ChangeLog for: 2026-02-17 05:33:58
a/kernel-firmware-20260214_3a0e2a5-noarch-1.txz: Upgraded.
a/kernel-generic-6.12.73-x86_64-1.txz: Upgraded.
a/lrzip-0.660-x86_64-1.txz: Upgraded.
Address multiple potential security issues with crafted or corrupt archives.
(* Security fix *)
d/kernel-headers-6.12.73-x86-1.txz: Upgraded.
k/kernel-source-6.12.73-noarch-1.txz: Upgraded.
FTRACE_SYSCALLS n -> y
Thanks to isaackwy.
l/libssh-0.12.0-x86_64-1.txz: Upgraded.
This update fixes security issues:
SCP Protocol Path Traversal in ssh_scp_pull_request().
Possible Denial of Service when parsing unexpected configuration files.
Buffer underflow in ssh_get_hexa() on invalid input.
Specially crafted patterns could cause DoS.
OOB Read in sftp_parse_longname().
Read buffer overrun when handling SFTP extensions.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-0964
https://www.cve.org/CVERecord?id=CVE-2026-0965
https://www.cve.org/CVERecord?id=CVE-2026-0966
https://www.cve.org/CVERecord?id=CVE-2026-0967
https://www.cve.org/CVERecord?id=CVE-2026-0968
https://www.cve.org/CVERecord?id=CVE-2025-14821
(* Security fix *)
l/mozilla-nss-3.120.1-x86_64-1.txz: Upgraded.
l/mozjs140-140.7.1esr-x86_64-1.txz: Upgraded.
n/cyrus-sasl-2.1.28-x86_64-5.txz: Rebuilt.
Recompiled with some experimental options that are commonly expected:
--enable-auth-sasldb, --enable-ntlm, --enable-httpform, --enable-alwaystrue.
Thanks to BigDumbDinosaur.
n/ethtool-6.19-x86_64-1.txz: Upgraded.
n/whois-5.6.6-x86_64-1.txz: Upgraded.
Added the .mc TLD server.
Updated the .ps TLD server.
Removed the .info, .mobi, .travel and .فلسطين (.xn--ygbi2ammx,
Palestinian Territory) TLD servers.
Removed 3 new gTLDs which are no longer active.
mkpasswd: added support the Chinese SM3-based hashing algorithms.
x/ibus-m17n-1.4.38-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-140.7.1esr-x86_64-1.txz: Upgraded.
This update contains a security fix:
Heap buffer overflow in libvpx.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.7.1/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-10/
https://www.cve.org/CVERecord?id=CVE-2026-2447
(* Security fix *)
xap/mozilla-thunderbird-140.7.2esr-x86_64-1.txz: Upgraded.
This update contains a security fix:
Heap buffer overflow in libvpx.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/140.7.2esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-11/
https://www.cve.org/CVERecord?id=CVE-2026-2447
(* Security fix *)
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-6.18.x/kernel-generic-6.18.12-x86_64-1.txz: Upgraded.
testing/packages/linux-6.18.x/kernel-headers-6.18.12-x86-1.txz: Upgraded.
testing/packages/linux-6.18.x/kernel-source-6.18.12-noarch-1.txz: Upgraded.
FTRACE_SYSCALLS n -> y
Thanks to isaackwy.
usb-and-pxe-installers/usbboot.img: Rebuilt.