diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest index ba5ac3f8f14..83745f905f1 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest @@ -1,24 +1,24 @@ -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 -MANIFEST Manifest.files.gz 607306 BLAKE2B 92017b6799c6b9c6711d15259ccc5be7553c29a3562d24a367c7d7fa515cce981f1217aad923c07afa53479c855092c79ea478c7db5c27df5970742f0481eaaf SHA512 4fb6dcd2062715f4926aa685e41323a46d1b1f83e7be9008f32bd997a354c2cf495d9a497cf42a39b59bc734dabbeb4a8cb987031227e5f6741d4c6fc3ec95bf -TIMESTAMP 2026-08-01T07:07:55Z +MANIFEST Manifest.files.gz 612581 BLAKE2B 70e3e306717703f3fbf1a8a9c7cae0f4812daaf3d43e90890bbd5c64e9df3de4df8cca770bc70e9438ad3ca219bb6f2aed2e387a7102f02bc8af523dff38ba08 SHA512 215fe72e306375efb547416df6750ce2e8dd3c4a5cd9ebc71c349b210ffe463bb96f78e41524be0e7234c9e9efac279e3c89596483cb77c4179fb88e80ac9c4d +TIMESTAMP 2026-09-01T06:38:17Z -----BEGIN PGP SIGNATURE----- -iQKvBAEBCgCZFiEE4dartjv8+0ugL98c7FkO6skYklAFAmptm0sbFIAAAAAABAAO +iQKvBAEBCgCZFiEE4dartjv8+0ugL98c7FkO6skYklAFAmqWctkbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25z Lm9wZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFMUQ2QUJCNjNCRkNGQjRCQTAyRkRG -MUNFQzU5MEVFQUM5MTg5MjUwAAoJEOxZDurJGJJQMkMP+wQdTfMDkg2LpEJNXFtK -VrRYtsSD4GaPv9NsIUd7Mb4byduJbYD3Qu6x2JCmybDdloKE72pzI3oMUXNuYoAl -2V2XWApgONSzEXE++3cGDr5nYhoprCRDfZ1LmLL0NiDkTdMUTABFeLmGxPakx1M3 -IYq5i1qBGNE6IOrBnLjSEg6cy9Pjn3NVKQp143Um6UXAyEnUyX8lF9BnsFeNrFLd -LqhNTcFsWivWLV5i66dzwvzqj/eVh+Zhj0nWbUgq31yTGtUEbrrwoo6R9OPOr0Dm -8A6ognIPnJLm6otd9QYQ6kxRsvY88mJ1ExvAhVbxScjdrLiZRknMuukx0FKTRnRX -OCh3P5TUWaufVkwHLnLJefvgxF7exSRYcd5nMvS0EHTYpH+yexAUr7ebdjgWFvRd -OPvIswgucF0LHZb2/cITzJolBpQWxeeUA/JoylDie2CPNEW2Q7785JA1acCn/5Xz -w+HuoR2spjkaEVvW6jzMFRIv54uw64Cq/0G3uvpevyHLOKF17jzpHu4t/MMUZ2jB -sx8F+9KL/4Ha9s1VAC6Rom3hMUsV1Wd5QjCaK3d++zF5RJpRKcCdTKrBiIqLkQ0G -TXfCwTKEszhmAkIpkgThYoIgj9JcEp4l7QTVE6aMSje+zLyZa6IgHqQAy1gVTILq -+eF1DgwLAnasON7quMs+PeYC -=rRry +MUNFQzU5MEVFQUM5MTg5MjUwAAoJEOxZDurJGJJQjWUP/RE/qWE9jZm2+oXp7CQa +JOu0gOuags0B+dYfV3fIPVLIhmWMjAgwaGaZNKmlg4rmwBPBP518ZAX8GBz3s8+E +xmdPhFJSNp0S8RdSbYNmSFDYRX1ML88TRMvHs/7CbJRjwtSrX8qpWUu+tmUkOhXz +zmN6atbbtN0TkhO24mH8RzrDxLC0VfBdwTlQJOTUC1O4zBxCMUZfPrXVSWYZ6vGg +6teWKBxBbxsKieSAVXNdqOojAkE+H9LfG8zZqj7VNwsnizLG2M944NGoDGdTYC/7 +8+njI8ifbYrZ6V/00X8WQN8JKwapwjIIMfJY2rsKJ4KovwcuS5dDzfgmMWvfeF4y +q3Km2Cyv8SrQrCC/DlytVt7aYVRSQxpG/J2kUzjYBrOgJdT3ZImwVqdvA+sSg1ka +4EuqRzFMBQLgof6mZlVbMHXzwE6vkNBxNBIsw/KClcqiP6jVWfs3UapwRvaHyLKT +R10WjLVhoTn8igPmbqKgXjFoZDgujOihIKQdwUYBipxsu0FycgWWVCTaJ8N1pgCx +6T5U7av7vz5+RqPlUwQsdFfAZxwIpl9f2Fc5rv/OUTq80J3/1WfYXqk4x8E+s7KB ++EwgP+Kg3mIPgU69/qjlb27LGpy9z8rUQSGybEBqKAUJ9f8pBUTzOFnIOgBemYbv +dJtlGKRBjwXdNS3HnR9dr7E8 +=yb0X -----END PGP SIGNATURE----- diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz index ec1a0a38f34..b15e89fd9f1 100644 Binary files a/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz and b/sdk_container/src/third_party/portage-stable/metadata/glsa/Manifest.files.gz differ diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-200502-20.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-200502-20.xml index 7d088a69e2a..4fd276db228 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-200502-20.xml +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-200502-20.xml @@ -1,15 +1,15 @@ - Emacs, XEmacs: Format string vulnerabilities in movemail + GNU Emacs, XEmacs: Format string vulnerabilities in movemail - The movemail utility shipped with Emacs and XEmacs contains several format + The movemail utility shipped with GNU Emacs and XEmacs contains several format string vulnerabilities, potentially leading to the execution of arbitrary code. Emacs 2005-02-15 - 2006-07-23 + 2026-08-20 79686 remote @@ -50,7 +50,7 @@

- All Emacs users should upgrade to the latest version: + All GNU Emacs users should upgrade to the latest version:

# emerge --sync diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml index 9fb9874f912..00bc45eb7e1 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202409-19.xml @@ -1,11 +1,11 @@ - Emacs, org-mode: Command Execution Vulnerability - A vulnerability has been found in Emacs and org-mode which could result in arbitrary code execution. + GNU Emacs, org-mode: Command Execution Vulnerability + A vulnerability has been found in GNU Emacs and org-mode which could result in arbitrary code execution. emacs,org-mode 2024-09-22 - 2024-09-22 + 2026-08-20 934736 local @@ -25,7 +25,7 @@ -

Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.

+

GNU Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.

%(...) link abbreviations could specify unsafe functions.

@@ -37,7 +37,7 @@

There is no known workaround at this time.

-

All Emacs users should upgrade to the latest version according to the installed slot, one of:

+

All GNU Emacs users should upgrade to the latest version according to the installed slot, one of:

# emerge --sync @@ -69,4 +69,4 @@ ajak graaff -
\ No newline at end of file +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-01.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-01.xml index 7d906610212..0273ad40dc3 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-01.xml +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-01.xml @@ -1,11 +1,11 @@ - Emacs: Multiple Vulnerabilities - Multiple vulnerabilities have been discovered in Emacs, the worst of which could lead to arbitrary code execution. + GNU Emacs: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in GNU Emacs, the worst of which could lead to arbitrary code execution. emacs 2025-06-12 - 2025-06-12 + 2026-08-20 945164 950192 local @@ -22,10 +22,10 @@ -

Emacs is the extensible, customizable, self-documenting real-time display editor. org-mode is an Emacs mode for notes and project planning.

+

GNU Emacs is the extensible, customizable, self-documenting real-time display editor.

-

Multiple vulnerabilities have been discovered in Emacs, org-mode. Please review the CVE identifiers referenced below for details.

+

Multiple vulnerabilities have been discovered in GNU Emacs. Please review the CVE identifiers referenced below for details.

Please review the referenced CVE identifiers for details.

@@ -34,7 +34,7 @@

There is no known workaround at this time.

-

All Emacs, org-mode users should upgrade to the latest version:

+

All GNU Emacs users should upgrade to the latest version:

# emerge --sync @@ -50,4 +50,4 @@ graaff graaff -
\ No newline at end of file + diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-05.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-05.xml index f1dade8e1c2..2a78dcdc4f4 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-05.xml +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202506-05.xml @@ -5,13 +5,13 @@ A vulnerability has been discovered in Gtk+, which can lead to arbitrary code execution. gtk+ 2025-06-12 - 2025-06-12 + 2026-08-20 949825 local - 3.24.48:3 - 3.24.48:3 + 3.24.48 + 3.24.48 diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202603-01.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202603-01.xml index 4a82cd39ff7..225eeb5635d 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202603-01.xml +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202603-01.xml @@ -21,7 +21,7 @@

The following vulnerabilities have been discovered in Exiv2: 2 out of bounds reads, an integer overflow, and an uncaught exception. The worst of which can lead to a Denial of Service via a crash of the program. Please review the CVE identifiers referenced below for details.

- +

The following is a possible outcome: data leakage via an out-of-bounds read or a Denial of Service via a crash of the program.

@@ -44,6 +44,6 @@ GHSA-9mxq-4j5g-5wrp GHSA-p2pw-7935-c73j - csfore - csfore + csfore + sam \ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-02.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-02.xml new file mode 100644 index 00000000000..d417a2bbe0c --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-02.xml @@ -0,0 +1,51 @@ + + + + FreeType: Multiple Vulnerabilities + Multiple vulnerabilities have been found in FreeType, one of which includes information leak. + freetype + 2026-08-12 + 2026-08-12 + 970886 + 971490 + remote + + + 2.14.3 + 2.14.3 + + + +

FreeType is a software font engine that is designed to be small, efficient, highly customizable, and portable while capable of producing high-quality output (glyph images).

+
+ +

Multiple vulnerabilities have been discovered in FreeType. Please review the CVE identifiers referenced below for details.

+
+ +

One of the possible outcomes allows for an out-of-bounds read. Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All FreeType users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-libs/freetype-2.14.3" + +
+ + CVE-2026-22007 + CVE-2026-22008 + CVE-2026-22013 + CVE-2026-22016 + CVE-2026-22018 + CVE-2026-22021 + CVE-2026-23865 + CVE-2026-34268 + CVE-2026-34282 + + csfore + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-03.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-03.xml new file mode 100644 index 00000000000..cab3a5b5169 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-03.xml @@ -0,0 +1,49 @@ + + + + rsync: Multiple Vulnerabilities + Multiple vulnerabilities have been found in rsync, the worst of which could result in privilege escalation. + rsync + 2026-08-13 + 2026-08-13 + 972779 + 975525 + local and remote + + + 3.4.3 + 3.4.3 + + + +

rsync is a server and client utility that provides fast incremental file transfers. It is used to efficiently synchronize files between hosts and is used by emerge to fetch Gentoo's Portage tree.

+
+ +

Multiple vulnerabilities have been discovered in rsync. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All rsync users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-misc/rsync-3.4.3" + +
+ + CVE-2026-29518 + CVE-2026-41035 + CVE-2026-43617 + CVE-2026-43618 + CVE-2026-43619 + CVE-2026-43620 + CVE-2026-45232 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-04.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-04.xml new file mode 100644 index 00000000000..d657aa12f5c --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-04.xml @@ -0,0 +1,47 @@ + + + + Dnsmasq: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Dnsmasq, one of which includes remote code execution. + dnsmasq + 2026-08-13 + 2026-08-13 + 974690 + remote + + + 2.92_p2 + 2.92_p2 + + + +

Dnsmasq is a lightweight and easily-configurable DNS forwarder and DHCP server.

+
+ +

Multiple vulnerabilities have been discovered in Dnsmasq. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Dnsmasq users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-dns/dnsmasq-2.92_p2" + +
+ + CVE-2026-2291 + CVE-2026-4890 + CVE-2026-4891 + CVE-2026-4892 + CVE-2026-4893 + CVE-2026-5172 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-05.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-05.xml new file mode 100644 index 00000000000..09b891f4fed --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-05.xml @@ -0,0 +1,86 @@ + + + + Apache HTTPD: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Apache HTTPD, the worst of which could result in remote code execution. + apache + 2026-08-13 + 2026-08-13 + 915996 + 959821 + 967089 + 973625 + 977098 + remote + + + 2.4.68 + 2.4.68 + + + +

The Apache HTTP server is one of the most popular web servers on the Internet.

+
+ +

Multiple vulnerabilities have been discovered in Apache HTTPD. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Apache HTTPD users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/apache-2.4.68" + +
+ + CVE-2023-31122 + CVE-2023-43622 + CVE-2023-44487 + CVE-2023-45802 + CVE-2024-42516 + CVE-2024-43204 + CVE-2024-43394 + CVE-2024-47252 + CVE-2025-23048 + CVE-2025-49630 + CVE-2025-49812 + CVE-2025-53020 + CVE-2025-55753 + CVE-2025-58098 + CVE-2025-59775 + CVE-2025-65082 + CVE-2025-66200 + CVE-2026-23918 + CVE-2026-24072 + CVE-2026-28780 + CVE-2026-29167 + CVE-2026-29168 + CVE-2026-29169 + CVE-2026-29170 + CVE-2026-33006 + CVE-2026-33007 + CVE-2026-33523 + CVE-2026-33857 + CVE-2026-34032 + CVE-2026-34059 + CVE-2026-34355 + CVE-2026-34356 + CVE-2026-42535 + CVE-2026-42536 + CVE-2026-43951 + CVE-2026-44119 + CVE-2026-44185 + CVE-2026-44186 + CVE-2026-44631 + CVE-2026-48913 + CVE-2026-49975 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-06.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-06.xml new file mode 100644 index 00000000000..b6d0423a97e --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-06.xml @@ -0,0 +1,43 @@ + + + + Flatpak: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Flatpak, the worst of which allows sandbox escape. + flatpak + 2026-08-14 + 2026-08-14 + 972414 + local + + + 1.16.4 + 1.16.4 + + + +

Flatpak is a Linux application sandboxing and distribution framework.

+
+ +

Multiple vulnerabilities have been discovered in Flatpak. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Flatpak users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/flatpak-1.16.4" + +
+ + CVE-2026-34078 + CVE-2026-34079 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-07.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-07.xml new file mode 100644 index 00000000000..ff914f4a85b --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-07.xml @@ -0,0 +1,50 @@ + + + + Exim: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Exim, the worst of which allows arbitrary code execution. + exim + 2026-08-14 + 2026-08-14 + 938214 + 952139 + 974785 + local and remote + + + 4.99.4 + 4.99.4 + + + +

Exim is a message transfer agent (MTA) designed to be a a highly configurable, drop-in replacement for sendmail.

+
+ +

Multiple vulnerabilities have been discovered in Exim. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Exim users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=mail-mta/exim-4.99.4" + +
+ + CVE-2024-39929 + CVE-2025-30232 + CVE-2026-40684 + CVE-2026-40685 + CVE-2026-40686 + CVE-2026-40687 + CVE-2026-45185 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-08.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-08.xml new file mode 100644 index 00000000000..db2cc1ee7d5 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-08.xml @@ -0,0 +1,44 @@ + + + + libinput: Multiple Vulnerabilities + Multiple vulnerabilities have been found in libinput, the worst of which could result in privilege escalation. + libinput + 2026-08-14 + 2026-08-14 + 971879 + 976730 + local + + + 1.31.3 + 1.31.3 + + + +

A library to handle input devices in Wayland and, via xf86-input-libinput, in X.org.

+
+ +

Multiple vulnerabilities have been discovered in libinput. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All libinput users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/libinput-1.31.3" + +
+ + CVE-2026-35093 + CVE-2026-35094 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-09.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-09.xml new file mode 100644 index 00000000000..2acdc50de5a --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-09.xml @@ -0,0 +1,42 @@ + + + + Bubblewrap: Root privilege escalation + A vulnerability has been discovered in Bubblewrap that would allow root privilege escalation. + bubblewrap + 2026-08-14 + 2026-08-14 + 973131 + local + + + 0.11.2 + 0.11.2 + + + +

Bubblewrap is an unprivileged sandboxing tool namespaces-powered chroot-like solution.

+
+ +

A vulnerability has been discovered in Bubblewrap. Please review the CVE identifier referenced below for details.

+
+ +

An attacker could achieve root privilege escalation if Bubblewrap is used in its suid mode.

+
+ +

There is no known workaround at this time.

+
+ +

All Bubblewrap users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/bubblewrap-0.11.2" + +
+ + CVE-2026-41163 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-10.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-10.xml new file mode 100644 index 00000000000..f2cd3d5bfa2 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-10.xml @@ -0,0 +1,42 @@ + + + + HTTP-Daemon: Improper header handling + A vulnerability was found in HTTP-Daemon allowing header manipulation or filter bypass. + HTTP-Daemon + 2026-08-14 + 2026-08-14 + 908905 + remote + + + 6.160.0 + 6.160.0 + + + +

HTTP-Daemon provides a base class for simple HTTP servers.

+
+ +

Inconsistent Interpretation of HTTP Requests.

+
+ +

The bug could potentially be exploited to gain privileged access to APIs or poison intermediate caches.

