ChangeLog for: 2026-05-03 02:36:26
a/dracut-111-x86_64-1.txz: Upgraded.
a/elogind-255.23-x86_64-1.txz: Upgraded.
a/haveged-1.9.20-x86_64-1.txz: Upgraded.
a/kernel-firmware-20260429_56a13f9-noarch-1.txz: Upgraded.
a/kernel-generic-6.18.26-x86_64-1.txz: Upgraded.
This update fixes a critical security issue:
An out-of-bounds write in the userspace interface for AEAD cipher algorithms
may be leveraged to get a root shell through a setuid binary. While the
proof of concepts for this have so far targeted different program versions
than Slackware uses, there's nothing preventing anyone from targeting one
a setuid binary that we use.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove
the algif_aead.ko kernel module to prevent the exploit.
For more information, see:
https://copy.fail/
https://www.cve.org/CVERecord?id=CVE-2026-31431
(* Security fix *)
ap/joe-4.8-x86_64-1.txz: Upgraded.
ap/lxc-7.0.0-x86_64-1.txz: Upgraded.
ap/vim-9.2.0433-x86_64-1.txz: Upgraded.
d/doxygen-1.17.0-x86_64-1.txz: Upgraded.
d/kernel-headers-6.18.26-x86-1.txz: Upgraded.
k/kernel-source-6.18.26-noarch-1.txz: Upgraded.
kde/xsimd-14.2.0-noarch-1.txz: Upgraded.
l/SDL2_image-2.8.12-x86_64-1.txz: Upgraded.
l/SDL3-3.4.8-x86_64-1.txz: Upgraded.
l/at-spi2-core-2.60.3-x86_64-1.txz: Upgraded.
l/cfitsio-4.6.4-x86_64-1.txz: Upgraded.
l/enchant-2.8.16-x86_64-1.txz: Upgraded.
l/glib2-2.88.1-x86_64-1.txz: Upgraded.
l/gtk4-4.22.4-x86_64-1.txz: Upgraded.
l/libgsf-1.14.58-x86_64-1.txz: Upgraded.
l/openexr-3.4.11-x86_64-1.txz: Upgraded.
Patch release that addresses the following security vulnerabilities:
Shift exponent overflow in readVariableLengthInteger().
Out-of-bounds read in IDManifest::init() during prefix expansion.
Integer overflow in ImageChannel::resize leads to heap OOB write via
OpenEXRUtil public API.
Heap-buffer-overflow in DwaCompressor_uncompress.
Null-dereference READ in Imf_3_3::prefixFromLayerName.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-42217
https://www.cve.org/CVERecord?id=CVE-2026-42216
https://www.cve.org/CVERecord?id=CVE-2026-41142
(* Security fix *)
l/python-build-1.5.0-x86_64-1.txz: Upgraded.
l/qtkeychain-0.16.0-x86_64-1.txz: Upgraded.
l/spirv-llvm-translator-22.1.2-x86_64-1.txz: Upgraded.
n/curl-8.20.0-x86_64-1.txz: Upgraded.
n/dhcpcd-10.3.2-x86_64-1.txz: Upgraded.
n/gnutls-3.8.13-x86_64-1.txz: Upgraded.
This update fixes a security issue:
Add more checks to DTLS reassembly. Previously, gnutls didn't check that
DTLS fragments claimed a consistent message_length value. Additionally,
a crucial array size check was missing, enabling an attacker to cause a
heap overwrite. Reject fragments with mismatching length and add a missing
boundary check. Independently reported by Haruto Kimura (Stella), Oscar
Reparaz and Zou Dikai.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-33846
(* Security fix *)
n/openvpn-2.7.4-x86_64-1.txz: Upgraded.
n/postfix-3.11.2-x86_64-1.txz: Upgraded.
x/ibus-1.5.34-x86_64-1.txz: Upgraded.
x/mesa-26.0.6-x86_64-1.txz: Upgraded.
x/noto-fonts-ttf-2026.05.01-noarch-1.txz: Upgraded.
x/xterm-410-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-140.10.1esr-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/140.10.1esr/releasenotes/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-39/
https://www.cve.org/CVERecord?id=CVE-2026-7320
https://www.cve.org/CVERecord?id=CVE-2026-7321
https://www.cve.org/CVERecord?id=CVE-2026-7322
https://www.cve.org/CVERecord?id=CVE-2026-7323
(* Security fix *)
xap/vim-gvim-9.2.0433-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-7.0.x/kernel-generic-7.0.3-x86_64-1.txz: Upgraded.
This update fixes a critical security issue:
An out-of-bounds write in the userspace interface for AEAD cipher algorithms
may be leveraged to get a root shell through a setuid binary. While the
proof of concepts for this have so far targeted different program versions
than Slackware uses, there's nothing preventing anyone from targeting one
a setuid binary that we use.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove
the algif_aead.ko kernel module to prevent the exploit.
For more information, see:
https://copy.fail/
https://www.cve.org/CVERecord?id=CVE-2026-31431
(* Security fix *)
testing/packages/linux-7.0.x/kernel-headers-7.0.3-x86-1.txz: Upgraded.
testing/packages/linux-7.0.x/kernel-source-7.0.3-noarch-1.txz: Upgraded.
testing/packages/mesa-26.1.0_rc3-x86_64-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.