<?xml version="1.0" ?>
<updates>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202603-1252</id>
		<title>关于 zlib 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-03-31 12:50:53"/>
		<updated date="2026-04-07 09:22:50"/>
		<severity>Low</severity>
		<description>关于 zlib 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-27171" id="CVE-2026-27171" title="zlib 1.3.2之前版本存在CPU资源消耗漏洞。该漏洞源于在crc32_combine64和crc32_combine_gen64函数中，内部函数x2nmodp在循环中执行右移操作时缺少终止条件，导致攻击者可通过调用这些函数触发无限循环，从而造成CPU资源耗尽，引发拒绝服务。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="minizip" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/minizip-1.2.13-5.ky11.loongarch64.rpm" version="1.2.13">
					<filename>minizip-1.2.13-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="minizip-devel" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/minizip-devel-1.2.13-5.ky11.loongarch64.rpm" version="1.2.13">
					<filename>minizip-devel-1.2.13-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="zlib" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/zlib-1.2.13-5.ky11.loongarch64.rpm" version="1.2.13">
					<filename>zlib-1.2.13-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="zlib-devel" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/zlib-devel-1.2.13-5.ky11.loongarch64.rpm" version="1.2.13">
					<filename>zlib-devel-1.2.13-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="zlib-help" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/zlib-help-1.2.13-5.ky11.noarch.rpm" version="1.2.13">
					<filename>zlib-help-1.2.13-5.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202604-1082</id>
		<title>关于 edk2 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-04-14 12:50:11"/>
		<updated date="2026-04-27 09:54:33"/>
		<severity>Low</severity>
		<description>关于 edk2 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2295" id="CVE-2025-2295" title="EDK2的BIOS模块存在整数溢出漏洞，该漏洞源于未对网络输入数据进行边界校验。可能导致攻击者通过网络提交特制数据，触发整数溢出或环绕，进而导致系统拒绝服务。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="noarch" epoch="0" name="edk2-aarch64" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/edk2-aarch64-202308-25.p08.ky11.noarch.rpm" version="202308">
					<filename>edk2-aarch64-202308-25.p08.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="edk2-devel" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/edk2-devel-202308-25.p08.ky11.loongarch64.rpm" version="202308">
					<filename>edk2-devel-202308-25.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="edk2-help" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/edk2-help-202308-25.p08.ky11.noarch.rpm" version="202308">
					<filename>edk2-help-202308-25.p08.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="edk2-ovmf" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/edk2-ovmf-202308-25.p08.ky11.noarch.rpm" version="202308">
					<filename>edk2-ovmf-202308-25.p08.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="edk2-ovmf-loongarch64" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/edk2-ovmf-loongarch64-202308-25.p08.ky11.noarch.rpm" version="202308">
					<filename>edk2-ovmf-loongarch64-202308-25.p08.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python3-edk2-devel" release="25.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-edk2-devel-202308-25.p08.ky11.noarch.rpm" version="202308">
					<filename>python3-edk2-devel-202308-25.p08.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202604-1083</id>
		<title>关于 freetype 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-04-14 12:50:11"/>
		<updated date="2026-04-20 13:41:44"/>
		<severity>Moderate</severity>
		<description>关于 freetype 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-23865" id="CVE-2026-23865" title="Freetype库的tt_var_load_item_variation_store函数存在整型溢出漏洞，该漏洞源于在处理OpenType可变字体中的HVAR/VVAR/MVAR表时，未正确校验数据长度，导致可能发生越界读取操作。攻击者可通过诱导用户解析特制的字体文件，利用此漏洞造成信息泄露或系统异常。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="freetype" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/freetype-2.13.2-5.ky11.loongarch64.rpm" version="2.13.2">
					<filename>freetype-2.13.2-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="freetype-demos" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/freetype-demos-2.13.2-5.ky11.loongarch64.rpm" version="2.13.2">
					<filename>freetype-demos-2.13.2-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="freetype-devel" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/freetype-devel-2.13.2-5.ky11.loongarch64.rpm" version="2.13.2">
					<filename>freetype-devel-2.13.2-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="freetype-help" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/freetype-help-2.13.2-5.ky11.noarch.rpm" version="2.13.2">
					<filename>freetype-help-2.13.2-5.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202604-1102</id>
		<title>关于 openldap 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-04-14 12:50:19"/>
		<updated date="2026-04-20 12:59:59"/>
		<severity>Moderate</severity>
		<description>关于 openldap 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-22185" id="CVE-2026-22185" title="OpenLDAP Lightning Memory-Mapped Database (LMDB) 0.9.14 及更早版本的 mdb_load 工具存在安全漏洞，该漏洞源于 readline() 函数在处理包含嵌入空字节的畸形输入时，无符号偏移量计算发生下溢。攻击者可通过构造恶意输入文件触发越界读取，导致程序崩溃（拒绝服务）或有限堆内存内容泄露。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="openldap" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openldap-2.6.5-7.ky11.loongarch64.rpm" version="2.6.5">
					<filename>openldap-2.6.5-7.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openldap-clients" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openldap-clients-2.6.5-7.ky11.loongarch64.rpm" version="2.6.5">
					<filename>openldap-clients-2.6.5-7.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openldap-devel" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openldap-devel-2.6.5-7.ky11.loongarch64.rpm" version="2.6.5">
					<filename>openldap-devel-2.6.5-7.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="openldap-help" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openldap-help-2.6.5-7.ky11.noarch.rpm" version="2.6.5">
					<filename>openldap-help-2.6.5-7.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openldap-servers" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openldap-servers-2.6.5-7.ky11.loongarch64.rpm" version="2.6.5">
					<filename>openldap-servers-2.6.5-7.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202604-1130</id>
		<title>关于 libsoup3 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-04-21 12:50:15"/>
		<updated date="2026-04-27 09:49:02"/>
		<severity>Moderate</severity>
		<description>关于 libsoup3 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-4476" id="CVE-2025-4476" title="在libsoup HTTP客户端库中发现了一个拒绝服务漏洞。当libsoup客户端接收到包含特定构造的domain参数的401（未授权）HTTP响应时，会触发此缺陷。处理这个格式错误的WWW-Authenticate头部可能导致使用libsoup的客户端应用程序崩溃。攻击者可以通过设置恶意HTTP服务器来利用此漏洞。如果用户的使用易受攻击的libsoup库的应用程序连接到该恶意服务器，则可能导致拒绝服务。成功利用需要诱使用户的客户端应用程序连接到攻击者的恶意服务器。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libsoup3" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup3-3.4.4-5.ky11.loongarch64.rpm" version="3.4.4">
					<filename>libsoup3-3.4.4-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libsoup3-devel" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup3-devel-3.4.4-5.ky11.loongarch64.rpm" version="3.4.4">
					<filename>libsoup3-devel-3.4.4-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="libsoup3-help" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup3-help-3.4.4-5.ky11.noarch.rpm" version="3.4.4">
					<filename>libsoup3-help-3.4.4-5.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202604-1171</id>
		<title>关于 expat 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-04-21 18:50:06"/>
		<updated date="2026-04-27 09:36:29"/>
		<severity>Low</severity>
		<description>关于 expat 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-59375" id="CVE-2025-59375" title="在 Expat 2.7.2 之前的版本中，libexpat 存在漏洞，攻击者可以通过提交一个小型文档进行解析，从而触发大量的动态内存分配。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-24515" id="CVE-2026-24515" title="libexpat的XML_ExternalEntityParserCreate函数存在空指针解引用漏洞，该漏洞源于在处理未知编码时未正确复制编码处理程序用户数据。可能导致程序崩溃，造成拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-25210" id="CVE-2026-25210" title="libexpat库的doContent函数在处理标签缓冲区重新分配时存在整数溢出漏洞，该漏洞源于未对缓冲区大小bufSize进行整数溢出检查。可能导致内存损坏，进而引发拒绝服务或潜在代码执行。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="expat" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-2.5.0-17.ky11.loongarch64.rpm" version="2.5.0">
					<filename>expat-2.5.0-17.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="expat-devel" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-devel-2.5.0-17.ky11.loongarch64.rpm" version="2.5.0">
					<filename>expat-devel-2.5.0-17.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="expat-help" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-help-2.5.0-17.ky11.noarch.rpm" version="2.5.0">
					<filename>expat-help-2.5.0-17.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1001</id>
		<title>关于 assimp 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-03 16:34:27"/>
		<updated date="2026-05-11 17:04:48"/>
		<severity>Moderate</severity>
		<description>关于 assimp 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2152" id="CVE-2025-2152" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被评为“严重”级别的漏洞。该问题影响 File Handler 组件中 BaseImporter.cpp 文件的 Assimp::BaseImporter::ConvertToUTF8 函数。该漏洞会导致堆缓冲区溢出。攻击可以通过远程方式发起。该漏洞的利用方式已被公开，可能会被恶意利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2591" id="CVE-2025-2591" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被归类为“问题”级别的漏洞。该漏洞影响 `code/AssetLib/MDL/MDLLoader.cpp` 文件中的 `MDLImporter::InternReadFile_Quake1` 函数。对 `skinwidth/skinheight` 参数的操作会导致除以零的错误。攻击可以远程发起。该漏洞利用已被公开，可能会被利用。补丁标识为 `ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd`。建议应用补丁以修复此问题。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2751" id="CVE-2025-2751" title="Open Asset Import Library Assimp 5.4.3 中发现了一个漏洞，该漏洞被归类为存在问题。此漏洞影响 CSM 文件处理程序组件中 `code/AssetLib/CSM/CSMLoader.cpp` 文件的 `Assimp::CSMImporter::InternReadFile` 函数。对参数 `na` 的操作导致越界读。攻击可以远程发起。该漏洞利用已被公开，可能会被利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2752" id="CVE-2025-2752" title="Open Asset Import Library Assimp 5.4.3 中发现了一个漏洞，该漏洞被归类为存在问题。此问题影响 CSM 文件处理程序组件中 `include/assimp/fast_atof.h` 库中的 `fast_atoreal_move` 函数。该漏洞会导致越界读。攻击可能通过远程方式发起。该漏洞利用已被公开，可能会被利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2754" id="CVE-2025-2754" title="Open Asset Import Library Assimp 5.4.3 中发现了一个漏洞，该漏洞被评为严重级别。受此漏洞影响的是 AC3D 文件处理组件中 `code/AssetLib/AC/ACLoader.cpp` 文件的 `Assimp::AC3DImporter::ConvertObjectSection` 函数。对该函数的参数的操作会导致堆缓冲区溢出。攻击者可以远程发起攻击。该漏洞的利用方法已经公开，可能会被用于攻击。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2755" id="CVE-2025-2755" title="Open Asset Import Library（assimp）是Open Asset Import Library开源的一个库。
