Last changes

Repository created for Dec. 11, 2025
Dec 10, 2025, 03:57 PM
#402299 sent by Alexander Danilov
fix_CVE-2024-50614,CVE-2024-50615
Simple, small, efficient, C++ XML parser
rebuild fuse-encfs-1.9.5-alt1
Encrypted pass-thru filesystem for Linux
Dec 10, 2025, 09:37 AM
#402195 sent by Anton Vyatkin
security_fix
A streaming multipart parser for Python
July 18, 2025 Anton Zhukharev:
- Removed 'multipart' import name to avoid conflict with 'multipart' package. - Actualized upstream VCS location.
The little ASGI framework that shines
Dec. 8, 2025 Anton Vyatkin:
- Security fixes (CVE-2024-47874, CVE-2025-54121).
Dec 8, 2025, 04:37 PM
#401821 sent by Alexander Danilov
fix_CVE-2025-66293
A library of functions for manipulating PNG image format files
Dec. 4, 2025 Sergey Bolshakov:
- 1.6.52 (fixes: CVE-2025-66293)
Dec 8, 2025, 04:31 PM
#401814 sent by Paul Wolneykien
OVE-20251204-0001
Generates checksum file for an RPM repo slice
Nov. 26, 2025 Paul Wolneykien:
- Note, that v0.3.0-alt1 fixes missing checksum data for *.ko.zst files by including *.ko.zst by default (Fixes: OVE-20251204-0001).
Dec 8, 2025, 10:36 AM
#402130 sent by Alexander Danilov
because_CVE-2025-66566
deleted lz4-java
Dec. 8, 2025 Alexander Danilov:
- package removed
Dec 5, 2025, 06:00 PM
#401805 sent by Alexander Danilov
fix_CVE-2025-31133,CVE-2025-52565,CVE-2025-52881
CLI for running Open Containers
Nov. 28, 2025 Vladimir Didenko:
- New version - Drop loongarch patches since it is already fixed by upstream
Dec 5, 2025, 05:10 PM
#401759 sent by Alexei Takaseev
New version fix CVE-2025-12819
Lightweight connection pooler for PostgreSQL
Dec. 4, 2025 Alexei Takaseev:
- 1.25.0 (Fixes: CVE-2025-12819) - Drop pgbouncer-1.25.0-Fix-build-on-i586.patch (Fix upstream)
Dec 5, 2025, 12:32 PM
#401783 sent by Alexander Danilov
fix_CVE-2025-31176,CVE-2025-31178,CVE-2025-31179,CVE-2025-31180,CVE-2025-31181
A program for plotting mathematical expressions and data
Dec. 4, 2025 Alexander Danilov:
- Applied upstream patchset (fixes: CVE-2025-31176, CVE-2025-31178, CVE-2025-31179, CVE-2025-31180, CVE-2025-31181).
Dec 4, 2025, 09:22 PM
#401533 sent by Evgeny Sinelnikov
security_release
System Security Services Daemon
Dec. 1, 2025 Evgeny Sinelnikov:
- Backport latest 2.9 LTM release for p10. - Disable Kerberos localauth an2ln plugin for AD/IPA (fixes: CVE-2025-11561).
Dec 3, 2025, 05:35 PM
#401287 sent by Paul Wolneykien
See_changelog
A general-purpose scalable concurrent malloc(3) implementation
Nov. 28, 2025 Paul Wolneykien:
- Added a note about CWE-489 fixed in 5.3.0.
Dec 3, 2025, 05:30 PM
#401692 sent by Alexander Danilov
because_CVE-2022-2787
deleted schroot
Dec. 3, 2025 Alexander Danilov:
- package removed
Dec 3, 2025, 09:57 AM
#401654 sent by Alexey Shabalin
cve-bugfix
The Go Programming Language
Dec. 2, 2025 Alexey Shabalin:
- 1.25.5 (Fixes: CVE-2025-61727, CVE-2025-61729).
Dec 1, 2025, 11:02 PM
#401292 sent by Alexander Danilov
fix_CVE-2025-58767
Provides lexical scanning operations on a String
REXML is an XML toolkit for Ruby
Oct. 13, 2025 Alexander Danilov:
- ^ 3.3.9 -> 3.4.4
Dec 1, 2025, 06:20 PM
#400922 sent by Kernel Bot
v6.12.59
The Linux kernel (the core of the Linux operating system)
Nov. 24, 2025 Kernel Bot:
- v6.12.59 (2025-11-24). - config: Enable CONFIG_MEMCG_V1=y, CONFIG_CPUSETS_V1=y. - input: serio: add an alias to the sersev-serio driver. - sound: hda: enable jack detection in polling mode on Baikal-M. - sound: hda: add driver for HDA controller on Baikal-M. - config-rt: CONFIG_DRM_MGAG200_DISABLE_WRITECOMBINE=y. - config: CONFIG_DRM_MGAG200=m.
LiME module for Linux kernel
Linux Kernel drivers support IPoE for accel-ppp
Anbox kernel modules
Modules for Broadcom IEEE 802.11a/b/g/n adapters
ch341 kernel module
dm-linear with secure deletion on discard
Kernel driver for DRBD
DisplayLink kernel module
Intel(R) 10GbE PCI Express Linux Network Driver
Iptables match for Security Options (IPSO) Labels (kernel module)
Netflow iptables module for Linux kernel
Intel(R) 10GbE PCI Express Linux Network Driver
Linux Kernel Runtime Guard module
nVidia video card drivers
Module for Realtek R8125
Linux driver for RealTek Ethernet controllers
Rockchip rk628_misc Linux driver
Realtek rtl8192eu official Linux driver
Module for Realtek RTL8812au
Module for Realtek RTL8821CE
Realtek RTL8811CU/RTL8821CU USB wifi adapter driver
Module for Realtek RTL88x2bu
Realtek RTL8852AE driver kernel module.
Translate between CISPO and GOST R 58256-2018 (Astra) labels
v4l2-loopback device
VHBA virtual host bus adapter module
VirtualBox modules
VirtualBox modules
xtables-addons kernel module
Driver for Motorcomm YT6801 ethernet adapter
ZFS Linux modules
Dec 1, 2025, 11:47 AM
#401263 sent by Alexander Danilov
fix_CVE-2024-52922
peer-to-peer network based anonymous digital currency
Sept. 23, 2025 Alexei Takaseev:
- Add BR libsqlite3-devel (ALT #56120)
Nov 28, 2025, 10:16 AM
#401143 sent by Alexei Takaseev
New version fix CVE-2025-11411
Validating, recursive, and caching DNS resolver
Nov. 27, 2025 Alexei Takaseev:
- 1.24.2 (Fixes: CVE-2025-11411)
Nov 28, 2025, 01:05 AM
#400476 sent by Alexander Danilov
fix_CVE-2025-53644
Open Source Computer Vision Library
Sept. 28, 2025 Anton Farygin:
- 4.11.0 -> 4.12.0 (Fixes: CVE-2025-53644) - built with gstreamer support (Closes: #56008)
rebuild eviacam-2.1.4-alt1
Mouse replacement software that moves the pointer as you move your head
rebuild frei0r-plugins-1.7.0-alt2
Frei0r - a minimalistic plugin API for video effects
rebuild gmic-2.9.9-alt2
GREYC's Magic Image Converter
rebuild gst-plugins-bad1.0-1.20.7-alt2
A set of GStreamer plugins that need more quality
rebuild kde5-digikam-7.10.0-alt2
digiKam is an advanced digital photo management application for linux
rebuild libopenimageio-2.2.16.0-alt1
Library for reading and writing images
rebuild libopenshot-0.3.3-alt1
OpenShot Video Library
rebuild mlt7-7.14.0-alt1
Multimedia framework designed for television broadcasting
rebuild opentoonz-1.5.0-alt2
2D animation software
rebuild os-autoinst-4.6-alt2.1
OS-level test automation
rebuild shotwell-0.31.3-alt3.1
digital photo organizer designed for the GNOME desktop environment
rebuild simarrange-0.0-alt4.git0f1fbef
STL 2D plate packer with collision simulation
Nov 27, 2025, 06:01 PM
#400903 sent by Alexander Danilov
fix_CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018
A library of functions for manipulating PNG image format files
Nov. 24, 2025 Sergey Bolshakov:
- 1.6.51 (fixes: CVE-2025-64505, CVE-2025-64506, CVE-2025-64720, CVE-2025-65018)
Perl interface to libpng
CRC32C implementation with support for CPU-specific acceleration instructions
Optimizer for PNG (Portable Network Graphics) files
Nov. 8, 2024 Artyom Bystrov:
- Fix build
Nov 27, 2025, 03:25 PM
#400985 sent by Alexander Danilov
fix_CVE-2022-0699
API in "C" for Shapefile handling
rebuild gpsbabel-1.5.4-alt5
A tool to convert between various formats used by GPS devices
rebuild kde5-marble-22.12.3-alt1
A virtual globe and world atlas
Nov 27, 2025, 03:10 PM
#401055 sent by Nazarov Denis
Remove illegal political lines from readme
An open-source formatting library for C++
Nov. 25, 2025 Nazarov Denis:
- Remove illegal political lines from readme
Nov 27, 2025, 01:47 PM
#400872 sent by Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
Nov. 14, 2025 Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-13012 Race condition in the Graphics component + CVE-2025-13016 Incorrect boundary conditions in the JavaScript: WebAssembly component + CVE-2025-13017 Same-origin policy bypass in the DOM: Notifications component + CVE-2025-13018 Mitigation bypass in the DOM: Security component + CVE-2025-13019 Same-origin policy bypass in the DOM: Workers component + CVE-2025-13013 Mitigation bypass in the DOM: Core & HTML component + CVE-2025-13020 Use-after-free in the WebRTC: Audio/Video component + CVE-2025-13014 Use-after-free in the Audio/Video component + CVE-2025-13015 Spoofing issue in Firefox - provides x-www-browser (Closes: #44717).
Nov 27, 2025, 01:35 PM
#401086 sent by Alexander Danilov
fix_CVE-2025-2337,CVE-2025-2338
Library for reading/writing Matlab MAT files
Nov. 26, 2025 Alexander Danilov:
- Version 1.5.29 (Fixes: CVE-2025-2337, CVE-2025-2338).
