[CLSA-2026:1787131590] inkscape: Fix of CVE-2026-4980
Type:
security
Severity:
Moderate
Release date:
2026-08-19 09:26:44 UTC
Description:
- CVE-2026-4980: Limit XInclude processing to shortcut keys files - Drop BuildRequires on aspell-en: the package is not present in AlmaLinux 9.6 (BaseOS, AppStream, CRB, devel) nor in the TuxCare 9.6 repositories; it is an EPEL-only package. It is a runtime dictionary that the build does not consume, and aspell-devel is retained, so the produced binaries are unchanged.
CVEs fixed:
Updated packages:
  • inkscape-1.1.1-6.el9_6.tuxcare.els1.x86_64.rpm
    sha:2b69e45de53dd41d016380f5e15cc8be4be1f7fb5ae2d3d29b200558297b2b91
  • inkscape-docs-1.1.1-6.el9_6.tuxcare.els1.x86_64.rpm
    sha:049875008d9c3affc54cf52ee71c21bf3e7b684d249991ab4bc40f459ea9d5bd
  • inkscape-view-1.1.1-6.el9_6.tuxcare.els1.x86_64.rpm
    sha:d7f8a59f6501d53c948c10843539c240f795109cff61a49b66857c4b22738ee5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.