6 days 16 hours ago
It was discovered that libeconf did not properly check the size of
input when copying data to a buffer. An attacker could possibly use
this issue to cause libeconf to crash, resulting in a denial of
service.
6 days 16 hours ago
It was discovered that tar-fs did not properly limit paths when
extracting crafted tar files. An attacker could possibly use this
issue to write or overwrite files outside the intended extraction
directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu
24.04 LTS. (CVE-2024-12905)
It was discovered that tar-fs did not properly validate extraction
paths for certain crafted tar archives. An attacker could possibly
use this issue to write files outside the intended extraction
directory. This issue only affected Ubuntu 22.04 LTS and Ubuntu
24.04 LTS. (CVE-2025-48387)
It was discovered that tar-fs had a symlink validation bypass when
extracting crafted tar files. An attacker could possibly use this
issue to write files outside the intended extraction directory.
(CVE-2025-59343)
6 days 17 hours ago
It was discovered that Luanti, when using LuaJIT, did not properly
enforce Lua sandbox restrictions. An attacker could possibly use
this issue to execute arbitrary code. (CVE-2026-40959)
It was discovered that Luanti did not properly restrict access to
insecure environments. An attacker could possibly use this issue to
obtain unintended access to the insecure environment or HTTP API.
(CVE-2026-40960)
6 days 17 hours ago
It was discovered that Dovecot incorrectly treated some variable expansion
pipelines as safe in authentication filters. An attacker could possibly use
this issue to perform SQL or LDAP injection attacks. This issue only
affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-27851)
It was discovered that Dovecot incorrectly verified SCRAM TLS channel
binding in certain base64 exchanges. A remote attacker could possibly use
this issue to obtain sensitive information in a machine-in-the-middle
attack. (CVE-2026-33603)
It was discovered that Dovecot incorrectly enforced Sieve script CPU
limits. An attacker could possibly use this issue to cause Dovecot to use
excessive resources, leading to a denial of service. (CVE-2026-40016)
It was discovered that Dovecot incorrectly handled certain IMAP SETACL
commands. An attacker could possibly use this issue to spam folders to
other users. (CVE-2026-40020)
It was discovered that Dovecot incorrectly handled excessive IMAP bracing.
An attacker could possibly use this issue to cause Dovecot to use excessive
resources, leading to a denial of service. (CVE-2026-42006)
6 days 17 hours ago
It was discovered that Apache Commons Lang incorrectly handled recursion
in the ClassUtils.getClass method. An attacker could possibly use this
issue to cause Apache Commons Lang to crash, resulting in a denial of
service.
6 days 17 hours ago
Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.
MySQL has been updated to 8.0.46 in Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
Ubuntu 25.10 and Ubuntu 26.04 LTS have been updated to MySQL 8.4.9.
In addition to security fixes, the updated packages contain bug fixes, new
features, and possibly incompatible changes.
Please see the following for more information:
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-46.html
https://dev.mysql.com/doc/relnotes/mysql/8.4/en/news-8-4-9.html
https://www.oracle.com/security-alerts/cpuapr2026.html
6 days 20 hours ago
It was discovered that XZ Utils did not properly manage memory when
attempting to append data to a decoded index that contained no records.
An attacker could possibly use this issue to cause XZ Utils to crash,
resulting in a denial of service, or execute arbitrary code.
6 days 22 hours ago
FEDORA-EPEL-2026-189ae0571a
Packages in this update:
- perl-Sereal-5.006-1.el10_2
- perl-Sereal-Decoder-5.006-1.el10_2
- perl-Sereal-Encoder-5.006-1.el10_2
Update description:
This update includes a security fix to make sure that COPY tags cannot be used to read past end of the buffer.
1 week ago
1 week ago
1 week ago
FEDORA-2026-557e726e74
Packages in this update:
- xorg-x11-server-Xwayland-24.1.12-1.fc43
Update description:
Update to xwayland 24.1.12, Security fixes for: ZDI-CAN-30136,
ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163,
ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168
1 week ago
FEDORA-2026-c3ea7d7b0e
Packages in this update:
- xorg-x11-server-21.1.23-1.fc43
Update description:
Update to xserver 21.1.23, Security fixes for: ZDI-CAN-30136,
ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164,
ZDI-CAN-30165, ZDI-CAN-30168
1 week ago
FEDORA-2026-7e38f57cef
Packages in this update:
- xorg-x11-server-21.1.23-1.fc44
Update description:
Update to xserver 21.1.23, security fixes for:
ZDI-CAN-30136, ZDI-CAN-30159, ZDI-CAN-30160,
ZDI-CAN-30161, ZDI-CAN-30163, ZDI-CAN-30164,
ZDI-CAN-30165, ZDI-CAN-30168
1 week ago
FEDORA-2026-f98eff99c4
Packages in this update:
- xorg-x11-server-Xwayland-24.1.12-1.fc44
Update description:
Update to xwayland 24.1.12, security fixes for ZDI-CAN-30136,
ZDI-CAN-30159, ZDI-CAN-30160, ZDI-CAN-30161, ZDI-CAN-30163,
ZDI-CAN-30164, ZDI-CAN-30165, ZDI-CAN-30168
1 week ago
A security issue was discovered in the Linux kernel.
An attacker could possibly use this to compromise the system.
This update corrects flaws in the following subsystem:
- Packet sockets;
(CVE-2026-31504)
1 week ago
Version:next-20260601 (linux-next)
Released:2026-06-01
1 week ago
USN-8209-1 fixed vulnerabilities in Little CMS. This update contains the
fixes for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that Little CMS incorrectly handled certain malformed ICC
profiles. An attacker could use this issue to cause Little CMS to crash,
resulting in a denial of service, or possibly execute arbitrary code.
1 week ago
1 week ago
1 week ago