1 REMOVED package
golang-torproject-pluggable-transports-goptlib 1.1.0-alt1_1
5 UPDATED packages
firefox-esr - The Mozilla Firefox project is a redesign of Mozilla's browser
[640M]
* Tue Sep 08 2026 Pavel Vasenkov <pav@altlinux> 140.14.0-alt0.p10.1
- Backport new version.
* Wed Aug 26 2026 Pavel Vasenkov <pav@altlinux> 140.14.0-alt1
- New ESR version.
- Security fixes:
+ CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component
+ CVE-2026-74935 Privilege escalation in the DOM: Networking component
+ CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component
+ CVE-2026-74939 Privilege escalation in the DOM: Navigation component
+ CVE-2026-74940 Use-after-free in the Graphics: Text component
+ CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component
+ CVE-2026-74942 Privilege escalation in the Remote Settings Client component
+ CVE-2026-74943 Use-after-free in the Graphics: ImageLib component
+ CVE-2026-74944 Use-after-free in the DOM: Core & HTML component
+ CVE-2026-74945 Information disclosure in the Graphics: Text component
+ CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in
the Graphics: CanvasWebGL component
+ CVE-2026-74948 Information disclosure in the Graphics component
+ CVE-2026-74953 Privilege escalation in the Networking: Cookies component
+ CVE-2026-74957 Mitigation bypass in the Safe Browsing component
+ CVE-2026-74959 Mitigation bypass in the Storage: Cache API component
+ CVE-2026-74960 Site isolation issue in the WebExtensions component
+ CVE-2026-74962 Site isolation issue in the Networking: Cookies component
+ CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies
component
+ CVE-2026-74964 Integer overflow in the Graphics component
+ CVE-2026-74965 Privilege escalation in the Shell Integration component
+ CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback
component
+ CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component
+ CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus
Handling component
+ CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions
component
+ CVE-2026-74949 Use-after-free in the Graphics: Canvas2D component
+ CVE-2026-74973 Race condition, use-after-free in the Graphics component
+ CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component
+ CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component
+ CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox
ESR 153.1 and Firefox 154
+ CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox
ESR 140.14, Firefox ESR 153.1 and Firefox 154
* Wed Jul 29 2026 Pavel Vasenkov <pav@altlinux> 140.13.0-alt1
- New ESR version.
- Security fixes:
+ CVE-2026-15718 Invalid pointer in the JavaScript: WebAssembly component
+ CVE-2026-15719 Site isolation issue in the DOM: Navigation component
+ CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component
+ CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb
component
+ CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component
+ CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation
component
+ CVE-2026-16352 Sandbox escape due to use-after-free in the Disability
Access APIs component
+ CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component
+ CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component
+ CVE-2026-16354 Information disclosure in the Graphics: ImageLib component
+ CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly
component
+ CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component
+ CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component
+ CVE-2026-16356 Sandbox escape due to use-after-free in the Disability
Access APIs component
+ CVE-2026-16357 Incorrect boundary conditions in the Graphics component
+ CVE-2026-16371 Privilege escalation in the DOM: Navigation component
+ CVE-2026-16374 Information disclosure in the Framework component in DevTools
+ CVE-2026-16375 Site isolation issue in the Networking: HTTP component
+ CVE-2026-16377 Mitigation bypass in the PDF Viewer component
+ CVE-2026-16379 Privilege escalation in the DOM: Content Processes component
+ CVE-2026-16358 Site isolation issue in the Graphics: WebRender component
+ CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component
+ CVE-2026-16383 Mitigation bypass in the DOM: Networking component
+ CVE-2026-16387 Site isolation issue in the Networking component
+ CVE-2026-16390 Mitigation bypass in the Enterprise Policies component
+ CVE-2026-16391 Information disclosure in the Storage: IndexedDB component
+ CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP
component
+ CVE-2026-16396 Privilege escalation in WebExtensions
+ CVE-2026-16405 Information disclosure in the Networking: WebSockets
component
+ CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox
153
+ CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR
140.13 and Firefox 153
+ CVE-2026-16361 Memory safety bugs fixed in Firefox ESR 115.38 and Firefox
ESR 140.13
* Thu Jun 18 2026 Pavel Vasenkov <pav@altlinux> 140.12.0-alt1
Note: changelog entry for 140.13.0-alt0.p10.1 not found.
glib2 - A library of handy utility functions
* Mon Sep 07 2026 Alexander Danilov <admsasha@altlinux> 2.68.4-alt5
- Backport upstream patchset (fixes: CVE-2026-58016, CVE-2026-58015,
CVE-2026-58014, CVE-2026-58013, CVE-2026-58012, CVE-2026-58011.
CVE-2026-58010, CVE-2026-15588).
* Thu Mar 17 2022 Slava Aseev <ptrnine@altlinux> 2.68.4-alt4
golang - The Go Programming Language [22M]
* Fri Sep 11 2026 Andrey Cherepanov <cas@altlinux> 1.26.7-alt0.p10.1
- Backported new version to p10 branch.
* Thu Aug 20 2026 Alexey Shabalin <shaba@altlinux> 1.26.7-alt1
- Updated from 1.26.6 to 1.26.7.
* Thu Aug 20 2026 Alexey Shabalin <shaba@altlinux> 1.26.6-alt1
- Updated from 1.26.5 to 1.26.6.
- Fixes:
+ CVE-2026-56853
+ CVE-2026-39821
+ CVE-2026-56862
+ CVE-2026-46600
+ CVE-2026-56859
+ CVE-2026-56860
+ CVE-2026-56864
+ CVE-2026-56865
+ CVE-2026-33818
+ CVE-2026-56858
* Wed Jul 08 2026 Alexey Shabalin <shaba@altlinux> 1.26.5-alt1
- Updated from 1.26.4 to 1.26.5.
- Fixes:
+ CVE-2026-39822
+ CVE-2026-42505
* Sun Jun 14 2026 Alexey Shabalin <shaba@altlinux> 1.26.4-alt1
- Updated from 1.26.3 to 1.26.4.
- Add race subpackage and disable build.
- Fixes:
+ CVE-2026-42504
+ CVE-2026-42507
+ CVE-2026-27145
* Fri May 08 2026 Alexey Shabalin <shaba@altlinux> 1.26.3-alt1
- updated from 1.26.2 to 1.26.3.
- Fixes:
+ CVE-2026-27142
+ CVE-2026-33811
+ CVE-2026-33814
+ CVE-2026-39817
+ CVE-2026-39819
+ CVE-2026-39820
+ CVE-2026-39823
+ CVE-2026-39825
+ CVE-2026-39826
+ CVE-2026-39836
+ CVE-2026-42499
+ CVE-2026-42501
* Fri Apr 10 2026 Alexey Shabalin <shaba@altlinux> 1.26.2-alt1
- updated from 1.26.1 to 1.26.2.
- Fixes:
+ CVE-2026-27140
+ CVE-2026-27143
+ CVE-2026-27144
+ CVE-2026-32280
+ CVE-2026-32281
+ CVE-2026-32282
+ CVE-2026-32283
+ CVE-2026-32288
+ CVE-2026-32289
+ CVE-2026-33810
* Fri Mar 06 2026 Alexey Shabalin <shaba@altlinux> 1.26.1-alt1
- updated from 1.26.0 to 1.26.1 (Fixes: CVE-2026-27139, CVE-2026-25679,
CVE-2026-27142,
CVE-2026-27137, CVE-2026-27138).
* Fri Feb 20 2026 Alexey Shabalin <shaba@altlinux> 1.26.0-alt1
- updated from 1.25.7 to 1.26.0
* Sat Feb 07 2026 Alexey Shabalin <shaba@altlinux> 1.25.7-alt1
- 1.25.7 (Fixes CVE-2025-61732, CVE-2025-61727).
* Thu Jan 29 2026 Alexey Shabalin <shaba@altlinux> 1.25.6-alt2
- Package lib/wasm/wasm_exec.js (ALT#57661).
* Mon Jan 19 2026 Alexey Shabalin <shaba@altlinux> 1.25.6-alt1
- 1.25.6 (Fixes: CVE-2025-68121, CVE-2025-61728, CVE-2025-61726,
CVE-2025-61731, CVE-2025-68119, CVE-2025-61730).