Open Asset Import Library（assimp） 5.4.3版本存在缓冲区错误漏洞，该漏洞源于对参数src.entries的错误操作会导致越界读取。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-2756" id="CVE-2025-2756" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被归类为“严重”的漏洞。该漏洞影响 AC3D 文件处理组件中 `code/AssetLib/AC/ACLoader.cpp` 文件的 `Assimp::AC3DImporter::ConvertObjectSection` 函数。对参数 `tmp` 的操作会导致堆缓冲区溢出。可以远程发起攻击。该漏洞利用信息已公开，可能会被利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-3158" id="CVE-2025-3158" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被评为“严重”级别的漏洞。该漏洞影响 LWO 文件处理组件中 `code/AssetLib/LWO/LWOAnimation.cpp` 文件的 `Assimp::LWO::AnimResolver::UpdateAnimRangeSetup` 函数，会导致堆缓冲区溢出。攻击者可以在本地主机上发起攻击。该漏洞利用信息已公开，可能会被利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-3196" id="CVE-2025-3196" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被评为“严重”级别的漏洞。受影响的是组件“Malformed File Handler”中的库代码 `code/AssetLib/MD2/MD2Loader.cpp` 中的函数 `Assimp::MD2Importer::InternReadFile`。对参数 `Name` 的操作会导致基于栈的缓冲区溢出。攻击需要通过本地方式进行。该漏洞利用已被公开，可能会被利用。建议升级受影响的组件。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-3548" id="CVE-2025-3548" title="Open Asset Import Library Assimp 5.4.3 及更早版本中发现了一个被评为“严重”级别的漏洞。该漏洞影响 File Handler 组件中 include/assimp/types.h 库的 aiString::Set 函数，会导致堆缓冲区溢出。攻击者可以在本地主机上发起攻击。该漏洞利用信息已公开，可能会被利用。建议应用补丁来修复此问题。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-3549" id="CVE-2025-3549" title="Open Asset Import Library Assimp 5.4.3 中发现了一个被评为“严重”级别的漏洞。受影响的是文件 `code/AssetLib/MD3/MD3Loader.cpp` 中 `File Handler` 组件的 `Assimp::MD3Importer::ValidateSurfaceHeaderOffsets` 函数。该漏洞会导致堆缓冲区溢出。攻击者需要通过本地方式进行攻击。该漏洞利用方式已被公开，可能会被利用。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5166" id="CVE-2025-5166" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于参数pcVerts操作导致越界读取。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5168" id="CVE-2025-5168" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于参数iIndex操作导致越界读取。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5200" id="CVE-2025-5200" title="Open Asset Import Library Assimp 5.4.3 中发现了一个漏洞，该漏洞被归类为存在问题。此问题影响文件 assimp/code/AssetLib/MDL/MDLLoader.cpp 中的 MDLImporter::InternReadFile_Quake1 函数。该漏洞会导致越界读。可以在本地主机上发起攻击。该漏洞利用已被公开，可能会被利用。该项目决定将所有模糊测试（Fuzzer）发现的漏洞收集到一个主问题中，以便将来解决。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5201" id="CVE-2025-5201" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于存在越界读取问题。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5202" id="CVE-2025-5202" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于文件assimp/code/AssetLib/MDL/HalfLife/HL1MDLLoader.cpp中的函数HL1MDLLoader::validate_header存在越界读取问题。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5203" id="CVE-2025-5203" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于文件assimp/include/assimp/ParsingUtils.h中的函数SkipSpaces存在越界读取问题。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-5204" id="CVE-2025-5204" title="Assimp是Assimp开源的一个库。用于导入和导出各种三维模型格式。
Assimp 5.4.3版本存在缓冲区错误漏洞，该漏洞源于文件assimp/code/AssetLib/MDL/MDLMaterialLoader.cpp中的函数MDLImporter::ParseSkinLump_3DGS_MDL7存在越界读取问题。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="assimp" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/assimp-5.3.1-17.ky11.loongarch64.rpm" version="5.3.1">
					<filename>assimp-5.3.1-17.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="assimp-devel" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/assimp-devel-5.3.1-17.ky11.loongarch64.rpm" version="5.3.1">
					<filename>assimp-devel-5.3.1-17.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="assimp-help" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/assimp-help-5.3.1-17.ky11.noarch.rpm" version="5.3.1">
					<filename>assimp-help-5.3.1-17.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python3-assimp" release="17.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-assimp-5.3.1-17.ky11.noarch.rpm" version="5.3.1">
					<filename>python3-assimp-5.3.1-17.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1022</id>
		<title>关于 libsoup 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-03 16:34:49"/>
		<updated date="2026-05-06 10:51:48"/>
		<severity>Moderate</severity>
		<description>关于 libsoup 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-2443" id="CVE-2026-2443" title="GNOME系统中广泛使用的HTTP库libsoup在处理特制的HTTP Range请求头时，未能正确验证所请求的字节范围。在某些构建配置下，远程攻击者可能利用此缺陷访问服务器内存中超出预期响应的部分内容。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libsoup" release="10.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup-2.74.3-10.p02.ky11.loongarch64.rpm" version="2.74.3">
					<filename>libsoup-2.74.3-10.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libsoup-devel" release="10.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup-devel-2.74.3-10.p02.ky11.loongarch64.rpm" version="2.74.3">
					<filename>libsoup-devel-2.74.3-10.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="libsoup-help" release="10.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsoup-help-2.74.3-10.p02.ky11.noarch.rpm" version="2.74.3">
					<filename>libsoup-help-2.74.3-10.p02.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1024</id>
		<title>关于 libtpms 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-03 16:34:49"/>
		<updated date="2026-05-06 10:52:30"/>
		<severity>Moderate</severity>
		<description>关于 libtpms 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-49133" id="CVE-2025-49133" title="libtpms的CryptHmacSign函数存在越界读取漏洞，该漏洞源于signKey与signScheme参数配对不一致，当signKey为ALG_KEYEDHASH密钥而inScheme为ECC或RSA方案时，CryptHmacSign函数会触发越界读取。攻击者可通过向基于受影响TCG参考实现的TPM 2.0/vTPM（swtpm）固件发送恶意命令触发此漏洞，导致libtpms因检测到越界访问而异常终止，进而使vTPM（swtpm）对虚拟机不可用。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libtpms" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libtpms-0.9.5-4.p02.ky11.loongarch64.rpm" version="0.9.5">
					<filename>libtpms-0.9.5-4.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libtpms-devel" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libtpms-devel-0.9.5-4.p02.ky11.loongarch64.rpm" version="0.9.5">
					<filename>libtpms-devel-0.9.5-4.p02.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1026</id>
		<title>关于 openssh 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-03 16:34:50"/>
		<updated date="2026-05-06 10:53:17"/>
		<severity>Moderate</severity>
		<description>关于 openssh 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-3497" id="CVE-2026-3497" title="各种 Linux 发行版中包含的 OpenSSH GSSAPI delta 存在漏洞。此漏洞影响各种 Linux 发行版添加的 GSSAPI 补丁，但不影响 OpenSSH 上游项目本身。在发生错误时使用 `sshpkt_disconnect()` 函数，该函数不会终止进程，这允许攻击者在 GSSAPI 密钥交换期间向服务器发送意外的 GSSAPI 消息类型，这将调用底层函数并继续执行程序，而不会设置相关的连接变量。由于变量未初始化为 NULL，因此代码稍后会访问这些未初始化的变量，从而访问随机内存，这可能导致未定义行为。建议的解决方法是使用 `ssh_packet_disconnect()` 函数，该函数会终止进程。该漏洞的影响在很大程度上取决于编译器的安全加固配置。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35386" id="CVE-2026-35386" title="在 OpenSSH 10.3 之前的版本中，由于命令行中的用户名包含 shell 元字符，可能导致命令执行漏洞。这需要满足以下条件：命令行中的用户名不受信任，并且 ssh_config 文件中存在非默认的 `%` 配置。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35387" id="CVE-2026-35387" title="OpenSSH（OpenBSD Secure Shell）是加拿大OpenBSD开源的一套用于安全访问远程计算机的连接工具。该工具是SSH协议的开源实现，支持对所有的传输进行加密，可有效阻止窃听、连接劫持以及其他网络级的攻击。
OpenSSH 10.3之前版本存在安全漏洞，该漏洞源于ECDSA算法配置被误解，可能导致使用非预期的算法。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35388" id="CVE-2026-35388" title="OpenSSH在10.3版本之前的代理模式复用会话中，存在连接复用确认绕过漏洞，该漏洞源于在代理模式复用会话时，未进行连接复用确认，可能导致攻击者利用此漏洞绕过安全确认机制，造成低完整性影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35414" id="CVE-2026-35414" title="在某些罕见情况下，OpenSSH 10.3 之前的版本会错误处理 `authorized_keys` 文件中的 `principals` 选项。具体来说，当 `principals` 选项包含一个列表，并且该列表与证书认证机构（CA）结合使用时，如果 CA 在证书中使用了逗号，则可能导致问题。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="openssh" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-9.6p1-5.p12.se.01.ky11.loongarch64.rpm" version="9.6p1">
					<filename>openssh-9.6p1-5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openssh-askpass" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-askpass-9.6p1-5.p12.se.01.ky11.loongarch64.rpm" version="9.6p1">
					<filename>openssh-askpass-9.6p1-5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openssh-clients" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-clients-9.6p1-5.p12.se.01.ky11.loongarch64.rpm" version="9.6p1">
					<filename>openssh-clients-9.6p1-5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="openssh-help" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-help-9.6p1-5.p12.se.01.ky11.noarch.rpm" version="9.6p1">
					<filename>openssh-help-9.6p1-5.p12.se.01.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openssh-keycat" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-keycat-9.6p1-5.p12.se.01.ky11.loongarch64.rpm" version="9.6p1">
					<filename>openssh-keycat-9.6p1-5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openssh-server" release="5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openssh-server-9.6p1-5.p12.se.01.ky11.loongarch64.rpm" version="9.6p1">
					<filename>openssh-server-9.6p1-5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="pam_ssh_agent_auth" release="4.5.p12.se.01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/pam_ssh_agent_auth-0.10.4-4.5.p12.se.01.ky11.loongarch64.rpm" version="0.10.4">
					<filename>pam_ssh_agent_auth-0.10.4-4.5.p12.se.01.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1028</id>
		<title>关于 python3 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-03 16:34:51"/>
		<updated date="2026-05-06 10:54:07"/>
		<severity>Moderate</severity>
		<description>关于 python3 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-15282" id="CVE-2025-15282" title="该漏洞存在于Python标准库的urllib.request.DataHandler组件中，当处理用户可控的数据URL时，攻击者可通过在数据URL的mediatype部分插入换行符（如CRLF）来注入任意HTTP头，这可能导致HTTP请求被篡改。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-0672" id="CVE-2026-0672" title="当使用Python的http.cookies.Morsel模块时，用户可控的cookie值和参数可能允许将HTTP头注入到消息中。攻击者可以通过构造恶意cookie值，诱导服务器在响应中插入非法HTTP头，从而可能导致HTTP头注入攻击，影响Web应用的安全性。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4224" id="CVE-2026-4224" title="Expat解析器的ElementDeclHandler在处理包含深度嵌套内容模型的内联文档类型定义时存在栈溢出漏洞，该漏洞源于对递归调用深度未进行有效限制，导致C语言栈溢出。攻击者可通过构造恶意的XML文档触发此漏洞，可能导致解析器崩溃或潜在的远程代码执行。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="python3" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-3.11.6-24.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-3.11.6-24.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-debug" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-debug-3.11.6-24.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-debug-3.11.6-24.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-devel" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-devel-3.11.6-24.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-devel-3.11.6-24.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python3-help" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-help-3.11.6-24.p01.ky11.noarch.rpm" version="3.11.6">
					<filename>python3-help-3.11.6-24.p01.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-tkinter" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-tkinter-3.11.6-24.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-tkinter-3.11.6-24.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-unversioned-command" release="24.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-unversioned-command-3.11.6-24.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-unversioned-command-3.11.6-24.p01.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1044</id>