Nov 27, 2025, 01:20 PM
#401159 sent by Alexander Danilov
because CVE-2022-40149 CVE-2022-40150 CVE-2022-45685 CVE-2022-45693 CVE-2023-1436
deleted jettison
Nov. 27, 2025 Alexander Danilov:
- package removed
Nov 26, 2025, 03:29 PM
#400415 sent by Andrey Cherepanov
CVE_fixes
Microcode definitions for Intel processors
Nov. 13, 2025 Konstantin Lepikhov:
- New upstream microcode datafile 20251111:
+ Update functional issues for Gen12th/13th/14th Core Processors
+ Update functional issues for 4th/5th Xeon Processors
+ Update functional issues for Core Ultra (Series 2)/Ultra 200 V Processors
+ Update functional issues for Core i3 N-Series Processors
+ Update functional issues for Xeon 6500/6700/6900 Processors
+ Update functional issues for Xeon 6700P-B/6500P-B Series SoC with P-Cores
+ Updated microcodes:
sig 0x000806f4, pf_mask 0x87, rev 0x2b000650
sig 0x000806f4, pf_mask 0x10, rev 0x2c000410
sig 0x000806f5, pf_mask 0x87, rev 0x2b000650
sig 0x000806f5, pf_mask 0x10, rev 0x2c000410
sig 0x000806f6, pf_mask 0x87, rev 0x2b000650
sig 0x000806f6, pf_mask 0x10, rev 0x2c000410
sig 0x000806f7, pf_mask 0x87, rev 0x2b000650
sig 0x000806f8, pf_mask 0x87, rev 0x2b000650
sig 0x000806f8, pf_mask 0x10, rev 0x2c000410
sig 0x00090672, pf_mask 0x07, rev 0x003d
sig 0x00090675, pf_mask 0x07, rev 0x003d
sig 0x000906a3, pf_mask 0x80, rev 0x043a
sig 0x000906a4, pf_mask 0x80, rev 0x043a
sig 0x000906a4, pf_mask 0x40, rev 0x000b
sig 0x000a06d1, pf_mask 0x95, rev 0x10003f0
sig 0x000a06d1, pf_mask 0x20, rev 0xa000124
sig 0x000a06f3, pf_mask 0x01, rev 0x3000382
sig 0x000b0650, pf_mask 0x80, rev 0x000a
sig 0x000b0671, pf_mask 0x32, rev 0x0132
sig 0x000b0674, pf_mask 0x32, rev 0x0132
sig 0x000b06a2, pf_mask 0xe0, rev 0x6133
sig 0x000b06a3, pf_mask 0xe0, rev 0x6133
sig 0x000b06a8, pf_mask 0xe0, rev 0x6133
sig 0x000b06d1, pf_mask 0x80, rev 0x0125
sig 0x000b06e0, pf_mask 0x19, rev 0x001e
sig 0x000b06f2, pf_mask 0x07, rev 0x003d
sig 0x000b06f5, pf_mask 0x07, rev 0x003d
sig 0x000b06f6, pf_mask 0x07, rev 0x003d
sig 0x000b06f7, pf_mask 0x07, rev 0x003d
sig 0x000c0652, pf_mask 0x82, rev 0x011a
sig 0x000c0662, pf_mask 0x82, rev 0x011a
sig 0x000c0664, pf_mask 0x82, rev 0x011a
sig 0x000c06a2, pf_mask 0x82, rev 0x011a
sig 0x000c06f1, pf_mask 0x87, rev 0x210002c0
sig 0x000c06f2, pf_mask 0x87, rev 0x210002c0
+ New microcode:
sig 0x000a06e1, pf_mask 0x97, rev 0x1000273Nov 24, 2025, 04:46 PM
#400831 sent by Mikhail Efremov
Fix_CVE-2025-9820
A TLS protocol implementation
Nov. 22, 2025 Mikhail Efremov:
- Patch from gnutls-3.8.11:
+ pkcs11: avoid stack overwrite when initializing a token
(fixes: CVE-2025-9820).Nov 23, 2025, 12:21 AM
#400672 sent by Paul Wolneykien
Replace_the_current_broken_and_unusable_version
Automatically logout users by idle timeouts
Nov. 21, 2025 Paul Wolneykien:
- Rebuild to reflect fixes since the broken version v1.5-alt2.1 (Fixes: OVE-20251121-0001).
Nov 21, 2025, 10:59 PM
#400585 sent by Alexander Stepchenko
Update etcd to version required by kubernetes, fix CVE
A highly-available key value store for shared configuration
Nov. 13, 2025 Alexander Stepchenko:
- 3.5.15 -> 3.5.24 (as required by Kubernetes v1.31.14). - Fixes: + CVE-2024-45337: Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto + CVE-2024-45338: Non-linear parsing of case-insensitive content in golang.org/x/net/html + CVE-2024-51744: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt + CVE-2025-22869: Potential denial of service in golang.org/x/crypto + CVE-2025-22870: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net + CVE-2025-22872: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net + CVE-2025-30204: jwt-go allows excessive memory allocation during header parsing
A highly-available key value store for shared configuration
Nov. 13, 2025 Alexander Stepchenko:
- 3.5.16 -> 3.5.24 (as required by Kubernetes v1.32.10).
Nov 21, 2025, 05:59 PM
#400036 sent by Kernel Bot
v6.12.58
The Linux kernel (the core of the Linux operating system)
Nov. 14, 2025 Kernel Bot:
- v6.12.58 (2025-11-13). - spec: Do not package -domU kernels. - config: CONFIG_SND_SOC_AMD_ACP_COMMON=m. - config: CONFIG_SOUNDWIRE_AMD=m.
LiME module for Linux kernel
Linux Kernel drivers support IPoE for accel-ppp
Anbox kernel modules
Modules for Broadcom IEEE 802.11a/b/g/n adapters
ch341 kernel module
dm-linear with secure deletion on discard
Kernel driver for DRBD
DisplayLink kernel module
Intel(R) 10GbE PCI Express Linux Network Driver
Iptables match for Security Options (IPSO) Labels (kernel module)
Netflow iptables module for Linux kernel
Intel(R) 10GbE PCI Express Linux Network Driver
Linux Kernel Runtime Guard module
nVidia video card drivers
Module for Realtek R8125
Linux driver for RealTek Ethernet controllers
Rockchip rk628_misc Linux driver
Realtek rtl8192eu official Linux driver
Module for Realtek RTL8812au
Module for Realtek RTL8821CE
Realtek RTL8811CU/RTL8821CU USB wifi adapter driver
Module for Realtek RTL88x2bu
Realtek RTL8852AE driver kernel module.
Translate between CISPO and GOST R 58256-2018 (Astra) labels
v4l2-loopback device
VHBA virtual host bus adapter module
VirtualBox modules
VirtualBox modules
xtables-addons kernel module
Driver for Motorcomm YT6801 ethernet adapter
ZFS Linux modules
Nov 21, 2025, 04:39 PM
#400658 sent by Alexander Danilov
fix_CVE-2021-37714
Java library for working with real-world HTML
Oct. 28, 2025 Pavel Vasenkov:
- new version
Nov 21, 2025, 03:42 PM
#400594 sent by Alexander Danilov
fix_CVE-2021-45340
A SIXEL encoder/decoder implementation
Nov. 20, 2025 Alexander Danilov:
- Security fix for CVE-2025-9300.
Nov 21, 2025, 02:42 PM
#400562 sent by Alexander Danilov
fix_CVE-2024-55549,CVE-2025-24855
Library providing XSLT support
Nov. 20, 2025 Alexander Danilov:
- Applied debian patchset (fixes: CVE-2024-55549, CVE-2025-24855).
Nov 21, 2025, 02:35 PM
#396537 sent by Leontiy Volodin
CVE_fix
Prometheus exporter for podman environment
Oct. 6, 2025 Leontiy Volodin:
- New version 1.19.0 (Fixes: CVE-2025-47910, CVE-2025-47906).
Nov 21, 2025, 09:45 AM
#400514 sent by Andrey Cherepanov
Security_fixes
Certificate manager for CryptoPro CSP
Nov. 19, 2025 Andrey Cherepanov:
- New version (fixes: OVE-20251119-0002 Support extra fields for cetificate check dates).
Nov 20, 2025, 05:55 PM
#400363 sent by Alexander Danilov
fix_CVE-2021-42717,CVE-2022-48279,CVE-2023-24021,CVE-2025-47947
Tighten web applications security for Apache 2.x
Nov. 17, 2025 Alexander Danilov:
- Version 2.9.12.
Nov 19, 2025, 06:17 PM
#400040 sent by Alexander Danilov
fix_golang_CVEs
Container cluster management
Container cluster management
Container cluster management
Kubernetes Container Runtime Interface for OCI-based containers
Kubernetes Container Runtime Interface for OCI-based containers
Kubernetes Container Runtime Interface for OCI-based containers
Kubernetes Container Runtime Interface for OCI-based containers
A highly-available key value store for shared configuration
CoreDNS is a DNS server that chains plugins
rebuild cri-tools1.33-1.33.0-alt1
CLI and validation tools for Kubelet Container Runtime Interface (CRI)
A command line tool used to creating OCI Images
Container Signing, Verification and Storage in an OCI registry
Microsoft LAPS alternative for Windows and Linux using Hashicorp Vault/OpenBao/StarVault
Oct. 17, 2025 Alexander Danilov:
- New version to 1.1.
Nov 19, 2025, 05:48 PM
#400412 sent by Alexander Danilov
fix_CVE-2025-11230
HA-Proxy is a TCP/HTTP reverse proxy for high availability environments
Nov. 18, 2025 Alexander Danilov:
- New version 2.6.23 (Fixes: CVE-2025-11230).
Nov 18, 2025, 12:29 PM
#400337 sent by Alexander Danilov
fix_CVE-2025-54812,CVE-2025-54813
A port to C++ of the Log4j project
Nov. 17, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2025-54812_1, CVE-2025-54813).
Nov 17, 2025, 09:23 PM
#400094 sent by Alexander Danilov
fix CVE-2023-52426, CVE-2024-28757, CVE-2024-45490, CVE-2024-45492
An XML parser written in C
Nov. 14, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2023-52426, CVE-2024-28757, CVE-2024-45490, CVE-2024-45492).
Nov 17, 2025, 05:48 PM
#400331 sent by Paul Wolneykien
Display_EOL.txt
ALT distro checksum downloader
Nov. 17, 2025 Paul Wolneykien:
- Notify the users about new security updates (Fixes: OVE-20251117-0001). - Display EOL.txt on validate if it exists.
Nov 17, 2025, 04:10 PM
#399950 sent by Alexander Danilov
fix_CVE-2022-37660
User space daemon for extended IEEE 802.11 management
July 23, 2024 Sergey Bolshakov:
- 2.11 released
Nov 17, 2025, 01:36 PM
#400092 sent by Paul Wolneykien
Updated_expired_GPG_keys
ALT distro checksum downloader
Nov. 14, 2025 Paul Wolneykien:
- Updated expired GPG keys (Fixes: OVE-20251114-0001). - Updated README.
Nov 17, 2025, 11:11 AM
#400105 sent by Alexander Danilov
fixes CVE-2023-1729, CVE-2025-43961, CVE-2025-43962, CVE-2025-43963, CVE-2025-43964
library for reading RAW files obtained from digital photo cameras
Nov. 14, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2023-1729). - Applied debian patchs (fixes: CVE-2025-43961, CVE-2025-43962, CVE-2025-43963, CVE-2025-43964).
Nov 14, 2025, 04:54 PM
#398434 sent by Andrey Cherepanov
New_versions
GPT applier
BaseALT-specific ADMX policy templates
Chromium-specific ADMX policy templates
July 22, 2025 Valentin Sokolov:
- Update to latest release 138.0-7204.158 - Translated Legacy Browser Support policy (closes: 42373)
Firefox-specific ADMX policy templates
ADMX msi file downloader and extractor
May 10, 2024 Evgeny Sinelnikov:
- Update Administrative Templates (.admx) default source URL: Windows 10 October 2020 Update -> Windows 10 2022 Update (22H2).
YandexBrowser-specific ADMX policy templates
Display applied policies
May 6, 2025 Maria Alexeeva:
- Removed libgvdb-gir dependency (automatic dependency lookup works) - Translation files moved to /usr/share/locale/ - Repackaged translations and added bash-completions to pyproject-toml
Common files for Alterator Entry specification
Active Directory domain environment diagnostic tool
Domain Controller Diagnostic Tool
May 31, 2025 Andrey Limachko:
- added the is_nslcd_service_disabled test (thx Sergey Savelev) - added the is_nscd_service_disabled test (thx Sergey Savelev) - added the is_list_trusts_validated test (thx Sergey Savelev) - added the is_dns_lookup_realm_disabled test (thx Sergey Savelev)
ALT Local Policies Default templates
Feb. 29, 2024 Evgeny Sinelnikov:
- Improve oddjob-gpupdate-dbus-timeout control. - Initial support build for debian.
Nov 14, 2025, 04:35 PM
#399906 sent by Alexei Takaseev
New version fix CVE-2025-12817, CVE-2025-12818
PostgreSQL client programs and libraries
PostgreSQL client programs and libraries
PostgreSQL client programs and libraries
PostgreSQL client programs and libraries
PostgreSQL client programs and libraries (edition for 1C 8.3.13 and later)
Nov. 13, 2025 Alexei Takaseev:
- 16.11 (Fixes CVE-2025-12817, CVE-2025-12818) - Fix 1C patch for PG 16.11
Nov 14, 2025, 01:46 PM
#398821 sent by Andrey Cherepanov
CVE_fixes
Timezone data
Timezone data for Java
OpenJDK 21 Runtime Environment
translations for all alterator modules
Nov. 13, 2025 Andrey Cherepanov:
- Backport tzdata translations.
Nov 14, 2025, 01:33 PM
#399631 sent by Anton Midyukov
fix_for_raid_on_nvme
Creates an initramfs image
Nov. 10, 2025 Anton Midyukov:
- OVE-20251110-0001: denial of service for NVME adapters on kernels >= 6.12.45 fix (RAID Intel VROC).
Nov 13, 2025, 05:46 PM
#399160 sent by Alexander Makeenkov
new_version;not_in_distros
Web UI and orchestrator for restic backup
Nov. 2, 2025 Alexander Makeenkov:
- Updated to version 1.10.1.
Nov 13, 2025, 05:42 PM
#399926 sent by Andrey Cherepanov
Request_202012
Ingesting, pipelining, and enhancing your DNS logs with usage indicators, security analysis, and additional metadata
Nov. 13, 2025 Andrey Cherepanov:
- New version.
Nov 13, 2025, 02:55 PM
#399844 sent by Alexander Danilov
fix_CVE-2025-8836,CVE-2025-8837
Implementation of the codec specified in the JPEG-2000 Part-1 standard
Nov. 12, 2025 Alexander Danilov:
- Applied upstream patch (fixes CVE-2025-8836, CVE-2025-8837).
Nov 13, 2025, 01:48 PM
#399854 sent by lesyafox
Request_155299
The DB is used in Trivy to discover information about jars without GAV inside them.
Sept. 4, 2025 Aleksandr Gamzin:
- Remove user from package, trivy-java-db can not work on server side - 20250904-alt1
Nov 13, 2025, 01:37 PM
#399903 sent by Leonid Krivoshein
Updated by the partner request
Link to the AKVIS repository
Nov. 13, 2025 Leonid Krivoshein:
- Change URL of the AKVIS repository to the russian mirror.
Nov 13, 2025, 01:33 PM
#399874 sent by Andrey Cherepanov
Request_204952
Apache Kafka is a distributed event store and stream-processing platform
Nov. 12, 2025 Andrey Cherepanov:
- New version (fixes: CVE-2025-27819, CVE-2025-27818, CVE-2025-27817).
Nov 13, 2025, 01:29 PM
#399847 sent by lesyafox
Request_196813
PAM Module for RADIUS Authentication
Oct. 30, 2025 Alexey Shabalin:
- New version 3.0.0.
Nov 13, 2025, 12:57 PM
#399316 sent by Leonid Krivoshein
as workaround when propagator does not work
bootchain modules set for make-initrd
Aug. 10, 2025 Leonid Krivoshein:
- rebuilt with shellcheck 0.11.0
Nov 12, 2025, 01:25 PM
#398035 sent by Anton Midyukov
CVE-2023-46047
This package contains the SANE docs and utils
Oct. 17, 2025 Vitaly Lipatov:
- new version 1.4.0 (with rpmrb script) (ALT bug 56269)
Nov 12, 2025, 01:06 PM
#399653 sent by Alexander Danilov
fix_CVE-2025-2704
a full-featured SSL VPN solution
Nov. 5, 2025 Nikolay A. Fetisov:
- New version - Fixes: + CVE-2025-2704: possible ASSERT() on OpenVPN servers using --tls-crypt-v2 + Improve server-side handling of clients sending too long usernames/passwords + Bring back configuring of broadcast address on Linux tun/tap interface + Linux DCO: repair source IP selection for --multihome + Correctly handle case of "route installation fails" for an already-existing routes - Fix format of the OpenSSL license exception in License tag
Nov 12, 2025, 12:59 PM
#399688 sent by Andrey Cherepanov
New_versiopn
SQL powered operating system instrumentation, monitoring, and analytics
Nov. 11, 2025 Andrey Cherepanov:
- Backport new version to c10 branch.
Nov 11, 2025, 09:52 PM
#399752 sent by Alexander Danilov
fix_CVE-2025-47286,CVE-2025-49145
IT Operations Portal
Aug. 22, 2025 Pavel Zilke:
- New version 3.2.2 - Security fixes: + CVE-2025-47286 : Remote Code Execution in the backup creation functionality + CVE-2025-49145 : Webhooks: check that callbacks signatures meet the documented expectation
Nov 11, 2025, 06:06 PM
#399683 sent by Alexander Danilov
fix_CVE-2025-2173
Raw VBI, Teletext and Closed Caption decoding library
Oct. 7, 2025 Alexander Danilov:
- Version 0.2.44
Nov 11, 2025, 06:01 PM
#399761 sent by Alexander Danilov
fix_CVE-2025-61919
Modular Ruby webserver interface
Nov. 11, 2025 Alexander Danilov:
- ^ 2.2.19 -> 2.2.21
Nov 11, 2025, 05:56 PM
#399766 sent by Alexander Danilov
fix_CVE-2025-62168
The Squid proxy caching server
Nov. 11, 2025 Alexander Danilov:
- Applied debian patch (fixes: CVE-2025-62168).
Nov 10, 2025, 02:12 PM
#397215 sent by Sergey V Turchin
lost_with_build_377694
NVIDIA drivers and OpenGL libraries for XOrg X-server
April 3, 2025 Sergey V Turchin:
- new version
Nov 10, 2025, 11:20 AM
#399186 sent by Vitaly Chikunov
kernel-6.12
BPF Compiler Collection (BCC)
Nov. 8, 2025 Vitaly Chikunov:
- Backport to c10f2 (linux 6.12, but older toolchain).
Nov 8, 2025, 11:44 PM
#399366 sent by Alexander Danilov
CVE-2024-25081 CVE-2024-25082
FontForge -- font editor
Oct. 28, 2025 Vitaly Lipatov:
- new version 20251009 (with rpmrb script)
Nov 7, 2025, 04:14 PM
#398182 sent by Alexander Danilov
fix_CVE-2024-45492
An XML parser written in C
Oct. 24, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2024-45491).
Nov 7, 2025, 04:07 PM
#398538 sent by Alexander Danilov
fix_CVE-2025-6021
The library for manipulating XML files
Oct. 28, 2025 Alexander Danilov:
- Applied security fixes from upstream (Fixes: CVE-2025-6021).
Nov 7, 2025, 03:58 PM
#398668 sent by Andrew Guschin
for_altsp
Rockchip rk628_misc Linux driver
Rockchip rk628_misc Linux driver
Nov. 6, 2025 Andrew Guschin:
- Build for kernel-image-6.12-6.12.56-alt0.c10f.2.
Nov 7, 2025, 01:15 PM
#399321 sent by Andrey Cherepanov
CVE_fixes
Intrusion Detection System
Nov. 6, 2025 Andrey Cherepanov:
- 8.0.2 (Fixed: CVE-2025-64344, CVE-2025-64333, CVE-2025-64332, CVE-2025-64331, CVE-2025-64330, CVE-2025-64335, CVE-2025-64334)
Nov 7, 2025, 09:15 AM
#399311 sent by Alexander Stepchenko
BUSL-1.1 is not an open source license
deleted packer
Nov. 7, 2025 Alexander Stepchenko:
- package removed
Nov 6, 2025, 05:56 PM
#398831 sent by Andrey Cherepanov
CVE_fixes
OpenJDK Runtime Environment 8
Additional Java components for OpenJDK - Java Web Start implementation
Nov 6, 2025, 05:41 PM
#398807 sent by Andrey Cherepanov
Request_204332
GitLab Runner is the open source project that is used to run your CI/CD jobs and send the results back to GitLab
Oct. 20, 2025 Andrew A. Vasilyev:
- New version 18.5.0
Nov 6, 2025, 04:14 PM
#385610 sent by Alexey Kostarev
toC10F
Set of scripts for Podman Security
Oct. 31, 2025 Alexey Kostarev:
- Tuned podsec-k8s-save-oci, podsec-save-oci scripts. - Added 0/27/3/kube-flannel.yml manifest. - Resolved CVE-2025-4563, CVE-2025-4563 in kubernetes version 1.33
Nov 6, 2025, 03:50 PM
#398827 sent by Andrey Cherepanov
CVE_fixes
OpenJDK 17 Runtime Environment
Oct. 31, 2025 Andrey Cherepanov:
- New version (fixes: CVE-2025-53057, CVE-2025-53066).
Nov 6, 2025, 03:37 PM
#399241 sent by Alexander Danilov
fix_CVE-2014-3539
python refactoring library
Nov. 5, 2025 Alexander Danilov:
- Applied debian patch (fixes: CVE-2014-3539).
Nov 6, 2025, 03:04 PM
#398801 sent by Andrey Cherepanov
CVE_fixes
OpenJDK Runtime Environment 11
Oct. 31, 2025 Andrey Cherepanov:
- Backport new version with security fix to c10 branch.