* Tue Dec 02 2025 Alexey Shabalin <shaba@altlinux> 1.25.5-alt1
- 1.25.5 (Fixes: CVE-2025-61727, CVE-2025-61729).
* Fri Nov 07 2025 Alexey Shabalin <shaba@altlinux> 1.25.4-alt1
- 1.25.4.
* Wed Oct 15 2025 Alexey Shabalin <shaba@altlinux> 1.25.3-alt1
- 1.25.3.
* Tue Oct 07 2025 Alexey Shabalin <shaba@altlinux> 1.25.2-alt1
- 1.25.2.
- Fixes:
+ CVE-2025-47912
+ CVE-2025-58183
+ CVE-2025-58185
+ CVE-2025-58186
+ CVE-2025-58187
+ CVE-2025-58188
+ CVE-2025-58189
+ CVE-2025-61723
+ CVE-2025-61724
+ CVE-2025-61725
* Mon Sep 08 2025 Alexey Shabalin <shaba@altlinux> 1.25.1-alt1
- New version (1.25.1) (Fixes: CVE-2025-47910).
* Tue Aug 19 2025 Alexey Shabalin <shaba@altlinux> 1.25.0-alt2
- Disabled dwarf5 debugdata collection (ALT#55626).
* Wed Aug 13 2025 Alexey Shabalin <shaba@altlinux> 1.25.0-alt1
- New version (1.25.0).
* Fri Aug 08 2025 Alexey Shabalin <shaba@altlinux> 1.24.6-alt1
Note: changelog entry for 1.24.13-alt1 not found.
gopls - The Go language server
* Fri Aug 22 2025 Artem Krasovskiy <aibure@altlinux> 0.20.0-alt1
- Updated to 0.20.0.
* Mon Jul 21 2025 Artem Krasovskiy <aibure@altlinux> 0.19.1-alt1
- Updated to 0.19.1.
* Thu Jun 19 2025 Artem Krasovskiy <aibure@altlinux> 0.19.0-alt1
- Updated to 0.19.0.
* Tue Feb 25 2025 Anton Zhukharev <ancieg@altlinux> 0.18.1-alt1
- Updated to 0.18.1.
* Sun Oct 13 2024 Anton Zhukharev <ancieg@altlinux> 0.16.2-alt1
- Updated to 0.16.2.
* Wed Jul 03 2024 Anton Zhukharev <ancieg@altlinux> 0.16.1-alt2
- Fixed gopls version detection.
* Wed Jul 03 2024 Anton Zhukharev <ancieg@altlinux> 0.16.1-alt1
- Updated to 0.16.1.
* Wed May 15 2024 Anton Zhukharev <ancieg@altlinux> 0.15.3-alt1
- Updated to 0.15.3.
* Mon Apr 01 2024 Anton Zhukharev <ancieg@altlinux> 0.15.2-alt1
- Updated to 0.15.2.
* Fri Nov 17 2023 Anton Zhukharev <ancieg@altlinux> 0.14.2-alt1
- Updated to 0.14.2.
* Tue Nov 07 2023 Anton Zhukharev <ancieg@altlinux> 0.14.1-alt1
- Updated to 0.14.1.
* Tue Aug 15 2023 Anton Zhukharev <ancieg@altlinux> 0.13.2-alt1
- Updated to 0.13.2.
* Wed Aug 02 2023 Anton Zhukharev <ancieg@altlinux> 0.13.1-alt1
grafana - Metrics dashboard and graph editor [414M]
* Tue Apr 21 2026 Alexey Shabalin <shaba@altlinux> 12.3.6-alt1
- 12.3.6+security-01
- Fixes:
+ CVE-2026-27876
+ CVE-2026-27877
+ CVE-2026-27879
+ CVE-2026-27880
+ CVE-2026-28375
+ CVE-2026-33375
* Fri Jan 30 2026 Alexey Shabalin <shaba@altlinux> 12.3.2-alt1
- 12.3.2 (Fixes: CVE-2026-21720, CVE-2026-21721).
* Wed Aug 13 2025 Alexey Shabalin <shaba@altlinux> 12.1.0-alt2
Total 19181 source packages.
_______________________________________________
Sisyphus-cybertalk mailing list
[email protected]
https://lists.altlinux.org/mailman/listinfo/sisyphus-cybertalk