		<title>关于 luksmeta 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-05 12:50:11"/>
		<updated date="2026-05-11 17:02:39"/>
		<severity>Moderate</severity>
		<description>关于 luksmeta 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-11568" id="CVE-2025-11568" title="luksmeta工具在处理LUKS1磁盘加密格式时存在数据损坏漏洞，该漏洞源于在元数据处理过程中未正确验证可用空间，导致攻击者可写入大量元数据覆盖用户数据，造成数据永久丢失。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="luksmeta" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/luksmeta-9-7.ky11.loongarch64.rpm" version="9">
					<filename>luksmeta-9-7.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="luksmeta-devel" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/luksmeta-devel-9-7.ky11.loongarch64.rpm" version="9">
					<filename>luksmeta-devel-9-7.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="luksmeta-help" release="7.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/luksmeta-help-9-7.ky11.noarch.rpm" version="9">
					<filename>luksmeta-help-9-7.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1050</id>
		<title>关于 poppler 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-05 12:50:13"/>
		<updated date="2026-05-11 15:40:39"/>
		<severity>Low</severity>
		<description>关于 poppler 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-43718" id="CVE-2025-43718" title="Poppler 24.06.1至25.x版本（不包括25.04.0）在处理PDF文档元数据中的深层嵌套结构时存在栈消耗问题，例如GTS_PDFEVersion字段中用于长pdfsubver字符串的正则表达式。该漏洞源于Dict::lookup、Catalog::getMetadata及相关PDFDoc函数中正则执行器(std::__detail::_Executor)发生的深度递归，可导致SIGSEGV信号触发，造成拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-52885" id="CVE-2025-52885" title="Poppler PDF渲染库的StructTreeRoot类在处理文档结构时存在释放后重用漏洞，该漏洞源于代码使用原始指针指向`std::vector`容器内的元素，当容器因添加新元素而重新分配内存时，这些指针将变为悬垂指针。攻击者可能通过构造特制的PDF文件，利用此悬垂指针进行写入操作，从而可能导致应用程序崩溃或执行任意代码。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="poppler" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-cpp" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-cpp-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-cpp-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-cpp-devel" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-cpp-devel-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-cpp-devel-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-devel" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-devel-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-devel-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-glib" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-glib-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-glib-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-glib-devel" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-glib-devel-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-glib-devel-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="poppler-glib-doc" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-glib-doc-23.12.0-13.ky11.noarch.rpm" version="23.12.0">
					<filename>poppler-glib-doc-23.12.0-13.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="poppler-help" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-help-23.12.0-13.ky11.noarch.rpm" version="23.12.0">
					<filename>poppler-help-23.12.0-13.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-qt5" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-qt5-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-qt5-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-qt5-devel" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-qt5-devel-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-qt5-devel-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-qt6" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-qt6-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-qt6-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-qt6-devel" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-qt6-devel-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-qt6-devel-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="poppler-utils" release="13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/poppler-utils-23.12.0-13.ky11.loongarch64.rpm" version="23.12.0">
					<filename>poppler-utils-23.12.0-13.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1054</id>
		<title>关于 kylin-device-daemon 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-06 12:24:26"/>
		<updated date="2026-05-06 15:25:22"/>
		<severity>Important</severity>
		<description>关于 kylin-device-daemon 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2024-1102" id="KVE-2024-1102" title="银河麒麟操作系统设备管理组件存在挂载操作权限控制不当漏洞，该漏洞源于挂载操作的权限管控不够严格，低权限用户可执行高危挂载，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="kylin-device-daemon" release="1.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kylin-device-daemon-3.24.0.0-1.p02.ky11.loongarch64.rpm" version="3.24.0.0">
					<filename>kylin-device-daemon-3.24.0.0-1.p02.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1055</id>
		<title>关于 libkysdk-base 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-06 12:24:27"/>
		<updated date="2026-05-06 15:25:06"/>
		<severity>Important</severity>
		<description>关于 libkysdk-base 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2024-0620" id="KVE-2024-0620" title="银河麒麟操作系统系统开发套件组件存在文件写入权限校验不充分漏洞，该漏洞源于执行文件写入操作前对调用者权限的验证不充分，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libkysdk-base" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-base-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-base-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-basecommon" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-basecommon-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-basecommon-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-base-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-base-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-base-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-conf2" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-conf2-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-conf2-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-conf2-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-conf2-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-conf2-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-conf2-tools" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-conf2-tools-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-conf2-tools-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-config" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-config-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-config-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-config-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-config-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-config-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-diagnostics" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-diagnostics-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-diagnostics-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-diagnostics-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-diagnostics-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-diagnostics-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-gsetting" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-gsetting-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-gsetting-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-gsetting-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-gsetting-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-gsetting-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-log" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-log-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-log-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-log-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-log-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-log-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-timer" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-timer-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-timer-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-timer-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-timer-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-timer-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-utils" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-utils-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-utils-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-utils-devel" release="1.p08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-utils-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm" version="2.5.1.0">
					<filename>libkysdk-utils-devel-2.5.1.0-1.p08.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1056</id>
		<title>关于 ukui-biometric-auth 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-06 12:24:29"/>
		<updated date="2026-05-06 14:43:56"/>
		<severity>Moderate</severity>
		<description>关于 ukui-biometric-auth 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0402" id="KVE-2026-0402" title="ukui-biometric-auth组件D-Bus 方法缺少授权检查，导致接口能被未授权用户访问。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0404" id="KVE-2026-0404" title="银河麒麟系统中的 uniauth-backend D-Bus 服务以 root 权限运行，负责用户认证信息管理。由于 D-Bus 权限策略配置不当且服务端缺少授权检查，普通本地用户可在无认证情况下直接调用接口，篡改 /var/lib/lightdm/.cache/ukui-greeter.conf 里的 lastLoginUser 、SaveQuickLoginUser 字段。攻击者可写入任意字符串（如不存在用户名），导致登录界面异常，造成拒绝服务或干扰正常登录流程。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libpam-biometric" release="1.p05.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libpam-biometric-4.10.0.0-1.p05.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>libpam-biometric-4.10.0.0-1.p05.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="ukui-biometric-auth" release="1.p05.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-biometric-auth-4.10.0.0-1.p05.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>ukui-biometric-auth-4.10.0.0-1.p05.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="ukui-polkit" release="1.p05.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-polkit-4.10.0.0-1.p05.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>ukui-polkit-4.10.0.0-1.p05.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1150</id>
		<title>关于 python-cryptography 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-10 18:33:49"/>
		<updated date="2026-05-11 16:42:44"/>
		<severity>Moderate</severity>
		<description>关于 python-cryptography 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-26007" id="CVE-2026-26007" title="cryptography 是一个为Python开发者提供加密原语和配方的软件包。在46.0.5版本之前，public_key_from_numbers（或EllipticCurvePublicNumbers.public_key()）、load_der_public_key() 和 load_pem_public_key() 函数未验证椭圆曲线点是否属于预期的素数阶子群。当受害者通过ECDH计算共享秘密S = [victim_private_key]P时，会泄露victim_private_key模small_subgroup_order的信息。对于cofactor大于1的曲线，这将暴露私钥的最低有效位。当这些弱公钥用于ECDSA时，攻击者可以轻易地在小子群上伪造签名。只有SECT曲线受此影响。该漏洞已在46.0.5版本中修复。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="python3-cryptography" release="9.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-cryptography-42.0.2-9.p01.ky11.loongarch64.rpm" version="42.0.2">
