ChangeLog for: 2026-05-27 00:17:58
kde/krita-6.0.2-x86_64-1.txz: Upgraded.
l/dtc-1.8.0-x86_64-1.txz: Upgraded.
l/imagemagick-7.1.2_24-x86_64-1.txz: Upgraded.
l/libvisio-0.1.11-x86_64-1.txz: Upgraded.
l/pipewire-1.6.6-x86_64-1.txz: Upgraded.
l/potrace-1.16-x86_64-1.txz: Added.
n/NetworkManager-1.56.1-x86_64-2.txz: Rebuilt.
Rebuilt to pick up the new plugin directory for ppp-2.5.3.
n/libslirp-4.9.3-x86_64-1.txz: Upgraded.
n/ppp-2.5.3-x86_64-1.txz: Upgraded.
n/rp-pppoe-4.0-x86_64-3.txz: Rebuilt.
Rebuilt to pick up the new plugin directory for ppp-2.5.3.
n/samba-4.24.3-x86_64-1.txz: Upgraded.
This is a security release in order to address the following defects:
Missing access checks on reparse point operations.
WORM vfs module does not block overwrites.
Auto-enrollment GPO installing CA certificate over http without verification.
Denial of service against AD DC WINS server.
Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server.
Unauthenticated Remote Code Execution in Samba printing subsystem.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-1933
https://www.cve.org/CVERecord?id=CVE-2026-2340
https://www.cve.org/CVERecord?id=CVE-2026-3012
https://www.cve.org/CVERecord?id=CVE-2026-3238
https://www.cve.org/CVERecord?id=CVE-2026-4408
https://www.cve.org/CVERecord?id=CVE-2026-4480
https://www.samba.org/samba/security/CVE-2026-1933.html
https://www.samba.org/samba/security/CVE-2026-2340.html
https://www.samba.org/samba/security/CVE-2026-3012.html
https://www.samba.org/samba/security/CVE-2026-3238.html
https://www.samba.org/samba/security/CVE-2026-4408.html
https://www.samba.org/samba/security/CVE-2026-4480.html
(* Security fix *)
x/labwc-0.20.0-x86_64-1.txz: Upgraded.
x/wlroots-0.20.1-x86_64-1.txz: Upgraded.
Shared library .so-version bump.
x/xlsclients-1.1.6-x86_64-1.txz: Upgraded.
xap/mozilla-thunderbird-140.11.1esr-x86_64-1.txz: Upgraded.
This release contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/thunderbird/140.11.1esr/releasenotes/
(* Security fix *)