Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-40416 http://linux.oracle.com/errata/ELSA-2026-40416.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: apcu-panel-5.1.23-1.module+el9.4.0+90261+af5cc950.noarch.rpm php-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-bcmath-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-cli-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-common-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-dba-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-dbg-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-devel-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-embedded-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-enchant-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-ffi-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-fpm-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-gd-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-gmp-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-intl-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-ldap-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-mbstring-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-mysqlnd-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-odbc-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-opcache-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-pdo-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-pecl-apcu-5.1.23-1.module+el9.4.0+90261+af5cc950.x86_64.rpm php-pecl-apcu-devel-5.1.23-1.module+el9.4.0+90261+af5cc950.x86_64.rpm php-pecl-rrd-2.0.3-4.module+el9.4.0+90261+af5cc950.x86_64.rpm php-pecl-xdebug3-3.2.2-2.module+el9.4.0+90261+af5cc950.x86_64.rpm php-pecl-zip-1.22.3-1.module+el9.4.0+90261+af5cc950.x86_64.rpm php-pgsql-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-process-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-snmp-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-soap-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm php-xml-8.2.32-1.module+el9.8.0+90965+26b10baf.x86_64.rpm aarch64: apcu-panel-5.1.23-1.module+el9.4.0+90261+af5cc950.noarch.rpm php-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-bcmath-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-cli-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-common-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-dba-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-dbg-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-devel-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-embedded-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-enchant-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-ffi-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-fpm-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-gd-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-gmp-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-intl-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-ldap-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-mbstring-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-mysqlnd-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-odbc-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-opcache-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-pdo-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-pecl-apcu-5.1.23-1.module+el9.4.0+90261+af5cc950.aarch64.rpm php-pecl-apcu-devel-5.1.23-1.module+el9.4.0+90261+af5cc950.aarch64.rpm php-pecl-rrd-2.0.3-4.module+el9.4.0+90261+af5cc950.aarch64.rpm php-pecl-xdebug3-3.2.2-2.module+el9.4.0+90261+af5cc950.aarch64.rpm php-pecl-zip-1.22.3-1.module+el9.4.0+90261+af5cc950.aarch64.rpm php-pgsql-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-process-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-snmp-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-soap-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm php-xml-8.2.32-1.module+el9.8.0+90965+26b10baf.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/php-8.2.32-1.module+el9.8.0+90965+26b10baf.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-apcu-5.1.23-1.module+el9.4.0+90261+af5cc950.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-rrd-2.0.3-4.module+el9.4.0+90261+af5cc950.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-xdebug3-3.2.2-2.module+el9.4.0+90261+af5cc950.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/php-pecl-zip-1.22.3-1.module+el9.4.0+90261+af5cc950.src.rpm Related CVEs: CVE-2026-14355 Description of changes: php [8.2.32-1] - rebase to 8.2.32 php-pecl-apcu [5.1.23-1] - update to 5.1.23 for PHP 8.2 RHEL-14699 php-pecl-rrd [2.0.3-4] - build for PHP 8.1 #2070040 [2.0.3-3] - Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688 [2.0.3-2] - Rebuilt for RHEL 9 BETA for openssl 3.0 Related: rhbz#1971065 [2.0.3-1] - update to 2.0.3 [2.0.2-1] - update to 2.0.2 [2.0.1-17] - Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937 [2.0.1-16] - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild [2.0.1-15] - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild php-pecl-xdebug3 [3.2.2-2] - drop inet_ntoa usage using upstream patch [3.2.2-1] - update to 3.2.2 for PHP 8.2 RHEL-14699 php-pecl-zip [1.22.3-1] - update to 1.22.3 for PHP 8.2 RHEL-14699 _______________________________________________ El-errata mailing list
