โŒ

Normale weergave

Stable Channel Update for Desktop

15 September 2026 om 22:40

The Stable channel has been updated to 153.0.8010.47/.48 for Windows and Mac andย 153.0.8010.47ย for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Logย 

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but havenโ€™t yet fixed.

This update includes 42 security fixes. Please see the Chrome Security Page for more information.

[N/A][556870863] Critical CVE-2026-91726: Out of bounds read in WebGL. Reported by Google on 2026-09-03 [TBD][557320614] Critical CVE-2026-91721: Use after free in Internals. Reported by xinyang on 2026-09-04 [TBD][558456602] Critical CVE-2026-91749: Use after free in Workers. Reported by WinD39 - Huynh Dinh Vu on 2026-09-08 [$1,500][552283275] High CVE-2026-91724: Use after free in Input. Reported by Hafiizh on 2026-08-25 [$1,000][556715288] High CVE-2026-91728: Integer overflow in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-09-03 [N/A][516780835] High CVE-2026-91734: Incorrect authorization in Core. Reported by Google on 2026-05-26 [N/A][516893912] High CVE-2026-91727: Incorrect reference resolution in Extensions. Reported by Google on 2026-05-26 [N/A][516947138] High CVE-2026-91743: Race condition in Core. Reported by Google on 2026-05-27 [N/A][520019273] High CVE-2026-91744: Race condition in PlatformIntegration. Reported by Google on 2026-06-04 [N/A][521486621] High CVE-2026-91712: Race condition in Extensions. Reported by Google on 2026-06-08 [N/A][521559611] High CVE-2026-91748: Race condition in Extensions. Reported by Google on 2026-06-09 [N/A][523470135] High CVE-2026-91720: Uninitialized resource in ANGLE. Reported by Google on 2026-06-13 [N/A][523554372] High CVE-2026-91731: Type confusion in Compositing. Reported by Google on 2026-06-13 [N/A][540016074] High CVE-2026-91747: Use after free in Skia. Reported by Google on 2026-07-28 [N/A][540021213] High CVE-2026-91733: Improper state validation in Skia. Reported by Google on 2026-07-28 [TBD][546413288] High CVE-2026-91741: Type confusion in CacheStorage. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-08-14 [TBD][547815507] High CVE-2026-91709: Type confusion in ServiceWorker. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [TBD][549225472] High CVE-2026-91717: Missing authorization in Android. Reported by jodyritonga on 2026-08-20 [N/A][552416113] High CVE-2026-91735: Incorrect authorization in WebUI. Reported by Google on 2026-08-25 [N/A][553115724] High CVE-2026-91708: Race condition in Network. Reported by Google on 2026-08-26 [N/A][553121008] High CVE-2026-91736: Use after free in DOM. Reported by Google on 2026-08-26 [N/A][553122373] High CVE-2026-91740: Uninitialized resource in Skia. Reported by Google on 2026-08-26 [N/A][553132148] High CVE-2026-91710: Use after free in WebAppInstalls. Reported by Google on 2026-08-26 [N/A][553133215] High CVE-2026-91718: Use after free in Core. Reported by Google on 2026-08-26 [N/A][554558368] High CVE-2026-91716: Use after free in Auth. Reported by Google on 2026-08-29 [N/A][556260782] High CVE-2026-91746: Integer overflow in Compositing. Reported by Google on 2026-09-02 [TBD][557206809] High CVE-2026-91729: Use after free in DigitalCredentials. Reported by sean geofrey on 2026-09-04 [TBD][558036280] High CVE-2026-91737: Use after free in PDF. Reported by SeungMyung Lee (@sm1ee), Siung kim (@ksw9722) on 2026-09-06 [TBD][558342353] High CVE-2026-91711: Out of bounds write in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07 [TBD][558367547] High CVE-2026-91715: Type confusion in ServiceWorker. Reported by Cristian Di Nicola (@crih.exe) on 2026-09-07 [N/A][558734727] High CVE-2026-91745: Use after free in V8. Reported by Google on 2026-09-08 [TBD][474131239] Medium CVE-2026-91723: Race condition in WebAppInstalls. Reported by Luan Herrera (@lbherrera_) on 2026-01-07 [TBD][511062248] Medium CVE-2026-91732: Missing authorization in AppManifest. Reported by pakhunov.anton.n on 2026-05-08 [N/A][513858387] Medium CVE-2026-91742: Confused deputy in PriceTracking. Reported by Google on 2026-05-16 [N/A][517710554] Medium CVE-2026-91714: Observable discrepancy in Fonts. Reported by Google on 2026-05-29 [N/A][518032534] Medium CVE-2026-91725: Observable discrepancy in CSS. Reported by Google on 2026-05-29 [N/A][521951328] Medium CVE-2026-91739: Missing authorization in Transactions Platform. Reported by Google on 2026-06-09 [N/A][523715133] Medium CVE-2026-91713: Missing authorization in Browser. Reported by Google on 2026-06-14 [N/A][536450979] Medium CVE-2026-91738: Improper input validation in ANGLE. Reported by Google on 2026-07-19 [TBD][543640868] Medium CVE-2026-91730: Incomplete cleanup in GetUserMedia. Reported by Keita Sode and Daisuke Hatakeyama (SYZD Research) on 2026-08-07 [TBD][554953456] Medium CVE-2026-91722: Use after free in Input. Reported by TIENPA on 2026-08-31 [TBD][542115030] Low CVE-2026-91719: Code injection in XML. Reported by Zabith Mohammed (@nmzabith) on 2026-08-03

We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.


Srinivas Sista

Google Chrome
  •  

Extended Stable Update for Desktop

15 September 2026 om 22:29

ย The Extended Stable channel has been updated to 152.0.7977.130 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome
  •  

Release 2026.09.15

15 September 2026 om 22:20

Docker Images

Docker images have been built and pushed:

Docker Hub:

  • alexta69/metube:latest
  • alexta69/metube:2026.09.15

GitHub Container Registry:

  • ghcr.io/alexta69/metube:latest
  • ghcr.io/alexta69/metube:2026.09.15

Changes

  • build: upgrade Python and npm dependencies (6708a88)
  • fix: stop resolving submitted URLs locally when a proxy will (closes #1079) (5cac98a)
  • docs: add MeTube Mobile (Android) to Sending links to MeTube (3516872)

  •  

v0.8.4

15 September 2026 om 20:40

What's Changed

  • feat(i18n): migrate catalogs to semantic TOML keys by @AprilNEA in #1169
  • perf(i18n): avoid copying borrowed translations by @AprilNEA in #1184
  • fix(i18n): polish supported locale copy by @AprilNEA in #1180
  • fix(i18n): localize DPI steps and correct count labels by @AprilNEA in #1292
  • fix(i18n): polish Brazilian Portuguese profile and settings copy by @uricholiveira in #1276
  • fix(i18n): refine French asset and control descriptions by @didlawowo in #1278
  • fix(hid): keep pairing phase after device selection by @AprilNEA in #1181
  • refactor(gui): model camera preview lifecycle states by @AprilNEA in #1182
  • refactor(agent): consolidate capture manager slots by @AprilNEA in #1183
  • docs(linux): fix the Debian install command and the bug form's platform note by @AalmanSadath in #791
  • docs: add Russian README translation by @MonteNegroX in #1039
  • Fix typo in installation guide by @mikevankuik in #1189
  • fix(i18n): correct mistranslations in the Spanish catalog by @eibidia in #1315
  • feat(i18n): Updated French README.md file by @DimitriDR in #1271
  • fix: add Debian runtime dependencies by @MauricioSilv in #1249
  • fix(hook): normalize Windows cursor position to DIP scale by @fly530 in #1246
  • fix(agent): restore diverted HID++ controls on a clean shutdown by @4ni1ak in #1106
  • refactor(hook): type windows cursor dpi normalization by @AprilNEA in #1318
  • fix(linux): declare F13-F20 in uinput key capabilities by @costantinoai in #1224
  • fix(core): stop seeding Back/Forward with a divertable default by @litityum in #1225
  • fix(agent): fence queued pairing discovery after selection by @AprilNEA in #1320
  • fix(agent): avoid capture recovery deadline busy loops by @AprilNEA in #1321
  • test(gui): cover camera preview lifecycle by @AprilNEA in #1322
  • fix(gui): place Windows actions ring correctly across mixed-DPI monitors by @AprilNEA in #1319
  • fix(gui): stop linking SMAppServiceErrorDomain so macOS 13 and 14 can launch by @AprilNEA in #1324
  • feat(hid): add hardware-aware mock device record and replay by @AprilNEA in #1165
  • test(agent): cover native and browser side-button profiles by @AprilNEA in #1325
  • fix(macos): bind Safari navigation to press-time process by @foleykyle01 in #1082
  • fix(camera): surface startup failures and retry preview by @yuzi-co in #1069
  • chore(gui): upgrade to gpui kit 0.6.1 and published pre adapters by @AprilNEA in #1338
  • feat(hid): add rgb-effects lighting and receiver routing by @LuisUrrutia in #351
  • fix(gui): keep update consent buttons visible by @AprilNEA in #1398
  • fix(linux): preserve gesture capture across receiver probes by @yvvlee in #1043
  • chore: release v0.8.4 by @AprilNEA[bot] in #1179

New Contributors

Full Changelog: v0.8.3...v0.8.4

  •  

Development Release: Fedora 45 Beta

15 September 2026 om 19:10
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. The Fedora project has announced the release of a development snapshot, Fedora 45 beta. The new release introduces new security features and package upgrades: "Fedora Linux 45 replaces the legacy in-kernel console with kmscon, bringing smooth rendering, better Unicode/font support, and enhanced system stability. Fedora Linux 45 now....
  •  

Minecraft 26.3 (stable) Released

15 September 2026 om 13:23
26.3, the release of Wilderness Bound, is a game drop for Java Edition released on September 15, 2026, which adds the dappled forest biome with the new poplars, red shrubs, and shelf mushrooms. It also adds wool stairs and slabs, concrete stairs and slabs, straw beds, cushions, and a new structure called the abandoned camp. Full changelog: https://minecraft.wiki/Java_Edition_26.3
  •  

Firefox 156.0

15 September 2026 om 15:00

New

  • Firefox on macOS can now be set to open automatically when the computer starts up, from the Startup section of Settings.

  • Localized Wikipedia and occasional sponsored suggestions in the address bar are now available in France, Germany, and Italy. These suggestions can be turned off in Firefox Suggest settings.

Fixed

  • Fixed an issue where dragging an image to a new position in a rich-text editor could replace it with a long line of text instead of moving it.

  • Fixed high-sample-rate FLAC audio in MP4 failing to play on sites such as Bilibili.

  • Fixed subtitles not appearing in the Picture-in-Picture window when they are turned on in the video player after the window has already opened.

  • Fixed bookmarks moving out of their folder when the folder and the bookmarks inside it were selected and dragged together in the Bookmarks sidebar.

  • Fixed the find bar becoming permanently unavailable in a tab after reversing the panes in Split View.

  • Fixed some sites failing to load when DNS over HTTPS is enabled and the site does not support HTTPS.

  • Fixed Firefox losing all network connectivity for some users with the built-in VPN enabled.

  • Fixed an issue on Windows where Firefox could block an auto-hiding taskbar from showing.

  • Various security fixes.

Changed

  • Firefox's built-in PDF viewer now starts up to 45% faster.

  • Improved memory and CPU usage when Firefox displays large JPEG images scaled down to fit a page.

  • On Windows devices with ARM64 processors, WebRTC video calls may now use hardware H264 decoding instead of falling back to software.

Enterprise

Developer

Web Platform

  • text-box-trim now uses the font metrics of a ::first-line pseudo-element when one applies, matching other browsers and the specification.

Community Contributions

  •  

v4.3.21

15 September 2026 om 14:39

Features

  • Made restart limits opt-in for applications, preview deployments, and service applications. Existing resources that still used the previous limit of 10 restarts were reset to unlimited.

Fixes

  • Hid application names, server names, deployment URLs, team member emails, and job IDs from the Helper deployment check unless detailed output was explicitly requested.

Improvements

  • Updated the supported Traefik patch releases to 3.7.13, 3.6.25, and 2.11.57.

Full Changelog: v4.3.20...v4.3.21

  •  

American Truck Simulator: 1.61 Update Release

Door: David
15 September 2026 om 09:25

We're excited to announce that the 1.61 update for American Truck Simulator has officially been released and is now available on Steam!

Before we head to the news, we would like to thank everyone who took part in the Open Beta and reported any issues or provided general feedback on our forum. This makes it much easier for our team to fine-tune everything and helps ensure a smooth transition to the full update release.

We'd also like to thank everyone who participated in the 1.61 Experimental Beta, especially those who shared their thoughts on the Multi-Function Display (MFD) and the In-Game Menu. These additions will be introduced in a future update, giving us more time to refine and polish these features and ensure they deliver the best possible experience when they are ready.

