 802.15.4 subsystem; - Multipath TCP; - NetLabel subsystem; - Open vSwitch; - Phonet protocol; - Qualcomm IPC Router (QRTR); - RDS protocol; - SCTP protocol; - SMC sockets; - TIPC protocol; - TLS protocol; - Unix domain sockets; - VMware vSockets driver; - Wireless networking; - eXpress Data Path; - AppArmor security module; - Linux Security Modules (LSM) Framework; - Apple Onboard Audio ALSA driver; - ALSA framework; - FireWire sound drivers; - HD-audio driver; - Gravis UltraSound ALSA driver; - C-Media CMI8x38 ALSA driver; - ESS Solo-1 ALSA driver; - ICE1712/ICE1724 (Envy24) ALSA driver; - Yamaha YMFPCI ALSA driver; - Wolfson Microelectronics audio codecs; - SoundWire (SDCA) ASoC drivers; - USB sound devices; - Virtio sound driver; (CVE-2026-52908, CVE-2026-52909, CVE-2026-52910, CVE-2026-52917, CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52938, CVE-2026-52939, CVE-2026-52940, CVE-2026-52942, CVE-2026-52947, CVE-2026-52948, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53139, CVE-2026-53140, CVE-2026-53141, CVE-2026-53142, CVE-2026-53143, CVE-2026-53144, CVE-2026-53145, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53152, CVE-2026-53153, CVE-2026-53154, CVE-2026-53155, CVE-2026-53156, CVE-2026-53157, CVE-2026-53158, CVE-2026-53159, CVE-2026-53160, CVE-2026-53161, CVE-2026-53162, CVE-2026-53163, CVE-2026-53164, CVE-2026-53165, CVE-2026-53167, CVE-2026-53168, CVE-2026-53169, CVE-2026-53170, CVE-2026-53171, CVE-2026-53172, CVE-2026-53173, CVE-2026-53177, CVE-2026-53178, CVE-2026-53179, CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183, CVE-2026-53184, CVE-2026-53185, CVE-2026-53187, CVE-2026-53188, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192, CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53197, CVE-2026-53198, CVE-2026-53199, CVE-2026-53200, CVE-2026-53201, CVE-2026-53202, CVE-2026-53203, CVE-2026-53204, CVE-2026-53205, CVE-2026-53206, CVE-2026-53207, CVE-2026-53208, CVE-2026-53209, CVE-2026-53210, CVE-2026-53211, CVE-2026-53213, CVE-2026-53214, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53222, CVE-2026-53223, CVE-2026-53226, CVE-2026-53227, CVE-2026-53229, CVE-2026-53230, CVE-2026-53231, CVE-2026-53232, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235, CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239, CVE-2026-53240, CVE-2026-53241, CVE-2026-53242, CVE-2026-53243, CVE-2026-53244, CVE-2026-53245, CVE-2026-53248, CVE-2026-53249, CVE-2026-53250, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53257, CVE-2026-53258, CVE-2026-53259, CVE-2026-53261, CVE-2026-53262, CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274, CVE-2026-53275, CVE-2026-53276, CVE-2026-53325, CVE-2026-53326, CVE-2026-53327, CVE-2026-53328, CVE-2026-53329, CVE-2026-53330, CVE-2026-53331, CVE-2026-53332, CVE-2026-53333, CVE-2026-53334, CVE-2026-53335, CVE-2026-53336, CVE-2026-53337, CVE-2026-53338, CVE-2026-53339, CVE-2026-53340, CVE-2026-53341, CVE-2026-53342, CVE-2026-53343, CVE-2026-53344, CVE-2026-53345, CVE-2026-53346