<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://www.sya54m.eu/ChangeLog-x86-15.0.xml" rel="self" type="application/rss+xml" />
    <title>Slackware-15.0 ChangeLog</title>
    <link>https://www.sya54m.eu</link>
    <description>Latest 20 entries in the Slackware-15.0 ChangeLog</description>
    <image>
      <url>https://www.sya54m.eu/immagini/s256.png</url>
      <title>Slackware-15.0 ChangeLog</title>
      <link>https://www.sya54m.eu</link>
    </image>
    <language>en</language>
    <pubDate>Mon, 13 Jul 2026 01:23:28 +0200</pubDate>
    <lastBuildDate>Wed, 15 Jul 2026 18:30:09 +0200</lastBuildDate>
    <generator>www.sya54m.eu</generator>
<item>
      <title>Sun Jul 12 23:23:28 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 13 Jul 2026 01:23:28 +0200</pubDate>
      <guid isPermaLink="false">1783898608</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/testing/packages/rust-1.97.0-i686-1_slack15.0.txz' rel='nofollow'>testing/packages/rust-1.97.0-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Add rustdoc to tools= in the bootstrap.toml because it no longer gets<br>&nbsp;&nbsp;installed otherwise.<br>&nbsp;&nbsp;Thanks to ZlatkO.<br>]]></description>
    </item>
<item>
      <title>Fri Jul 10 22:25:39 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 11 Jul 2026 00:25:39 +0200</pubDate>
      <guid isPermaLink="false">1783722339</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/p11-kit-0.26.4-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/p11-kit-0.26.4-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;server: fixed stack exhaustion via unbounded recursion in RPC attribute<br>&nbsp;&nbsp;parsing by enforcing a recursion depth limit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-13757<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Thu Jul  9 23:55:49 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 10 Jul 2026 01:55:49 +0200</pubDate>
      <guid isPermaLink="false">1783641349</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/glibc-zoneinfo-2026c-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/glibc-zoneinfo-2026c-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This package provides the latest timezone updates.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/extra/tigervnc/tigervnc-1.16.2-i586-4_slack15.0.txz' rel='nofollow'>extra/tigervnc/tigervnc-1.16.2-i586-4_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;Recompiled against xorg-server-1.20.14, including patches for<br>&nbsp;&nbsp;security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Wed Jul  8 21:48:24 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 08 Jul 2026 23:48:24 +0200</pubDate>
      <guid isPermaLink="false">1783547304</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/c-ares-1.34.8-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/c-ares-1.34.8-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libXfont2-2.0.8-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libXfont2-2.0.8-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow.<br>&nbsp;&nbsp;PCF Font Parsing Heap Buffer Overflow.<br>&nbsp;&nbsp;computeProps Property Buffer Heap Buffer Overflow.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062253.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56001<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56002<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56003<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/proftpd-1.3.9c-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/proftpd-1.3.9c-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;ExecEnviron values not passed due to regression since 1.3.8.d.<br>&nbsp;&nbsp;Stack buffer overflow in MLSD/MLST handling for long path names.<br>&nbsp;&nbsp;MaxTransfersPerUser no longer enforces configured limits.<br>&nbsp;&nbsp;AdminControlsACLs for config, get actions not honored as they should be.<br>&nbsp;&nbsp;Memcached/Redis-cached JSON TLS session/OCSP entries decoded into fixed<br>&nbsp;&nbsp;buffers without bounds checking.<br>&nbsp;&nbsp;RewriteMap unescape builtin use causes one-byte out-of-bounds write,<br>&nbsp;&nbsp;fails to reject illegal characters.<br>&nbsp;&nbsp;SQL group name lookup concatenates client-provided group names without<br>&nbsp;&nbsp;escaping.<br>&nbsp;&nbsp;Authenticated SFTP sessions can overflow the SFTP packet buffer.<br>&nbsp;&nbsp;Default Controls socket ACLs unintentionally allow all users access for<br>&nbsp;&nbsp;sending Controls requests.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-1.20.14-i586-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-1.20.14-i586-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xephyr-1.20.14-i586-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xephyr-1.20.14-i586-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xnest-1.20.14-i586-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xnest-1.20.14-i586-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xvfb-1.20.14-i586-21_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xvfb-1.20.14-i586-21_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xwayland-21.1.4-i586-19_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xwayland-21.1.4-i586-19_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;glamor Font Atlas Heap Buffer Overflow.<br>&nbsp;&nbsp;GLX contextTags Use-After-Free in CommonMakeCurrent().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-July/062255.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-55999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-56000<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Jul  7 21:49:57 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 07 Jul 2026 23:49:57 +0200</pubDate>
