AlmaLinux 2615 Published by

AlmaLinux released a batch of important security errata, targeting multiple core libraries across both the AlmaLinux 8 and 10 operating systems. The updates address memory corruption flaws in gstreamer1-plugins-bad-free, libXfont2, rest, nodejs versions 22 and 24, and libtiff that could allow remote code execution or cause system crashes. Administrators will also find patches for denial-of-service vulnerabilities in the Node.js tar and brace-expansion modules alongside a weak random number generation issue inside the librest PKCE implementation.

ALSA-2026:47180: gstreamer1-plugins-bad-free security update (Important)
ALSA-2026:47079: libXfont2 security update (Important)
ALSA-2026:47085: rest security update (Important)
ALSA-2026:47059: nodejs:22 security update (Important)
ALSA-2026:47060: nodejs:24 security update (Important)
ALSA-2026:47184: libtiff security update (Important)
ALSA-2026:47731: gstreamer1-plugins-bad-free security update (Important)
ALSA-2026:47103: libXfont2 security update (Important)




ALSA-2026:47180: gstreamer1-plugins-bad-free security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691)
* gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-47180.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47079: libXfont2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

X.Org X11 libXfont2 runtime library

Security Fix(es):

* libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001)
* libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-47079.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47085: rest security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 10
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

The rest packages provide a library for access to the RESTful web services.

Security Fix(es):

* librest: weak random number generation in PKCE implementation (CVE-2026-16615)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/10/ALSA-2026-47085.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47059: nodejs:22 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47059.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47060: nodejs:24 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47060.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47184: libtiff security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files.

Security Fix(es):

* libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image (CVE-2026-12912)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47184.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47731: gstreamer1-plugins-bad-free security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer.

Security Fix(es):

* gstreamer: gstreamer: rfbsrc/librfb Hextile heap out-of-bounds write with 16bpp framebuffer (CVE-2026-59691)
* gstreamer: gstreamer: DTLS certificate Subject DN stack buffer overflow in openssl_verify_callback (CVE-2026-59692)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47731.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team



ALSA-2026:47103: libXfont2 security update (Important)


Hi,

You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Important
Release date: 2026-07-29

Summary:

X.Org X11 libXfont2 runtime library

Security Fix(es):

* libXfont2: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (CVE-2026-56001)
* libXfont2: PCF Font Parsing Heap Buffer Overflow (CVE-2026-56002)
* libXfont2: computeProps Property Buffer Heap Buffer Overflow (CVE-2026-56003)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-47103.html

This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org.

Kind regards,
AlmaLinux Team