ChangeLog for: 2026-10-02 01:44:52

a/glibc-zoneinfo-2026e-noarch-1.txz: Upgraded. This package provides the latest timezone updates. a/openssl-solibs-3.5.9-x86_64-1.txz: Upgraded. d/patchelf-0.19.2-x86_64-1.txz: Upgraded. kde/kstars-3.8.5-x86_64-1.txz: Upgraded. kde/libindi-2.2.5-x86_64-1.txz: Upgraded. l/harfbuzz-14.5.1-x86_64-1.txz: Upgraded. l/libsoup3-3.8.0-x86_64-1.txz: Upgraded. l/spirv-llvm-translator-23.1.2-x86_64-1.txz: Upgraded. n/httpd-2.4.69-x86_64-1.txz: Upgraded. This is a bugfix release. For more information, see: https://downloads.apache.org/httpd/CHANGES_2.4.69 n/openssl-3.5.9-x86_64-1.txz: Upgraded. This update fixes security issues: Fixed DTLS retransmissions of handshake messages from a stale buffer offset. Fixed excessive memory allocation in relative CRLDP processing. Fixed QUIC unvalidated amplification credit may be over-accounted. Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC. Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves. Fixed QUIC `STREAM` fragment metadata DoS. Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V. Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake. Fixed QUIC connection-level flow control was not enforced for streams. Fixed a NULL pointer dereference in CMP client revocation response handling. Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS. Fixed a timing side-channel in SM2 signature generation. Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack implementation. For more information, see: https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782 https://openssl-library.org/news/vulnerabilities/#CVE-2026-35189 https://openssl-library.org/news/vulnerabilities/#CVE-2026-35191 https://openssl-library.org/news/vulnerabilities/#CVE-2026-42772 https://openssl-library.org/news/vulnerabilities/#CVE-2026-54872 https://openssl-library.org/news/vulnerabilities/#CVE-2026-54873 https://openssl-library.org/news/vulnerabilities/#CVE-2026-54875 https://openssl-library.org/news/vulnerabilities/#CVE-2026-72897 https://openssl-library.org/news/vulnerabilities/#CVE-2026-75804 https://openssl-library.org/news/vulnerabilities/#CVE-2026-75805 https://openssl-library.org/news/vulnerabilities/#CVE-2026-75806 https://openssl-library.org/news/vulnerabilities/#CVE-2026-77696 https://openssl-library.org/news/vulnerabilities/#CVE-2026-84784 https://www.cve.org/CVERecord?id=CVE-2026-84782 https://www.cve.org/CVERecord?id=CVE-2026-35189 https://www.cve.org/CVERecord?id=CVE-2026-35191 https://www.cve.org/CVERecord?id=CVE-2026-42772 https://www.cve.org/CVERecord?id=CVE-2026-54872 https://www.cve.org/CVERecord?id=CVE-2026-54873 https://www.cve.org/CVERecord?id=CVE-2026-54875 https://www.cve.org/CVERecord?id=CVE-2026-72897 https://www.cve.org/CVERecord?id=CVE-2026-75804 https://www.cve.org/CVERecord?id=CVE-2026-75805 https://www.cve.org/CVERecord?id=CVE-2026-75806 https://www.cve.org/CVERecord?id=CVE-2026-77696 https://www.cve.org/CVERecord?id=CVE-2026-84784 (* Security fix *) x/mesa-26.2.4-x86_64-1.txz: Upgraded. x/noto-fonts-ttf-2026.10.01-noarch-1.txz: Upgraded.