1 week ago
FEDORA-2026-1ab61e6e20
Packages in this update:
Update description:
This is an update fixing several security related problems in putty.
1 week ago
Warisjeet Singh discovered that Exim with SUPPORT_PROXY enabled did not
properly handle memory before SMTP authentication. A remote attacker could
possibly use this issue to obtain sensitive information.
1 week ago
Duc Anh Nguyen discovered that LibreOffice incorrectly handled mismatched
encryption salt parameters in crafted OOXML documents. An attacker could
use this issue to cause LibreOffice to crash, resulting in a denial of
service, or possibly execute arbitrary code.
1 week ago
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Ethernet bonding driver;
- Packet sockets;
- TLS protocol;
(CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033,
CVE-2026-43077, CVE-2026-43078, CVE-2026-46028)
1 week ago
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container. (CVE-2026-31431)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- Ethernet bonding driver;
- Packet sockets;
- TLS protocol;
(CVE-2026-31419, CVE-2026-31504, CVE-2026-31533, CVE-2026-43033,
CVE-2026-43077, CVE-2026-43078, CVE-2026-46028)
1 week ago
Calum Hutton discovered that rsync contained a heap-based out-of-bounds
read when handling file transfers. A remote attacker with read access
to an rsync server could possibly use this issue to cause a denial of
service. (CVE-2025-10158)
Batuhan Sancak, Damien Neil, and Michael Stapelberg discovered that
rsync daemons configured without chroot protection were exposed to a
race condition on parent path components. A local attacker with write
access to a module could possibly use this issue to overwrite files,
obtain sensitive information, or escalate privileges.
(CVE-2026-29518)
It was discovered that rsync did not properly validate a length value
while sorting extended attributes. An attacker could possibly use this
issue to cause a denial of service. (CVE-2026-41035)
It was discovered that rsync performed reverse-DNS lookups after
chrooting in some daemon configurations. A remote attacker could
possibly use this issue to bypass hostname-based access controls and
access network services. (CVE-2026-43617)
Omar Elsayed discovered that rsync did not properly check for integer
overflows while decoding compressed tokens. A remote attacker could
possibly use this issue to obtain sensitive information.
(CVE-2026-43618)
Andrew Tridgell discovered that rsync did not fully fix a symlink race
condition in path-based system calls for daemons configured without
chroot protection. A local attacker could possibly use this issue to
overwrite files, obtain sensitive information, or escalate privileges.
(CVE-2026-43619)
Pratham Gupta discovered that rsync did not properly validate an index
while processing file lists. A remote attacker could possibly use this
issue to cause rsync to crash, resulting in a denial of service.
(CVE-2026-43620)
Michal Ruprich discovered that rsync contained an off-by-one error
while handling HTTP proxy responses. An attacker able to intercept network
communications or a malicious proxy server could possibly use this issue to
cause a denial of service. (CVE-2026-45232)
1 week ago
In the Linux kernel, the following vulnerability has been
resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If
kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we
propagate the error back to the ioctl but leave the vGIC vCPU data
initialised.
In the Linux kernel, the following vulnerability has been
resolved: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
nvmet_tcp_build_pdu_iovec() could walk past cmd->req.sg when a PDU length
or offset exceeds sg_cnt and then use bogus sg->length/offset values,
leading to _copy_to_iter() GPF/KASAN.
It was discovered that the Linux kernel algif_aead module did not properly
handle in-place cryptographic operations. This flaw is known as Copy Fail.
A local attacker could use this to escalate privileges, or possibly escape
a container.)(CVE-2026-31431)
1 week 1 day ago
1 week 1 day ago
1 week 1 day ago
1 week 1 day ago
FEDORA-2026-de23fedf3e
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-2026-2aa17af701
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-EPEL-2026-943bd8b933
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-2026-d1580bc2d5
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-EPEL-2026-8865722a0e
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-EPEL-2026-74e26da380
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-EPEL-2026-bea3e12246
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-2026-729e540d74
Packages in this update:
Update description:
Update to 1.5.5, containing many bug fixes, some also security related.
1 week 1 day ago
FEDORA-EPEL-2026-86ff0eb5f1
Packages in this update:
- python-wsgidav-4.3.3-10.el9
Update description:
Backport fix for CVE-2026-48099
1 week 1 day ago
FEDORA-EPEL-2026-7ae2e107f2
Packages in this update:
- python-wsgidav-4.3.4-1.el10_2
Update description:
4.3.4 / 2026-05-24