3 UPDATED packages
binutils - GNU Binary Utility Development Utilities [20M]
* Tue May 19 2026 Alexander Danilov <admsasha@altlinux> 1:2.31.1-alt5
- Applied upstream patchs (fixes: CVE-2025-11412).
* Sun Dec 02 2018 Dmitry V. Levin <ldv@altlinux> 1:2.31.1-alt4
expat - An XML parser written in C
* Mon Apr 20 2026 Michael Shigorin <mike@altlinux> 2.5.0-alt5
- Adapted upstream CVE-2024-50602 patch;
no code difference, tests got split since then
with a new macro added for those (ilyakurdyukov@).
* Thu Dec 11 2025 Pavel Vasenkov <pav@altlinux> 2.5.0-alt4
- Fixed:
+ CVE-2024-8176 Improper restriction of xml entity expansion depth in
libexpat.
* Fri Nov 14 2025 Alexander Danilov <admsasha@altlinux> 2.5.0-alt3
- Applied upstream patch (fixes: CVE-2023-52426, CVE-2024-28757,
CVE-2024-45490, CVE-2024-45492).
* Fri Oct 24 2025 Alexander Danilov <admsasha@altlinux> 2.5.0-alt2
- Applied upstream patch (fixes: CVE-2024-45491).
* Sat Oct 29 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.5.0-alt1
- Updated to 2.5.0 (fixes: CVE-2022-43680 Fix heap use-after-free after
overeager destruction of a shared DTD in function
XML_ExternalEntityParserCreate
in out-of-memory situations, DoS or potentially ACE).
* Sat Sep 24 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.9-alt1
- Updated to 2.4.9 (fixes: CVE-2022-40674 Heap use-after-free vulnerability in
function doContent).
* Wed Mar 09 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.7-alt1
- Updated to 2.4.7 (relax fix to CVE-2022-25236).
* Sun Feb 20 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.6-alt1
- Updated to 2.4.6 (fixes: CVE-2022-25235, CVE-2022-25236, CVE-2022-25313,
CVE-2022-25314 and CVE-2022-25315).
* Fri Feb 04 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.4-alt1
- Updated to 2.4.4 (fixes: CVE-2022-23852 and CVE-2022-23990).
* Tue Jan 18 2022 Vladimir D. Seleznev <vseleznv@altlinux> 2.4.3-alt1
gnutls30 - A TLS protocol implementation
* Fri May 08 2026 Mikhail Efremov <sem@altlinux> 3.6.16-alt11
- Patches backported from 3.8.13 (fixes: CVE-2026-33846, CVE-2026-42009,
CVE-2026-33845, CVE-2026-42010, CVE-2026-3833, CVE-2026-42011,
CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-5260,
CVE-2026-42015).
* Thu Feb 12 2026 Mikhail Efremov <sem@altlinux> 3.6.16-alt10
- Patches from gnutls-3.8.12:
+ x509/name_constraints: use actual zeroes in universal exclude IP NC.
+ tests/name-constraints-ip: stop swallowing errors.
+ x509/name_constraints: reject some malformed domain names.
+ x509/name_constraints: name_constraints_node_add_{new,copy}.
+ x509/name_constraints: introduce a rich comparator.
+ x509/name_constraints: add sorted_view.
+ x509/name_constraints: implement name_constraints_node_list_union.
+ x509/name_constraints: make types_with_empty_intersection a bitmask.
+ x509/name_constraints: name_constraints_node_list_intersect over sorted
(fixes: CVE-2025-14831).
* Sat Nov 22 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt9
- Patch from gnutls-3.8.11:
+ pkcs11: avoid stack overwrite when initializing a token
(fixes: CVE-2025-9820).
* Thu Jul 10 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt8
- Patches from gnutls-3.8.10:
+ handshake: clear HSK_PSK_SELECTED is when resetting binders
(fixes: CVE-2025-6395).
+ x509: reject zero-length version in certificate request.
+ psk: fix read buffer overrun in the "pre_shared_key" extension.
+ x509: avoid double free when exporting othernames in SAN
(fixes: CVE-2025-32988).
+ certtool: avoid 1-byte write buffer overrun when parsing template
(fixes: CVE-2025-32990).
* Fri Feb 21 2025 Mikhail Efremov <sem@altlinux> 3.6.16-alt7
Total 18274 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk