15 UPDATED packages cbindgen - A project for generating C bindings from Rust code. * Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 0.29.4-alt1 - New version. * Fri Oct 24 2025 Ajrat Makhmutov <rauty@altlinux> 0.29.2-alt1
firefox - Fast, private and secure web browser [739M] * Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 153.0-alt1 - New version. - Build with llvm21.1 (upstream requires clang >= 19.0). - Raise minimal rust/cargo version to 1.90.0. - Fixes: + CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component + CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component + CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component + CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component + CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component + CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component + CVE-2026-16365: Privilege escalation in the DOM: Workers component + CVE-2026-16366: Privilege escalation in the DOM: Navigation component + CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component + CVE-2026-16354: Information disclosure in the Graphics: ImageLib component + CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component + CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component + CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component + CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-16357: Incorrect boundary conditions in the Graphics component + CVE-2026-16370: Mitigation bypass in the DOM: Networking component + CVE-2026-16371: Privilege escalation in the DOM: Navigation component + CVE-2026-16372: Privilege escalation in the DOM: Content Processes component + CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android + CVE-2026-16374: Information disclosure in the Framework component in DevTools + CVE-2026-16375: Site isolation issue in the Networking: HTTP component + CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component + CVE-2026-16377: Mitigation bypass in the PDF Viewer component + CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component + CVE-2026-16379: Privilege escalation in the DOM: Content Processes component + CVE-2026-16358: Site isolation issue in the Graphics: WebRender component + CVE-2026-16380: Mitigation bypass in the Networking component + CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component + CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component + CVE-2026-16383: Mitigation bypass in the DOM: Networking component + CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16387: Site isolation issue in the Networking component + CVE-2026-16388: Sandbox escape in the DOM: Networking component + CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS + CVE-2026-16390: Mitigation bypass in the Enterprise Policies component + CVE-2026-16391: Information disclosure in the Storage: IndexedDB component + CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component + CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component + CVE-2026-16394: Mitigation bypass in the DOM: Security component + CVE-2026-16395: Integer overflow in the Audio/Video component + CVE-2026-16396: Privilege escalation in WebExtensions + CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android + CVE-2026-16398: Site isolation issue in the Graphics component + CVE-2026-16399: Site isolation issue in the DOM: Navigation component + CVE-2026-16400: Information disclosure in the DOM: Security component + CVE-2026-16401: Privilege escalation in the Data Loss Prevention component + CVE-2026-16402: Integer overflow in the Graphics: ImageLib component + CVE-2026-16403: Spoofing issue in the Address Bar component + CVE-2026-16404: Spoofing issue in Firefox for Android + CVE-2026-16405: Information disclosure in the Networking: WebSockets component + CVE-2026-16406: Mitigation bypass in the Networking component + CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component + CVE-2026-16408: Integer overflow in the Audio/Video: Playback component + CVE-2026-16409: Invalid pointer in the Security: PSM component + CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16411: Memory safety bugs fixed in Firefox 153 + CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 + CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Tue Jul 14 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.6-alt1 - New version. - Fixes: + CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component + CVE-2026-15719: Site isolation in the DOM: Navigation component * Wed Jul 08 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.5-alt1 - New version. * Tue Jun 30 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.4-alt1 java-11-openjdk - OpenJDK Runtime Environment 11 [70M] * Sat Jul 25 2026 Andrey Cherepanov <cas@altlinux> 0:11.0.32.0.9-alt1 - New version (fixes: CVE-2026-41254, CVE-2026-46917, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-60147). - Remove unsupported NEWS. * Thu Apr 30 2026 Andrey Cherepanov <cas@altlinux> 0:11.0.31.0.11-alt1 libXfont - X.Org libXfont runtime library * Thu Jul 30 2026 Alexander Danilov <admsasha@altlinux> 1.5.4-alt3 - Applied upstream patch (fixed CVE-2026-56002). * Tue Apr 02 2019 Valery Inozemtsev <shrek@altlinux> 1.5.4-alt2 nss - Netscape Network Security Services(NSS) [52M] * Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 3.126-alt1 - New version. + Add CN=SECOM SMIME RSA Root CA 2024 + Add CN=SECOM TLS ECC Root CA 2024 + Add CN=SECOM TLS RSA Root CA 2024 + Add CN=Telia EC Email Root CA v3 + Add CN=Telia EC TLS Root CA v3 + Add CN=Telia RSA Email Root CA v3 + Add CN=Telia RSA TLS Root CA v3 + Remove OU=ePKI Root Certification Authority * Tue May 26 2026 Ajrat Makhmutov <rauty@altlinux> 3.124-alt1 perl-Net-SSLeay - Perl extension for using OpenSSL * Mon Mar 23 2026 Andrew A. Vasilyev <andy@altlinux> 1.96-alt1 - NMU: new version * Sat Dec 27 2025 Andrew A. Vasilyev <andy@altlinux> 1.94-alt2 - NMU: fix FTBFS with Debian patches * Sun Feb 18 2024 Igor Vlasenko <viy@altlinux> 1.94-alt1 python3-module-django-environ - Django-environ allows you to utilize 12factor inspired environment variables to configure your D * Mon Feb 16 2026 Martynenko Evgeniy <enimalojd@altlinux> 0.12.1-alt1 - New version (0.12.1). * Sat Jul 05 2025 Martynenko Evgeniy <enimalojd@altlinux> 0.12.0-alt1 - New version (0.12.0). * Mon May 15 2023 Dmitry Lyalyaev <fruktime@altlinux> 0.10.0-alt1 python3-module-handy-archives - Some handy archive helpers for Python * Thu Dec 18 2025 Anton Zhukharev <ancieg@altlinux> 0.2.0-alt3.35.g735b08c - Fixed FTBFS (apply upstream fixes). * Sun Oct 19 2025 Grigory Ustinov <grenka@altlinux> 0.2.0-alt2 - Fixed FTBFS. * Mon Jan 29 2024 Grigory Ustinov <grenka@altlinux> 0.2.0-alt1.1 python3-module-joblib - Lightweight pipelining: using Python functions as pipeline jobs * Tue Dec 16 2025 Stanislav Levin <slev@altlinux> 1.5.3-alt1 - 1.5.2 -> 1.5.3. * Tue Sep 02 2025 Stanislav Levin <slev@altlinux> 1.5.2-alt1 - 1.5.1 -> 1.5.2. * Thu May 29 2025 Stanislav Levin <slev@altlinux> 1.5.1-alt1 - 1.4.2 -> 1.5.1. * Fri May 03 2024 Stanislav Levin <slev@altlinux> 1.4.2-alt1 python3-module-loky - A robust implementation of concurrent.futures.ProcessPoolExecutor * Wed Mar 25 2026 Grigory Ustinov <grenka@altlinux> 3.5.6-alt1.1 - Demodernized packaging. * Tue Sep 02 2025 Stanislav Levin <slev@altlinux> 3.5.6-alt1 - 3.5.5 -> 3.5.6. * Thu May 29 2025 Stanislav Levin <slev@altlinux> 3.5.5-alt1 - 3.5.1 -> 3.5.5. * Wed Mar 19 2025 Stanislav Levin <slev@altlinux> 3.5.1-alt1 - 3.5.0 -> 3.5.1. * Mon Mar 17 2025 Stanislav Levin <slev@altlinux> 3.5.0-alt1 - 3.4.1 -> 3.5.0. * Thu Mar 21 2024 Stanislav Levin <slev@altlinux> 3.4.1-alt2 python3-module-skosprovider - Abstraction layer for SKOS vocabularies * Fri Jan 23 2026 Anton Vyatkin <toni@altlinux> 1.5.1-alt1 - New version 1.5.1. * Fri Oct 31 2025 Anton Vyatkin <toni@altlinux> 1.3.0-alt1 - New version 1.3.0. - New upstream url. * Fri Apr 14 2023 Anton Vyatkin <toni@altlinux> 1.2.0-alt1 python3-module-tomlkit - Style preserving TOML library * Thu Jun 05 2025 Stanislav Levin <slev@altlinux> 0.13.3-alt1 - 0.13.2 -> 0.13.3. * Wed Sep 25 2024 Stanislav Levin <slev@altlinux> 0.13.2-alt1 - 0.13.0 -> 0.13.2. * Fri Jul 12 2024 Stanislav Levin <slev@altlinux> 0.13.0-alt1 - 0.12.5 -> 0.13.0. * Mon May 13 2024 Stanislav Levin <slev@altlinux> 0.12.5-alt1 python3-module-uritools - URI parsing, classification and composition * Wed May 29 2024 Grigory Ustinov <grenka@altlinux> 4.0.3-alt1 - Automatically updated to 4.0.3. * Mon Sep 11 2023 Grigory Ustinov <grenka@altlinux> 4.0.2-alt1 sscg - Simple SSL certificate generator * Wed Aug 05 2026 Anton Midyukov <antohami@altlinux> 4.0.3-alt2 - Applied upstream fix: + Avoid segfault on receiving bad CLI arguments (Closes: 60094). * Tue Feb 17 2026 Andrey Limachko <liannnix@altlinux> 4.0.3-alt1 - Update to upstream version 4.0.3. - Breaking changes: * Minimum OpenSSL version raised to 3.x (dropped 1.1/2.x support). * DH parameters no longer generated by default (use --dhparams-file). * Custom DH parameter generation deprecated (will be removed in 5.0). * Removed --package argument (was deprecated in 3.0). * Minimum RSA key strength for private CA raised to 4096 bits. - New features: * Added ML-DSA (Module-Lattice Digital Signature Algorithm) support for post-quantum cryptography. * Added ECDSA (Elliptic Curve Digital Signature Algorithm) key generation. * Enhanced command-line interface with logically grouped help output. - Improvements: * Extended maximum DNS name length to 255 characters. * Improved compatibility with OpenSSL 3.4+. * Enhanced security: basicConstraint marked as critical for CA certificates. * Added internationalization (i18n) support and updated README. * Refactored key creation logic for better modularity. * Reworked file opening