      <guid isPermaLink="false">1783460997</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/tftp-hpa-5.4-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/tftp-hpa-5.4-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;Fix several security-relevant bugs in path validation<br>&nbsp;&nbsp;(tftpd/path.c): an uninitialized buffer read and a broken<br>&nbsp;&nbsp;path tokenizer could let a crafted or unlucky request bypass<br>&nbsp;&nbsp;path restrictions or crash the daemon.<br>&nbsp;&nbsp;Fix buffer overflows in the tftp client: an unbounded strcpy()<br>&nbsp;&nbsp;when building requests, an out-of-bounds write when putting<br>&nbsp;&nbsp;multiple files to a remote directory, and an unbounded write<br>&nbsp;&nbsp;into the interactive command-line argument array.<br>&nbsp;&nbsp;Fix an out-of-bounds read while scanning request fields in<br>&nbsp;&nbsp;tftpd, and an incorrect address family used when creating the<br>&nbsp;&nbsp;per-transfer socket on platforms without recvmsg().<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon Jul  6 22:46:09 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 07 Jul 2026 00:46:09 +0200</pubDate>
      <guid isPermaLink="false">1783377969</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/c-ares-1.34.7-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/c-ares-1.34.7-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release fixes the following security issues:<br>&nbsp;&nbsp;Use-after-free / double-free in c-ares' query-completion handling, remotely<br>&nbsp;&nbsp;triggerable via ares_getaddrinfo() over TCP.<br>&nbsp;&nbsp;CPU-exhaustion denial of service via unbounded DNS name compression pointer<br>&nbsp;&nbsp;chains.<br>&nbsp;&nbsp;Memory-amplification denial of service via unvalidated DNS header record<br>&nbsp;&nbsp;counts.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33630<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openssh-10.4p1-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/openssh-10.4p1-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains a number of security fixes:<br>&nbsp;&nbsp;sftp(1): when downloading files on the command-line using<br>&nbsp;&nbsp;"sftp host:/path .", a malicious server could cause the file to<br>&nbsp;&nbsp;be downloaded to an unexpected location. This issue was identified<br>&nbsp;&nbsp;by the Swival Security Scanner.<br>&nbsp;&nbsp;scp(1): when copying files between two remote destinations, do<br>&nbsp;&nbsp;not allow a malicious server to write files to the parent<br>&nbsp;&nbsp;directory of the intended target directory.&nbsp;&nbsp;This issue was<br>&nbsp;&nbsp;identified by the Swival Security Scanner.<br>&nbsp;&nbsp;sshd(8): when using the "internal-sftp" SFTP server implementation<br>&nbsp;&nbsp;(this is not the default), long command lines were previously<br>&nbsp;&nbsp;truncated silently after the 9th argument. If a security-relevant<br>&nbsp;&nbsp;option was in the 10th or later position, it would be discarded.<br>&nbsp;&nbsp;Reported by Steve Caffrey.<br>&nbsp;&nbsp;sshd(8): add a documentation note to mention that the<br>&nbsp;&nbsp;GSSAPIStrictAcceptorCheck option is ineffective when the server<br>&nbsp;&nbsp;is joined to a Windows Active Directory. Reported by Yarin Aharoni<br>&nbsp;&nbsp;of Safebreach.<br>&nbsp;&nbsp;sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes<br>&nbsp;&nbsp;as it was documented to do. Note that PermitTunnel is not enabled<br>&nbsp;&nbsp;by default. Reported independently by Huzaifa Sidhpurwala of<br>&nbsp;&nbsp;Redhat and Marko Jevtic.<br>&nbsp;&nbsp;sshd(8): avoid a potential pre-authentication denial of service<br>&nbsp;&nbsp;when GSSAPIAuthentication was enabled (this feature is off by<br>&nbsp;&nbsp;default). This was not mitigated by MaxAuthTries, but would be<br>&nbsp;&nbsp;penalised by PerSourcePenalties. This was reported by Manfred<br>&nbsp;&nbsp;Kaiser of the milCERT AT (Austrian Ministry of Defence).<br>&nbsp;&nbsp;sshd(8): fix a number of cases where the minimum authentication<br>&nbsp;&nbsp;delay was not being enforced. Reported by the Orange Cyberdefense<br>&nbsp;&nbsp;Vulnerability Team.<br>&nbsp;&nbsp;ssh(1): fix a possible client-side use-after-free if the server<br>&nbsp;&nbsp;changes its host key during a key reexchange. This was reported by<br>&nbsp;&nbsp;Zhenpeng (Leo) Lin of Depthfirst.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.openssh.org/releasenotes.html#10.4<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun Jul  5 22:39:09 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 06 Jul 2026 00:39:09 +0200</pubDate>
      <guid isPermaLink="false">1783291149</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/extra/php82/php82-8.2.32-i586-1_slack15.0.txz' rel='nofollow'>extra/php82/php82-8.2.32-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;OpenSSL: Fixed memory corruption (zend_mm_heap corrupted) in<br>&nbsp;&nbsp;openssl_encrypt with AES-WRAP-PAD.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.php.net/ChangeLog-8.php#8.2.32<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-14355<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun Jul  5 21:18:31 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sun, 05 Jul 2026 23:18:31 +0200</pubDate>
      <guid isPermaLink="false">1783286311</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mutt-2.4.1-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/mutt-2.4.1-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Prevent unsigned int overflow in imap_cmd_step buffer growth.<br>&nbsp;&nbsp;The idata-&gt;blen field is unsigned int (32-bit) while the companion<br>&nbsp;&nbsp;variable len is size_t (64-bit on LP64). When a malicious IMAP server<br>&nbsp;&nbsp;sends a response line longer than UINT_MAX bytes without newline, the<br>&nbsp;&nbsp;expression wraps to a small value, causing safe_realloc() to shrink the<br>&nbsp;&nbsp;buffer while len retains its original huge value. The subsequent<br>&nbsp;&nbsp;mutt_socket_readln() then writes far past the shrunken allocation.<br>&nbsp;&nbsp;Fix by changing idata-&gt;blen from unsigned int to size_t, matching the<br>&nbsp;&nbsp;type of len and preventing the overflow on all platforms.<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri Jul  3 22:58:14 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 04 Jul 2026 00:58:14 +0200</pubDate>
      <guid isPermaLink="false">1783119494</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libseccomp-2.6.1-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libseccomp-2.6.1-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp;Fix incorrect 64-bit comparison merge that can weaken libseccomp filters.<br>&nbsp;&nbsp;Fix issue where oversized libseccomp filters can trigger a double free.<br>&nbsp;&nbsp;Fix issue where oversized libseccomp filters can trigger a heap corruption.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-4q85-33p6-j5g6<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-46fr-jh49-xvhx<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/seccomp/libseccomp/security/advisories/GHSA-2hqh-5c36-grrm`<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Wed Jul  1 23:55:11 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 02 Jul 2026 01:55:11 +0200</pubDate>
      <guid isPermaLink="false">1782950111</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libevent-2.1.13-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libevent-2.1.13-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains several security fixes, affecting users of the<br>&nbsp;&nbsp;following modules: evbuffer, bufferevent, evtag, evrpc, evdns, evhttp.<br>&nbsp;&nbsp;If you have a program that uses one of those modules you should upgrade.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.12.1esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.12.1esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.12.1esr/releasenotes/<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Jun 30 23:25:25 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 01 Jul 2026 01:25:25 +0200</pubDate>
      <guid isPermaLink="false">1782861925</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/gmime-3.2.15-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/gmime-3.2.15-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Thanks to Lockywolf.<br>]]></description>
    </item>
<item>
      <title>Thu Jun 25 21:03:32 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 25 Jun 2026 23:03:32 +0200</pubDate>
      <guid isPermaLink="false">1782421412</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/fetchmail-6.4.27-i586-3_slack15.0.txz' rel='nofollow'>patches/packages/fetchmail-6.4.27-i586-3_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This release contains an important bugfix:<br>&nbsp;&nbsp;The IMAP client, which has always used message indexes for the selected<br>&nbsp;&nbsp;mailbox, did not abort when receiving an EXPUNGE response - which changes<br>&nbsp;&nbsp;message numbers inside the mailbox.&nbsp;&nbsp;Unlike UIDs, the message numbers are<br>&nbsp;&nbsp;not stable and fetchmail does not have internal interfaces to track which<br>&nbsp;&nbsp;messages are deleted, and adding those to a 6.6.X release would be too<br>&nbsp;&nbsp;risky, and switching to UID is also too big a change, so we have no<br>&nbsp;&nbsp;choice but to abort the session when seeing an EXPUNGE response without<br>&nbsp;&nbsp;our own EXPUNGE request, to avoid marking the wrong message as seen/deleted<br>&nbsp;&nbsp;or skip the wrong one, or assume the wrong message size.<br>&nbsp;&nbsp;Earl Chew reported this versus Yahoo Mail via Gitlab Work Item #91, which<br>&nbsp;&nbsp;automatically expunges messages that are marked with the \Deleted flag.<br>]]></description>
    </item>
<item>
      <title>Tue Jun 23 23:52:16 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 24 Jun 2026 01:52:16 +0200</pubDate>
      <guid isPermaLink="false">1782258736</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libarchive-3.8.8-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libarchive-3.8.8-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Libarchive 3.8.8 is a security, bugfix and minor feature release.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/libarchive/libarchive/releases/tag/v3.8.8<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sat Jun 20 21:07:46 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 20 Jun 2026 23:07:46 +0200</pubDate>
      <guid isPermaLink="false">1781989666</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/ffmpeg-4.4.7-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/ffmpeg-4.4.7-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>]]></description>
    </item>
<item>
      <title>Thu Jun 18 21:09:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 18 Jun 2026 23:09:08 +0200</pubDate>
      <guid isPermaLink="false">1781816948</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libidn-1.44-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libidn-1.44-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Looks like I typoed the $BUILD number on the previous packages (1-slack15.0<br>&nbsp;&nbsp;instead of 1_slack15.0). That extra dash made it a malformed package name<br>&nbsp;&nbsp;and prevented it from being recognized as an upgrade to the libidn package.<br>&nbsp;&nbsp;This has been corrected. <br>&nbsp;&nbsp;Thanks to drumz for the report.<br>]]></description>
    </item>
<item>
      <title>Wed Jun 17 23:29:52 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 18 Jun 2026 01:29:52 +0200</pubDate>
      <guid isPermaLink="false">1781738992</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libinput-1.30.4-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libinput-1.30.4-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Switch to libinput-1.30.4 which contains the recent CVE fix, but does<br>&nbsp;&nbsp;not break the API so that wlroots won't build.<br>&nbsp;&nbsp;Thanks to falcon314.&nbsp;&nbsp;<br>]]></description>
    </item>
<item>
      <title>Wed Jun 17 21:45:03 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 17 Jun 2026 23:45:03 +0200</pubDate>
      <guid isPermaLink="false">1781732703</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/bind-9.18.50-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/bind-9.18.50-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Fix DNS64 owner case after DNAME restart.<br>&nbsp;&nbsp;When BIND 9 is configured to use DNS64 and encounters a DNAME<br>&nbsp;&nbsp;redirect, it could end up using freed memory for the DNS response<br>&nbsp;&nbsp;owner name. This caused the response to contain corrupted data. This<br>&nbsp;&nbsp;fix ensures the correct owner name is used when constructing the<br>&nbsp;&nbsp;synthesized response after a DNAME redirect.<br>&nbsp;&nbsp;ISC thanks Qifan Zhang of Palo Alto Networks for reporting the issue.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libidn-1.44-i586-1-slack15.0.txz' rel='nofollow'>patches/packages/libidn-1.44-i586-1-slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;libidn: Fix read-out-of-bounds error in ToUnicode APIs.<br>&nbsp;&nbsp;examples: Fix strcpy buffer overflow.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.gnu.org/archive/html/help-libidn/2025-06/msg00000.html<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.12.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.12.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.12.0/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-58<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12289<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12290<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12291<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12292<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12294<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12295<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12298<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12296<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12297<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12299<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12329<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12302<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12304<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12305<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12306<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12307<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12308<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12309<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12310<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12311<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12312<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12313<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12314<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12315<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12330<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12324<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12325<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12327<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12328<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.12.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.12.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.12.0esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-61/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12289<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12290<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12291<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12292<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12294<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12295<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12298<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12296<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12297<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12299<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12329<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12302<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12304<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12305<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12306<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12307<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12308<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12309<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12310<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12311<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12312<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12313<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12314<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12315<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12330<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12324<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12325<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12327<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-12328<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/net-tools-20181103_0eebece-i586-5_slack15.0.txz' rel='nofollow'>patches/packages/net-tools-20181103_0eebece-i586-5_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;The upstream patch for CVE-2025-46836 introduced a regression that broke<br>&nbsp;&nbsp;packet and byte reporting. Thanks to jtsn for a working alternate patch.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openssl-1.1.1zh-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/openssl-1.1.1zh-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Apply patch to fix the following security issues:<br>&nbsp;&nbsp;Heap Buffer Over-read in ASN.1 Content Parsing.<br>&nbsp;&nbsp;Possible NULL Dereference in Password-Based CMS Decryption.<br>&nbsp;&nbsp;Heap Use-After-Free in the PKCS7_verify() Function.<br>&nbsp;&nbsp;Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion.<br>&nbsp;&nbsp;Out-of-Bounds Read in CMS Password-Based Decryption.<br>&nbsp;&nbsp;These CVEs were fixed by the 1.1.1zh release that is only available to<br>&nbsp;&nbsp;subscribers to OpenSSL's premium extended support. The patch was prepared<br>&nbsp;&nbsp;by backporting from the OpenSSL-3.0 repo.<br>&nbsp;&nbsp;Thanks to Ken Zalewski for the patch!<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-34180<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-7383<br>&nbsp;&nbsp;&nbsp;&nbsp;https://openssl-library.org/news/vulnerabilities/#CVE-2026-9076<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34180<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-42766<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45447<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7383<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-9076<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/openssl-solibs-1.1.1zh-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/openssl-solibs-1.1.1zh-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>]]></description>
    </item>
<item>
      <title>Tue Jun 16 21:35:01 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 16 Jun 2026 23:35:01 +0200</pubDate>
      <guid isPermaLink="false">1781645701</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/ca-certificates-20260616-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/ca-certificates-20260616-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update provides the latest CA certificates to check for the<br>&nbsp;&nbsp;authenticity of SSL connections.<br>]]></description>
    </item>
<item>
      <title>Mon Jun 15 23:27:31 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 16 Jun 2026 01:27:31 +0200</pubDate>
      <guid isPermaLink="false">1781566051</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/dev86-0.16.21-i586-5_slack15.0.txz' rel='nofollow'>patches/packages/dev86-0.16.21-i586-5_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;bcc: patched to account for ${LIBDIRSUFFIX}.<br>&nbsp;&nbsp;Thanks to tauon.<br>]]></description>
    </item>
<item>
      <title>Wed Jun 10 20:15:05 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 10 Jun 2026 22:15:05 +0200</pubDate>
      <guid isPermaLink="false">1781122505</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/httpd-2.4.68-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.68-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release (CVE-2026-49975 was already patched here.)<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://downloads.apache.org/httpd/CHANGES_2.4.68<br>]]></description>
    </item>
</channel>
</rss>