[<prev day] [next day>] [month] [year] [list]
oss-security mailing list - 2026/09/18
- CVE-2026-75157: Apache Airflow: Asset queued-events DELETE
endpoints gated on Dag READ instead of Dag EDIT (asset-triggered
… (Rahul Vats <rahulvats@...che.org>)
- Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Jacob Bachmeyer <jcb62281@...il.com>)
- A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill (manizada <manizada@...me>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Hanno Böck <hanno@...eck.de>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Valtteri Vuorikoski <vuori@...com.org>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Kevin Riggle <kevinr@...plexsystems.group>)
- Re: Removing dead code (was: Retrospective by
'gpg.fail' authors) (Peter Gutmann <pgut001@...auckland.ac.nz>)
- CVE-2026-93018: Imager versions before 1.036 for Perl disclose
uninitialised heap memory reading a paletted image with pixel inde… (Stig Palmquist <stig@...g.io>)
- CVE-2026-93019: Imager versions before 1.036 for Perl exit the
process reading a TGA with a colour map length of 32768 or more in… (Stig Palmquist <stig@...g.io>)
- CVE-2026-91863: Apache Neethi: Uncontrolled recursion while
parsing crafted WS-Policy documents allows denial of servic… (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91864: Apache Neethi: Crafted WS-Policy documents bypass
element/attribute limits causing memory exhaustion (Colm O hEigeartaigh <coheigea@...che.org…)
- CVE-2026-91865: Apache Neethi: Crafted policy references cause
exponential expansion during normalization leading to de… (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91866: Apache Neethi: Crafted policies cause unbounded
work during intersection leading to denial of service (Colm O hEigeartaigh <coheigea@...che.or…)
- CVE-2026-91867: Apache Neethi: Remote policy fetch lacks a total
timeout, allowing a slow server to hang the request in… (Colm O hEigeartaigh <coheigea@...che.or…)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (Eli Schwartz <eschwartz@...too.org>)
- Re: A quartet of Linux local root vulns: DirtyAH6,
PPPoEject, TUNderflow, and DiagSpill (SOFIA ETCHEPARE DARONCO <sofia.etchepare@...d.ufsm.br>)
- Vulnerabilities in libheif and libde265 (Alan Coopersmith <alan.coopersmith@...cle.com>)
17 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.