Moderate: libarchive security update
Libcupsfilters provides a library, which implements common functions used in cups-browsed daemon and printing filters, and additional files as banner templates and character sets. The filters are used in CUPS daemon and in printer applications.Security Fix(es): libcupsfilters: cups-filters: libcupsfilters: CPU exhaustion via infinite loop in cfIEEE1284NormalizeMakeModel() (CVE-2026-64611) libcupsfilters: cups-filters: libcupsfilters: CUPS image filter process abort via malformed PNG (CVE-2026-64612) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: python-idna security update
GNOME Remote Desktop is a remote desktop and screen sharing service for the GNOME desktop environment.Security Fix(es): gnome-remote-desktop: gnome-remote-desktop system-mode RDP server missing connection throttling allows unauthenticated denial of service (CVE-2026-18358) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377) grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376) grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route (CVE-2026-8609) grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads (CVE-2026-33382) Bug Fix(es) and Enhancement(s): [grafana / rhel-10.2.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:RHEL-188282) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: dhcpcd security update
Moderate: modmd security update
Moderate: libarchive security update
Moderate: libgcrypt security update
Moderate: kernel security, bug fix, and enhancement update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer FILEINFO metadata parser (CVE-2026-53704) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: kernel security, bug fix, and enhancement update
Moderate: p11-kit security update
Moderate: kernel security update
Moderate: libsolv security update
libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices.Security Fix(es): libinput: local privilege escalation via crafted uinput devices (CVE-2026-50292) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: glibc security update
Moderate: cups security update
Moderate: freeipmi security update
GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.Security Fix(es): gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: opencryptoki security update
Authoritative DNS server for A/AAAA container records Forwards other request to configured resolvers. Read more about configuration in src/backend/mod.rs.Security Fix(es): aardvark-dns: Aardvark-dns: Denial of Service via truncated TCP DNS query and connection reset (CVE-2026-35406) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Moderate: freeipmi security update
Moderate: modhttp2 security, bug fix, and enhancement update
Moderate: rrdtool security update
Moderate: modmd security update
Moderate: coreutils security update
Moderate: glibc security update
Moderate: golang security, bug fix, and enhancement update