version bumped from 1.15.1 to 1.15.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-17dbeca425 2026-04-25 01:21:36.171367+00:00 -------------------------------------------------------------------------------- Name : rauc Product : Fedora 44 Version : 1.15.2 Release : 1.fc44 URL : https://rauc.io/ Summary : Safe and secure software updates for embedded Linux Description : RAUC is a lightweight update client that runs on your Embedded Linux device and reliably controls the procedure of updating your device with a new firmware revision. RAUC is also the tool on your host system that lets you create, inspect and modify update artifacts for your device. Service is not installed as that is only needed on device. -------------------------------------------------------------------------------- Update Information: version bumped from 1.15.1 to 1.15.2 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 30 2026 Bruno Thomsen - 1.15.2-1 - Update package from 1.15.1 to 1.15.2 - Fixes CVE-2026-34155 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452217 - rauc-1.15.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452217 [ 2 ] Bug #2453895 - CVE-2026-34155 rauc: improper signing of plain bundles exceeding 2 GiB [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453895 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-17dbeca425' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Context a general-purpose document processor was affected by CVE-2023-32700 fix that by default disable luasocket. This bugfix release, fix the mtxrun program used at install time . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3946-1
* bsc#1218845 * bsc#1218846 Cross-References: * CVE-2024-0408 . # Security update for xorg-x11-server Announcement ID: SUSE-SU-2024:0249-1 Rating: moderate References: * bsc#1218845 * bsc#1218846 Cross-References: * CVE-2024-0408 * CVE-2024-0409 CVSS scores: * CVE-2024-0408 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2024-0409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP5 * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues: * CVE-2024-0408: Fixed SELinux unlabeled GLX PBuffer. (bsc#1218845) * CVE-2024-0409: Fixed SELinux context corruption. (bsc#1218846) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-249=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-249=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-249=1 openSUSE-SLE-15.5-2024-249=1 ## Package List: * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-debugsource-21.1.4-150500.7.21.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.21.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-21.1.4-150500.7.21.1 * xorg-x11-server-extra-21.1.4-150500.7.21.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-debugsource-21.1.4-150500.7.21.1 * xorg-x11-server-sdk-21.1.4-150500.7.21.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-sdk-21.1.4-150500.7.21.1 * xorg-x11-server-debugsource-21.1.4-150500.7.21.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.21.1 * xorg-x11-server-source-21.1.4-150500.7.21.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.21.1 * xorg-x11-server-21.1.4-150500.7.21.1 * xorg-x11-server-extra-21.1.4-150500.7.21.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0408.html * https://www.suse.com/security/cve/CVE-2024-0409.html * https://bugzilla.suse.com/show_bug.cgi?id=1218845 * https://bugzilla.suse.com/show_bug.cgi?id=1218846 . The latest update for xorg-x11-server addresses significant issues and improves the handling of SELinux contexts. Find additional information here.. SELinux Context Fix, SUSE Update, Xorg Issue, Security Fix, Patch Instructions. . LinuxSecurity.com Team
- https:// - [Moderately critical - Cross site scripting - SA-CONTRIB-2019-028](https://) - https:// - https://. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5ab3464a23 2019-06-02 00:53:19.135309 --------------------------------------------------------------------------------Name : drupal7-context Product : Fedora 30 Version : 3.10 Release : 1.fc30 URL : https:// Summary : Allows contextual conditions and reactions management Description : Context allows you to manage contextual conditions and reactions for different portions of your site. You can think of each context as representing a "section" of your site. For each context, you can choose the conditions that trigger this context to be active and choose different aspects of Drupal that should react to this active context. Think of conditions as a set of rules that are checked during page load to see what context is active. Any reactions that are associated with active contexts are then fired. This package provides the following Drupal modules: * context * context_layouts * context_ui --------------------------------------------------------------------------------Update Information: - https:// - [Moderately critical - Cross site scripting - SA-CONTRIB-2019-028](https://) -https:// -https:// --------------------------------------------------------------------------------ChangeLog: * Fri May 24 2019 Shawn Iwinski - 3.10-1 - Updated to 3.10 (RHBZ #1683780) --------------------------------------------------------------------------------References: [ 1 ] Bug #1683780 - drupal7-context-3.10 is available https://bugzilla.redhat.com/show_bug.cgi?id=1683780 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5ab3464a23' at the command line. For more information, refer tothe dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.