<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://www.sya54m.eu/ChangeLog-arm-15.0.xml" rel="self" type="application/rss+xml" />
    <title>Slackwarearm-15.0 ChangeLog</title>
    <link>https://www.sya54m.eu</link>
    <description>Latest 20 entries in the Slackwarearm-15.0 ChangeLog</description>
    <image>
      <url>https://www.sya54m.eu/immagini/s256.png</url>
      <title>Slackwarearm-15.0 ChangeLog</title>
      <link>https://www.sya54m.eu</link>
    </image>
    <language>en</language>
    <pubDate>Sat, 11 Jul 2026 10:08:08 +0200</pubDate>
    <lastBuildDate>Wed, 15 Jul 2026 18:30:09 +0200</lastBuildDate>
    <generator>www.sya54m.eu</generator>
<item>
      <title>Sat Jul 11 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 11 Jul 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1783757288</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/extra/tigervnc/tigervnc-1.16.2-arm-4_slack15.0.txz' rel='nofollow'>extra/tigervnc/tigervnc-1.16.2-arm-4_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;Recompiled against xorg-server-1.20.14, including patches for<br>&nbsp;&nbsp;security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/glibc-zoneinfo-2026c-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/glibc-zoneinfo-2026c-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This package provides the latest timezone updates.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/p11-kit-0.26.4-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/p11-kit-0.26.4-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;server: fixed stack exhaustion via unbounded recursion in RPC attribute<br>&nbsp;&nbsp;parsing by enforcing a recursion depth limit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-13757<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Thu Jul 09 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 09 Jul 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1783584488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/testing/packages/autoconf-2.73-noarch-1_slack15.0.txz' rel='nofollow'>testing/packages/autoconf-2.73-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Added.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/c-ares-1.34.8-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/c-ares-1.34.8-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libXfont2-2.0.8-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libXfont2-2.0.8-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow.<br>&nbsp;&nbsp;PCF Font Parsing Heap Buffer Overflow.<br>&nbsp;&nbsp;computeProps Property Buffer Heap Buffer Overflow.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062253.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56001<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56002<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56003<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/proftpd-1.3.9c-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/proftpd-1.3.9c-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;ExecEnviron values not passed due to regression since 1.3.8.d.<br>&nbsp;&nbsp;Stack buffer overflow in MLSD/MLST handling for long path names.<br>&nbsp;&nbsp;MaxTransfersPerUser no longer enforces configured limits.<br>&nbsp;&nbsp;AdminControlsACLs for config, get actions not honored as they should be.<br>&nbsp;&nbsp;Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed<br>&nbsp;&nbsp;buffers without bounds checking.<br>&nbsp;&nbsp;RewriteMap unescape builtin use causes one-byte out-of-bounds write,<br>&nbsp;&nbsp;fails to reject illegal characters.<br>&nbsp;&nbsp;SQL group name lookup concatenates client-provided group names without<br>&nbsp;&nbsp;escaping.<br>&nbsp;&nbsp;Authenticated SFTP sessions can overflow the SFTP packet buffer.<br>&nbsp;&nbsp;Default Controls socket ACLs unintentionally allow all users access for<br>&nbsp;&nbsp;sending Controls requests.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/tftp-hpa-5.4-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/tftp-hpa-5.4-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;Fix several security-relevant bugs in path validation<br>&nbsp;&nbsp;(tftpd/path.c): an uninitialized buffer read and a broken<br>&nbsp;&nbsp;path tokenizer could let a crafted or unlucky request bypass<br>&nbsp;&nbsp;path restrictions or crash the daemon.<br>&nbsp;&nbsp;Fix buffer overflows in the tftp client: an unbounded strcpy()<br>&nbsp;&nbsp;when building requests, an out-of-bounds write when putting<br>&nbsp;&nbsp;multiple files to a remote directory, and an unbounded write<br>&nbsp;&nbsp;into the interactive command-line argument array.<br>&nbsp;&nbsp;Fix an out-of-bounds read while scanning request fields in<br>&nbsp;&nbsp;tftpd, and an incorrect address family used when creating the<br>&nbsp;&nbsp;per-transfer socket on platforms without recvmsg().<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-1.20.14-arm-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-1.20.14-arm-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xephyr-1.20.14-arm-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xephyr-1.20.14-arm-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xnest-1.20.14-arm-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xnest-1.20.14-arm-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xvfb-1.20.14-arm-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xvfb-1.20.14-arm-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xwayland-21.1.4-arm-13_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xwayland-21.1.4-arm-13_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Jul 07 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 07 Jul 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1783411688</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/extra/php82/php82-8.2.32-arm-1.txz' rel='nofollow'>extra/php82/php82-8.2.32-arm-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;OpenSSL: Fixed memory corruption (zend_mm_heap corrupted) in<br>&nbsp;&nbsp;openssl_encrypt with AES-WRAP-PAD.