django-page-cms through version 2.0.13 contains an authorization bypass vulnerability in its admin helper views. The flaw allows low-privilege staff accounts to read unpublished drafts, page listings, and stored media paths without proper permission validation. This matters because it exposes sensitive organizational content to internal users who should not have access.
The lxc-ci project inadvertently included a static pacman local-signing private key within Arch Linux container and virtual machine images built prior to May 28, 2026. This allows a malicious or compromised package mirror to issue cryptographically trusted packages to clients. Consequently, attackers can achieve arbitrary code execution as root on affected systems.
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplication and addition fit in 32 bits. A crafted DLS file can supply a large connblocks value that wraps the expression and bypasses the chunk-size check, after which the parser performs approximately one billion 12-byte iterations beyond the chunk boundary. The excessive processing and invalid reads can cause denial of service. Builds with the CMake option enable-native-dls set to OFF do not expose the parser. This issue is fixed in version 2.5.6.
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication and addition fit in 32 bits. A crafted DLS file can supply a large cues value that wraps the expression and passes the chunk-size check, causing poolcues.resize(cues) to request approximately four gigabytes and the parser to read billions of entries beyond the chunk boundary. The excessive allocation and invalid reads can cause denial of service. Builds with enable-native-dls set to OFF are not exposed. This issue is fixed in version 2.5.6.