Now, letโ€™s dive into what you can expect in the 1.61 Update:


Proximity Exploration

In the 1.61 update, we are introducing a new feature designed to assist players with exploring the world map and discovering more along their journey. Introducing Proximity Exploration, a new quality-of-life feature that makes map discovery a little more intuitive, while still keeping the enjoyment of exploring the world for yourself.

When enabled, Proximity Exploration automatically reveals a small area around your vehicle as you travel. This means you will no longer need to drive over every tiny section of road to mark it as explored, which should be especially useful for those of you chasing that elusive 100% map discovery! It can also help reveal nearby accessible roads and areas around locations such as rest stops, toll gates, border crossings, gas stations, and other places where multiple road segments may sit closely together.

And don't worry, secret roads will still have secrets to uncover! Proximity Exploration will only reveal the first segment of a secret road when you get close enough, giving you a small hint that there might be somewhere new to explore. From there, however, the rest is up to you, as the remaining route will only be discovered by actually driving along it.

Whether you use Proximity Exploration to help hunt down those final percentages or simply make exploring the map a little smoother, the choice is yours!

Improved Material System

The Improved Material System significantly improves the lighting and visual quality of vehicle interiors in selected trucks. Its main focus is to enhance how interior materials react to light, which results in a more readable, detailed, and visually pleasing cabin environment.

One of the most significant changes was a redesign of the materials used in vehicle interiors. As a result, it makes differences between materials such as leather, fabric, plastic, and metal far more apparent, even in low-light conditions. The new solution uses multiple variants of dynamic cubemaps, allowing all materials to reflect their surroundings more naturally and respond to ambient light in a more realistic way.

The entire system was designed from the start with the interiors of trucks in both games in mind, so the base games and their existing fleets will gradually benefit from these improvements as well. In this update, we're excited to bring the Improved Material System to the International LT and International LoneStar.

With future updates, we will gradually add this technology for other trucks across both games. You can read more about this feature here.

Map Changes for Road Trip

With the upcoming Road Trip project, our map and asset teams have also been preparing the world of American Truck Simulator for a new way to explore the roads. While many of these changes are happening behind the scenes, they help lay the groundwork for future features and ensure the map is ready for the journey ahead.

We have implemented inactive Tourist Boards across several states, including California, Oregon, Washington, Idaho, Montana, Wyoming, and the upcoming South Dakota DLC. These Tourist Boards will remain unavailable until the Road Trip project is released, but they are already in place and ready for the future. Alongside these additions, we have also applied various small visual improvements and polish to selected areas across the map.

As part of these preparations, we have also added a number of new gas stations across the map. These locations will not only serve truck drivers but will also become available for cars when the Road Trip project releases, giving players more places to stop and refuel during their travels.

These changes are just a small part of the preparation work being done behind the scenes, helping us make sure the American Truck Simulator world is ready for new adventures on the road.

New Cargoes

We are also introducing new cargo options and improving the visuals of some existing ones. Players can now transport new types of freight, including Seed Containers, Trailers, and Truss, adding more variety to their hauling jobs across America.

Alongside these additions, we also updated the existing Rails cargo with a brand-new model and improved textures. These changes help bring more detail and visual quality to the cargo you see on the road, making each delivery feel even more realistic.

Changelog:

Map

  • Proximity Exploration
  • Map Changes for Road Trip

Vehicles

  • New Cargoes

Visual

  • Improved Material System: International LT & International LoneStar

We hope you are also excited to try out all the new features! Make sure to keep up to date with future updates by following us on X/Twitter, Facebook, BlueSky, YouTube, TikTok, and Instagram, and by subscribing to our newsletter! Until next time, happy haulin'!

  •  

v4.3.20

15 September 2026 om 09:20

Features

  • Added an All option to the log viewer and accepted lines=all across application, database, and service log APIs. The existing -1 value remained available for compatibility.

Fixes

  • Fixed scheduled backup deletion for service databases so it kept the database context and returned to the correct backup page.
  • Preserved each service componentโ€™s stored application or database type when generating Traefik labels.
  • Restored hourly Sentinel version checks for enabled, eligible servers while continuing to exclude build servers.

Improvements

  • Ran Traefik version checks whenever Coolify checked for updates instead of only once a week.
  • Updated Coolify Helper to 1.0.17 and moved the bundled MinIO client to a pinned AIStor release.

