ChangeLog for: 2026-07-08 22:48:24

l/libdiscid-0.7.0-x86_64-1.txz: Upgraded. l/libffi-3.7.0-x86_64-1.txz: Upgraded. l/netpbm-11.15.02-x86_64-1.txz: Upgraded. l/pipewire-1.6.7-x86_64-7.txz: Rebuilt. pipewire.sh: make the script a lot more robust, starting only if needed, and waiting for the pipewire socket to be available before starting the other daemons. pipewire.csh: start pipewire.sh through bash, which seems like cheating but hey, it works. Thanks to Petri Kaukasoina. pipewire-disable.sh: disable the pipewire profile.d scripts. pipewire-enable.sh: enable the pipewire profile.d scripts. l/python-hatchling-1.31.0-x86_64-1.txz: Upgraded. n/c-ares-1.34.8-x86_64-1.txz: Upgraded. n/ethtool-7.1-x86_64-1.txz: Upgraded. n/proftpd-1.3.9c-x86_64-1.txz: Upgraded. This update fixes bugs and security issues: ExecEnviron values not passed due to regression since 1.3.8.d. Stack buffer overflow in MLSD/MLST handling for long path names. MaxTransfersPerUser no longer enforces configured limits. AdminControlsACLs for config, get actions not honored as they should be. Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed buffers without bounds checking. RewriteMap unescape builtin use causes one-byte out-of-bounds write, fails to reject illegal characters. SQL group name lookup concatenates client-provided group names without escaping. Authenticated SFTP sessions can overflow the SFTP packet buffer. Default Controls socket ACLs unintentionally allow all users access for sending Controls requests. (* Security fix *) x/libXfont2-2.0.8-x86_64-1.txz: Upgraded. This update fixes security issues: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow. PCF Font Parsing Heap Buffer Overflow. computeProps Property Buffer Heap Buffer Overflow. For more information, see: https://lists.x.org/archives/xorg/2026-July/062253.html https://www.cve.org/CVERecord?id=CVE-2026-56001 https://www.cve.org/CVERecord?id=CVE-2026-56002 https://www.cve.org/CVERecord?id=CVE-2026-56003 (* Security fix *) x/libva-2.24.1-x86_64-1.txz: Upgraded. x/wlroots-0.20.2-x86_64-1.txz: Upgraded. x/xkbutils-1.0.7-x86_64-1.txz: Upgraded. x/xlsatoms-1.1.5-x86_64-1.txz: Upgraded. x/xlsfonts-1.0.9-x86_64-1.txz: Upgraded. x/xorg-server-21.1.24-x86_64-1.txz: Upgraded. This update fixes security issues: glamor Font Atlas Heap Buffer Overflow. GLX contextTags Use-After-Free in CommonMakeCurrent(). For more information, see: https://lists.x.org/archives/xorg/2026-July/062255.html https://www.cve.org/CVERecord?id=CVE-2026-55999 https://www.cve.org/CVERecord?id=CVE-2026-56000 (* Security fix *) x/xorg-server-xephyr-21.1.24-x86_64-1.txz: Upgraded. x/xorg-server-xnest-21.1.24-x86_64-1.txz: Upgraded. x/xorg-server-xvfb-21.1.24-x86_64-1.txz: Upgraded. x/xorg-server-xwayland-24.1.13-x86_64-1.txz: Upgraded. This update fixes security issues: glamor Font Atlas Heap Buffer Overflow. GLX contextTags Use-After-Free in CommonMakeCurrent(). For more information, see: https://lists.x.org/archives/xorg/2026-July/062255.html https://www.cve.org/CVERecord?id=CVE-2026-55999 https://www.cve.org/CVERecord?id=CVE-2026-56000 (* Security fix *)