dev-8f9871e
Pre-release
Pre-release
π¦ hubzilla β v0.0.0-dev+8f9871e
Release type: prerelease β’ Commit:
8f9871e
Security: π‘οΈ β Critical β 22 critical and 348 high vulnerabilities detected
Image Availability
| Registry | Image | Tags |
|---|---|---|
| Docker Hub | docker.io/hlhd/hubzilla |
dev-8f9871e latest-dev latest-v11-dev |
| cr.pcfae.com | cr.pcfae.com/hlhd/hubzilla |
dev-8f9871e latest-dev latest-v11-dev |
| GitHub Container Registry | ghcr.io/homelabhd/hubzilla |
dev-8f9871e latest-dev latest-v11-dev |
Digest pull commands & supply chain artifacts
docker.io/hlhd/hubzilla
docker pull docker.io/hlhd/hubzilla@sha256:c99c341064598119a4509873ecea2b9f6a9e9f5e3bfcac9c14484d01d24c9fde
cr.pcfae.com/hlhd/hubzilla
docker pull cr.pcfae.com/hlhd/hubzilla@sha256:c99c341064598119a4509873ecea2b9f6a9e9f5e3bfcac9c14484d01d24c9fde
ghcr.io/homelabhd/hubzilla
docker pull ghcr.io/homelabhd/hubzilla@sha256:c99c341064598119a4509873ecea2b9f6a9e9f5e3bfcac9c14484d01d24c9fde
Notable Changes
Breaking Changes
- image: link bundled addons into the path hubzilla scans, so pubcrawl and the rest load (SoFMeRight)
- image: serve hubzilla from the image so its routing contract ships with the code (SoFMeRight)
Features
- image: build hubzilla at a pinned revision from our own mirrors (SoFMeRight)
Bug Fixes
- image: drop an msmtp flag that was passed a value, which failed every send at option parsing (SoFMeRight)
- image: give the image a mail transport and restore libzip (SoFMeRight)
Documentation
- refresh generated badges (stagefreight) Γ5
- drop the decorative emoji from the title (SoFMeRight)
- describe the image serving http on 8080 and its proxy requirements (SoFMeRight)
- add readme, upstream license and configuration reference (SoFMeRight)
Maintenance
- governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) Γ2
Security
π‘οΈ β Critical β 22 critical and 348 high vulnerabilities detected
Vulnerability details (22 critical, 348 high, 1632 medium, 949 low)
| Severity | CVE | Package | Installed | Fixed | Description |
|---|---|---|---|---|---|
| Critical | CVE-2023-6879 | libaom3 | 3.6.0-1+deb12u3 | β | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). |
| Critical | CVE-2026-58016 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with... |
| Critical | CVE-2026-58016 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with... |
| Critical | CVE-2023-5841 | libopenexr-3-1-30 | 3.1.5-5 | β | Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEXΒ image parsing library version 3.2.1 and prior is... |
| Critical | CVE-2026-42216 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| Critical | CVE-2026-42217 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| Critical | CVE-2026-13221 | libperl5.36 | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string... |
| Critical | CVE-2026-42496 | libperl5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | libperl5.36 | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit... |
| Critical | CVE-2025-7458 | libsqlite3-0 | 3.40.1-2+deb12u2 | β | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of... |
| Critical | CVE-2026-6653 | libxml2 | 2.9.14+dfsg-1.3~deb12u6 | β | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper... |
| Critical | CVE-2026-43185 | linux-libc-dev | 6.1.180-1 | β | kernel: ksmbd: fix signededness bug in smb_direct_prepare_negotiation() |
| Critical | CVE-2026-13221 | perl | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string... |
| Critical | CVE-2026-42496 | perl | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit... |
| Critical | CVE-2026-13221 | perl-base | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string... |
| Critical | CVE-2026-42496 | perl-base | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-base | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit... |
| Critical | CVE-2026-13221 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string... |
| Critical | CVE-2026-42496 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink()... |
| Critical | CVE-2026-8376 | perl-modules-5.36 | 5.36.0-7+deb12u3 | β | Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit... |
| Critical | CVE-2023-45853 | zlib1g | 1:1.2.13.dfsg-1 | β | zlib: integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_6 |
| High | CVE-2026-53613 | bsdutils | 1:2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-76642 | bsdutils | 1:2.38.1-5+deb12u3 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | bsdutils | 1:2.38.1-5+deb12u3 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | bsdutils | 1:2.38.1-5+deb12u3 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | bsdutils | 1:2.38.1-5+deb12u3 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-12064 | curl | 7.88.1-10+deb12u15 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-6276 | curl | 7.88.1-10+deb12u15 | β | Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the... |
| High | CVE-2026-8286 | curl | 7.88.1-10+deb12u15 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | curl | 7.88.1-10+deb12u15 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | curl | 7.88.1-10+deb12u15 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-41992 | gzip | 1.12-1 | β | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single... |
| High | CVE-2026-86420 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | imagemagick | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-86420 | imagemagick-6-common | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | imagemagick-6-common | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-86420 | imagemagick-6.q16 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | imagemagick-6.q16 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-54369 | libacl1 | 2.3.1-3 | β | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that... |
| High | CVE-2023-39616 | libaom3 | 3.6.0-1+deb12u3 | β | AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h. |
| High | CVE-2026-53613 | libblkid1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-76642 | libblkid1 | 2.38.1-5+deb12u3 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libblkid1 | 2.38.1-5+deb12u3 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libblkid1 | 2.38.1-5+deb12u3 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libblkid1 | 2.38.1-5+deb12u3 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2026-12064 | libcurl4 | 7.88.1-10+deb12u15 | β | When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl... |
| High | CVE-2026-6276 | libcurl4 | 7.88.1-10+deb12u15 | β | Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the... |
| High | CVE-2026-8286 | libcurl4 | 7.88.1-10+deb12u15 | β | A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not. |
| High | CVE-2026-8458 | libcurl4 | 7.88.1-10+deb12u15 | β | libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl features a pool of recent... |
| High | CVE-2026-8927 | libcurl4 | 7.88.1-10+deb12u15 | β | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests... |
| High | CVE-2026-33164 | libde265-0 | 1.0.11-1+deb12u2 | β | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values()... |
| High | CVE-2025-59375 | libexpat1 | 2.5.0-1+deb12u3 | β | firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing |
| High | CVE-2026-25210 | libexpat1 | 2.5.0-1+deb12u3 | β | In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation. |
| High | CVE-2026-45186 | libexpat1 | 2.5.0-1+deb12u3 | β | In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input. |
| High | CVE-2026-58010 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check... |
| High | CVE-2026-58011 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the... |
| High | CVE-2026-58012 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append... |
| High | CVE-2026-58013 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing... |
| High | CVE-2026-58014 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value... |
| High | CVE-2026-58015 | libglib2.0-0 | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server... |
| High | CVE-2026-58010 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check... |
| High | CVE-2026-58011 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the... |
| High | CVE-2026-58012 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append... |
| High | CVE-2026-58013 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing... |
| High | CVE-2026-58014 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value... |
| High | CVE-2026-58015 | libglib2.0-data | 2.74.6-2+deb12u9 | β | A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server... |
| High | CVE-2023-25193 | libharfbuzz0b | 6.0.0+dfsg-3 | β | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. |
| High | CVE-2025-68431 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in... |
| High | CVE-2026-32740 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to... |
| High | CVE-2026-32741 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image()... |
| High | CVE-2026-32882 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc... |
| High | CVE-2026-41071 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's... |
| High | CVE-2026-47178 | libheif1 | 1.15.1-1+deb12u1 | β | libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed unci codec, tiled, component-interleaved, 4:2:0) triggers a heap... |
| High | CVE-2023-2953 | libldap-2.5-0 | 2.5.13+dfsg-5 | β | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
| High | CVE-2026-86420 | libmagickcore-6.q16-6 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | libmagickcore-6.q16-6 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-86420 | libmagickcore-6.q16-6-extra | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | libmagickcore-6.q16-6-extra | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-86420 | libmagickwand-6.q16-6 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails... |
| High | CVE-2026-86421 | libmagickwand-6.q16-6 | 8:6.9.11.60+dfsg-1.6+deb12u13 | β | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to... |
| High | CVE-2026-53613 | libmount1 | 2.38.1-5+deb12u3 | β | util-linux: util-linux: TOCTOU in the mount program via ancestor directory swap on target path |
| High | CVE-2026-76642 | libmount1 | 2.38.1-5+deb12u3 | β | util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing... |
| High | CVE-2026-78408 | libmount1 | 2.38.1-5+deb12u3 | β | The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve()... |
| High | CVE-2026-78409 | libmount1 | 2.38.1-5+deb12u3 | β | The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW... |
| High | CVE-2026-78410 | libmount1 | 2.38.1-5+deb12u3 | β | A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount... |
| High | CVE-2025-12495 | libopenexr-3-1-30 | 3.1.5-5 | β | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability... |
| High | CVE-2025-12839 | libopenexr-3-1-30 | 3.1.5-5 | β | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability... |
| High | CVE-2025-12840 | libopenexr-3-1-30 | 3.1.5-5 | β | Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability... |
| High | CVE-2025-64181 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-27622 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-34379 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-34543 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-34544 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-34545 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-34588 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-40244 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-40250 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-41142 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry... |
| High | CVE-2026-68515 | libopenexr-3-1-30 | 3.1.5-5 | β | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry... |
... and 2851 more of lower severity (see full report in release assets)
Full changelog
- [
8f9871e] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight) - [
6b88bf3] refresh generated badges (stagefreight) - [
4f7ff7a] drop the decorative emoji from the title (SoFMeRight) - [
a0e914d] refresh generated badges (stagefreight) - [
dd48c8e] link bundled addons into the path hubzilla scans, so pubcrawl and the rest load (SoFMeRight) - [
151f78f] refresh generated badges (stagefreight) - [
e6d31b0] drop an msmtp flag that was passed a value, which failed every send at option parsing (SoFMeRight) - [
e7e45f1] refresh generated badges (stagefreight) - [
50b3a1c] describe the image serving http on 8080 and its proxy requirements (SoFMeRight) - [
e36aec0] serve hubzilla from the image so its routing contract ships with the code (SoFMeRight) - [
477353c] refresh generated badges (stagefreight) - [
b0bdc7d] add readme, upstream license and configuration reference (SoFMeRight) - [
1180583] give the image a mail transport and restore libzip (SoFMeRight) - [
7da3d79] build hubzilla at a pinned revision from our own mirrors (SoFMeRight) - [
cde0c2f] governance reconcile from gitlab.prplanit.com/PrPlanIT/MaintenancePolicy (StageFreight)