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.php.net/ChangeLog-8.php#8.2.32<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-14355<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/c-ares-1.34.7-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/c-ares-1.34.7-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release fixes the following security issues:<br>&nbsp;&nbsp;Use-after-free / double-free in c-ares' query-completion handling, remotely<br>&nbsp;&nbsp;triggerable via ares_getaddrinfo() over TCP.<br>&nbsp;&nbsp;CPU-exhaustion denial of service via unbounded DNS name compression pointer<br>&nbsp;&nbsp;chains.<br>&nbsp;&nbsp;Memory-amplification denial of service via unvalidated DNS header record<br>&nbsp;&nbsp;counts.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33630<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/mutt-2.4.1-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/mutt-2.4.1-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Prevent unsigned int overflow in imap_cmd_step buffer growth.<br>&nbsp;&nbsp;The idata-&gt;blen field is unsigned int (32-bit) while the companion<br>&nbsp;&nbsp;variable len is size_t (64-bit on LP64). When a malicious IMAP server<br>&nbsp;&nbsp;sends a response line longer than UINT_MAX bytes without newline, the<br>&nbsp;&nbsp;expression wraps to a small value, causing safe_realloc() to shrink the<br>&nbsp;&nbsp;buffer while len retains its original huge value. The subsequent<br>&nbsp;&nbsp;mutt_socket_readln() then writes far past the shrunken allocation.<br>&nbsp;&nbsp;Fix by changing idata-&gt;blen from unsigned int to size_t, matching the<br>&nbsp;&nbsp;type of len and preventing the overflow on all platforms.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/openssh-10.4p1-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/openssh-10.4p1-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains a number of security fixes:<br>&nbsp;&nbsp;sftp(1): when downloading files on the command-line using<br>&nbsp;&nbsp;"sftp host:/path .", a malicious server could cause the file to<br>&nbsp;&nbsp;be downloaded to an unexpected location. This issue was identified<br>&nbsp;&nbsp;by the Swival Security Scanner.<br>&nbsp;&nbsp;scp(1): when copying files between two remote destinations, do<br>&nbsp;&nbsp;not allow a malicious server to write files to the parent<br>&nbsp;&nbsp;directory of the intended target directory.&nbsp;&nbsp;This issue was<br>&nbsp;&nbsp;identified by the Swival Security Scanner.<br>&nbsp;&nbsp;sshd(8): when using the "internal-sftp" SFTP server implementation<br>&nbsp;&nbsp;(this is not the default), long command lines were previously<br>&nbsp;&nbsp;truncated silently after the 9th argument. If a security-relevant<br>&nbsp;&nbsp;option was in the 10th or later position, it would be discarded.<br>&nbsp;&nbsp;Reported by Steve Caffrey.<br>&nbsp;&nbsp;sshd(8): add a documentation note to mention that the<br>&nbsp;&nbsp;GSSAPIStrictAcceptorCheck option is ineffective when the server<br>&nbsp;&nbsp;is joined to a Windows Active Directory. Reported by Yarin Aharoni<br>&nbsp;&nbsp;of Safebreach.<br>&nbsp;&nbsp;sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes<br>&nbsp;&nbsp;as it was documented to do. Note that PermitTunnel is not enabled<br>&nbsp;&nbsp;by default. Reported independently by Huzaifa Sidhpurwala of<br>&nbsp;&nbsp;Redhat and Marko Jevtic.<br>&nbsp;&nbsp;sshd(8): avoid a potential pre-authentication denial of service<br>&nbsp;&nbsp;when GSSAPIAuthentication was enabled (this feature is off by<br>&nbsp;&nbsp;default). This was not mitigated by MaxAuthTries, but would be<br>&nbsp;&nbsp;penalised by PerSourcePenalties. This was reported by Manfred<br>&nbsp;&nbsp;Kaiser of the milCERT AT (Austrian Ministry of Defence).<br>&nbsp;&nbsp;sshd(8): fix a number of cases where the minimum authentication<br>&nbsp;&nbsp;delay was not being enforced. Reported by the Orange Cyberdefense<br>&nbsp;&nbsp;Vulnerability Team.<br>&nbsp;&nbsp;ssh(1): fix a possible client-side use-after-free if the server<br>&nbsp;&nbsp;changes its host key during a key reexchange. This was reported by<br>&nbsp;&nbsp;Zhenpeng (Leo) Lin of Depthfirst.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.openssh.org/releasenotes.html#10.4<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sat Jul 04 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 04 Jul 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1783152488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libseccomp-2.6.1-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libseccomp-2.6.1-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;Fix incorrect 64-bit comparison merge that can weaken libseccomp filters.<br>&nbsp;&nbsp;Fix issue where oversized libseccomp filters can trigger a double free.<br>&nbsp;&nbsp;Fix issue where oversized libseccomp filters can trigger a heap corruption.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-4q85-33p6-j5g6<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-46fr-jh49-xvhx<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-2hqh-5c36-grrm`<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri Jul 03 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 03 Jul 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1783066088</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/gmime-3.2.15-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/gmime-3.2.15-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Thanks to Lockywolf.