ChangeLog for: 2026-04-08 23:26:28
a/bcachefs-tools-1.37.5-x86_64-1.txz: Upgraded.
a/nut-2.8.5-x86_64-1.txz: Upgraded.
a/openssl-solibs-3.5.6-x86_64-1.txz: Upgraded.
ap/nano-9.0-x86_64-1.txz: Upgraded.
ap/sox-14.7.1.2-x86_64-1.txz: Upgraded.
d/llvm-22.1.3-x86_64-1.txz: Upgraded.
kde/krita-6.0.1.1-x86_64-1.txz: Upgraded.
l/gst-plugins-bad-free-1.28.2-x86_64-1.txz: Upgraded.
l/gst-plugins-base-1.28.2-x86_64-1.txz: Upgraded.
l/gst-plugins-good-1.28.2-x86_64-1.txz: Upgraded.
l/gst-plugins-libav-1.28.2-x86_64-1.txz: Upgraded.
l/gstreamer-1.28.2-x86_64-1.txz: Upgraded.
l/libclc-22.1.3-x86_64-1.txz: Upgraded.
l/mozjs140-140.9.1esr-x86_64-1.txz: Upgraded.
n/openssl-3.5.6-x86_64-1.txz: Upgraded.
This update fixes security issues:
Potential Use-after-free in DANE Client Code.
NULL Pointer Dereference When Processing a Delta CRL.
Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo.
Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo.
Converting an excessively large OCTET STRING value to a hexadecimal string
leads to a heap buffer overflow on 32 bit platforms.
Heap Buffer Overflow in Hexadecimal Conversion.
Incorrect Failure Handling in RSA KEM RSASVE Encapsulation.
For more information, see:
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28387
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28388
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28389
https://openssl-library.org/news/vulnerabilities/#CVE-2026-28390
https://openssl-library.org/news/vulnerabilities/#CVE-2026-31789
https://openssl-library.org/news/vulnerabilities/#CVE-2026-31790
https://www.cve.org/CVERecord?id=CVE-2026-28387
https://www.cve.org/CVERecord?id=CVE-2026-28388
https://www.cve.org/CVERecord?id=CVE-2026-28389
https://www.cve.org/CVERecord?id=CVE-2026-28390
https://www.cve.org/CVERecord?id=CVE-2026-31789
https://www.cve.org/CVERecord?id=CVE-2026-31790
(* Security fix *)
xap/mozilla-firefox-140.9.1esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.9.1/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-27/
https://www.cve.org/CVERecord?id=CVE-2026-5732
https://www.cve.org/CVERecord?id=CVE-2026-5731
https://www.cve.org/CVERecord?id=CVE-2026-5734
(* Security fix *)
xap/mozilla-thunderbird-140.9.1esr-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/140.9.1esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-29/
https://www.cve.org/CVERecord?id=CVE-2026-5732
https://www.cve.org/CVERecord?id=CVE-2026-5731
https://www.cve.org/CVERecord?id=CVE-2026-5734
(* Security fix *)
extra/brltty/brltty-6.9.1-x86_64-1.txz: Upgraded.