					<filename>python3-cryptography-42.0.2-9.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python-cryptography-help" release="9.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python-cryptography-help-42.0.2-9.p01.ky11.noarch.rpm" version="42.0.2">
					<filename>python-cryptography-help-42.0.2-9.p01.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1200</id>
		<title>关于 tar 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-12 12:50:23"/>
		<updated date="2026-05-18 17:52:36"/>
		<severity>Moderate</severity>
		<description>关于 tar 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-45582" id="CVE-2025-45582" title="GNU Tar组件存在目录遍历漏洞，该漏洞源于在解压TAR存档时未正确校验路径逻辑，允许攻击者通过分两步解压包含符号链接和关键文件的特制存档，绕过原有的'成员名称包含..'保护机制，导致关键文件被覆盖。攻击者可利用该漏洞覆盖系统配置文件，可能引发权限提升或敏感数据篡改。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="2" name="tar" release="3.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/tar-1.35-3.ky11.loongarch64.rpm" version="1.35">
					<filename>tar-1.35-3.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="2" name="tar-help" release="3.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/tar-help-1.35-3.ky11.noarch.rpm" version="1.35">
					<filename>tar-help-1.35-3.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1235</id>
		<title>关于 expat 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:50:32"/>
		<updated date="2026-05-25 18:22:41"/>
		<severity>Low</severity>
		<description>关于 expat 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-41080" id="CVE-2026-41080" title="libexpat的XML解析器存在熵不足漏洞，该漏洞源于libexpat 2.7.6之前版本在生成哈希值时使用了不足的随机熵，导致攻击者可通过特制的XML文档触发哈希冲突攻击，进而造成服务端拒绝服务。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="expat" release="18.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-2.5.0-18.ky11.loongarch64.rpm" version="2.5.0">
					<filename>expat-2.5.0-18.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="expat-devel" release="18.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-devel-2.5.0-18.ky11.loongarch64.rpm" version="2.5.0">
					<filename>expat-devel-2.5.0-18.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="expat-help" release="18.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/expat-help-2.5.0-18.ky11.noarch.rpm" version="2.5.0">
					<filename>expat-help-2.5.0-18.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1309</id>
		<title>关于 mutt 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:38"/>
		<updated date="2026-05-25 18:42:52"/>
		<severity>Low</severity>
		<description>关于 mutt 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-43861" id="CVE-2026-43861" title="Mutt的url_pct_decode函数存在空字节检查缺失漏洞，该漏洞源于在版本2.3.2之前，Mutt在处理URL百分号编码解码时未对解码结果中的空字节（'\0'）进行有效性检查。攻击者可能利用此缺陷构造特制的URL，导致Mutt在处理时产生非预期的字符串截断，进而可能影响后续的URL处理逻辑，造成信息泄露或绕过安全限制。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="5" name="mutt" release="4.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/mutt-2.2.12-4.ky11.loongarch64.rpm" version="2.2.12">
					<filename>mutt-2.2.12-4.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="5" name="mutt-help" release="4.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/mutt-help-2.2.12-4.ky11.noarch.rpm" version="2.2.12">
					<filename>mutt-help-2.2.12-4.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1310</id>
		<title>关于 nano 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:39"/>
		<updated date="2026-05-25 18:43:05"/>
		<severity>Moderate</severity>
		<description>关于 nano 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-6842" id="CVE-2026-6842" title="nano的`~/.local`目录存在权限设置不当漏洞，该漏洞源于在宽松的umask设置环境下，目录权限被错误地设置为0777而非0700。本地攻击者可利用此不正确的目录权限注入恶意的`.desktop`启动器，若该启动器后续被处理，可能导致意外操作或信息泄露。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-6843" id="CVE-2026-6843" title="Red Hat Enterprise Linux是美国红帽（Red Hat）公司的面向企业用户的Linux操作系统。
Red Hat Enterprise Linux 10存在格式化字符串错误漏洞，该漏洞源于statusline函数存在格式字符串漏洞，本地用户可通过创建包含printf说明符的目录名，导致应用程序尝试显示该名称时发生分段错误，造成拒绝服务。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="nano" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nano-8.0-2.ky11.loongarch64.rpm" version="8.0">
					<filename>nano-8.0-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="nano-help" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nano-help-8.0-2.ky11.noarch.rpm" version="8.0">
					<filename>nano-help-8.0-2.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1311</id>
		<title>关于 NetworkManager 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:41"/>
		<updated date="2026-05-25 18:43:17"/>
		<severity>Low</severity>
		<description>关于 NetworkManager 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-9615" id="CVE-2025-9615" title="NetworkManager组件存在权限管理不当漏洞，该漏洞源于其允许非root用户配置系统网络，而守护进程以root权限运行，可能访问到不属于当前用户的文件。攻击者可利用此缺陷读取其他用户拥有的敏感文件，造成信息泄露。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="1" name="NetworkManager" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-bluetooth" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-bluetooth-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-bluetooth-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-cloud-setup" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-cloud-setup-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-cloud-setup-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="NetworkManager-config-server" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-config-server-1.44.2-3.p04.ky11.noarch.rpm" version="1.44.2">
					<filename>NetworkManager-config-server-1.44.2-3.p04.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="NetworkManager-help" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-help-1.44.2-3.p04.ky11.noarch.rpm" version="1.44.2">
					<filename>NetworkManager-help-1.44.2-3.p04.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-libnm" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-libnm-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-libnm-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-libnm-devel" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-libnm-devel-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-libnm-devel-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-ppp" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-ppp-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-ppp-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-team" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-team-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-team-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-wifi" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-wifi-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-wifi-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="NetworkManager-wwan" release="3.p04.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/NetworkManager-wwan-1.44.2-3.p04.ky11.loongarch64.rpm" version="1.44.2">
					<filename>NetworkManager-wwan-1.44.2-3.p04.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1314</id>
		<title>关于 openvswitch 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:43"/>
		<updated date="2026-05-25 18:43:56"/>
		<severity>Moderate</severity>
		<description>关于 openvswitch 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-34956" id="CVE-2026-34956" title="Open vSwitch 的用户态连接跟踪模块在处理特定构造的FTP报文时存在堆溢出漏洞，该漏洞源于在复制FTP子字符串时发生类型窄化，导致非法内存访问。攻击者可利用此漏洞通过发送恶意构造的FTP流量引发拒绝服务或可能的远程代码执行。触发该漏洞需要配置了FTP ALG处理器的连接跟踪规则，而默认情况下ALG处理器不会自动应用。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="network-scripts-openvswitch" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/network-scripts-openvswitch-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>network-scripts-openvswitch-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openvswitch" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>openvswitch-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openvswitch-devel" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-devel-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>openvswitch-devel-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openvswitch-dpdk" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-dpdk-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>openvswitch-dpdk-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openvswitch-ipsec" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-ipsec-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>openvswitch-ipsec-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="openvswitch-test" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-test-3.2.1-5.ky11.noarch.rpm" version="3.2.1">
					<filename>openvswitch-test-3.2.1-5.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="openvswitch-testcontroller" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/openvswitch-testcontroller-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>openvswitch-testcontroller-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-openvswitch" release="5.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-openvswitch-3.2.1-5.ky11.loongarch64.rpm" version="3.2.1">
					<filename>python3-openvswitch-3.2.1-5.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1317</id>
		<title>关于 postfix 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:47"/>
		<updated date="2026-05-25 18:44:35"/>
		<severity>Low</severity>
		<description>关于 postfix 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-43964" id="CVE-2026-43964" title="Postfix是Postfix开源的一个邮件传输代理软件。
Postfix存在安全漏洞，该漏洞源于增强状态码在第三位数字后缺少文本，可能导致缓冲区过度读取和进程崩溃。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="2" name="postfix" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/postfix-3.8.4-2.ky11.loongarch64.rpm" version="3.8.4">
					<filename>postfix-3.8.4-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="2" name="postfix-help" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/postfix-help-3.8.4-2.ky11.noarch.rpm" version="3.8.4">
					<filename>postfix-help-3.8.4-2.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="2" name="postfix-perl-scripts" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/postfix-perl-scripts-3.8.4-2.ky11.loongarch64.rpm" version="3.8.4">
					<filename>postfix-perl-scripts-3.8.4-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="2" name="postfix-pgsql" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/postfix-pgsql-3.8.4-2.ky11.loongarch64.rpm" version="3.8.4">
					<filename>postfix-pgsql-3.8.4-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="2" name="postfix-sysvinit" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/postfix-sysvinit-3.8.4-2.ky11.noarch.rpm" version="3.8.4">
					<filename>postfix-sysvinit-3.8.4-2.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1321</id>
		<title>关于 python3 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:53"/>
		<updated date="2026-05-25 18:45:42"/>
		<severity>Important</severity>
		<description>关于 python3 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-1502" id="CVE-2026-1502" title="CPython的HTTP客户端在代理隧道（proxy tunnel）的请求头或主机（host）字段中未正确拒绝CR/LF字节，导致存在CRLF注入漏洞。该漏洞源于对HTTP请求头中特殊字符的校验不充分，攻击者可能利用此漏洞向HTTP请求中注入额外的头部或主体内容，从而可能劫持请求或进行HTTP请求走私攻击。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-2297" id="CVE-2026-2297" title="CPython解释器在处理旧版*.pyc文件时存在安全审计绕过漏洞。该漏洞源于SourcelessFileLoader导入钩子在FileLoader基类中未正确使用io.open_code()函数来读取.pyc文件，导致sys.audit事件处理程序无法被正常触发。攻击者可利用此漏洞绕过Python的安全审计机制，在受影响的系统上执行未被监控的代码操作。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-3479" id="CVE-2026-3479" title="CPython是Python基金会的一个用C语言实现的Python解释器。
CPython存在安全漏洞，该漏洞源于未验证资源参数，可能导致路径遍历。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-3644" id="CVE-2026-3644" title="Python的http.cookies模块中针对CVE-2026-0672的修复不完整，攻击者仍可通过Morsel.update()方法、|=操作符以及反序列化路径绕过控制字符的输入校验。此外，BaseCookie.js_output()方法缺少与BaseCookie.output()相同的输出校验机制。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4519" id="CVE-2026-4519" title="Python的webbrowser模块中的open()函数存在输入验证不当漏洞，该漏洞源于未正确校验URL参数中的前导短横线字符，导致某些Web浏览器可能将其解析为命令行选项。攻击者可通过诱导用户访问特制URL，利用此漏洞导致浏览器执行非预期的命令行操作，造成低度信息泄露影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4786" id="CVE-2026-4786" title="CPython的webbrowser.open() API存在命令注入漏洞，该漏洞源于对CVE-2026-4519的修复不完整，当URL中包含&quot;%action&quot;时，针对特定浏览器类型的修复措施可被绕过，导致攻击者可能向底层shell注入命令。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-6019" id="CVE-2026-6019" title="CPython的http.cookies模块中的Morsel.js_output()函数存在跨站脚本漏洞，该漏洞源于函数返回的内联&lt;script&gt;代码片段仅对JavaScript字符串上下文中的双引号进行了转义，但未对HTML解析器敏感的序列&lt;/script&gt;进行有效中和。攻击者可通过特制的Cookie值注入&lt;/script&gt;序列，导致在生成的script元素中提前闭合HTML标签，从而可能引发跨站脚本攻击。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-6100" id="CVE-2026-6100" title="Python的`lzma.LZMADecompressor`、`bz2.BZ2Decompressor`和`gzip.GzipFile`解压缩模块存在释放后重用漏洞，该漏洞源于在解压缩过程中因内存压力触发`MemoryError`后，解压缩实例内部未正确清理悬空指针，若程序在发生此类错误后仍继续复用该解压缩实例，则可能触发释放后重用。可能导致进程崩溃或潜在代码执行。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="python3" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-3.11.6-29.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-3.11.6-29.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-debug" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-debug-3.11.6-29.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-debug-3.11.6-29.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-devel" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-devel-3.11.6-29.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-devel-3.11.6-29.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python3-help" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-help-3.11.6-29.p01.ky11.noarch.rpm" version="3.11.6">
					<filename>python3-help-3.11.6-29.p01.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-tkinter" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-tkinter-3.11.6-29.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-tkinter-3.11.6-29.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-unversioned-command" release="29.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-unversioned-command-3.11.6-29.p01.ky11.loongarch64.rpm" version="3.11.6">
					<filename>python3-unversioned-command-3.11.6-29.p01.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1326</id>
		<title>关于 python-ecdsa 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:51:55"/>
		<updated date="2026-05-25 18:46:04"/>
		<severity>Moderate</severity>
		<description>关于 python-ecdsa 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-33936" id="CVE-2026-33936" title="python-ecdsa库在0.19.2版本之前存在DER解析缺陷，该漏洞源于其低层DER解析函数未正确校验输入边界。具体而言，`ecdsa.der.remove_octet_string()`会接受长度声明超过实际缓冲区大小的截断DER编码数据，例如一个声明为4096字节但只提供了3字节的数据会被错误地解析成功。攻击者可构造恶意DER输入，导致`SigningKey.from_der()`抛出内部异常（如`IndexError: index out of bounds on dimension 1`），而非正常拒绝非法格式。若应用程序使用该库解析不受信任的DER私钥且未能妥善处理此类异常，则可能因异常崩溃而导致拒绝服务。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="noarch" epoch="0" name="python3-ecdsa" release="2.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-ecdsa-0.18.0-2.p01.ky11.noarch.rpm" version="0.18.0">
					<filename>python3-ecdsa-0.18.0-2.p01.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python-ecdsa-help" release="2.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python-ecdsa-help-0.18.0-2.p01.ky11.noarch.rpm" version="0.18.0">
					<filename>python-ecdsa-help-0.18.0-2.p01.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1331</id>
		<title>关于 python-pygments 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:03"/>
		<updated date="2026-05-25 18:11:03"/>
		<severity>Low</severity>
		<description>关于 python-pygments 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4539" id="CVE-2026-4539" title="Pygments语法高亮库的`pygments/lexers/archetype.py`文件中的`AdlLexer`函数存在正则表达式拒绝服务漏洞，该漏洞源于该函数使用了低效的正则表达式。攻击者可通过本地访问利用此漏洞发起拒绝服务攻击。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="noarch" epoch="0" name="python3-pygments" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-pygments-2.17.2-2.ky11.noarch.rpm" version="2.17.2">
					<filename>python3-pygments-2.17.2-2.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python-pygments-help" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python-pygments-help-2.17.2-2.ky11.noarch.rpm" version="2.17.2">
					<filename>python-pygments-help-2.17.2-2.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1334</id>
		<title>关于 python-requests 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:05"/>
		<updated date="2026-05-25 18:11:17"/>
		<severity>Moderate</severity>
		<description>关于 python-requests 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-25645" id="CVE-2026-25645" title="Requests库的`requests.utils.extract_zipped_paths()`工具函数存在路径穿越漏洞，该漏洞源于该函数在从ZIP归档中提取文件到系统临时目录时使用了可预测的文件名，且当目标文件已存在时会直接复用而不进行验证。本地攻击者若对临时目录具有写入权限，可预先创建恶意文件以替换应被加载的合法文件，从而可能影响依赖此函数的应用程序。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="noarch" epoch="0" name="python3-requests" release="5.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-requests-2.31.0-5.p01.ky11.noarch.rpm" version="2.31.0">
					<filename>python3-requests-2.31.0-5.p01.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="python-requests-help" release="5.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python-requests-help-2.31.0-5.p01.ky11.noarch.rpm" version="2.31.0">
					<filename>python-requests-help-2.31.0-5.p01.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1347</id>
		<title>关于 sudo 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:16"/>
		<updated date="2026-05-25 18:08:52"/>
		<severity>Important</severity>
		<description>关于 sudo 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35535" id="CVE-2026-35535" title="Sudo组件在降权运行邮件程序之前，未能正确检查setuid、setgid或setgroups系统调用的返回值。当这些调用失败时，Sudo未将其视为致命错误，导致可能仍然保留了较高的权限。攻击者可利用该漏洞在本地系统上实现权限提升。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="sudo" release="4.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/sudo-1.9.15p5-4.p01.ky11.loongarch64.rpm" version="1.9.15p5">
					<filename>sudo-1.9.15p5-4.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="sudo-devel" release="4.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/sudo-devel-1.9.15p5-4.p01.ky11.loongarch64.rpm" version="1.9.15p5">
					<filename>sudo-devel-1.9.15p5-4.p01.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="sudo-help" release="4.p01.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/sudo-help-1.9.15p5-4.p01.ky11.noarch.rpm" version="1.9.15p5">
					<filename>sudo-help-1.9.15p5-4.p01.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1351</id>
		<title>关于 tomcat 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:20"/>
		<updated date="2026-05-25 18:07:51"/>
		<severity>Moderate</severity>
		<description>关于 tomcat 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-66614" id="CVE-2025-66614" title="Apache Tomcat的SNI扩展主机名与HTTP主机头字段校验功能存在输入验证不当漏洞，该漏洞源于Tomcat未验证通过SNI扩展提供的主机名与HTTP主机头字段中提供的主机名是否一致。当Tomcat配置了多个虚拟主机，且其中一台主机的TLS配置未要求客户端证书认证而另一台要求时，攻击者可通过在SNI扩展和HTTP主机头字段中发送不同的主机名，绕过客户端证书认证，导致安全限制被绕过。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-24733" id="CVE-2026-24733" title="Apache Tomcat组件存在输入验证不当漏洞。该漏洞源于Tomcat未对HTTP/0.9请求的方法进行限制。当安全策略配置为允许对某URI接受HEAD请求但拒绝GET请求时，攻击者可通过发送一个（不符合规范的）HTTP/0.9 HEAD请求绕过该限制。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-24734" id="CVE-2026-24734" title="Apache Tomcat和Apache Tomcat Native都是美国阿帕奇（Apache）基金会的产品。Apache Tomcat是一款轻量级Web应用服务器。用于实现对Servlet和JavaServer Page（JSP）的支持。Apache Tomcat Native是一个本地组件库。
Apache Tomcat Native 1.3.4及之前版本、2.0.11及之前版本和Apache Tomcat 11.0.17及之前版本、10.1.51及之前版本、9.0.114及之前版本存在输入验证错误漏洞，该漏洞源于使用OCSP响应器时未完成对OCSP响应的验证或新鲜度检查，可能导致绕过证书吊销检查。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-34500" id="CVE-2026-34500" title="Apache Tomcat 11.0.0-M14至11.0.20版本、10.1.22至10.1.53版本和9.0.92至9.0.116版本存在安全漏洞，该漏洞源于当软故障禁用且使用FFM时，CLIENT_CERT身份验证在某些场景下未按预期失败。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="noarch" epoch="1" name="tomcat" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/tomcat-9.0.118-1.ky11.noarch.rpm" version="9.0.118">
					<filename>tomcat-9.0.118-1.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="tomcat-help" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/tomcat-help-9.0.118-1.ky11.noarch.rpm" version="9.0.118">
					<filename>tomcat-help-9.0.118-1.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="tomcat-jsvc" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/tomcat-jsvc-9.0.118-1.ky11.noarch.rpm" version="9.0.118">
					<filename>tomcat-jsvc-9.0.118-1.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1352</id>
		<title>关于 uriparser 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:21"/>
		<updated date="2026-05-25 18:07:35"/>
		<severity>Moderate</severity>
		<description>关于 uriparser 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-42371" id="CVE-2026-42371" title="在 1.0.1 版本之前的 uriparser 中，文本范围比较存在数值截断问题，如果应用程序接受长度为千兆字节的 URI，则可能导致漏洞。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="uriparser" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/uriparser-1.0.1-2.ky11.loongarch64.rpm" version="1.0.1">
					<filename>uriparser-1.0.1-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="uriparser-devel" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/uriparser-devel-1.0.1-2.ky11.loongarch64.rpm" version="1.0.1">
					<filename>uriparser-devel-1.0.1-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="uriparser-help" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/uriparser-help-1.0.1-2.ky11.noarch.rpm" version="1.0.1">
					<filename>uriparser-help-1.0.1-2.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1354</id>
		<title>关于 vim 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:22"/>
		<updated date="2026-05-25 18:07:07"/>
		<severity>Moderate</severity>