Nov 6, 2025, 01:14 PM
#398770 sent by Alexei Takaseev
New version fix CVE-2025-49641
A network monitor
Provides native Zabbix solution for monitoring MongoDB
Provides native Zabbix solution for monitoring MS-SQL
Provides native Zabbix solution for monitoring PostgreSQL
Oct. 30, 2025 Alexei Takaseev:
- 7.0.20
Nov 6, 2025, 12:51 PM
#398694 sent by Kernel Bot
v6.12.56
The Linux kernel (the core of the Linux operating system)
LiME module for Linux kernel
Linux Kernel drivers support IPoE for accel-ppp
Anbox kernel modules
Modules for Broadcom IEEE 802.11a/b/g/n adapters
ch341 kernel module
dm-linear with secure deletion on discard
Kernel driver for DRBD
DisplayLink kernel module
Intel(R) 10GbE PCI Express Linux Network Driver
Iptables match for Security Options (IPSO) Labels (kernel module)
Netflow iptables module for Linux kernel
Intel(R) 10GbE PCI Express Linux Network Driver
Linux Kernel Runtime Guard module
nVidia video card drivers
Module for Realtek R8125
Linux driver for RealTek Ethernet controllers
Realtek rtl8192eu official Linux driver
Module for Realtek RTL8812au
Module for Realtek RTL8821CE
Realtek RTL8811CU/RTL8821CU USB wifi adapter driver
Module for Realtek RTL88x2bu
Realtek RTL8852AE driver kernel module.
Translate between CISPO and GOST R 58256-2018 (Astra) labels
v4l2-loopback device
VHBA virtual host bus adapter module
VirtualBox modules
VirtualBox modules
xtables-addons kernel module
Driver for Motorcomm YT6801 ethernet adapter
ZFS Linux modules
Nov 6, 2025, 11:36 AM
#397937 sent by Andrey Cherepanov
Request_200020
Ultracopier acts as a replacement for files copy dialogs
Oct. 9, 2025 Andrey Cherepanov:
- Initial build for Sisyphus.
Nov 6, 2025, 11:32 AM
#398659 sent by Alexander Danilov
fix_CVE-2025-53859
A graphics library for drawing image files in various formats
Fast HTTP server
Oct. 28, 2025 Anton Farygin:
- Applied upstream patch to fix memory over-read in ngx_mail_smtp_module during SMTP auth (Fixes: CVE-2025-53859)
Nov 6, 2025, 11:15 AM
#398179 sent by Andrey Cherepanov
Request_202573
Export smartctl statistics to prometheus
Nov. 5, 2025 Andrey Cherepanov:
- Remove PrivateDevices=true from service file (ALT #56728).
Nov 5, 2025, 06:02 PM
#398189 sent by Andrey Cherepanov
New_package
Utilities for managing the global file system (GFS2)
Aug. 2, 2024 Andrey Cherepanov:
- Backport to p10 branch.
Nov 5, 2025, 05:56 PM
#398639 sent by Alexei Takaseev
new versio clamav fix CVE-2025-20260 and remove unsupported havp
Clam Antivirus scanner
Oct. 30, 2025 Alexei Takaseev:
- 1.0.9 (Fixes CVE-2025-20260) - Add vendoring for rust - Update patches - Change soname 9 -> 11 - Use cmake for build - Use PrivateMirror's by default - Set Conflicts and Obsolete to "< %version-%release" (ALT #56685)
rebuild c-icap-modules-0.5.4-alt1
ICAP server modules
deleted havp
Nov. 5, 2025 Alexei Takaseev:
- package removed
Nov 5, 2025, 05:43 PM
#398839 sent by Alexander Danilov
fix_CVE-2023-52160
wpa_supplicant is an implementation of the WPA Supplicant component
June 30, 2025 Sergey Bolshakov:
- limit CTRL-EVENT-SIGNAL-CHANGE log messages (closes: 54973)
Nov 1, 2025, 03:02 PM
#398734 sent by Alexander Danilov
fix_CVE-2025-5473,CVE-2025-2761,CVE-2025-2760
The GNU Image Manipulation Program
Oct. 30, 2025 Alexander Danilov:
- upstream: plug-ins: ZDI-CAN-26752 mitigation (fixes: CVE-2025-5473) - upstream: plug-ins: Fix ZDI-CAN-25100 for FLI plug-in (fixes: CVE-2025-2761) - upstream: plug-ins/dds: fix #12790 for 32-bit (fixes: CVE-2025-2760) - upstream: plug-ins: Integer Overflow or Wraparound in Despeckle (fixes: CVE-2025-6035)
Nov 1, 2025, 11:04 AM
#398428 sent by Daniil-Viktor Ratkin
update
C++11 library codec for base64, base64url, base32, base32hex and hex
Library for CryptoPro PDF electronic signatures support.
Oct. 13, 2025 Oleg Proskurin:
- New features: + Add machine-readable power of attorney (MRPA) support. + ZIP archives supports. + Attached and detached signature files support.
Verification and creation of digitally signed pdf documents.
Oct. 29, 2025 Daniil-Viktor Ratkin:
Oct 31, 2025, 09:59 PM
#398448 sent by Alexander Danilov
fix_CVE-2022-4132
Java Security Services (JSS)
Oct. 27, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2022-4132).
Oct 31, 2025, 06:06 PM
#398855 sent by Alexander Danilov
because_CVE-2013-2018
deleted boinc
Oct. 31, 2025 Alexander Danilov:
- package removed
Oct 31, 2025, 02:54 PM
#398709 sent by Anton Midyukov
CVE-2025-62229,CVE-2025-62230,CVE-2025-62231
Xserver - X Window System display server
Oct. 29, 2025 Valery Inozemtsev:
- cherry pick upstream fixes for CVE-2025-62229, CVE-2025-62230, CVE-2025-62231
Wayland X server
Oct. 29, 2025 Valery Inozemtsev:
- cherry pick upstream fixes for CVE-2025-62229, CVE-2025-62230, CVE-2025-62231
Oct 31, 2025, 02:45 PM
#398575 sent by Vitaly Lipatov
CVE fix
.NET 8 SDK binaries
Oct. 24, 2025 Vitaly Lipatov:
- The .NET 8.0.21 and .NET SDK 8.0.121 release - update sources' URLs - fixed CVEs: + CVE-2025-55248: .NET Information Disclosure Vulnerability + CVE-2025-55315: .NET Security Feature Bypass Vulnerability + CVE-2025-55247: .NET Denial of Service Vulnerability + CVE-2025-26646: .NET and Visual Studio Spoofing Vulnerability + CVE-2025-26682: .NET Denial of Service Vulnerability + CVE-2025-24070: .NET Elevation of Privilege Vulnerability
Microsoft .NET Runtime and Microsoft.NETCore.App
Oct. 24, 2025 Vitaly Lipatov:
- .NET 8.0.21 release - fixed CVEs: + CVE-2025-55248: .NET Information Disclosure Vulnerability
SDK for the .NET 8
Oct. 28, 2025 Vitaly Lipatov:
- .NET SDK 8.0.121 release - fixed CVEs: + CVE-2025-26646: .NET and Visual Studio Spoofing Vulnerability + CVE-2025-30399: .NET Remote Code Execution Vulnerability
ASP.NET is a cross-platform .NET framework for building modern cloud-based web application
Oct. 28, 2025 Vitaly Lipatov:
- ASP.NET 8.0.21 release - fixed CVEs: + CVE-2025-24070: .NET Elevation of Privilege Vulnerability + CVE-2025-26682: .NET Denial of Service Vulnerability + CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Oct 31, 2025, 02:30 PM
#398504 sent by Alexander Danilov
fix_CVE-2025-2588
A library for changing configuration files
May 28, 2025 Anton Farygin:
- added commit af2aa88ab with null pointer dereference fix (Fixes CVE-2025-2588)
Oct 30, 2025, 11:20 AM
#398149 sent by Pavel Vasenkov
New_version_with_CVE
The Mozilla Firefox project is a redesign of Mozilla's browser
Oct. 15, 2025 Pavel Vasenkov:
- New ESR version. - Security fixes: + CVE-2025-11708 Use-after-free in MediaTrackGraphImpl::GetInstance() + CVE-2025-11709 Out of bounds read/write in a privileged process triggered by WebGL textures + CVE-2025-11710 Cross-process information leaked due to malicious IPC messages + CVE-2025-11711 Some non-writable Object properties could be modified + CVE-2025-11712 An OBJECT tag type attribute overrode browser behavior on web resources without a content-type + CVE-2025-11713 Potential user-assisted code execution in 'Copy as cURL' command + CVE-2025-11714 Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 + CVE-2025-11715 Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Oct 29, 2025, 12:21 PM
#398451 sent by Alexander Danilov
fix_CVE-2025-11626
The BugTraq Award Winning Network Traffic Analyzer
Oct. 23, 2025 Anton Farygin:
- 4.4.10 (Fixes: CVE-2025-11626)
Oct 28, 2025, 11:06 PM
#398072 sent by Stanislav Levin
cve_fixes
rebuild bind-dyndb-ldap-11.11-alt1
LDAP back-end plug-in for BIND
Oct 28, 2025, 06:11 PM
#398107 sent by Alexander Danilov
fix_CVE-2023-51764
Postfix Mail Transport Agent
May 1, 2024 Gleb Fotengauer-Malinovskiy:
- Updated to 3.8.6 (ALT#49734) (fixes CVE-2023-51764). - Fixed the pluginization patch to remove (harmless) warnings related to loading of unimplemented mkmap_ plugins (ALT#48908).
Oct 28, 2025, 05:08 PM
#398077 sent by Alexander Danilov
fix_CVE-2025-48174,CVE-2025-48175
Implementation of the AV1 Image File Format
Oct. 23, 2025 Alexander Danilov:
- Applied debian patch (fixes: CVE-2025-48174,CVE-2025-48175).
Oct 28, 2025, 05:03 PM
#398438 sent by Alexander Danilov
fix_CVE-2025-26625
Git extension for versioning large files
Oct. 24, 2025 Artem Krasovskiy:
- Updated to 3.7.1 (fixes CVE-2025-26625).
Oct 27, 2025, 01:16 PM
#397869 sent by Alexander Danilov
fix_CVE-2024-56171,CVE-2025-32415,CVE-2025-24928
The library for manipulating XML files
Oct. 21, 2025 Alexander Danilov:
- Applied security fixes from upstream (Fixes: CVE-2024-56171, CVE-2025-32415, CVE-2025-24928).
Oct 24, 2025, 05:59 PM
#398101 sent by Alexander Danilov
fix_CVE-2022-43550
Multiprotocol (SIP, XMPP/Jabber, ecc.) VoIP and instant messaging software
Oct. 23, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2022-43550).
Oct 24, 2025, 04:53 PM
#398007 sent by Alexey Appolonov
Bugfixes for a stable version https://github.com/OpenSCAP/openscap/releases
Set of open source libraries enabling integration of the SCAP line of standards
Oct. 16, 2025 Alexey Appolonov:
- New version.