+
+ +

There is no known workaround at this time.

+
+ +

All HTTP-Daemon users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-perl/HTTP-Daemon-6.160.0" + +
+ + CVE-2022-31081 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-11.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-11.xml new file mode 100644 index 00000000000..cde72a48c09 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-11.xml @@ -0,0 +1,44 @@ + + + + haveged: Privilege escalation + A vulnerability has been discovered in haveged which could allow local privilege escalation + haveged + 2026-08-15 + 2026-08-15 + 975496 + local + + + 1.9.21 + 1.9.21 + + + +

haveged is a simple entropy daemon using the HAVEGE algorithm.

+
+ +

A vulnerability has been discovered in haveged. Please review the CVE identifier referenced below for details.

+
+ +

Root privilege escalation may be achieved by an attacker.

+
+ +

There is no known workaround at this time.

+
+ +

All haveged users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/haveged-1.9.21" + + +

Alternatively, consider not using haveged anymore on modern Linux kernel versions, per https://www.openwall.com/lists/oss-security/2026/05/19/4

+
+ + CVE-2026-41054 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-12.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-12.xml new file mode 100644 index 00000000000..0de1abb55ec --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-12.xml @@ -0,0 +1,49 @@ + + + + Portage: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Portage. + portage + 2026-08-15 + 2026-08-15 + 978478 + 979026 + local and remote + + + 3.0.81.2 + 3.0.81.2 + + + +

Portage is the default Gentoo package management system.

+
+ +

Multiple vulnerabilities have been discovered in Portage. Please review the bugs referenced below for details. + +The first bug (bug 978478) allows a malicious ebuild (including a build system it uses indirectly) to write outside of the work directory. While malicious artifacts could be installed by a package itself, this is still unexpected if one only ran the configure phrase during development. + +The second bug (bug 979026) is regarding insufficient sandboxing in global scope. Untrusted ebuilds, even if not emerged, may have the opportunity to run code in global scope depending on whether the repository has metadata available. Additional sandboxing has been added.

+
+ +

Please review the referenced bugs for details.

+
+ +

Avoid using untrusted repositories or ebuilds, even without installing them.

+
+ +

All Portage users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/portage-3.0.81.2" + + +

In general, we recommend users add external repositories with caution. If using external repositories, it is good practice to mask all packages by default from that repository, and unmask only needed packages.

+
+ + CAN-2026-2033132 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-13.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-13.xml new file mode 100644 index 00000000000..4cc2f7d538f --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-13.xml @@ -0,0 +1,52 @@ + + + + NTFS-3G: Multiple Vulnerabilities + Multiple vulnerabilities have been found in NTFS-3G, the worst of which could result in privilege escalation. + ntfs3g + 2026-08-16 + 2026-08-16 + 973067 + 979306 + local + + + 2026.7.7 + 2026.7.7 + + + +

NTFS-3G is a stable, full-featured, read-write NTFS driver for various operating systems.

+
+ +

Multiple vulnerabilities have been discovered in NTFS-3G. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All NTFS-3G users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-fs/ntfs3g-2026.7.7" + +
+ + CVE-2026-40706 + CVE-2026-42616 + CVE-2026-42617 + CVE-2026-42618 + CVE-2026-46569 + CVE-2026-46570 + CVE-2026-46571 + CVE-2026-46572 + CVE-2026-56135 + CVE-2026-56136 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-14.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-14.xml new file mode 100644 index 00000000000..599d122f67a --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-14.xml @@ -0,0 +1,80 @@ + + + + X.Org X server, XWayland: Multiple Vulnerabilities + Multiple vulnerabilities have been found in X.Org X server, XWayland. + xorg-server,xwayland + 2026-08-17 + 2026-08-17 + 958340 + 965271 + 972712 + 976628 + 978969 + remote + + + 21.1.24 + 21.1.24 + + + 24.1.13 + 24.1.13 + + + +

The X Window System is a graphical windowing system based on a client/server model.

+
+ +

Multiple vulnerabilities have been discovered in X.Org X server, XWayland. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All X.Org X server, XWayland users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-base/xorg-server-21.1.24" + + +

All X.Org X server, XWayland users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=x11-base/xwayland-24.1.13" + +
+ + CVE-2025-49175 + CVE-2025-49176 + CVE-2025-49177 + CVE-2025-49178 + CVE-2025-49179 + CVE-2025-49180 + CVE-2025-62229 + CVE-2025-62230 + CVE-2025-62231 + CVE-2026-33999 + CVE-2026-34000 + CVE-2026-34001 + CVE-2026-34002 + CVE-2026-34003 + CVE-2026-50256 + CVE-2026-50257 + CVE-2026-50258 + CVE-2026-50259 + CVE-2026-50260 + CVE-2026-50261 + CVE-2026-50262 + CVE-2026-50263 + CVE-2026-55999 + CVE-2026-56000 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-15.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-15.xml new file mode 100644 index 00000000000..86f0ed9b4e8 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-15.xml @@ -0,0 +1,104 @@ + + + + PostgreSQL: Multiple Vulnerabilities + Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in arbitrary code execution. + postgresql + 2026-08-17 + 2026-08-17 + 949747 + 955658 + 961496 + 966064 + 969976 + 974982 + local and remote + + + 14.23-r1 + 15.18-r1 + 16.14-r1 + 17.10 + 18.4 + 14.23-r1 + 15.18-r1 + 16.14-r1 + 17.10 + 18.4 + + + +

PostgreSQL is an open source object-relational database management system.

+
+ +

Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All PostgreSQL 14 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-14.23-r1:14" + + +

All PostgreSQL 15 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-15.18-r1:15" + + +

All PostgreSQL 16 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-16.14-r1:16" + + +

All PostgreSQL 17 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-17.10:17" + + +

All PostgreSQL 18 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-db/postgresql-18.4:18" + +
+ + CVE-2025-1094 + CVE-2025-4207 + CVE-2025-8713 + CVE-2025-8714 + CVE-2025-8715 + CVE-2025-12817 + CVE-2026-2003 + CVE-2026-2004 + CVE-2026-2005 + CVE-2026-2006 + CVE-2026-2007 + CVE-2026-6472 + CVE-2026-6473 + CVE-2026-6474 + CVE-2026-6475 + CVE-2026-6476 + CVE-2026-6477 + CVE-2026-6478 + CVE-2026-6479 + CVE-2026-6575 + CVE-2026-6637 + CVE-2026-6638 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-16.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-16.xml new file mode 100644 index 00000000000..fb8644d1b0c --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-16.xml @@ -0,0 +1,68 @@ + + + + nginx: Multiple Vulnerabilities + Multiple vulnerabilities have been found in nginx, the worst of which could result in arbitrary code execution. + nginx + 2026-08-17 + 2026-08-17 + 949354 + 967910 + 969626 + 971553 + 974894 + 975844 + 977606 + 979311 + remote + + + 1.30.4-r1 + 1.30.4-r1 + + + +

nginx is a robust, small, and high performance HTTP and reverse proxy server.

+
+ +

Multiple vulnerabilities have been discovered in nginx. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All nginx users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/nginx-1.30.4-r1" + +
+ + CVE-2025-23419 + CVE-2025-53859 + CVE-2026-1642 + CVE-2026-9256 + CVE-2026-27651 + CVE-2026-27654 + CVE-2026-27784 + CVE-2026-28753 + CVE-2026-28755 + CVE-2026-32647 + CVE-2026-40701 + CVE-2026-42055 + CVE-2026-42530 + CVE-2026-42533 + CVE-2026-42934 + CVE-2026-42945 + CVE-2026-42946 + CVE-2026-48142 + CVE-2026-56434 + CVE-2026-60005 + + sam + sam +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-17.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-17.xml new file mode 100644 index 00000000000..fb2863f4eff --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-17.xml @@ -0,0 +1,45 @@ + + + + libssh2: Multiple Vulnerabilities + Multiple vulnerabilities have been found in libssh2, the worst of which could result in remote code execution. + libssh2 + 2026-08-20 + 2026-08-20 + 977961 + remote + + + 1.11.1-r2 + 1.11.1-r2 + + + +

libssh2 is a library implementing the SSH2 protocol.

+
+ +

Multiple vulnerabilities have been discovered in libssh2. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All libssh2 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-libs/libssh2-1.11.1-r2" + +
+ + CVE-2025-15661 + CVE-2026-7598 + CVE-2026-55199 + CVE-2026-55200 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-18.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-18.xml new file mode 100644 index 00000000000..964bb5494ab --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-18.xml @@ -0,0 +1,60 @@ + + + + GNU Emacs: Arbitrary code execution + A vulnerability has been discovered in GNU Emacs which could lead to arbitrary code execution. + emacs + 2026-08-20 + 2026-08-20 + 980616 + remote + + + 28.2-r21 + 29.4-r9 + 30.2-r5 + 28 + 28.2-r21 + 29.4-r9 + 30.2-r5 + + + +

GNU Emacs is the extensible, customizable, self-documenting real-time display editor.

+
+ +

A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details.

+
+ +

An attacker could achieve arbitrary code execution by tricking a user into opening a file with malicious content. No other action by the user is required.

+
+ +

Avoid opening any untrusted files.

+
+ +

All GNU Emacs 28 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r21:28" + + +

All GNU Emacs 29 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r9:29" + + +

All GNU Emacs 30 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r5:30" + +
+ + + sam + sam +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-19.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-19.xml new file mode 100644 index 00000000000..c8c937c2f21 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-19.xml @@ -0,0 +1,44 @@ + + + + quickjs-ng: Multiple Vulnerabilities + Multiple vulnerabilities have been found in quickjs-ng, the worst of which could result in arbitrary code execution. + quickjs-ng + 2026-08-20 + 2026-08-20 + 969863 + remote + + + 0.12.0 + 0.12.0 + + + +

quickjs-ng is a small and embeddable JavaScript engine. It aims to support the latest ECMAScript specification. It is a fork of QuickJS.

+
+ +

Multiple vulnerabilities have been discovered in quickjs-ng. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All quickjs-ng users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-libs/quickjs-ng-0.12.0" + +
+ + CVE-2026-0821 + CVE-2026-1144 + CVE-2026-1145 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-20.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-20.xml new file mode 100644 index 00000000000..6838c317ce4 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-20.xml @@ -0,0 +1,55 @@ + + + + acl, attr: Multiple vulnerabilities + Multiple vulnerabilities have been found in acl and attr, the worst of which could lead to local privilege escalation. + acl,attr + 2026-08-20 + 2026-08-20 + 978280 + local + + + 2.4.0 + 2.4.0 + + + 2.6.0 + 2.6.0 + + + +

For more information on the packages listed in this GLSA, please see their homepage referenced in the ebuild.

+
+ +

Multiple vulnerabilities have been discovered in acl and attr. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All acl users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/acl-2.4.0" + + +

All attr users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=sys-apps/attr-2.6.0" + +
+ + CVE-2026-54369 + CVE-2026-54370 + CVE-2026-54371 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-21.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-21.xml new file mode 100644 index 00000000000..dfaa6eab354 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-21.xml @@ -0,0 +1,69 @@ + + + + GNU Emacs: Arbitrary code execution + A vulnerability has been discovered in GNU Emacs allowing arbitrary code execution. + emacs + 2026-08-24 + 2026-08-26 + 981157 + local and remote + + + 27.2-r4 + 28.2-r22 + 29.4-r10 + 30.2-r6 + 27.2-r4 + 28.2-r22 + 29.4-r10 + 30.2-r6 + + + +

GNU Emacs is the extensible, customizable, self-documenting real-time display editor.

+
+ +

A vulnerability has been discovered in GNU Emacs. Please review the CVE identifier referenced below for details.