Update to 1.12.1 Update to 1.12.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5924722657 2026-07-18 00:27:50.464606+00:00 -------------------------------------------------------------------------------- Name : node-exporter Product : Fedora 43 Version : 1.12.1 Release : 1.fc43 URL : https://github.com/prometheus/node_exporter Summary : Exporter for machine metrics Description : Prometheus exporter for hardware and OS metrics exposed by *NIX kernels, written in Go with pluggable metric collectors. -------------------------------------------------------------------------------- Update Information: Update to 1.12.1 Update to 1.12.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Packit - 1.12.1-1 - Update to 1.12.1 upstream release - Resolves: rhbz#2500038 * Sat Jul 11 2026 Mikel Olasagasti Uranga - 1.12.0-1 - Update to 1.12.0 - Closes rhbz#2499355 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494365 - CVE-2026-27145 node-exporter: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494365 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5924722657' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update python-django5 to version 5.2.16 Fixes three low-severity CVEs CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response CVE-2026-53877: Heap buffer over-read in GDALRaster. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-595d35a4d1 2026-07-18 00:26:14.273091+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 44 Version : 5.2.16 Release : 1.fc44 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Update python-django5 to version 5.2.16 Fixes three low-severity CVEs CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response CVE-2026-53877: Heap buffer over-read in GDALRaster CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michel Lind - 5.2.16-1 - Update to version 5.2.16; Resolves RHBZ#2497734 - Fixes three low-severity CVEs - CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response - CVE-2026-53877: Heap buffer over-read in GDALRaster - CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input * Thu Jul 16 2026 Fedora Release Engineering - 5.2.15-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 19 2026 Miro Hrončok - 5.2.15-5 - Heavily reduce the list of skipped tests * Sat Jun 6 2026 Michel Lind - 5.2.15-4 - Remove dump of disabled tests from the end of thespec * Sat Jun 6 2026 Michel Lind - 5.2.15-3 - Disable failing tests on Python 3.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497734 - python-django5-5.2.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=2497734 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-595d35a4d1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Upgrade python-django5 to version 5.2.16 to fix low-severity issues with potential data exposure and buffer over-read.. Fedora security patch, python-django5 update, data protection Linux, buffer over-read issue, web framework vulnerabilities. . Severity: Low. LinuxSecurity.com Team
Update to upstream release 0.13.0; update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e0bcb90c9f 2026-07-16 01:19:18.912113+00:00 -------------------------------------------------------------------------------- Name : python-tiktoken Product : Fedora 44 Version : 0.13.0 Release : 2.fc44 URL : https://pypi.org/project/tiktoken/ Summary : tiktoken is a fast BPE tokeniser for use with OpenAI's models Description : tiktoken is a fast BPE tokeniser for use with OpenAI's models. -------------------------------------------------------------------------------- Update Information: Update to upstream release 0.13.0; update PyO3 to 0.29, fixing RUSTSEC-2026-0176 and RUSTSEC-2026-0177. -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 6 2026 Benjamin A. Beasley - 0.13.0-2 - Update PyO3 to 0.29 - Fixes RUSTSEC-2026-0176 and RUSTSEC-2026-0177 * Mon Jul 6 2026 Benjamin A. Beasley - 0.13.0-1 - Update to 0.13.0 (close RHBZ#2477785) * Mon Jul 6 2026 Benjamin A. Beasley - 0.12.0-6 - Add a comment to justify not running the tests * Mon Jul 6 2026 Benjamin A. Beasley - 0.12.0-5 - Avoid installing duplicate license files * Mon Jul 6 2026 Benjamin A. Beasley - 0.12.0-4 - Improve/simplify handling of Rust dependency licenses * Wed Jun 3 2026 Python Maint - 0.12.0-3 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2477785 - python-tiktoken-0.13.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2477785 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e0bcb90c9f' at the command line. For more information, refer to thednf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Low: libxml2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39304", "synopsis": "Low: libxml2 security update", "severity": "SEVERITY_LOW", "topic": "An update is available for libxml2.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libxml2 library is a development toolbox providing the implementation of various XML standards.\n\nSecurity Fix(es):\n\n* libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling (CVE-2025-6170)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2372952", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2372952", "description": ""}], "cves": [{"name": "CVE-2025-6170", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6170", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "cvss3BaseScore": "2.5", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-07-15T12:06:01.640959Z", "rpms": {"Rocky Linux 10": {"nvras": ["libxml2-static-0:2.12.5-10.el10_2.2.s390x.rpm", "python3-libxml2-debuginfo-0:2.12.5-10.el10_2.2.x86_64.rpm", "python3-libxml2-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-static-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-static-0:2.12.5-10.el10_2.2.x86_64.rpm", "libxml2-debuginfo-0:2.12.5-10.el10_2.2.ppc64le.rpm", "libxml2-debuginfo-0:2.12.5-10.el10_2.2.s390x.rpm", "libxml2-debuginfo-0:2.12.5-10.el10_2.2.x86_64.rpm", "libxml2-debugsource-0:2.12.5-10.el10_2.2.x86_64.rpm", "libxml2-debugsource-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-static-0:2.12.5-10.el10_2.2.ppc64le.rpm","libxml2-0:2.12.5-10.el10_2.2.s390x.rpm", "python3-libxml2-debuginfo-0:2.12.5-10.el10_2.2.ppc64le.rpm", "libxml2-debugsource-0:2.12.5-10.el10_2.2.s390x.rpm", "python3-libxml2-debuginfo-0:2.12.5-10.el10_2.2.aarch64.rpm", "python3-libxml2-0:2.12.5-10.el10_2.2.ppc64le.rpm", "libxml2-devel-0:2.12.5-10.el10_2.2.x86_64.rpm", "python3-libxml2-0:2.12.5-10.el10_2.2.s390x.rpm", "libxml2-0:2.12.5-10.el10_2.2.ppc64le.rpm", "python3-libxml2-debuginfo-0:2.12.5-10.el10_2.2.s390x.rpm", "libxml2-devel-0:2.12.5-10.el10_2.2.s390x.rpm", "libxml2-debuginfo-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-0:2.12.5-10.el10_2.2.x86_64.rpm", "libxml2-devel-0:2.12.5-10.el10_2.2.aarch64.rpm", "libxml2-devel-0:2.12.5-10.el10_2.2.ppc64le.rpm", "libxml2-debugsource-0:2.12.5-10.el10_2.2.ppc64le.rpm", "libxml2-0:2.12.5-10.el10_2.2.src.rpm", "python3-libxml2-0:2.12.5-10.el10_2.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A new low-severity update for libxml2 addresses a buffer overflow issue impacting Rocky Linux 10 with CVE-2025-6170.. libxml2 security update, rocky linux advisory, libxml2 buffer overflow. . Severity: Low. LinuxSecurity.com Team
Low: capstone security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39309", "synopsis": "Low: capstone security update", "severity": "SEVERITY_LOW", "topic": "An update is available for capstone.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Capstone is a disassembly framework with the target of becoming the ultimate disasm engine for binary analysis and reversing in the security community.\n\nSecurity Fix(es):\n\n* capstone: Capstone: Memory corruption via unchecked vsnprintf return (CVE-2025-68114)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2423416", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2423416", "description": ""}], "cves": [{"name": "CVE-2025-68114", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-68114", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.3", "cwe": "CWE-787"}], "references": [], "publishedAt": "2026-07-15T12:03:43.176942Z", "rpms": {"Rocky Linux 9": {"nvras": ["capstone-0:4.0.2-13.el9_8.aarch64.rpm", "capstone-0:4.0.2-13.el9_8.ppc64le.rpm", "capstone-0:4.0.2-13.el9_8.s390x.rpm", "capstone-0:4.0.2-13.el9_8.src.rpm", "capstone-0:4.0.2-13.el9_8.x86_64.rpm", "capstone-debuginfo-0:4.0.2-13.el9_8.aarch64.rpm", "capstone-debuginfo-0:4.0.2-13.el9_8.ppc64le.rpm", "capstone-debuginfo-0:4.0.2-13.el9_8.s390x.rpm", "capstone-debuginfo-0:4.0.2-13.el9_8.x86_64.rpm", "capstone-debugsource-0:4.0.2-13.el9_8.aarch64.rpm", "capstone-debugsource-0:4.0.2-13.el9_8.ppc64le.rpm", "capstone-debugsource-0:4.0.2-13.el9_8.s390x.rpm","capstone-debugsource-0:4.0.2-13.el9_8.x86_64.rpm", "capstone-devel-0:4.0.2-13.el9_8.aarch64.rpm", "capstone-devel-0:4.0.2-13.el9_8.ppc64le.rpm", "capstone-devel-0:4.0.2-13.el9_8.s390x.rpm", "capstone-devel-0:4.0.2-13.el9_8.x86_64.rpm", "capstone-java-0:4.0.2-13.el9_8.noarch.rpm", "python3-capstone-0:4.0.2-13.el9_8.aarch64.rpm", "python3-capstone-0:4.0.2-13.el9_8.ppc64le.rpm", "python3-capstone-0:4.0.2-13.el9_8.s390x.rpm", "python3-capstone-0:4.0.2-13.el9_8.x86_64.rpm", "python3-capstone-debuginfo-0:4.0.2-13.el9_8.aarch64.rpm", "python3-capstone-debuginfo-0:4.0.2-13.el9_8.ppc64le.rpm", "python3-capstone-debuginfo-0:4.0.2-13.el9_8.s390x.rpm", "python3-capstone-debuginfo-0:4.0.2-13.el9_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A low severity capstone update is available for Rocky Linux 9 that addresses memory corruption issues effectively.. Rocky Linux capstone update security memory corruption. . Severity: Low. LinuxSecurity.com Team
