tarpit
Security & Cryptography desk
PHP security releases fix SQL injection and out-of-bounds write
Four branches ship fixes for PostgreSQL injection, Phar crashes, libgd, and a BCMath flaw limited to newer lines.
Researcher discloses 33 flaws in stagnant cJSON library
Memory-safety and logic bugs remain unfixed in a widely vendored C JSON parser after years of stalled maintenance.
Apache Traffic Server patches 38 flaws, some CVSS 10
Versions 9.2.15 and 10.1.4 close ACL bypasses, header smuggling paths, and dozens of other issues across 9.x and 10.x.
Xen ships batch of fixes for guest escapes spanning grant tables, pygrub, and more
Six advisories close privilege-escalation and crash bugs across years of Xen releases, several reachable from untrusted guests.
Resolver stacks buckle together under DNSSEC and transport CVEs
Same-day HIGH batches from Unbound, BIND, and PowerDNS show wildcard label logic and new encrypted paths failing in parallel across the software that is supposed to enforce DNS integrity.
OpenStack Ironic Python Agent allows root command execution via NTP config
Unsanitized ntp_server values let project managers run arbitrary commands during ramdisk startup.
Knot Resolver 6.3.0 DoQ overflow allows unauthenticated RCE
A single DNS-over-QUIC connection could overflow a heap buffer; the flaw is fixed in 6.4.1.
IETF TLS list: structural CoI question over Security AD meets moderation warning
A challenge to whether a long-career former NSA cryptographer can neutrally steward pure-ML-KEM standardization was answered mainly with character defenses and a chair's formal warning, not a structural debate.
Linux UDP corking bugs yield local root on kernels since 6.1
Two heap out-of-bounds writes in fragment-boundary handling are exploitable for privilege escalation, and public exploits are out.
Linux XFS privilege escalation, BIND and Unbound DNS flaws, and Exim local bugs land together
A kernel race, two major resolver security releases, and an Exim privilege fix were disclosed the same day.
TLS chairs refuse to release the weighting behind a contested ML-KEM consensus call
After citing a 7/10 figure among pre-existing participants to advance pure ML-KEM, the chairs told the European Commission's PQC lead they would not disclose numbers, weights, or methods.
Moderated over a footnote: Bernstein, pure ML-KEM, and the IETF's closed door
While the TLS working group pushed pure ML-KEM through last call, chairs repeatedly silenced the draft's most rigorous critic over a copyright protest footnote, as signals-intelligence participation went largely unexamined.
TLS chairs call rough consensus to advance pure ML-KEM over sustained objection
Across draft-ietf-tls-mlkem-05, -07, and -08 the working group split over whether an RFC for standalone post-quantum key establishment was necessary plumbing or a dangerous signal. On 19 July 2026 the chairs found rough consensus to advance it anyway.
libssh 0.12.1 and 0.11.5 fix stack overflow and nine other flaws
Security releases address an SFTP server buffer overflow, GSSAPI and ProxyCommand leaks, an AES-GCM integrity downgrade, and multiple denial-of-service bugs.
snapd 2.76.1 patches LPE and two sandbox flaws
Qualys found a capabilities misconfiguration in snap-confine that yields local root, fixed alongside AppArmor and seccomp issues in Ubuntu packages from 16.04 onward.