This release contains fixes for the following vulnerabilities:
-
- CVE-2026-56392: coreutils: GNU coreutils unexpand: Denial of Service via crafted tab stop values
-
- CVE-2023-40546: shim: Out-of-bounds read printing error messages
- CVE-2023-40547: shim: RCE in http boot support may lead to Secure Boot bypass
- CVE-2023-40548: shim: Interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
- CVE-2023-40549: shim: Out-of-bounds read in verify_buffer_authenticode() malformed PE file
- CVE-2023-40550: shim: Out-of-bound read in verify_buffer_sbat()
- CVE-2023-40551: shim: out of bounds read when parsing MZ binaries
-
- CVE-2026-5201: gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image
-
- CVE-2026-4786: python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API
- CVE-2026-6100: python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules
-
- CVE-2025-9714: libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c
-
- CVE-2026-34982: vim: arbitrary command execution via modeline sandbox bypass
-
- CVE-2026-35535: sudo: Sudo: Privilege escalation due to failure in privilege drop calls
-
- CVE-2026-4878: libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file()
-
- CVE-2026-35385: OpenSSH: OpenSSH: Privilege escalation via scp legacy protocol when not preserving file mode
- CVE-2026-35386: OpenSSH: OpenSSH: Arbitrary command execution via shell metacharacters in username
- CVE-2026-35387: OpenSSH: OpenSSH: Information disclosure due to unintended cryptographic algorithm usage
- CVE-2026-35388: OpenSSH: OpenSSH: Low integrity impact from unconfirmed proxy-mode multiplexing sessions
- CVE-2026-35414: OpenSSH: OpenSSH: Security bypass via mishandling of authorized_keys principals option
-
- CVE-2026-5119: libsoup: libsoup: Information disclosure via cleartext transmission of cookies during HTTPS tunnel establishment
-
- CVE-2025-14087: glib: GLib: Buffer underflow in GVariant parser leads to heap corruption
- CVE-2025-14512: glib: Integer Overflow in GLib GIO Attribute Escaping Causes Heap Buffer Overflow
-
- CVE-2026-4775: libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing
-
- CVE-2026-39979: jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers
- CVE-2026-40164: jq: jq: Denial of Service via crafted JSON object causing hash collisions
-
- CVE-2026-40355: krb5: MIT Kerberos 5: Denial of Service via NULL pointer dereference in NegoEx mechanism
- CVE-2026-40356: krb5: MIT Kerberos 5 (krb5): Denial of Service via integer underflow and out-of-bounds read
-
- CVE-2026-41035: rsync: Rsync: Use-after-free vulnerability in extended attribute handling
-
- CVE-2026-37555: libsndfile: integer overflow in ima_reader_init()
-
- CVE-2026-4046: glibc: glibc: Denial of Service via iconv() function with specific character sets
-
- CVE-2026-3833: gnutls: GnuTLS: Policy bypass due to case-sensitive nameConstraints comparison
- CVE-2026-5260: gnutls: gnutls: Information disclosure via heap overread in RSA key exchange
- CVE-2026-33845: gnutls: GnuTLS: Denial of Service via DTLS zero-length fragment
- CVE-2026-33846: gnutls: GnuTLS: Denial of Service via heap buffer overflow in DTLS handshake fragment reassembly
- CVE-2026-42009: gnutls: gnutls: Denial of Service via DTLS packet reordering vulnerability
- CVE-2026-42010: gnutls: gnutls: Authentication Bypass via NUL Character in Username
- CVE-2026-42011: gnutls: gnutls: Security bypass due to incorrect name constraint handling
- CVE-2026-42012: gnutls: gnutls: Certificate validation bypass due to improper handling of URI and SRV SANs
- CVE-2026-42013: gnutls: gnutls: Certificate validation bypass due to oversized Subject Alternative Name
- CVE-2026-42014: gnutls: gnutls: Use-after-free in gnutls_pkcs11_token_set_pin
- CVE-2026-42015: gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
-
- CVE-2026-1933: samba: Missing access check on reparse point operations
- CVE-2026-2340: samba: vfs_worm does not block directory modification
- CVE-2026-3012: samba: group policy certificate enrollment uses http:// without validation
- CVE-2026-4408: samba: Remote Code Execution in SAMR
- CVE-2026-4480: samba: Samba: Remote Code Execution in printing subsystem via unescaped job description
-
- CVE-2026-45186: libexpat: denial of service via crafted XML input
-
- CVE-2026-3039: bind: BIND 9 server memory exhaustion during GSS-API TKEY negotiation
- CVE-2026-5946: bind: BIND: Denial of Service via specially crafted DNS messages
-
- CVE-2026-6472: postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
- CVE-2026-6473: postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write
- CVE-2026-6474: postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function
- CVE-2026-6475: postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind
- CVE-2026-6477: postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory
- CVE-2026-6478: postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison
- CVE-2026-6479: postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation
- CVE-2026-6637: postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module
-
- CVE-2024-4741: openssl: Use After Free with SSL_free_buffers
- CVE-2026-45447: openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
-
- CVE-2024-34459: libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c
-
- CVE-2025-10911: libxslt: use-after-free with key data stored cross-RVT
-
- CVE-2026-29518: rsync: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot.
- CVE-2026-43618: rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding
-
- CVE-2026-6893: dracut: dracut: Root code execution via DHCP options command injection
- CVE-2026-16445: dracut: dracut: Root code execution via DHCP options command injection in NetworkManager initrd module
-
- CVE-2026-41411: vim: Command injection allows arbitrary code execution via malicious tag files
-
- CVE-2026-33416: libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
-
- CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in
scanfwith%mcformat specifier and large width
- CVE-2026-5450: glibc: glibc: Heap Buffer Overflow in
-
- CVE-2025-9230: openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap
-
- CVE-2025-13151: libtasn1: libtasn1: Denial of Service via stack-based buffer overflow in asn1_expend_octet_string
-
- CVE-2026-48864: libsolv: Heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
-
- CVE-2026-44431: urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
-
- CVE-2025-6170: libxml2: Stack Buffer Overflow in xmllint Interactive Shell Command Handling
-
- CVE-2026-28390: openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing
-
- CVE-2026-15308: python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations
-
- CVE-2025-12801: nfs-utils: rpc.mountd in the nfs-utils privilege escalation
-
- CVE-2026-12505: cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall
-
- CVE-2026-2003: postgresql: PostgreSQL oidvector discloses a few bytes of memory
- CVE-2026-2004: postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
- CVE-2026-2005: postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
- CVE-2026-2006: postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code
-
- CVE-2026-58016: glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml"
-
- CVE-2026-5435: glibc: glibc: Out-of-bounds write via TSIG record processing
- CVE-2026-5928: glibc: glibc: Information disclosure or denial of service via ungetwc function with specific wide character encodings
- CVE-2026-6238: glibc: glibc: Application crash or uninitialized memory read via crafted DNS response
-
- CVE-2026-41254: Little CMS: lcms2: mm2/Little-CMS: Little CMS: Information disclosure or denial of service via integer overflow in CubeSize
- CVE-2026-46968: openjdk: Enhance TLS certificate handling (Oracle CPU 2026-07)
- CVE-2026-47010: openjdk: Enhance JPEG handling (Oracle CPU 2026-07)
- CVE-2026-47021: openjdk: Enhance XBM image support (Oracle CPU 2026-07)
- CVE-2026-47027: openjdk: Enhance Jar file processing (Oracle CPU 2026-07)
- CVE-2026-47057: openjdk: Improve Nashorn index handling (Oracle CPU 2026-07)
- CVE-2026-47058: openjdk: Enhance Dataview Implementation (Oracle CPU 2026-07)
- CVE-2026-47059: openjdk: Enhance AWT ImagingLib (Oracle CPU 2026-07)
- CVE-2026-47063: openjdk: Enhance Jar handling (Oracle CPU 2026-07)
- CVE-2026-60147: openjdk: Improve certification checking (Oracle CPU 2026-07)
-