Oct 24, 2025, 10:49 AM
#397812 sent by Denis Medvedev
recurrent_update
Database for Trivy
Sept. 4, 2025 Aleksandr Gamzin:
- fix: change user home directory name in sharestatedir to trivy - 20250904-alt1
Oct 24, 2025, 10:45 AM
#397446 sent by Alexei Takaseev
Backport from Sisyphus for issue #201550
TDS Foreign data wrapper
TDS Foreign data wrapper
TDS Foreign data wrapper
TDS Foreign data wrapper
Sept. 18, 2025 Alexei Takaseev:
- 2.0.5 - Add lost %install section
Oct 24, 2025, 10:35 AM
#398087 sent by Alexei Takaseev
Fix CVE-2025-11411
Validating, recursive, and caching DNS resolver
Oct. 23, 2025 Alexei Takaseev:
- 1.24.1 (Fixes: CVE-2025-11411)
Oct 23, 2025, 04:48 PM
#397974 sent by Alexander Danilov
fix_CVE-2025-59362
The Squid proxy caching server
Oct. 22, 2025 Alexander Danilov:
- Applied upstream patch (fixes: CVE-2025-59362).
Oct 23, 2025, 10:22 AM
#396593 sent by Alexander Stepchenko
PVE bug fixes
PVE base library
Oct. 10, 2025 Alexander Stepchenko:
- Infer vlan_raw_device from interface name of form id.VID (ALT #44032). - Fix "VLAN aware" flag in web client not setting VIDS in etcnet options. - Fixes: + OVE-20251008-0001: Failure to set vlan raw device for vlan interfaces + OVE-20251008-0002: Failure to set vlan ids on bridge in vlan aware mode
/etc/net network configuration system
Oct. 9, 2025 Alexander Stepchenko:
- Include brivlanport in the list of known interface groups - Fixes: + OVE-20251010-0001: Failure to configure brivlanport interface type
Oct 22, 2025, 03:07 PM
#397904 sent by Alexander Danilov
fix_CVE-2025-4478
Remote Desktop Protocol functionality
Sept. 14, 2025 Michael Shigorin:
- E2K: drop chrpath as unneeded
Oct 22, 2025, 12:33 PM
#397242 sent by Gleb Fotengauer-Malinovskiy
Add openssl3 package.
OpenSSL - Secure Sockets Layer and cryptography shared libraries and tools
Oct. 16, 2025 Gleb Fotengauer-Malinovskiy:
- Backported to c10f2 branch (new standalone package).
Oct 22, 2025, 11:06 AM
#397844 sent by Alexander Danilov
fix_CVE-2025-6297
Package maintenance system for Debian Linux
Oct. 20, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2025-6297).
Oct 21, 2025, 06:16 PM
#397090 sent by Alexei Takaseev
Add deploy for PostgreSQL 16-1C
deploy script for postgresql cert config
Oct. 17, 2025 Alexei Takaseev:
- Add lost postgresql16-1C-contrib for deploy
Oct 21, 2025, 06:12 PM
#397799 sent by Alexei Takaseev
Build for postgresql16-1C and fix OVE-20251020-0001, OVE-20251020-0002, OVE-20251020-0003
Replication Manager for PostgreSQL Clusters
Oct. 14, 2025 Alexei Takaseev:
- No build for older unsupported and vulnerable versions PostgreSQL (Fixes: OVE-20251020-0002)
- Build for postgresql16-1C (Fixes: OVE-20251020-0003):
* resolving dependencies on postgresql packages postgresql-1C-deploy-cert
- Fix service name (Fixes: OVE-20251020-0001):
* Error 'Unit file does not exist' when installing/updating a package (ALT #53502)Replication Manager for PostgreSQL Clusters
Oct. 14, 2025 Alexei Takaseev:
- No build for older unsupported and vulnerable versions PostgreSQL (Fixes: OVE-20251020-0002)
- Build for postgresql16-1C (Fixes: OVE-20251020-0003):
* resolving dependencies on postgresql packages postgresql-1C-deploy-cert
- Fix service name (Fixes: OVE-20251020-0001):
* Error 'Unit file does not exist' when installing/updating a package (ALT #53502)Replication Manager for PostgreSQL Clusters
Oct. 14, 2025 Alexei Takaseev:
- No build for older unsupported and vulnerable versions PostgreSQL (Fixes: OVE-20251020-0002)
- Build for postgresql16-1C (Fixes: OVE-20251020-0003):
* resolving dependencies on postgresql packages postgresql-1C-deploy-cert
- Fix service name (Fixes: OVE-20251020-0001):
* Error 'Unit file does not exist' when installing/updating a package (ALT #53502)Replication Manager for PostgreSQL Clusters
Oct. 14, 2025 Alexei Takaseev:
- No build for older unsupported and vulnerable versions PostgreSQL (Fixes: OVE-20251020-0002)
- Build for postgresql16-1C (Fixes: OVE-20251020-0003):
* resolving dependencies on postgresql packages postgresql-1C-deploy-cert
- Fix service name (Fixes: OVE-20251020-0001):
* Error 'Unit file does not exist' when installing/updating a package (ALT #53502)Replication Manager for PostgreSQL Clusters
Oct. 14, 2025 Alexei Takaseev:
- No build for older unsupported and vulnerable versions PostgreSQL (Fixes: OVE-20251020-0002)
- Build for postgresql16-1C (Fixes: OVE-20251020-0003):
* resolving dependencies on postgresql packages postgresql-1C-deploy-cert
- Fix service name (Fixes: OVE-20251020-0001):
* Error 'Unit file does not exist' when installing/updating a package (ALT #53502)Oct 21, 2025, 03:53 PM
#397140 sent by Alexei Takaseev
Rebuild Postgresql 16-1C
PostgreSQL client programs and libraries (edition for 1C 8.3.13 and later)
Oct. 14, 2025 Alexei Takaseev:
- Add coverage support
- Fixed run regressions tests (Fixes: OVE-20251020-0004):
* Add run test regressions (64-bit arch only)
* Add 00002-1C-Fix-test-join.patch and 00003-1C-Fix-test-sysviews.patch
- Fixed checking checksums on a schedule and at each start (Fixes: OVE-20251020-0005):
* Add Requires to pg_checksums
* Add postgresql-check-db
- Setting a mandatory password during cluster initialization (Fixes: OVE-20251020-0006)Oct 21, 2025, 03:42 PM
#397796 sent by Alexander Danilov
fix_CVE-2025-48924
Provides a host of helper utilities for the java.lang API
Oct. 20, 2025 Alexander Danilov:
- new version
Oct 20, 2025, 06:31 PM
#395540 sent by Sergey Gvozdetskiy
Fix_CVE-2020-13956_CVE-2021-37533
HTTP agent implementation based on httpcomponents HttpCore
Internet protocol suite Java library
Sept. 23, 2025 Sergey Gvozdetskiy:
- security fix: + CVE-2021-37533: FTP client trusts the host from PASV
Oct 20, 2025, 06:26 PM
#397104 sent by Alexander Stepchenko
Fix CVE
A highly-available key value store for shared configuration
Oct. 14, 2025 Alexander Stepchenko:
- 3.5.16 -> 3.5.23 - Fixes: + CVE-2024-45337: Misuse of connection.serverAuthenticate may cause authorization bypass in golang.org/x/crypto + CVE-2024-45338: Non-linear parsing of case-insensitive content in golang.org/x/net/html + CVE-2024-51744: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt + CVE-2025-22869: Potential denial of service in golang.org/x/crypto + CVE-2025-22870: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net + CVE-2025-22872: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net + CVE-2025-30204: jwt-go allows excessive memory allocation during header parsing
Oct 20, 2025, 02:16 PM
#397208 sent by Vitaly Lipatov
CVEs fixes
.NET 9 SDK binaries
Oct. 15, 2025 Vitaly Lipatov:
- The .NET 9.0.10 and .NET SDK 9.0.111 release - fixed CVEs: + CVE-2025-24070: .NET Elevation of Privilege Vulnerability + CVE-2025-26682: .NET Denial of Service Vulnerability + CVE-2025-26646: .NET and Visual Studio Spoofing Vulnerability + CVE-2025-30399: .NET Remote Code Execution Vulnerability + CVE-2025-55248: .NET Information Disclosure Vulnerability + CVE-2025-55315: .NET Security Feature Bypass Vulnerability + CVE-2025-55247: .NET Denial of Service Vulnerability
Microsoft .NET 9 Runtime and Microsoft.NETCore.App
Oct. 15, 2025 Vitaly Lipatov:
- .NET 9.0.10 - fixed CVEs: + CVE-2025-55248: .NET Information Disclosure Vulnerability
SDK for the .NET 9
Oct. 15, 2025 Vitaly Lipatov:
- .NET SDK 9.0.111 release - fixed CVEs: + CVE-2025-26646: .NET and Visual Studio Spoofing Vulnerability + CVE-2025-30399: .NET Remote Code Execution Vulnerability + CVE-2025-55247: .NET Denial of Service Vulnerability
ASP.NET is a cross-platform .NET framework for building modern cloud-based web application
Oct. 15, 2025 Vitaly Lipatov:
- ASP.NET 9.0.10 release - fixed CVEs: + CVE-2025-24070: .NET Elevation of Privilege Vulnerability + CVE-2025-26682: .NET Denial of Service Vulnerability + CVE-2025-55315: .NET Security Feature Bypass Vulnerability
Oct 20, 2025, 10:23 AM
#396140 sent by Vitaly Lipatov
new version
Wine - environment for running Windows applications
Work around common problems in Wine
April 28, 2025 Vitaly Lipatov:
- vcrun2019: Install correct version of msvcp140.dll into 64bit - ie8: removed dll that cannot be registered - redo opensymbol download, remove w_try_ar function
Windows build of Mono to run .NET applications via Wine
Custom version of Mozilla's Gecko Layout Engine for Wine
July 29, 2023 Vitaly Lipatov:
- new version 2.47.4 (with rpmrb script)
Oct 17, 2025, 10:03 AM
#397209 sent by Alexander Danilov
fix_CVE-2025-61770,CVE-2025-61771,CVE-2025-61772
Modular Ruby webserver interface
Oct. 15, 2025 Alexander Danilov:
- ^ 2.2.6.3 -> 2.2.19
Oct 16, 2025, 06:42 PM
#397006 sent by Alexander Danilov
fix_CVE-2025-31115
LZMA/XZ compression programs
June 11, 2025 Arseny Maslennikov:
- 5.4.5 -> 5.4.7. - Apply patches by Lasse Collin to fix CVE-2025-31115.
Oct 16, 2025, 06:32 PM
#396735 sent by Alexander Danilov
fix_CVE-2025-9566
Manage pods, containers, and container images
Oct. 10, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2025-9566).
Oct 16, 2025, 06:15 PM
#397081 sent by Kirill Izmestev
Fix_CVE-2025-4790,CVE-2025-47907,CVE-2025-22871
Git with a cup of tea, painless self-hosted git service
Act runner is a runner for Gitea based on Gitea fork of act.
The Go language server
July 3, 2024 Anton Zhukharev:
- Fixed gopls version detection.
