ChangeLog for: 2026-05-03 02:36:26

a/dracut-111-x86_64-1.txz: Upgraded. a/elogind-255.23-x86_64-1.txz: Upgraded. a/haveged-1.9.20-x86_64-1.txz: Upgraded. a/kernel-firmware-20260429_56a13f9-noarch-1.txz: Upgraded. a/kernel-generic-6.18.26-x86_64-1.txz: Upgraded. This update fixes a critical security issue: An out-of-bounds write in the userspace interface for AEAD cipher algorithms may be leveraged to get a root shell through a setuid binary. While the proof of concepts for this have so far targeted different program versions than Slackware uses, there's nothing preventing anyone from targeting one a setuid binary that we use. Mitigation: If for some reason it's not possible to upgrade the kernel right away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove the algif_aead.ko kernel module to prevent the exploit. For more information, see: https://copy.fail/ https://www.cve.org/CVERecord?id=CVE-2026-31431 (* Security fix *) ap/joe-4.8-x86_64-1.txz: Upgraded. ap/lxc-7.0.0-x86_64-1.txz: Upgraded. ap/vim-9.2.0433-x86_64-1.txz: Upgraded. d/doxygen-1.17.0-x86_64-1.txz: Upgraded. d/kernel-headers-6.18.26-x86-1.txz: Upgraded. k/kernel-source-6.18.26-noarch-1.txz: Upgraded. kde/xsimd-14.2.0-noarch-1.txz: Upgraded. l/SDL2_image-2.8.12-x86_64-1.txz: Upgraded. l/SDL3-3.4.8-x86_64-1.txz: Upgraded. l/at-spi2-core-2.60.3-x86_64-1.txz: Upgraded. l/cfitsio-4.6.4-x86_64-1.txz: Upgraded. l/enchant-2.8.16-x86_64-1.txz: Upgraded. l/glib2-2.88.1-x86_64-1.txz: Upgraded. l/gtk4-4.22.4-x86_64-1.txz: Upgraded. l/libgsf-1.14.58-x86_64-1.txz: Upgraded. l/openexr-3.4.11-x86_64-1.txz: Upgraded. Patch release that addresses the following security vulnerabilities: Shift exponent overflow in readVariableLengthInteger(). Out-of-bounds read in IDManifest::init() during prefix expansion. Integer overflow in ImageChannel::resize leads to heap OOB write via OpenEXRUtil public API. Heap-buffer-overflow in DwaCompressor_uncompress. Null-dereference READ in Imf_3_3::prefixFromLayerName. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-42217 https://www.cve.org/CVERecord?id=CVE-2026-42216 https://www.cve.org/CVERecord?id=CVE-2026-41142 (* Security fix *) l/python-build-1.5.0-x86_64-1.txz: Upgraded. l/qtkeychain-0.16.0-x86_64-1.txz: Upgraded. l/spirv-llvm-translator-22.1.2-x86_64-1.txz: Upgraded. n/curl-8.20.0-x86_64-1.txz: Upgraded. n/dhcpcd-10.3.2-x86_64-1.txz: Upgraded. n/gnutls-3.8.13-x86_64-1.txz: Upgraded. This update fixes a security issue: Add more checks to DTLS reassembly. Previously, gnutls didn't check that DTLS fragments claimed a consistent message_length value. Additionally, a crucial array size check was missing, enabling an attacker to cause a heap overwrite. Reject fragments with mismatching length and add a missing boundary check. Independently reported by Haruto Kimura (Stella), Oscar Reparaz and Zou Dikai. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-33846 (* Security fix *) n/openvpn-2.7.4-x86_64-1.txz: Upgraded. n/postfix-3.11.2-x86_64-1.txz: Upgraded. x/ibus-1.5.34-x86_64-1.txz: Upgraded. x/mesa-26.0.6-x86_64-1.txz: Upgraded. x/noto-fonts-ttf-2026.05.01-noarch-1.txz: Upgraded. x/xterm-410-x86_64-1.txz: Upgraded. xap/mozilla-thunderbird-140.10.1esr-x86_64-1.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/thunderbird/140.10.1esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2026-39/ https://www.cve.org/CVERecord?id=CVE-2026-7320 https://www.cve.org/CVERecord?id=CVE-2026-7321 https://www.cve.org/CVERecord?id=CVE-2026-7322 https://www.cve.org/CVERecord?id=CVE-2026-7323 (* Security fix *) xap/vim-gvim-9.2.0433-x86_64-1.txz: Upgraded. isolinux/initrd.img: Rebuilt. kernels/*: Upgraded. testing/packages/linux-7.0.x/kernel-generic-7.0.3-x86_64-1.txz: Upgraded. This update fixes a critical security issue: An out-of-bounds write in the userspace interface for AEAD cipher algorithms may be leveraged to get a root shell through a setuid binary. While the proof of concepts for this have so far targeted different program versions than Slackware uses, there's nothing preventing anyone from targeting one a setuid binary that we use. Mitigation: If for some reason it's not possible to upgrade the kernel right away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove the algif_aead.ko kernel module to prevent the exploit. For more information, see: https://copy.fail/ https://www.cve.org/CVERecord?id=CVE-2026-31431 (* Security fix *) testing/packages/linux-7.0.x/kernel-headers-7.0.3-x86-1.txz: Upgraded. testing/packages/linux-7.0.x/kernel-source-7.0.3-noarch-1.txz: Upgraded. testing/packages/mesa-26.1.0_rc3-x86_64-1.txz: Upgraded. usb-and-pxe-installers/usbboot.img: Rebuilt.