<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://www.sya54m.eu/ChangeLog-x86-15.0.xml" rel="self" type="application/rss+xml" />
    <title>Slackware-15.0 ChangeLog</title>
    <link>https://www.sya54m.eu</link>
    <description>Latest 20 entries in the Slackware-15.0 ChangeLog</description>
    <image>
      <url>https://www.sya54m.eu/immagini/s256.png</url>
      <title>Slackware-15.0 ChangeLog</title>
      <link>https://www.sya54m.eu</link>
    </image>
    <language>en</language>
    <pubDate>Wed, 20 May 2026 01:45:24 +0200</pubDate>
    <lastBuildDate>Wed, 20 May 2026 18:30:09 +0200</lastBuildDate>
    <generator>www.sya54m.eu</generator>
<item>
      <title>Tue May 19 23:45:24 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 20 May 2026 01:45:24 +0200</pubDate>
      <guid isPermaLink="false">1779234324</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/haveged-1.9.21-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/haveged-1.9.21-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Missing exit out of permission check could lead to root exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-41054<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.11.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.11.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.11.0/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-48<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8388<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8391<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8401<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8949<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8953<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8954<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8955<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8956<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8957<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8958<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8959<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8961<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8962<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8968<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8970<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8974<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8975<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.11.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.11.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.11.0esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-51/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8388<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8391<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8401<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8949<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8953<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8954<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8955<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8956<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8957<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8958<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8959<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8961<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8962<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8968<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8970<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8974<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8975<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun May 17 23:23:26 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 18 May 2026 01:23:26 +0200</pubDate>
      <guid isPermaLink="false">1779060206</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/dcron-4.5-i586-14_slack15.0.txz' rel='nofollow'>patches/packages/dcron-4.5-i586-14_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Rebase the run-parts script on the latest version from Fedora's crontabs<br>&nbsp;&nbsp;package. Thanks to avian.<br>&nbsp;&nbsp;rc.crond: ensure world-writable permissions on /run/cron, needed for<br>&nbsp;&nbsp;crontab -e with some editors. Thanks to lostintime.<br>&nbsp;&nbsp;Add /etc/default/run-parts. Thanks to lostintime.<br>&nbsp;&nbsp;run-parts: don't redirect stderr to stdout. Thanks to Thom1b.<br>&nbsp;&nbsp;run-parts: skip *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;run-parts.8: document skiping *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;/etc/default/crond: Set the same minimal PATH that's provided by sysvinit at<br>&nbsp;&nbsp;boot time to keep things consistent when using rc.crond restart. This PATH<br>&nbsp;&nbsp;will be used both at boot and with a restart through rc.crond. Feel free to<br>&nbsp;&nbsp;adjust it if needed. Thanks to Ken Zalewski.<br>]]></description>
    </item>
<item>
      <title>Sat May 16 02:48:04 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 16 May 2026 04:48:04 +0200</pubDate>
      <guid isPermaLink="false">1778899684</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/dnsmasq-2.92rel2-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/dnsmasq-2.92rel2-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2291<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4890<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4891<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4892<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4893<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5172<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-generic-5.15.207-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-generic-5.15.207-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-generic-smp-5.15.207_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-generic-smp-5.15.207_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-headers-5.15.207_smp-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-headers-5.15.207_smp-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-huge-5.15.207-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-huge-5.15.207-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-huge-smp-5.15.207_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-huge-smp-5.15.207_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-modules-5.15.207-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-modules-5.15.207-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-modules-smp-5.15.207_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-modules-smp-5.15.207_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.207/kernel-source-5.15.207_smp-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-source-5.15.207_smp-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Tue May 12 02:16:39 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 12 May 2026 04:16:39 +0200</pubDate>
      <guid isPermaLink="false">1778552199</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/expat-2.7.5-i586-2_slack15.0.txz' rel='nofollow'>patches/packages/expat-2.7.5-i586-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Fix quadratic runtime from attribute name collision checks that allowed<br>&nbsp;&nbsp;denial of service attacks through moderately sized crafted XML input<br>&nbsp;&nbsp;(CWE-407). Please note that a layer of compression around XML can<br>&nbsp;&nbsp;significantly reduce the minimum attack payload size.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45186<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sat May  9 21:25:03 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 09 May 2026 23:25:03 +0200</pubDate>
      <guid isPermaLink="false">1778361903</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-generic-5.15.206-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-generic-5.15.206-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-generic-smp-5.15.206_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-generic-smp-5.15.206_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-headers-5.15.206_smp-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-headers-5.15.206_smp-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-huge-5.15.206-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-huge-5.15.206-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-huge-smp-5.15.206_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-huge-smp-5.15.206_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-modules-5.15.206-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-modules-5.15.206-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a regression in Linux 5.15.205:<br>&nbsp;&nbsp;xfrm: esp: ipv4: fix up flags setting.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-modules-smp-5.15.206_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-modules-smp-5.15.206_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a regression in Linux 5.15.205:<br>&nbsp;&nbsp;xfrm: esp: ipv4: fix up flags setting.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.206/kernel-source-5.15.206_smp-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-source-5.15.206_smp-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Fri May  8 22:14:25 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 09 May 2026 00:14:25 +0200</pubDate>
      <guid isPermaLink="false">1778278465</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-generic-5.15.205-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-generic-5.15.205-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-generic-smp-5.15.205_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-generic-smp-5.15.205_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-headers-5.15.205_smp-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-headers-5.15.205_smp-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-huge-5.15.205-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-huge-5.15.205-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-huge-smp-5.15.205_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-huge-smp-5.15.205_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-modules-5.15.205-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-modules-5.15.205-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;xfrm: esp: avoid in-place decrypt on shared skb frags.<br>&nbsp;&nbsp;This update addresses a Linux kernel local privilege escalation attack known<br>&nbsp;&nbsp;as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that<br>&nbsp;&nbsp;is not yet patched upstream.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away you may blacklist or remove the kernel modules esp4.ko and esp6.ko<br>&nbsp;&nbsp;(CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).<br>&nbsp;&nbsp;Also remove the modules from the kernel if they have been loaded:<br>&nbsp;&nbsp;&nbsp;&nbsp;rmmod esp4 esp6 rxrpc<br>&nbsp;&nbsp;And, drop the file caches in case in-memory program copies have already<br>&nbsp;&nbsp;been compromised. Make sure possibly affected programs do not have any<br>&nbsp;&nbsp;open sessions first:<br>&nbsp;&nbsp;&nbsp;&nbsp;sh -c "echo 3 &gt; /proc/sys/vm/drop_caches"<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/V4bel/dirtyfrag<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43284<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-modules-smp-5.15.205_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-modules-smp-5.15.205_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;xfrm: esp: avoid in-place decrypt on shared skb frags.<br>&nbsp;&nbsp;This update addresses a Linux kernel local privilege escalation attack known<br>&nbsp;&nbsp;as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that<br>&nbsp;&nbsp;is not yet patched upstream.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away you may blacklist or remove the kernel modules esp4.ko and esp6.ko<br>&nbsp;&nbsp;(CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).<br>&nbsp;&nbsp;Also remove the modules from the kernel if they have been loaded:<br>&nbsp;&nbsp;&nbsp;&nbsp;rmmod esp4 esp6 rxrpc<br>&nbsp;&nbsp;And, drop the file caches in case in-memory program copies have already<br>&nbsp;&nbsp;been compromised. Make sure possibly affected programs do not have any<br>&nbsp;&nbsp;open sessions first:<br>&nbsp;&nbsp;&nbsp;&nbsp;sh -c "echo 3 &gt; /proc/sys/vm/drop_caches"<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/V4bel/dirtyfrag<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43284<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.205/kernel-source-5.15.205_smp-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-source-5.15.205_smp-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.10.2esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.10.2esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.10.2esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-44/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8090<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8094<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8092<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri May  8 05:00:03 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 08 May 2026 07:00:03 +0200</pubDate>
