15 UPDATED packages

cbindgen - A project for generating C bindings from Rust code.
* Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 0.29.4-alt1
- New version.
* Fri Oct 24 2025 Ajrat Makhmutov <rauty@altlinux> 0.29.2-alt1

firefox - Fast, private and secure web browser                          [739M]
* Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 153.0-alt1
- New version.
- Build with llvm21.1 (upstream requires clang >= 19.0).
- Raise minimal rust/cargo version to 1.90.0.
- Fixes:
  + CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
  + CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb 
component
  + CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
  + CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation 
component
  + CVE-2026-16352: Sandbox escape due to use-after-free in the Disability 
Access APIs component
  + CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
  + CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback 
component
  + CVE-2026-16365: Privilege escalation in the DOM: Workers component
  + CVE-2026-16366: Privilege escalation in the DOM: Navigation component
  + CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
  + CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
  + CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability 
Access APIs component
  + CVE-2026-16368: Incorrect boundary conditions in the JavaScript: 
WebAssembly component
  + CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
  + CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16356: Sandbox escape due to use-after-free in the Disability 
Access APIs component
  + CVE-2026-16357: Incorrect boundary conditions in the Graphics component
  + CVE-2026-16370: Mitigation bypass in the DOM: Networking component
  + CVE-2026-16371: Privilege escalation in the DOM: Navigation component
  + CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
  + CVE-2026-16373: Information disclosure in the Privacy component in Firefox 
for Android
  + CVE-2026-16374: Information disclosure in the Framework component in 
DevTools
  + CVE-2026-16375: Site isolation issue in the Networking: HTTP component
  + CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
  + CVE-2026-16377: Mitigation bypass in the PDF Viewer component
  + CVE-2026-16378: Other issue in the DOM: Copy &amp; Paste and Drag &amp; 
Drop component
  + CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
  + CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
  + CVE-2026-16380: Mitigation bypass in the Networking component
  + CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
  + CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
  + CVE-2026-16383: Mitigation bypass in the DOM: Networking component
  + CVE-2026-16384: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16385: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16386: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16387: Site isolation issue in the Networking component
  + CVE-2026-16388: Sandbox escape in the DOM: Networking component
  + CVE-2026-16389: Incorrect boundary conditions, integer overflow in the 
Libraries component in NSS
  + CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
  + CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
  + CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU 
component
  + CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP 
component
  + CVE-2026-16394: Mitigation bypass in the DOM: Security component
  + CVE-2026-16395: Integer overflow in the Audio/Video component
  + CVE-2026-16396: Privilege escalation in WebExtensions
  + CVE-2026-16397: Clickjacking issue in the WebExtensions component in 
Firefox for Android
  + CVE-2026-16398: Site isolation issue in the Graphics component
  + CVE-2026-16399: Site isolation issue in the DOM: Navigation component
  + CVE-2026-16400: Information disclosure in the DOM: Security component
  + CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
  + CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
  + CVE-2026-16403: Spoofing issue in the Address Bar component
  + CVE-2026-16404: Spoofing issue in Firefox for Android
  + CVE-2026-16405: Information disclosure in the Networking: WebSockets 
component
  + CVE-2026-16406: Mitigation bypass in the Networking component
  + CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
  + CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
  + CVE-2026-16409: Invalid pointer in the Security: PSM component
  + CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16411: Memory safety bugs fixed in Firefox 153
  + CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 
153
  + CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 
140.13 and Firefox 153
* Tue Jul 14 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.6-alt1
- New version.
- Fixes:
  + CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
  + CVE-2026-15719: Site isolation in the DOM: Navigation component
* Wed Jul 08 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.5-alt1
- New version.
* Tue Jun 30 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.4-alt1

java-11-openjdk - OpenJDK Runtime Environment 11                        [70M]
* Sat Jul 25 2026 Andrey Cherepanov <cas@altlinux> 0:11.0.32.0.9-alt1
- New version (fixes: CVE-2026-41254, CVE-2026-46917, CVE-2026-46968,
  CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057,
  CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147).
- Remove unsupported NEWS.
* Thu Apr 30 2026 Andrey Cherepanov <cas@altlinux> 0:11.0.31.0.11-alt1

libXfont - X.Org libXfont runtime library
* Thu Jul 30 2026 Alexander Danilov <admsasha@altlinux> 1.5.4-alt3
- Applied upstream patch (fixed CVE-2026-56002).
* Tue Apr 02 2019 Valery Inozemtsev <shrek@altlinux> 1.5.4-alt2

nss - Netscape Network Security Services(NSS)                           [52M]
* Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 3.126-alt1
- New version.
  + Add CN=SECOM SMIME RSA Root CA 2024
  + Add CN=SECOM TLS ECC Root CA 2024
  + Add CN=SECOM TLS RSA Root CA 2024
  + Add CN=Telia EC Email Root CA v3
  + Add CN=Telia EC TLS Root CA v3
  + Add CN=Telia RSA Email Root CA v3
  + Add CN=Telia RSA TLS Root CA v3
  + Remove OU=ePKI Root Certification Authority
* Tue May 26 2026 Ajrat Makhmutov <rauty@altlinux> 3.124-alt1

