Zvipingamupinyi zvakawanda zvine njodzi zvakawanikwa munguva pfupi yapfuura:
- Pane matambudziko matanhatu aripo mukushandiswa kwe rsync file synchronization. Dambudziko guru (CVE-2026-29518), rinokonzerwa nemamiriro emujaho pakubata ma symbol links, rinobvumira ropafadzo yekuwedzera kana uchimhanya rsync kumashure pasina chroot isolation. Kurwiswa kunoitwa nekutsiva faira ne symbol link inonongedzera kufaira risingatarisirwi mu system, mushure mekunge cheki yaitwa asi usati watanga kunyora. Matambudziko acho anogadziriswa mu rsync 3.4.3. CVEs mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Dambudziko (CVE-2026-8631) muHPLIP, seti yemadhiraivha eprinta anovhura-source uye MFP, inobvumira kuwedzera kwekodzero uye kuita kodhi. Matambudziko aya anokonzerwa nekutsiviwa kwemirairo uye buffer overflow. Dambudziko iri rakagadziriswa muHPLIP 3.26.4. MaCVE mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Kusagadzikana kuri muD-Bus service inoshandiswa muqSnapper, iyo graphical interface yekugadzirisa Btrfs snapshots, kuripo. Kusagadzikana uku kunogona kutungamira mukuwedzera kwekodzero (CVE-2026-41046), kubuda kwemashoko nezve shanduko pakati pe snapshots (CVE-2026-41047), uye kunzvenga authentication paunenge uchipinda Polkit (CVE-2026-41045). Kusagadzikana kwakanyanya kunokonzerwa nekushaikwa kwekutarisa mavara e "../" munzira dzinopfuudzwa kubasa re snapper::Snapper() paunenge uchipinda kuburikidza neD-Bus. Izvi zvinogona kushandiswa kunyengedza faira re libsnapper configuration mu handler inomhanya nekodzero dzakakwira.
Kugoverwa kweCVE: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch. - Kukuvara (CVE-2026-48095) mu 7-Zip archiver kunoita kuti buffer iwande zvakanyanya kana uchigadzirisa data re NTFS rakamanikidzwa. Kukuvara uku kunogona kukonzera kuurayiwa kwekodhi yemurwisi kana ukawana mufananidzo wefaira reNTFS wakagadzirwa zvakananga kuburikidza ne 7-Zip. Kukuvara uku kwakagadziriswa mu 7-Zip version 26.01. MaCVE ari mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Sevha yeDNS isina kusungwa 1.25.1 inogadzirisa matambudziko gumi nerimwe. Matambudziko akakomba ndeaya CVE-2026-33278 (kuitwa kwekodhi iri kure panguva yekusimbisa DNSSEC), CVE-2026-44608 (kushandisa-after-free memory muRPZ code), uye CVE-2026-42944 (heap overflow panguva yekugadzirisa nsid). MaCVE ari mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ (CVE-2026-3593) Π² DNS-ΡΠ΅ΡΠ²Π΅ΡΠ΅ BIND, ΠΏΠΎΠ·Π²ΠΎΠ»ΡΡΡΠ°Ρ Π²ΡΠ·Π²Π°ΡΡ ΠΎΠ±ΡΠ°ΡΠ΅Π½ΠΈΠ΅ ΠΊ ΠΏΠ°ΠΌΡΡΠΈ ΠΏΠΎΡΠ»Π΅ Π΅Ρ ΠΎΡΠ²ΠΎΠ±ΠΎΠΆΠ΄Π΅Π½ΠΈΡ ΠΈ ΠΏΠΎΠ²ΡΠ΅ΠΆΠ΄Π΅Π½ΠΈΠ΅ ΡΠΎΠ΄Π΅ΡΠΆΠΈΠΌΠΎΠ³ΠΎ ΠΏΠ°ΠΌΡΡΠΈ ΡΠ΅ΡΠ΅Π· ΠΎΡΠΏΡΠ°Π²ΠΊΡ ΡΠΏΠ΅ΡΠΈΠ°Π»ΡΠ½ΠΎ ΠΎΡΠΎΡΠΌΠ»Π΅Π½Π½ΠΎΠ³ΠΎ Π·Π°ΠΏΡΠΎΡΠ° ΠΊ sevha DNS-over-HTTPS. ΠΡΠΎΠ±Π»Π΅ΠΌΠ° ΡΡΡΡΠ°Π½Π΅Π½Π° Π² Π²Π΅ΡΡΠΈΡΡ BIND 9.20.23 ΠΈ 9.21.22. ΠΠΎΠ½ΡΠΈΠ³ΡΡΠ°ΡΠΈΠΈ Π½Π΅ ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡΡΠΈΠ΅ DNS-over-HTTPS ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ Π½Π΅ ΠΏΠΎΠ΄Π²Π΅ΡΠΆΠ΅Π½Ρ. CVE Π² Π΄ΠΈΡΡΡΠΈΠ±ΡΡΠΈΠ²Π°Ρ : Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Kukuvara (CVE-2026-47243) muKata Containers, iyo container execution stack inoshandisa virtualization-based isolation, inobvumira root privileges mu container kugadzira symbol link pane host system. Nekugadzira symbol link mu /etc/cron.d , vashandisi vanogona kuita custom code ine root privileges munzvimbo ye host. Kukuvara uku kunokonzerwa nekukwanisa kutumira direct FUSE_SYMLINK request kune virtiofsd handler iri kushanda pa host. Dambudziko iri rinozviratidza pakushandisa runtime-rs uye rakagadziriswa mu release 3.31.0.
Kugoverwa kweCVE: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Dambudziko (CVE-2026-46529) riri muAtril document viewer rinobvumira kodhi yemurwisi kuti ishandiswe kana uchidzvanya link iri mukati mePDF file yakagadzirwa zvakanaka inosanganisa PDF document neELF library. Pane exploit iripo. Dambudziko rakafanana riripo muEvince neXreader PDF viewers. Dambudziko iri rinokonzerwa nekushaikwa kwekubuda kwe shell quoting special characters mu ev_spawn() function. Dambudziko iri rakagadziriswa muEvince 48.2, Atril 1.28.4/1.26.3, uye Xreader 4.6.4/3.6.7. CVEs mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Dambudziko (CVE isina kugoverwa) muYelp help viewer (GNOME Help) rinobvumira kupinda mumafaira ehurongwa hwehost nekupfuura Flatpak package sandbox nekuvhura faira rerubatsiro rakagadzirwa nehunyanzvi. Dambudziko iri rakafanana neregore rapfuura uye rinosiyana nekuti rinoshandisa masitayera eCSS akaiswa muSVG file pakugadzira. Dambudziko iri rakagadziriswa muYelp 49.1.
- Dambudziko (CVE-2026-41054) riri mu haveged, maitiro ekumashure anogadzira entropy ye pseudo-random number generator, inobvumira ropafadzo yekuwedzera kumushandisi weroot nekutumira murairo wakagadzirwa zvakananga pamusoro peUnix control socket. Dambudziko racho rakagadziriswa mu haveged 1.9.21. CVEs mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- 11 ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π² Π‘Π£ΠΠ PostgreSQL, Π½Π°ΠΈΠ±ΠΎΠ»Π΅Π΅ ΠΎΠΏΠ°ΡΠ½Π°Ρ ΠΈΠ· ΠΊΠΎΡΠΎΡΡΡ
