What's Changed
- libarchive 3.8.8 (CVE-2026-14164) [stable/4.0] by @laffer1 in #454
- tzdata 2026c
- llvm: CVE-2026-13574 gc.relocate malformed index diagnostic crash
- ldns 1.9.2: CVE-2026-10846 off-path DNS response spoofing in the stub resolver and drill; responses are now matched to the query by source address/port, transaction ID and question
- openssl: CVE-2026-45447 PKCS#7/S/MIME verification use-after-free fix.
- openssl: CVE-2026-34180 ASN.1 decoder large primitive length over-read fix.
- openssl: CVE-2026-7383 ASN1_mbstring_ncopy() Unicode output size overflow fix.
- openssl: CVE-2026-28388 delta CRL missing CRL Number NULL pointer dereference fix.
- llvm: CVE-2026-13574 gc.relocate malformed index diagnostic crash fix.
- vm: CVE-2026-49418 device pager page list use-after-free fix.
- iconv: CVE-2026-58081, CVE-2026-58082 buffer overflows in the HZ,UTF-7, VIQR, ZW and ISO-2022 iconv(3) encoding modules.
- audit: CVE-2026-49426 incorrect audit records for ptrace(PT_SC_REMOTE) syscall requests
- posixshm: CVE-2026-49427, CVE-2026-49428 use-after-free in POSIX largepage shared memory objects (sendfile SF_NOCACHE and O_TRUNC paths).
- tcp: CVE-2026-49422 use-after-free in the RACK TCP stack setsockopt(2) handler (tcp_rack.ko).
- unlinkat: CVE-2026-49421 unlinkat(2)/funlinkat(2) silently ignored the AT_RESOLVE_BENEATH path-containment flag.
- libalias: CVE-2026-49420 buffer overflow in the RTSP handler (alias_smedia).
- zfs: CVE-2026-49429, CVE-2026-49430, CVE-2026-49431 OpenZFS heap overflow (USERSPACE_MANY), receive-path memory corruption (RECV_NEW heal) and improper SET_PROP privilege check.
- execve: CVE-2026-49415 local privilege escalation via a procfs debugging permission race.
Full Changelog: 4.0.6...4.0.7