ChangeLog for: 2026-05-12 03:16:39
a/bcachefs-tools-1.38.3-x86_64-1.txz: Upgraded.
a/kernel-generic-6.18.29-x86_64-1.txz: Upgraded.
This update fixes a security issue:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present.
This fixes the second "Dirty Frag" vulnerability.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away you may blacklist or remove the kernel module rxrpc.ko (CVE-2026-43500).
Also remove the module from the kernel if it has been loaded:
rmmod rxrpc
And, drop the file caches in case in-memory program copies have already
been compromised. Make sure possibly affected programs do not have any
open sessions first:
sh -c "echo 3 > /proc/sys/vm/drop_caches"
For more information, see:
https://github.com/V4bel/dirtyfrag
https://www.cve.org/CVERecord?id=CVE-2026-43500
(* Security fix *)
ap/vim-9.2.0475-x86_64-1.txz: Upgraded.
d/kernel-headers-6.18.29-x86-1.txz: Upgraded.
k/kernel-source-6.18.29-noarch-1.txz: Upgraded.
kde/wcslib-8.7-x86_64-1.txz: Upgraded.
l/SDL2_mixer-2.8.2-x86_64-1.txz: Upgraded.
l/expat-2.8.1-x86_64-1.txz: Upgraded.
This update fixes a security issue:
Fix quadratic runtime from attribute name collision checks that allowed
denial of service attacks through moderately sized crafted XML input
(CWE-407). Please note that a layer of compression around XML can
significantly reduce the minimum attack payload size.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-45186
(* Security fix *)
l/python-idna-3.14-x86_64-1.txz: Upgraded.
l/python-installer-1.0.1-x86_64-1.txz: Upgraded.
l/python-requests-2.34.0-x86_64-1.txz: Upgraded.
xap/vim-gvim-9.2.0475-x86_64-1.txz: Upgraded.
isolinux/initrd.img: Rebuilt.
kernels/*: Upgraded.
testing/packages/linux-7.0.x/kernel-generic-7.0.6-x86_64-1.txz: Upgraded.
This update fixes a security issue:
rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present.
This fixes the second "Dirty Frag" vulnerability.
Mitigation: If for some reason it's not possible to upgrade the kernel right
away you may blacklist or remove the kernel module rxrpc.ko (CVE-2026-43500).
Also remove the module from the kernel if it has been loaded:
rmmod rxrpc
And, drop the file caches in case in-memory program copies have already
been compromised. Make sure possibly affected programs do not have any
open sessions first:
sh -c "echo 3 > /proc/sys/vm/drop_caches"
For more information, see:
https://github.com/V4bel/dirtyfrag
https://www.cve.org/CVERecord?id=CVE-2026-43500
(* Security fix *)
testing/packages/linux-7.0.x/kernel-headers-7.0.6-x86-1.txz: Upgraded.
testing/packages/linux-7.0.x/kernel-source-7.0.6-noarch-1.txz: Upgraded.
usb-and-pxe-installers/usbboot.img: Rebuilt.