ChangeLog for: 2026-04-22 01:29:07

d/cmake-4.3.2-x86_64-1.txz: Upgraded. d/llvm-22.1.4-x86_64-1.txz: Upgraded. d/meson-1.11.1-x86_64-1.txz: Upgraded. d/ruby-4.0.3-x86_64-1.txz: Upgraded. This update fixes a security issue: ERB @_init deserialization guard bypass via def_module / def_method / def_class. Any Ruby application that calls Marshal.load on untrusted data AND has both erb and activesupport loaded is vulnerable to arbitrary code execution. For more information, see: https://www.ruby-lang.org/en/news/2026/04/21/ruby-4-0-3-released/ https://www.cve.org/CVERecord?id=CVE-2026-41316 (* Security fix *) d/valgrind-3.27.0-x86_64-1.txz: Upgraded. l/libclc-22.1.4-x86_64-1.txz: Upgraded. l/python-idna-3.12-x86_64-1.txz: Upgraded. x/labwc-0.9.7-x86_64-1.txz: Upgraded. x/libXpm-3.5.19-x86_64-1.txz: Upgraded. This update fixes a security issue: Out-of-bounds read in xpmNextWord(). For more information, see: https://lists.x.org/archives/xorg-devel/2026-April/059452.html https://www.cve.org/CVERecord?id=CVE-2026-4367 (* Security fix *) xap/mozilla-firefox-140.10.0esr-x86_64-1.txz: Upgraded. This update contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/firefox/140.10.0/releasenotes/ https://www.mozilla.org/security/advisories/mfsa2026-32/ https://www.cve.org/CVERecord?id=CVE-2026-6746 https://www.cve.org/CVERecord?id=CVE-2026-6747 https://www.cve.org/CVERecord?id=CVE-2026-6748 https://www.cve.org/CVERecord?id=CVE-2026-6749 https://www.cve.org/CVERecord?id=CVE-2026-6750 https://www.cve.org/CVERecord?id=CVE-2026-6751 https://www.cve.org/CVERecord?id=CVE-2026-6752 https://www.cve.org/CVERecord?id=CVE-2026-6753 https://www.cve.org/CVERecord?id=CVE-2026-6754 https://www.cve.org/CVERecord?id=CVE-2026-6757 https://www.cve.org/CVERecord?id=CVE-2026-6759 https://www.cve.org/CVERecord?id=CVE-2026-6761 https://www.cve.org/CVERecord?id=CVE-2026-6762 https://www.cve.org/CVERecord?id=CVE-2026-6763 https://www.cve.org/CVERecord?id=CVE-2026-6764 https://www.cve.org/CVERecord?id=CVE-2026-6765 https://www.cve.org/CVERecord?id=CVE-2026-6766 https://www.cve.org/CVERecord?id=CVE-2026-6767 https://www.cve.org/CVERecord?id=CVE-2026-6769 https://www.cve.org/CVERecord?id=CVE-2026-6770 https://www.cve.org/CVERecord?id=CVE-2026-6771 https://www.cve.org/CVERecord?id=CVE-2026-6772 https://www.cve.org/CVERecord?id=CVE-2026-6776 https://www.cve.org/CVERecord?id=CVE-2026-6785 https://www.cve.org/CVERecord?id=CVE-2026-6786 (* Security fix *) xap/mozilla-thunderbird-140.10.0esr-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/thunderbird/140.10.0esr/releasenotes/ https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird140.10 (* Security fix *)