Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-30860 http://linux.oracle.com/errata/ELSA-2026-30860.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: perl-IO-Compress-2.212-512.el10_2.1.noarch.rpm aarch64: perl-IO-Compress-2.212-512.el10_2.1.noarch.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/perl-IO-Compress-2.212-512.el10_2.1.src.rpm Related CVEs: CVE-2026-48962 Description of changes: [2.212-512.1] - Fix CVE-2026-48962: remove use of eval in File::GlobMapper - Resolves: RHEL-180415 _______________________________________________ El-errata mailing list
nginx-mod-brotli: Rebuild for 1.30.3 nginx-mod-fancyindex: Rebuild for 1.30.3 nginx-mod-vts:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b8e751787c 2026-06-27 01:10:00.374795+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-brotli Product : Fedora 44 Version : 1.0.0~rc Release : 11.fc44 URL : https://github.com/google/ngx_brotli Summary : NGINX module for Brotli compression Description : NGINX module for Brotli compression. -------------------------------------------------------------------------------- Update Information: nginx-mod-brotli: Rebuild for 1.30.3 nginx-mod-fancyindex: Rebuild for 1.30.3 nginx-mod-vts: Rebuild for 1.30.3 nginx-mod-modsecurity: Rebuild for 1.30.3 nginx-mod-headers-more: Rebuild for 1.30.3 nginx-mod-naxsi: Rebuild for 1.30.3 nginx-mod-js-challenge: Rebuild for 1.30.3 nginx: update to 1.30.3 fixes CVE-2026-42055, CVE-2026-42530 and CVE-2026-48142 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Felix Kaechele - 1.0.0~rc-11 - Rebuild for 1.30.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b8e751787c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
nginx-mod-vts: Rebuild for 1.30.1 nginx-mod-fancyindex: Rebuild for 1.30.1 nginx-mod-naxsi:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-38623b4fed 2026-05-15 22:44:59.632855+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-brotli Product : Fedora 42 Version : 1.0.0~rc Release : 9.fc42 URL : https://github.com/google/ngx_brotli Summary : NGINX module for Brotli compression Description : NGINX module for Brotli compression. -------------------------------------------------------------------------------- Update Information: nginx-mod-vts: Rebuild for 1.30.1 nginx-mod-fancyindex: Rebuild for 1.30.1 nginx-mod-naxsi: Rebuild for 1.30.1 nginx-mod-headers-more: Rebuild for 1.30.1 nginx-mod-brotli: Rebuild for 1.30.1 nginx-mod-modsecurity: Rebuild for 1.30.1 nginx: update to 1.30.1 fixes CVE-2026-42926, CVE-2026-42945, CVE-2026-42946, CVE-2026-42934, CVE-2026-40460 and CVE-2026-40701 -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2026 Felix Kaechele - 1.0.0~rc-9 - Rebuild for 1.30.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477413 - CVE-2026-42945 nginx: NGINX: Arbitrary Code Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2477413 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-38623b4fed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was discovered that there was a potential use-after-free issue in the lrzip compression/decompression program. For Debian 11 bullseye, this problem has been fixed in version 0.641-1+deb11u2. We recommend that you upgrade your lrzip packages.. Debian LTS Advisory DLA-4567-1
Latest Monkey's Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-43278d411e 2026-04-18 01:08:05.671399+00:00 -------------------------------------------------------------------------------- Name : mac Product : Fedora 42 Version : 12.63 Release : 1.fc42 URL : https://monkeysaudio.com Summary : Monkey's Audio Codec Description : Monkey's Audio is a fast and easy way to compress digital music. Unlike traditional methods such as mp3, ogg, or lqt that permanently discard quality to save space, Monkey's Audio only makes perfect, bit-for-bit copies of your music. That means it always sounds perfect \u2013 exactly the same as the original. Even though the sound is perfect, it still saves a lot of space. -------------------------------------------------------------------------------- Update Information: Latest Monkey's Audio Codec release. Changes: https://monkeysaudio.com/versionhistory.html . -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Dominik 'Rathann' Mierzejewski - 12.63-1 - Updated to 12.63 (resolves rhbz#2446305) - Dropped obsolete patch - Bump ABI to 15 * Tue Mar 10 2026 Dominik 'Rathann' Mierzejewski - 12.50-1 - Updated to 12.50 (resolves rhbz#2363650) * Tue Feb 24 2026 Dominik 'Rathann' Mierzejewski - 12.35-3 - assume platform is Linux in headers if unspecified * Mon Feb 23 2026 Dominik 'Rathann' Mierzejewski - 12.35-2 - bump minimum CMake version (resolves rhbz#2380887) * Mon Feb 23 2026 Dominik 'Rathann' Mierzejewski - 12.35-1 - update to 12.35 (resolves rhbz#2363650) * Fri Jan 16 2026 Fedora Release Engineering - 10.18-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Jul 24 2025 Fedora Release Engineering - 10.18-7 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2406922 - CVE-2025-61043 mac: out-of-bounds read in CAPECharacterHelper::GetUTF16FromUTF8 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2406922 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-43278d411e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Monkey's Audio for Fedora 42 receives an important update addressing an out-of-bounds read issue. Install now.. Monkeys Audio Codec, Fedora Update, Audio Compression, Fedora 42. . Severity: Important. LinuxSecurity.com Team
Important: brotli security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2042", "synopsis": "Important: brotli security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for brotli.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. \n\nSecurity Fix(es):\n\n* Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2408762", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", "description": ""}], "cves": [{"name": "CVE-2025-6176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-6176", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2026-02-07T09:06:42.672591Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3-brotli-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-0:1.0.9-9.el9_7.i686.rpm", "brotli-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-0:1.0.9-9.el9_7.s390x.rpm", "brotli-0:1.0.9-9.el9_7.src.rpm", "brotli-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.i686.rpm","brotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.i686.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.s390x.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-devel-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-devel-0:1.0.9-9.el9_7.i686.rpm", "brotli-devel-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-devel-0:1.0.9-9.el9_7.s390x.rpm", "brotli-devel-0:1.0.9-9.el9_7.x86_64.rpm", "libbrotli-0:1.0.9-9.el9_7.aarch64.rpm", "libbrotli-0:1.0.9-9.el9_7.i686.rpm", "libbrotli-0:1.0.9-9.el9_7.ppc64le.rpm", "libbrotli-0:1.0.9-9.el9_7.s390x.rpm", "libbrotli-0:1.0.9-9.el9_7.x86_64.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.i686.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm", "python3-brotli-0:1.0.9-9.el9_7.ppc64le.rpm", "python3-brotli-0:1.0.9-9.el9_7.s390x.rpm", "python3-brotli-0:1.0.9-9.el9_7.x86_64.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Brotli security update for Rocky Linux addresses a DoS threat. Updates are critical for maintaining system integrity.. Brotli security update, Rocky Linux DoS threat, Important security fix. . Severity: Important. LinuxSecurity.com Team
MGAA-2025-0079 - Updated rocksdb packages fix bug. MGAA-2025-0079 - Updated rocksdb packages fix bug Publication date: 01 Sep 2025 URL: https://advisories.mageia.org/MGAA-2025-0079.html Type: bugfix Affected Mageia releases: 9 Description: Thia update adds support to LZ4 and other compression formats. References: - https://bugs.mageia.org/show_bug.cgi?id=34583 SRPMS: - 9/core/rocksdb-7.7.8-1.2.mga9 . Revised RocksDB versions for Mageia 9 enhance functionality and rectify issues, while also optimizing compression formats. Consult the announcement for details.. RocksDB Mageia Bugfix Compression Update. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2010-1028 and other security-relevant bugs; see https://github.com/bramstein/sfnt2woff-zopfli/pull/20/commits.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a2a56326b3 2025-05-20 01:45:49.098290+00:00 -------------------------------------------------------------------------------- Name : sfnt2woff-zopfli Product : Fedora 41 Version : 1.3.1 Release : 15.fc41 URL : https://github.com/bramstein/sfnt2woff-zopfli Summary : Create WOFF files with Zopfli compression Description : This is a modified version of the sfnt2woff utility that uses Zopfli as a compression algorithm instead of zlib. This results in compression gains of â on average â 5-8% compared to regular WOFF files. Zopfli generates compressed output that is compatible with regular zlib compression so the resulting WOFF files can be used everywhere. A corresponding version of the woff2sfnt utility is also provided. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2010-1028 and other security-relevant bugs; see https://github.com/bramstein/sfnt2woff-zopfli/pull/20/commits. -------------------------------------------------------------------------------- ChangeLog: * Sun May 11 2025 Benjamin A. Beasley - 1.3.1-15 - Security fix for CVE-2010-1028 - Various other fixes collected by Debian and contributed back upstream: https://github.com/bramstein/sfnt2woff-zopfli/pull/20 * Sun May 11 2025 Benjamin A. Beasley - 1.3.1-14 - Update .rpmlintrc file for current rpmlint * Sun Jan 19 2025 Fedora Release Engineering - 1.3.1-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a2a56326b3' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . Ubuntu 22.04 upgrade for font2woff-zopfli resolves CVE-2010-1029 and additional high-severity vulnerabilities; check release notes for setup instructions.. Fedora 41, sfnt2woff-zopfli, CVE-2010-1028, bug fixes, security alert. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.