1 ADDED package
libfido2 - Library functionality to communicate with a FIDO device over USB
* Thu Feb 12 2026 Anton Zhukharev <ancieg@altlinux> 1.16.0-alt6
- Removed 'plugdev' from 70-u2f.rules to use 'uaccess' only (ALT#57844).
* Thu Jan 22 2026 Anton Zhukharev <ancieg@altlinux> 1.16.0-alt5
- Removed libfido2 obsoletion for future ABI version change (ALT#56956).
* Wed Jan 21 2026 Anton Zhukharev <ancieg@altlinux> 1.16.0-alt4
- Unbound library name and source package name (ALT#56956).
* Tue Jan 20 2026 Anton Zhukharev <ancieg@altlinux> 1.16.0-alt3
1 REMOVED package
fido2 1.13.0-alt2
3 UPDATED packages
7-zip - Official 7-zip for linux, the file archiver with a high compression
ratio
* Sat Jun 27 2026 Fr. Br. George <george@altlinux> 26.02-alt1
- Autobuild version bump to 26.02
* Wed Apr 29 2026 Vitaly Lipatov <lav@altlinux> 26.01-alt1
- new version 26.01 (ALT #58910)
* Fri Apr 10 2026 Vitaly Lipatov <lav@altlinux> 26.00-alt3
- add Provides: 7zip
* Fri Feb 27 2026 Vitaly Lipatov <lav@altlinux> 26.00-alt2
- Add /usr/bin/7z, /usr/bin/7za and provide p7zip (ALT bug 49730)
* Sat Feb 14 2026 Fr. Br. George <george@altlinux> 26.00-alt1
- Autobuild version bump to 26.00
* Mon Aug 18 2025 Fr. Br. George <george@altlinux> 25.01-alt1
- Autobuild version bump to 25.01
- Fixes: CVE-2025-55188
* Sun Jul 06 2025 Fr. Br. George <george@altlinux> 25.00-alt1
- Autobuild version bump to 25.00
* Fri May 23 2025 Alexander Danilov <admsasha@altlinux> 24.09-alt2
- Fix build for old branch.
* Thu May 22 2025 Fr. Br. George <george@altlinux> 24.09-alt1
- Autobuild version bump to 24.09
* Thu May 23 2024 Ilya Kurdyukov <ilyakurdyukov@altlinux> 24.05-alt2
- remove obsolete patch for Elbrus
* Mon May 20 2024 Fr. Br. George <george@altlinux> 24.05-alt1
- Manual version bump to 24.05
* Tue Mar 05 2024 Ilya Kurdyukov <ilyakurdyukov@altlinux> 23.01-alt2
- update patch for Elbrus
- compile with profiling
- fix armh build
* Sat Mar 02 2024 Ilya Kurdyukov <ilyakurdyukov@altlinux> 23.01-alt1.1
- simd patch for Elbrus
* Thu Sep 28 2023 Fr. Br. George <george@altlinux> 23.01-alt1
freerdp3 - Remote Desktop Protocol functionality
* Wed Aug 05 2026 Andrey Cherepanov <cas@altlinux> 3.30.0-alt2
- Built with all channels and support for Opus and Cairo.
* Tue Jul 28 2026 Andrey Cherepanov <cas@altlinux> 3.30.0-alt1
- New version (fixes: GHSA-m37j-jcr2-8gcc, GHSA-vv64-95pc-vj9v,
GHSA-rqgv-grx4-xm6x).
* Sat Jun 20 2026 Andrey Cherepanov <cas@altlinux> 3.27.1-alt1
thunderbird - Thunderbird is Mozilla's e-mail client [793M]
* Thu Aug 13 2026 Pavel Vasenkov <pav@altlinux> 148.0.1-alt0.p10.1
- Backported new version to p10 branch.
* Sun Mar 15 2026 Ajrat Makhmutov <rauty@altlinux> 148.0.1-alt1
- New version.
* Sat Feb 28 2026 Ajrat Makhmutov <rauty@altlinux> 148.0-alt2
- Update l10n for the 148.
* Wed Feb 25 2026 Ajrat Makhmutov <rauty@altlinux> 148.0-alt1
- New version.
- Fixes:
+ CVE-2026-2757: Incorrect boundary conditions in the WebRTC: Audio/Video
component
+ CVE-2026-2758: Use-after-free in the JavaScript: GC component
+ CVE-2026-2759: Incorrect boundary conditions in the Graphics: ImageLib
component
+ CVE-2026-2795: Use-after-free in the JavaScript: GC component
+ CVE-2026-2760: Sandbox escape due to incorrect boundary conditions in the
Graphics: WebRender component
+ CVE-2026-2761: Sandbox escape in the Graphics: WebRender component
+ CVE-2026-2762: Integer overflow in the JavaScript: Standard Library
component
+ CVE-2026-2763: Use-after-free in the JavaScript Engine component
+ CVE-2026-2764: JIT miscompilation, use-after-free in the JavaScript Engine:
JIT component
+ CVE-2026-2796: JIT miscompilation in the JavaScript: WebAssembly component
+ CVE-2026-2797: Use-after-free in the JavaScript: GC component
+ CVE-2026-2765: Use-after-free in the JavaScript Engine component
+ CVE-2026-2766: Use-after-free in the JavaScript Engine: JIT component
+ CVE-2026-2767: Use-after-free in the JavaScript: WebAssembly component
+ CVE-2026-2768: Sandbox escape in the Storage: IndexedDB component
+ CVE-2026-2798: Use-after-free in the DOM: Core & HTML component
+ CVE-2026-2769: Use-after-free in the Storage: IndexedDB component
+ CVE-2026-2799: Use-after-free in the DOM: Core & HTML component
+ CVE-2026-2770: Use-after-free in the DOM: Bindings (WebIDL) component
+ CVE-2026-2771: Undefined behavior in the DOM: Core & HTML component
+ CVE-2026-2772: Use-after-free in the Audio/Video: Playback component
+ CVE-2026-2773: Incorrect boundary conditions in the Web Audio component
+ CVE-2026-2774: Integer overflow in the Audio/Video component
+ CVE-2026-2775: Mitigation bypass in the DOM: HTML Parser component
+ CVE-2026-2776: Sandbox escape due to incorrect boundary conditions in the
Telemetry component in External Software
+ CVE-2026-2777: Privilege escalation in the Messaging System component
+ CVE-2026-2778: Sandbox escape due to incorrect boundary conditions in the
DOM: Core & HTML component
+ CVE-2026-2779: Incorrect boundary conditions in the Networking: JAR
component
+ CVE-2026-2800: Spoofing issue in the WebAuthn component in Firefox for
Android
+ CVE-2026-2780: Privilege escalation in the Netmonitor component
+ CVE-2026-2781: Integer overflow in the Libraries component in NSS
+ CVE-2026-2801: Incorrect boundary conditions in the JavaScript: WebAssembly
component
+ CVE-2026-2782: Privilege escalation in the Netmonitor component
+ CVE-2026-2783: Information disclosure due to JIT miscompilation in the
JavaScript Engine: JIT component
+ CVE-2026-2802: Race condition in the JavaScript: GC component
+ CVE-2026-2803: Information disclosure, mitigation bypass in the Settings UI
component
+ CVE-2026-2784: Mitigation bypass in the DOM: Security component
+ CVE-2026-2785: Invalid pointer in the JavaScript Engine component
+ CVE-2026-2804: Use-after-free in the JavaScript: WebAssembly component
+ CVE-2026-2786: Use-after-free in the JavaScript Engine component
+ CVE-2026-2805: Invalid pointer in the DOM: Core & HTML component
+ CVE-2026-2787: Use-after-free in the DOM: Window and Location component
+ CVE-2026-2788: Incorrect boundary conditions in the Audio/Video: GMP
component
+ CVE-2026-2789: Use-after-free in the Graphics: ImageLib component
+ CVE-2026-2806: Uninitialized memory in the Graphics: Text component
+ CVE-2026-2790: Same-origin policy bypass in the Networking: JAR component
+ CVE-2026-2791: Mitigation bypass in the Networking: Cache component
+ CVE-2026-2807: Memory safety bugs fixed in Firefox 148 and Thunderbird 148
+ CVE-2026-2792: Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird
ESR 140.8, Firefox 148 and Thunderbird 148
+ CVE-2026-2793: Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR
140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
* Fri Feb 20 2026 Ajrat Makhmutov <rauty@altlinux> 147.0.2-alt1
- New version.