to avoid TOCTOU issues. - Bug fixes: * Fixed IP address handling in CA certificate SAN constraints. * Fixed regression when attempting to use same file for both CA and certificate. * Fixed various issues discovered by Coverity analysis. * Fixed detection of invalid hashes. * Better handling of files in general. * Tue Feb 07 2023 Andrey Limachko <liannnix@altlinux> 3.0.3-alt1 thunderbird - Thunderbird is Mozilla's e-mail client [956M] * Wed Jul 22 2026 Ajrat Makhmutov <rauty@altlinux> 153.0-alt1 - New version. - Fixes: + CVE-2026-14899: Off-by-one out of bounds read in MIME header parser for forwarding + CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component + CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component + CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component + CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component + CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component + CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component + CVE-2026-16365: Privilege escalation in the DOM: Workers component + CVE-2026-16366: Privilege escalation in the DOM: Navigation component + CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component + CVE-2026-16354: Information disclosure in the Graphics: ImageLib component + CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component + CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component + CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component + CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-16357: Incorrect boundary conditions in the Graphics component + CVE-2026-16370: Mitigation bypass in the DOM: Networking component + CVE-2026-16371: Privilege escalation in the DOM: Navigation component + CVE-2026-16372: Privilege escalation in the DOM: Content Processes component + CVE-2026-16374: Information disclosure in the Framework component in DevTools + CVE-2026-16375: Site isolation issue in the Networking: HTTP component + CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component + CVE-2026-16377: Mitigation bypass in the PDF Viewer component + CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component + CVE-2026-16379: Privilege escalation in the DOM: Content Processes component + CVE-2026-16358: Site isolation issue in the Graphics: WebRender component + CVE-2026-16380: Mitigation bypass in the Networking component + CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component + CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component + CVE-2026-16383: Mitigation bypass in the DOM: Networking component + CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component + CVE-2026-16387: Site isolation issue in the Networking component + CVE-2026-16388: Sandbox escape in the DOM: Networking component + CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS + CVE-2026-16390: Mitigation bypass in the Enterprise Policies component + CVE-2026-16391: Information disclosure in the Storage: IndexedDB component + CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component + CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component + CVE-2026-16394: Mitigation bypass in the DOM: Security component + CVE-2026-16395: Integer overflow in the Audio/Video component + CVE-2026-16396: Privilege escalation in WebExtensions + CVE-2026-16398: Site isolation issue in the Graphics component + CVE-2026-16399: Site isolation issue in the DOM: Navigation component + CVE-2026-16400: Information disclosure in the DOM: Security component + CVE-2026-16401: Privilege escalation in the Data Loss Prevention component + CVE-2026-16402: Integer overflow in the Graphics: ImageLib component + CVE-2026-16403: Spoofing issue in the Address Bar component + CVE-2026-16405: Information disclosure in the Networking: WebSockets component + CVE-2026-16406: Mitigation bypass in the Networking component + CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component + CVE-2026-16408: Integer overflow in the Audio/Video: Playback component + CVE-2026-16409: Invalid pointer in the Security: PSM component + CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-16411: Memory safety bugs fixed in Thunderbird 153 + CVE-2026-16412: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 + CVE-2026-16360: Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 * Wed Jul 01 2026 Ajrat Makhmutov <rauty@altlinux> 152.0.1-alt1 - New version. - Fixes: + CVE-2026-57962: Denial-of-service via malicious LDAP address-book server + CVE-2026-57963: Chat UI manipulation by injection - Disable the chat/instant-messaging feature by default via mail.chat.enabled (Closes: 44712, 52473, 56109, 57572). * Wed Jun 17 2026 Ajrat Makhmutov <rauty@altlinux> 152.0-alt1 Total 20601 source packages. _______________________________________________ Sisyphus-cybertalk mailing list [email protected] https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk