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libevent-2.1.13-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libevent-2.1.13-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains several security fixes, affecting users of the<br>&nbsp;&nbsp;following modules: evbuffer, bufferevent, evtag, evrpc, evdns, evhttp.<br>&nbsp;&nbsp;If you have a program that uses one of those modules you should upgrade.<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon Jun 29 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 29 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1782720488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/fetchmail-6.4.27-arm-3_slack15.0.txz' rel='nofollow'>patches/packages/fetchmail-6.4.27-arm-3_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This release contains an important bugfix:<br>&nbsp;&nbsp;The IMAP client, which has always used message indexes for the selected<br>&nbsp;&nbsp;mailbox, did not abort when receiving an EXPUNGE response - which changes<br>&nbsp;&nbsp;message numbers inside the mailbox.&nbsp;&nbsp;Unlike UIDs, the message numbers are<br>&nbsp;&nbsp;not stable and fetchmail does not have internal interfaces to track which<br>&nbsp;&nbsp;messages are deleted, and adding those to a 6.6.X release would be too<br>&nbsp;&nbsp;risky, and switching to UID is also too big a change, so we have no<br>&nbsp;&nbsp;choice but to abort the session when seeing an EXPUNGE response without<br>&nbsp;&nbsp;our own EXPUNGE request, to avoid marking the wrong message as seen/deleted<br>&nbsp;&nbsp;or skip the wrong one, or assume the wrong message size.<br>&nbsp;&nbsp;Earl Chew reported this versus Yahoo Mail via Gitlab Work Item #91, which<br>&nbsp;&nbsp;automatically expunges messages that are marked with the \Deleted flag.<br>]]></description>
    </item>
<item>
      <title>Wed Jun 24 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 24 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1782288488</guid>
      <description><![CDATA[<br>If you appreciate what we're doing with Slackware Linux on ARM, please consider<br>making a donation to support the project. Contributions go directly toward<br>maintaining essential build hardware, covering electricity costs, and keeping<br>this long-running labour of love alive and moving forward.<br>Every bit helps and is genuinely appreciated.<br><br>You can find out how to contribute here:<br>&nbsp;&nbsp;https://arm.slackware.com/sponsor/<br><br>Thank you for your continued support!<br><br>&nbsp;&nbsp;Stuart Winter &lt;mozes@slackware&gt;<br><br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libarchive-3.8.8-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libarchive-3.8.8-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Libarchive 3.8.8 is a security, bugfix and minor feature release.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/libarchive/libarchive/releases/tag/v3.8.8<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Thu Jun 18 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 18 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1781770088</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/bind-9.18.50-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/bind-9.18.50-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Fix DNS64 owner case after DNAME restart.<br>&nbsp;&nbsp;When BIND 9 is configured to use DNS64 and encounters a DNAME<br>&nbsp;&nbsp;redirect, it could end up using freed memory for the DNS response<br>&nbsp;&nbsp;owner name. This caused the response to contain corrupted data. This<br>&nbsp;&nbsp;fix ensures the correct owner name is used when constructing the<br>&nbsp;&nbsp;synthesized response after a DNAME redirect.<br>&nbsp;&nbsp;ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/ca-certificates-20260616-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/ca-certificates-20260616-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update provides the latest CA certificates to check for the<br>&nbsp;&nbsp;authenticity of SSL connections.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libidn-1.44-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libidn-1.44-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;libidn: Fix read-out-of-bounds error in ToUnicode APIs.<br>&nbsp;&nbsp;examples: Fix strcpy buffer overflow.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libinput-1.30.4-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libinput-1.30.4-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Switch to libinput-1.30.4 which contains the recent CVE fix, but does<br>&nbsp;&nbsp;not break the API so that wlroots won't build.<br>&nbsp;&nbsp;Thanks to falcon314.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/net-tools-20181103_0eebece-arm-4_slack15.0.txz' rel='nofollow'>patches/packages/net-tools-20181103_0eebece-arm-4_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;The upstream patch for CVE-2025-46836 introduced a regression that broke<br>&nbsp;&nbsp;packet and byte reporting. Thanks to jtsn for a working alternate patch.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/openssl-1.1.1zh-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/openssl-1.1.1zh-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Apply patch to fix the following security issues:<br>&nbsp;&nbsp;Heap Buffer Over-read in ASN.1 Content Parsing.<br>&nbsp;&nbsp;Possible NULL Dereference in Password-Based CMS Decryption.