		<description>关于 vim 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-35177" id="CVE-2026-35177" title="Vim的zip.vim插件存在路径遍历漏洞，该漏洞源于对CVE-2025-53906的修复不完善，导致在处理特制的zip压缩包时，攻击者可以绕过路径限制，覆盖任意文件。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="2" name="vim-common" release="32.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/vim-common-9.0.2092-32.ky11.loongarch64.rpm" version="9.0.2092">
					<filename>vim-common-9.0.2092-32.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="2" name="vim-enhanced" release="32.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/vim-enhanced-9.0.2092-32.ky11.loongarch64.rpm" version="9.0.2092">
					<filename>vim-enhanced-9.0.2092-32.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="2" name="vim-filesystem" release="32.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/vim-filesystem-9.0.2092-32.ky11.noarch.rpm" version="9.0.2092">
					<filename>vim-filesystem-9.0.2092-32.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="2" name="vim-minimal" release="32.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/vim-minimal-9.0.2092-32.ky11.loongarch64.rpm" version="9.0.2092">
					<filename>vim-minimal-9.0.2092-32.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="2" name="vim-X11" release="32.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/vim-X11-9.0.2092-32.ky11.loongarch64.rpm" version="9.0.2092">
					<filename>vim-X11-9.0.2092-32.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1357</id>
		<title>关于 wireshark 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 12:52:26"/>
		<updated date="2026-05-25 18:05:38"/>
		<severity>Moderate</severity>
		<description>关于 wireshark 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-13946" id="CVE-2025-13946" title="Wireshark 4.6.0版本至4.6.1版本和4.4.0版本至4.4.11版本存在安全漏洞，该漏洞源于MEGACO解析器无限循环，可能导致拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-9817" id="CVE-2025-9817" title="Wireshark 4.4.0至4.4.8版本存在代码问题漏洞，该漏洞源于SSH解析器崩溃，可能导致拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-0959" id="CVE-2026-0959" title="Wireshark的IEEE 802.11协议解析器模块存在拒绝服务漏洞，该漏洞源于程序在解析畸形或特制的IEEE 802.11数据包时未正确处理输入数据导致程序崩溃。可能导致导致应用程序意外终止，造成拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-0960" id="CVE-2026-0960" title="Wireshark的HTTP/3协议解析器模块在4.6.0至4.6.2版本中存在拒绝服务漏洞，该漏洞源于程序在处理特制的HTTP/3数据包时逻辑判断失误，进入了无限循环状态。可能导致导致应用程序资源耗尽并停止响应，从而造成拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-0961" id="CVE-2026-0961" title="Wireshark的BLF文件解析器模块存在拒绝服务漏洞，该漏洞源于程序在解析畸形或特制的BLF格式文件时未正确处理异常输入导致程序崩溃。可能导致导致应用程序意外终止，造成拒绝服务。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-5299" id="CVE-2026-5299" title="Wireshark 4.6.0 到 4.6.4 以及 4.4.0 到 4.4.14 版本中，ICMPv6 PvD 协议解析器存在崩溃漏洞，可能导致拒绝服务攻击。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="1" name="wireshark" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/wireshark-4.4.15-1.ky11.loongarch64.rpm" version="4.4.15">
					<filename>wireshark-4.4.15-1.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="wireshark-devel" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/wireshark-devel-4.4.15-1.ky11.loongarch64.rpm" version="4.4.15">
					<filename>wireshark-devel-4.4.15-1.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="wireshark-help" release="1.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/wireshark-help-4.4.15-1.ky11.noarch.rpm" version="4.4.15">
					<filename>wireshark-help-4.4.15-1.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1388</id>
		<title>关于 libxml2 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 18:50:17"/>
		<updated date="2026-05-25 17:12:33"/>
		<severity>Low</severity>
		<description>关于 libxml2 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2025-8732" id="CVE-2025-8732" title="libxml2 库在 2.14.5 及之前版本中的 xmlcatalog 组件存在未控制递归漏洞，具体影响函数 xmlParseSGMLCatalog。攻击者可利用本地权限通过构造恶意的 SGML 目录文件触发该问题，导致拒绝服务（资源耗尽）。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libxml2" release="6.p03.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libxml2-2.11.9-6.p03.ky11.loongarch64.rpm" version="2.11.9">
					<filename>libxml2-2.11.9-6.p03.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libxml2-devel" release="6.p03.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libxml2-devel-2.11.9-6.p03.ky11.loongarch64.rpm" version="2.11.9">
					<filename>libxml2-devel-2.11.9-6.p03.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="libxml2-help" release="6.p03.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libxml2-help-2.11.9-6.p03.ky11.noarch.rpm" version="2.11.9">
					<filename>libxml2-help-2.11.9-6.p03.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libxml2-kycompat" release="6.p03.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libxml2-kycompat-2.11.9-6.p03.ky11.loongarch64.rpm" version="2.11.9">
					<filename>libxml2-kycompat-2.11.9-6.p03.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-libxml2" release="6.p03.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-libxml2-2.11.9-6.p03.ky11.loongarch64.rpm" version="2.11.9">
					<filename>python3-libxml2-2.11.9-6.p03.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1389</id>
		<title>关于 libXpm 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-19 18:50:18"/>
		<updated date="2026-05-25 17:12:47"/>
		<severity>Important</severity>
		<description>关于 libXpm 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4367" id="CVE-2026-4367" title="X.org libXpm库在3.5.4及之前版本中存在安全漏洞，该漏洞源于在处理图像数据时未能正确验证缓冲区边界，导致产品会读取超出预期缓冲区起始或结束位置的数据。攻击者可利用此漏洞读取敏感内存信息，从而对机密性造成影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libXpm" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libXpm-3.5.17-2.ky11.loongarch64.rpm" version="3.5.17">
					<filename>libXpm-3.5.17-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libXpm-devel" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libXpm-devel-3.5.17-2.ky11.loongarch64.rpm" version="3.5.17">
					<filename>libXpm-devel-3.5.17-2.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="libXpm-help" release="2.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libXpm-help-3.5.17-2.ky11.noarch.rpm" version="3.5.17">
					<filename>libXpm-help-3.5.17-2.ky11.noarch.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1401</id>
		<title>关于 cockpit 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:02"/>
		<updated date="2026-05-25 03:36:45"/>
		<severity>Low</severity>
		<description>关于 cockpit 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0415" id="KVE-2026-0415" title="Cockpit后端日志功能代码层面存在 Shell 元字符过滤不严的编码缺陷，导致存在命令注入。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="cockpit" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/cockpit-309-4.p02.ky11.loongarch64.rpm" version="309">
					<filename>cockpit-309-4.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="cockpit-devel" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/cockpit-devel-309-4.p02.ky11.loongarch64.rpm" version="309">
					<filename>cockpit-devel-309-4.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="cockpit-help" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/cockpit-help-309-4.p02.ky11.noarch.rpm" version="309">
					<filename>cockpit-help-309-4.p02.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="cockpit-pcp" release="4.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/cockpit-pcp-309-4.p02.ky11.loongarch64.rpm" version="309">
					<filename>cockpit-pcp-309-4.p02.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1408</id>
		<title>关于 kycompatguard 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:05"/>
		<updated date="2026-05-25 03:37:08"/>
		<severity>Moderate</severity>
		<description>关于 kycompatguard 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0411" id="KVE-2026-0411" title="kycompatguard 工具在处理 RPM 文件名时未进行转义，直接拼接到系统命令中执行。攻击者可通过构造包含 Shell 元字符的文件名，诱使管理员或 root 用户使用该工具检查文件，从而以 root 权限执行任意命令。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="kycompatguard" release="4.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kycompatguard-1.0-4.ky11.loongarch64.rpm" version="1.0">
					<filename>kycompatguard-1.0-4.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1412</id>
		<title>关于 kylin-subscription 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:06"/>
		<updated date="2026-05-25 03:36:31"/>
		<severity>Low</severity>
		<description>关于 kylin-subscription 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0417" id="KVE-2026-0417" title="kylin-subscription组件存在路径穿越漏洞，特殊情况下攻击者可利用此漏洞进行任意文件写操作。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="kylin-subscription" release="1.p10.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kylin-subscription-1.0.0-1.p10.ky11.loongarch64.rpm" version="1.0.0">
					<filename>kylin-subscription-1.0.0-1.p10.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-dnf-plugin-kylin-subscription" release="1.p10.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-dnf-plugin-kylin-subscription-1.0.0-1.p10.ky11.loongarch64.rpm" version="1.0.0">
					<filename>python3-dnf-plugin-kylin-subscription-1.0.0-1.p10.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1413</id>
		<title>关于 kylin-user-guide 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:06"/>
		<updated date="2026-05-25 03:36:57"/>
		<severity>Low</severity>
		<description>关于 kylin-user-guide 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0413" id="KVE-2026-0413" title="kylin-user-guide ghelp: scheme 参数未过滤导致的 JS 注入，进而通过暴露的 bridge.js_executeCommand 实现本地命令执行。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="kylin-user-guide" release="1.p13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kylin-user-guide-4.10.0.0-1.p13.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>kylin-user-guide-4.10.0.0-1.p13.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="kylin-user-guide-common" release="1.p13.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kylin-user-guide-common-4.10.0.0-1.p13.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>kylin-user-guide-common-4.10.0.0-1.p13.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1418</id>
		<title>关于 libkysdk-system 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:10"/>
		<updated date="2026-05-25 03:35:13"/>
		<severity>Important</severity>