Low: libxml2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39317", "synopsis": "Low: libxml2 security update", "severity": "SEVERITY_LOW", "topic": "An update is available for libxml2.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libxml2 library is a development toolbox providing the implementation of various XML standards.\n\nSecurity Fix(es):\n\n* libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling (CVE-2025-6170)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2372952", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2372952", "description": ""}], "cves": [{"name": "CVE-2025-6170", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-6170", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L", "cvss3BaseScore": "2.5", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-07-15T12:03:43.176942Z", "rpms": {"Rocky Linux 9": {"nvras": ["libxml2-0:2.9.13-14.el9_8.2.aarch64.rpm", "libxml2-0:2.9.13-14.el9_8.2.i686.rpm", "libxml2-0:2.9.13-14.el9_8.2.ppc64le.rpm", "libxml2-0:2.9.13-14.el9_8.2.s390x.rpm", "libxml2-0:2.9.13-14.el9_8.2.src.rpm", "libxml2-0:2.9.13-14.el9_8.2.x86_64.rpm", "libxml2-debuginfo-0:2.9.13-14.el9_8.2.aarch64.rpm", "libxml2-debuginfo-0:2.9.13-14.el9_8.2.i686.rpm", "libxml2-debuginfo-0:2.9.13-14.el9_8.2.ppc64le.rpm", "libxml2-debuginfo-0:2.9.13-14.el9_8.2.s390x.rpm", "libxml2-debuginfo-0:2.9.13-14.el9_8.2.x86_64.rpm", "libxml2-debugsource-0:2.9.13-14.el9_8.2.aarch64.rpm", "libxml2-debugsource-0:2.9.13-14.el9_8.2.i686.rpm","libxml2-debugsource-0:2.9.13-14.el9_8.2.ppc64le.rpm", "libxml2-debugsource-0:2.9.13-14.el9_8.2.s390x.rpm", "libxml2-debugsource-0:2.9.13-14.el9_8.2.x86_64.rpm", "libxml2-devel-0:2.9.13-14.el9_8.2.aarch64.rpm", "libxml2-devel-0:2.9.13-14.el9_8.2.i686.rpm", "libxml2-devel-0:2.9.13-14.el9_8.2.ppc64le.rpm", "libxml2-devel-0:2.9.13-14.el9_8.2.s390x.rpm", "libxml2-devel-0:2.9.13-14.el9_8.2.x86_64.rpm", "python3-libxml2-0:2.9.13-14.el9_8.2.aarch64.rpm", "python3-libxml2-0:2.9.13-14.el9_8.2.ppc64le.rpm", "python3-libxml2-0:2.9.13-14.el9_8.2.s390x.rpm", "python3-libxml2-0:2.9.13-14.el9_8.2.x86_64.rpm", "python3-libxml2-debuginfo-0:2.9.13-14.el9_8.2.aarch64.rpm", "python3-libxml2-debuginfo-0:2.9.13-14.el9_8.2.ppc64le.rpm", "python3-libxml2-debuginfo-0:2.9.13-14.el9_8.2.s390x.rpm", "python3-libxml2-debuginfo-0:2.9.13-14.el9_8.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A low severity security update is available for libxml2 in Rocky Linux 9 to fix a stack buffer overflow issue.. Rocky Linux security update, libxml2 low severity, buffer overflow fix. . Severity: Low. LinuxSecurity.com Team
Low: qemu-kvm security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39311", "synopsis": "Low: qemu-kvm security update", "severity": "SEVERITY_LOW", "topic": "An update is available for qemu-kvm.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM.\n\nSecurity Fix(es):\n\n* qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling (CVE-2026-48914)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2488283", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2488283", "description": ""}], "cves": [{"name": "CVE-2026-48914", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-48914", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H", "cvss3BaseScore": "6.7", "cwe": "CWE-122"}], "references": [], "publishedAt": "2026-07-15T12:03:43.176942Z", "rpms": {"Rocky Linux 9": {"nvras": ["qemu-guest-agent-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-guest-agent-17:10.1.0-17.el9_8.4.ppc64le.rpm", "qemu-guest-agent-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-guest-agent-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-guest-agent-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-guest-agent-debuginfo-17:10.1.0-17.el9_8.4.ppc64le.rpm", "qemu-guest-agent-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-guest-agent-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-img-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-img-17:10.1.0-17.el9_8.4.ppc64le.rpm","qemu-img-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-img-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-img-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-img-debuginfo-17:10.1.0-17.el9_8.4.ppc64le.rpm", "qemu-img-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-img-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-17:10.1.0-17.el9_8.4.src.rpm", "qemu-kvm-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-audio-pa-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-audio-pa-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-audio-pa-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-audio-pa-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-audio-pa-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-audio-pa-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-blkio-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-blkio-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-blkio-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-blkio-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-blkio-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