(CVE-2026-6637) ΠΌΠΎΠΆΠ΅Ρ ΠΏΡΠΈΠ²Π΅ΡΡΠΈ ΠΊ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΡ ΠΊΠΎΠ΄Π° Π½Π° ΡΡΠΎΠ²Π½Π΅ ΠΎΠΏΠ΅ΡΠ°ΡΠΈΠΎΠ½Π½ΠΎΠΉ ΡΠΈΡΡΠ΅ΠΌΡ Ρ ΠΏΡΠ°Π²Π°ΠΌΠΈ ΡΠ΅ΡΠ²Π΅ΡΠ½ΠΎΠ³ΠΎ ΠΏΡΠΎΡΠ΅ΡΡΠ° PostgreSQL ΠΏΡΠΈ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΠΈ ΡΠΏΠ΅ΡΠΈΠ°Π»ΡΠ½ΠΎ ΠΎΡΠΎΡΠΌΠ»Π΅Π½Π½ΡΡ
SQL-Π·Π°ΠΏΡΠΎΡΠΎΠ² (Π°ΡΠ°ΠΊΡΡΡΠΈΠΉ Π΄ΠΎΠ»ΠΆΠ΅Π½ ΠΈΠΌΠ΅ΡΡ Π½Π΅ΠΏΡΠΈΠ²ΠΈΠ»Π΅Π³ΠΈΡΠΎΠ²Π°Π½Π½ΡΠΉ Π΄ΠΎΡΡΡΠΏ ΠΊ Π‘Π£ΠΠ). ΠΡΡΠ³Π°Ρ ΠΎΠΏΠ°ΡΠ½Π°Ρ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΡ (CVE-2026-6475) ΠΏΠΎΠ·Π²ΠΎΠ»ΡΠ΅Ρ ΠΏΠ΅ΡΠ΅Π·Π°ΠΏΠΈΡΠ°ΡΡ ΡΠ°ΠΉΠ»Ρ Π½Π° server (Π½Π°ΠΏΡΠΈΠΌΠ΅Ρ, /var/lib/postgres/.bashrc) ΡΠ΅ΡΠ΅Π· ΠΌΠ°Π½ΠΈΠΏΡΠ»ΡΡΠΈΠΈ Ρ ΡΠΈΠΌΠ²ΠΎΠ»ΠΈΡΠ΅ΡΠΊΠΈΠΌΠΈ ΡΡΡΠ»ΠΊΠ°ΠΌΠΈ ΠΏΡΠΈ Π²ΡΠΏΠΎΠ»Π½Π΅Π½ΠΈΠΈ ΠΎΠΏΠ΅ΡΠ°ΡΠΈΠΉ Ρ pg_basebackup ΠΈ pg_rewind. ΠΡΠΎΠ±Π»Π΅ΠΌΡ ΡΡΡΡΠ°Π½Π΅Π½Ρ Π² Π²ΡΠΏΡΡΠΊΠ°Ρ
PostgreSQL 18.4, 17.10, 16.14, 15.18 ΠΈ 14.23. Π’Π°ΠΊΠΆΠ΅ ΠΌΠΎΠΆΠ½ΠΎ ΠΎΡΠΌΠ΅ΡΠΈΡΡ ΠΏΡΠ±Π»ΠΈΠΊΠ°ΡΠΈΡ ΡΠ°Π±ΠΎΡΠ΅Π³ΠΎ ΡΠΊΡΠΏΠ»ΠΎΠΈΡΠ° Π΄Π»Ρ ΡΠ°Π½Π΅Π΅ Π²ΡΡΠ²Π»Π΅Π½Π½ΠΎΠΉ ΡΡΠ·Π²ΠΈΠΌΠΎΡΡΠΈ (CVE-2026-2005) Π² ΡΠ°ΡΡΠΈΡΠ΅Π½ΠΈΠΈ pgcrypto.
Kugoverwa kweCVE: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Zvine njodzi gumi nematanhatu zvakawanikwa muSuricata network intrusion detection and prevention system, zvina zvacho zvakaongororwa kuti zvakakosha. Ruzivo rwezvine njodzi harusati rwaburitswa pachena, asi tichitarisa huwandu hwazvo hwekuoma, zvinobvumira kushandiswa kwekodhi paserver kana uchitarisa traffic yakagadzirwa zvakanaka. Zvine njodzi zvakagadziriswa muSuricata 8.0.5 na7.0.16.
- Kukuvadzwa (CVE-2026-8053) muMongoDB Server kunobvumira mushandisi ane mukana wekunyora kudhatabhesi kuti atange kubuda kwebuffer uye aite kodhi isina kurongeka paseva ine kodzero dzemaitiro emongod. Kukuvadzwa kwacho kwakagadziriswa muMongoDB 5.0.33, 6.0.28, 7.0.34, 8.0.23, 8.2.9, uye 8.3.2. MaCVE mukugoverwa: Debian, Ubuntu, SUSE, RHEL, Gentoo, Arch.
- Matambudziko gumi (CVE haina kupihwa) muMemcached in-memory data caching system akawanikwa, akakomba zvikuru ayo aikonzera buffer overflows pakutumira zvikumbiro zvakagadzirwa zvakananga uye zvinogona kushandiswa kuita kodhi paserver. Matambudziko acho akagadziridzwa muMemcached 1.6.42.
Source: opennet.ru
