ChangeLog for: 2026-04-17 22:28:08

ap/cups-2.4.17-x86_64-1.txz: Upgraded. This update fixes security issues: The scheduler treated local user and group names as case-insensitive. The RSS notifier could write outside the scheduler's RSS directory. The scheduler did not filter control characters from option values. The scheduler did not always allocate enough memory for a job's options string. The scheduler incorrectly allowed local certificates over the loopback interface. Fixed the range check for job password strings. Fixed a printer subscription bug in the scheduler. Fixed a SNMP string conversion bug in the backends. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-27447 https://www.cve.org/CVERecord?id=CVE-2026-34978 https://www.cve.org/CVERecord?id=CVE-2026-34980 https://www.cve.org/CVERecord?id=CVE-2026-34979 https://www.cve.org/CVERecord?id=CVE-2026-34990 https://www.cve.org/CVERecord?id=CVE-2026-39314 https://www.cve.org/CVERecord?id=CVE-2026-39316 (* Security fix *) l/fast_float-8.2.5-x86_64-1.txz: Upgraded. l/mozilla-nss-3.123-x86_64-1.txz: Upgraded. l/openexr-3.4.10-x86_64-1.txz: Upgraded. HTJ2K Signed Integer Overflow in `ht_undo_impl()` Integer overflow in DWA `setupChannelData` `planarUncRle` pointer arithmetic (missed variant of CVE-2026-34589). Integer overflow in DWA decoder `outBufferEnd` pointer arithmetic (missed variant of CVE-2026-34589). For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-39886 https://www.cve.org/CVERecord?id=CVE-2026-40244 https://www.cve.org/CVERecord?id=CVE-2026-40250 (* Security fix *) n/samba-4.24.1-x86_64-1.txz: Upgraded. xap/gimp-3.2.4-x86_64-1.txz: Upgraded.