AlmaLinux 2608 Published by

AlmaLinux issued a batch of security advisories on July 21, 2026, patching dozens of critical vulnerabilities across packages like gstreamer1-plugins-good, freerdp, webkit2gtk3, nodejs, python3.14, and the Apache httpd server for versions 8, 9, and 10. The flaws span memory corruption issues, heap buffer overflows triggered by malformed media files or network packets, denial of service conditions caused by unbounded resource consumption, and remote code execution risks embedded in directory services and web rendering engines. Several advisories specifically address sandbox escape vulnerabilities that allow malicious websites to access restricted system resources or leak sensitive user data directly from the browser process.

ALSA-2026:36675: gstreamer1-plugins-good security update (Important)
ALSA-2026:39547: perl-XML-LibXML security update (Important)
ALSA-2026:36196: 389-ds-base security update (Important)
ALSA-2026:39976: hplip security update (Important)
ALSA-2026:36203: freerdp security update (Important)
ALSA-2026:36673: gstreamer1-plugins-ugly-free security update (Moderate)
ALSA-2026:39573: yggdrasil security update (Important)
ALSA-2026:41988: dovecot security update (Important)
ALSA-2026:42063: glib2 security update (Important)
ALSA-2026:42096: c-ares security update (Important)
ALSA-2026:41947: nodejs:22 security, bug fix, and enhancement update (Important)
ALSA-2026:42088: webkit2gtk3 security update (Important)
ALSA-2026:42090: glib2 security update (Important)
ALSA-2026:42550: kernel-rt security, bug fix, and enhancement update (Important)
ALSA-2026:42552: kernel security, bug fix, and enhancement update (Important)
ALSA-2026:42062: webkit2gtk3 security update (Important)
ALSA-2026:42089: glib2 security update (Important)
ALSA-2026:41949: python3.14 security update (Important)
ALSA-2026:41906: httpd security, bug fix, and enhancement update (Important)




ALSA-2026:36675: gstreamer1-plugins-good security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license.

Security Fix(es):

* gstreamer1-plugins-good: GStreamer: Heap buffer overflow in WavPack decoder via integer overflow (CVE-2026-53705)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-36675.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:39547: perl-XML-LibXML security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

This module implements a Perl interface to the GNOME libxml2 library which provides interfaces for parsing and manipulating XML files. This module allows Perl programmers to make use of the highly capable validating XML parser and the high performance DOM implementation.

Security Fix(es):

* perl-XML-LibXML: XML::LibXML: Denial of Service via truncated UTF-8 in XML node names (CVE-2026-8177)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-39547.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:36196: 389-ds-base security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

389 Directory Server is an LDAP version 3 (LDAPv3) compliant server. The base packages include the Lightweight Directory Access Protocol (LDAP) server and command-line utilities for server administration.

Security Fix(es):

* 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND (CVE-2026-11610)
* 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow (CVE-2026-11774)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-36196.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:39976: hplip security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

The hplip packages contain the Hewlett-Packard Linux Imaging and Printing Project (HPLIP), which provides drivers for Hewlett-Packard printers and multi-function peripherals.

Security Fix(es):

* HPLIP: Incomplete Fix for CVE-2026-8631 (CVE-2026-14544)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-39976.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:36203: freerdp security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.

Security Fix(es):

* freerdp: FreeRDP: Remote code execution via heap-buffer-overflow in gdi_CacheToSurface (CVE-2026-40033)
* freerdp: FreeRDP: Arbitrary code execution or denial of service via heap use-after-free in RDPEAR NDR parser (CVE-2026-44422)
* freerdp: FreeRDP: Out-of-bounds write in planar bitmap decoder allows arbitrary code execution (CVE-2026-45700)
* freerdp: FreeRDP: Arbitrary code execution via crafted RDPGFX PDUs (CVE-2026-44421)
* freerdp: FreeRDP: Arbitrary code execution and denial of service via heap-buffer-overflow (CVE-2026-44420)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-36203.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:36673: gstreamer1-plugins-ugly-free security update (Moderate)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Moderate
Release date: 2026-07-21

Summary:

GStreamer is a streaming media framework, based on graphs of elements which operate on media data. This package contains plug-ins whose license is not fully compatible with LGPL.

