FYI: Slackware -current changelog includes ffmpeg-9.0. A lot of packages are relinked against it, including tigervnc-1.16.2-x86_64-6

Todays changelog:

Fri Aug  7 02:15:06 UTC 2026
a/aaa_libraries-15.1-x86_64-53.txz:  Rebuilt.
  Upgraded: libpsl.so.5.3.8.
  Added (temporarily): libavcodec.so.62.28.102, libavdevice.so.62.3.102,
  libavfilter.so.11.14.102, libavformat.so.62.12.102, libavutil.so.60.26.102,
  libswresample.so.6.3.102, libswscale.so.9.5.102.
a/kernel-firmware-20260806_16d815d-noarch-1.txz:  Upgraded.
a/kernel-generic-6.18.43-x86_64-1.txz:  Upgraded.
a/lvm2-2.03.42-x86_64-1.txz:  Upgraded.
a/udisks2-2.11.2-x86_64-1.txz:  Upgraded.
d/kernel-headers-6.18.43-x86-1.txz:  Upgraded.
d/python-pip-26.2.1-x86_64-1.txz:  Upgraded.
d/swig-4.5.0-x86_64-1.txz:  Upgraded.
k/kernel-source-6.18.43-noarch-1.txz:  Upgraded.
kde/digikam-9.1.0-x86_64-5.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/dragon-26.04.3-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/ffmpegthumbs-26.04.3-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/glaxnimate-0.6.0-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/haruna-1.8.1-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/k3b-26.04.3-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/kdenlive-26.04.3-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/kfilemetadata-6.28.0-x86_64-3.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/kfilemetadata5-5.116.0-x86_64-4.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/kpipewire-6.7.4-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
kde/kstars-3.8.4.1-x86_64-1.txz:  Upgraded.
kde/libindi-2.2.4.2-x86_64-1.txz:  Upgraded.
kde/subtitlecomposer-0.8.2-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/alsa-plugins-1.2.12-x86_64-4.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/apr-util-1.6.4-x86_64-1.txz:  Upgraded.
l/ffmpeg-9.0-x86_64-1.txz:  Upgraded.
  Shared library .so-version bump.
l/gegl-0.4.70-x86_64-3.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/gexiv2-0.16.2-x86_64-1.txz:  Upgraded.
l/graphviz-15.1.1-x86_64-1.txz:  Upgraded.
l/gst-plugins-bad-free-1.28.6-x86_64-1.txz:  Upgraded.
l/gst-plugins-base-1.28.6-x86_64-1.txz:  Upgraded.
l/gst-plugins-good-1.28.6-x86_64-1.txz:  Upgraded.
l/gst-plugins-libav-1.28.6-x86_64-1.txz:  Upgraded.
  Compiled against ffmpeg-9.0.
l/gstreamer-1.28.6-x86_64-1.txz:  Upgraded.
l/libcec-8.1.4-x86_64-2.txz:  Rebuilt.
  Build with -DDISABLE_STATIC=ON.
  Thanks to reddog83.
l/mlt-7.40.0-x86_64-3.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/netpbm-11.15.05-x86_64-1.txz:  Upgraded.
l/opencv-4.14.0-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/pango-1.58.2-x86_64-1.txz:  Upgraded.
l/pipewire-1.6.8-x86_64-5.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/qt5-5.15.19_20260520_aa749695-x86_64-5.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
l/qt6-6.11.1_20260508_bfde7b89-x86_64-3.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
n/dhcpcd-10.5.0-x86_64-1.txz:  Upgraded.
n/openvpn-2.7.6-x86_64-1.txz:  Upgraded.
n/p11-kit-0.26.5-x86_64-1.txz:  Upgraded.
  This update fixes a security issue:
  rpc: guard against overflow when decoding nested attributes.
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2026-18938
  (* Security fix *)
x/fontconfig-2.18.3-x86_64-1.txz:  Upgraded.
x/intel-gmmlib-22.10.1-x86_64-1.txz:  Upgraded.
x/libXfont2-2.0.9-x86_64-1.txz:  Upgraded.
  This update fixes security issues:
  Font Server Client encoding Out-Of-Bounds Read/Write.
  Font Server Client Cumulative Glyph Data Heap Buffer Overflow.
  For more information, see:
    https://lists.x.org/archives/xorg/2026-August/062274.html
    https://www.cve.org/CVERecord?id=CVE-2026-59679
    https://www.cve.org/CVERecord?id=CVE-2026-44950
  (* Security fix *)
xap/MPlayer-20260805-x86_64-1.txz:  Upgraded.
  Compiled against ffmpeg-9.0.
xap/audacious-plugins-4.6.1-x86_64-3.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
xap/ffmpegthumbnailer-2.3.0-x86_64-4.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
xap/freerdp-3.30.0-x86_64-2.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
xap/mpv-0.41.0-x86_64-7.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
xap/ssr-20260523_ad99c7e-x86_64-1.txz:  Upgraded.
  Compiled against ffmpeg-9.0.
xap/xine-lib-1.2.13-x86_64-20.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
xap/xscreensaver-6.15-x86_64-4.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
extra/tigervnc/tigervnc-1.16.2-x86_64-6.txz:  Rebuilt.
  Recompiled against ffmpeg-9.0.
isolinux/initrd.img:  Rebuilt.
kernels/*:  Upgraded.
testing/packages/linux-7.1.x/kernel-generic-7.1.7-x86_64-1.txz:  Upgraded.
testing/packages/linux-7.1.x/kernel-headers-7.1.7-x86-1.txz:  Upgraded.
testing/packages/linux-7.1.x/kernel-source-7.1.7-noarch-1.txz:  Upgraded.
testing/packages/mesa-26.2.0-x86_64-1.txz:  Upgraded.
usb-and-pxe-installers/usbboot.img:  Rebuilt.
reddit.com
u/ddmayne — 13 days ago

