24 UPDATED packages curl - Gets a file from a FTP, GOPHER or HTTP server * Wed Sep 02 2026 Anton Farygin <rider@altlinux> 8.22.0-alt1 - 8.21.0 -> 8.22.0 - Fixes: * CVE-2026-82209: domain-scoped PSL domain cookie * CVE-2026-82208: wolfSSL CA-cache hit overrides callback * CVE-2026-80255: secure cookie attribute bypass with tab * CVE-2026-80231: native CA store conn reuse * CVE-2026-80230: OpenSSL pinning bypass * CVE-2026-80229: OpenSSL provider use-after-free * CVE-2026-19931: Negotiate ambient user conn reuse * CVE-2026-18924: HTTP/2 server push UAF * CVE-2026-13608: OpenLDAP SASL authentication bypass * Tue Aug 25 2026 Anton Farygin <rider@altlinux> 8.21.0-alt2
firefox-esr - The Mozilla Firefox project is a redesign of Mozilla's browser [640M] * Wed Aug 26 2026 Pavel Vasenkov <pav@altlinux> 140.14.0-alt1 - New ESR version. - Security fixes: + CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component + CVE-2026-74935 Privilege escalation in the DOM: Networking component + CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component + CVE-2026-74939 Privilege escalation in the DOM: Navigation component + CVE-2026-74940 Use-after-free in the Graphics: Text component + CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component + CVE-2026-74942 Privilege escalation in the Remote Settings Client component + CVE-2026-74943 Use-after-free in the Graphics: ImageLib component + CVE-2026-74944 Use-after-free in the DOM: Core & HTML component + CVE-2026-74945 Information disclosure in the Graphics: Text component + CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component + CVE-2026-74948 Information disclosure in the Graphics component + CVE-2026-74953 Privilege escalation in the Networking: Cookies component + CVE-2026-74957 Mitigation bypass in the Safe Browsing component + CVE-2026-74959 Mitigation bypass in the Storage: Cache API component + CVE-2026-74960 Site isolation issue in the WebExtensions component + CVE-2026-74962 Site isolation issue in the Networking: Cookies component + CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component + CVE-2026-74964 Integer overflow in the Graphics component + CVE-2026-74965 Privilege escalation in the Shell Integration component + CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component + CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component + CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component + CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component + CVE-2026-74949 Use-after-free in the Graphics: Canvas2D component + CVE-2026-74973 Race condition, use-after-free in the Graphics component + CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component + CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component + CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 + CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * Wed Jul 29 2026 Pavel Vasenkov <pav@altlinux> 140.13.0-alt1 gitea - Git with a cup of tea, painless self-hosted git service [35M] * Thu Sep 03 2026 Alexey Shabalin <shaba@altlinux> 1.27.3-alt1 - 1.27.3 (Fixes: CVE-2026-60010, CVE-2026-60018, CVE-2026-60021, CVE-2026-62925, CVE-2026-63021, CVE-2026-63792, CVE-2026-66849, CVE-2026-66853, CVE-2026-66874, CVE-2026-66877, CVE-2026-67577, CVE-2026-68957, CVE-2026-68964, CVE-2026-78433). - Pass -D_GNU_SOURCE via CGO_CFLAGS so msteinert/pam (C.RTLD_NEXT) builds on glibc < 2.34 (upstream PR #35 not merged yet). * Thu Aug 27 2026 Alexey Shabalin <shaba@altlinux> 1.27.2-alt1 postgresql14-orafce - The "orafce" project implements in Postgres some of the functions from the Oracle database that are missin * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 4.16.8-alt1 - 4.16.8 * Sun Jun 07 2026 Alexei Takaseev <taf@altlinux> 4.16.7-alt1 postgresql14-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql14-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql15-orafce - The "orafce" project implements in Postgres some of the functions from the Oracle database that are missin * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 4.16.8-alt1 - 4.16.8 * Sun Jun 07 2026 Alexei Takaseev <taf@altlinux> 4.16.7-alt1 postgresql15-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql15-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql16-orafce - The "orafce" project implements in Postgres some of the functions from the Oracle database that are missin * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 4.16.8-alt1 - 4.16.8 * Sun Jun 07 2026 Alexei Takaseev <taf@altlinux> 4.16.7-alt1 postgresql16-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql16-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql17-1C-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql17-1C-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql17-orafce - The "orafce" project implements in Postgres some of the functions from the Oracle database that are missin * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 4.16.8-alt1 - 4.16.8 * Sun Jun 07 2026 Alexei Takaseev <taf@altlinux> 4.16.7-alt1 postgresql17-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql17-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql18-1C-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql18-1C-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 postgresql18-orafce - The "orafce" project implements in Postgres some of the functions from the Oracle database that are missin * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 4.16.8-alt1 - 4.16.8 * Sun Jun 07 2026 Alexei Takaseev <taf@altlinux> 4.16.7-alt1 postgresql18-pg_background - Run SQL queries in background workers with autonomous transactions * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 2.0.3-alt1 - 2.0.3 * Fri Jun 19 2026 Alexei Takaseev <taf@altlinux> 2.0.2-alt1 postgresql18-pg_checksums - pg_checksums_ext can verify, activate or deactivate checksums * Wed Sep 02 2026 Alexei Takaseev <taf@altlinux> 1.4-alt1 - 1.4 * Tue Sep 09 2025 Alexei Takaseev <taf@altlinux> 1.3-alt1 pve-firewall - Proxmox VE Firewall * Thu Sep 03 2026 Sergey Konev <darisishe@altlinux> 6.0.5-alt4 - Use nftables-compatible ebtables tools (Closes: 60373) * Sun Aug 30 2026 Sergey Konev <darisishe@altlinux> 6.0.5-alt3 python3-module-jwcrypto - Implementation of JOSE Web standards * Wed Sep 02 2026 Stanislav Levin <slev@altlinux> 1.6.0-alt1 - 1.5.9 -> 1.6.0 (fixes: CVE-2026-84185). * Thu Aug 27 2026 Stanislav Levin <slev@altlinux> 1.5.9-alt1 Total 20660 source packages. _______________________________________________ Sisyphus-cybertalk mailing list [email protected] https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk
