This update addresses some input validation issues: Reject Unicode digits and trailing newlines in parser inputs (CVE-2026-45190) Reject zero-padded CIDR masks (CVE-2026-45191). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6f3d2d0d82 2026-05-15 20:57:10.102582+00:00 -------------------------------------------------------------------------------- Name : perl-Net-CIDR-Lite Product : Fedora 44 Version : 0.24 Release : 1.fc44 URL : https://metacpan.org/release/Net-CIDR-Lite Summary : Perl extension for merging IPv4 or IPv6 CIDR addresses Description : Faster alternative to Net::CIDR when merging a large number of CIDR address ranges. Works for IPv4 and IPv6 addresses. -------------------------------------------------------------------------------- Update Information: This update addresses some input validation issues: Reject Unicode digits and trailing newlines in parser inputs (CVE-2026-45190) Reject zero-padded CIDR masks (CVE-2026-45191) -------------------------------------------------------------------------------- ChangeLog: * Mon May 11 2026 Paul Howarth - 0.24-1 - Update to 0.24 - Reject Unicode digits and trailing newlines in parser inputs (CVE-2026-45190) - Reject zero-padded CIDR masks (CVE-2026-45191) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6f3d2d0d82' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the . Hash: SHA512 Package : libxml2 Version : 2.8.0+dfsg1-7+wheezy11 CVE ID : CVE-2017-16931 CVE-2017-16932 CVE-2017-16931 parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro calls the xmlParserHandlePEReference function in the case of a '%' character in a DTD name. CVE-2017-16932 parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities. For Debian 7 "Wheezy", these problems have been fixed in version 2.8.0+dfsg1-7+wheezy11. We recommend that you upgrade your libxml2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential security patches for libxml2 have been released to fix vulnerabilities related to parameter-entity management. An upgrade is advised for Debian 7 users.. Debian Security, libxml2 Update, Parameter-Entity Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.