FYI: Today's Slackware -current changelog is extensive: updates to Plasma 6 (mostly for KDE), ffmpeg8, and updates compiler gcc 15.3.

Partial changelog for slackware -current; kernel 6.18.35 is recompiled with new toolset.

Mon Jun 15 23:27:31 UTC 2026
Well folks, it seems that the stars have aligned to bring us a bunch of long-
awaited updates, including ffmpeg8 and Plasma 6! This has been developed in a
side tree for several weeks, and I'll be happy to get that off my plate and
have a greatly reduced todo list. Many thanks to alienBOB for getting the tree
in good shape, helping when I got stuck, and for being a good manager who
inspires me to do my best work. :-) And we both extend our thanks to the
illustrious LuckyCyborg who ported the build scripts to Plasma 6 in the first
place and then maintained Plasma 6 for Slackware users to test for a couple of
years. And thanks to everyone else who helped out with either of the Slackware
Plasma 6 projects that these updates grew out of.
Have fun!
a/exfatprogs-1.4.2-x86_64-1.txz:  Upgraded.
a/kernel-firmware-20260610_e7eb98a-noarch-1.txz:  Upgraded.
a/kernel-generic-6.18.35-x86_64-2.txz:  Rebuilt.
  Recompiled with gcc-15.3.0.

In addition to kde updates, tigervnc is updated:

extra/tigervnc/tigervnc-1.16.2-x86_64-4.txz:  Rebuilt.
  Recompiled against ffmpeg-8.1.1.
reddit.com
u/ddmayne — 2 months ago

FYI: Slackware -15.0 changelog includes kernel 5.15.209 which addresses CVE's relating to rxrpc. Also, Slackware -current updates to kernel 6.18.34

For 15.0, kernel 5.15.209 is integrated. Partial changelog:

Tue Jun  2 02:32:11 UTC 2026
patches/packages/linux-5.15.209/kernel-generic-5.15.209-x86_64-1.txz:  Upgraded.
  This update fixes security issues:
  rxrpc: Fix missing validation of ticket length in non-XDR key preparsing
  rxrpc: Fix anonymous key handling
  rxrpc: only handle RESPONSE during service challenge
  rxrpc: Fix recvmsg() unconditional requeue
  rxrpc: reject undecryptable rxkad response tickets
  rxrpc: Fix call removal to use RCU safe deletion
  rxrpc: Fix key quota calculation for multitoken keys
  rxrpc: proc: size address buffers for %pISpc output
  For more information, see:
    https://www.cve.org/CVERecord?id=CVE-2026-31696
    https://www.cve.org/CVERecord?id=CVE-2026-31676
    https://www.cve.org/CVERecord?id=CVE-2026-23066
    https://www.cve.org/CVERecord?id=CVE-2026-31637
    https://www.cve.org/CVERecord?id=CVE-2026-31642
    https://www.cve.org/CVERecord?id=CVE-2026-31630
  (* Security fix *)

edit: Also, I am not sure PV meant to delete these directories, but maybe he did:

packages/old-linux-5.15.117
packages/old-linux-5.15.139
packages/old-linux-5.15.145
packages/old-linux-5.15.160
packages/old-linux-5.15.161
packages/old-linux-5.15.187
packages/old-linux-5.15.188
packages/old-linux-5.15.193
packages/old-linux-5.15.204
packages/old-linux-5.15.205
packages/old-linux-5.15.206
packages/old-linux-5.15.207
reddit.com
u/ddmayne — 3 months ago

FYI: Slackware -15.0 and -current changelogs with respect to newest kernel exploit, "dirty frag." PV notes there is an unpatched component remaining and offers a mitigation suggestion.

Partial changelog for slackware 15.0. Note that kernel 5.15.206 is out at kernel.org with a short changelog.

Fri May  8 22:14:25 UTC 2026
patches/packages/linux-5.15.205/kernel-generic-5.15.205-x86_64-1.txz:  Upgraded.
patches/packages/linux-5.15.205/kernel-headers-5.15.205-x86-1.txz:  Upgraded.
patches/packages/linux-5.15.205/kernel-huge-5.15.205-x86_64-1.txz:  Upgraded.
patches/packages/linux-5.15.205/kernel-modules-5.15.205-x86_64-1.txz:  Upgraded.
  This update fixes a critical security issue:
  xfrm: esp: avoid in-place decrypt on shared skb frags.
  This update addresses a Linux kernel local privilege escalation attack known
  as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that
  is not yet patched upstream.
  Mitigation: If for some reason it's not possible to upgrade the kernel right
  away you may blacklist or remove the kernel modules esp4.ko and esp6.ko
  (CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).
  Also remove the modules from the kernel if they have been loaded:
    rmmod esp4 esp6 rxrpc
  And, drop the file caches in case in-memory program copies have already
  been compromised. Make sure possibly affected programs do not have any
  open sessions first:
    sh -c "echo 3 > /proc/sys/vm/drop_caches"
  For more information, see:
    https://github.com/V4bel/dirtyfrag
    https://www.cve.org/CVERecord?id=CVE-2026-43284
  (* Security fix *)

Partial changelog for slackware -current:

Fri May  8 22:14:25 UTC 2026
a/kernel-generic-6.18.28-x86_64-1.txz:  Upgraded.
  This update fixes a critical security issue:
  xfrm: esp: avoid in-place decrypt on shared skb frags.
  This update addresses a Linux kernel local privilege escalation attack known
  as "Dirty Frag." Please note that there's a second CVE (CVE-2026-43500) that
  is not yet patched upstream.
  Mitigation: If for some reason it's not possible to upgrade the kernel right
  away you may blacklist or remove the kernel modules esp4.ko and esp6.ko
  (CVE-2026-43284) and rxrpc.ko (CVE-2026-43500).
  Also remove the modules from the kernel if they have been loaded:
    rmmod esp4 esp6 rxrpc
  And, drop the file caches in case in-memory program copies have already
  been compromised. Make sure possibly affected programs do not have any
  open sessions first:
    sh -c "echo 3 > /proc/sys/vm/drop_caches"
  For more information, see:
    https://github.com/V4bel/dirtyfrag
    https://www.cve.org/CVERecord?id=CVE-2026-43284
  (* Security fix *)
u/ddmayne — 3 months ago

FYI: Slackware 15.0 and -current changelogs with respect to "CopyFail" kernel exploit

For 15.0, 64-bit:

Sun May  3 01:36:26 UTC 2026
patches/packages/linux-5.15.204/kernel-generic-5.15.204-x86_64-1.txz:  Upgraded.
  This update fixes a critical security issue:
  An out-of-bounds write in the userspace interface for AEAD cipher algorithms
  may be leveraged to get a root shell through a setuid binary. While the
  proof of concepts for this have so far targeted different program versions
  than Slackware uses, there's nothing preventing anyone from targeting one
  a setuid binary that we use.
  Mitigation: If for some reason it's not possible to upgrade the kernel right
  away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove
  the algif_aead.ko kernel module to prevent the exploit.
  For more information, see:
    https://copy.fail/
    https://www.cve.org/CVERecord?id=CVE-2026-31431
  (* Security fix *)

For current, 64-bit:

Sun May  3 01:36:26 UTC 2026
a/kernel-generic-6.18.26-x86_64-1.txz:  Upgraded.
  This update fixes a critical security issue:
  An out-of-bounds write in the userspace interface for AEAD cipher algorithms
  may be leveraged to get a root shell through a setuid binary. While the
  proof of concepts for this have so far targeted different program versions
  than Slackware uses, there's nothing preventing anyone from targeting one
  a setuid binary that we use.
  Mitigation: If for some reason it's not possible to upgrade the kernel right
  away, since we use CONFIG_CRYPTO_USER_API_AEAD=m you may blacklist or remove
  the algif_aead.ko kernel module to prevent the exploit.
  For more information, see:
    https://copy.fail/
    https://www.cve.org/CVERecord?id=CVE-2026-31431
  (* Security fix *)
u/ddmayne — 4 months ago