From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: DKIM-Filter: OpenDKIM Filter v2.11.0 mskdc-relay.altlinux.org BD68E60182 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=altlinux.org; s=relay-alt2025; t=1775694060; bh=L4uJTS/uYqBcreGiCj5Ty1cjLT++lJ75FVzuDR/7M9A=; h=Date:From:To:Subject:From; b=dAfQU0TxQIlpM3tDBxB1Pp+ZwtuHMmEqbfSpu10JsdjUWISW34m5YY1/Hb+6sw1C9 v5rBSBgxPbTwEoWvlmKryH+YYEgx0sdhG1N9gLXtlBnSNKVpyiita+H4Bw1nxSdMsb Qn+WKwZFgokismeWDrYUDOp+fcaKuojnA/W17pfs= Date: Thu, 9 Apr 2026 00:21:00 +0000 From: QA Team Robot To: sisyphus-cybertalk@lists.altlinux.org Message-ID: Mail-Followup-To: sisyphus-cybertalk@lists.altlinux.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Subject: [cyber] I: p11/branch packages: +4! -2 +11 (20220) X-BeenThere: sisyphus-cybertalk@lists.altlinux.org X-Mailman-Version: 2.1.12 Precedence: list Reply-To: devel@lists.altlinux.org List-Id: ALT Linux Sisyphus cybertalk List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 09 Apr 2026 00:21:00 -0000 Archived-At: List-Archive: 4 ADDED packages curlie - User-friendly curl wrapper with HTTPie-style syntax and features * Fri May 23 2025 Maxim Tulskiy 1.8.1-alt1 - Initial build for ALT Sisyphus. gatekeeper - An OpenID / Proxy service [40M] * Thu Apr 02 2026 Evgeniy Martynenko 4.7.1-alt1 - Initial build for ALT. python3-module-tempita - Tempita is a small templating language for text substitution * Thu Aug 07 2025 Maxim Tulskiy 0.6.0-alt1 - Initial build for ALT Sisyphus. rtk - CLI proxy that reduces LLM token consumption on common dev commands [10M] * Thu Mar 26 2026 Vladislav Glinkin 0.33.1-alt1 - Initial build for ALT 2 REMOVED packages freeipa-desktop-profile 0.0.8-alt4 openct 0.6.20-alt4.qa1 11 UPDATED packages alt-releases-matrix - A comprehensive, cross-language set of constants and definitions related to ALT Linux repositories and dis * Mon Apr 06 2026 Danil Shein 0.2.4-alt1 - new version * Mon Jan 19 2026 Danil Shein 0.2.3-alt1 docs-alt-server - ALT Server documentation [38M] * Mon Mar 23 2026 Elena Mishina 11.1-alt6 - update to ALT Server 11.1RC2 - fix some typos (closes #57752, #57753) - update docker (closes #57754) - add FreeRADIUS * Thu Jan 29 2026 Elena Mishina 11.1-alt5 firefox - The Mozilla Firefox project is a redesign of Mozilla's browser [707M] * Thu Mar 26 2026 Ajrat Makhmutov 149.0-alt1 - New version (149.0). - Fixes: + CVE-2026-4684: Race condition, use-after-free in the Graphics: WebRender component + CVE-2026-4685: Incorrect boundary conditions in the Graphics: Canvas2D component + CVE-2026-4686: Incorrect boundary conditions in the Graphics: Canvas2D component + CVE-2026-4687: Sandbox escape due to incorrect boundary conditions in the Telemetry component + CVE-2026-4688: Sandbox escape due to use-after-free in the Disability Access APIs component + CVE-2026-4689: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component + CVE-2026-4690: Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component + CVE-2026-4691: Use-after-free in the CSS Parsing and Computation component + CVE-2026-4692: Sandbox escape in the Responsive Design Mode