- CVE-2026-54369: acl: Symlink traversal privilege escalation via libacl functions
- CVE-2026-54370: acl: TOCTOU Symlink Traversal via getfacl/setfacl
-
- CVE-2026-25749: vim: Vim: Arbitrary code execution via 'helpfile' option processing
-
- CVE-2025-61662: grub2: Missing unregister call for gettext command may lead to use-after-free
-
- CVE-2026-14474: sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation
- CVE-2026-14476: sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
-
- CVE-2026-41989: Libgcrypt: Libgcrypt: Denial of Service and buffer overflow via crafted ECDH ciphertext
-
- CVE-2026-12912: libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image
-
- CVE-2026-22695: libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
- CVE-2026-22801: libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
- CVE-2026-25646: libpng: LIBPNG has a heap buffer overflow in png_set_quantize
-
- CVE-2025-15281: glibc: wordexp with WRDE_REUSE and WRDE_APPEND may return uninitialized memory
- CVE-2026-0915: glibc: glibc: Information disclosure via zero-valued network query
-
- CVE-2026-55653: openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service
- CVE-2026-55655: openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions
-
- CVE-2026-55995: open-isns: open-iscsi: Denial of Service via double-free in iSNS attribute decoder
-
- CVE-2026-45409: python-idna: idna: Denial of Service via specially crafted long inputs
-
- CVE-2026-15816: dracut: dracut: root code execution via unescaped error message written to sourced emergency hook script in die()
-
- CVE-2026-10723: bind: bind9: Incorrect acceptance of NSEC3 records
- CVE-2026-11622: bind: bind9: Potential memory usage beyond configured limits
- CVE-2026-11721: bind: bind9: Cache poisoning via label count discrepancy, RRSIG, wildcards
- CVE-2026-13204: bind: bind9: Unexpected exit with NSEC and NSEC3 both present
- CVE-2026-13321: bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
-
- CVE-2026-60589: OpenJDK: Improve Resource Resolving (2026-08 Security Update)
- CVE-2026-61308: OpenJDK: Enhance HTTP Connections (2026-08 Security Update)
- CVE-2026-70907: OpenJDK: Enhance TLS server (2026-08 Security Update)
-
- CVE-2026-58055: nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests
-
- CVE-2025-9820: gnutls: Stack-based Buffer Overflow in gnutls_pkcs11_token_init() Function
- CVE-2025-14831: gnutls: GnuTLS: Denial of Service via excessive resource consumption during certificate verification
-
- CVE-2025-0938: python: cpython: URL parser allowed square brackets in domain names
-
- CVE-2026-16313: sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export
-
- CVE-2026-54411: linux-pam: Plaintext password recovery via timing discrepancy in pam_userdb module
-
- CVE-2026-54371: attr: attr: Symlink Traversal Privilege Escalation via getfattr and setfattr
-
- CVE-2026-11940: python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory
-
- CVE-2026-8286: curl: curl: Insecure connection establishment due to TLS configuration mismatch
-
- CVE-2026-10805: NetworkManager: NetworkManager: Local privilege escalation via malformed MUD URLs in dhclient backend
-
- CVE-2026-9323: urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure
-
- CVE-2026-11822: sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
- CVE-2026-11824: sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
-
- CVE-2026-11979: libxml2: libxml2: Arbitrary code execution in xmlcatalog utility via buffer overflow
-
- CVE-2026-71217: iperf3: iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion
-
- CVE-2026-15588: GDBusServer: glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering
- CVE-2026-58010: glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()
- CVE-2026-58011: glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid GDateTime
- CVE-2026-58012: glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()
- CVE-2026-58013: glib: buffer over-read in glib/giochannel.c via "g_io_channel_read_line_backend"
- CVE-2026-58014: glib: off-by-one error in glib/gkeyfile.c via "g_key_file_get_locale_string_list"
- CVE-2026-58015: glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive
-
- CVE-2026-58469: wget: GNU Wget: Memory corruption via crafted Metalink URL
