ChangeLog for: 2026-05-08 06:00:03
a/kernel-firmware-20260507_b3d71e9-noarch-1.txz: Upgraded.
a/kernel-generic-6.18.27-x86_64-1.txz: Upgraded.
a/xfsprogs-7.0.0-x86_64-1.txz: Upgraded.
d/kernel-headers-6.18.27-x86-1.txz: Upgraded.
d/mercurial-7.2.2-x86_64-1.txz: Upgraded.
k/kernel-source-6.18.27-noarch-1.txz: Upgraded.
l/mozjs140-140.10.2esr-x86_64-1.txz: Upgraded.
l/openjph-0.27.1-x86_64-1.txz: Upgraded.
l/python-urllib3-2.7.0-x86_64-1.txz: Upgraded.
n/libgpg-error-1.61-x86_64-1.txz: Upgraded.
This update fixes bugs and security issues:
Fix possible stack overflow in es_printf for %.100f format.
Fix out-of-bounds read in vfnameconcat.
(* Security fix *)
n/php-8.4.21-x86_64-1.txz: Upgraded.
This update fixes security issues:
DOM: Fixed Dom\XMLDocument::C14N() emits duplicate xmlns declarations after
setAttributeNS().
FPM: Fixed XSS within status endpoint.
MBString: Fixed Null pointer dereference in php_mb_check_encoding()
via mb_ereg_search_init().
MBString: Fixed Out-of-bounds access in mbfl_name2encoding_ex().
PDO_Firebird: Fixed SQL injection via NUL bytes in quoted strings.
SOAP: Fixed Stale SOAP_GLOBAL(ref_map) pointer with Apache Map.
SOAP: Fixed Use-after-free after header parsing failure with
SOAP_PERSISTENCE_SESSION.
SOAP: Fixed Broken Apache map value NULL check.
Standard: Fixed Signed integer overflow of char array offset.
Standard: Fixed Consistently pass unsigned char to ctype.h functions.
URI: Fixed uriparser before 1.0.1 has numeric truncation in text range comparison.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.4.21
https://www.cve.org/CVERecord?id=CVE-2026-7263
https://www.cve.org/CVERecord?id=CVE-2026-6735
https://www.cve.org/CVERecord?id=CVE-2026-7259
https://www.cve.org/CVERecord?id=CVE-2026-6104
https://www.cve.org/CVERecord?id=CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2026-6722
https://www.cve.org/CVERecord?id=CVE-2026-7261
https://www.cve.org/CVERecord?id=CVE-2026-7262
https://www.cve.org/CVERecord?id=CVE-2026-7568
https://www.cve.org/CVERecord?id=CVE-2026-7258
https://www.cve.org/CVERecord?id=CVE-2026-42371
(* Security fix *)
xap/mozilla-firefox-140.10.2esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.10.2/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-41
https://www.cve.org/CVERecord?id=CVE-2026-8090
https://www.cve.org/CVERecord?id=CVE-2026-8094
https://www.cve.org/CVERecord?id=CVE-2026-8092
(* Security fix *)
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-7.0.x/kernel-generic-7.0.4-x86_64-1.txz: Upgraded.
testing/packages/linux-7.0.x/kernel-headers-7.0.4-x86-1.txz: Upgraded.
testing/packages/linux-7.0.x/kernel-source-7.0.4-noarch-1.txz: Upgraded.
testing/packages/php-8.5.6-x86_64-1.txz: Upgraded.
This update fixes security issues:
DOM: Fixed Dom\XMLDocument::C14N() emits duplicate xmlns declarations after
setAttributeNS().
FPM: Fixed XSS within status endpoint.
MBString: Fixed Null pointer dereference in php_mb_check_encoding()
via mb_ereg_search_init().
MBString: Fixed Out-of-bounds access in mbfl_name2encoding_ex().
PDO_Firebird: Fixed SQL injection via NUL bytes in quoted strings.
SOAP: Fixed Stale SOAP_GLOBAL(ref_map) pointer with Apache Map.
SOAP: Fixed Use-after-free after header parsing failure with
SOAP_PERSISTENCE_SESSION.
SOAP: Fixed Broken Apache map value NULL check.
Standard: Fixed Signed integer overflow of char array offset.
Standard: Fixed Consistently pass unsigned char to ctype.h functions.
URI: Fixed uriparser before 1.0.1 has numeric truncation in text range comparison.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.5.6
https://www.cve.org/CVERecord?id=CVE-2026-7263
https://www.cve.org/CVERecord?id=CVE-2026-6735
https://www.cve.org/CVERecord?id=CVE-2026-7259
https://www.cve.org/CVERecord?id=CVE-2026-6104
https://www.cve.org/CVERecord?id=CVE-2025-14179
https://www.cve.org/CVERecord?id=CVE-2026-6722
https://www.cve.org/CVERecord?id=CVE-2026-7261
https://www.cve.org/CVERecord?id=CVE-2026-7262
https://www.cve.org/CVERecord?id=CVE-2026-7568
https://www.cve.org/CVERecord?id=CVE-2026-7258
https://www.cve.org/CVERecord?id=CVE-2026-42371
(* Security fix *)
usb-and-pxe-installers/usbboot.img: Rebuilt.