component + CVE-2026-4693: Incorrect boundary conditions in the Audio/Video: Playback component + CVE-2026-4694: Incorrect boundary conditions, integer overflow in the Graphics component + CVE-2026-4695: Incorrect boundary conditions in the Audio/Video: Web Codecs component + CVE-2026-4696: Use-after-free in the Layout: Text and Fonts component + CVE-2026-4697: Incorrect boundary conditions in the Audio/Video: Web Codecs component + CVE-2026-4698: JIT miscompilation in the JavaScript Engine: JIT component + CVE-2026-4699: Incorrect boundary conditions in the Layout: Text and Fonts component + CVE-2026-4700: Mitigation bypass in the Networking: HTTP component + CVE-2026-4701: Use-after-free in the JavaScript Engine component + CVE-2026-4722: Privilege escalation in the IPC component + CVE-2026-4702: JIT miscompilation in the JavaScript Engine component + CVE-2026-4723: Use-after-free in the JavaScript Engine component + CVE-2026-4724: Undefined behavior in the Audio/Video component + CVE-2026-4704: Denial-of-service in the WebRTC: Signaling component + CVE-2026-4705: Undefined behavior in the WebRTC: Signaling component + CVE-2026-4706: Incorrect boundary conditions in the Graphics: Canvas2D component + CVE-2026-4707: Incorrect boundary conditions in the Graphics: Canvas2D component + CVE-2026-4708: Incorrect boundary conditions in the Graphics component + CVE-2026-4709: Incorrect boundary conditions in the Audio/Video: GMP component + CVE-2026-4710: Incorrect boundary conditions in the Audio/Video component + CVE-2026-4711: Use-after-free in the Widget: Cocoa component + CVE-2026-4725: Sandbox escape due to use-after-free in the Graphics: Canvas2D component + CVE-2026-4712: Information disclosure in the Widget: Cocoa component + CVE-2026-4713: Incorrect boundary conditions in the Graphics component + CVE-2026-4714: Incorrect boundary conditions in the Audio/Video component + CVE-2026-4715: Uninitialized memory in the Graphics: Canvas2D component + CVE-2026-4716: Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component + CVE-2026-4717: Privilege escalation in the Netmonitor component + CVE-2026-4726: Denial-of-service in the XML component + CVE-2025-59375: Denial-of-service in the XML component + CVE-2026-4727: Denial-of-service in the Libraries component in NSS + CVE-2026-4728: Spoofing issue in the Privacy: Anti-Tracking component + CVE-2026-4718: Undefined behavior in the WebRTC: Signaling component + CVE-2026-4719: Incorrect boundary conditions in the Graphics: Text component + CVE-2026-4720: Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 + CVE-2026-4729: Memory safety bugs fixed in Firefox 149 and Thunderbird 149 + CVE-2026-4721: Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 * Tue Mar 10 2026 Ajrat Makhmutov 148.0.2-alt1 - New version (148.0.2). - Fixes: + CVE-2026-3845: Heap buffer overflow in the Audio/Video: Playback component in Firefox for Android + CVE-2026-3846: Same-origin policy bypass in the CSS Parsing and Computation component + CVE-2026-3847: Memory safety bugs fixed in Firefox 148.0.2 * Sat Feb 28 2026 Ajrat Makhmutov 148.0-alt2 kdiff3 - Compare + merge 2 or 3 files or directories * Fri Apr 03 2026 Sergey V Turchin 1.12.4-alt1 - new version * Tue Jul 22 2025 Sergey V Turchin 1.12.3-alt1 ollama - Get up and running with large language models [29M] * Sun Apr 05 2026 Vitaly Chikunov 0.20.2-alt1 - Update to v0.20.2 (2026-04-03). * Tue Mar 10 2026 Vitaly Chikunov 0.17.7-alt1 - Update to v0.17.7 (2026-03-05). * Mon Mar 02 2026 Vitaly Chikunov 0.17.5-alt1 - Update to v0.17.5 (2026-03-01). * Thu Feb 26 2026 Vitaly Chikunov 0.17.1-alt1 - Experimental update to v0.17.1 (2026-02-25). * Sat Feb 07 2026 Vitaly Chikunov 0.15.6-alt1 - Update to v0.15.6 (2026-02-06). * Sun Jan 25 2026 Vitaly Chikunov 0.15.1-alt1 - Update to v0.15.1 (2026-01-24). * Wed Jan 14 2026 Vitaly Chikunov 0.14.0-alt1 - Update to v0.14.0 (2026-01-13). * Wed Jan 07 2026 Vitaly Chikunov 0.13.5-alt1 - Update to v0.13.5 (2025-12-18). * Fri Dec 12 2025 Vitaly Chikunov 0.13.3-alt1 - Update to v0.13.3 (2025-12-11). * Sat Nov 15 2025 Vitaly Chikunov 0.12.11-alt1 opensc - OpenSC library - for accessing SmartCard devices using PC/SC Lite * Tue Mar 31 2026 Andrey Cherepanov 0.27.0-alt1 - New version (fixes: CVE-2025-13763, CVE-2025-49010, CVE-2025-66215, CVE-2025-66038, CVE-2025-66037). * Wed Mar 05 2025 Alexander Danilov 0.26.1-alt1 pkcs11-provider - A PKCS#11 provider for OpenSSL 3.0+ * Fri Feb 20 2026 Stanislav Levin 1.2.0-alt1 - 1.1.0 -> 1.2.0. * Thu Oct 02 2025 Stanislav Levin 1.1.0-alt1 - 1.0 -> 1.1.0. * Mon Feb 17 2025 Stanislav Levin 1.0-alt1 python3-module-ecdsa - ECDSA cryptographic signature library (pure python) * Tue Apr 07 2026 Alexander Danilov 0.19.2-alt1 - new version 0.19.2 * Sat Mar 07 2026 Vitaly Lipatov 0.19.1-alt1 - new version 0.19.1 * Tue Mar 18 2025 Vitaly Lipatov 0.19.0-alt1 - new version 0.19.0 (with rpmrb script) * Sun Sep 11 2022 Vitaly Lipatov 0.18.0-alt1 python3-module-nltk - Python modules for Natural Language Processing (NLP) * Mon Apr 06 2026 Stanislav Levin 3.9.4-alt1.p11.1 - Backported to p11. * Mon Apr 06 2026 Stanislav Levin 3.9.4-alt2 - Added missing runtime dependency on sqlite3. * Fri Apr 03 2026 Stanislav Levin 3.9.4-alt1 - 3.9.1 -> 3.9.4. - (Fixes: CVE-2025-14009, CVE-2026-0846, CVE-2026-0847, CVE-2026-0848) - (Fixes: CVE-2026-33230, CVE-2026-33231, CVE-2026-33236) * Thu Nov 21 2024 Stanislav Levin 3.9.1-alt2.p11.1 qtgraphs-qt6 - Qt Graphs library for data visualization * Mon Apr 06 2026 Yuri N. Sedunov 6.10.2-alt1.1 - fixed %files after qt6-base-6.10.2-alt2 * Fri Feb 13 2026 Yuri N. Sedunov 6.10.2-alt1 rspamd - Fast and modular antispam system written in C * Tue Mar 31 2026 Vitaly Lipatov 4.0.0-alt1 - new version 4.0.0 (with rpmrb script) - add mapstats to files list - add BR: perl-JSON-PP perl-NetAddr-IP (for mapstats perl script) - disable SYSTEM_DOCTEST (incompatible with doctest 2.5.0) * Wed Mar 11 2026 Vitaly Lipatov 3.14.2-alt1 - new version 3.14.2 (with rpmrb script) - add antivirus.conf.example to files list * Wed Feb 25 2026 Michael Shigorin 3.12.1-alt2 - E2K: avoid BR: libunwind-devel (cf.: mcst#6690) * Wed Jul 30 2025 Vitaly Lipatov 3.12.1-alt1 Total 20220 source packages.