January 2026 - Page 94 of 150

AlmaLinux 9 — jackson-core — vulnerability — patch and remediation guide — diagnosis and fix on AlmaLinux 9

AlmaLinux 9 — jackson-core — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 9 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2025:12280 Related CVEs: CVE-2025-52999 Upstream summary: Core part of Jackson that defines Streaming API as well as basic shared abstractions. Security Fix(es): * com.fasterxml.jackson.core/jackson-core: jackson-core Potential StackoverflowError (CVE-2025-52999) For more details about […]

Read more
FreeBSD 15 — php71-imap — security advisory — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — php71-imap — security advisory — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: php-imap — imap_open allows to run arbitrary shell commands via mailbox parameter Upstream summary: The PHP team reports: imap_open allows to run arbitrary shell commands via mailbox parameter. Table of […]

Read more
FreeBSD 12 — linux-c7-sqlite — multiple vulnerabilities (6 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — linux-c7-sqlite — multiple vulnerabilities (6 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 January 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: SQLite < 3.50.3 — CWE-190 Integer Overflow or Wraparound in FTS5 module Related CVEs: CVE-2024-0232 CVE-2025-29088 CVE-2025-3277 CVE-2025-52099 CVE-2025-6965 CVE-2025-7709 Upstream summary: https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g reports: An integer overflow exists in the […]

Read more
Amazon Linux 2023 — apache-commons-lang3 — vulnerability — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — apache-commons-lang3 — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2025-1150 Related CVEs: CVE-2025-48924 Upstream summary: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before […]

Read more
FreeBSD 15 — postgresql-jdbc — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — postgresql-jdbc — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL JDBC library — Improper Authentication Related CVEs: CVE-2025-49146 Upstream summary: PostgreSQL JDBC Driver project reports: Client Allows Fallback to Insecure Authentication Despite channelBinding=require configuration. Fix channel binding required handling […]

Read more
FreeBSD 15 — libwasmtime — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — libwasmtime — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libwasmtime — host panic with fd_renumber WASIp1 function Related CVEs: CVE-2025-53901 Upstream summary: WasmTime development team reports: A bug in Wasmtime's implementation of the WASIp1 set of import functions can […]

Read more
NetBSD 9.4 — xenkernel420 — multiple vulnerabilities (8 CVEs) — patch and remediation guide — diagnosis and fix on NetBSD 9.4

NetBSD 9.4 — xenkernel420 — multiple vulnerabilities (8 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 25 May 2026 Affected versions: NetBSD 9.4 📖 ~4 min read  •  Source: pkgsrc audit-packages entry Related CVEs: CVE-2025-27466 CVE-2025-58142 CVE-2025-58143 CVE-2025-58149 CVE-2025-58150 CVE-2025-58147 CVE-2025-58148 CVE-2026-23553 Upstream summary: pkgsrc audit-packages flagged xenkernel420<20251113 for vulnerability class 'null-pointer-dereference'. Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-27466 Table of contents Symptom & Impact Environment & Reproduction […]

Read more
FreeBSD 15 — freeimage — multiple vulnerabilities (3 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — freeimage — multiple vulnerabilities (3 CVEs) — patch and remediation guide

🟡 Medium   ⏱ 10–30 min  Last verified: 15 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: freeimage — code execution vulnerability Related CVEs: CVE-2015-0852 CVE-2015-3885 CVE-2016-5684 Upstream summary: TALOS reports: An exploitable out-of-bounds write vulnerability exists in the XMP image handling functionality of the FreeImage library. […]

Read more
FreeBSD 15 — ru-bogofilter — vulnerability — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — ru-bogofilter — vulnerability — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 15 January 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: bogofilter — RFC 2047 decoder denial-of-service vulnerability Related CVEs: CVE-2004-1007 Upstream summary: The bogofilter team has been provided with a test case of a malformatted (non-conformant) RFC-2047 encoded word that […]

Read more
Amazon Linux 2023 — python3.11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2023

Amazon Linux 2023 — python3.11 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2023 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2023-2026-1620 Related CVEs: CVE-2026-0672 CVE-2026-3644 CVE-2026-4224 CVE-2026-4519 CVE-2026-4786 CVE-2026-6100 CVE-2025-8194 CVE-2024-12718  +12 more Upstream summary: The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= […]

Read more
CHAT