perl-Net-SSLeay - Perl extension for using OpenSSL
* Mon Mar 23 2026 Andrew A. Vasilyev <andy@altlinux> 1.96-alt1
- NMU: new version
* Sat Dec 27 2025 Andrew A. Vasilyev <andy@altlinux> 1.94-alt2
- NMU: fix FTBFS with Debian patches
* Sun Feb 18 2024 Igor Vlasenko <viy@altlinux> 1.94-alt1

python3-module-django-environ - Django-environ allows you to utilize 12factor 
inspired environment variables to configure your D
* Mon Feb 16 2026 Martynenko Evgeniy <enimalojd@altlinux> 0.12.1-alt1
- New version (0.12.1).
* Sat Jul 05 2025 Martynenko Evgeniy <enimalojd@altlinux> 0.12.0-alt1
- New version (0.12.0).
* Mon May 15 2023 Dmitry Lyalyaev <fruktime@altlinux> 0.10.0-alt1

python3-module-handy-archives - Some handy archive helpers for Python
* Thu Dec 18 2025 Anton Zhukharev <ancieg@altlinux> 0.2.0-alt3.35.g735b08c
- Fixed FTBFS (apply upstream fixes).
* Sun Oct 19 2025 Grigory Ustinov <grenka@altlinux> 0.2.0-alt2
- Fixed FTBFS.
* Mon Jan 29 2024 Grigory Ustinov <grenka@altlinux> 0.2.0-alt1.1

python3-module-joblib - Lightweight pipelining: using Python functions as 
pipeline jobs
* Tue Dec 16 2025 Stanislav Levin <slev@altlinux> 1.5.3-alt1
- 1.5.2 -> 1.5.3.
* Tue Sep 02 2025 Stanislav Levin <slev@altlinux> 1.5.2-alt1
- 1.5.1 -> 1.5.2.
* Thu May 29 2025 Stanislav Levin <slev@altlinux> 1.5.1-alt1
- 1.4.2 -> 1.5.1.
* Fri May 03 2024 Stanislav Levin <slev@altlinux> 1.4.2-alt1

python3-module-loky - A robust implementation of 
concurrent.futures.ProcessPoolExecutor
* Wed Mar 25 2026 Grigory Ustinov <grenka@altlinux> 3.5.6-alt1.1
- Demodernized packaging.
* Tue Sep 02 2025 Stanislav Levin <slev@altlinux> 3.5.6-alt1
- 3.5.5 -> 3.5.6.
* Thu May 29 2025 Stanislav Levin <slev@altlinux> 3.5.5-alt1
- 3.5.1 -> 3.5.5.
* Wed Mar 19 2025 Stanislav Levin <slev@altlinux> 3.5.1-alt1
- 3.5.0 -> 3.5.1.
* Mon Mar 17 2025 Stanislav Levin <slev@altlinux> 3.5.0-alt1
- 3.4.1 -> 3.5.0.
* Thu Mar 21 2024 Stanislav Levin <slev@altlinux> 3.4.1-alt2

python3-module-skosprovider - Abstraction layer for SKOS vocabularies
* Fri Jan 23 2026 Anton Vyatkin <toni@altlinux> 1.5.1-alt1
- New version 1.5.1.
* Fri Oct 31 2025 Anton Vyatkin <toni@altlinux> 1.3.0-alt1
- New version 1.3.0.
- New upstream url.
* Fri Apr 14 2023 Anton Vyatkin <toni@altlinux> 1.2.0-alt1

python3-module-tomlkit - Style preserving TOML library
* Thu Jun 05 2025 Stanislav Levin <slev@altlinux> 0.13.3-alt1
- 0.13.2 -> 0.13.3.
* Wed Sep 25 2024 Stanislav Levin <slev@altlinux> 0.13.2-alt1
- 0.13.0 -> 0.13.2.
* Fri Jul 12 2024 Stanislav Levin <slev@altlinux> 0.13.0-alt1
- 0.12.5 -> 0.13.0.
* Mon May 13 2024 Stanislav Levin <slev@altlinux> 0.12.5-alt1

python3-module-uritools - URI parsing, classification and composition
* Wed May 29 2024 Grigory Ustinov <grenka@altlinux> 4.0.3-alt1
- Automatically updated to 4.0.3.
* Mon Sep 11 2023 Grigory Ustinov <grenka@altlinux> 4.0.2-alt1

