ChangeLog for: 2026-04-22 01:29:07
d/cmake-4.3.2-x86_64-1.txz: Upgraded.
d/llvm-22.1.4-x86_64-1.txz: Upgraded.
d/meson-1.11.1-x86_64-1.txz: Upgraded.
d/ruby-4.0.3-x86_64-1.txz: Upgraded.
This update fixes a security issue:
ERB @_init deserialization guard bypass via def_module / def_method /
def_class. Any Ruby application that calls Marshal.load on untrusted data
AND has both erb and activesupport loaded is vulnerable to arbitrary code
execution.
For more information, see:
https://www.ruby-lang.org/en/news/2026/04/21/ruby-4-0-3-released/
https://www.cve.org/CVERecord?id=CVE-2026-41316
(* Security fix *)
d/valgrind-3.27.0-x86_64-1.txz: Upgraded.
l/libclc-22.1.4-x86_64-1.txz: Upgraded.
l/python-idna-3.12-x86_64-1.txz: Upgraded.
x/labwc-0.9.7-x86_64-1.txz: Upgraded.
x/libXpm-3.5.19-x86_64-1.txz: Upgraded.
This update fixes a security issue:
Out-of-bounds read in xpmNextWord().
For more information, see:
https://lists.x.org/archives/xorg-devel/2026-April/059452.html
https://www.cve.org/CVERecord?id=CVE-2026-4367
(* Security fix *)
xap/mozilla-firefox-140.10.0esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.10.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-32/
https://www.cve.org/CVERecord?id=CVE-2026-6746
https://www.cve.org/CVERecord?id=CVE-2026-6747
https://www.cve.org/CVERecord?id=CVE-2026-6748
https://www.cve.org/CVERecord?id=CVE-2026-6749
https://www.cve.org/CVERecord?id=CVE-2026-6750
https://www.cve.org/CVERecord?id=CVE-2026-6751
https://www.cve.org/CVERecord?id=CVE-2026-6752
https://www.cve.org/CVERecord?id=CVE-2026-6753
https://www.cve.org/CVERecord?id=CVE-2026-6754
https://www.cve.org/CVERecord?id=CVE-2026-6757
https://www.cve.org/CVERecord?id=CVE-2026-6759
https://www.cve.org/CVERecord?id=CVE-2026-6761
https://www.cve.org/CVERecord?id=CVE-2026-6762
https://www.cve.org/CVERecord?id=CVE-2026-6763
https://www.cve.org/CVERecord?id=CVE-2026-6764
https://www.cve.org/CVERecord?id=CVE-2026-6765
https://www.cve.org/CVERecord?id=CVE-2026-6766
https://www.cve.org/CVERecord?id=CVE-2026-6767
https://www.cve.org/CVERecord?id=CVE-2026-6769
https://www.cve.org/CVERecord?id=CVE-2026-6770
https://www.cve.org/CVERecord?id=CVE-2026-6771
https://www.cve.org/CVERecord?id=CVE-2026-6772
https://www.cve.org/CVERecord?id=CVE-2026-6776
https://www.cve.org/CVERecord?id=CVE-2026-6785
https://www.cve.org/CVERecord?id=CVE-2026-6786
(* Security fix *)
xap/mozilla-thunderbird-140.10.0esr-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/140.10.0esr/releasenotes/
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird140.10
(* Security fix *)