, CVE-2026-53347, CVE-2026-53348, CVE-2026-53349, CVE-2026-53350, CVE-2026-53351, CVE-2026-53352, CVE-2026-53353, CVE-2026-53355, CVE-2026-53356, CVE-2026-53361, CVE-2026-53362, CVE-2026-53363, CVE-2026-53366, CVE-2026-53381, CVE-2026-53382, CVE-2026-53383, CVE-2026-53384, CVE-2026-53385, CVE-2026-53386, CVE-2026-53387, CVE-2026-53388, CVE-2026-53389, CVE-2026-53390, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53395, CVE-2026-53396, CVE-2026-53397, CVE-2026-53398, CVE-2026-53399, CVE-2026-53400, CVE-2026-53401, CVE-2026-53402, CVE-2026-53403, CVE-2026-63794, CVE-2026-63795, CVE-2026-63796, CVE-2026-63797, CVE-2026-63798, CVE-2026-63799, CVE-2026-63800, CVE-2026-63801, CVE-2026-63802, CVE-2026-63803, CVE-2026-63804, CVE-2026-63805, CVE-2026-63806, CVE-2026-63807, CVE-2026-63808, CVE-2026-63809, CVE-2026-63810, CVE-2026-63811, CVE-2026-63812, CVE-2026-63813, CVE-2026-63814, CVE-2026-63815, CVE-2026-63816, CVE-2026-63817, CVE-2026-63818, CVE-2026-63819, CVE-2026-63820, CVE-2026-63821, CVE-2026-63822, CVE-2026-63823, CVE-2026-63824, CVE-2026-63825, CVE-2026-63826, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63831, CVE-2026-63832, CVE-2026-63833, CVE-2026-63834, CVE-2026-63835, CVE-2026-63836, CVE-2026-63867, CVE-2026-63868, CVE-2026-63869, CVE-2026-63870, CVE-2026-63871, CVE-2026-63873, CVE-2026-63874, CVE-2026-64187, CVE-2026-64188, CVE-2026-64189, CVE-2026-64191, CVE-2026-64192, CVE-2026-64205, CVE-2026-64206, CVE-2026-64207, CVE-2026-64244, CVE-2026-64245, CVE-2026-64246, CVE-2026-64247, CVE-2026-64249, CVE-2026-64251, CVE-2026-64253, CVE-2026-64254, CVE-2026-64255, CVE-2026-64256, CVE-2026-64258, CVE-2026-64259, CVE-2026-64260, CVE-2026-64261, CVE-2026-64262, CVE-2026-64263, CVE-2026-64264, CVE-2026-64265, CVE-2026-64266, CVE-2026-64267, CVE-2026-64268, CVE-2026-64269, CVE-2026-64270, CVE-2026-64271, CVE-2026-64272, CVE-2026-64273, CVE-2026-64274, CVE-2026-64275, CVE-2026-64276, CVE-2026-64277, CVE-2026-64278, CVE-2026-64279, CVE-2026-64280, CVE-2026-64282, CVE-2026-64283, CVE-2026-64284, CVE-2026-64285, CVE-2026-64286, CVE-2026-64287, CVE-2026-64288, CVE-2026-64289, CVE-2026-64290, CVE-2026-64291, CVE-2026-64292, CVE-2026-64293, CVE-2026-64294, CVE-2026-64295, CVE-2026-64296, CVE-2026-64297, CVE-2026-64298, CVE-2026-64299, CVE-2026-64300, CVE-2026-64301, CVE-2026-64302, CVE-2026-64303, CVE-2026-64304, CVE-2026-64305, CVE-2026-64306, CVE-2026-64307, CVE-2026-64308, CVE-2026-64309, CVE-2026-64310, CVE-2026-64312, CVE-2026-64313, CVE-2026-64314, CVE-2026-64315, CVE-2026-64316, CVE-2026-64317, CVE-2026-64318, CVE-2026-64319, CVE-2026-64320, CVE-2026-64321, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64325, CVE-2026-64326, CVE-2026-64327, CVE-2026-64328, CVE-2026-64329, CVE-2026-64330, CVE-2026-64331, CVE-2026-64332, CVE-2026-64333, CVE-2026-64334, CVE-2026-64335, CVE-2026-64336, CVE-2026-64337, CVE-2026-64338, CVE-2026-64339, CVE-2026-64340, CVE-2026-64341, CVE-2026-64342, CVE-2026-64343, CVE-2026-64344, CVE-2026-64345, CVE-2026-64346, CVE-2026-64347, CVE-2026-64348, CVE-2026-64350, CVE-2026-64351, CVE-2026-64352, CVE-2026-64353, CVE-2026-64354, CVE-2026-64355, CVE-2026-64356, CVE-2026-64357, CVE-2026-64358, CVE-2026-64359, CVE-2026-64360, CVE-2026-64361, CVE-2026-64362, CVE-2026-64363, CVE-2026-64364, CVE-2026-64365, CVE-2026-64366, CVE-2026-64367, CVE-2026-64368, CVE-2026-64369, CVE-2026-64370, CVE-2026-64371, CVE-2026-64372, CVE-2026-64373, CVE-2026-64374, CVE-2026-64375, CVE-2026-64376, CVE-2026-64377, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64388, CVE-2026-64389, CVE-2026-64390, CVE-2026-64391, CVE-2026-64392, CVE-2026-64393, CVE-2026-64394, CVE-2026-64395, CVE-2026-64396, CVE-2026-64397, CVE-2026-64398, CVE-2026-64399, CVE-2026-64400, CVE-2026-64401, CVE-2026-64402, CVE-2026-64403, CVE-2026-64404, CVE-2026-64405, CVE-2026-64406, CVE-2026-64407, CVE-2026-64408, CVE-2026-64409, CVE-2026-64410, CVE-2026-64411, CVE-2026-64412, CVE-2026-64413, CVE-2026-64414, CVE-2026-64415, CVE-2026-64416, CVE-2026-64417, CVE-2026-64418, CVE-2026-64419, CVE-2026-64420, CVE-2026-64421, CVE-2026-64422, CVE-2026-64423, CVE-2026-64424, CVE-2026-64425, CVE-2026-64426, CVE-2026-64428, CVE-2026-64429, CVE-2026-64430, CVE-2026-64432, CVE-2026-64433, CVE-2026-64434, CVE-2026-64435, CVE-2026-64436, CVE-2026-64438, CVE-2026-64439, CVE-2026-64440, CVE-2026-64441, CVE-2026-64442, CVE-2026-64443, CVE-2026-64444, CVE-2026-64445, CVE-2026-64446, CVE-2026-64447, CVE-2026-64448, CVE-2026-64449, CVE-2026-64450, CVE-2026-64451, CVE-2026-64452, CVE-2026-64453, CVE-2026-64454, CVE-2026-64455, CVE-2026-64456, CVE-2026-64457, CVE-2026-64458, CVE-2026-64459, CVE-2026-64460, CVE-2026-64461, CVE-2026-64462, CVE-2026-64463, CVE-2026-64464, CVE-2026-64465, CVE-2026-64466, CVE-2026-64467, CVE-2026-64468, CVE-2026-64469, CVE-2026-64470, CVE-2026-64471, CVE-2026-64472, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64476, CVE-2026-64477, CVE-2026-64478, CVE-2026-64479, CVE-2026-64480, CVE-2026-64481, CVE-2026-64482, CVE-2026-64483, CVE-2026-64484, CVE-2026-64485, CVE-2026-64486, CVE-2026-64487, CVE-2026-64488, CVE-2026-64489, CVE-2026-64490, CVE-2026-64491, CVE-2026-64492, CVE-2026-64493, CVE-2026-64494, CVE-2026-64495, CVE-2026-64496, CVE-2026-64497, CVE-2026-64499, CVE-2026-64500, CVE-2026-64501, CVE-2026-64502, CVE-2026-64503, CVE-2026-64504, CVE-2026-64505, CVE-2026-64507, CVE-2026-64508, CVE-2026-64509, CVE-2026-64510, CVE-2026-64511, CVE-2026-64512, CVE-2026-64513, CVE-2026-64514, CVE-2026-64529, CVE-2026-64531, CVE-2026-64536, CVE-2026-64556, CVE-2026-64588, CVE-2026-64589, CVE-2026-64590, CVE-2026-64591, CVE-2026-64592, CVE-2026-64593, CVE-2026-64594, CVE-2026-64596, CVE-2026-64597, CVE-2026-64598, CVE-2026-64599, CVE-2026-64600, CVE-2026-64601, CVE-2026-64602, CVE-2026-64603, CVE-2026-64604, CVE-2026-68084, CVE-2026-68085, CVE-2026-68087, CVE-2026-68088, CVE-2026-68089, CVE-2026-68090, CVE-2026-68091, CVE-2026-68092, CVE-2026-68459, CVE-2026-68460, CVE-2026-68461, CVE-2026-74584, CVE-2026-80591, CVE-2026-80952, CVE-2026-90386)

chromium-153.0.8010.52-1.el9

3 days 1 hour ago
FEDORA-EPEL-2026-3c8ff9535a Packages in this update:
  • chromium-153.0.8010.52-1.el9
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.fc45

3 days 1 hour ago
FEDORA-2026-6edc80db3f Packages in this update:
  • chromium-153.0.8010.52-1.fc45
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.el10_3

3 days 1 hour ago
FEDORA-EPEL-2026-d8fda74079 Packages in this update:
  • chromium-153.0.8010.52-1.el10_3
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.fc44

3 days 1 hour ago
FEDORA-2026-f910229c11 Packages in this update:
  • chromium-153.0.8010.52-1.fc44
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.el10_4

3 days 1 hour ago
FEDORA-EPEL-2026-ef33948ace Packages in this update:
  • chromium-153.0.8010.52-1.el10_4
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.fc43

3 days 1 hour ago
FEDORA-2026-dd12c89e57 Packages in this update:
  • chromium-153.0.8010.52-1.fc43
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

chromium-153.0.8010.52-1.el10_2

3 days 1 hour ago
FEDORA-EPEL-2026-db43927aa0 Packages in this update:
  • chromium-153.0.8010.52-1.el10_2
Update description:

Update to 153.0.8010.52

  • CVE-2026-91708: Race condition in Network
  • CVE-2026-91709: Type confusion in ServiceWorker
  • CVE-2026-91710: Use after free in WebAppInstalls
  • CVE-2026-91711: Out of bounds write in ServiceWorker
  • CVE-2026-91712: Race condition in Extensions
  • CVE-2026-91713: Missing authorization in Browser
  • CVE-2026-91714: Observable discrepancy in Fonts
  • CVE-2026-91715: Type confusion in ServiceWorker
  • CVE-2026-91716: Use after free in Auth
  • CVE-2026-91717: Missing authorization in Android
  • CVE-2026-91718: Use after free in Core
  • CVE-2026-91719: Code injection in XML
  • CVE-2026-91720: Uninitialized resource in ANGLE
  • CVE-2026-91721: Use after free in Internals
  • CVE-2026-91722: Use after free in Input
  • CVE-2026-91723: Race condition in WebAppInstalls
  • CVE-2026-91724: Use after free in Input
  • CVE-2026-91725: Observable discrepancy in CSS
  • CVE-2026-91726: Out of bounds read in WebGL
  • CVE-2026-91727: Incorrect reference resolution in Extensions
  • CVE-2026-91728: Integer overflow in V8
  • CVE-2026-91729: Use after free in DigitalCredentials
  • CVE-2026-91730: Incomplete cleanup in GetUserMedia
  • CVE-2026-91731: Type confusion in Compositing
  • CVE-2026-91732: Missing authorization in AppManifest
  • CVE-2026-91733: Improper state validation in Skia
  • CVE-2026-91734: Incorrect authorization in Core
  • CVE-2026-91735: Incorrect authorization in WebUI
  • CVE-2026-91736: Use after free in DOM
  • CVE-2026-91737: Use after free in PDF
  • CVE-2026-91738: Improper input validation in ANGLE
  • CVE-2026-91739: Missing authorization in Transactions Platform
  • CVE-2026-91740: Uninitialized resource in Skia
  • CVE-2026-91741: Type confusion in CacheStorage
  • CVE-2026-91742: Confused deputy in PriceTracking
  • CVE-2026-91743: Race condition in Core
  • CVE-2026-91744: Race condition in PlatformIntegration
  • CVE-2026-91745: Use after free in V8
  • CVE-2026-91746: Integer overflow in Compositing
  • CVE-2026-91747: Use after free in Skia
  • CVE-2026-91748: Race condition in Extensions
  • CVE-2026-91749: Use after free in Workers
  • CVE-2026-93372: Buffer overflow in WebGL
  • CVE-2026-93373: Use after free in Extensions
  • CVE-2026-93374: Use after free in Dawn
  • CVE-2026-93375: Incorrect reference resolution in Tracing
  • CVE-2026-93376: Out of bounds read in DataTransfer
  • CVE-2026-93377: Type confusion in V8
  • CVE-2026-93378: Missing authorization in Storage
  • CVE-2026-93379: Incorrect authorization in ORB
  • CVE-2026-93380: Race condition in FileSystem
  • CVE-2026-93381: Buffer overflow in PDFium
  • CVE-2026-93382: Use after free in PDFium
  • CVE-2026-93383: Information leak in Permissions
  • CVE-2026-93384: Server-side request forgery in Omnibox
  • CVE-2026-93385: Information leak in Paint
  • CVE-2026-93386: UI misrepresentation in WebAppInstalls
  • CVE-2026-93387: Improper state validation in Skia

USN-8799-1: libssh2 vulnerabilities

3 days 5 hours ago
It was discovered that libssh2 incorrectly handled certain publickey subsystem attributes. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58050) It was discovered that libssh2 did not properly initialize publickey list entries before parsing. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code. (CVE-2026-58051) It was discovered that libssh2 incorrectly handled certain SFTP server responses. A remote attacker controlling an SSH server could use this issue to cause libssh2 to crash or possibly execute arbitrary code. (CVE-2026-66032) It was discovered that libssh2 did not properly check bounds in certain publickey subsystem responses. A remote attacker controlling a malicious SSH server could use this issue to cause a denial of service or possibly execute arbitrary code.. (CVE-2026-66034)

kernel-7.2.7-300.fc45

3 days 9 hours ago
FEDORA-2026-4c098c462e Packages in this update:
  • kernel-7.2.7-300.fc45
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.

kernel-7.2.7-200.fc44

3 days 9 hours ago
FEDORA-2026-ca91e91bf0 Packages in this update:
  • kernel-7.2.7-200.fc44
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.

kernel-7.2.7-100.fc43

3 days 9 hours ago
FEDORA-2026-8202400aa0 Packages in this update:
  • kernel-7.2.7-100.fc43
Update description:

The 7.2.7 stable kernel update contains a number of important fixes across the tree.