<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://www.sya54m.eu/ChangeLog-x86_64-15.0.xml" rel="self" type="application/rss+xml" />
    <title>Slackware64-15.0 ChangeLog</title>
    <link>https://www.sya54m.eu</link>
    <description>Latest 20 entries in the Slackware64-15.0 ChangeLog</description>
    <image>
      <url>https://www.sya54m.eu/immagini/s256.png</url>
      <title>Slackware64-15.0 ChangeLog</title>
      <link>https://www.sya54m.eu</link>
    </image>
    <language>en</language>
    <pubDate>Wed, 10 Jun 2026 22:15:05 +0200</pubDate>
    <lastBuildDate>Fri, 12 Jun 2026 19:30:06 +0200</lastBuildDate>
    <generator>www.sya54m.eu</generator>
<item>
      <title>Wed Jun 10 20:15:05 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 10 Jun 2026 22:15:05 +0200</pubDate>
      <guid isPermaLink="false">1781122505</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/httpd-2.4.68-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.68-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release (CVE-2026-49975 was already patched here.)<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://downloads.apache.org/httpd/CHANGES_2.4.68<br>]]></description>
    </item>
<item>
      <title>Tue Jun  9 21:03:28 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 09 Jun 2026 23:03:28 +0200</pubDate>
      <guid isPermaLink="false">1781039008</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/testing/packages/autoconf-2.73-noarch-1_slack15.0.txz' rel='nofollow'>testing/packages/autoconf-2.73-noarch-1_slack15.0.txz</a>:&nbsp;&nbsp;Added.<br></b>]]></description>
    </item>
<item>
      <title>Mon Jun  8 20:41:30 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 08 Jun 2026 22:41:30 +0200</pubDate>
      <guid isPermaLink="false">1780951290</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/rsync-3.4.4-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/rsync-3.4.4-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Rsync version 3.4.4 has been released. This is a regression fix release for<br>&nbsp;&nbsp;the issues that have been reported with the 3.4.3 security release. Many<br>&nbsp;&nbsp;thanks to everyone who reported the issues (see NEWS.md for credits).<br>&nbsp;&nbsp;The 3.4.3 release had so many issues for two main reasons:<br>&nbsp;&nbsp;* the 3.4 testsuite did not have broad enough coverage to catch the<br>&nbsp;&nbsp;&nbsp;&nbsp;regressions noticed by users<br>&nbsp;&nbsp;* the nature of a security release prevents wide beta testing, resulting in<br>&nbsp;&nbsp;&nbsp;&nbsp;not enough manual testing in disparate environments<br>&nbsp;&nbsp;To fix this for future releases we have greatly expanded the test suite for<br>&nbsp;&nbsp;3.5 (currently in master) and grown the development team, especially with<br>&nbsp;&nbsp;more people with security expertise. Thanks for your patience!<br>]]></description>
    </item>
<item>
      <title>Sun Jun  7 22:20:12 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 08 Jun 2026 00:20:12 +0200</pubDate>
      <guid isPermaLink="false">1780870812</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/extra/samba-4.22.10-x86_64-1_slack15.0.txz' rel='nofollow'>extra/samba-4.22.10-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a security release in order to address the following defects:<br>&nbsp;&nbsp;Missing access checks on reparse point operations.<br>&nbsp;&nbsp;WORM vfs module does not block overwrites.<br>&nbsp;&nbsp;auto-enrolment GPO installing CA certificate over http without verification.<br>&nbsp;&nbsp;Denial of service against AD DC WINS server.<br>&nbsp;&nbsp;Unauthenticated Remote Code Execution in Samba DCE/RPC SAMR server.<br>&nbsp;&nbsp;Unauthenticated Remote Code Execution in Samba printing subsystem.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-1933.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-2340.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-3012.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-3238.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-4408.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.samba.org/samba/security/CVE-2026-4480.html<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-1933<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2340<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3012<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3238<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4408<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4480<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Thu Jun  4 21:45:06 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 04 Jun 2026 23:45:06 +0200</pubDate>
      <guid isPermaLink="false">1780609506</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/dnsmasq-2.93-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/dnsmasq-2.93-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Rework storage allocation for domain names. This fixes a security bug that<br>&nbsp;&nbsp;can cause heap-overwrite with long domain names.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2291<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libinput-1.31.3-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/libinput-1.31.3-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;libinput-device-group unescaped phys output can inject udev properties<br>&nbsp;&nbsp;leading to arbitrary root code execution.<br>&nbsp;&nbsp;Note that since /dev/uinput and /dev/uhid are only accessible by root on<br>&nbsp;&nbsp;Slackware (and unlike some other distributions we make no exceptions), we<br>&nbsp;&nbsp;were not vulnerable to this flaw.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/meson-1.11.1-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/meson-1.11.1-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is needed to compile libinput-1.31.3.<br>]]></description>
