ChangeLog for: 2026-05-21 05:59:09

a/xfsprogs-7.0.1-x86_64-1.txz: Upgraded. ap/hplip-3.26.4-x86_64-1.txz: Upgraded. ap/tmux-3.6b-x86_64-1.txz: Upgraded. d/ruby-4.0.5-x86_64-1.txz: Upgraded. This update fixes a security issue: Use-after-free in pthread-based getaddrinfo timeout handler. For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-46727 (* Security fix *) d/valgrind-3.27.1-x86_64-1.txz: Upgraded. kde/marble-23.08.5-x86_64-14.txz: Rebuilt. Recompiled against protobuf-35.0. l/PyQt6-6.10.2-x86_64-1.txz: Added. Thanks to Gérard Monpontet. l/PyQt6_sip-13.11.1-x86_64-1.txz: Added. Thanks to Gérard Monpontet. l/SDL3_ttf-3.2.2-x86_64-1.txz: Added. Thanks to alienBOB. l/protobuf-35.0-x86_64-1.txz: Upgraded. Shared library .so-version bump. (Or, at least, we've been told to always expect ABI breakage) l/python-certifi-2026.5.20-x86_64-1.txz: Upgraded. l/python-trove-classifiers-2026.5.20.19-x86_64-1.txz: Upgraded. l/qt6-6.10.3_20260330_6417867c-x86_64-4.txz: Rebuilt. Recompiled against protobuf-35.0. n/bind-9.20.23-x86_64-1.txz: Upgraded. This update fixes security issues: Fix outgoing zone transfers' quota issue. Limit resolver server list size. Fix GSS-API resource leak. Fix crash in resolver when SIG(0)-signed responses are received under load. Add system test for HTTP/2 SETTINGS frame flood. Disable recursion, UPDATE, and NOTIFY for non-IN views. For more information, see: https://kb.isc.org/docs/CVE-2026-3592 https://kb.isc.org/docs/CVE-2026-3039 https://kb.isc.org/docs/CVE-2026-5947 https://kb.isc.org/docs/CVE-2026-3593 https://kb.isc.org/docs/CVE-2026-5946 https://www.cve.org/CVERecord?id=CVE-2026-3592 https://www.cve.org/CVERecord?id=CVE-2026-3039 https://www.cve.org/CVERecord?id=CVE-2026-5947 https://www.cve.org/CVERecord?id=CVE-2026-3593 https://www.cve.org/CVERecord?id=CVE-2026-5946 (* Security fix *) n/mosh-1.4.0-x86_64-20.txz: Rebuilt. Recompiled against protobuf-35.0. n/rsync-3.4.3-x86_64-1.txz: Upgraded. This update fixes security issues: TOCTOU symlink race condition allowing local privilege escalation in daemon mode without chroot. Hostname/ACL bypass on an rsync daemon configured with `daemon chroot = /X` in rsyncd.conf when the chroot tree lacks DNS resolution support. Integer overflow in the compressed-token decoder enabling remote memory disclosure to an authenticated daemon peer. Symlink races on path-based system calls in "use chroot = no" daemon mode. Out-of-bounds read in the receiver's recv_files() enabling remote denial-of-service of any client pulling from a malicious server. Off-by-one out-of-bounds stack write in the rsync client's HTTP CONNECT proxy handler (`establish_proxy_connection()` in `socket.c`). For more information, see: https://www.cve.org/CVERecord?id=CVE-2026-29518 https://www.cve.org/CVERecord?id=CVE-2026-43617 https://www.cve.org/CVERecord?id=CVE-2026-43618 https://www.cve.org/CVERecord?id=CVE-2026-43619 https://www.cve.org/CVERecord?id=CVE-2026-43620 https://www.cve.org/CVERecord?id=CVE-2026-45232 (* Security fix *)