Aggregator
gdk-pixbuf2-2.44.6^really2.44.4-2.fc43
- gdk-pixbuf2-2.44.6^really2.44.4-2.fc43
Fixes CVE-2026-16768: https://access.redhat.com/security/cve/CVE-2026-16768
gdk-pixbuf2-2.44.6^really2.44.4-2.fc44
- gdk-pixbuf2-2.44.6^really2.44.4-2.fc44
Fixes CVE-2026-16768: https://access.redhat.com/security/cve/CVE-2026-16768
gdk-pixbuf2-2.44.8-2.fc45
- gdk-pixbuf2-2.44.8-2.fc45
Fixes CVE-2026-16768: https://access.redhat.com/security/cve/CVE-2026-16768
bubblewrap-0.12.0-1.fc43
- bubblewrap-0.12.0-1.fc43
- Update to 0.12.0
- Fixes GHSA-pxhw-h44j-8pfx
- Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon
bubblewrap-0.12.0-1.fc44
- bubblewrap-0.12.0-1.fc44
- Update to 0.12.0
- Fixes GHSA-pxhw-h44j-8pfx
- Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon
bubblewrap-0.12.0-1.fc45
- bubblewrap-0.12.0-1.fc45
- Update to 0.12.0
- Fixes GHSA-pxhw-h44j-8pfx
GitPython-3.1.60-1.fc44
- GitPython-3.1.60-1.fc44
Update to 3.1.60.
Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.
USN-8683-1: libheif vulnerabilities
USN-8682-1: Bind vulnerabilities
GitPython-3.1.60-1.fc45
- GitPython-3.1.60-1.fc45
Update to 3.1.60.
Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.
bluez-5.87-6.fc43
- bluez-5.87-6.fc43
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-6.fc44
- bluez-5.87-6.fc44
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-7.fc45
- bluez-5.87-7.fc45
BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
next-20260826: linux-next
bluez-5.87-5.fc43
- bluez-5.87-5.fc43
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-5.fc44
- bluez-5.87-5.fc44
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bluez-5.87-6.fc45
- bluez-5.87-6.fc45
A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.
bind-9.18.50-2.fc43
- bind-9.18.50-2.fc43
Fixes multiple CVEs
- Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
- Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
- Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
- Potential memory usage beyond configured limits (CVE-2026-11622)
- Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
- Incorrect acceptance of NSEC3 records (CVE-2026-10723)
- Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
- DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)
bind-9.18.50-2.fc44
- bind-9.18.50-2.fc44
Fixes multiple CVEs
- Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
- Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
- Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
- Potential memory usage beyond configured limits (CVE-2026-11622)
- Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
- Incorrect acceptance of NSEC3 records (CVE-2026-10723)
- Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
- DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)