sscg - Simple SSL certificate generator
* Wed Aug 05 2026 Anton Midyukov <antohami@altlinux> 4.0.3-alt2
- Applied upstream fix:
  + Avoid segfault on receiving bad CLI arguments (Closes: 60094).
* Tue Feb 17 2026 Andrey Limachko <liannnix@altlinux> 4.0.3-alt1
- Update to upstream version 4.0.3.
- Breaking changes:
  * Minimum OpenSSL version raised to 3.x (dropped 1.1/2.x support).
  * DH parameters no longer generated by default (use --dhparams-file).
  * Custom DH parameter generation deprecated (will be removed in 5.0).
  * Removed --package argument (was deprecated in 3.0).
  * Minimum RSA key strength for private CA raised to 4096 bits.
- New features:
  * Added ML-DSA (Module-Lattice Digital Signature Algorithm) support for 
post-quantum cryptography.
  * Added ECDSA (Elliptic Curve Digital Signature Algorithm) key generation.
  * Enhanced command-line interface with logically grouped help output.
- Improvements:
  * Extended maximum DNS name length to 255 characters.
  * Improved compatibility with OpenSSL 3.4+.
  * Enhanced security: basicConstraint marked as critical for CA certificates.
  * Added internationalization (i18n) support and updated README.
  * Refactored key creation logic for better modularity.
  * Reworked file opening to avoid TOCTOU issues.
- Bug fixes:
  * Fixed IP address handling in CA certificate SAN constraints.
  * Fixed regression when attempting to use same file for both CA and 
certificate.
  * Fixed various issues discovered by Coverity analysis.
  * Fixed detection of invalid hashes.
  * Better handling of files in general.
* Tue Feb 07 2023 Andrey Limachko <liannnix@altlinux> 3.0.3-alt1

thunderbird - Thunderbird is Mozilla's e-mail client                    [956M]
* Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 153.0-alt1
- New version.
- Fixes:
  + CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for 
forwarding
  + CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component
  + CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb 
component
  + CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component
  + CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation 
component
  + CVE-2026-16352: Sandbox escape due to use-after-free in the Disability 
Access APIs component
  + CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component
  + CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback 
component
  + CVE-2026-16365: Privilege escalation in the DOM: Workers component
  + CVE-2026-16366: Privilege escalation in the DOM: Navigation component
  + CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component
  + CVE-2026-16354: Information disclosure in the Graphics: ImageLib component
  + CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability 
Access APIs component
  + CVE-2026-16368: Incorrect boundary conditions in the JavaScript: 
WebAssembly component
  + CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component
  + CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16356: Sandbox escape due to use-after-free in the Disability 
Access APIs component
  + CVE-2026-16357: Incorrect boundary conditions in the Graphics component
  + CVE-2026-16370: Mitigation bypass in the DOM: Networking component
  + CVE-2026-16371: Privilege escalation in the DOM: Navigation component
  + CVE-2026-16372: Privilege escalation in the DOM: Content Processes component
  + CVE-2026-16374: Information disclosure in the Framework component in 
DevTools
  + CVE-2026-16375: Site isolation issue in the Networking: HTTP component
  + CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component
  + CVE-2026-16377: Mitigation bypass in the PDF Viewer component
  + CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop 
component
  + CVE-2026-16379: Privilege escalation in the DOM: Content Processes component
  + CVE-2026-16358: Site isolation issue in the Graphics: WebRender component
  + CVE-2026-16380: Mitigation bypass in the Networking component
  + CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component
  + CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component
  + CVE-2026-16383: Mitigation bypass in the DOM: Networking component
  + CVE-2026-16384: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16385: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16386: Information disclosure due to uninitialized memory in the 
Graphics: WebGPU component
  + CVE-2026-16387: Site isolation issue in the Networking component
  + CVE-2026-16388: Sandbox escape in the DOM: Networking component
  + CVE-2026-16389: Incorrect boundary conditions, integer overflow in the 
Libraries component in NSS
  + CVE-2026-16390: Mitigation bypass in the Enterprise Policies component
  + CVE-2026-16391: Information disclosure in the Storage: IndexedDB component
  + CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU 
component
  + CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP 
component
  + CVE-2026-16394: Mitigation bypass in the DOM: Security component
  + CVE-2026-16395: Integer overflow in the Audio/Video component
  + CVE-2026-16396: Privilege escalation in WebExtensions
  + CVE-2026-16398: Site isolation issue in the Graphics component
  + CVE-2026-16399: Site isolation issue in the DOM: Navigation component
  + CVE-2026-16400: Information disclosure in the DOM: Security component
  + CVE-2026-16401: Privilege escalation in the Data Loss Prevention component
  + CVE-2026-16402: Integer overflow in the Graphics: ImageLib component
  + CVE-2026-16403: Spoofing issue in the Address Bar component
  + CVE-2026-16405: Information disclosure in the Networking: WebSockets 
component
  + CVE-2026-16406: Mitigation bypass in the Networking component
  + CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component
  + CVE-2026-16408: Integer overflow in the Audio/Video: Playback component
  + CVE-2026-16409: Invalid pointer in the Security: PSM component
  + CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component
  + CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153
  + CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and 
Thunderbird 153
  + CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and 
Thunderbird 153
* Wed Jul 01 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.1-alt1
- New version.
- Fixes:
  + CVE-2026-57962: Denial-of-service via malicious LDAP address-book server
  + CVE-2026-57963: Chat UI manipulation by injection
- Disable the chat/instant-messaging feature by default via
  mail.chat.enabled (Closes: 44712, 52473, 56109, 57572).
* Wed Jun 17 2026 Ajrat Makhmutov <rauty@altlinux> 152.0-alt1

Total 20601 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk

Reply via email to