    </item>
<item>
      <title>Thu Jun  4 01:22:28 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 04 Jun 2026 03:22:28 +0200</pubDate>
      <guid isPermaLink="false">1780536148</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/extra/tigervnc/tigervnc-1.16.2-x86_64-3_slack15.0.txz' rel='nofollow'>extra/tigervnc/tigervnc-1.16.2-x86_64-3_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;Patched with fixes for the following xorg-server security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/httpd-2.4.67-x86_64-2_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.67-x86_64-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes "HTTP/2 Bomb", a resource exhaustion denial-of-service<br>&nbsp;&nbsp;attack against HTTP/2.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://seclists.org/oss-sec/2026/q2/790<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-49975<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/net-tools-20181103_0eebece-x86_64-4_slack15.0.txz' rel='nofollow'>patches/packages/net-tools-20181103_0eebece-x86_64-4_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;interface.c: Stack-based Buffer Overflow in get_name().<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2025-46836<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/proftpd-1.3.9b-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/proftpd-1.3.9b-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Additional fixes for SQL injection, notably for handling `%{env:...}`<br>&nbsp;&nbsp;and `%{note:...}` variables.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-42167<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/xorg-server-1.20.14-x86_64-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-1.20.14-x86_64-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;DRI2 DRIGetBuffers/DRIGetBuffersWithFormat Out-Of-Bounds Write.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/xorg-server-xephyr-1.20.14-x86_64-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xephyr-1.20.14-x86_64-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/xorg-server-xnest-1.20.14-x86_64-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xnest-1.20.14-x86_64-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/xorg-server-xvfb-1.20.14-x86_64-20_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xvfb-1.20.14-x86_64-20_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/xorg-server-xwayland-21.1.4-x86_64-18_slack15.0.txz' rel='nofollow'>patches/packages/xorg-server-xwayland-21.1.4-x86_64-18_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Font Alias Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in miSyncDestroyFence().<br>&nbsp;&nbsp;XKB Key Types Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XKB SetMap Request Stack-based Buffer Overflow.<br>&nbsp;&nbsp;XSYNC Use-After-Free in FreeCounter().<br>&nbsp;&nbsp;XSYNC Use-After-Free in SyncChangeCounter().<br>&nbsp;&nbsp;GLX ChangeDrawableAttributes Out-Of-Bounds Read/Write.<br>&nbsp;&nbsp;CreateSaverWindow Use-After-Free Information Disclosure.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://lists.x.org/archives/xorg/2026-June/062239.html<br>&nbsp;&nbsp;&nbsp;&nbsp;Zero Day Initiative identifiers:<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30136<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30159<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30160<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30161<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30163<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30164<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30165<br>&nbsp;&nbsp;&nbsp;&nbsp;ZDI-CAN-30168<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/testing/packages/openrsync-20250126_a257c0f-x86_64-1_slack15.0.txz' rel='nofollow'>testing/packages/openrsync-20250126_a257c0f-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Added.<br></b>]]></description>
    </item>
<item>
      <title>Tue Jun  2 02:32:11 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 02 Jun 2026 04:32:11 +0200</pubDate>
      <guid isPermaLink="false">1780367531</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.209/kernel-generic-5.15.209-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.209/kernel-generic-5.15.209-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;rxrpc: Fix missing validation of ticket length in non-XDR key preparsing<br>&nbsp;&nbsp;rxrpc: Fix anonymous key handling<br>&nbsp;&nbsp;rxrpc: only handle RESPONSE during service challenge<br>&nbsp;&nbsp;rxrpc: Fix recvmsg() unconditional requeue<br>&nbsp;&nbsp;rxrpc: reject undecryptable rxkad response tickets<br>&nbsp;&nbsp;rxrpc: Fix call removal to use RCU safe deletion<br>&nbsp;&nbsp;rxrpc: Fix key quota calculation for multitoken keys<br>&nbsp;&nbsp;rxrpc: proc: size address buffers for %pISpc output<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31696<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31676<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-23066<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31637<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31642<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31630<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.209/kernel-headers-5.15.209-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.209/kernel-headers-5.15.209-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.209/kernel-huge-5.15.209-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.209/kernel-huge-5.15.209-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;rxrpc: Fix missing validation of ticket length in non-XDR key preparsing<br>&nbsp;&nbsp;rxrpc: Fix anonymous key handling<br>&nbsp;&nbsp;rxrpc: only handle RESPONSE during service challenge<br>&nbsp;&nbsp;rxrpc: Fix recvmsg() unconditional requeue<br>&nbsp;&nbsp;rxrpc: reject undecryptable rxkad response tickets<br>&nbsp;&nbsp;rxrpc: Fix call removal to use RCU safe deletion<br>&nbsp;&nbsp;rxrpc: Fix key quota calculation for multitoken keys<br>&nbsp;&nbsp;rxrpc: proc: size address buffers for %pISpc output<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31696<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31676<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-23066<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31637<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31642<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-31630<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.209/kernel-modules-5.15.209-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.209/kernel-modules-5.15.209-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.209/kernel-source-5.15.209-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.209/kernel-source-5.15.209-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Tue May 26 23:17:58 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 27 May 2026 01:17:58 +0200</pubDate>
      <guid isPermaLink="false">1779837478</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-thunderbird-140.11.1esr-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.11.1esr-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.11.1esr/releasenotes/<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun May 24 20:43:18 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sun, 24 May 2026 22:43:18 +0200</pubDate>
      <guid isPermaLink="false">1779655398</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.208/kernel-generic-5.15.208-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.208/kernel-generic-5.15.208-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;net: skbuff: propagate shared-frag marker through frag-transfer helpers.<br>&nbsp;&nbsp;net: skbuff: preserve shared-frag marker during coalescing.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43503<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46300<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.208/kernel-headers-5.15.208-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.208/kernel-headers-5.15.208-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.208/kernel-huge-5.15.208-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.208/kernel-huge-5.15.208-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;net: skbuff: propagate shared-frag marker through frag-transfer helpers.<br>&nbsp;&nbsp;net: skbuff: preserve shared-frag marker during coalescing.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43503<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46300<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.208/kernel-modules-5.15.208-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.208/kernel-modules-5.15.208-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.208/kernel-source-5.15.208-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.208/kernel-source-5.15.208-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Fri May 22 20:33:38 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 22 May 2026 22:33:38 +0200</pubDate>
      <guid isPermaLink="false">1779482018</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/lxc-4.0.12-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/lxc-4.0.12-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Thanks to fourtysixandtwo.<br>]]></description>
    </item>
<item>
      <title>Thu May 21 04:59:09 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Thu, 21 May 2026 06:59:09 +0200</pubDate>
      <guid isPermaLink="false">1779339549</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/bind-9.18.49-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/bind-9.18.49-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;Fix outgoing zone transfers' quota issue.<br>&nbsp;&nbsp;Limit resolver server list size.<br>&nbsp;&nbsp;Fix GSS-API resource leak.<br>&nbsp;&nbsp;Avoid unbounded recursion loop.<br>&nbsp;&nbsp;Disable recursion, UPDATE, and NOTIFY for non-IN views.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-3592<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-3039<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://kb.isc.org/docs/CVE-2026-5946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3592<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-3039<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5946<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/rsync-3.4.3-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/rsync-3.4.3-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;TOCTOU symlink race condition allowing local privilege escalation in daemon<br>&nbsp;&nbsp;mode without chroot.<br>&nbsp;&nbsp;Hostname/ACL bypass on an rsync daemon configured with `daemon chroot = /X`<br>&nbsp;&nbsp;in rsyncd.conf when the chroot tree lacks DNS resolution support.<br>&nbsp;&nbsp;Integer overflow in the compressed-token decoder enabling remote memory<br>&nbsp;&nbsp;disclosure to an authenticated daemon peer.<br>&nbsp;&nbsp;Symlink races on path-based system calls in "use chroot = no" daemon mode.<br>&nbsp;&nbsp;Out-of-bounds read in the receiver's recv_files() enabling remote<br>&nbsp;&nbsp;denial-of-service of any client pulling from a malicious server.<br>&nbsp;&nbsp;Off-by-one out-of-bounds stack write in the rsync client's HTTP CONNECT proxy<br>&nbsp;&nbsp;handler (`establish_proxy_connection()` in `socket.c`).<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29518<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43617<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43618<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43619<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43620<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45232<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue May 19 23:45:24 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Wed, 20 May 2026 01:45:24 +0200</pubDate>
      <guid isPermaLink="false">1779234324</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/haveged-1.9.21-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/haveged-1.9.21-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Missing exit out of permission check could lead to root exploit.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-41054<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-firefox-140.11.0esr-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.11.0esr-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.11.0/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-48<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8388<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8391<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8401<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8949<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8953<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8954<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8955<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8956<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8957<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8958<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8959<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8961<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8962<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8968<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8970<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8974<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8975<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-thunderbird-140.11.0esr-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.11.0esr-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.11.0esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-51/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8946<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8388<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8947<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8391<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8401<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8949<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8950<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8953<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8954<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8955<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8956<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8957<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8958<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8959<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8961<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8962<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8968<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8970<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8974<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8975<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sun May 17 23:23:26 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Mon, 18 May 2026 01:23:26 +0200</pubDate>
      <guid isPermaLink="false">1779060206</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/dcron-4.5-x86_64-14_slack15.0.txz' rel='nofollow'>patches/packages/dcron-4.5-x86_64-14_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This is a bugfix release.<br>&nbsp;&nbsp;Rebase the run-parts script on the latest version from Fedora's crontabs<br>&nbsp;&nbsp;package. Thanks to avian.<br>&nbsp;&nbsp;rc.crond: ensure world-writable permissions on /run/cron, needed for<br>&nbsp;&nbsp;crontab -e with some editors. Thanks to lostintime.<br>&nbsp;&nbsp;Add /etc/default/run-parts. Thanks to lostintime.<br>&nbsp;&nbsp;run-parts: don't redirect stderr to stdout. Thanks to Thom1b.<br>&nbsp;&nbsp;run-parts: skip *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;run-parts.8: document skiping *.orig files. Thanks to metaed.<br>&nbsp;&nbsp;/etc/default/crond: Set the same minimal PATH that's provided by sysvinit at<br>&nbsp;&nbsp;boot time to keep things consistent when using rc.crond restart. This PATH<br>&nbsp;&nbsp;will be used both at boot and with a restart through rc.crond. Feel free to<br>&nbsp;&nbsp;adjust it if needed. Thanks to Ken Zalewski.<br>]]></description>
    </item>
<item>
      <title>Sat May 16 02:48:04 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 16 May 2026 04:48:04 +0200</pubDate>
