ChangeLog for: 2026-06-04 22:45:06
ap/sqlite-3.53.2-x86_64-1.txz: Upgraded.
l/QScintilla-2.14.1-x86_64-5.txz: Removed.
Nothing in Slackware still uses this, so let's just drop it.
l/cairomm1-1.19.1-x86_64-1.txz: Upgraded.
n/dnsmasq-2.93-x86_64-1.txz: Upgraded.
Rework storage allocation for domain names. This fixes a security bug that
can cause heap-overwrite with long domain names.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-2291
(* Security fix *)
x/libinput-1.31.3-x86_64-1.txz: Upgraded.
This update fixes a security issue:
libinput-device-group unescaped phys output can inject udev properties
leading to arbitrary root code execution.
Note that since /dev/uinput and /dev/uhid are only accessible by root on
Slackware (and unlike some other distributions we make no exceptions), we
were not vulnerable to this flaw.
(* Security fix *)
testing/packages/php-8.5.7-x86_64-1.txz: Upgraded.
This is a bugfix release.
For more information, see:
https://www.php.net/ChangeLog-8.php#8.5.7