- CVE-2026-58471: wget: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption
- CVE-2026-58472: wget: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute
-
- CVE-2026-59843: libssh: libssh: denial of service via zero advertised channel packet size
- CVE-2026-59844: libssh: libssh: denial of service via oversized SFTP read length
- CVE-2026-59845: libssh: libssh: denial of service via unchecked ProxyCommand fork() failure
- CVE-2026-59846: libssh: libssh: information disclosure via ProxyCommand %r username expansion
- CVE-2026-59847: libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification
- CVE-2026-59848: libssh: libssh: denial of service via SFTP responses with unknown request IDs
- CVE-2026-59850: libssh: libssh: use-after-free via data callbacks on closed channels
-
- CVE-2025-10158: rsync: Rsync: Out of bounds array access via negative index
-
- CVE-2026-3497: openssh: OpenSSH GSSAPI: Information disclosure or denial of service due to uninitialized variables
-
- CVE-2026-4519: python: Python: Command-line option injection in webbrowser.open() via crafted URLs
-
- CVE-2026-50219: expat: libexpat: Use-after-free vulnerability due to improper handler call depth tracking
- CVE-2026-56132: expat: libexpat: Arbitrary Code Execution via Heap-based Buffer Overflow
-
- CVE-2025-31936: kernel: microcode_ctl: Intel Xeon 6 Processors: Privilege escalation via improper memory range handling in SMM
- CVE-2025-35973: kernel: hypervisor: Intel Processors: Privilege escalation in Ring 0 via improper value handling
-
- CVE-2026-9499: qt: Qt: Denial of Service via out-of-bounds read in text codec handling
-
- CVE-2026-41991: gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility
- CVE-2026-41992: gzip: gzip: Information disclosure via global buffer overflow in LZH decompression
-
- CVE-2026-16118: xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c
-
- CVE-2026-13221: perl: Perl: Incorrect regular expression processing via large regular expressions
-
- CVE-2026-71225: libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
- CVE-2026-71226: libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path
- CVE-2026-71227: libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
-
- CVE-2026-63382: libevent: libevent: Multiple HTTP Parser Bugs Enable Request Smuggling
- CVE-2026-63383: libevent: Libevent: Denial of Service via malformed RPC data
- CVE-2026-63384: libevent: Libevent: Denial of Service via integer conversion error in
evtag_unmarshal_header - CVE-2026-63385: libevent: Libevent: HTTP header handling bugs create risk of access control bypass.
- CVE-2026-63387: libevent: Libevent: Off-by-one stack buffer overflow leading to denial of service or data corruption
- CVE-2026-63388: libevent: Libevent: Arbitrary code execution via heap out-of-bounds write in AF_UNIX handling
-
- CVE-2026-15711: libsoup: SoupWebsocketConnection: libsoup: WebSocket remote denial of service via oversized control frame protocol violation
-
- CVE-2026-52490: libtiff: libtiff: Arbitrary code execution via process_command_opts() function
-
- CVE-2025-49506: apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation
- CVE-2026-32327: apr-util: Apache Portable Runtime Utility: Denial of Service via XML stack recursion attack
- CVE-2026-34501: apr-util: Apache Portable Runtime Utility: Heap buffer overflow in redis client
- CVE-2026-34502: apr-util: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client
-
- CVE-2026-59995: openssh: OpenSSH: sftp client allows attacker to control downloaded file location
- CVE-2026-59999: openssh: OpenSSH sshd: Security bypass due to incorrect handling of forwarding and tunneling options
- CVE-2026-73282: openssh: OpenSSH: Information disclosure and data corruption via use-after-free in ssh client
-
- CVE-2026-6653: libxml2: mingw-libxml2: libxml2: Denial of Service via crafted XML input due to use-after-free
-
- CVE-2026-6464: postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN
- CVE-2026-6471: postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin
- CVE-2026-14662: postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions
- CVE-2026-14664: postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp
- CVE-2026-14668: postgresql: PostgreSQL: Information disclosure via type confusion in ctid selectivity estimator
- CVE-2026-14669: postgresql: PostgreSQL: Arbitrary code execution via long POSIX timezone abbreviation
- CVE-2026-14670: postgresql: PostgreSQL: Arbitrary code execution via plperl tied hash heap buffer overflow
- CVE-2026-14671: postgresql: PostgreSQL: Arbitrary code execution via type confusion in 'refint' module
- CVE-2026-14677: postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl
- CVE-2026-14679: postgresql: PostgreSQL: Stack buffer overflow via OUT parameter count manipulation
- CVE-2026-14680: postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments
- CVE-2026-15741: postgresql: PostgreSQL: Privilege escalation via SQL injection in EXTRACT() deparse
- CVE-2026-15742: postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparound
- CVE-2026-16239: postgresql: PostgreSQL: Arbitrary code execution via type confusion in cursor lifecycle
- CVE-2026-18408: postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump
- CVE-2026-19385: postgresql: PostgreSQL pg_dump: Arbitrary code execution via crafted transform lists
-
- CVE-2025-5278: coreutils: Heap Buffer Under-Read in GNU Coreutils sort via Key Specification
-
- CVE-2025-45582: tar: Tar path traversal
- CVE-2026-5704: tar: tar: Hidden file injection via crafted archives
- CVE-2026-18477: tar: tar: TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
- CVE-2026-18508: tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
-
- CVE-2026-74860: libxml2: double-free/UAF in libxml2 Python bindings
- CVE-2026-86138: libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow
- CVE-2026-86140: libxml2: libxml2: Arbitrary code execution via stack-based buffer overflow in xmlSnprintfElements
- CVE-2026-86143: libxml2: libxml2: Data integrity issues due to integer overflow in write callbacks
- CVE-2026-86144: libxml2: libxml2: Information disclosure, SSRF, or denial of service due to improper parseFlags propagation.
-
- CVE-2026-66046: expat: Expat: Denial of Service via quadratic complexity in attribute processing
- CVE-2026-93990: expat: Expat: XML Injection via Malformed UTF-16 Input
-
- CVE-2026-13732: gdb: gdb: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF
-
- CVE-2026-40467: gawk: gawk: Denial of Service due to Use After Free vulnerability in io.c
- CVE-2026-40468: gawk: gawk: Memory corruption via integer overflow
-
- CVE-2026-27135: nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
-
- CVE-2026-21710: Node.js: Node.js: Denial of Service due to crafted HTTP
__proto__header - CVE-2026-26996: minimatch: minimatch: Denial of Service via specially crafted glob patterns
- CVE-2026-27135: nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination
- CVE-2026-27904: minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions
- CVE-2026-21710: Node.js: Node.js: Denial of Service due to crafted HTTP
-
- CVE-2026-1519: bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone
-
- CVE-2026-4424: libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing
- CVE-2026-5121: libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing
-
- CVE-2026-22007: openjdk: Enhance crypto algorithm support (Oracle CPU 2026-04)
- CVE-2026-22013: openjdk: Improve Kerberos credentialing (Oracle CPU 2026-04)
- CVE-2026-22016: openjdk: Enhance Path Factories Redux (Oracle CPU 2026-04)
- CVE-2026-22018: openjdk: Enhance Zip file reading (Oracle CPU 2026-04)
- CVE-2026-22021: openjdk: Enhance certificate chain validation (Oracle CPU 2026-04)
- CVE-2026-22695: libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
- CVE-2026-22801: libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
- CVE-2026-23865: freetype: Information disclosure or denial of service via specially crafted font files
- CVE-2026-26740: giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension
- CVE-2026-33416: libpng: libpng: Arbitrary code execution due to use-after-free vulnerability
- CVE-2026-33636: libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
- CVE-2026-34268: openjdk: Enhance key generation (Oracle CPU 2026-04)
Comments
Please sign in to leave a comment.