3 days 17 hours ago
Sean Gilligan discovered that AIOHTTP did not properly limit memory
usage when processing HTTP headers and trailers. An attacker could
possibly use this issue to consume excessive system resources, resulting
in a denial of service. (CVE-2026-22815)
It was discovered that AIOHTTP did not properly limit the size of its
DNS cache. An attacker could possibly use this issue to consume
excessive system resources, resulting in a denial of service.
(CVE-2026-34513)
Mingi Jung discovered that AIOHTTP did not properly sanitize the
content_type parameter. An attacker could possibly use this issue to
inject malicious HTTP headers, resulting in HTTP response splitting.
(CVE-2026-34514)
It was discovered that AIOHTTP did not properly limit memory usage when
processing multipart headers. An attacker could possibly use this issue
to consume excessive system resources, resulting in a denial of service.
(CVE-2026-34516)
3 days 17 hours ago
FEDORA-2026-68853bb50c
Packages in this update:
- dokuwiki-20250514b-4.fc43
Update description:
Backport some security fixes
3 days 17 hours ago
FEDORA-2026-d37b1b981a
Packages in this update:
- dokuwiki-20250514b-6.fc44
Update description:
Backport some security fixes
3 days 18 hours ago
FEDORA-2026-9af234bcd6
Packages in this update:
Update description:
Fixes for CVE-2026-6067 and CVE-2026-6068.
3 days 20 hours ago
It was discovered that Exim incorrectly handled certain command line
options. A local attacker could possibly use this issue to access files
outside of the spool area.
It was discovered that Exim incorrectly handled string expansion in
.local files. A local attacker could possibly use this issue to escalate
privileges.
3 days 21 hours ago
It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)
Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)
3 days 21 hours ago
It was discovered that Gawk incorrectly handled memory when processing
input using the getline redirection. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-40467)
It was discovered that Gawk incorrectly handled certain integer
calculations when allocating memory. An attacker could possibly use
this issue to cause a denial of service or overwrite heap memory with
attacker-controlled data. (CVE-2026-40468)
It was discovered that Gawk incorrectly handled certain integer
calculations when performing substitutions. An attacker could possibly
use this issue to cause a denial of service. (CVE-2026-40469)
It was discovered that Gawk incorrectly handled memory when reading
directory entries. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-40553)
3 days 22 hours ago
Version:next-20260722 (linux-next)
Released:2026-07-22
3 days 22 hours ago
3 days 22 hours ago
USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could
cause tar to fail to extract old archives that recorded a nonzero size for
directory entries, resulting in a regression.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that tar incorrectly handled certain crafted archive files.
An attacker could possibly use this to inject hidden files with
attacker-controlled content, bypassing pre-extraction inspection mechanisms.
3 days 22 hours ago
FEDORA-2026-30e8e9a2b2
Packages in this update:
Update description:
Update to 5.3.1
3 days 22 hours ago
FEDORA-2026-256592dfe7
Packages in this update:
Update description:
Update to 5.3.1
4 days ago
It was discovered that HTML-Parser incorrectly handled entity references
when the input string was identical to an entity value in the lookup table.
An attacker could possibly use this issue to obtain sensitive information.
4 days ago
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS image format data. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40333)
It was discovered that libgphoto2 did not properly null-terminate buffers
when parsing Canon folder entries. An attacker with physical access could
possibly use this issue to obtain sensitive information. (CVE-2026-40334)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing device property values. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40335)
It was discovered that libgphoto2 had a memory leak when parsing Sony
device property descriptors. An attacker with physical access could
possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-40336)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property enumeration data. An attacker
with physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40338)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing Sony device property form flags. An attacker with
physical access could possibly use this issue to obtain sensitive
information. (CVE-2026-40339)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing object information. An attacker with physical
access could possibly use this issue to obtain sensitive information.
(CVE-2026-40340)
It was discovered that libgphoto2 did not properly validate buffer
boundaries when parsing EOS focus information. An attacker with physical
access could possibly use this issue to cause libgphoto2 to crash,
resulting in a denial of service. (CVE-2026-40341)
4 days ago
It was discovered that Kerberos had an integer underflow vulnerability
in the berval2tl_data() function. An attacker could possibly use this issue
to cause Kerberos to crash, resulting in a denial of service.
(CVE-2026-11850)
It was discovered that Kerberos had vulnerabilities in its NegoEx mechanism
parsing. A remote attacker could possibly use these issues to cause
Kerberos to crash, resulting in a denial of service. (CVE-2026-40355,
CVE-2026-40356)
4 days 1 hour ago
It was discovered that GStreamer Good Plugins incorrectly handled certain
Matroska files. An attacker could possibly use this issue to cause
GStreamer Good Plugins to crash, resulting in a denial of service. This
issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39043)
It was discovered that GStreamer Good Plugins incorrectly handled certain
WAV files. An attacker could possibly use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-39044)
It was discovered that GStreamer Good Plugins incorrectly handled certain
WavPack audio files. An attacker could use this issue to cause GStreamer
Good Plugins to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-53705)
4 days 1 hour ago
It was discovered that GIFLIB incorrectly handled certain GIF image files.
If a user or automated system were tricked into opening a specially crafted
GIF file, a remote attacker could use this issue to cause GIFLIB to crash,
resulting in a denial of service, or possibly execute arbitrary code.
4 days 2 hours ago
FEDORA-EPEL-2026-c4fcc3f6fd
Packages in this update:
- ImageMagick-6.9.13.52-2.el8
Update description:
Add upstream patch to revert the unexpected soname change
Update to upstream 6.9.13-52
4 days 4 hours ago
FEDORA-2026-0b2cbe3d44
Packages in this update:
Update description:
Update to version 22.23.1
4 days 7 hours ago
FEDORA-2026-1b33b87fff
Packages in this update:
Update description:
- New upstream release (153.0)
- Updated to latest upstream (153.0)