      <guid isPermaLink="false">1778216403</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/extra/php82/php82-8.2.31-i586-1_slack15.0.txz' rel='nofollow'>extra/php82/php82-8.2.31-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;FPM: Fixed XSS within status endpoint.<br>&nbsp;&nbsp;MBString: Fixed Null pointer dereference in php_mb_check_encoding()<br>&nbsp;&nbsp;via mb_ereg_search_init().<br>&nbsp;&nbsp;PDO_Firebird: Fixed SQL injection via NUL bytes in quoted strings.<br>&nbsp;&nbsp;SOAP: Fixed Stale SOAP_GLOBAL(ref_map) pointer with Apache Map.<br>&nbsp;&nbsp;SOAP: Fixed Use-after-free after header parsing failure with<br>&nbsp;&nbsp;SOAP_PERSISTENCE_SESSION.<br>&nbsp;&nbsp;SOAP: Fixed Broken Apache map value NULL check.<br>&nbsp;&nbsp;Standard: Fixed Signed integer overflow of char array offset.<br>&nbsp;&nbsp;Standard: Fixed Consistently pass unsigned char to ctype.h functions.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.php.net/ChangeLog-8.php#8.2.31<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6735<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7259<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2025-14179<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6722<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7261<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7262<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7568<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7258<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libgpg-error-1.61-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libgpg-error-1.61-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp; Fix possible stack overflow in es_printf for %.100f format.<br>&nbsp;&nbsp; Fix out-of-bounds read in vfnameconcat.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.10.2esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.10.2esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.10.2/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-41<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8090<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8094<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8092<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue May  5 20:12:56 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 05 May 2026 22:12:56 +0200</pubDate>
      <guid isPermaLink="false">1778011976</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/hunspell-1.7.3-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/hunspell-1.7.3-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/hunspell/hunspell/releases/tag/v1.7.3<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon May  4 22:37:35 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 05 May 2026 00:37:35 +0200</pubDate>
      <guid isPermaLink="false">1777934255</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/httpd-2.4.67-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.67-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release fixes bugs and the following security issues:<br>&nbsp;&nbsp;mod_proxy_ajp: Heap Over-Read and memory disclosure in&nbsp;&nbsp;ajp_parse_data().<br>&nbsp;&nbsp;mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check.<br>&nbsp;&nbsp;Off-by-one OOB reads in AJP getter functions.<br>&nbsp;&nbsp;HTTP response splitting forwarding malicious status line.<br>&nbsp;&nbsp;mod_authn_socache crash.<br>&nbsp;&nbsp;mod_auth_digest timing attack.<br>&nbsp;&nbsp;mod_md unrestricted OCSP response.<br>&nbsp;&nbsp;buffer overflow in mod_proxy_ajp via ajp_msg_check_header().<br>&nbsp;&nbsp;mod_rewrite elevation of privileges via ap_expr.<br>&nbsp;&nbsp;http2: double free and possible RCE on early reset.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://downloads.apache.org/httpd/CHANGES_2.4.67<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34059<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34032<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33857<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33523<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33007<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33006<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29169<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29168<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-28780<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-24072<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-23918<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun May  3 01:36:26 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sun, 03 May 2026 03:36:26 +0200</pubDate>
      <guid isPermaLink="false">1777772186</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/gnutls-3.8.13-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/gnutls-3.8.13-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Add more checks to DTLS reassembly. Previously, gnutls didn't check that<br>&nbsp;&nbsp;DTLS fragments claimed a consistent message_length value. Additionally,<br>&nbsp;&nbsp;a crucial array size check was missing, enabling an attacker to cause a<br>&nbsp;&nbsp;heap overwrite. Reject fragments with mismatching length and add a missing<br>&nbsp;&nbsp;boundary check. Independently reported by Haruto Kimura (Stella), Oscar<br>&nbsp;&nbsp;Reparaz and Zou Dikai.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33846<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-generic-5.15.204-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-generic-5.15.204-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-generic-smp-5.15.204_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-generic-smp-5.15.204_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-headers-5.15.204_smp-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-headers-5.15.204_smp-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-huge-5.15.204-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-huge-5.15.204-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-huge-smp-5.15.204_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-huge-smp-5.15.204_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-modules-5.15.204-i586-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-modules-5.15.204-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-modules-smp-5.15.204_smp-i686-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-modules-smp-5.15.204_smp-i686-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;An out-of-bounds write in the userspace interface for AEAD cipher algorithms<br>&nbsp;&nbsp;may be leveraged to get a root shell through a setuid binary. While the<br>&nbsp;&nbsp;proof of concepts for this have so far targeted different program versions<br>&nbsp;&nbsp;than Slackware uses, there's nothing preventing anyone from targeting one<br>&nbsp;&nbsp;a setuid binary that we use.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove<br>&nbsp;&nbsp;the algif_aead.ko kernel module to prevent the exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://copy.fail/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31431<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/linux-5.15.204/kernel-source-5.15.204_smp-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.204/kernel-source-5.15.204_smp-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.10.1esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.10.1esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.10.1esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-39/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7320<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7321<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7322<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7323<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri May  1 19:44:58 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 01 May 2026 21:44:58 +0200</pubDate>