      <guid isPermaLink="false">1778899684</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/dnsmasq-2.92rel2-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/dnsmasq-2.92rel2-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-2291<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4890<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4891<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4892<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-4893<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-5172<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.207/kernel-generic-5.15.207-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-generic-5.15.207-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.207/kernel-headers-5.15.207-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-headers-5.15.207-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.207/kernel-huge-5.15.207-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-huge-5.15.207-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;ptrace: slightly saner 'get_dumpable()' logic.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/0xdeadbeefnetwork/ssh-keysign-pwn<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-46333<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.207/kernel-modules-5.15.207-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-modules-5.15.207-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.207/kernel-source-5.15.207-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.207/kernel-source-5.15.207-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Tue May 12 02:16:39 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 12 May 2026 04:16:39 +0200</pubDate>
      <guid isPermaLink="false">1778552199</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/expat-2.7.5-x86_64-2_slack15.0.txz' rel='nofollow'>patches/packages/expat-2.7.5-x86_64-2_slack15.0.txz</a>:&nbsp;&nbsp;Rebuilt.<br></b>&nbsp;&nbsp;This update fixes a security issue:<br>&nbsp;&nbsp;Fix quadratic runtime from attribute name collision checks that allowed<br>&nbsp;&nbsp;denial of service attacks through moderately sized crafted XML input<br>&nbsp;&nbsp;(CWE-407). Please note that a layer of compression around XML can<br>&nbsp;&nbsp;significantly reduce the minimum attack payload size.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-45186<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Sat May  9 21:25:03 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 09 May 2026 23:25:03 +0200</pubDate>
      <guid isPermaLink="false">1778361903</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.206/kernel-generic-5.15.206-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-generic-5.15.206-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.206/kernel-headers-5.15.206-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-headers-5.15.206-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.206/kernel-huge-5.15.206-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-huge-5.15.206-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.206/kernel-modules-5.15.206-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-modules-5.15.206-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a regression in Linux 5.15.205:<br>&nbsp;&nbsp;xfrm: esp: ipv4: fix up flags setting.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.206/kernel-source-5.15.206-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.206/kernel-source-5.15.206-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br>]]></description>
    </item>
<item>
      <title>Fri May  8 22:14:25 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Sat, 09 May 2026 00:14:25 +0200</pubDate>
      <guid isPermaLink="false">1778278465</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.205/kernel-generic-5.15.205-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-generic-5.15.205-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.205/kernel-headers-5.15.205-x86-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-headers-5.15.205-x86-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.205/kernel-huge-5.15.205-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-huge-5.15.205-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.205/kernel-modules-5.15.205-x86_64-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-modules-5.15.205-x86_64-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes a critical security issue:<br>&nbsp;&nbsp;xfrm: esp: avoid in-place decrypt on shared skb frags.<br>&nbsp;&nbsp;This update addresses a Linux kernel local privilege escalation attack known<br>&nbsp;&nbsp;as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that<br>&nbsp;&nbsp;is not yet patched upstream.<br>&nbsp;&nbsp;Mitigation: If for some reason it's not possible to upgrade the kernel right<br>&nbsp;&nbsp;away you may blacklist or remove the kernel modules esp4.ko and esp6.ko<br>&nbsp;&nbsp;(CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).<br>&nbsp;&nbsp;Also remove the modules from the kernel if they have been loaded:<br>&nbsp;&nbsp;&nbsp;&nbsp;rmmod esp4 esp6 rxrpc<br>&nbsp;&nbsp;And, drop the file caches in case in-memory program copies have already<br>&nbsp;&nbsp;been compromised. Make sure possibly affected programs do not have any<br>&nbsp;&nbsp;open sessions first:<br>&nbsp;&nbsp;&nbsp;&nbsp;sh -c "echo 3 &gt; /proc/sys/vm/drop_caches"<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/V4bel/dirtyfrag<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-43284<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/linux-5.15.205/kernel-source-5.15.205-noarch-1.txz' rel='nofollow'>patches/packages/linux-5.15.205/kernel-source-5.15.205-noarch-1.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;Be sure to upgrade your initrd after upgrading the kernel packages.<br>&nbsp;&nbsp;If you use lilo to boot your machine, be sure lilo.conf points to the correct<br>&nbsp;&nbsp;kernel and initrd and run lilo as root to update the bootloader.<br>&nbsp;&nbsp;If you use elilo to boot your machine, you should run eliloconfig to copy the<br>&nbsp;&nbsp;kernel and initrd to the EFI System Partition.<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-thunderbird-140.10.2esr-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-thunderbird-140.10.2esr-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/thunderbird/140.10.2esr/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/security/advisories/mfsa2026-44/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8090<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8094<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8092<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Fri May  8 05:00:03 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Fri, 08 May 2026 07:00:03 +0200</pubDate>