+
+ +

An attacker could achieve arbitrary code execution by tricking a user into opening a file or directory with a malicious filename via TRAMP.

+
+ +

There is no known workaround at this time.

+
+ +

All GNU Emacs 27 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-27.2-r4:27" + + +

All GNU Emacs 28 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-28.2-r22:28" + + +

All GNU Emacs 29 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-29.4-r10:29" + + +

All GNU Emacs 30 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-editors/emacs-30.2-r6:30" + +
+ + CVE-2026-79992 + + sam + sam +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-22.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-22.xml new file mode 100644 index 00000000000..cacd6d844c3 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-22.xml @@ -0,0 +1,45 @@ + + + + needrestart: Multiple vulnerabilities + Multiple vulnerabilities have been discovered in needrestart, the worst of which allowing root privilege escalation. + needrestart + 2026-08-24 + 2026-08-24 + 944015 + local + + + 3.8 + 3.8 + + + +

needrestart is a tool to restart daemons after library updates.

+
+ +

Multiple vulnerabilities have been discovered in needrestart. Please review the CVE identifier referenced below for details.

+
+ +

An attacker could achieve root privilege escalation.

+
+ +

There is no known workaround at this time.

+
+ +

All needrestart users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-admin/needrestart-3.8" + +
+ + CVE-2024-11003 + CVE-2024-48990 + CVE-2024-48991 + CVE-2024-48992 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-23.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-23.xml new file mode 100644 index 00000000000..9bca52f2edb --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-23.xml @@ -0,0 +1,65 @@ + + + + Incus: Multiple Vulnerabilities + Multiple vulnerabilities have been found in incus, the worst of which could result in privilege escalation. + incus + 2026-08-25 + 2026-08-25 + 969235 + 974495 + 978133 + 980304 + local and remote + + + 7.0.1-r1 + 7.0.1-r1 + + + +

Incus is a container and virtual machine manager.

+
+ +

Multiple vulnerabilities have been discovered in Incus. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Incus users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-containers/incus-7.0.1-r1" + +
+ + CVE-2026-23953 + CVE-2026-23954 + CVE-2026-35527 + CVE-2026-40195 + CVE-2026-40197 + CVE-2026-40243 + CVE-2026-40251 + CVE-2026-41647 + CVE-2026-41648 + CVE-2026-41684 + CVE-2026-41685 + CVE-2026-48749 + CVE-2026-48750 + CVE-2026-48751 + CVE-2026-48752 + CVE-2026-48755 + CVE-2026-48769 + CVE-2026-55621 + CVE-2026-55622 + GHSA-7f67-crqm-jgh7 + GHSA-x6jc-phwx-hp32 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-24.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-24.xml new file mode 100644 index 00000000000..6bbbb003d69 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-24.xml @@ -0,0 +1,43 @@ + + + + DTrace: Multiple Vulnerabilities + Multiple vulnerabilities have been found in DTrace, the worst of which could allow denial of service. + dtrace + 2026-08-26 + 2026-08-26 + 974696 + local + + + 2.0.7 + 2.0.7 + + + +

DTrace is a dynamic tracing tool for analysing or debugging the whole system. Specifically, dtprobed is a component of the DTrace system that keeps track of USDT probes within running processes, parsing and storing the DOF they provide for later consumption by dtrace proper.

+
+ +

Multiple vulnerabilities have been discovered in DTrace. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All DTrace users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-debug/dtrace-2.0.7" + +
+ + CVE-2026-21996 + CVE-2026-35233 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-25.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-25.xml new file mode 100644 index 00000000000..89c7a17c4d6 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-25.xml @@ -0,0 +1,41 @@ + + + + UnrealIRCd: Denial of service + A vulnerability has been discovered in UnrealIRCd, possibly allowing denial of service. + unrealircd + 2026-08-26 + 2026-08-26 + 832272 + remote + + + 6.0.2 + 6.0.2 + + + +

UnrealIRCd is an Internet Relay Chat (IRC) daemon.

+
+ +

A vulnerability has been discovered in UnrealIRCd. Please review the CVE identifier referenced below for details.

+
+ +

An attacker may be able to achieve denial of service.

+
+ +

There is no known workaround at this time.

+
+ +

All UnrealIRCd users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-irc/unrealircd-6.0.2" + +
+ + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-26.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-26.xml new file mode 100644 index 00000000000..c8c30db8803 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-26.xml @@ -0,0 +1,51 @@ + + + + Vinyl Cache: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Vinyl Cache, allowing request smuggling and denial of service. + vinyl-cache + 2026-08-26 + 2026-08-27 + 880627 + 918416 + 959302 + 964043 + 975350 + remote + + + 8.0.2 + 8.0.2 + + + +

Vinyl Cache is a web application accelerator. Vinyl Cache was previously named Varnish.

+
+ +

Multiple vulnerabilities have been discovered in Vinyl Cache. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Vinyl Cache users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-servers/vinyl-cache-8.0.2" + +
+ + CVE-2022-45059 + CVE-2022-45060 + CVE-2025-8671 + CVE-2025-30346 + CVE-2025-47905 + CVE-2026-50052 + + sam + sam +
diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-27.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-27.xml new file mode 100644 index 00000000000..c8046ee7666 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-27.xml @@ -0,0 +1,46 @@ + + + + GNU screen: Multiple Vulnerabilities + Multiple vulnerabilities have been found in GNU screen. + screen + 2026-08-26 + 2026-08-26 + 955907 + local and remote + + + 4.9.1-r2 + 4.9.1-r2 + + + +

GNU screen is a full-screen window manager that multiplexes a physical terminal between several processes, typically interactive shells.

