Important: kpatch-patch-4180-4771071, kpatch-patch-4180-4771201, kpatch-patch-4180-4771301, and kpatch-patch-4180-477971 security update
Important: firefox security update
Important: firefox security update
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: Heap buffer overflow in sasliorecv() via padded SASL UNBIND (CVE-2026-11610) 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: Heap buffer overflow in sasliorecv() via padded SASL UNBIND (CVE-2026-11610) 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration. Security Fix(es): 389-ds-base: 389-ds-base: Heap buffer overflow in sasliorecv() via padded SASL UNBIND (CVE-2026-11610) 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: compat-openssl10 security update
Important: httpd:2.4 security update
EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: kernel security, bug fix, and enhancement update
Important: ruby:2.5 security update
Important: ruby:2.5 security update
Important: libpq security update
Important: kernel security update
Important: kernel security update
Important: kernel security, bug fix, and enhancement update
Important: postgresql:12 security update
Important: ruby:2.5 security update
Important: postgresql:13 security update
Important: vim security update
Important: vim security update
Important: redis:6 security update
giflib is a library for reading and writing gif images.Security Fix(es): giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: vim security update
giflib is a library for reading and writing gif images.Security Fix(es): giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
giflib is a library for reading and writing gif images.Security Fix(es): giflib: giflib: Denial of Service via buffer overflow in EGifGCBToExtension (CVE-2026-26740) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
libxslt is a library for transforming XML files into other textual formats (including HTML, plain text, and other XML representations of the underlying data) using the standard XSLT stylesheet transformation mechanism. Security Fix(es): libxslt: use-after-free with key data stored cross-RVT (CVE-2025-10911) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: gnutls and libtasn1 security update
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.Security Fix(es): flatpak: Flatpak: Arbitrary code execution via crafted symlinks in sandbox-expose options (CVE-2026-34078) flatpak: Flatpak: Arbitrary file deletion on host via improper cache file path validation (CVE-2026-34079) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Important: postgresql:13 security update