Oct 16, 2025, 05:23 PM
#396560 sent by Kernel Bot
v6.12.51
The Linux kernel (the core of the Linux operating system)
LiME module for Linux kernel
Linux Kernel drivers support IPoE for accel-ppp
Anbox kernel modules
Modules for Broadcom IEEE 802.11a/b/g/n adapters
ch341 kernel module
dm-linear with secure deletion on discard
Kernel driver for DRBD
DisplayLink kernel module
Intel(R) 10GbE PCI Express Linux Network Driver
Iptables match for Security Options (IPSO) Labels (kernel module)
Netflow iptables module for Linux kernel
Intel(R) 10GbE PCI Express Linux Network Driver
Linux Kernel Runtime Guard module
nVidia video card drivers
Module for Realtek R8125
Linux driver for RealTek Ethernet controllers
Realtek rtl8192eu official Linux driver
Module for Realtek RTL8812au
Module for Realtek RTL8821CE
Realtek RTL8811CU/RTL8821CU USB wifi adapter driver
Module for Realtek RTL88x2bu
Realtek RTL8852AE driver kernel module.
Translate between CISPO and GOST R 58256-2018 (Astra) labels
v4l2-loopback device
VHBA virtual host bus adapter module
VirtualBox modules
VirtualBox modules
xtables-addons kernel module
Driver for Motorcomm YT6801 ethernet adapter
ZFS Linux modules
Oct 16, 2025, 11:12 AM
#396319 sent by Alexander Danilov
fix_CVE-2025-9714
The library for manipulating XML files
Oct. 3, 2025 Alexander Danilov:
- Applied security fixes from upstream (Fixes: CVE-2025-9714).
Oct 16, 2025, 10:59 AM
#396879 sent by Constantin Sunzow
Security update
Library of functions for manipulating TIFF format image files
Oct. 11, 2025 Constantin Sunzow:
- Fixes: + CVE-2025-9900 Write-what-where condition
Oct 16, 2025, 04:12 AM
#396330 sent by Alexander Danilov
fix_CVEs
The GNU Scientific Library for numerical analysis
Sept. 13, 2025 Anton Farygin:
- applied patch from Debian to fix integer overflow in gsl_siman_solve_many (Fixes: CVE-2024-50610)
rebuild ThePEG-1.5.0-alt3.3
Toolkit for High Energy Physics Event Generation.
rebuild calligra-3.2.1-alt5
An integrated office suite
rebuild enblend-4.2-alt5
A tool for combine images (make a panoramas) using a multiresolution spline
rebuild gambas-3.18.4-alt1
IDE based on a basic interpreter with object extensions
rebuild getdp-3.3.0-alt4
A General Environment for the Treatment of Discrete Problems
rebuild gnuradio-3.9.1.0-alt1
Software defined radio framework
rebuild guvcview-2.0.7-alt1
A GTK UVC video viewer
rebuild igt-gpu-tools-1.26-alt2
tools for debugging the Intel graphics driver
rebuild indilib-1.8.9-alt1
Library to control astronomical devices
rebuild kde5-step-22.12.3-alt1
Interactive physical simulator
rebuild krita-5.1.5-alt3
A creative sketching and painting application
rebuild labplot-2.9.0-alt1
Function and Data Plotter
rebuild lib2geom-1.2.2-alt1
Easy to use 2D geometry library in C++
rebuild nip2-8.7.1-alt1
An image processing system
rebuild octave-gsl-2.1.1-alt3
GNU Scientific Library
rebuild perl-PDL-2.052-alt1
The Perl Data Language
rebuild pspp-2.0.1-alt1
A program for statistical analysis of sampled data.
rebuild qgis3-3.20.3-alt3
A user friendly Open Source Geographic Information System
rebuild tamu_anova-0.2-alt3.qa1
ANOVA Extensions to the GNU Scientific Library
rebuild xaos-3.6-alt3
A real-time fractal zoomer
rebuild inkscape-1.2.2-alt2
A Vector Drawing Application
deleted python3-module-pygsl
Fast anti-spam filtering by Bayesian statistical analysis
April 2, 2023 Alexey Gladkov:
- Split package by database backends (Berkeley DB and SQLite). - Put all utilites in the single package. - Add alternative for utilities to be able to install them in parallel. - Make bf_tar use tar instead of pax. - Move contrib to _datadir. - Move docs in to separate package. - Fix License tag.
A parser for Coffeescript Object Notation (CSON)
Descriptive vector graphics language
A PEG-based parser interpreter with memoization (in time)
March 17, 2024 Vitaly Lipatov:
- new version (0.3) with rpmgs script
Oct 15, 2025, 04:03 PM
#396577 sent by Stanislav Levin
fix_CVE-2025-7493
389 Directory Server (base)
The Identity, Policy and Audit system
Oct. 6, 2025 Stanislav Levin:
- Backported upstream fixes (fixes: CVE-2025-7493).
Oct 15, 2025, 03:26 PM
#396884 sent by Andrey Cherepanov
CVE_fixes
Open Source Identity and Access Management For Modern Applications and Services
Oct. 1, 2025 Andrey Cherepanov:
- New version (fixes: CVE-2025-48924, CVE-2025-7962).
Oct 15, 2025, 11:11 AM
#396643 sent by Alexander Danilov
fix_CVE-2025-5244,CVE-2025-5245
GNU Binary Utility Development Utilities
Oct. 8, 2025 Alexander Danilov:
- Applied upstream patchs (fixes: CVE-2025-5244, CVE-2025-5245).
Oct 14, 2025, 09:53 PM
#396684 sent by Alexander Danilov
fix_CVE-2024-9287
Version 3 of the Python programming language aka Python 3000
Oct. 9, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2024-9287).
Oct 14, 2025, 04:23 PM
#396637 sent by Kernel Bot
migration to 6.12
deleted kernel-image-un-def
deleted kernel-modules-LiME-un-def
deleted kernel-modules-accel-ppp-un-def
deleted kernel-modules-bcmwl-un-def
deleted kernel-modules-dm-secdel-un-def
deleted kernel-modules-drbd9-un-def
deleted kernel-modules-i40e-un-def
deleted kernel-modules-ipt-so-un-def
deleted kernel-modules-ixgbe-un-def
deleted kernel-modules-kvdo-un-def
deleted kernel-modules-lin-tape-un-def
deleted kernel-modules-lkrg-un-def
deleted kernel-modules-mpi3mr-un-def
deleted kernel-modules-nvidia-un-def
deleted kernel-modules-r8125-un-def
deleted kernel-modules-r8168-un-def
deleted kernel-modules-rtl8188eu-un-def
deleted kernel-modules-rtl8188fu-un-def
deleted kernel-modules-rtl8192eu-un-def
deleted kernel-modules-rtl8723du-un-def
deleted kernel-modules-rtl8812au-un-def
deleted kernel-modules-rtl8821ce-un-def
deleted kernel-modules-rtl8821cu-un-def
deleted kernel-modules-rtl88x2bu-un-def
deleted kernel-modules-rtw89-un-def
deleted kernel-modules-tripso-un-def
deleted kernel-modules-vhba-un-def
deleted kernel-modules-virtualbox-un-def
deleted kernel-modules-zfs-un-def
Dynamic Kernel Module Support Framework
Dec. 5, 2024 Vitaly Chikunov:
- Fix filetrigger (postinst) invocation. - spec: Add filetrigger test in checkinstall.
deleted bcc
deleted bpftrace
deleted kernel-source-hinic
deleted spdk
Oct. 14, 2025 Kernel Bot:
- package removed
Oct 14, 2025, 01:33 PM
#396993 sent by Alexander Danilov
fix_CVE-2024-57822,CVE-2024-57823
RDF Parser Toolkit for Redland
Oct. 7, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2024-57822, CVE-2024-57823).
Oct 14, 2025, 12:05 PM
#392875 sent by Sergey Gvozdetskiy
Fix_CVE-2021-46877
General data-binding package for Jackson (2.x)
Oct. 10, 2025 Sergey Gvozdetskiy:
- security fix: + CVE-2021-46877: denial of service
Oct 13, 2025, 05:55 PM
#396991 sent by Alexander Danilov
fix_CVE-2025-49844
Redis is an advanced key-value store
Oct. 7, 2025 Alexander Danilov:
- 7.2.11 (Fixes: CVE-2025-49844, CVE-2025-46817, CVE-2025-46818, CVE-2025-46819).
Oct 9, 2025, 12:50 PM
#395620 sent by Alexander Danilov
fix_CVE-2025-58060,CVE-2025-58364
Common Unix Printing System - server package
Sept. 12, 2025 Anton Farygin:
- 2.4.13 -> 2.4.14
Oct 9, 2025, 10:09 AM
#396642 sent by Anton Farygin
remove orphaned package
deleted goldendict
deleted task-edu
Oct. 9, 2025 Anton Farygin:
- package removed
Oct 9, 2025, 05:00 AM
#395055 sent by Alexander Danilov
fix_CVE-2023-6349
rebuild qt6-webengine-6.4.2-alt3
Qt6 - QtWebEngine components
rebuild avidemux-qt-2.8.1-alt3
Avidemux is a graphical AVI files editor
rebuild baresip-0.6.5-alt1
Baresip is a portable and modular SIP User-Agent with audio and video support
rebuild drawpile-2.1.20-alt1
A collaborative drawing program
rebuild ffmpeg-4.4.5-alt2
A command line toolbox to manipulate, convert and stream multimedia content
rebuild firefox-141.0.3-alt0.c10f2.1
The Mozilla Firefox project is a redesign of Mozilla's browser
rebuild firefox-esr-140.2.0-alt0.c10.1
The Mozilla Firefox project is a redesign of Mozilla's browser
rebuild gst-plugins-good1.0-1.20.7-alt1
A set of GStreamer plugins considered good
rebuild gzdoom-4.9.0-alt1
Enhanced Doom engine
rebuild handbrake-1.4.2-alt0.p10.1
Multithreaded Video Transcoder
rebuild jami-20230922-alt4
SIP and IAX2 compatible softphone
rebuild libowt-tg-4.3.0.5-alt3
Open WebRTC Toolkit with Telegram desktop patches
rebuild libxine2-1.2.9-alt3
Free libraries for play video and audio
rebuild mediastreamer2-5.3.74-alt6
Mediastreamer2 is a powerful and lightweight streaming engine for voice/video telephony applications
SIP SIMPLE implementation for Python
rebuild qt5-webengine-5.15.17-alt2
Qt5 - QtWebEngine components
rebuild raze-1.1.2-alt1
Raze is a fork of Build engine games backed by GZDoom tech
rebuild thunderbird-141.0-alt0.p10.1
Thunderbird is Mozilla's e-mail client
rebuild toxcore-0.1.11-alt2
All-in-one secure communication platform
rebuild virtualbox-7.1.6-alt0.c10f2.1
VM VirtualBox OSE - Virtual Machine for x86 hardware
rebuild vlc-3.0.20-alt1
VLC media player
rebuild xpra-4.4.4-alt3
X Persistent Remote Applications
Oct 8, 2025, 04:42 PM
#395331 sent by Andrey Cherepanov
Request_169086
Dependency injection specification for Java (JSR-330)
CDI API
Feb. 18, 2025 Andrey Cherepanov:
- Return javax.enterprise.inject.spi. - Fix license name according to SPDX.
