Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : plasma-workspace Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/plasma-workspace Summary : Plasma workspace, applications and applets Description : Plasma 6 libraries and runtime components -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Unauthorized local user access to the session manager has been fixed in the Plasma Workspace component of the KDE Plasma desktop environment. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3827-1
CVE-2024-36041. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d120dc28b8 2024-06-02 03:36:56.060521 -------------------------------------------------------------------------------- Name : plasma-workspace Product : Fedora 39 Version : 5.27.11.1 Release : 1.fc39 URL : Summary : Plasma workspace, applications and applets Description : Plasma 5 libraries and runtime components -------------------------------------------------------------------------------- Update Information: CVE-2024-36041 -------------------------------------------------------------------------------- ChangeLog: * Fri May 31 2024 Alessandro Astone - 5.27.11.1-1 - CVE-2024-36041 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d120dc28b8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2024-36041. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-83fc86a0bc 2024-06-02 01:21:00.959170 -------------------------------------------------------------------------------- Name : plasma-workspace Product : Fedora 40 Version : 6.0.5.1 Release : 1.fc40 URL : Summary : Plasma workspace, applications and applets Description : Plasma 6 libraries and runtime components -------------------------------------------------------------------------------- Update Information: CVE-2024-36041 -------------------------------------------------------------------------------- ChangeLog: * Fri May 31 2024 Alessandro Astone - 6.0.5.1-1 - CVE-2024-36041 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-83fc86a0bc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
KDE Plasma 5.21.3 release. ---- Fix for CVE-2021-28117. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-85c9774673 2021-03-20 00:16:30.596946 --------------------------------------------------------------------------------Name : plasma-workspace Product : Fedora 34 Version : 5.21.3 Release : 1.fc34 URL : Summary : Plasma workspace, applications and applets Description : Plasma 5 libraries and runtime components --------------------------------------------------------------------------------Update Information: KDE Plasma 5.21.3 release. ---- Fix for CVE-2021-28117 --------------------------------------------------------------------------------ChangeLog: * Tue Mar 16 2021 Jan Grulich - 5.21.3-1 - 5.21.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1937887 - CVE-2021-28117 plasma-discover: missing URI scheme validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1937887 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-85c9774673' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix for CVE-2018-6790 CVE-2018-6791, backport crashfix for xembedsniproxy. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-337757e11f 2018-02-20 16:35:51.259892 --------------------------------------------------------------------------------Name : plasma-workspace Product : Fedora 26 Version : 5.10.5 Release : 6.fc26 URL : Summary : Plasma workspace, applications and applets Description : Plasma 5 libraries and runtime components --------------------------------------------------------------------------------Update Information: Fix for CVE-2018-6790 CVE-2018-6791, backport crashfix for xembedsniproxy --------------------------------------------------------------------------------References: [ 1 ] Bug #1543457 - CVE-2018-6791 kde-runtime: Arbitrary command execution in the removable device notifier https://bugzilla.redhat.com/show_bug.cgi?id=1543457 [ 2 ] Bug #1543454 - CVE-2018-6790 kde-workspace: Missing sanitization of notifications allows to leak client IP address via IMG element https://bugzilla.redhat.com/show_bug.cgi?id=1543454 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade plasma-workspace' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that solves two vulnerabilities and has one errata is now available.. openSUSE Security Update: Security update for plasma5-workspace ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0398-1 Rating: important References: #1013550 #1079429 #1079751 Cross-References: CVE-2018-6790 CVE-2018-6791 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for plasma5-workspace fixes security issues and bugs. The following vulnerabilities were fixed: - CVE-2018-6790: Desktop notifications could have been used to load arbitrary remote images into Plasma, allowing for client IP discovery (boo#1079429) - CVE-2018-6791: A specially crafted file system label may have allowed execution of arbitrary code (boo#1079751) The following bugs were fixed: - Plasma could freeze with certain notifications (boo#1013550) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-147=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64): drkonqi5-5.8.7-8.1 plasma5-workspace-5.8.7-8.1 plasma5-workspace-devel-5.8.7-8.1 plasma5-workspace-libs-5.8.7-8.1 - SUSE Package Hub for SUSE Linux Enterprise 12 (noarch): plasma5-workspace-lang-5.8.7-8.1 References: https://www.suse.com/security/cve/CVE-2018-6790.html https://www.suse.com/security/cve/CVE-2018-6791.html https://bugzilla.suse.com/1013550 https://bugzilla.suse.com/1079429 https://bugzilla.suse.com/1079751 -- .Vital openSUSE patch tackles two significant flaws in plasma5-workspace to bolster security measures.. openSUSE Security Update, plasma workspace patch, important fix, software security updates. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.