      <guid isPermaLink="false">1777664698</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.10.1esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.10.1esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.10.1/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-36<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7320<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7321<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7322<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7323<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Apr 28 05:57:29 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 28 Apr 2026 07:57:29 +0200</pubDate>
      <guid isPermaLink="false">1777355849</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/cups-2.4.19-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/cups-2.4.19-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Fixed a regression in shared printing from non-local accounts (Issue #1557).<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/proftpd-1.3.9a-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/proftpd-1.3.9a-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Fix for an SQL injection that may lead to authentication bypass, privilege<br>&nbsp;&nbsp;escalation, and arbitrary code execution. Slackware does not build mol_sql,<br>&nbsp;&nbsp;but this may be an important upgrade for those rebuilding proftpd in order<br>&nbsp;&nbsp;to add this module.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-42167<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon Apr 27 22:56:19 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 28 Apr 2026 00:56:19 +0200</pubDate>
      <guid isPermaLink="false">1777330579</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mpg123-1.33.5-i586-1.txz' rel='nofollow'>patches/packages/mpg123-1.33.5-i586-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;mpg123: Fix generic control mode for largefile-sensitive builds, where 32 bit<br>&nbsp;&nbsp;off_t was used with mpg123 API calls expecting 64 bit off_t.<br>&nbsp;&nbsp;I am appalled that it took a user on 32 bit ARM and a specific https stream<br>&nbsp;&nbsp;to notice this (bug 385, regression since 1.32.0).<br>&nbsp;&nbsp;The security impact of this could be serious, with memory corruption<br>&nbsp;&nbsp;including segfault being observed.<br>&nbsp;&nbsp;mpg123-id3dump, out123: Enable 64 bit offset usage on largefile-sensitive<br>&nbsp;&nbsp;platforms (regression since 1.32.0).<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri Apr 24 18:56:04 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 24 Apr 2026 20:56:04 +0200</pubDate>
      <guid isPermaLink="false">1777056964</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/cups-2.4.18-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/cups-2.4.18-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Fixed cupsd crash if user does not exist (Issue #1555).<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/glibc-zoneinfo-2026b-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/glibc-zoneinfo-2026b-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This package provides the latest timezone updates.<br>]]></description>
    </item>
<item>
      <title>Wed Apr 22 00:29:07 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 22 Apr 2026 02:29:07 +0200</pubDate>
      <guid isPermaLink="false">1776817747</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libXpm-3.5.19-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libXpm-3.5.19-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Out-of-bounds read in xpmNextWord().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg-devel/2026-April/059452.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4367<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-firefox-140.10.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.10.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.10.0/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-32/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6746<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6747<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6748<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6749<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6750<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6751<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6752<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6753<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6754<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6757<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6759<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6761<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6762<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6763<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6764<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6765<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6766<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6767<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6769<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6770<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6771<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6772<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6776<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6785<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6786<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/mozilla-thunderbird-140.10.0esr-i686-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.10.0esr-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.10.0esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird140.10<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun Apr 19 00:05:42 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sun, 19 Apr 2026 02:05:42 +0200</pubDate>
      <guid isPermaLink="false">1776557142</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/extra/tigervnc/tigervnc-1.16.2-i586-2_slack15.0.txz' rel='nofollow'>extra/tigervnc/tigervnc-1.16.2-i586-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;Rebuilt against xorg-server-1.20.14 patched to fix security issues:<br>&nbsp;&nbsp;XKB Integer Underflow in XkbSetCompatMap().<br>&nbsp;&nbsp;XKB Out-of-bounds Read in CheckSetGeom().<br>&nbsp;&nbsp;XSYNC Use-after-free in miSyncTriggerFence().<br>&nbsp;&nbsp;XKB Out-of-bounds read in CheckModifierMap().<br>&nbsp;&nbsp;XKB Buffer overflow in CheckKeyTypes().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg-devel/2026-April/059446.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34000<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34001<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34002<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34003<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri Apr 17 21:28:08 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 17 Apr 2026 23:28:08 +0200</pubDate>