Infinispan is an open source data grid platform and highly scalable NoSQL cloud data store.
Oct. 8, 2025 Andrey Cherepanov:
- Required commons-compress.jar for cli.sh. - Used CLASSPATH from common.sh in cli.sh.
Oct 8, 2025, 09:46 AM
#396546 sent by Alexander Danilov
fix_CVE-2021-46310
DjVu viewers, encoders and utilities
July 14, 2025 Konstantin Lepikhov:
- 3.5.29. - Fix FTBFS on ix86.
Oct 8, 2025, 09:38 AM
#396483 sent by Kirill Izmestev
Fix_CVE-2024-53263
Git extension for versioning large files
April 8, 2025 Artem Krasovskiy:
- Updated to 3.6.1 (fixes CVE-2024-53263)
Oct 7, 2025, 05:59 PM
#396204 sent by Alexander Danilov
fix_CVE-2025-59800
PostScript interpreter and renderer, most printer drivers
Sept. 30, 2025 Alexander Danilov:
- New version 10.06.0.
Oct 7, 2025, 12:47 PM
#396331 sent by Alexander Danilov
fix_CVE-2025-49133
Library providing Trusted Platform Module (TPM) functionality
June 20, 2025 Alexey Shabalin:
- New version 0.10.1 (Fixes: CVE-2025-49133).
Oct 7, 2025, 09:55 AM
#396334 sent by Alexei Takaseev
New version fix CVE-2025-27233, CVE-2025-27238, CVE-2025-27240
A network monitor
Provides native Zabbix solution for monitoring MongoDB
Provides native Zabbix solution for monitoring MS-SQL
Provides native Zabbix solution for monitoring PostgreSQL
Oct. 3, 2025 Alexei Takaseev:
- 7.0.19
Oct 3, 2025, 11:13 PM
#395754 sent by Alexander Danilov
fix_CVE-2024-28085
A collection of basic system utilities
May 23, 2024 Kirill Izmestev:
- Backported upstream security fix (fixes CVE-2024-28085).
Oct 3, 2025, 10:43 PM
#396069 sent by Anton Midyukov
fix_run_stop_service
alterator module for vsftpd configuration
Sept. 30, 2025 Anton Midyukov:
- OVE-20250930-0001: Fix the inability to enable/disable the service.
Oct 3, 2025, 04:24 PM
#396139 sent by Vitaly Lipatov
fixed CVEs
A package manager for node
Sept. 30, 2025 Vitaly Lipatov:
- update node-ip to 2.0.1 (CVE-2023-42282) - update node-ip to 2.0.2 from fork https://github.com/eggjs/node-ip (CVE-2024-29415) - update brace-expansion to 1.1.12 and 2.0.2 (CVE-2025-5889) - update tar to 6.2.1 (CVE-2024-28863)
Oct 2, 2025, 05:18 PM
#396149 sent by Alexander Danilov
fix_CVE-2025-22247
Open Virtual Machine Tools for virtual machines hosted on VMware
Sept. 30, 2025 Andrew A. Vasilyev:
- 13.0.5 (CVE-2025-41244)
Oct 2, 2025, 04:08 PM
#394479 sent by Anton Midyukov
v10.2.2
System/Base
Sept. 9, 2025 Anton Midyukov:
- indexhtml.desktop: use xdg-open instead xbrowser - os-release: add LOGO
System/Base
Sept. 9, 2025 Anton Midyukov:
- indexhtml.desktop: use xdg-open instead xbrowser - os-release: add LOGO
Oct 2, 2025, 03:52 PM
#396098 sent by Alexander Danilov
fix_CVE-2018-13410
A file compression and packaging utility compatible with PKZIP/WinZIP
Sept. 30, 2025 Alexander Danilov:
- Applied debian patch (fixed CVE-2018-13410).
Oct 2, 2025, 01:40 PM
#395698 sent by Alexander Danilov
fix_CVE-2025-8114,CVE-2025-8277
C library to authenticate in a simple manner to one or more SSH servers
Sept. 24, 2025 Alexander Danilov:
- new version (fixes: CVE-2025-8114 CVE-2025-8277)
Oct 2, 2025, 10:09 AM
#396118 sent by Leontiy Volodin
CVE_fix
A lightweight docker management UI
Agent for portainer
Sept. 30, 2025 Leontiy Volodin:
- New LTS version 2.33.2.
Oct 1, 2025, 06:22 PM
#395690 sent by Alexander Danilov
fix_CVE-2025-26594
Xserver - X Window System display server
Wayland X server
Sept. 24, 2025 Alexander Danilov:
- cherry pick upstream fixes for CVE-2025-26594
Oct 1, 2025, 06:00 PM
#396093 sent by Alexander Danilov
fix_CVE-2025-5999,CVE-2025-6000,CVE-2025-6004,CVE-2025-6010,CVE-2025-6011
A tool for secrets management, encryption as a service, and privileged access management
Sept. 14, 2025 Nikolay Burykin:
- Security fixes: + CVE-2025-5999 + CVE-2025-6000 + CVE-2025-6004 + CVE-2025-6010 + CVE-2025-6011
Oct 1, 2025, 05:54 PM
#395773 sent by Alexander Stepchenko
CVE-2025-22868
flannel is a network fabric for containers
Sept. 9, 2025 Alexander Stepchenko:
- Update to 0.27.3. - Fixes: + CVE-2025-22868: Unexpected memory consumption during token parsing in golang.org/x/oauth2
Oct 1, 2025, 05:45 PM
#396112 sent by Alexander Danilov
fix_CVE-2025-58068
Highly concurrent networking library
Aug. 28, 2025 Anton Vyatkin:
- new version 0.40.3
Sep 30, 2025, 08:35 PM
#395353 sent by Kernel Bot
v6.12.48
The Linux kernel (the core of the Linux operating system)
LiME module for Linux kernel
Linux Kernel drivers support IPoE for accel-ppp
Anbox kernel modules
Modules for Broadcom IEEE 802.11a/b/g/n adapters
ch341 kernel module
dm-linear with secure deletion on discard
Kernel driver for DRBD
DisplayLink kernel module
Intel(R) 10GbE PCI Express Linux Network Driver
Iptables match for Security Options (IPSO) Labels (kernel module)
Netflow iptables module for Linux kernel
Intel(R) 10GbE PCI Express Linux Network Driver
Linux Kernel Runtime Guard module
nVidia video card drivers
Module for Realtek R8125
Linux driver for RealTek Ethernet controllers
Realtek rtl8192eu official Linux driver
Module for Realtek RTL8812au
Module for Realtek RTL8821CE
Realtek RTL8811CU/RTL8821CU USB wifi adapter driver
Module for Realtek RTL88x2bu
Realtek RTL8852AE driver kernel module.
Translate between CISPO and GOST R 58256-2018 (Astra) labels
v4l2-loopback device
VHBA virtual host bus adapter module
VirtualBox modules
VirtualBox modules
xtables-addons kernel module
Driver for Motorcomm YT6801 ethernet adapter
ZFS Linux modules
Sep 30, 2025, 05:19 PM
#395710 sent by Alexander Danilov
fix_CVEs
An X application for displaying and manipulating images
Sept. 11, 2025 Anton Farygin:
- 7.1.2.2 -> 7.1.2.3 (Fixes: CVE-2025-57807)
Sep 30, 2025, 04:55 PM
#395785 sent by Alexander Danilov
fix_CVE-2024-52304
http client/server for asyncio
Sept. 25, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2024-52304).
Sep 30, 2025, 03:27 PM
#395709 sent by Alexander Danilov
fix_CVE-2024-47606
GStreamer streaming media framework runtime
May 29, 2025 Yuri N. Sedunov:
- fixed CVE-2024-47606
Sep 30, 2025, 01:36 PM
#395762 sent by Alexander Danilov
fix_CVEs
GNU Binary Utility Development Utilities
June 25, 2024 Alexander Danilov:
- Applied upstream patchs (fixes: CVE-2021-45078, CVE-2022-4285, CVE-2022-47008, CVE-2022-47011, CVE-2022-47695, CVE-2022-48063, CVE-2021-46174, CVE-2022-47007, CVE-2022-47010, CVE-2022-47673, CVE-2022-47696, CVE-2023-1972, CVE-2022-48064, CVE-2022-38533, CVE-2022-44840, CVE-2022-44840).
Sep 30, 2025, 01:24 PM
#395839 sent by Alexander Danilov
fix_CVE-2023-46045
Graphs visualization tools
Sept. 26, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2023-46045).
Sep 30, 2025, 10:56 AM
#395814 sent by Andrey Cherepanov
New_version_with_security_fixes
Open Source Identity and Access Management For Modern Applications and Services
Sept. 25, 2025 Andrey Cherepanov:
- New version (fixes: CVE-2025-58057, CVE-2025-58056).
Sep 29, 2025, 06:05 PM
#395852 sent by Alexander Danilov
fix_CVE-2025-57052
Ultralightweight JSON parser in ANSI C
Sept. 26, 2025 Alexander Danilov:
- new version 1.7.19 (fixes CVE-2025-57052).
Sep 29, 2025, 12:55 PM
#395755 sent by Alexander Danilov
fix_CVE-2023-4016
System and process monitoring utilities
Dec. 12, 2023 Mikhail Efremov:
- Patch from Fedora: + ps: Fix possible buffer overflow in -C option (fixes: CVE-2023-4016). - Fixed NEWS file. - spec: added a knob to build without systemd (by Alexey Sheplyakov) - Makefile.am: fixed build without systemd (by Alexey Sheplyakov)
Sep 29, 2025, 11:48 AM
#395323 sent by Alexander Danilov
fix_CVE-2023-21971
MySQL Connector for Python 3
Sept. 19, 2025 Alexander Danilov:
- new version 8.0.33
Sep 29, 2025, 11:42 AM
#395553 sent by Alexander Danilov
fix_CVE-2022-38223
w3m is a pager with Web browsing capability
Sept. 22, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2022-38223).
Sep 29, 2025, 11:33 AM
#395373 sent by Constantin Sunzow
Security update
Library of functions for manipulating TIFF format image files
Sept. 20, 2025 Constantin Sunzow:
- Fixes: + CVE-2025-8961 Improper bounds checking on memory operations
Sep 26, 2025, 10:34 PM
#395738 sent by Anton Vyatkin
cve_fix
The new and improved version of a small but fast template engine
Sept. 19, 2025 Anton Vyatkin:
- Fixed CVE-2024-56201, CVE-2024-56326, CVE-2025-27516.