Full Changelog: v4.3.19...v4.3.20

  •  

12.1

15 September 2026 om 03:23

๐Ÿš€ Jellyfin Web 12.1

We are pleased to announce the latest stable release of Jellyfin, version 12.1! This minor release brings several bugfixes to improve your Jellyfin experience. As always, please ensure you take a full backup before upgrading!

Discuss this release further on our forums.

Changelog (4)

๐Ÿ—๏ธ Enhancements

๐Ÿ“ˆ General Changes

  •  

v0.20.0-rc.3

15 September 2026 om 03:02

โ— This is a pre-release

  • May contain bugs and unfinished features.

โš ๏ธ Note for macOS users

Builds are unsigned (no Apple Developer ID). After dragging MarkText into Applications, clear the quarantine flag once:

xattr -cr /Applications/marktext.app

Verifying downloads

All artifacts are listed with their SHA-256 in SHA256SUMS.txt. Verify with:

sha256sum -c SHA256SUMS.txt --ignore-missing

What's Changed

  • fix(muya): make a code block a diagram when its language is a diagram language (#5060) by @Jocs in #5304
  • docs: fix the macOS alias path in the CLI docs by @Jocs in #5308
  • chore: run only eslint --fix on staged desktop TS/Vue files by @Jocs in #5318
  • fix(desktop): ignore line-ending menu updates for a closed window (#4923) by @Jocs in #5319
  • fix: #4926 prevent emoji deletion from splitting surrogate pairs by @Renakoni in #4931
  • fix(desktop): keep exported links working from folders named with #, ? or % by @Dev-next-gen in #5320
  • fix(desktop): explain the max width format in preferences (#5331) by @Jocs in #5334
  • fix(muya): delete emoji whole in code blocks and drop the caret-inside-cluster handler (#4926) by @Jocs in #5332
  • fix(desktop): keep exported images working from folders named with #, ? or % (#5335) by @Jocs in #5337
  • fix(muya): regex search freezes on zero-width patterns and splits emoji by @Jocs in #5333
  • fix(desktop): keep the share host in exported links from UNC documents (#5336) by @Jocs in #5338
  • fix: #4899 keep trailing content out of the child list when outdenting a list item by @doktorigi in #4913
  • fix(muya): keep the link popover open when moving between links (#5313) by @anandghegde in #5324
  • fix: reuse image on case-insensitive path match (#3119) by @dzid26 in #5326
  • fix(desktop): name copied images after their content, not their path (#5344) by @Jocs in #5346
  • fix(muya): only outdent a paragraph that sits in a nested list item (#5342) by @Jocs in #5345
  • fix(muya): split the list when outdenting a task item into a plain list (#5341) by @Jocs in #5348
  • fix(muya): edit a footnote definition as its own container (#5340, #5343) by @Jocs in #5347
  • fix(muya): keep a Tab-indented list item out of a sublist of the other kind (#5349) by @Jocs in #5354
  • fix(muya): preserve ordered list source markers by @Renakoni in #4776

New Contributors

Full Changelog: v0.20.0-rc.2...v0.20.0-rc.3

  •  

12.1

15 September 2026 om 03:23

๐Ÿš€ Jellyfin Server 12.1

We are pleased to announce the latest stable release of Jellyfin, version 12.1! This minor release brings several bugfixes to improve your Jellyfin experience. As always, please ensure you take a full backup before upgrading!

Discuss this release further on our forums.

Changelog (47)

๐Ÿ“ˆ General Changes

  •  

v0.20.0-beta.2

14 September 2026 om 20:44

Version 0.20 of the Android TV app is coming. To read more about the release process and follow updates, please see the release plan discussion.

This second beta will slowly rollout to the Google Play store beta channel.

If you appreciate my work, you can show your support with a donation through Buy Me a Coffee or GitHub sponsors. Your support helps me continue improving and growing the app. Thank you!

๐Ÿ› Beta information

Beta versions are not guaranteed to work as expected. We encourage users to create detailed bug reports if any problems arise. Read our blog post for more information about our Android beta programs.

๐Ÿ’ฅ Crash fixes

๐Ÿ“ˆ Dependency updates

  • Update androidx.compose to v1.12.1 #5811, by renovate[bot]
  • Update kotest to v6.2.5 #5813, by renovate[bot]
  • Update androidx.media3 to v1.11.1 #5815, by renovate[bot]
  • Update CI dependencies #5808, by renovate[bot]

Contributors

  •  

v1.18.31

14 September 2026 om 19:47

Core

Bugfixes

  • Restored ACP session model, effort, mode, and reasoning chunk boundaries when loading, resuming, or forking sessions. (@JacobNWolf)

TUI

Bugfixes

  • Show remote config authentication errors during startup and exit with a failure status.

Extensions

Improvements

  • Request summarized adaptive thinking for GitHub Copilot models.

Thank you to 4 community contributors:

  •  

Minecraft 26.3-rc-3 (snapshot) Released

14 September 2026 om 14:58
26.3 Release Candidate 3 (known as 26.3-rc-3 in the launcher) is the third release candidate for Java Edition 26.3, released on September 14, 2026, which fixes bugs and reverts a bug. Full changelog: https://minecraft.wiki/Java_Edition_26.3-rc-3
  •  

v1.20.1-pre

14 September 2026 om 17:58
  • Raised the default open file descriptor soft limit at startup on Unix/macOS to prevent EMFILE (Too many open files) errors in large workspaces. (#64188)
  • Added dev: Debug Filesystem Watching to inspect local watcher events, watch roots, and scan exclusions, and export diagnostic captures as JSON. (#64186)
  • Fixed Linux mailto: URI handling when using Help โ†’ Email Us.... (#64090)
  • Fixed diagnostics batches stopping at paths without a worktree (#64073)
  • Fixed an issue in SSH remote mode where reopening a newly created file at a path that was previously renamed could incorrectly reuse the buffer for the renamed file. (#64028)
  • Fixed CRLF line breaks not normalized in completion labels (#63984)
  • Improved trial descriptions to show $5 of GPT Luna and unlimited edit predictions for 14 days from trial start. (#63972)

  •  

MKVToolNix v102.0 released

Door: mosu
14 September 2026 om 15:52

Hello gentle people!

An unsually short time between releases means a security fix, and thatโ€™s almost all this release is.

You can download the source code or one of the packages. The Windows packages as well as the Linux AppImage are available already. The other Linux packages & the macOS disk image are still being built and will be available over the course of the next couple of hours.

Here are the NEWS since the previous release:

Version 102.0 โ€œLittle Housesโ€ 2026-09-14

Bug fixes

  • MKVToolNix GUI: executing actions, type โ€œexecute a programโ€: all the variables (<MTX_โ€ฆ>) will now be replaced again in the argument list to the program to be executed. This was broken in v100. Fixes #6306.

Security fixes

  • CVE-2026-90783: avilib: fixed potential heap overflows/invalid memory access in the ODML index handling due to unsiged integer multiplication wrapping around (colloquially known as โ€œoverflowingโ€) with specifically crafted AVI files. Affects only mkvmerge as the other tools do not read AVIs. Reported by Tristan Madani TristanInSec@gmail.com.

Have fun! ๐Ÿ˜

  •  

HWMonitor 1.68

14 September 2026 om 16:42
  • PCI Express errors counters on AMD and Intel GPUs.
  • New metrics on AMD Strix Point, Strix Halo and Kraken Point : NPU power, NPU clocks, NPU TOPS and TOPS per watt, NPU DRAM bandwidth usage, global platform power and DRAM read and write bandwidths.
  • New HDD metrics (IOPS, average latency, NVMe controller link speed).
  • Remembers devices & sensor types nodes state.
  •  

BookStack v26.05.5

14 September 2026 om 16:02

Security Release

This is a security release which addresses a vulnerability related to social login accounts, to prevent accounts from different services being potentially mis-matched.

Upgrading is strongly advised if the instance has ever used more than one third-party/social login option (including previously used options which are no longer active).

Thanks to Google and Ada Logics for the discovery and responsible disclosure of this issue.

Full List of Changes

  • Updated social logins to scope social account queries to social system.
  • Updated PHP package versions.

  •  

DistroWatch Weekly, Issue 1190

14 September 2026 om 02:11
The DistroWatch news feed is brought to you by TUXEDO COMPUTERS. This week in DistroWatch Weekly:
Review: Vanilla OS 3 "Reunion"
News: Asahi Linux works on M3-powered Apple computers, FreeBSD tests new service manager, Arch seeks help triaging bugs, openSUSE introduces tool to compare package versions, Linux Mint updates XApp, Debian publishes media update
Questions and answers: The smallest possible Linux
Released....
  •  
โŒ