ChangeLog for: 2026-04-17 22:28:08
ap/cups-2.4.17-x86_64-1.txz: Upgraded.
This update fixes security issues:
The scheduler treated local user and group names as case-insensitive.
The RSS notifier could write outside the scheduler's RSS directory.
The scheduler did not filter control characters from option values.
The scheduler did not always allocate enough memory for a job's options
string.
The scheduler incorrectly allowed local certificates over the loopback
interface.
Fixed the range check for job password strings.
Fixed a printer subscription bug in the scheduler.
Fixed a SNMP string conversion bug in the backends.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-27447
https://www.cve.org/CVERecord?id=CVE-2026-34978
https://www.cve.org/CVERecord?id=CVE-2026-34980
https://www.cve.org/CVERecord?id=CVE-2026-34979
https://www.cve.org/CVERecord?id=CVE-2026-34990
https://www.cve.org/CVERecord?id=CVE-2026-39314
https://www.cve.org/CVERecord?id=CVE-2026-39316
(* Security fix *)
l/fast_float-8.2.5-x86_64-1.txz: Upgraded.
l/mozilla-nss-3.123-x86_64-1.txz: Upgraded.
l/openexr-3.4.10-x86_64-1.txz: Upgraded.
HTJ2K Signed Integer Overflow in `ht_undo_impl()`
Integer overflow in DWA `setupChannelData` `planarUncRle` pointer arithmetic
(missed variant of CVE-2026-34589).
Integer overflow in DWA decoder `outBufferEnd` pointer arithmetic
(missed variant of CVE-2026-34589).
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-39886
https://www.cve.org/CVERecord?id=CVE-2026-40244
https://www.cve.org/CVERecord?id=CVE-2026-40250
(* Security fix *)
n/samba-4.24.1-x86_64-1.txz: Upgraded.
xap/gimp-3.2.4-x86_64-1.txz: Upgraded.