Security Fix(es):

* gstreamer1-plugins-ugly-free: GStreamer: Out-of-bounds read in RealMedia demuxer audio stream header parser (CVE-2026-53703)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-36673.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:39573: yggdrasil security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker.

Security Fix(es):

* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)
* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)
* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-39573.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:41988: dovecot security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

Dovecot is an IMAP server for Linux and other UNIX-like systems, written primarily with security in mind. It also contains a small POP3 server, and supports e-mail in either the maildir or mbox format. The SQL drivers and authentication plug-ins are provided as subpackages.

Security Fix(es):

* dovecot: Dovecot: Denial of Service via excessive IMAP bracing (CVE-2026-42006)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-41988.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42063: glib2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

* glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" (CVE-2026-58016)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-42063.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42096: c-ares security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

The c-ares C library defines asynchronous DNS (Domain Name System) requests and provides name resolving API.

Security Fix(es):

* c-ares: c-ares: Use-after-free / double-free in query-completion handling (CVE-2026-33630)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-42096.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:41947: nodejs:22 security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933)
* nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934)
* Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928)
* nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615)
* nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618)

Bug Fix(es) and Enhancement(s):

* nodejs:22/nodejs: Rebase to the latest Node.js 22 release [almalinux-8] (JIRA:AlmaLinux-176170)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-41947.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42088: webkit2gtk3 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)
* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)
* webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)
* webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721)
* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731)
* webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734)
* webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42088.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42090: glib2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

* glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" (CVE-2026-58016)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42090.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42550: kernel-rt security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

* kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117)
* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)

Bug Fix(es) and Enhancement(s):

* [almalinux-8] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected - at: vmd_pci_write+0x85/0xe0 - deadlock (JIRA:AlmaLinux-174916)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42550.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42552: kernel security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

* kernel: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (CVE-2026-46117)
* kernel: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (CVE-2026-53071)

Bug Fix(es) and Enhancement(s):

* [almalinux-8] WARNING: HARDIRQ-safe -> HARDIRQ-unsafe lock order detected - at: vmd_pci_write+0x85/0xe0 - deadlock (JIRA:AlmaLinux-174916)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-42552.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42062: webkit2gtk3 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.

Security Fix(es):

* Mozilla: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-39872)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43663)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43676)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43699)
* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43701)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43705)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43707)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43712)
* webkitgtk: webkitgtk: Visiting a website may leak sensitive data (CVE-2026-43713)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43715)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43716)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43720)
* webkitgtk: webkitgtk: A malicious website may silently hijack clipboard data (CVE-2026-43721)
* webkitgtk: webkitgtk: A malicious website may process restricted web content outside the sandbox (CVE-2026-43725)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43726)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43727)
* webkitgtk: webkitgtk: Maliciously crafted web content may lead to memory corruption (CVE-2026-43731)
* webkitgtk: webkitgtk: Maliciously crafted web content may disclose sensitive user information (CVE-2026-43732)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43734)
* webkitgtk: webkitgtk: Maliciously crafted web content may disclose process memory (CVE-2026-43740)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43742)
* webkitgtk: webkitgtk: Maliciously crafted web content may cause unexpected process crash (CVE-2026-43745)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42062.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:42089: glib2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.

Security Fix(es):

* glib: integer underflow in gio/gdbusintrospection.c via "g_dbus_node_info_new_for_xml" (CVE-2026-58016)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-42089.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:41949: python3.14 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations (CVE-2026-15308)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-41949.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:41906: httpd security, bug fix, and enhancement update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 9
Type: Security
Severity: Important
Release date: 2026-07-21

Summary:

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
* httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
* httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)

Bug Fix(es) and Enhancement(s):

* address Moderate severity issues from httpd 2.4.68 [almalinux-9.8.z] (JIRA:AlmaLinux-184520)
* mod_proxy_html regression in CVE-2026-34355 fix [almalinux-9.8.z] (JIRA:AlmaLinux-192752)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/9/ALSA-2026-41906.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team