Aggregator

USN-8352-1: LibreOffice vulnerability

1 week ago
Duc Anh Nguyen discovered that LibreOffice incorrectly handled mismatched encryption salt parameters in crafted OOXML documents. An attacker could use this issue to cause LibreOffice to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8351-1: Linux kernel (Low Latency) vulnerabilities

1 week ago
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - Packet sockets; - TLS protocol; (CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028)

USN-8350-1: Linux kernel (NVIDIA Tegra) vulnerabilities

1 week ago
It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-31431) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Ethernet bonding driver; - Packet sockets; - TLS protocol; (CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033, CVE-2026-43077, CVE-2026-43078, CVE-2026-46028)

USN-8349-1: rsync vulnerabilities

1 week ago
Calum Hutton discovered that rsync contained a heap-based out-of-bounds read when handling file transfers. A remote attacker with read access to an rsync server could possibly use this issue to cause a denial of service. (CVE-2025-10158) Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that rsync daemons configured without chroot protection were exposed to a race condition on parent path components. A local attacker with write access to a module could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-29518) It was discovered that rsync did not properly validate a length value while sorting extended attributes. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-41035) It was discovered that rsync performed reverse-DNS lookups after chrooting in some daemon configurations. A remote attacker could possibly use this issue to bypass hostname-based access controls and access network services. (CVE-2026-43617) Omar Elsayed discovered that rsync did not properly check for integer overflows while decoding compressed tokens. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2026-43618) Andrew Tridgell discovered that rsync did not fully fix a symlink race condition in path-based system calls for daemons configured without chroot protection. A local attacker could possibly use this issue to overwrite files, obtain sensitive information, or escalate privileges. (CVE-2026-43619) Pratham Gupta discovered that rsync did not properly validate an index while processing file lists. A remote attacker could possibly use this issue to cause rsync to crash, resulting in a denial of service. (CVE-2026-43620) Michal Ruprich discovered that rsync contained an off-by-one error while handling HTTP proxy responses. An attacker able to intercept network communications or a malicious proxy server could possibly use this issue to cause a denial of service. (CVE-2026-45232)

LSN-120-1: Kernel Live Patch Security Notice

1 week ago
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length or offset exceeds sg_cnt and then use bogus sg->length/offset values, leading to _copy_to_iter() GPF/KASAN. It was discovered that the Linux kernel algif_aead module did not properly handle in-place cryptographic operations. This flaw is known as Copy Fail. A local attacker could use this to escalate privileges, or possibly escape a container.)(CVE-2026-31431)

objfw-1.5.5-1.el10_2

1 week 1 day ago
FEDORA-EPEL-2026-943bd8b933 Packages in this update:
  • objfw-1.5.5-1.el10_2
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.

objfw-1.5.5-1.fc43

1 week 1 day ago
FEDORA-2026-d1580bc2d5 Packages in this update:
  • objfw-1.5.5-1.fc43
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.

objfw-1.5.5-1.el8

1 week 1 day ago
FEDORA-EPEL-2026-8865722a0e Packages in this update:
  • objfw-1.5.5-1.el8
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.

objfw-1.5.5-1.el9

1 week 1 day ago
FEDORA-EPEL-2026-74e26da380 Packages in this update:
  • objfw-1.5.5-1.el9
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.

objfw-1.5.5-1.el10_3

1 week 1 day ago
FEDORA-EPEL-2026-bea3e12246 Packages in this update:
  • objfw-1.5.5-1.el10_3
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.

objfw-1.5.5-1.fc44

1 week 1 day ago
FEDORA-2026-729e540d74 Packages in this update:
  • objfw-1.5.5-1.fc44
Update description:

Update to 1.5.5, containing many bug fixes, some also security related.