Aggregator

bubblewrap-0.12.0-1.fc43

4 days 9 hours ago
FEDORA-2026-96e0765328 Packages in this update:
  • bubblewrap-0.12.0-1.fc43
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

bubblewrap-0.12.0-1.fc44

4 days 9 hours ago
FEDORA-2026-3d9bd126ce Packages in this update:
  • bubblewrap-0.12.0-1.fc44
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

GitPython-3.1.60-1.fc44

4 days 9 hours ago
FEDORA-2026-32054fb87a Packages in this update:
  • GitPython-3.1.60-1.fc44
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

USN-8683-1: libheif vulnerabilities

4 days 12 hours ago
Feng Ning discovered that libheif incorrectly handled certain image transforms. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-62289) Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS. (CVE-2026-62291)

USN-8682-1: Bind vulnerabilities

4 days 12 hours ago
Vitaly Simonovich discovered that Bind could exhaust memory during GSS-API TKEY negotiation. A remote attacker could possibly use this issue to cause Bind to use excessive resources, leading to a denial of service. (CVE-2026-3039) Shuhan Zhang discovered that Bind incorrectly handled self-pointed glue records. A remote attacker could possibly use this issue to use Bind in denial of service amplification attacks against other systems. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-3592) It was discovered that Bind incorrectly handled DNS messages whose class was not IN. A remote attacker could possibly use this issue to cause Bind to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-5946)

GitPython-3.1.60-1.fc45

4 days 14 hours ago
FEDORA-2026-63e7132525 Packages in this update:
  • GitPython-3.1.60-1.fc45
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

bluez-5.87-6.fc43

4 days 14 hours ago
FEDORA-2026-d4eec45564 Packages in this update:
  • bluez-5.87-6.fc43
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc44

4 days 14 hours ago
FEDORA-2026-1fba3f22c9 Packages in this update:
  • bluez-5.87-6.fc44
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-7.fc45

4 days 14 hours ago
FEDORA-2026-84b4f1c43a Packages in this update:
  • bluez-5.87-7.fc45
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc43

4 days 16 hours ago
FEDORA-2026-432a1ef311 Packages in this update:
  • bluez-5.87-5.fc43
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc44

4 days 16 hours ago
FEDORA-2026-01488a5766 Packages in this update:
  • bluez-5.87-5.fc44
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc45

4 days 16 hours ago
FEDORA-2026-f4d10955d6 Packages in this update:
  • bluez-5.87-6.fc45
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bind-9.18.50-2.fc43

4 days 19 hours ago
FEDORA-2026-875d2a5154 Packages in this update:
  • bind-9.18.50-2.fc43
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-2.fc44

4 days 20 hours ago
FEDORA-2026-d87e7f498a Packages in this update:
  • bind-9.18.50-2.fc44
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)