ChangeLog for: 2026-05-04 23:37:35

a/util-linux-2.42-x86_64-2.txz: Rebuilt. Harden perms on /bin/mount and /bin/umount. ap/lxc-7.0.0-x86_64-2.txz: Rebuilt. Harden perms on /usr/libexec/lxc/lxc-user-nic. d/ccache-4.13.6-x86_64-1.txz: Upgraded. d/python-pip-26.1.1-x86_64-1.txz: Upgraded. l/fuse-2.9.9-x86_64-5.txz: Rebuilt. Harden perms on /bin/fusermount. l/fuse3-3.16.2-x86_64-2.txz: Rebuilt. Harden perms on /usr/bin/fusermount3. l/libgtop-2.41.3-x86_64-2.txz: Rebuilt. Harden perms on /usr/lib64/libgtop/libgtop_server2. l/polkit-127-x86_64-2.txz: Rebuilt. n/httpd-2.4.67-x86_64-1.txz: Upgraded. This release fixes bugs and the following security issues: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data(). mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check. Off-by-one OOB reads in AJP getter functions. HTTP response splitting forwarding malicious status line. mod_authn_socache crash. mod_auth_digest timing attack. mod_md unrestricted OCSP response. buffer overflow in mod_proxy_ajp via ajp_msg_check_header(). mod_rewrite elevation of privileges via ap_expr. http2: double free and possible RCE on early reset. For more information, see: https://downloads.apache.org/httpd/CHANGES_2.4.67 https://www.cve.org/CVERecord?id=CVE-2026-34059 https://www.cve.org/CVERecord?id=CVE-2026-34032 https://www.cve.org/CVERecord?id=CVE-2026-33857 https://www.cve.org/CVERecord?id=CVE-2026-33523 https://www.cve.org/CVERecord?id=CVE-2026-33007 https://www.cve.org/CVERecord?id=CVE-2026-33006 https://www.cve.org/CVERecord?id=CVE-2026-29169 https://www.cve.org/CVERecord?id=CVE-2026-29168 https://www.cve.org/CVERecord?id=CVE-2026-28780 https://www.cve.org/CVERecord?id=CVE-2026-24072 https://www.cve.org/CVERecord?id=CVE-2026-23918 (* Security fix *) n/krb5-1.22.2-x86_64-2.txz: Rebuilt. Harden perms on /usr/bin/ksu. x/xf86-video-intel-20230201_b74b67f0-x86_64-2.txz: Rebuilt. Harden perms on /usr/libexec/xf86-video-intel-backlight-helper. x/xorg-server-21.1.22-x86_64-3.txz: Rebuilt. Harden perms on /usr/libexec/Xorg.wrap. x/xorg-server-xephyr-21.1.22-x86_64-3.txz: Rebuilt. x/xorg-server-xnest-21.1.22-x86_64-3.txz: Rebuilt. x/xorg-server-xvfb-21.1.22-x86_64-3.txz: Rebuilt. xap/xscreensaver-6.15-x86_64-2.txz: Rebuilt. Harden perms on /usr/libexec/xscreensaver/sonar and /usr/libexec/xscreensaver/xscreensaver-auth. y/nethack-5.0.0-x86_64-1.txz: Upgraded. Thanks to zapwai.