ChangeLog for: 2026-10-02 01:44:52
a/glibc-zoneinfo-2026e-noarch-1.txz: Upgraded.
This package provides the latest timezone updates.
a/openssl-solibs-3.5.9-x86_64-1.txz: Upgraded.
d/patchelf-0.19.2-x86_64-1.txz: Upgraded.
kde/kstars-3.8.5-x86_64-1.txz: Upgraded.
kde/libindi-2.2.5-x86_64-1.txz: Upgraded.
l/harfbuzz-14.5.1-x86_64-1.txz: Upgraded.
l/libsoup3-3.8.0-x86_64-1.txz: Upgraded.
l/spirv-llvm-translator-23.1.2-x86_64-1.txz: Upgraded.
n/httpd-2.4.69-x86_64-1.txz: Upgraded.
This is a bugfix release.
For more information, see:
https://downloads.apache.org/httpd/CHANGES_2.4.69
n/openssl-3.5.9-x86_64-1.txz: Upgraded.
This update fixes security issues:
Fixed DTLS retransmissions of handshake messages from a stale buffer offset.
Fixed excessive memory allocation in relative CRLDP processing.
Fixed QUIC unvalidated amplification credit may be over-accounted.
Fixed potential CPU DoS via O(n^2) fragment reassembly in QUIC.
Fixed a timing side-channel in scalar multiplication for mon-NIST EC curves.
Fixed QUIC `STREAM` fragment metadata DoS.
Fixed non-constant-time SM2 scalar multiplication on ARM64 and RISC-V.
Fixed out-of-bounds access after `SSL_set_SSL_CTX()` during a handshake.
Fixed QUIC connection-level flow control was not enforced for streams.
Fixed a NULL pointer dereference in CMP client revocation response handling.
Fixed an unauthenticated and undersized DTLS 1.2 AEAD record causing DoS.
Fixed a timing side-channel in SM2 signature generation.
Fixed an unbounded `RETIRE_CONNECTION_ID` backlog in QUIC stack
implementation.
For more information, see:
https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782
https://openssl-library.org/news/vulnerabilities/#CVE-2026-35189
https://openssl-library.org/news/vulnerabilities/#CVE-2026-35191
https://openssl-library.org/news/vulnerabilities/#CVE-2026-42772
https://openssl-library.org/news/vulnerabilities/#CVE-2026-54872
https://openssl-library.org/news/vulnerabilities/#CVE-2026-54873
https://openssl-library.org/news/vulnerabilities/#CVE-2026-54875
https://openssl-library.org/news/vulnerabilities/#CVE-2026-72897
https://openssl-library.org/news/vulnerabilities/#CVE-2026-75804
https://openssl-library.org/news/vulnerabilities/#CVE-2026-75805
https://openssl-library.org/news/vulnerabilities/#CVE-2026-75806
https://openssl-library.org/news/vulnerabilities/#CVE-2026-77696
https://openssl-library.org/news/vulnerabilities/#CVE-2026-84784
https://www.cve.org/CVERecord?id=CVE-2026-84782
https://www.cve.org/CVERecord?id=CVE-2026-35189
https://www.cve.org/CVERecord?id=CVE-2026-35191
https://www.cve.org/CVERecord?id=CVE-2026-42772
https://www.cve.org/CVERecord?id=CVE-2026-54872
https://www.cve.org/CVERecord?id=CVE-2026-54873
https://www.cve.org/CVERecord?id=CVE-2026-54875
https://www.cve.org/CVERecord?id=CVE-2026-72897
https://www.cve.org/CVERecord?id=CVE-2026-75804
https://www.cve.org/CVERecord?id=CVE-2026-75805
https://www.cve.org/CVERecord?id=CVE-2026-75806
https://www.cve.org/CVERecord?id=CVE-2026-77696
https://www.cve.org/CVERecord?id=CVE-2026-84784
(* Security fix *)
x/mesa-26.2.4-x86_64-1.txz: Upgraded.
x/noto-fonts-ttf-2026.10.01-noarch-1.txz: Upgraded.