Sep 26, 2025, 01:50 PM
#395317 sent by Anton Midyukov
c10_not_ready_for_usrmerge
ZFS on Linux
Sept. 19, 2025 Anton Midyukov:
- OVE-20250919-0006: Revert "move tools and libs to /usr"
Sep 26, 2025, 01:38 PM
#395552 sent by Alexander Danilov
fix_CVE-2025-54874
JPEG 2000 codec library (API version 2.0)
Sept. 21, 2025 Yuri N. Sedunov:
- 2.5.4
Sep 25, 2025, 02:57 PM
#395567 sent by Alexander Danilov
fix_CVE-2025-50181
Library with thread-safe connection pooling, file post support, sanity friendly etc
Sept. 22, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2025-50181).
Sep 24, 2025, 09:11 PM
#394393 sent by Ajrat Makhmutov
Firefox and Thunderbird CVE fixes
Common CA Certificates
Set of RPM macros for packaging applications that requires thunderbird
It is a tool for updating checksum files in vendor directories
Is a command-line utility for parsing the debugging information the compiler provides
Thunderbird is Mozilla's e-mail client
Virtual packages for KDE 5
A system tray extension for Thunderbird
Educational software (base set)
The Mozilla Firefox project is a redesign of Mozilla's browser
Sept. 11, 2025 Ajrat Makhmutov:
- New backported version (141.0.3) in c10f2 branch.
Sep 24, 2025, 08:07 PM
#395044 sent by Ilfat Aminov
openstack_antelope_version
OpenStack Image Service
Sept. 16, 2025 Ilfat Aminov:
- delete max version from python3-module-glance_store requirement
Sep 22, 2025, 08:31 PM
#394545 sent by Kirill Izmestev
rebuilding_dependent_packages_after_golang_update_CVE-2025-47906_CVE-2025-47907
rebuild micro-2.0.10-alt1
A modern and intuitive terminal-based text editor
rebuild podman-5.4.2-alt0.p10.2
Manage pods, containers, and container images
rebuild cri-o1.31-1.31.9-alt1
Kubernetes Container Runtime Interface for OCI-based containers
rebuild cni-plugin-flannel-1.7.1.1-alt1
A CNI network plugin that is powered by flannel
rebuild runc-1.3.0-alt1
CLI for running Open Containers
rebuild buildah-1.39.4-alt0.p10
A command line tool used to creating OCI Images
rebuild trivy-0.59.1-alt2
A Fast Vulnerability Scanner for Containers
rebuild skopeo-1.18.0-alt1
skopeo is a command line utility that performs various operations on container images and image repositories
rebuild etcd-3.5.15-alt1
A highly-available key value store for shared configuration
rebuild gvisor-tap-vsock-0.7.4-alt1
Go replacement for libslirp and VPNKit
rebuild cri-tools1.31-1.31.1-alt1
CLI and validation tools for Kubelet Container Runtime Interface (CRI)
rebuild cni-plugins-1.5.0-alt1
Container Network Interface plugins
rebuild cni-1.2.0-alt1
Container Network Interface - networking for Linux containers
rebuild docker-registry-2.8.3-alt2
The Docker toolset to pack, ship, store, and deliver content
rebuild rootlesskit-2.1.0-alt1
Linux-native "fake root" for implementing rootless containers
rebuild prometheus-2.51.1-alt1
Prometheus monitoring system and time series database
rebuild kubernetes1.30-1.30.14-alt1
Container cluster management
rebuild cri-o1.30-1.30.14-alt1
Kubernetes Container Runtime Interface for OCI-based containers
rebuild cri-o1.32-1.32.5-alt1
Kubernetes Container Runtime Interface for OCI-based containers
rebuild cri-o1.33-1.33.1-alt1
Kubernetes Container Runtime Interface for OCI-based containers
A highly-available key value store for shared configuration
CoreDNS is a DNS server that chains plugins
rebuild cri-tools1.33-1.33.0-alt1
CLI and validation tools for Kubelet Container Runtime Interface (CRI)
rebuild flannel-0.26.7-alt2
flannel is a network fabric for containers
k8s-Node-collector is an open source collector who collect Node information (fs and process data) and output in a table/json format
Prometheus Alertmanager
Prometheus blackbox prober exporter
Prometheus exporter for hardware and OS metrics exposed by *NIX kernels.
rebuild zabbix-7.0.12-alt0.c10f2.1
A network monitor
rebuild coredns1.11.3-1.11.3-alt2
CoreDNS is a DNS server that chains plugins
rebuild kubernetes1.31-1.31.12-alt1
Container cluster management
rebuild kubernetes1.32-1.32.8-alt1
Container cluster management
rebuild kubernetes1.33-1.33.4-alt1
Container cluster management
Sep 22, 2025, 11:52 AM
#394973 sent by Alexander Danilov
fix_CVE-2025-1695
NGINX Unit - Web Application Server
Sept. 14, 2025 Andrew A. Vasilyev:
- Update to 1.35.0 (2025-08-26) (Fixes: CVE-2025-1695).
Sep 22, 2025, 11:44 AM
#393930 sent by Denis Medvedev
not in distros
ipp-usb -- HTTP reverse proxy, backed by IPP-over-USB connection to device
March 24, 2025 Anton Midyukov:
- New version 0.9.30.
Sep 18, 2025, 07:23 PM
#395043 sent by Alexander Danilov
fix_CVE-2025-9817
The BugTraq Award Winning Network Traffic Analyzer
Sept. 11, 2025 Anton Farygin:
- 4.4.9 (Fixes: CVE-2025-9817)
Sep 18, 2025, 07:12 PM
#394690 sent by Alexander Danilov
fix_CVE-2024-4140
Easy MIME message parsing
An "archives first" approach to mailing lists
Dec. 23, 2023 Alexey Gladkov:
- New git snapshot (v1.9.0-1113-g84874a85).
Sep 18, 2025, 07:06 PM
#394958 sent by Leontiy Volodin
CVE_fix
Prometheus exporter for podman environment
Sept. 15, 2025 Leontiy Volodin:
- Specified closed security vulnerabilities (Fixes: CVE-2025-58058).
Sep 18, 2025, 06:59 PM
#395127 sent by Anton Meleshnikov
Closed_CVE
Grafana Mimir is an open source software project that provides a scalable long-term storage for Prometheus
Sept. 17, 2025 Anton Meleshnikov:
- Fixed EnvironmentFile variable in mimir.service.
Sep 17, 2025, 04:06 PM
#394963 sent by Constantin Sunzow
Security update
DCMTK - DICOM Toolkit
Sept. 15, 2025 Constantin Sunzow:
- Fixes: + CVE-2025-9732 Out-of-bounds Write
Sep 17, 2025, 09:57 AM
#394952 sent by Alexander Danilov
fix_CVE-2025-9019
A tool to replay captured network traffic
Sept. 13, 2025 Anton Farygin:
- 4.5.1 -> 4.5.2 (Fixes: CVE-2025-9019)
Sep 16, 2025, 12:32 PM
#394549 sent by Alexander Danilov
fix_CVE-2024-31047
A high-dynamic-range image file library
Sept. 10, 2025 Alexander Danilov:
- Applied upstream patch (fixed CVE-2024-31047).
Sep 15, 2025, 04:59 PM
#394443 sent by Alexander Danilov
fix_CVE-2019-19847
Library to simplify the drawing of beautiful curves
rebuild fontforge-20201107-alt1
FontForge -- font editor
Sep 13, 2025, 12:06 AM
#394602 sent by Alexander Danilov
fix_CVE-2007-1349
An embedded Perl interpreter for the Apache2 Web server
Nov. 2, 2023 Nikolay A. Fetisov:
- New version (Closes: 48272) - fix build for perl >= 5.37.1. - fix SIGSEGV crash due to wrong use of perl_parse() - Update Apache::Reload module to 1.14
Sep 12, 2025, 06:05 PM
#394623 sent by Alexander Danilov
fix_CVE-2001-1593,CVE-2014-0466,CVE-2015-8107
Any to PostScript filter
June 30, 2025 Petr Usoltsev:
- Version up - Update koi8 patch - Removing outdated third-party patches - Fix build - Deleting libraries, because upstream remove libs(noinst_LTLIBRARIES = liba2ps.la) in commit 267dc6a67c361179ddb267ee75e9e11291b43c67
Sep 12, 2025, 11:59 AM
#394435 sent by Alexander Danilov
fix_CVE-2021-41043
A tool to merge or split pcap files
Sept. 9, 2025 Alexander Danilov:
- New version 1.8.
Sep 12, 2025, 11:54 AM
#394554 sent by Alexander Danilov
fix_CVE-2024-52616
Local network service discovery
Jan. 20, 2025 Sergey Bolshakov:
- updated to v0.9-rc2 - fixes: CVE-2024-52616
Sep 12, 2025, 10:56 AM
#394067 sent by Anton Midyukov
fix_dependecies
Python krb5 API interface
Sept. 4, 2025 Anton Midyukov:
- OVE-20250904-0101: remove runtime dependency on development packages.
Sep 11, 2025, 06:19 PM
#393749 sent by Pavel Vasenkov
New_version_with_CVE
Netscape Network Security Services(NSS)
A project for generating C bindings from Rust code.
The Mozilla Firefox project is a redesign of Mozilla's browser
Sept. 2, 2025 Pavel Vasenkov:
- Backport new version to c10 branch.
Sep 11, 2025, 06:03 PM
#393859 sent by Alexander Stepchenko
CVE-2025-5187
Container cluster management
Aug. 18, 2025 Alexander Stepchenko:
- Update to 1.31.12. - Fixes: + CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference
Container cluster management
Aug. 30, 2025 Alexander Stepchenko:
- Update to 1.32.8. - Fixes: + CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference
Container cluster management
Aug. 30, 2025 Alexander Stepchenko:
- Update to 1.33.4. - Fixes: + CVE-2025-5187: Nodes can delete themselves by adding an OwnerReference
Sep 11, 2025, 05:49 PM
#393992 sent by Anton Vyatkin
fix
API for Linux kernel LIO SCSI target
An administration shell for storage targets
deleted python-module-configshell
A framework to implement simple but nice CLIs
May 21, 2025 Anton Vyatkin:
- Initial build for Sisyphus.
Sep 9, 2025, 05:57 PM
#393546 sent by Pavel Skrylev
bugfix
Server automation framework and application
Aug. 29, 2025 Pavel Skrylev:
- ! fixed service file to drop syslog and optimize some others
Sep 9, 2025, 03:39 PM
#393821 sent by Constantin Sunzow
Security update
Library of functions for manipulating TIFF format image files
Sept. 2, 2025 Constantin Sunzow:
- Fixes: + CVE-2024-13978 NULL Pointer Dereference + CVE-2025-8851 Stack-based Buffer Overflow + CVE-2025-9165 Missing Release of Memory after Effective Lifetime
Sep 9, 2025, 03:32 PM
#394023 sent by Alexander Danilov
fix_CVE-2024-22195,CVE-2024-34064,CVE-2024-56326,CVE-2025-27516
The new and improved version of a small but fast template engine
Sept. 4, 2025 Alexander Danilov:
- patches from debian (fixes: CVE-2024-56326, CVE-2025-27516, CVE-2024-22195, CVE-2024-34064).