ChangeLog for: 2026-07-06 23:46:09
a/sysvinit-scripts-15.1-noarch-39.txz: Rebuilt.
rc.M: don't use a relative path when looking in /var/lib/dkms/.
Thanks to jayjwa.
l/libfyaml-0.9.6-x86_64-1.txz: Upgraded.
l/librevenge-0.0.6-x86_64-1.txz: Upgraded.
l/python-pyproject_metadata-0.12.1-x86_64-1.txz: Upgraded.
l/qtkeychain-0.17.0-x86_64-1.txz: Upgraded.
n/c-ares-1.34.7-x86_64-1.txz: Upgraded.
This release fixes the following security issues:
Use-after-free / double-free in c-ares' query-completion handling, remotely
triggerable via ares_getaddrinfo() over TCP.
CPU-exhaustion denial of service via unbounded DNS name compression pointer
chains.
Memory-amplification denial of service via unvalidated DNS header record
counts.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-33630
https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
(* Security fix *)
n/openssh-10.4p1-x86_64-1.txz: Upgraded.
This release contains a number of security fixes:
sftp(1): when downloading files on the command-line using
"sftp host:/path .", a malicious server could cause the file to
be downloaded to an unexpected location. This issue was identified
by the Swival Security Scanner.
scp(1): when copying files between two remote destinations, do
not allow a malicious server to write files to the parent
directory of the intended target directory. This issue was
identified by the Swival Security Scanner.
sshd(8): when using the "internal-sftp" SFTP server implementation
(this is not the default), long command lines were previously
truncated silently after the 9th argument. If a security-relevant
option was in the 10th or later position, it would be discarded.
Reported by Steve Caffrey.
sshd(8): add a documentation note to mention that the
GSSAPIStrictAcceptorCheck option is ineffective when the server
is joined to a Windows Active Directory. Reported by Yarin Aharoni
of Safebreach.
sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes
as it was documented to do. Note that PermitTunnel is not enabled
by default. Reported independently by Huzaifa Sidhpurwala of
Redhat and Marko Jevtic.
sshd(8): avoid a potential pre-authentication denial of service
when GSSAPIAuthentication was enabled (this feature is off by
default). This was not mitigated by MaxAuthTries, but would be
penalised by PerSourcePenalties. This was reported by Manfred
Kaiser of the milCERT AT (Austrian Ministry of Defence).
sshd(8): fix a number of cases where the minimum authentication
delay was not being enforced. Reported by the Orange Cyberdefense
Vulnerability Team.
ssh(1): fix a possible client-side use-after-free if the server
changes its host key during a key reexchange. This was reported by
Zhenpeng (Leo) Lin of Depthfirst.
For more information, see:
https://www.openssh.org/releasenotes.html#10.4
(* Security fix *)
xap/freerdp-3.28.0-x86_64-1.txz: Upgraded.
This update fixes security issues.
For more information, see:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9g22-w2gr-vcmp
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f27x-frr8-j9hc
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v64m-xxfw-hrv6
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47fr-jw86-c3fj
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v5wf-j8j4-77h7
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m
(* Security fix *)
extra/bash-completion/bash-completion-2.18.0-noarch-1.txz: Upgraded.