      <guid isPermaLink="false">1776461288</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/cups-2.4.17-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/cups-2.4.17-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;The scheduler treated local user and group names as case-insensitive.<br>&nbsp;&nbsp;The RSS notifier could write outside the scheduler's RSS directory.<br>&nbsp;&nbsp;The scheduler did not filter control characters from option values.<br>&nbsp;&nbsp;The scheduler did not always allocate enough memory for a job's options<br>&nbsp;&nbsp;string.<br>&nbsp;&nbsp;The scheduler incorrectly allowed local certificates over the loopback<br>&nbsp;&nbsp;interface.<br>&nbsp;&nbsp;Fixed the range check for job password strings.<br>&nbsp;&nbsp;Fixed a printer subscription bug in the scheduler.<br>&nbsp;&nbsp;Fixed a SNMP string conversion bug in the backends.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-27447<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34978<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34980<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34979<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34990<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-39314<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-39316<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/testing/packages/rust-1.95.0-i686-1_slack15.0.txz' rel='nofollow'>testing/packages/rust-1.95.0-i686-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>]]></description>
    </item>
<item>
      <title>Thu Apr 16 22:36:54 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 17 Apr 2026 00:36:54 +0200</pubDate>
      <guid isPermaLink="false">1776379014</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libpng-1.6.58-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libpng-1.6.58-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Fixed a regression introduced in version 1.6.56 that caused `png_get_PLTE`<br>&nbsp;&nbsp;to return stale palette data after applying gamma and background transforms<br>&nbsp;&nbsp;in-place.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libxml2-2.11.9-i586-9_slack15.0.txz' rel='nofollow'>patches/packages/libxml2-2.11.9-i586-9_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;entities: copy children in xmlCopyEntity.<br>&nbsp;&nbsp;c14n: Fix Type confusion in xmlC14NProcessAttrsAxis.<br>&nbsp;&nbsp;python: Do not decref string after adding to the list<br>&nbsp;&nbsp;(double-free / use-after-free).<br>&nbsp;&nbsp;c14n: Reuse tmp_str, xmlStrcat reallocates *cur (double-free).<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue Apr 14 22:07:31 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 15 Apr 2026 00:07:31 +0200</pubDate>
      <guid isPermaLink="false">1776204451</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libexif-0.6.26-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libexif-0.6.26-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;An unsigned integer underflow in Fuji and Olympus makernote handling.<br>&nbsp;&nbsp;An unsigned integer overflow on 32bit systems in Nikon makernote handling.<br>&nbsp;&nbsp;A buffer overwrite via integer underflow in makernote handling.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-40386<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-40385<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-32775<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-1.20.14-i586-19_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-1.20.14-i586-19_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;XKB Integer Underflow in XkbSetCompatMap().<br>&nbsp;&nbsp;XKB Out-of-bounds Read in CheckSetGeom().<br>&nbsp;&nbsp;XSYNC Use-after-free in miSyncTriggerFence().<br>&nbsp;&nbsp;XKB Out-of-bounds read in CheckModifierMap().<br>&nbsp;&nbsp;XKB Buffer overflow in CheckKeyTypes().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg-devel/2026-April/059446.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34000<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34001<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34002<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34003<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xephyr-1.20.14-i586-19_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xephyr-1.20.14-i586-19_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xnest-1.20.14-i586-19_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xnest-1.20.14-i586-19_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xvfb-1.20.14-i586-19_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xvfb-1.20.14-i586-19_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/xorg-server-xwayland-21.1.4-i586-17_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xwayland-21.1.4-i586-17_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;XKB Integer Underflow in XkbSetCompatMap().<br>&nbsp;&nbsp;XKB Out-of-bounds Read in CheckSetGeom().<br>&nbsp;&nbsp;XSYNC Use-after-free in miSyncTriggerFence().<br>&nbsp;&nbsp;XKB Out-of-bounds read in CheckModifierMap().<br>&nbsp;&nbsp;XKB Buffer overflow in CheckKeyTypes().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg-devel/2026-April/059446.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33999<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34000<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34001<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34002<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34003<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon Apr 13 21:39:25 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 13 Apr 2026 23:39:25 +0200</pubDate>
      <guid isPermaLink="false">1776116365</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/ca-certificates-20260413-noarch-1_slack15.0.txz' rel='nofollow'>patches/packages/ca-certificates-20260413-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update provides the latest CA certificates to check for the<br>&nbsp;&nbsp;authenticity of SSL connections.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/libarchive-3.8.7-i586-1_slack15.0.txz' rel='nofollow'>patches/packages/libarchive-3.8.7-i586-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Libarchive 3.8.7 is a security and bugfix release.<br>&nbsp;&nbsp;Notable fixes:<br>&nbsp;&nbsp;CAB: fix NULL pointer dereference during skip (#2900)<br>&nbsp;&nbsp;CAB: Fix Heap OOB Write in CAB LZX decoder (#2919)<br>&nbsp;&nbsp;cpio: various fixes and improvements (#2899, #2908, #2910, #2939)<br>&nbsp;&nbsp;contrib/untar: fix out-of-bounds read (#2903)<br>&nbsp;&nbsp;iso9660: fix undefined behavior (#2897)<br>&nbsp;&nbsp;iso9660: fix posibble heap buffer overflow on 32-bit systems (#2934)<br>&nbsp;&nbsp;libarchive: fix handling of option failures (#2871)<br>&nbsp;&nbsp;libarchive: do not continue with truncated numbers (#2911)<br>&nbsp;&nbsp;libarchive: lzop and grzip filter support (#2947)<br>&nbsp;&nbsp;RAR: fix LZSS window size mismatch after PPMd block (#2898)<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
</channel>
</rss>