ChangeLog for: 2026-07-08 22:48:24
l/libdiscid-0.7.0-x86_64-1.txz: Upgraded.
l/libffi-3.7.0-x86_64-1.txz: Upgraded.
l/netpbm-11.15.02-x86_64-1.txz: Upgraded.
l/pipewire-1.6.7-x86_64-7.txz: Rebuilt.
pipewire.sh: make the script a lot more robust, starting only if needed,
and waiting for the pipewire socket to be available before starting the
other daemons.
pipewire.csh: start pipewire.sh through bash, which seems like cheating
but hey, it works.
Thanks to Petri Kaukasoina.
pipewire-disable.sh: disable the pipewire profile.d scripts.
pipewire-enable.sh: enable the pipewire profile.d scripts.
l/python-hatchling-1.31.0-x86_64-1.txz: Upgraded.
n/c-ares-1.34.8-x86_64-1.txz: Upgraded.
n/ethtool-7.1-x86_64-1.txz: Upgraded.
n/proftpd-1.3.9c-x86_64-1.txz: Upgraded.
This update fixes bugs and security issues:
ExecEnviron values not passed due to regression since 1.3.8.d.
Stack buffer overflow in MLSD/MLST handling for long path names.
MaxTransfersPerUser no longer enforces configured limits.
AdminControlsACLs for config, get actions not honored as they should be.
Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed
buffers without bounds checking.
RewriteMap unescape builtin use causes one-byte out-of-bounds write,
fails to reject illegal characters.
SQL group name lookup concatenates client-provided group names without
escaping.
Authenticated SFTP sessions can overflow the SFTP packet buffer.
Default Controls socket ACLs unintentionally allow all users access for
sending Controls requests.
(* Security fix *)
x/libXfont2-2.0.8-x86_64-1.txz: Upgraded.
This update fixes security issues:
BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow.
PCF Font Parsing Heap Buffer Overflow.
computeProps Property Buffer Heap Buffer Overflow.
For more information, see:
https://lists.x.org/archives/xorg/2026-July/062253.html
https://www.cve.org/CVERecord?id=CVE-2026-56001
https://www.cve.org/CVERecord?id=CVE-2026-56002
https://www.cve.org/CVERecord?id=CVE-2026-56003
(* Security fix *)
x/libva-2.24.1-x86_64-1.txz: Upgraded.
x/wlroots-0.20.2-x86_64-1.txz: Upgraded.
x/xkbutils-1.0.7-x86_64-1.txz: Upgraded.
x/xlsatoms-1.1.5-x86_64-1.txz: Upgraded.
x/xlsfonts-1.0.9-x86_64-1.txz: Upgraded.
x/xorg-server-21.1.24-x86_64-1.txz: Upgraded.
This update fixes security issues:
glamor Font Atlas Heap Buffer Overflow.
GLX contextTags Use-After-Free in CommonMakeCurrent().
For more information, see:
https://lists.x.org/archives/xorg/2026-July/062255.html
https://www.cve.org/CVERecord?id=CVE-2026-55999
https://www.cve.org/CVERecord?id=CVE-2026-56000
(* Security fix *)
x/xorg-server-xephyr-21.1.24-x86_64-1.txz: Upgraded.
x/xorg-server-xnest-21.1.24-x86_64-1.txz: Upgraded.
x/xorg-server-xvfb-21.1.24-x86_64-1.txz: Upgraded.
x/xorg-server-xwayland-24.1.13-x86_64-1.txz: Upgraded.
This update fixes security issues:
glamor Font Atlas Heap Buffer Overflow.
GLX contextTags Use-After-Free in CommonMakeCurrent().
For more information, see:
https://lists.x.org/archives/xorg/2026-July/062255.html
https://www.cve.org/CVERecord?id=CVE-2026-55999
https://www.cve.org/CVERecord?id=CVE-2026-56000
(* Security fix *)