<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/osv_rocky/10</id>
  <title>Most recent entries from osv_rocky</title>
  <updated>2026-10-02T09:45:35.036908+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19061</id>
    <title>RLSA-2026:19061 — Moderate: glibc security update</title>
    <updated>2026-06-12T12:06:11.879207+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: glibc</p>
<p>The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the name service cache daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly.</p>
<p>Security Fix(es):</p>
<p>* glibc: glibc: Incorrect DNS response parsing via crafted DNS server response (CVE-2026-4437)</p>
<p>* glibc: glibc: Invalid DNS hostname returned via gethostbyaddr functions (CVE-2026-4438)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19061"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19127</id>
    <title>RLSA-2026:19127 — Important: gdk-pixbuf2 security update</title>
    <updated>2026-06-12T12:06:13.602794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: gdk-pixbuf2</p>
<p>The gdk-pixbuf2 packages provide an image loading library that can be extended by loadable modules for new image formats. It is used by toolkits such as GTK+ or clutter.</p>
<p>Security Fix(es):</p>
<p>* gdk-pixbuf: gdk-pixbuf: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (CVE-2026-5201)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19127"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19128</id>
    <title>RLSA-2026:19128 — Important: yggdrasil-worker-package-manager security update</title>
    <updated>2026-06-12T12:06:12.474089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: yggdrasil-worker-package-manager</p>
<p>yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19128"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19130</id>
    <title>RLSA-2026:19130 — Important: libcap security update</title>
    <updated>2026-06-12T12:06:13.964756+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: libcap</p>
<p>Libcap is a library for getting and setting POSIX.1e (formerly POSIX 6) draft 15 capabilities.</p>
<p>Security Fix(es):</p>
<p>* libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() (CVE-2026-4878)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19130"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19133</id>
    <title>RLSA-2026:19133 — Important: git-lfs security update</title>
    <updated>2026-06-12T12:06:13.150214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: git-lfs</p>
<p>Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server.</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19133"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19134</id>
    <title>RLSA-2026:19134 — Important: grafana security update</title>
    <updated>2026-06-12T12:06:12.561156+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* grafana: Grafana: Information disclosure of data-source passwords via public dashboards (CVE-2026-27877)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19134"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19135</id>
    <title>RLSA-2026:19135 — Important: opentelemetry-collector security update</title>
    <updated>2026-06-12T12:06:12.122817+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: opentelemetry-collector</p>
<p>Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry</p>
<p>Security Fix(es):</p>
<p>* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)</p>
<p>* google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation (CVE-2026-33186)</p>
<p>* github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object (CVE-2026-34986)</p>
<p>* crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281)</p>
<p>* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19135"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19136</id>
    <title>RLSA-2026:19136 — Important: grafana-pcp security update</title>
    <updated>2026-06-12T12:06:12.203597+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: grafana-pcp</p>
<p>The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.</p>
<p>Security Fix(es):</p>
<p>* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19136"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19138</id>
    <title>RLSA-2026:19138 — Important: fence-agents security update</title>
    <updated>2026-06-12T12:06:13.470629+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: fence-agents</p>
<p>The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.</p>
<p>Security Fix(es):</p>
<p>* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)</p>
<p>* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19138"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19139</id>
    <title>RLSA-2026:19139 — Important: go-fdo-client security update</title>
    <updated>2026-06-12T12:06:12.032645+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: go-fdo-client</p>
<p>go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding.</p>
<p>Security Fix(es):</p>
<p>* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19139"/>
    <published>2026-05-29T16:03:24.060458+00:00</published>
  </entry>
</feed>
