3 UPDATED packages

binutils - GNU Binary Utility Development Utilities                     [20M]
* Tue May 19 2026 Alexander Danilov <admsasha@altlinux> 1:2.31.1-alt5
- Applied upstream patchs (fixes: CVE-2025-11412).
* Sun Dec 02 2018 Dmitry V. Levin <ldv@altlinux> 1:2.31.1-alt4

expat - An XML parser written in C
* Mon Apr 20 2026 Michael Shigorin <mike@altlinux> 2.5.0-alt5
- Adapted upstream CVE-2024-50602 patch;
  no code difference, tests got split since then
  with a new macro added for those (ilyakurdyukov@).
* Thu Dec 11 2025 Pavel Vasenkov <pav@altlinux> 2.5.0-alt4
- Fixed:
  + CVE-2024-8176 Improper restriction of xml entity expansion depth in 
libexpat.
* Fri Nov 14 2025 Alexander Danilov <admsasha@altlinux> 2.5.0-alt3
- Applied upstream patch (fixes: CVE-2023-52426, CVE-2024-28757, 
CVE-2024-45490, CVE-2024-45492).
* Fri Oct 24 2025 Alexander Danilov <admsasha@altlinux> 2.5.0-alt2
- Applied upstream patch (fixes: CVE-2024-45491).
* Sat Oct 29 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.5.0-alt1
- Updated to 2.5.0 (fixes: CVE-2022-43680 Fix heap use-after-free after
  overeager destruction of a shared DTD in function 
XML_ExternalEntityParserCreate
  in out-of-memory situations, DoS or potentially ACE).
* Sat Sep 24 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.9-alt1
- Updated to 2.4.9 (fixes: CVE-2022-40674 Heap use-after-free vulnerability in
  function doContent).
* Wed Mar 09 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.7-alt1
- Updated to 2.4.7 (relax fix to CVE-2022-25236).
* Sun Feb 20 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.6-alt1
- Updated to 2.4.6 (fixes: CVE-2022-25235, CVE-2022-25236, CVE-2022-25313,
  CVE-2022-25314 and CVE-2022-25315).
* Fri Feb 04 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.4-alt1
- Updated to 2.4.4 (fixes: CVE-2022-23852 and CVE-2022-23990).
* Tue Jan 18 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.3-alt1

gnutls30 - A TLS protocol implementation
* Fri May 08 2026 Mikhail Efremov <sem@altlinux> 3.6.16-alt11
- Patches backported from 3.8.13 (fixes: CVE-2026-33846, CVE-2026-42009,
  CVE-2026-33845, CVE-2026-42010, CVE-2026-3833, CVE-2026-42011,
  CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-5260,
  CVE-2026-42015).
* Thu Feb 12 2026 Mikhail Efremov <sem@altlinux> 3.6.16-alt10
- Patches from gnutls-3.8.12:
  + x509/name_constraints: use actual zeroes in universal exclude IP NC.
  + tests/name-constraints-ip: stop swallowing errors.
  + x509/name_constraints: reject some malformed domain names.
  + x509/name_constraints: name_constraints_node_add_{new,copy}.
  + x509/name_constraints: introduce a rich comparator.
  + x509/name_constraints: add sorted_view.
  + x509/name_constraints: implement name_constraints_node_list_union.
  + x509/name_constraints: make types_with_empty_intersection a bitmask.
  + x509/name_constraints: name_constraints_node_list_intersect over sorted
    (fixes: CVE-2025-14831).
* Sat Nov 22 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt9
- Patch from gnutls-3.8.11:
  + pkcs11: avoid stack overwrite when initializing a token
    (fixes: CVE-2025-9820).
* Thu Jul 10 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt8
- Patches from gnutls-3.8.10:
  + handshake: clear HSK_PSK_SELECTED is when resetting binders
    (fixes: CVE-2025-6395).
  + x509: reject zero-length version in certificate request.
  + psk: fix read buffer overrun in the "pre_shared_key" extension.
  + x509: avoid double free when exporting othernames in SAN
    (fixes: CVE-2025-32988).
  + certtool: avoid 1-byte write buffer overrun when parsing template
    (fixes: CVE-2025-32990).
* Fri Feb 21 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt7

Total 18274 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk

Reply via email to