		<description>关于 libkysdk-system 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0703" id="KVE-2025-0703" title="银河麒麟操作系统系统开发套件组件存在权限管理机制不完善漏洞，该漏洞源于权限管理体系未对所有特权操作实施充分的身份与授权验证，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0704" id="KVE-2025-0704" title="银河麒麟操作系统系统开发套件组件存在权限管理机制不完善漏洞，该漏洞源于权限管理体系未对所有特权操作实施充分的身份与授权验证，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0705" id="KVE-2025-0705" title="银河麒麟操作系统系统开发套件组件存在对外部输入校验不严格漏洞，该漏洞源于对外部传入的参数或数据进行校验与过滤的环节存在疏漏，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0706" id="KVE-2025-0706" title="银河麒麟操作系统系统开发套件组件存在身份验证机制不完善漏洞，该漏洞源于操作者身份验证环节存在检查不充分或可被绕过的缺陷，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0707" id="KVE-2025-0707" title="银河麒麟操作系统系统开发套件组件存在安全机制设计存在缺陷漏洞，该漏洞源于安全机制的设计未能覆盖特定攻击路径或使用场景，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0801" id="KVE-2025-0801" title="银河麒麟操作系统系统开发套件组件存在安全机制设计存在缺陷漏洞，该漏洞源于安全机制的设计未能覆盖特定攻击路径或使用场景，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-1001" id="KVE-2025-1001" title="银河麒麟操作系统系统开发套件组件存在对外部输入校验不严格漏洞，该漏洞源于对外部传入的参数或数据进行校验与过滤的环节存在疏漏，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-259872293" id="KVE-2025-259872293" title="银河麒麟操作系统系统开发套件组件存在文件写入权限校验不充分漏洞，该漏洞源于执行文件写入操作前对调用者权限的验证不充分，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libkysdk-accounts" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-accounts-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-accounts-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-accounts-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-accounts-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-accounts-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-battery" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-battery-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-battery-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-battery-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-battery-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-battery-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-disk" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-disk-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-disk-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-disk-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-disk-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-disk-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-filesystem" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-filesystem-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-filesystem-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-filesystem-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-filesystem-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-filesystem-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-global" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-global-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-global-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-global-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-global-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-global-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-hardware" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-hardware-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-hardware-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-hardware-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-hardware-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-hardware-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-imageproc" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-imageproc-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-imageproc-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-imageproc-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-imageproc-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-imageproc-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-location" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-location-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-location-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-location-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-location-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-location-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-logrotate" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-logrotate-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-logrotate-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-net" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-net-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-net-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-net-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-net-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-net-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-ocr" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-ocr-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-ocr-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-ocr-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-ocr-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-ocr-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-package" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-package-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-package-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-package-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-package-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-package-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-powermanagement" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-powermanagement-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-powermanagement-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-powermanagement-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-powermanagement-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-powermanagement-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-proc" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-proc-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-proc-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-proc-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-proc-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-proc-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-realtime" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-realtime-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-realtime-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-realtime-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-realtime-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-realtime-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-search" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-search-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-search-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-search-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-search-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-search-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-storage" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-storage-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-storage-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-storage-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-storage-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-storage-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-sysinfo" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-sysinfo-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-sysinfo-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-sysinfo-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-sysinfo-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-sysinfo-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-systemcommon" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-systemcommon-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-systemcommon-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-dbus" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-dbus-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-dbus-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-java" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-java-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-java-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-javascript-http" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-javascript-http-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-javascript-http-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-javascript-websocket" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-javascript-websocket-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-javascript-websocket-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-system-python" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-system-python-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-system-python-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-systime" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-systime-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-systime-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libkysdk-systime-devel" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libkysdk-systime-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm" version="2.5.1.2">
					<filename>libkysdk-systime-devel-2.5.1.2-1.p06.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1420</id>
		<title>关于 security-reinforce 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:12"/>
		<updated date="2026-05-25 03:34:54"/>
		<severity>Moderate</severity>
		<description>关于 security-reinforce 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0409" id="KVE-2026-0409" title="security-reinforce 工具输出报告路径未检查符号链接，当 root 用户执行报告导出功能操作后，低权限用户可将其指向恶意路径。管理员或 root 用户登录时，以 root 权限执行任意命令。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0420" id="KVE-2026-0420" title="security-reinforce组件存在路径穿越漏洞，该漏洞源于模版TEMPLATE_NAME参数因作为文件名传递，拼接跨目录字符可导出到任意路径，最终导致操作系统以当前用户权限执行系统命令。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="security-reinforce" release="08.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/security-reinforce-3.0.0-08.ky11.loongarch64.rpm" version="3.0.0">
					<filename>security-reinforce-3.0.0-08.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1421</id>
		<title>关于 ukui-bluetooth 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:12"/>
		<updated date="2026-05-25 03:34:42"/>
		<severity>Important</severity>
		<description>关于 ukui-bluetooth 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0414" id="KVE-2026-0414" title="银河麒麟操作系统蓝牙管理组件存在对外部输入校验不严格漏洞，该漏洞源于对外部传入的参数或数据进行校验与过滤的环节存在疏漏，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="ukui-bluetooth" release="1.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-bluetooth-4.10.1.0-1.p07.ky11.loongarch64.rpm" version="4.10.1.0">
					<filename>ukui-bluetooth-4.10.1.0-1.p07.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1422</id>
		<title>关于 ukui-session-manager 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:13"/>
		<updated date="2026-05-25 03:34:27"/>
		<severity>Important</severity>
		<description>关于 ukui-session-manager 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0412" id="KVE-2026-0412" title="银河麒麟操作系统桌面会话管理组件存在身份认证机制缺陷漏洞，该漏洞源于身份认证流程存在检查缺失，允许未经充分验证的连接通过认证，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="ukui-session-manager" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-session-manager-4.0.0.0-1.p06.ky11.loongarch64.rpm" version="4.0.0.0">
					<filename>ukui-session-manager-4.0.0.0-1.p06.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="ukui-session-wayland" release="1.p06.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-session-wayland-4.0.0.0-1.p06.ky11.loongarch64.rpm" version="4.0.0.0">
					<filename>ukui-session-wayland-4.0.0.0-1.p06.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1423</id>
		<title>关于 ukui-settings-daemon 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-24 13:09:14"/>
		<updated date="2026-05-25 03:34:12"/>
		<severity>Important</severity>
		<description>关于 ukui-settings-daemon 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2025-0305" id="KVE-2025-0305" title="ukui-settings-daemon组件readGlobalConfig函数存在任意文件读取漏洞,攻击者通过特制的输入如../符号，跨越当前路径读取普通用户权限不应被访问敏感数据，从而造成信息泄露。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=KVE-2026-0508" id="KVE-2026-0508" title="银河麒麟操作系统桌面设置服务组件存在文件写入权限校验不充分漏洞，该漏洞源于执行文件写入操作前对调用者权限的验证不充分，特殊情况下可能对系统整体安全性造成不利影响。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="kylin-display-switch" release="1.p14.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/kylin-display-switch-4.10.0.0-1.p14.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>kylin-display-switch-4.10.0.0-1.p14.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="ukui-settings-daemon" release="1.p14.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-settings-daemon-4.10.0.0-1.p14.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>ukui-settings-daemon-4.10.0.0-1.p14.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="ukui-settings-daemon-common" release="1.p14.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/ukui-settings-daemon-common-4.10.0.0-1.p14.ky11.loongarch64.rpm" version="4.10.0.0">
					<filename>ukui-settings-daemon-common-4.10.0.0-1.p14.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1455</id>
		<title>关于 nginx 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-26 10:43:15"/>
		<updated date="2026-06-01 14:14:30"/>
		<severity>Important</severity>
		<description>关于 nginx 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-32647" id="CVE-2026-32647" title="NGINX开源版及NGINX Plus的ngx_http_mp4_module模块存在缓冲区溢出漏洞，该漏洞源于模块在处理特制MP4文件时未能正确执行边界检查。当NGINX在配置中启用了mp4指令且攻击者能够诱使服务处理特制MP4文件时，可能触发缓冲区越界读取或写入，导致NGINX工作进程终止或潜在远程代码执行。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-42945" id="CVE-2026-42945" title="F5 NGINX Plus和F5 NGINX Open Source都是美国F5公司的产品。F5 NGINX Plus是一个基于软件的应用程序交付平台。F5 NGINX Open Source是一个高性能Web服务器、反向代理服务器、负载均衡器和API网关。
F5 NGINX Plus和F5 NGINX Open Source存在安全漏洞，该漏洞源于ngx_http_rewrite_module模块中rewrite指令后跟rewrite、if或set指令时，可能导致堆缓冲区溢出，导致重启或代码执行。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="1" name="nginx" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="nginx-all-modules" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-all-modules-1.24.0-6.p02.ky11.noarch.rpm" version="1.24.0">
					<filename>nginx-all-modules-1.24.0-6.p02.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="nginx-filesystem" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-filesystem-1.24.0-6.p02.ky11.noarch.rpm" version="1.24.0">
					<filename>nginx-filesystem-1.24.0-6.p02.ky11.noarch.rpm</filename>
				</package>
				<package arch="noarch" epoch="1" name="nginx-help" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-help-1.24.0-6.p02.ky11.noarch.rpm" version="1.24.0">
					<filename>nginx-help-1.24.0-6.p02.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-devel" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-devel-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-devel-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-http-image-filter" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-http-image-filter-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-http-image-filter-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-http-perl" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-http-perl-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-http-perl-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-http-xslt-filter" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-http-xslt-filter-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-http-xslt-filter-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-mail" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-mail-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-mail-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="1" name="nginx-mod-stream" release="6.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/nginx-mod-stream-1.24.0-6.p02.ky11.loongarch64.rpm" version="1.24.0">
					<filename>nginx-mod-stream-1.24.0-6.p02.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1558</id>
		<title>关于 systemd 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-26 18:51:15"/>
		<updated date="2026-06-01 16:55:34"/>
		<severity>Moderate</severity>
		<description>关于 systemd 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-29111" id="CVE-2026-29111" title="systemd v239版本至v259.2及之前版本存在安全漏洞，该漏洞源于未授权IPC API调用处理不当，可能导致断言失败、执行冻结或栈覆盖。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-40226" id="CVE-2026-40226" title="systemd的nspawn组件存在容器逃逸漏洞，该漏洞源于对可选配置文件处理不当，攻击者可通过构造恶意的配置文件，在特定条件下实现从容器逃逸至宿主机，从而获取宿主机的高权限访问能力。" type="cve"/>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-4105" id="CVE-2026-4105" title="systemd组件中的systemd-machined服务存在访问控制不当漏洞，该漏洞源于在RegisterMachine D-Bus方法中未充分验证class参数。本地非特权用户可利用此漏洞通过尝试注册具有特定class值的机器，在系统中遗留一个可供攻击者控制的机器对象。攻击者可借此调用特权对象上的方法，从而在主机上以root权限执行任意命令。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="systemd" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-container" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-container-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-container-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-cryptsetup" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-cryptsetup-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-cryptsetup-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-devel" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-devel-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-devel-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="systemd-help" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-help-255-44.p07.ky11.noarch.rpm" version="255">
					<filename>systemd-help-255-44.p07.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-libs" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-libs-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-libs-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-networkd" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-networkd-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-networkd-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-nspawn" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-nspawn-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-nspawn-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-oomd" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-oomd-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-oomd-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-pam" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-pam-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-pam-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-resolved" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-resolved-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-resolved-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-sysprocess-manage" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-sysprocess-manage-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-sysprocess-manage-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-timesyncd" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-timesyncd-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-timesyncd-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="systemd-udev" release="44.p07.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/systemd-udev-255-44.p07.ky11.loongarch64.rpm" version="255">
					<filename>systemd-udev-255-44.p07.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
	<update from="cve_manager@kylinos.cn" status="stable" type="security" version="">
		<id>KYSA-202605-1560</id>
		<title>关于 util-linux 的补丁包公告</title>
		<release>Kylin Linux Advanced Server release V11 SP1(swan26)</release>
		<issued date="2026-05-26 18:51:17"/>
		<updated date="2026-06-01 16:58:39"/>
		<severity>Moderate</severity>
		<description>关于 util-linux 的软件包现在已有更新补丁提供。
您可在CVE详情页查看各个CVE的详细信息与补丁包下载链接。
</description>
		<references>
			<reference href="https://support.kylinos.cn/#/security/cveDetail?allTitle=CVE-2026-27456" id="CVE-2026-27456" title="util-linux是util-linux开源的一个软件包。util-linux 存在安全漏洞，该漏洞源于SUID二进制文件mount存在TOCTOU竞争条件，可能导致未经授权的文件访问。" type="cve"/>
		</references>
		<pkglist>
			<collection short="Kylin Linux Advanced Server release V11 SP1(swan26)">
				<name>银河麒麟高级服务器操作系统 V11 SP1</name>
				<package arch="loongarch64" epoch="0" name="libblkid" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libblkid-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>libblkid-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libfdisk" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libfdisk-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>libfdisk-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libmount" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libmount-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>libmount-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libsmartcols" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libsmartcols-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>libsmartcols-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="libuuid" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/libuuid-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>libuuid-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="python3-libmount" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/python3-libmount-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>python3-libmount-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="util-linux" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/util-linux-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>util-linux-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="util-linux-devel" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/util-linux-devel-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>util-linux-devel-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="noarch" epoch="0" name="util-linux-help" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/util-linux-help-2.39.1-35.p02.ky11.noarch.rpm" version="2.39.1">
					<filename>util-linux-help-2.39.1-35.p02.ky11.noarch.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="util-linux-user" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/util-linux-user-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>util-linux-user-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
				<package arch="loongarch64" epoch="0" name="uuidd" release="35.p02.ky11" src="https://update.cs2c.com.cn/NS/V11/V11SP1-2603/os/adv/lic/updates/loongarch64/Packages/uuidd-2.39.1-35.p02.ky11.loongarch64.rpm" version="2.39.1">
					<filename>uuidd-2.39.1-35.p02.ky11.loongarch64.rpm</filename>
				</package>
			</collection>
		</pkglist>
	</update>
</updates>
