4 days 2 hours ago
FEDORA-2026-2b8ae366f4
Packages in this update:
Update description:
Update to 3.4.8.
4 days 2 hours ago
Michael Randrianantenaina discovered that GStreamer's Ugly Plugins
incorrectly handled certain malformed RealMedia files. If a user were
tricked into opening a crafted media file, an attacker could possibly use
this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-38103,
CVE-2023-38104)
It was discovered that GStreamer's Ugly Plugins incorrectly handled certain
malformed ASF and RealMedia files. If a user were tricked into opening a
crafted media file, an attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-2920,
CVE-2026-2922)
Tianshuo Han discovered that GStreamer's Ugly Plugins incorrectly handled
certain malformed RealMedia files. If a user were tricked into opening a
crafted media file, an attacker could possibly use this issue to cause a
denial of service or expose sensitive information. (CVE-2026-53703,
CVE-2026-53704)
Seonwook Kim discovered that GStreamer's Ugly Plugins incorrectly handled
certain malformed ASF files. If a user were tricked into opening a crafted
media file, an attacker could possibly use this issue to cause a denial of
service or expose sensitive information. (CVE-2026-19389)
4 days 2 hours ago
FEDORA-2026-25e13e26b3
Packages in this update:
- rust-onefetch-2.28.1-4.fc45
Update description:
Backport fix for CVE-2026-100866 from 3.0.0
4 days 2 hours ago
It was discovered that Go Networking did not properly handle server
errors after sending a GOAWAY frame during HTTP/2 connection shutdown,
which could cause the connection to hang. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2022-27664)
It was discovered that Go Networking had quadratic complexity when
decoding HPACK headers in HTTP/2 streams. A remote attacker could
possibly use this issue to cause Go Networking to use excessive
resources, leading to a denial of service. (CVE-2022-41723)
It was discovered that Go Networking incorrectly rendered text nodes
outside of the HTML namespace literally, causing text that should be
escaped to not be escaped. A remote attacker could possibly use this
issue to perform cross-site scripting attacks. (CVE-2023-3978)
Guido Vranken discovered that Go Networking processed certain inputs to
the HTML parsing functions non-linearly with respect to their length. A
remote attacker could possibly use this issue to cause Go Networking to
use excessive resources, leading to a denial of service.
(CVE-2024-45338)
Sean Ng discovered that Go Networking incorrectly interpreted tags in
foreign content with unquoted attribute values ending with a solidus
character as self-closing, which could result in content being placed
in the wrong scope during DOM construction. A remote attacker could
possibly use this issue to perform cross-site scripting attacks.
(CVE-2025-22872)
It was discovered that Go Networking had quadratic parsing complexity
when processing certain HTML inputs. A remote attacker could possibly
use this issue to cause Go Networking to use excessive resources,
leading to a denial of service. (CVE-2025-47911)
It was discovered that Go Networking could enter an infinite loop when
parsing certain HTML inputs. A remote attacker could possibly use this
issue to cause Go Networking to use excessive resources, leading to a
denial of service. (CVE-2025-58190)
It was discovered that Go Networking incorrectly accepted
Punycode-encoded labels that decoded to ASCII-only labels when
processing internationalized domain names. A remote attacker could
possibly use this issue to bypass access control restrictions and
escalate privileges. (CVE-2026-39821)
4 days 3 hours ago
FEDORA-2026-0bf84c3130
Packages in this update:
- log4net-3.5.0-1.fc44
- nant-0.92-43.fc44
Update description:
Update log4net to 3.5.0. Nant is rebuilt (only dependency in Fedora).
4 days 3 hours ago
FEDORA-2026-6515ac01d8
Packages in this update:
- log4net-3.5.0-1.fc45
- nant-0.92-43.fc45
Update description:
Update log4net to 3.5.0. Nant is rebuilt (only dependency in Fedora).
4 days 3 hours ago
FEDORA-2026-588bc7e01c
Packages in this update:
- log4net-3.5.0-1.fc43
- nant-0.92-43.fc43
Update description:
Update log4net to 3.5.0. Nant is rebuilt (only dependency in Fedora).
4 days 5 hours ago
FEDORA-EPEL-2026-7addd7a2bf
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
FEDORA-2026-0344d4bcdb
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
FEDORA-EPEL-2026-79e0927ac1
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
FEDORA-2026-a5b9928f10
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
FEDORA-2026-773e644d9d
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
FEDORA-EPEL-2026-05efddaadc
Packages in this update:
Update description:
Update to version 2.1.6.
Release notes:
4 days 5 hours ago
Guillem Lefait discovered that lxml incorrectly handled certain URL
attributes. A remote attacker could possibly use this issue to bypass
URL sanitization, leading to a cross-site scripting attack.
(CVE-2026-49825)
Qiu Sihao discovered that lxml incorrectly handled untrusted XML input.
A remote attacker could possibly use this issue to read local files and
expose sensitive information. This issue was only addressed in Ubuntu 24.04
LTS and Ubuntu 26.04 LTS. (CVE-2026-41066)
4 days 8 hours ago
Version:next-20261007 (linux-next)
Released:2026-10-07
4 days 8 hours ago
FEDORA-EPEL-2026-67a0bf9fc1
Packages in this update:
Update description:
Update to upstream 2.7.8 release
4 days 8 hours ago
It was discovered that Sudo did not properly handle time-based access
restrictions when sudoers rules used NOTBEFORE or NOTAFTER with
timestamps omitting the trailing timezone indicator. A local attacker
could possibly use this issue to execute commands outside the intended
time window by manipulating the TZ environment variable.
4 days 8 hours ago
FEDORA-2026-112c430ffc
Packages in this update:
- xorg-x11-server-Xwayland-24.1.14-1.fc43
Update description:
Update to xwayland 24.1.14
CVE fix for: CVE-2026-88812, CVE-2026-93515, CVE-2026-93516
CVE-2026-93517, CVE-2026-93518, CVE-2026-93519,
CVE-2026-93520, CVE-2026-93521, CVE-2026-93522,
CVE-2026-93523, CVE-2026-93524, CVE-2026-93536
4 days 8 hours ago
It was discovered that Poppler had an integer overflow in
FoFiTrueType::cvtSfnts. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102620)
It was discovered that Poppler had an integer overflow in
SplashClip::clipToPath. An attacker could possibly use this issue to
cause Poppler to crash, resulting in a denial of service, or execute
arbitrary code.
(CVE-2026-102621)
It was discovered that Poppler had a null pointer dereference in
JBIG2Stream. An attacker could possibly use this issue to cause
Poppler to crash, resulting in a denial of service.
(CVE-2026-93312)
It was discovered that Poppler had an integer overflow in
JBIG2Stream::readCodeTableSeg. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93313)
It was discovered that Poppler had an integer overflow in
FoFiTrueType::mapCodeToGID. An attacker could possibly use this
issue to cause Poppler to crash, resulting in a denial of service,
or execute arbitrary code.
(CVE-2026-93314)
4 days 8 hours ago
FEDORA-2026-7d4732cbab
Packages in this update:
Update description:
Fix for CVE-2026-96512