+
+ +

Multiple vulnerabilities have been discovered in GNU screen. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All GNU screen users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-misc/screen-4.9.1-r2" + +
+ + CVE-2025-23395 + CVE-2025-46802 + CVE-2025-46803 + CVE-2025-46804 + CVE-2025-46805 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-28.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-28.xml new file mode 100644 index 00000000000..a2f5f502587 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-28.xml @@ -0,0 +1,140 @@ + + + + Chromium, Google Chrome, Microsoft Edge. Opera: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Chromium, Google Chrome, Microsoft Edge. Opera. + chromium,google-chrome,microsoft-edge,opera + 2026-08-27 + 2026-08-27 + 931653 + 931897 + 932394 + 934536 + 934959 + 936611 + 937510 + 938295 + remote + + + 128.0.6613.84 + 128.0.6613.84 + + + 128.0.6613.84 + 128.0.6613.84 + + + 128.0.2739.42 + 128.0.2739.42 + + + 114.0.5282.21 + 114.0.5282.21 + + + +

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.

+
+ +

Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-128.0.6613.84" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/google-chrome-128.0.6613.84" + + +

All Microsoft Edge users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-128.0.2739.42" + + +

All Opera users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/opera-114.0.5282.21" + +
+ + CVE-2024-4671 + CVE-2024-4761 + CVE-2024-5157 + CVE-2024-5158 + CVE-2024-5159 + CVE-2024-5160 + CVE-2024-6100 + CVE-2024-6101 + CVE-2024-6102 + CVE-2024-6103 + CVE-2024-6290 + CVE-2024-6291 + CVE-2024-6292 + CVE-2024-6293 + CVE-2024-6988 + CVE-2024-6989 + CVE-2024-6991 + CVE-2024-6994 + CVE-2024-6995 + CVE-2024-6996 + CVE-2024-6997 + CVE-2024-6998 + CVE-2024-6999 + CVE-2024-7000 + CVE-2024-7001 + CVE-2024-7003 + CVE-2024-7004 + CVE-2024-7005 + CVE-2024-7532 + CVE-2024-7533 + CVE-2024-7534 + CVE-2024-7535 + CVE-2024-7536 + CVE-2024-7550 + CVE-2024-7964 + CVE-2024-7965 + CVE-2024-7966 + CVE-2024-7967 + CVE-2024-7968 + CVE-2024-7971 + CVE-2024-7972 + CVE-2024-7973 + CVE-2024-7974 + CVE-2024-7975 + CVE-2024-7976 + CVE-2024-7977 + CVE-2024-7978 + CVE-2024-7979 + CVE-2024-7980 + CVE-2024-7981 + CVE-2024-8033 + CVE-2024-8034 + CVE-2024-8035 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-29.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-29.xml new file mode 100644 index 00000000000..15404c36346 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-29.xml @@ -0,0 +1,111 @@ + + + + Chromium, Google Chrome, Microsoft Edge, Opera: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Chromium, Google Chrome, Microsoft Edge, and Opera. + chromium,google-chrome,microsoft-edge,opera + 2026-08-27 + 2026-08-27 + 939217 + 939451 + 939801 + 940208 + 940637 + 941186 + 941989 + 944072 + remote + + + 131.0.6778.85 + 131.0.6778.85 + + + 131.0.6778.85 + 131.0.6778.85 + + + 131.0.2903.63 + 131.0.2903.63 + + + 116.0.5366.21 + 116.0.5366.21 + + + +

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.

+
+ +

Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-131.0.6778.85" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/google-chrome-131.0.6778.85" + + +

All Microsoft Edge users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-131.0.2903.63" + + +

All Opera users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/opera-116.0.5366.21" + +
+ + CVE-2024-7025 + CVE-2024-7970 + CVE-2024-8362 + CVE-2024-8636 + CVE-2024-8637 + CVE-2024-8638 + CVE-2024-8639 + CVE-2024-8904 + CVE-2024-8905 + CVE-2024-8906 + CVE-2024-8907 + CVE-2024-8908 + CVE-2024-8909 + CVE-2024-9121 + CVE-2024-9122 + CVE-2024-9123 + CVE-2024-9369 + CVE-2024-9370 + CVE-2024-9602 + CVE-2024-9603 + CVE-2024-10229 + CVE-2024-10230 + CVE-2024-10231 + CVE-2024-11395 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-30.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-30.xml new file mode 100644 index 00000000000..400630169ba --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-30.xml @@ -0,0 +1,44 @@ + + + + OpenRGB: Multiple Vulnerabilities + Multiple vulnerabilities have been found in OpenRGB, allowing root remote command execution. + openrgb + 2026-08-27 + 2026-08-27 + 981449 + local and remote + + + 1.0_rc3_p1 + 1.0_rc3_p1 + + + +

OpenRGB is a cross-platform software suite for controlling RGB LED lighting devices.

+
+ +

Multiple vulnerabilities have been discovered in OpenRGB. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time. Users are recommended to avoid exposing OpenRGB to the network even with these fixes.

+
+ +

All OpenRGB users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=app-misc/openrgb-1.0_rc3_p1" + +
+ + CVE-2026-18794 + CVE-2026-59682 + CVE-2026-59683 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-31.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-31.xml new file mode 100644 index 00000000000..78b9db019b1 --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-31.xml @@ -0,0 +1,125 @@ + + + + Chromium, Google Chrome, Microsoft Edge, Opera, Vivaldi: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Chromium, Google Chrome, Microsoft Edge, Opera, and Vivaldi. + chromium,google-chrome,microsoft-edge,opera,vivaldi + 2026-08-27 + 2026-08-27 + 970044 + 970045 + 970311 + 970511 + 970908 + remote + + + 145.0.7632.159 + 145.0.7632.159 + + + 145.0.7632.159 + 145.0.7632.159 + + + 145.0.3800.97 + 145.0.3800.97 + + + 130.0.5846.0 + 130.0.5846.0 + + + 7.8.3925.76 + 7.8.3925.76 + + + +

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser. + +Vivaldi is a powerful, personal and private browser that adapts to you.

+
+ +

Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, Opera, and Vivaldi. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-145.0.7632.159" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/google-chrome-145.0.7632.159" + + +

All Microsoft Edge users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-145.0.3800.97" + + +

All Opera users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/opera-130.0.5846.0" + + +

All Vivaldi users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/vivaldi-7.8.3925.76" + +
+ + CVE-2026-2313 + CVE-2026-2314 + CVE-2026-2315 + CVE-2026-2316 + CVE-2026-2317 + CVE-2026-2318 + CVE-2026-2319 + CVE-2026-2320 + CVE-2026-2321 + CVE-2026-2322 + CVE-2026-2323 + CVE-2026-2441 + CVE-2026-2648 + CVE-2026-2649 + CVE-2026-2650 + CVE-2026-3061 + CVE-2026-3062 + CVE-2026-3063 + CVE-2026-3536 + CVE-2026-3537 + CVE-2026-3538 + CVE-2026-3539 + CVE-2026-3540 + CVE-2026-3541 + CVE-2026-3542 + CVE-2026-3543 + CVE-2026-3544 + CVE-2026-3545 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-32.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-32.xml new file mode 100644 index 00000000000..a77db95045e --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-32.xml @@ -0,0 +1,68 @@ + + + + Tor: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Tor, the worst of which could allow remote code execution. + tor + 2026-08-29 + 2026-08-29 + 965987 + 969415 + 971568 + 974279 + 976637 + 977978 + 978087 + remote + + + 0.4.9.11 + 0.4.9.11 + + + +

Tor is an implementation of second generation Onion Routing, a connection-oriented anonymizing communication service.

+
+ +

Multiple vulnerabilities have been discovered in Tor. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Tor users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.9.11" + +
+ + TROVE-2025-014 + TROVE-2025-015 + TROVE-2025-016 + TROVE-2026-003 + TROVE-2026-004 + TROVE-2026-006 + TROVE-2026-007 + TROVE-2026-008 + TROVE-2026-009 + TROVE-2026-010 + TROVE-2026-011 + TROVE-2026-013 + TROVE-2026-014 + TROVE-2026-015 + TROVE-2026-017 + TROVE-2026-018 + TROVE-2026-019 + TROVE-2026-020 + TROVE-2026-021 + TROVE-2026-025 + TROVE-2026-026 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-33.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-33.xml new file mode 100644 index 00000000000..3ebb7c7328a --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-33.xml @@ -0,0 +1,41 @@ + + + + Freenet: Deanonymization Vulnerability + A vulnerability has been discovered in Freenet, where an XSS vulnerability could lead to deanonymization. + freenet + 2026-08-29 + 2026-08-29 + 970477 + remote + + + 0.7.5_p1505 + 0.7.5_p1505 + + + +

Freenet is an encrypted network without censorship.

+
+ +

A vulnerability has been discovered in Freenet. Please review the CVE identifier referenced below for details.

+
+ +

This release fixes as an XSS vulnerability that may allow an attacker to deanonymize the user.

+
+ +

There is no known workaround at this time.

+
+ +

All Freenet users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-p2p/freenet-0.7.5_p1505" + +
+ + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-34.xml b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-34.xml new file mode 100644 index 00000000000..0defe60543e --- /dev/null +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/glsa-202608-34.xml @@ -0,0 +1,113 @@ + + + + Chromium, Google Chrome, Microsoft Edge, Opera: Multiple Vulnerabilities + Multiple vulnerabilities have been found in Chromium, Google Chrome, Microsoft Edge, and Opera. + chromium,google-chrome,microsoft-edge,opera + 2026-08-31 + 2026-08-31 + 945839 + 946253 + 948596 + 949327 + 949698 + 949956 + 953069 + 953456 + 953897 + remote + + + 135.0.7049.95 + 135.0.7049.95 + + + 135.0.7049.95 + 135.0.7049.95 + + + 135.0.3179.85 + 135.0.3179.85 + + + 120.0.5543.8 + 120.0.5543.8 + + + +

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. + +Google Chrome is one fast, simple, and secure browser for all your devices. + +Microsoft Edge is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. + +Opera is a fast and secure web browser.

+
+ +

Multiple vulnerabilities have been discovered in Chromium, Google Chrome, Microsoft Edge, and Opera. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All Chromium users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/chromium-135.0.7049.95" + + +

All Google Chrome users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/google-chrome-135.0.7049.95" + + +

All Microsoft Edge users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/microsoft-edge-135.0.3179.85" + + +

All Opera users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-client/opera-120.0.5543.8" + +
+ + CVE-2024-12053 + CVE-2024-12381 + CVE-2024-12382 + CVE-2025-0444 + CVE-2025-0445 + CVE-2025-0451 + CVE-2025-0611 + CVE-2025-0612 + CVE-2025-0995 + CVE-2025-0996 + CVE-2025-0997 + CVE-2025-0998 + CVE-2025-0999 + CVE-2025-1006 + CVE-2025-1426 + CVE-2025-3066 + CVE-2025-3067 + CVE-2025-3068 + CVE-2025-3069 + CVE-2025-3070 + CVE-2025-3071 + CVE-2025-3072 + CVE-2025-3073 + CVE-2025-3074 + CVE-2025-3620 + + sam + sam +
\ No newline at end of file diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk index 003c838d873..d7536d73019 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.chk @@ -1 +1 @@ -Sat, 01 Aug 2026 07:07:54 +0000 +Tue, 01 Sep 2026 06:38:16 +0000 diff --git a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit index cd55ba34aa3..8673fc0bd6b 100644 --- a/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit +++ b/sdk_container/src/third_party/portage-stable/metadata/glsa/timestamp.commit @@ -1 +1 @@ -f40d2fdd24a34342a4c050396f064a038ebebb9b 1776459195 2026-04-17T20:53:15Z +094e7ce86b9627f326c34f9ba9f681d9d7da3b1d 1788179524 2026-08-31T12:32:04Z