ChangeLog for: 2026-07-22 01:25:16
a/sysvinit-3.18-x86_64-2.txz: Rebuilt.
Fix init --version. Thanks to r1w1s1.
d/cbindgen-0.29.4-x86_64-1.txz: Upgraded.
d/parallel-20260722-noarch-1.txz: Upgraded.
kde/kddockwidgets-2.4.1-x86_64-1.txz: Upgraded.
kde/kimageformats-6.28.1-x86_64-1.txz: Upgraded.
kde/qgpgme-2.2.0-x86_64-1.txz: Upgraded.
kde/syntax-highlighting-6.28.1-x86_64-1.txz: Upgraded.
l/libssh-0.12.1-x86_64-1.txz: Upgraded.
This update fixes security issues:
Stack buffer overflow in SFTP server longname construction.
Information disclosure via short GSSAPI Curve25519 public key.
Denial of service via zero advertised channel packet size.
Denial of service via oversized SFTP read length.
Denial of service via unchecked ProxyCommand fork() failure.
Information disclosure via ProxyCommand %r username expansion.
Integrity downgrade via OpenSSL AES-GCM tag verification.
Denial of service via SFTP responses with unknown request IDs.
Denial of service via automatic certificate authentication loop.
Use-after-free via data callbacks on closed channels.
Authentication bypass via missing GSSAPI principal check.
Zero-initialize every ssh_string.
For more information, see:
https://www.cve.org/CVERecord?id=CVE-2026-15370
https://www.cve.org/CVERecord?id=CVE-2026-59842
https://www.cve.org/CVERecord?id=CVE-2026-59843
https://www.cve.org/CVERecord?id=CVE-2026-59844
https://www.cve.org/CVERecord?id=CVE-2026-59845
https://www.cve.org/CVERecord?id=CVE-2026-59846
https://www.cve.org/CVERecord?id=CVE-2026-59847
https://www.cve.org/CVERecord?id=CVE-2026-59848
https://www.cve.org/CVERecord?id=CVE-2026-59849
https://www.cve.org/CVERecord?id=CVE-2026-59850
https://www.cve.org/CVERecord?id=CVE-2026-59851
(* Security fix *)
l/mozjs140-140.13.0esr-x86_64-1.txz: Upgraded.
l/python-setuptools_scm-10.2.1-x86_64-1.txz: Upgraded.
xap/mozilla-firefox-140.13.0esr-x86_64-1.txz: Upgraded.
This update contains security fixes and improvements.
For more information, see:
https://www.mozilla.org/en-US/firefox/140.13.0/releasenotes/
https://www.mozilla.org/security/advisories/mfsa2026-70/
https://www.cve.org/CVERecord?id=CVE-2026-15718
https://www.cve.org/CVERecord?id=CVE-2026-15719
https://www.cve.org/CVERecord?id=CVE-2026-16349
https://www.cve.org/CVERecord?id=CVE-2026-16350
https://www.cve.org/CVERecord?id=CVE-2026-16362
https://www.cve.org/CVERecord?id=CVE-2026-16351
https://www.cve.org/CVERecord?id=CVE-2026-16352
https://www.cve.org/CVERecord?id=CVE-2026-16363
https://www.cve.org/CVERecord?id=CVE-2026-16353
https://www.cve.org/CVERecord?id=CVE-2026-16354
https://www.cve.org/CVERecord?id=CVE-2026-16368
https://www.cve.org/CVERecord?id=CVE-2026-16369
https://www.cve.org/CVERecord?id=CVE-2026-16355
https://www.cve.org/CVERecord?id=CVE-2026-16356
https://www.cve.org/CVERecord?id=CVE-2026-16357
https://www.cve.org/CVERecord?id=CVE-2026-16371
https://www.cve.org/CVERecord?id=CVE-2026-16374
https://www.cve.org/CVERecord?id=CVE-2026-16375
https://www.cve.org/CVERecord?id=CVE-2026-16377
https://www.cve.org/CVERecord?id=CVE-2026-16379
https://www.cve.org/CVERecord?id=CVE-2026-16358
https://www.cve.org/CVERecord?id=CVE-2026-16381
https://www.cve.org/CVERecord?id=CVE-2026-16383
https://www.cve.org/CVERecord?id=CVE-2026-16387
https://www.cve.org/CVERecord?id=CVE-2026-16390
https://www.cve.org/CVERecord?id=CVE-2026-16391
https://www.cve.org/CVERecord?id=CVE-2026-16359
https://www.cve.org/CVERecord?id=CVE-2026-16396
https://www.cve.org/CVERecord?id=CVE-2026-16405
https://www.cve.org/CVERecord?id=CVE-2026-16412
(* Security fix *)