      <guid isPermaLink="false">1778216403</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/extra/php82/php82-8.2.31-x86_64-1_slack15.0.txz' rel='nofollow'>extra/php82/php82-8.2.31-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes security issues:<br>&nbsp;&nbsp;FPM: Fixed XSS within status endpoint.<br>&nbsp;&nbsp;MBString: Fixed Null pointer dereference in php_mb_check_encoding()<br>&nbsp;&nbsp;via mb_ereg_search_init().<br>&nbsp;&nbsp;PDO_Firebird: Fixed SQL injection via NUL bytes in quoted strings.<br>&nbsp;&nbsp;SOAP: Fixed Stale SOAP_GLOBAL(ref_map) pointer with Apache Map.<br>&nbsp;&nbsp;SOAP: Fixed Use-after-free after header parsing failure with<br>&nbsp;&nbsp;SOAP_PERSISTENCE_SESSION.<br>&nbsp;&nbsp;SOAP: Fixed Broken Apache map value NULL check.<br>&nbsp;&nbsp;Standard: Fixed Signed integer overflow of char array offset.<br>&nbsp;&nbsp;Standard: Fixed Consistently pass unsigned char to ctype.h functions.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.php.net/ChangeLog-8.php#8.2.31<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6735<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7259<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2025-14179<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-6722<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7261<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7262<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7568<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-7258<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/libgpg-error-1.61-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/libgpg-error-1.61-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues:<br>&nbsp;&nbsp; Fix possible stack overflow in es_printf for %.100f format.<br>&nbsp;&nbsp; Fix out-of-bounds read in vfnameconcat.<br>&nbsp;&nbsp;(* Security fix *)<br><b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/mozilla-firefox-140.10.2esr-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/mozilla-firefox-140.10.2esr-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update contains security fixes and improvements.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/en-US/firefox/140.10.2/releasenotes/<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.mozilla.org/security/advisories/mfsa2026-41<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8090<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8094<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-8092<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Tue May  5 20:12:56 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 05 May 2026 22:12:56 +0200</pubDate>
      <guid isPermaLink="false">1778011976</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/hunspell-1.7.3-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/hunspell-1.7.3-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This update fixes bugs and security issues.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://github.com/hunspell/hunspell/releases/tag/v1.7.3<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
<item>
      <title>Mon May  4 22:37:35 UTC 2026</title>
      <link>https://www.sya54m.eu</link>
      <pubDate>Tue, 05 May 2026 00:37:35 +0200</pubDate>
      <guid isPermaLink="false">1777934255</guid>
      <description><![CDATA[<b><a href='http://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/httpd-2.4.67-x86_64-1_slack15.0.txz' rel='nofollow'>patches/packages/httpd-2.4.67-x86_64-1_slack15.0.txz</a>:&nbsp;&nbsp;Upgraded.<br></b>&nbsp;&nbsp;This release fixes bugs and the following security issues:<br>&nbsp;&nbsp;mod_proxy_ajp: Heap Over-Read and memory disclosure in&nbsp;&nbsp;ajp_parse_data().<br>&nbsp;&nbsp;mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check.<br>&nbsp;&nbsp;Off-by-one OOB reads in AJP getter functions.<br>&nbsp;&nbsp;HTTP response splitting forwarding malicious status line.<br>&nbsp;&nbsp;mod_authn_socache crash.<br>&nbsp;&nbsp;mod_auth_digest timing attack.<br>&nbsp;&nbsp;mod_md unrestricted OCSP response.<br>&nbsp;&nbsp;buffer overflow in mod_proxy_ajp via ajp_msg_check_header().<br>&nbsp;&nbsp;mod_rewrite elevation of privileges via ap_expr.<br>&nbsp;&nbsp;http2: double free and possible RCE on early reset.<br>&nbsp;&nbsp;For more information, see:<br>&nbsp;&nbsp;&nbsp;&nbsp;https://downloads.apache.org/httpd/CHANGES_2.4.67<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34059<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-34032<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33857<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33523<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33007<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-33006<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29169<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-29168<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-28780<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-24072<br>&nbsp;&nbsp;&nbsp;&nbsp;https://www.cve.org/CVERecord?id=CVE-2026-23918<br>&nbsp;&nbsp;(* Security fix *)<br>]]></description>
    </item>
</channel>
</rss>