5 days 12 hours ago
FEDORA-2026-9e18ff28a6
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.8
5 days 12 hours ago
It was discovered that Python's http.cookies module incorrectly handled
control characters in certain cookie operations. An attacker could possibly
use this issue to inject arbitrary content. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)
It was discovered that the Python pyexpat module was vulnerable to
unbounded recursion in the Expat XML parser. An attacker could possibly use
this issue to cause Python to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)
It was discovered that Python's tarfile module did not correctly apply the
filter parameter when extracting hard links. An attacker could possibly use
this issue to cause files to be extracted with an unexpected uid or gid,
bypassing the restrictions requested via filter='data'. (CVE-2026-4360)
It was discovered that Python's http.cookies module incorrectly escaped
values in the js_output() method. An attacker could possibly use this issue
to inject arbitrary JavaScript. (CVE-2026-6019)
It was discovered that Python's html.parser module incorrectly handled
repeated unterminated markup declarations. An attacker could possibly use
this issue to cause Python to consume excessive CPU resources, leading to a
denial of service. (CVE-2026-15308)
5 days 14 hours ago
It was discovered that PHP incorrectly handled backslash escaping in the
PostgreSQL extension. An attacker could use this issue to perform SQL
injection attacks. (CVE-2026-17543)
It was discovered that PHP incorrectly handled certain inputs to the
bccomp() function. An attacker could use this issue to cause an out-of-
bounds write, resulting in a denial of service or possibly execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-17544)
It was discovered that PHP incorrectly handled circular symbolic links in
phar archives. An attacker could use this issue to cause unbounded
recursion, resulting in a denial of service. (CVE-2026-7260)
5 days 15 hours ago
USN-8737-1 fixed vulnerabilities in GNU C Library. This update provides
the corresponding fixes for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that GNU C Library had a buffer overflow in the strfmon
function when handling right-justification padding. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-19499)
It was discovered that GNU C Library had an out-of-bounds stack array
access in the tdelete function. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-19542)
It was discovered that GNU C Library incorrectly handled memory when
calling wordexp with the WRDE_APPEND flag. An attacker could possibly use
this issue to cause a denial of service. (CVE-2026-6368)
It was discovered that GNU C Library had a stack overflow in the wordexp
function when expanding paths beginning with a tilde followed by a long
username. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-6791)
It was discovered that GNU C Library had a hang in the SHIFT_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-77117)
It was discovered that GNU C Library had a hang in the EUC_JISX0213
character set converter. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-80489)
5 days 15 hours ago
FEDORA-2026-b3bccd6a30
Packages in this update:
Update description:
This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.
5 days 15 hours ago
FEDORA-2026-da06bdeb38
Packages in this update:
Update description:
This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.
5 days 15 hours ago
FEDORA-2026-ab0c751524
Packages in this update:
Update description:
This rpm updates included resolv gem to 0.7.2 to resolve CVE security issues.
5 days 15 hours ago
FEDORA-2026-fbf03424ec
Packages in this update:
Update description:
Update resolv gem in ruby.src to resolve security issues.
5 days 16 hours ago
FEDORA-EPEL-2026-50f70dc75c
Packages in this update:
- stb-0^20260802.2c980bb-2.el10_4
Update description:
Patch stb_sprintf: security fix for CVE-2026-79516
5 days 16 hours ago
FEDORA-2026-0cae436fa5
Packages in this update:
- stb-0^20260802.2c980bb-2.fc43
Update description:
Patch stb_sprintf: security fix for CVE-2026-79516
5 days 16 hours ago
FEDORA-2026-195d764078
Packages in this update:
Update description:
1.653
Fix test for 32bit-perl
Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030)
Tighten symlink outside of f_dir (CVE-2026-15392) check
5 days 16 hours ago
FEDORA-2026-2bf3261da2
Packages in this update:
Update description:
1.653
Fix test for 32bit-perl
Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030)
Tighten symlink outside of f_dir (CVE-2026-15392) check
5 days 16 hours ago
FEDORA-2026-a4674c5df6
Packages in this update:
Update description:
1.653
Fix test for 32bit-perl
Fix arbitrary module and file loading via dbm_type/dbm_mldbm (CVE-2026-78030)
Tighten symlink outside of f_dir (CVE-2026-15392) check
5 days 17 hours ago
FEDORA-2026-2a592f622a
Packages in this update:
- stb-0^20260802.2c980bb-2.fc44
Update description:
Patch stb_sprintf: security fix for CVE-2026-79516
5 days 17 hours ago
FEDORA-2026-63e7be05c3
Packages in this update:
- stb-0^20260802.2c980bb-2.fc45
Update description:
Patch stb_sprintf: security fix for CVE-2026-79516
5 days 17 hours ago
FEDORA-2026-ee846faf9d
Packages in this update:
- stb-0^20260802.2c980bb-2.fc46
Update description:
Automatic update for stb-0^20260802.2c980bb-2.fc46.
Changelog
* Thu Sep 10 2026 Benjamin A. Beasley <
code@musicinmybrain.net> - 0^20260802.2c980bb-2
- Patch stb_sprintf: security fix for CVE-2026-79516
- Fixes RHBZ#2531291; Fixes RHBZ#2531290
* Thu Sep 10 2026 Benjamin A. Beasley <
code@musicinmybrain.net> - 0^20260802.2c980bb-1
- Update to 0^20260802.2c980bb
5 days 17 hours ago
It was discovered that Netty incorrectly validates the bailiwick of NS
records. An attacker could possibly use this issue to facilitate DNS
cache poisoning attacks.
5 days 17 hours ago
FEDORA-2026-4401b94ad0
Packages in this update:
Update description:
New version 10.7.1
Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912
5 days 17 hours ago
FEDORA-2026-c3fb234b87
Packages in this update:
Update description:
New version 10.7.1
Fix for CVE-2026-0799, CVE-2026-6244, CVE-2026-6554, CVE-2026-18238, CVE-2026-18313, CVE-2026-31911, CVE-2026-31912
5 days 17 hours ago
It was discovered that Flatpak did not properly validate paths in
sandbox-expose options. A malicious or compromised Flatpak app could
use app-controlled symlinks to access arbitrary host files and gain
code execution in the host context. This issue was addressed in Ubuntu
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-34078)
It was discovered that Flatpak did not properly validate paths when
removing outdated ld.so cache files. A malicious or compromised Flatpak
app could use this issue to delete arbitrary files on the host.
(CVE-2026-34079)