-blkio-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-curl-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-curl-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-curl-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-curl-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-curl-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-curl-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-rbd-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-rbd-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-rbd-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-block-rbd-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-block-rbd-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-block-rbd-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-common-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-common-17:10.1.0-17.el9_8.4.s390x.rpm","qemu-kvm-common-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-common-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-common-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-common-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-core-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-core-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-core-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-core-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-core-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-core-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-debuginfo-17:10.1.0-17.el9_8.4.ppc64le.rpm", "qemu-kvm-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-debugsource-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-debugsource-17:10.1.0-17.el9_8.4.ppc64le.rpm", "qemu-kvm-debugsource-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-debugsource-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-display-virtio-gpu-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-display-virtio-gpu-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-display-virtio-gpu-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-display-virtio-gpu-ccw-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-display-virtio-gpu-ccw-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-display-virtio-gpu-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-display-virtio-gpu-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-display-virtio-gpu-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-display-virtio-gpu-pci-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-display-virtio-gpu-pci-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-display-virtio-gpu-pci-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-display-virtio-gpu-pci-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-display-virtio-vga-17:10.1.0-17.el9_8.4.x86_64.rpm","qemu-kvm-device-display-virtio-vga-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-usb-host-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-usb-host-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-usb-host-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-usb-host-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-usb-host-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-device-usb-host-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-usb-redirect-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-usb-redirect-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-device-usb-redirect-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-device-usb-redirect-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-docs-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-docs-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-docs-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-tools-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-tools-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-tools-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-tools-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-kvm-tools-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-kvm-tools-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-ui-egl-headless-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-ui-egl-headless-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-ui-opengl-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-kvm-ui-opengl-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-pr-helper-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-pr-helper-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-pr-helper-17:10.1.0-17.el9_8.4.x86_64.rpm", "qemu-pr-helper-debuginfo-17:10.1.0-17.el9_8.4.aarch64.rpm", "qemu-pr-helper-debuginfo-17:10.1.0-17.el9_8.4.s390x.rpm", "qemu-pr-helper-debuginfo-17:10.1.0-17.el9_8.4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security update for qemu-kvm in Rocky Linux 9 addresses a critical buffer overflow issue affecting virtual machines.. Rocky Linux,qemu-kvm,heap overflow,security update. . Severity: Low.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.