<br>&nbsp;&nbsp;Heap Use-After-Free in the PKCS7_verify() Function.<br>&nbsp;&nbsp;Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion.<br>&nbsp;&nbsp;Out-of-Bounds Read in CMS Password-Based Decryption.<br>&nbsp;&nbsp;These CVEs were fixed by the 1.1.1zh release that is only available to<br>&nbsp;&nbsp;subscribers to OpenSSL's premium extended support. The patch was prepared<br>&nbsp;&nbsp;by backporting from the OpenSSL-3.0 repo.<br>&nbsp;&nbsp;Thanks to Ken Zalewski for the patch!<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-34180<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-7383<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-9076<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34180<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-42766<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45447<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7383<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-9076<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/openssl-solibs-1.1.1zh-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/openssl-solibs-1.1.1zh-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>]]></description>
    </item>
<item>
      <title>Fri Jun 12 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 12 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1781251688</guid>
      <description><![CDATA[<br>If you appreciate what we're doing with Slackware Linux on ARM, please consider<br>making a donation to support the project. Contributions go directly toward<br>maintaining essential build hardware, covering electricity costs, and keeping<br>this long-running labour of love alive and moving forward.<br>Every bit helps and is genuinely appreciated.<br><br>You can find out how to contribute here:<br>&nbsp;&nbsp;https://arm.slackware.com/sponsor/<br><br>Thank you for your continued support!<br><br>&nbsp;&nbsp;Stuart Winter &lt;mozes@slackware&gt;<br><br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/httpd-2.4.68-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.68-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release (CVE-2026-49975 was already patched here.)<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://downloads.apache.org/httpd/CHANGES_2.4.68<br>]]></description>
    </item>
<item>
      <title>Tue Jun 09 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 09 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1780992488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/extra/samba/samba-4.22.10-arm-1.txz' rel='nofollow'>extra/samba/samba-4.22.10-arm-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a security release in order to address the following defects:<br>&nbsp;&nbsp;Missing access checks on reparse point operations.<br>&nbsp;&nbsp;WORM vfs module does not block overwrites.<br>&nbsp;&nbsp;auto-enrolment GPO installing CA certificate over http without verification.<br>&nbsp;&nbsp;Denial of service against AD DC WINS server.<br>&nbsp;&nbsp;Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server.<br>&nbsp;&nbsp;Unauthenticated Remote Code Execution in Samba printing subsystem.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-1933.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-2340.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-3012.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-3238.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-4408.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-4480.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-1933<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2340<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3012<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3238<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4408<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4480<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/rsync-3.4.4-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/rsync-3.4.4-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Rsync version 3.4.4 has been released. This is a regression fix release for<br>&nbsp;&nbsp;the issues that have been reported with the 3.4.3 security release. Many<br>&nbsp;&nbsp;thanks to everyone who reported the issues (see NEWS.md for credits).<br>&nbsp;&nbsp;The 3.4.3 release had so many issues for two main reasons:<br>&nbsp;&nbsp;* the 3.4 testsuite did not have broad enough coverage to catch the<br>&nbsp;&nbsp;&nbsp;&nbsp;regressions noticed by users<br>&nbsp;&nbsp;* the nature of a security release prevents wide beta testing, resulting in<br>&nbsp;&nbsp;&nbsp;&nbsp;not enough manual testing in disparate environments<br>&nbsp;&nbsp;To fix this for future releases we have greatly expanded the test suite for<br>&nbsp;&nbsp;3.5 (currently in master) and grown the development team, especially with<br>&nbsp;&nbsp;more people with security expertise. Thanks for your patience!<br>]]></description>
    </item>
<item>
      <title>Fri Jun 05 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 05 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1780646888</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/dnsmasq-2.93-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/dnsmasq-2.93-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Rework storage allocation for domain names. This fixes a security bug that<br>&nbsp;&nbsp;can cause heap-overwrite with long domain names.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2291<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/libinput-1.31.3-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/libinput-1.31.3-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;libinput-device-group unescaped phys output can inject udev properties<br>&nbsp;&nbsp;leading to arbitrary root code execution.<br>&nbsp;&nbsp;Note that since /dev/uinput and /dev/uhid are only accessible by root on<br>&nbsp;&nbsp;Slackware (and unlike some other distributions we make no exceptions), we<br>&nbsp;&nbsp;were not vulnerable to this flaw.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/meson-1.11.1-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/meson-1.11.1-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is needed to compile libinput-1.31.3.<br>]]></description>
    </item>
<item>
      <title>Thu Jun 04 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 04 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1780560488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/extra/tigervnc/tigervnc-1.16.2-arm-3_slack15.0.txz' rel='nofollow'>extra/tigervnc/tigervnc-1.16.2-arm-3_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;Patched with fixes for the following xorg-server security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/httpd-2.4.67-arm-2_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.67-arm-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes "HTTP/2 Bomb", a resource exhaustion denial-of-service<br>&nbsp;&nbsp;attack against HTTP/2.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://seclists.org/oss-sec/2026/q2/790<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-49975<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/net-tools-20181103_0eebece-arm-3_slack15.0.txz' rel='nofollow'>patches/packages/net-tools-20181103_0eebece-arm-3_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;interface.c: Stack-based Buffer Overflow in get_name().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2025-46836<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/proftpd-1.3.9b-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/proftpd-1.3.9b-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Additional fixes for SQL injection, notably for handling `%{env:...}`<br>&nbsp;&nbsp;and `%{note:...}` variables.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-42167<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-1.20.14-arm-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-1.20.14-arm-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xephyr-1.20.14-arm-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xephyr-1.20.14-arm-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xnest-1.20.14-arm-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xnest-1.20.14-arm-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xvfb-1.20.14-arm-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xvfb-1.20.14-arm-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/xorg-server-xwayland-21.1.4-arm-12_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xwayland-21.1.4-arm-12_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Jun 02 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 02 Jun 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1780387688</guid>
      <description><![CDATA[patches/packages/linux-5.15.209/*:&nbsp;&nbsp;Upgraded.<br>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;rxrpc: Fix missing validation of ticket length in non-XDR key preparsing<br>&nbsp;&nbsp;rxrpc: Fix anonymous key handling<br>&nbsp;&nbsp;rxrpc: only handle RESPONSE during service challenge<br>&nbsp;&nbsp;rxrpc: Fix recvmsg() unconditional requeue<br>&nbsp;&nbsp;rxrpc: reject undecryptable rxkad response tickets<br>&nbsp;&nbsp;rxrpc: Fix call removal to use RCU safe deletion<br>&nbsp;&nbsp;rxrpc: Fix key quota calculation for multitoken keys<br>&nbsp;&nbsp;rxrpc: proc: size address buffers for %pISpc output<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31696<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31676<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-23066<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31637<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31642<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31630<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue May 26 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 26 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1779782888</guid>
      <description><![CDATA[<br>Hello!<br><br>If you appreciate what we're doing with Slackware Linux on ARM, please consider<br>making a donation to support the project. Contributions go directly toward<br>maintaining essential build hardware, covering electricity costs, and keeping<br>this long-running labour of love alive and moving forward.<br>Every bit helps and is genuinely appreciated.<br><br>You can find out how to contribute here:<br>&nbsp;&nbsp;https://arm.slackware.com/sponsor/<br><br>Thank you for your continued support!<br><br>&nbsp;&nbsp;Stuart Winter &lt;mozes@slackware&gt;<br><br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/lxc-4.0.12-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/lxc-4.0.12-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Thanks to fourtysixandtwo.<br>]]></description>
    </item>
<item>
      <title>Mon May 25 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 25 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1779696488</guid>
