Search CVE reports


Toggle filters

31 – 40 of 1370 results


CVE-2026-91837

Medium priority
Needs evaluation

[network-manager-iodine: Option confusion reaches iodine's pre-drop root shell]

1 affected package

network-manager-iodine

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager-iodine Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-75131

Medium priority
Needs evaluation

security update

1 affected package

network-manager-l2tp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager-l2tp Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-19816

Medium priority
Not affected

A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real...

1 affected package

packagekit

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
packagekit Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-19624

Medium priority
Needs evaluation

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged...

1 affected package

network-manager-l2tp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
network-manager-l2tp Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-87737

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time required for a lookup can depend on a secret.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87736

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87735

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87733

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, as a public key. With that public key,...

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-87732

Medium priority
Needs evaluation

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and...

1 affected package

ocaml-mirage-crypto

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocaml-mirage-crypto Needs evaluation Needs evaluation Needs evaluation — —
Show less packages

CVE-2026-86425

Medium priority
Needs evaluation

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation,...

1 affected package

imagemagick

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages