Aggregator

USN-8823-1: PyJWT vulnerabilities

6 days 4 hours ago
It was discovered that PyJWT incorrectly handled certain URIs when using PyJWKClient. A remote attacker could possibly use this issue to perform server-side request forgery (SSRF) or expose sensitive local files. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48522) It was discovered that PyJWT incorrectly verified cryptographic signatures when decoding tokens with PyJWK keys. A remote attacker could possibly use this issue to bypass signature verification and forge valid JSON Web Tokens. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-48523) It was discovered that PyJWT incorrectly handled unknown key identifiers in PyJWKClient. A remote attacker could possibly use this issue to cause PyJWT to make excessive network requests, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48524) It was discovered that PyJWT incorrectly handled payload decoding during detached JWS token verification. A remote attacker could possibly use this issue to cause PyJWT to consume excessive resources, resulting in a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-48525) It was discovered that PyJWT incorrectly validated JSON Web Keys when decoding tokens with both HMAC and asymmetric algorithms enabled. A remote attacker could possibly use this issue to forge valid tokens, resulting in an authentication bypass. (CVE-2026-48526)

libical-3.0.20-5.fc43

6 days 4 hours ago
FEDORA-2026-d4c8dad1fd Packages in this update:
  • libical-3.0.20-5.fc43
Update description:

Add a patch for CVE-2026-88383: Denial of Service via crafted iCalendar property parsing

libical-3.0.20-8.fc44

6 days 4 hours ago
FEDORA-2026-a76bba1412 Packages in this update:
  • libical-3.0.20-8.fc44
Update description:

Add a patch for CVE-2026-88383: Denial of Service via crafted iCalendar property parsing

libical-3.0.20-10.fc45

6 days 4 hours ago
FEDORA-2026-9616ace61b Packages in this update:
  • libical-3.0.20-10.fc45
Update description:

Add a patch for CVE-2026-88383: Denial of Service via crafted iCalendar property parsing

0ad-0.28.0-7.fc45 GAPDoc-1.6.10-4.fc45 GConf2-3.2.6-51.fc45 GraphicsMagick-1.3.45-11.fc45 ImageMagick-7.1.2.31-2.fc45 Io-language-20170906-30.fc45 Macaulay2-1.26.06-4.fc45 NetworkManager-openconnect-1.2.10-13.fc45 PDAL-2.10.2-5.fc45 R-XML-3.99.0.23-3…

6 days 4 hours ago
FEDORA-2026-91259c13b9 Packages in this update:
  • 0ad-0.28.0-7.fc45
  • abiword-3.0.8-6.fc45
  • adobe-afdko-4.0.3-5.fc45
  • akonadi-server-26.08.1-2.fc45
  • anaconda-45.27-2.fc45
  • anjuta-3.34.0-32.fc45
  • appstream-1.1.3-4.fc45
  • appstream-generator-0.10.1-5.fc45
  • aqbanking-6.9.2-2.fc45
  • aqualung-2.0-13.fc45
  • ardour6-6.9.0-35.fc45
  • ardour7-7.5.0-26.fc45
  • ardour8-8.12.0-14.fc45
  • ardour9-9.8.0-2.fc45
  • aria2-1.37.0-12.fc45
  • armacycles-ad-0.2.9.3.0-2.20260806gitv0.2.9.3.0.fc45
  • artikulate-26.08.1-2.fc45
  • asterisk-23.5.0-5.fc45.1
  • atomes-1.3.1-5.fc45
  • atril-1.28.7-2.fc45
  • audacious-plugins-4.6.1-7.fc45
  • augeas-1.14.2-0.13.20260408gitada6219.fc45
  • autofs-5.1.9-15.fc45
  • autogen-5.18.16-37.fc45
  • bijiben-40.2-11.fc45
  • bind-9.18.50-35.fc45
  • bind9-next-9.21.22-5.fc45
  • blackbox-terminal-0.15.2-3.fc45
  • bluefish-2.4.2-3.fc45
  • bodr-10-30.fc45
  • bookworm-1.1.3-0.21.20200414git.c7c3643.fc45
  • booth-1.2-10.fc45
  • brasero-3.12.3-30.fc45
  • budgie-control-center-2.1.3-2.fc45
  • cairo-dock-3.6.2-5.fc45
  • cairo-dock-plug-ins-3.6.2-9.fc45
  • caja-1.28.0-13.fc45
  • caja-actions-1.28.0-11.fc45
  • caja-extensions-1.28.0-13.fc45
  • cantor-26.08.1-2.fc45
  • caribou-0.4.21-54.fc45
  • castget-2.0.1-27.fc45
  • certmonger-0.79.21-10.fc45
  • cgreen-1.7.0-4.fc45
  • chatty-0.8.9-11.fc45
  • chemical-mime-data-0.1.94-44.fc45
  • cinnamon-6.7.8^unstable-2.fc45
  • clamav-1.4.6-2.fc45
  • clang18-18.1.8-11.fc45
  • collada-dom-2.5.0-47.fc45
  • collectd-5.12.0-71.fc45
  • compiz-0.8.18-22.fc45
  • compizconfig-python-0.8.18-24.fc45
  • compiz-plugins-experimental-0.8.18-18.fc45
  • compiz-plugins-extra-0.8.18-18.fc45
  • compiz-plugins-main-0.8.18-18.fc45
  • conky-1.24.2-3.fc45
  • cptutils-1.82-8.fc45
  • createrepo_c-1.2.1-11.fc45
  • ctags-6.2.1-5.fc45
  • cyrus-imapd-3.12.4-2.fc45
  • darktable-5.6.1-3.fc45
  • davix-0.8.10-11.fc45
  • dcmtk-3.6.9-9.fc45
  • ddccontrol-3.3.0-2.fc45
  • denemo-2.6.0-22.fc45
  • dia-0.97.3-34.fc45
  • dicomanonymizer-1-0.22.20210920gitf076264.fc45
  • diffmark-0.10-40.fc45
  • digikam-9.1.0-5.fc45
  • dleyna-0.8.3-11.fc45
  • dnf5-5.4.5.0-2.fc45
  • docbook5-schemas-5.1-19.fc45
  • docbook5-style-xsl-1.79.2-28.fc45
  • docbook-dtds-1.0-93.fc45
  • docbook-simple-1.1-39.fc45
  • docbook-slides-3.4.0-40.fc45
  • docbook-style-xsl-1.79.2-29.fc45
  • dumpet-2.1-36.fc45
  • dvdauthor-0.7.2-31.fc45
  • ebook-tools-0.2.2-33.fc45
  • emacs-31.1-5.fc45
  • envytools-0.0-0.36.git20200810.fc45
  • eom-1.28.1-4.fc45
  • epiphany-51.0-2.fc45
  • erlang-cowboy-2.18.0-2.fc45
  • erofs-utils-1.9.4-2.fc45
  • evince-48.1-11.fc45
  • evolution-3.62.0-2.fc45
  • evolution-data-server-3.62.0-2.fc45
  • evolution-ews-3.62.0-2.fc45
  • evolution-rspam-0.6.0-67.fc45
  • ezstream-1.0.2-17.fc45
  • fcitx-4.2.9.9-15.fc45
  • fence-agents-4.17.0-4.fc45
  • ffmpeg-9.0.2-2.fc45
  • flam3-3.1.1-13.fc45
  • flatpak-1.19.0^really1.18.2-3.fc45
  • flatpak-builder-1.4.12-2.fc45
  • flickcurl-1.26-33.fc45
  • florence-0.6.3-31.fc45
  • folks-0.15.12-11.fc45
  • fontconfig-2.18.3-2.fc45
  • fontforge-20251009-6.fc45
  • foomatic-4.0.13-38.fc45
  • foundry-1.2.0-2.fc45
  • freewrl-6.7-5.20240420gitb3254b1.fc45
  • frogr-1.7-11.fc45
  • fuse-emulator-1.6.0-16.fc45
  • gambas3-3.22.1-2.fc45
  • GAPDoc-1.6.10-4.fc45
  • gcc-16.2.1-2.fc45.1
  • GConf2-3.2.6-51.fc45
  • gdal-3.13.3-2.fc45
  • gdcm-3.0.24-24.fc45
  • gdigi-0.4.0-20140233gitcada964d.fc45
  • geany-plugins-2.1-6.fc45
  • geary-46.0-22.fc45
  • gettext-1.0-4.fc45
  • gimp-3.2.6-2.fc45
  • gitg-50-5.fc45
  • glabels-3.4.1-35.fc45
  • glade-3.40.0-18.fc45
  • glusterfs-11.2-12.fc45
  • gnome-applets-3.58.0-4.fc45
  • gnome-app-list-2026.08-2.fc45
  • gnome-boxes-50.0-8.fc45
  • gnome-builder-50.0-5.fc45
  • gnome-calculator-51.0-2.fc45
  • gnome-chemistry-utils-0.14.17-57.fc45
  • gnome-connections-51.0-2.fc45
  • gnome-control-center-51.0-2.fc45
  • gnome-doc-utils-0.20.10-48.fc45
  • gnome-epub-thumbnailer-1.8-6.fc45
  • gnome-maps-51.1-2.fc45
  • gnome-online-accounts-3.58.1-4.fc45
  • gnome-panel-3.58.1-7.fc45
  • gnome-radio-83.0.2-2.fc45
  • gnome-vfs2-2.24.4-53.fc45
  • gnote-51~beta-2.fc45
  • gnucash-5.16-2.fc45
  • gnucobol-3.2-12.fc45
  • gnumeric-1.12.59-8.fc45
  • gnustep-base-1.31.0-11.fc45
  • goffice-0.10.57-6.fc45
  • gpac-26.07.0-5.fc45
  • gpscorrelate-2.1-8.fc45
  • gpx-viewer-0.4.0-35.fc45
  • gq-1.3.4-59.fc45
  • GraphicsMagick-1.3.45-11.fc45
  • gretl-2026b-2.fc45
  • gridsite-3.0.0-0.40.20260121git7a7b764.fc45
  • grilo-plugins-0.3.18-14.fc45
  • grisbi-2.0.5-12.fc45
  • gsequencer-8.4.2-2.fc45
  • gssntlmssp-1.3.2-2.fc45
  • gssproxy-0.9.2-13.fc45
  • gst-editing-services-1.28.7-2.fc45
  • gstreamer1-plugins-bad-free-1.28.7-2.fc45
  • gstreamer1-plugins-good-1.28.7-2.fc45
  • gtkpod-2.1.5-36.fc45
  • gtk-sharp2-2.12.45-28.fc45
  • gtksourceview2-2.11.2-48.fc45
  • gtksourceview3-3.24.11-19.fc45
  • gtksourceview4-4.8.4-13.fc45
  • gtksourceview5-5.21.0-3.fc45
  • gtranslator-50.0-7.fc45
  • guestfs-tools-1.57.3-2.fc45
  • gupnp-1.6.10-4.fc45
  • gupnp-av-0.14.5-4.fc45
  • gupnp-dlna-0.12.0-22.fc45
  • gupnp-tools-0.12.4-3.fc45
  • gvfs-1.62.0-2.fc45
  • happy-2.1.7-3.fc45
  • hidrd-0.2.0-29.20180117git7e94881a.fc45
  • hitori-44.0-10.fc45
  • hivex-1.3.24-22.fc45
  • httpd-2.4.68-7.fc45
  • hwloc-2.14.0-3.fc45
  • icecast-2.4.4-29.fc45
  • igraph-1.0.1-4.fc45
  • ImageMagick-7.1.2.31-2.fc45
  • inkscape-1.4.4-5.fc45
  • input-pad-1.1.0-7.fc45
  • intel-lpmd-0.1.0^git20260608.40d18a6-2.fc45
  • Io-language-20170906-30.fc45
  • jgmenu-4.6.0-2.fc45
  • kanatest-0.4.10-0.1.D20170810git19dd1a7d.fc45.21
  • kdelibs3-3.5.10-138.fc45
  • kdelibs-4.14.38-56.fc45
  • kf5-akonadi-server-23.08.5-15.fc45
  • kf6-kdoctools-6.30.0-2.fc45
  • kf6-kio-6.30.0-2.fc45
  • khelpcenter-26.08.1-2.fc45
  • kitinerary-26.08.1-2.fc45
  • ktouch-26.08.1-2.fc45
  • labwc-0.20.2-2.fc45
  • labwc-tweaks-0.1.0-3.fc45
  • lasem-0.6.0-6.fc45
  • lash-0.5.4-60.fc45
  • lasso-2.9.0-11.fc45
  • lastpass-cli-1.6.1-7.fc45
  • libabigail-2.10-4.fc45
  • libabw-0.1.4-2.fc45
  • libaccounts-glib-1.25-28.fc45
  • libarchive-3.8.9-2.fc45
  • libavif-1.3.0-7.fc45
  • libbluray-1.4.0-5.fc45
  • libbonobo-2.32.1-36.fc45
  • libbonoboui-2.24.5-35.fc45
  • libcmis-0.6.3-2.fc45
  • libcmpiutil-0.5.7-31.fc45
  • libcompizconfig-0.8.18-22.fc45
  • libcomps-0.1.24-5.fc45
  • libdap-3.21.1-5.fc45
  • libdatovka-0.7.4-2.fc45
  • libeasyfc-0.14.1-9.fc45
  • libe-book-0.1.4-2.fc45
  • libecoli-0.11.7-3.fc45
  • libei-1.6.0-3.fc45
  • libetonyek-0.1.13-4.fc45
  • libgda5-5.2.10-30.fc45
  • libgda-6.0.0-28.fc45
  • libgdamm-4.99.11-26.fc45
  • libgdl-3.40.0-16.fc45
  • libgedit-gtksourceview-299.7.0-3.fc45
  • libgepub-0.7.3-14.fc45
  • libglade2-2.6.4-39.fc45
  • libgnomecanvas-2.30.3-35.fc45
  • libgnt-2.14.3-4.fc45
  • libgphoto2-2.5.33-4.fc45
  • libgpod-0.8.3-59.fc45
  • libgrss-0.7.0-26.fc45
  • libgsf-1.14.59-2.fc45
  • libguestfs-1.61.3-3.fc45
  • libgweather-4.6.0-6.fc45
  • libideviceactivation-1.1.1^20250907git9ca1851-3.fc45
  • libiio-0.26-12.fc45
  • libisds-0.11.2-17.fc45
  • liblangtag-0.6.8-2.fc45
  • liblouisutdml-2.12.0-10.fc45
  • liblxi-1.22-6.fc45
  • libmateweather-1.28.0-12.fc45
  • libmodsecurity-3.0.16-3.fc45
  • libmusicbrainz5-5.1.0-32.fc45
  • libnbd-1.25.7-3.fc45
  • libodfgen-0.1.8-18.fc45
  • libosinfo-1.12.0-12.fc45
  • libpeas-2.2.1-9.fc45
  • libqalculate-5.11.0-3.fc45
  • libqb-2.0.10-3.fc45
  • libquentier-0.5.0-26.fc45
  • librasterlite2-1.1.0-0.23.beta1.fc45
  • libreoffice-26.8.1.1-0.2.fc45
  • librepo-1.21.1-2.fc45
  • libreport-2.17.15-14.fc45
  • librsvg2-2.63.2-2.fc45
  • libs3-4.1-0.28.20190408git287e4be.fc45
  • libsbml-5.20.5-18.fc45
  • libsbw-2.12.2-23.fc45
  • libsexy-0.1.11-51.fc45
  • libsolv-0.7.40-2.fc45
  • libsoup-2.74.3-12.fc45
  • libspatialite-5.1.0-14.fc45
  • libtnc-1.25-53.fc45
  • libvirt-12.6.0-2.fc45
  • libvirt-glib-5.0.0-11.fc45
  • libvirt-sandbox-0.8.0-22.fc45
  • libvisio-0.1.11-4.fc45
  • libwebcam-0.2.5-26.fc45
  • libwmf-0.2.16-2.fc45
  • libxkbcommon-1.13.1-4.fc45
  • libxklavier-5.4-32.fc45
  • libxml2_2.13-2.13.9-4.fc45
  • libxml2-2.15.4-1.fc45
  • libxml++-2.42.3-10.fc45
  • libxml++30-3.2.5-9.fc45
  • libxml++40-4.4.0-3.fc45
  • libxml++50-5.4.0-7.fc45
  • libxslt-1.1.43-10.fc45
  • libzypp-17.38.1-4.fc45
  • liferea-2.0.1-2.fc45
  • lighttpd-1.4.85-3.fc45
  • linsmith-0.99.33-16.fc45
  • lldpd-1.0.18-8.fc45
  • llvm20-20.1.8-13.fc45
  • llvm21-21.1.8-10.fc45
  • llvm22-22.1.8-2.fc45
  • llvm-23.1.2-2.fc45
  • localsearch-3.12.0-2.fc45
  • logjam-4.6.2-41.fc45
  • lordsawar-0.3.2-20.fc45
  • lxappearance-obconf-0.2.4-5.fc45
  • lxpanel-0.11.1^20260313git4dec3d0d-3.fc45
  • m17n-lib-1.8.6-5.fc45
  • Macaulay2-1.26.06-4.fc45
  • mail-notification-5.4-119.git.9ae8768.fc45
  • mallard-rng-1.1.0-18.fc45
  • mapnik-4.3.1-2.fc45
  • mapserver-8.6.5-6.fc45
  • mariadb10.11-10.11.18-4.fc45
  • mariadb11.8-11.8.8-101.fc45
  • mariadb12.3-12.3.2-101.fc45
  • mate-applets-1.28.1-6.fc45
  • mate-calc-1.28.0-11.fc45
  • mate-control-center-1.28.2-2.fc45
  • mate-media-1.28.1-9.fc45
  • mate-notification-daemon-1.28.5-5.fc45
  • mate-system-monitor-1.28.1-9.fc45
  • mediaconch-25.04-4.fc45
  • mlt-7.40.0-3.fc45
  • mobile-broadband-provider-info-20240407-7.fc45
  • mod_auth_mellon-0.19.1-7.fc45
  • mod_security-2.9.14-2.fc45
  • moreutils-0.70-3.fc45
  • mstflint-4.36.0-4.fc45
  • nagios-plugins-bonding-1.4-31.fc45
  • nagios-plugins-openmanage-3.7.12-29.fc45
  • nemiver-0.9.6-30.fc45
  • netcdf-4.10.1-4.fc45
  • netpbm-11.14-3.fc45
  • NetworkManager-openconnect-1.2.10-13.fc45
  • newsboat-2.44-3.fc45
  • nexus-4.4.3-28.fc45
  • nfs-utils-2.9.2-1.rc1.fc45.1
  • nghttp2-1.69.0-6.fc45
  • nginx-1.30.5-2.fc45
  • nip2-8.9.1-11.fc45
  • noctalia-5.1.0-2.fc45
  • nordugrid-arc-7.2.0-2.fc45
  • nx-libs-3.5.99.27-11.fc45
  • oath-toolkit-2.6.14-4.fc45
  • obconf-2.0.4-32.20150213git63ec47.fc45
  • obconf-qt-0.16.6-4.fc45
  • ocaml-gettext-0.5.0-12.fc45
  • ochusha-0.6.0.1-0.25.cvs20100817T0000.fc45
  • oddjob-0.34.7-20.fc45
  • openbabel-3.2.0-7.fc45
  • openbox-3.6.1-32.fc45
  • openconnect-9.21-3.fc45
  • opendnssec-2.1.14-6.fc45
  • openlierox-0.58-0.43.rc5.fc45
  • openscad-2021.01-33.fc45
  • openscap-1.4.4-10.fc45
  • opensips-4.0.2-4.fc45
  • openslide-4.0.1-3.fc45
  • open-vm-tools-13.1.0-9.fc45
  • openwsman-2.8.1-22.fc45
  • osc-source_validator-0.43-2.fc45
  • osinfo-db-tools-1.12.0-10.fc45
  • osmo-0.4.4-7.fc45
  • ots-0.5.0-38.fc45
  • pacemaker-3.0.3-2.fc45
  • pam_mount-2.20-8.fc45
  • pasdoc-1.0.4-3.fc45
  • PDAL-2.10.2-5.fc45
  • perl-RDF-Trine-Node-Literal-XML-0.16-23.fc45
  • perl-XML-LibXML-2.0213-4.fc45
  • perl-XML-LibXML-Devel-SetLineNumber-0.002-35.fc45
  • pgmodeler-1.2.2-4.fc45
  • phodav-3.0-15.fc45
  • php-8.5.11-2.fc45
  • php-libvirt-0.5.8-7.fc45
  • php-pecl-xmlrpc-1.0.0~rc3-20.fc45
  • pidgin-2.14.14-6.fc45
  • pidgin-chime-1.5-16.fc45
  • pidgin-sipe-1.25.0-27.fc45
  • pluma-1.28.1-4.fc45
  • podofo0.10-0.10.5-5.fc45
  • podofo-1.1.2-2.fc45
  • postgresql16-16.14-5.fc45
  • postgresql16-postgis-3.6.4-6.fc45
  • postgresql17-17.9-10.fc45
  • postgresql17-postgis-3.6.4-6.fc45
  • postgresql18-18.3-12.fc45
  • postgresql18-postgis-3.6.4-6.fc45
  • postgresql19-19beta1-6.fc45
  • pragha-1.3.3-36.fc45
  • pspp-2.1.1-7.fc45
  • pymol-3.1.0-18.fc45
  • python-firehose-0.5-40.fc45
  • python-html5-parser-0.4.12-14.fc45
  • python-igraph-1.0.0-6.fc45
  • python-lxml-6.1.1-7.fc45
  • python-ovirt-engine-sdk4-4.6.2-17.fc45
  • python-pyside6-6.11.2-2.fc45
  • qdl-2.8-3.fc45
  • qgis-4.2.2-2.fc45
  • qt5-qtwebkit-5.212.0-0.101alpha4.fc45
  • qt6-qtwebengine-6.11.2-4.fc45
  • ramond-0.5-33.fc45
  • raptor2-2.0.15-53.fc45
  • rarian-0.8.6-8.fc45
  • recoll-1.44.2-2.fc45
  • rest-0.10.2-13.fc45
  • rest0.7-0.8.1-13.fc45
  • rhythmbox-3.5.0-2.fc45
  • R-igraph-2.2.3-3.fc45
  • root-6.40.04-2.fc45
  • rpminspect-2.1-6.fc45
  • rrdtool-1.11.0-2.fc45
  • rubygem-nokogiri-1.19.4-5.fc45
  • R-xml2-1.5.2-4.fc45
  • R-XML-3.99.0.23-3.fc45
  • rygel-46.0-2.fc45
  • s3fs-fuse-1.97-4.fc45
  • sane-airscan-0.99.36-4.fc45
  • sane-backends-1.4.0-9.fc45
  • sbd-1.5.2-7.fc45
  • scribus-1.6.6-10.fc45
  • sgml-common-0.6.3-70.fc45
  • shared-mime-info-2.5.1-3.fc45
  • shigofumi-0.9-17.fc45
  • shotwell-33.0-2.fc45
  • snapper-0.13.0-5.fc45
  • snownews-1.9-15.fc45
  • sooperlooper-1.7.9-6.fc45
  • soundmodem-0.20-40.fc45
  • soundtracker-1.0.5-5.fc45
  • sparse-0.6.4-4.gce1a6720f69e.fc45.9
  • spatialite-tools-5.1.0a-8.fc45
  • sqliteodbc-0.99991-12.fc45
  • srcpd-2.1.7-8.fc45
  • sssd-2.13.1-7.fc45
  • strongswan-6.1.0-2.fc45
  • subtitleeditor-0.56.2-7.fc45
  • syncevolution-2.0.0-22.fc45
  • synfig-1.5.4-4.fc45
  • synfigstudio-1.5.4-3.fc45
  • systemtap-5.6-2.fc45
  • t4k_common-0.1.1-42.fc45
  • teg-0.13.0-6.fc45
  • telepathy-gabble-0.18.4-29.fc45
  • telepathy-salut-0.8.1-37.fc45
  • tellico-4.1.2-9.fc45
  • thermald-2.5.13-2.fc45
  • tinyows-1.2.2-10.fc45
  • tinysparql-3.12.0-2.fc45
  • tiptop-2.3.2-8.fc45
  • tomboy-1.15.9-27.fc45
  • totem-pl-parser-3.26.7-4.fc45
  • transactional-update-6.0.6-4.fc45
  • tuba-0.10.3-5.fc45
  • tuxpaint-0.9.35-6.fc45
  • tvtime-1.0.11-3.fc45
  • twinkle-1.11.0-2.fc45
  • umbrello-26.08.1-2.fc45
  • usbguard-1.1.4-7.fc45
  • uwsgi-2.0.31-17.fc45
  • vdr-epg-daemon-1.3.29-19.fc45
  • verbiste-0.1.49-8.fc45
  • vfrnav-20230429-38.fc45
  • vhostmd-1.2-3.fc45
  • vim-syntastic-3.10.0-32.fc45
  • virt-top-1.1.3-3.fc45
  • virt-v2v-2.13.6-2.fc45
  • virt-viewer-11.0-20.fc45
  • vlc-3.0.24-3.fc45
  • vtk-9.6.2-13.fc45
  • warmux-11.04.1-45.fc45
  • wayfire-config-manager-0.10.0-3.fc45
  • wayland-1.26.0-3.fc45
  • webkitgtk-2.54.0-3.fc45
  • wf-config-0.10.0-4.fc45
  • wireshark-4.6.8-3.fc45
  • wmbusmeters-3.0.0-2.fc45
  • wv-1.2.9-43.fc45
  • xar-1.8.0.417.1-21.fc45
  • xcb-proto-1.17.0-12.fc45
  • xed-3.9.0-2.fc45
  • xfce4-weather-plugin-0.12.0-2.fc45
  • xgrep-0.08-37.fc45
  • xhtml1-dtds-1.0-20020801.26.fc45
  • xiphos-4.5.0-2.fc45
  • xml2-0.5-35.fc45
  • xmlsec1-1.3.11-7.fc45
  • xmms2-0.9.7-9.fc45
  • xmoto-0.6.3-8.fc45
  • xournalpp-1.3.7-2.fc45
  • xreader-4.6.9-2.fc45
  • xrootd-6.1.1-2.fc45
  • xscreensaver-6.16-3.fc45
  • YafaRay-3.5.1-59.fc45
  • yaz-5.38.0-3.fc45
  • yelp-49.2-2.fc45
  • yelp-tools-42.1-15.fc45
  • zabbix-7.4.15-2.fc45
  • zypper-1.14.94-3.fc45
Update description:

libxml2 updated to version 2.15.4, compat libxml2_2.13 added, and rebuilds of packages linking to libxml2. Packages that FTBFS will require the compat package. It should be installed automatically by dnf if required.

Fix for CVE-2026-84975

Prevent arbitrary code execution in flymake.

Update to 51.0

New upstream development version 1.57.3

This release fixes handling SuSE metadata. We deliver it mainly to provide an up-to-date version string.

LLVM 23.1.2 update

Fix FTBFS with a modern radcli2

* Tue Sep 08 2026 Klaus Wenninger <kwenning@redhat.com> - 3.0.3-1 - Update for new upstream release tarball: Pacemaker-3.0.3, for full details, see included ChangeLog.md file or https://github.com/ClusterLabs/pacemaker/releases/tag/Pacemaker-3.0.3 - move from deprecated py3_build & py3_install to pyproject_wheel & pyproject_install - adapt python-package files to the new tooling - disable "-Waggregate-return" in cmocka files

PHP version 8.5.11 (24 Sep 2026)

BCMath:

  • Fixed out-of-bounds read in bc_is_zero_for_scale() when scale exceeds n_scale. (Ilia Alshanetsky)

Core:

  • Fixed out-of-bounds reads during automatic UTF-16/32 encoding detection. (Yudai Takada)
  • Fixed bug GH-15375 (Nested "yield from" skips items after a valid() or next() call on the inner generator). (iliaal)
  • Fixed bug GH-23232 (lone namespace separator asks the autoloader for an empty class name). (spawnia)
  • Fixed bug GH-23301 (Nested "yield from" yields a value twice when the middle generator delegates again). (Lazizbek Ergashev)

DOM:

  • Fixed NamedNodeMap::getNamedItemNS() with an empty URI not matching the null namespace in spec-following mode. (Ilia Alshanetsky)
  • Fixed stale getElementsByClassName() and other node list caches after className/classList writes and attribute removals. (Ilia Alshanetsky)
  • Fixed a use-after-free when cloning a DOMNameSpaceNode after DOMDocument::xinclude(). (iliaal)
  • Fixed a crash in DOMXPath when a php:function callback receives a nodeset and a later callback returns a node from another document. (iliaal)
  • Fixed bug GH-23331 (UAF when node_list_unlink() skips attribute children that still have a live wrapper). (iliaal)
  • Fixed a use-after-free when Dom\Element::setAttributeNS() replaces the value of an attribute whose child still has a live wrapper. (iliaal)

GD:

  • Fixed imageaffinematrixget() and imageaffinematrixconcat() reporting the wrong argument in error messages. (Weilin Du)

FPM:

  • Fixed bug GH-19320 (FPM UID and GID overflow). (Pratik Bhujel)
  • Fixed GHSA-62xp-839h-2637 (IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison). (CVE-2026-91768) (Alexandre Daubois)

Intl:

  • Fixed grapheme_strpos() and grapheme_strrpos() with an empty needle returning UTF-16 offsets instead of grapheme offsets. (Ilia Alshanetsky)
  • Fixed a memory leak when dumping IntlCalendar instances. (Ilia Alshanetsky)
  • Fixed a memory leak when iterating IntlBreakIterator::getPartsIterator() results. (iliaal)
  • Fixed a double-free when IntlGregorianCalendar construction fails after the ICU constructor adopts the TimeZone. (iliaal)
  • Fixed bug GH-23094 (NumberFormatter parsing offsets use UTF-16 positions for UTF-8 strings). (ColumbusLabs)
  • Fixed Locale::parseLocale() reading past a trailing '-' or '_'. (iliaal, Xuyang Zhang)
  • Fixed grapheme_str_split() treating UBRK_DONE as a byte index. (iliaal)
  • Fixed a leak in Locale::getKeywords() when a keyword value cannot be read. (iliaal)
  • Fixed a use-after-free when IntlRuleBasedBreakIterator is constructed from compiled rules. (iliaal)

MBString:

  • Fixed mb_ereg_replace() emitting a NUL or out-of-bounds bytes in the replacement when a \k<name> backref has no closing delimiter. (Ilia Alshanetsky)

MySQLnd:

  • Fixed GHSA-r6x9-5r99-36j7 (Various packet overreads in mysqlnd wire protocol). (CVE-2025-1218) (Jakub Zelenka, Nora Dossche)

ODBC:

  • Fixed odbc_field_len(), odbc_field_scale() and odbc_field_type() returning uninitialized memory when SQLColAttribute fails. (Ilia Alshanetsky)

Opcache:

  • Fixed opcache.protect_memory race under ZTS. (realFlowControl)
  • Fixed a tracing JIT crash when compiling a side trace for a method of a class that could not be stored in the inheritance cache. (GH-21710) (Arnaud, iliaal)
  • Fixed a crash when the huge page SHM remap discarded mappings outside the reserved address range. (Piotr Hałas)

OpenSSL:

  • Fixed GHSA-vvx9-73fr-5jjx (TLS hostname verification falls back to CN after SAN mismatch). (CVE-2026-91769) (Jakub Zelenka)
  • Fixed GHSA-xr7j-rvgx-xq5p (Heap buffer overflow in php_openssl_matches_wildcard_name() on crafted server certificate wildcard CN). (CVE-2026-91767) (Jakub Zelenka)

PDO:

  • Fixed a leak when a persistent connection failed a liveness check with no other live PDO handle. (iliaal)

PDO_PGSQL:

  • Fixed PDO::CURSOR_SCROLL statements failing under lazy fetching (PDO::ATTR_PREFETCH => 0). (KentarouTakeda)

PDO Sqlite:

  • Fixed bug GH-20214 (PDO::FETCH_DEFAULT unexpected behavior with PDOStatement::setFetchMode). (SakiTakamachi)

Phar:

  • Fixed bug GH-23418 (Use-after-free when looking up mounted directories). (Weilin Du)
  • Fixed bug GH-23477 (Memory leak on duplicate native Phar manifest entries). (Weilin Du)
  • Fixed GHSA-j3wh-g957-2m85 (Integer overflow in phar_tar_number() allowing TAR archive entry injection). (CVE-2026-6103) (Jakub Zelenka)

Readline:

  • Fixed the interactive shell not waiting for the pager process to exit. (Weilin Du)

SOAP:

  • Fixed WSDL cache corruption when a soap:header defines headerfaults. (Ilia Alshanetsky)
  • Fixed stack overflow when parsing a WSDL with self-referential schema groups or attributeGroups. (Ilia Alshanetsky)
  • Fixed GHSA-rgrp-mwpx-f6rm (Unbounded recursion in server-side cleanup_xml_node()). (CVE-2026-91765) (Alexandre Daubois)
  • Fixed GHSA-cj93-vc83-wgqv (Integer overflow to buffer overflow in SOAP HTTP parsing). (CVE-2025-14181) (Nora Dossche, Jakub Zelenka)

Standard:

  • Fixed a segfault when a stream filter callback unsets StreamBucket::$data before re-attaching the bucket. (iliaal)
  • Fixed GHSA-7875-c8px-7q5f (Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header). (CVE-2026-93682) (Ilia Alshanetsky, Jordi Kroon)
  • Fixed read buffer compaction in php_stream_filter_flush(). (crystarm)
  • Fixed bug GH-22410 (Incorrect float behavior with large numbers). (arshidkv12)
  • Fixed GH-23338 (fsockopen()/pfsockopen() ValueError reported wrong argument number for $timeout). (lacatoire)
  • Fixed bug GH-23576 (Next index for array returned from array_keys() is wrong). (Lazizbek Ergashev)
  • Fixed GHSA-88hq-2827-7pg6 (Out-of-bounds read in convert. stream filters when line-break-chars contains NUL). (CVE-2026-92842*) (geeknik)
  • Fixed GHSA-fpwc-w8rq-cr92 (Cross-origin credential leak in HTTP stream wrapper redirects). (CVE-2026-91766) (Alexandre Daubois)

SimpleXML:

  • Fixed writing to a dimension of the object returned by attributes() not creating the attribute. (Ilia Alshanetsky)
  • Fixed child elements of the element returned by SimpleXMLElement::addChild() not being accessible by property name when namespaces are involved. (Ilia Alshanetsky)

SAPI:

  • Fixed fuzzer targets failing to build in isolation. (Mrmaxmeier)
  • Fixed returns uninitialized value on LiteSpeed lsapi SAPI (Go Kudo)

Update to podofo-1.1.2.

Backport fix for CVE-2026-73515.

  • Update to 6.1.0 for CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134 and CVE-2026-78135

Upstream release, see wiki page below for detailed notes.

Update to twinkle-1.11.0.

VLC 3.0.24: https://code.videolan.org/videolan/vlc/-/tags/3.0.24

  • Switch GUI to Qt6
  • Re-enable AS-DCP plugin
  • Disable RDP plugin
  • Disable Real RTSP plugin

7.4.15

USN-8822-1: Libwebsockets vulnerabilities

6 days 9 hours ago
It was discovered that Libwebsockets incorrectly handled certain SSH protocol messages in its SSH protocol handler. A remote attacker could possibly use this issue to cause Libwebsockets to consume excessive resources, resulting in a denial of service. (CVE-2026-10650) It was discovered that Libwebsockets incorrectly handled certain malformed CBOR data. A remote attacker could possibly use this issue to cause Libwebsockets to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-78161)

docker-distribution-3.1.2-1.fc43

6 days 15 hours ago
FEDORA-2026-e60ac68542 Packages in this update:
  • docker-distribution-3.1.2-1.fc43
Update description:
  • Update to release v3.1.2
  • Resolves: rhbz#2540024
  • Resolves CVE-2026-41178: rhbz#2515091
  • Resolves CVE-2026-85747
  • Upstream fixes and enhancements

USN-8820-1: curl vulnerabilities

6 days 15 hours ago
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for LDAP authentication in certain circumstances. A machine-in-the-middle attacker could possibly use this issue to bypass peer validation. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-13608) Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server Push streams when sharing connections between handles. A remote attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-18924) Stanislav Fort discovered that curl incorrectly managed the lifetime of pooled TLS connections when using the multi interface. An attacker could possibly use this issue to cause curl to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80229) Stanislav Fort discovered that curl did not properly enforce public key pinning when certificate verification was disabled in certain circumstances. A remote attacker could possibly use this issue to bypass pinning checks and cause curl to accept connections that should have been rejected. (CVE-2026-80230) Stanislav Fort discovered that curl incorrectly handled the Secure attribute of cookies in certain circumstances. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-80255) Stanislav Fort discovered that curl did not properly enforce Public Suffix List boundaries when handling cookies in certain circumstances. A remote attacker could possibly use this issue to cause cookies to be sent to unrelated domains, resulting in sensitive information being exposed. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-82209) Ady Elouej discovered that curl did not clear proxy authentication state between requests when reusing a handle with environment-variable proxy configuration. A remote attacker could possibly use this issue to obtain sensitive credentials. This issue was previously fixed in USN-8487-1, but that fix was incomplete for Ubuntu 16.04 LTS. (CVE-2026-8927)

docker-distribution-3.1.2-1.fc44

6 days 16 hours ago
FEDORA-2026-6ac19bf6ee Packages in this update:
  • docker-distribution-3.1.2-1.fc44
Update description:
  • Update to release v3.1.2
  • Resolves: rhbz#2540024
  • Resolves CVE-2026-41178: rhbz#2515091
  • Resolves CVE-2026-85747
  • Upstream fixes and enhancements

docker-distribution-3.1.2-1.fc45

6 days 16 hours ago
FEDORA-2026-13584cfe41 Packages in this update:
  • docker-distribution-3.1.2-1.fc45
Update description:
  • Update to release v3.1.2
  • Resolves: rhbz#2540024
  • Resolves CVE-2026-41178: rhbz#2515091
  • Resolves CVE-2026-85747
  • Upstream fixes and enhancements

USN-8821-1: OpenStack Swift vulnerability

6 days 16 hours ago
It was discovered that OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could possibly use this issue to cause OpenStack Swift to use excessive resources, leading to a denial of service.

docker-distribution-3.1.2-1.fc46

6 days 16 hours ago
FEDORA-2026-a5209e3552 Packages in this update:
  • docker-distribution-3.1.2-1.fc46
Update description:

Automatic update for docker-distribution-3.1.2-1.fc46.

Changelog * Thu Sep 24 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 3.1.2-1 - Update to release v3.1.2 - Resolves: rhbz#2540024 - Resolves CVE-2026-41178: rhbz#2515091 - Resolves CVE-2026-85747 - Upstream fixes and enhancements

ntfs-3g-2022.10.3-11.el9

6 days 20 hours ago
FEDORA-EPEL-2026-c518f1078d Packages in this update:
  • ntfs-3g-2022.10.3-11.el9
Update description:

Apply backported fixes for CVE-2026-42616 CVE-2026-42617 CVE-2026-42618 CVE-2026-46569 CVE-2026-46571 CVE-2026-46570 CVE-2026-46572 CVE-2026-56135 CVE-2026-56136