      <description><![CDATA[patches/packages/linux-5.15.208/*:&nbsp;&nbsp;Upgraded.<br>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;net: skbuff: propagate shared-frag marker through frag-transfer helpers.<br>&nbsp;&nbsp;net: skbuff: preserve shared-frag marker during coalescing.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43503<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46300<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Thu May 21 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 21 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1779350888</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/bind-9.18.49-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/bind-9.18.49-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Fix outgoing zone transfers' quota issue.<br>&nbsp;&nbsp;Limit resolver server list size.<br>&nbsp;&nbsp;Fix GSS-API resource leak.<br>&nbsp;&nbsp;Avoid unbounded recursion loop.<br>&nbsp;&nbsp;Disable recursion, UPDATE, and NOTIFY for non-IN views.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-3592<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-3039<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3592<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3039<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5946<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/rsync-3.4.3-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/rsync-3.4.3-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;TOCTOU symlink race condition allowing local privilege escalation in daemon<br>&nbsp;&nbsp;mode without chroot.<br>&nbsp;&nbsp;Hostname/ACL bypass on an rsync daemon configured with `daemon chroot = /X`<br>&nbsp;&nbsp;in rsyncd.conf when the chroot tree lacks DNS resolution support.<br>&nbsp;&nbsp;Integer overflow in the compressed-token decoder enabling remote memory<br>&nbsp;&nbsp;disclosure to an authenticated daemon peer.<br>&nbsp;&nbsp;Symlink races on path-based system calls in "use chroot = no" daemon mode.<br>&nbsp;&nbsp;Out-of-bounds read in the receiver's recv_files() enabling remote<br>&nbsp;&nbsp;denial-of-service of any client pulling from a malicious server.<br>&nbsp;&nbsp;Off-by-one out-of-bounds stack write in the rsync client's HTTP CONNECT proxy<br>&nbsp;&nbsp;handler (`establish_proxy_connection()` in `socket.c`).<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29518<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43617<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43618<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43619<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43620<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45232<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Wed May 20 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 20 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1779264488</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/dcron-4.5-arm-9_slack15.0.txz' rel='nofollow'>patches/packages/dcron-4.5-arm-9_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Rebase the run-parts script on the latest version from Fedora's crontabs<br>&nbsp;&nbsp;package. Thanks to avian.<br>&nbsp;&nbsp;rc.crond: ensure world-writable permissions on /run/cron, needed for<br>&nbsp;&nbsp;crontab -e with some editors. Thanks to lostintime.<br>&nbsp;&nbsp;Add /etc/default/run-parts. Thanks to lostintime.<br>&nbsp;&nbsp;run-parts: don't redirect stderr to stdout. Thanks to Thom1b.<br>&nbsp;&nbsp;run-parts: skip *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;run-parts.8: document skiping *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;/etc/default/crond: Set the same minimal PATH that's provided by sysvinit at<br>&nbsp;&nbsp;boot time to keep things consistent when using rc.crond restart. This PATH<br>&nbsp;&nbsp;will be used both at boot and with a restart through rc.crond. Feel free to<br>&nbsp;&nbsp;adjust it if needed. Thanks to Ken Zalewski.<br><b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/haveged-1.9.21-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/haveged-1.9.21-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Missing exit out of permission check could lead to root exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-41054<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun May 17 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sun, 17 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1779005288</guid>
      <description><![CDATA[patches/packages/linux-5.15.207/*:&nbsp;&nbsp;Upgraded.<br>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sat May 16 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 16 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1778918888</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/dnsmasq-2.92rel2-arm-1_slack15.0.txz' rel='nofollow'>patches/packages/dnsmasq-2.92rel2-arm-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2291<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4890<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4891<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4892<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4893<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5172<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Wed May 13 08:08:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 13 May 2026 10:08:08 +0200</pubDate>
      <guid isPermaLink="false">1778659688</guid>
      <description><![CDATA[<b><a href='http://ftp.arm.slackware.com/slackwarearm/slackwarearm-15.0/patches/packages/expat-2.7.5-arm-2_slack15.0.txz' rel='nofollow'>patches/packages/expat-2.7.5-arm-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Fix quadratic runtime from attribute name collision checks that allowed<br>&nbsp;&nbsp;denial of service attacks through moderately sized crafted XML input<br>&nbsp;&nbsp;(CWE-407). Please note that a layer of compression around XML can<br>&nbsp;&nbsp;significantly reduce the minimum attack payload size.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45186<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
</channel>
</rss>