ChangeLog for: 2026-04-14 23:07:31
l/jemalloc-5.3.1-x86_64-1.txz: Upgraded.
l/libexif-0.6.26-x86_64-1.txz: Upgraded.
This update fixes security issues:
An unsigned integer underflow in Fuji and Olympus makernote handling.
An unsigned integer overflow on 32bit systems in Nikon makernote handling.
A buffer overwrite via integer underflow in makernote handling.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-40386
https://www.cve.org/CVERecord?id=CVE-2026-40385
https://www.cve.org/CVERecord?id=CVE-2026-32775
(* Security fix *)
l/libxmlb-0.3.26-x86_64-1.txz: Upgraded.
Add bounds check to prevent OOB read in token index lookup (Richard Hughes).
Prevent stack overflow from unbounded recursion in export (Richard Hughes).
(* Security fix *)
l/mozilla-nss-3.122.1-x86_64-1.txz: Upgraded.
l/openexr-3.4.9-x86_64-2.txz: Rebuilt.
Recompiled against openjph-0.27.0.
l/openjph-0.27.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
l/python-editables-0.6-x86_64-1.txz: Upgraded.
n/iproute2-7.0.0-x86_64-1.txz: Upgraded.
x/xorg-server-21.1.22-x86_64-1.txz: Upgraded.
This update fixes security issues:
XKB Integer Underflow in XkbSetCompatMap().
XKB Out-of-bounds Read in CheckSetGeom().
XSYNC Use-after-free in miSyncTriggerFence().
XKB Out-of-bounds read in CheckModifierMap().
XKB Buffer overflow in CheckKeyTypes().
For more information, see:
https://lists.x.org/archives/xorg-devel/2026-April/059446.html
https://www.cve.org/CVERecord?id=CVE-2026-33999
https://www.cve.org/CVERecord?id=CVE-2026-34000
https://www.cve.org/CVERecord?id=CVE-2026-34001
https://www.cve.org/CVERecord?id=CVE-2026-34002
https://www.cve.org/CVERecord?id=CVE-2026-34003
(* Security fix *)
x/xorg-server-xephyr-21.1.22-x86_64-1.txz: Upgraded.
x/xorg-server-xnest-21.1.22-x86_64-1.txz: Upgraded.
x/xorg-server-xvfb-21.1.22-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-24.1.10-x86_64-1.txz: Upgraded.
This update fixes security issues:
XKB Integer Underflow in XkbSetCompatMap().
XKB Out-of-bounds Read in CheckSetGeom().
XSYNC Use-after-free in miSyncTriggerFence().
XKB Out-of-bounds read in CheckModifierMap().
XKB Buffer overflow in CheckKeyTypes().
For more information, see:
https://lists.x.org/archives/xorg-devel/2026-April/059446.html
https://www.cve.org/CVERecord?id=CVE-2026-33999
https://www.cve.org/CVERecord?id=CVE-2026-34000
https://www.cve.org/CVERecord?id=CVE-2026-34001
https://www.cve.org/CVERecord?id=CVE-2026-34002
https://www.cve.org/CVERecord?id=CVE-2026-34003
(* Security fix *)
x/xterm-409-x86_64-1.txz: Upgraded.