- Fixes:
+ CVE-2026-2447: Heap buffer overflow in libvpx
* Thu Feb 12 2026 Ajrat Makhmutov <rauty@altlinux> 147.0.1-alt1
- New version.
- Fixes:
+ CVE-2026-0818: CSS-based exfiltration of the content from partially
encrypted emails when allowing remote content
* Thu Jan 15 2026 Ajrat Makhmutov <rauty@altlinux> 147.0-alt1
- New version.
- Fixes:
+ CVE-2026-0877: Mitigation bypass in the DOM: Security component
+ CVE-2026-0878: Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component
+ CVE-2026-0879: Sandbox escape due to incorrect boundary conditions in the
Graphics component
+ CVE-2026-0880: Sandbox escape due to integer overflow in the Graphics
component
+ CVE-2026-0881: Sandbox escape in the Messaging System component
+ CVE-2026-0882: Use-after-free in the IPC component
+ CVE-2026-0883: Information disclosure in the Networking component
+ CVE-2026-0884: Use-after-free in the JavaScript Engine component
+ CVE-2026-0885: Use-after-free in the JavaScript: GC component
+ CVE-2026-0886: Incorrect boundary conditions in the Graphics component
+ CVE-2026-0887: Clickjacking issue, information disclosure in the PDF Viewer
component
+ CVE-2026-0888: Information disclosure in the XML component
+ CVE-2026-0889: Denial-of-service in the DOM: Service Workers component
+ CVE-2026-0890: Spoofing issue in the DOM: Copy & Paste and Drag & Drop
component
+ CVE-2026-0891: Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird
ESR 140.7, Firefox 147 and Thunderbird 147
+ CVE-2026-0892: Memory safety bugs fixed in Firefox 147 and Thunderbird 147
* Sat Dec 20 2025 Ajrat Makhmutov <rauty@altlinux> 146.0.1-alt1
- New version.
* Thu Dec 11 2025 Ajrat Makhmutov <rauty@altlinux> 146.0-alt1
- New version.
- Fixes:
+ CVE-2025-14321: Use-after-free in the WebRTC: Signaling component
+ CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the
Graphics: CanvasWebGL component
+ CVE-2025-14323: Privilege escalation in the DOM: Notifications component
+ CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2025-14326: Use-after-free in the Audio/Video: GMP component
+ CVE-2025-14327: Spoofing issue in the Downloads Panel component
+ CVE-2025-14328: Privilege escalation in the Netmonitor component
+ CVE-2025-14329: Privilege escalation in the Netmonitor component
+ CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2025-14331: Same-origin policy bypass in the Request Handling component
+ CVE-2025-14332: Memory safety bugs fixed in Firefox 146 and Thunderbird 146
+ CVE-2025-14333: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird
ESR 140.6, Firefox 146 and Thunderbird 146
* Mon Nov 17 2025 Ajrat Makhmutov <rauty@altlinux> 145.0-alt1
- New version.
- Fixes:
+ CVE-2025-13021: Incorrect boundary conditions in the Graphics: WebGPU
component
+ CVE-2025-13022: Incorrect boundary conditions in the Graphics: WebGPU
component
+ CVE-2025-13012: Race condition in the Graphics component
+ CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in the
Graphics: WebGPU component
+ CVE-2025-13016: Incorrect boundary conditions in the JavaScript:
WebAssembly component
+ CVE-2025-13024: JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2025-13025: Incorrect boundary conditions in the Graphics: WebGPU
component
+ CVE-2025-13026: Sandbox escape due to incorrect boundary conditions in the
Graphics: WebGPU component
+ CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications
component
+ CVE-2025-13018: Mitigation bypass in the DOM: Security component
+ CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component
+ CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component
+ CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component
+ CVE-2025-13014: Use-after-free in the Audio/Video component
+ CVE-2025-13015: Spoofing issue in Thunderbird
+ CVE-2025-13027: Memory safety bugs fixed in Firefox 145 and Thunderbird 145
* Fri Oct 17 2025 Ajrat Makhmutov <rauty@altlinux> 144.0.1-alt1
Note: changelog entry for 145.0-alt0.p10.1 not found.
Total 19182 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk