ChangeLog for: 2026-05-21 05:59:09
a/xfsprogs-7.0.1-x86_64-1.txz: Upgraded.
ap/hplip-3.26.4-x86_64-1.txz: Upgraded.
ap/tmux-3.6b-x86_64-1.txz: Upgraded.
d/ruby-4.0.5-x86_64-1.txz: Upgraded.
This update fixes a security issue:
Use-after-free in pthread-based getaddrinfo timeout handler.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-46727
(* Security fix *)
d/valgrind-3.27.1-x86_64-1.txz: Upgraded.
kde/marble-23.08.5-x86_64-14.txz: Rebuilt.
Recompiled against protobuf-35.0.
l/PyQt6-6.10.2-x86_64-1.txz: Added.
Thanks to Gérard Monpontet.
l/PyQt6_sip-13.11.1-x86_64-1.txz: Added.
Thanks to Gérard Monpontet.
l/SDL3_ttf-3.2.2-x86_64-1.txz: Added.
Thanks to alienBOB.
l/protobuf-35.0-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
(Or, at least, we've been told to always expect ABI breakage)
l/python-certifi-2026.5.20-x86_64-1.txz: Upgraded.
l/python-trove-classifiers-2026.5.20.19-x86_64-1.txz: Upgraded.
l/qt6-6.10.3_20260330_6417867c-x86_64-4.txz: Rebuilt.
Recompiled against protobuf-35.0.
n/bind-9.20.23-x86_64-1.txz: Upgraded.
This update fixes security issues:
Fix outgoing zone transfers' quota issue.
Limit resolver server list size.
Fix GSS-API resource leak.
Fix crash in resolver when SIG(0)-signed responses are received under load.
Add system test for HTTP/2 SETTINGS frame flood.
Disable recursion, UPDATE, and NOTIFY for non-IN views.
For more information, see:
https://kb.isc.org/docs/CVE-2026-3592
https://kb.isc.org/docs/CVE-2026-3039
https://kb.isc.org/docs/CVE-2026-5947
https://kb.isc.org/docs/CVE-2026-3593
https://kb.isc.org/docs/CVE-2026-5946
https://www.cve.org/CVERecord?id=CVE-2026-3592
https://www.cve.org/CVERecord?id=CVE-2026-3039
https://www.cve.org/CVERecord?id=CVE-2026-5947
https://www.cve.org/CVERecord?id=CVE-2026-3593
https://www.cve.org/CVERecord?id=CVE-2026-5946
(* Security fix *)
n/mosh-1.4.0-x86_64-20.txz: Rebuilt.
Recompiled against protobuf-35.0.
n/rsync-3.4.3-x86_64-1.txz: Upgraded.
This update fixes security issues:
TOCTOU symlink race condition allowing local privilege escalation in daemon
mode without chroot.
Hostname/ACL bypass on an rsync daemon configured with `daemon chroot = /X`
in rsyncd.conf when the chroot tree lacks DNS resolution support.
Integer overflow in the compressed-token decoder enabling remote memory
disclosure to an authenticated daemon peer.
Symlink races on path-based system calls in "use chroot = no" daemon mode.
Out-of-bounds read in the receiver's recv_files() enabling remote
denial-of-service of any client pulling from a malicious server.
Off-by-one out-of-bounds stack write in the rsync client's HTTP CONNECT proxy
handler (`establish_proxy_connection()` in `socket.c`).
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-29518
https://www.cve.org/CVERecord?id=CVE-2026-43617
https://www.cve.org/CVERecord?id=CVE-2026-43618
https://www.cve.org/CVERecord?id=CVE-2026-43619
https://www.cve.org/CVERecord?id=CVE-2026-43620
https://www.cve.org/CVERecord?id=CVE-2026-45232
(* Security fix *)