CVE-2026-81881: Fix Swift Mach-O field metadata bounds check
(boo#1282341).
CVE-2026-81880: Decode PEF relocs lazily, add more bounds and
overflow checks (boo#1282340).
CVE-2026-81879: Fix oobread in ELF PN_XNUM phdr count handling
(boo#1282339).
CVE-2026-81878: Fix heap write overflow in Python loader
(boo#1282338).
CVE-2026-14788: Denial of Service via use-after-free in
r_core_bin_load function (boo#1270453).
CVE-2026-14761: Denial of service via integer overflow in string
manipulation functions (boo#1270452).
CVE-2026-14760: Denial of Service via local use-after-free
vulnerability (boo#1270450).
CVE-2026-14759: Denial of Service via heap-based buffer overflow
(boo#1270449).
CVE-2026-14758: Denial of Service via integer overflow in hexpairs
parser (boo#1270447).
CVE-2026-14757: Integer overflow allows local impact (boo#1270445).
CVE-2026-40527: Command injection vulnerability in the afsv/afsvj
(boo#1262336).
CVE-2026-4174: Missing validation against an upper limit when
allocating memory in the Mach-O file parser can lead to excessive
resource consumption (boo#1259722).
Security issue fixed with the previous release:
CVE-2026-41015: Configured on UNIX without SSL, allows command
injection via a PDB name to rabin2 (boo#1262190).
CVE-2026-40517: Crafted PDB file with newline characters in symbol
names can allow to inject arbitrary commands (boo#1262680).
CVE-2026-8695: UAFs in the gdb remote protocol ##crash (boo#1265403).