4 days 23 hours ago
FEDORA-2026-3e85d87212
Packages in this update:
Update description:
Automatic update for kronosnet-1.35-1.fc45.
Changelog
* Mon Jul 20 2026 Fabio M. Di Nitto <
fdinitto@redhat.com> - 1.35-1
- New upstream release
- CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
- CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
- CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
- tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets
- libnozzle: Introduce test macros similar to libknet
- docs: convert README to markdown format
* Thu Jul 16 2026 Fedora Release Engineering <
releng@fedoraproject.org> - 1.34-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
4 days 23 hours ago
FEDORA-2026-c87cc5b948
Packages in this update:
Update description:
Update to 0.19.1
4 days 23 hours ago
FEDORA-2026-a006788209
Packages in this update:
Update description:
Update to 0.19.1
5 days ago
It was discovered that SQLite did not properly handle NULL pointer
dereferences in the Session Extension when applying a corrupt changeset.
An attacker could possibly use this issue to cause SQLite to crash,
resulting in a denial of service. (CVE-2026-50812)
It was discovered that SQLite had a buffer overread in the Session
Extension when processing a corrupt changeset. An attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-50813)
5 days ago
It was discovered that PHP incorrectly handled certain TLS setup failures,
resulting in a NULL pointer dereference. An attacker could possibly use
this issue to cause PHP to crash, resulting in a denial of service. This
issue only affected Ubuntu 26.04 LTS. (CVE-2026-12184)
It was discovered that PHP contained a buffer allocation flaw in the
OpenSSL extension when using the AES-WRAP-PAD algorithm. An attacker could
use this issue to cause PHP to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-14355)
5 days ago
It was discovered that libXfont incorrectly handled scaling bitmap
fonts, leading to a heap buffer overflow. An attacker able to access
the X server could use this issue to cause libXfont to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2026-56001)
It was discovered that libXfont did not properly check glyph bounds
when reading PCF fonts, leading to a heap buffer overflow. An
authenticated X client could use this issue to cause libXfont to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2026-56002)
It was discovered that libXfont did not properly check the size of the
property buffer when parsing PCF fonts, leading to a heap buffer
overflow. An authenticated X client could use this issue to cause
libXfont to crash, resulting in a denial of service, or possibly
execute arbitrary code. (CVE-2026-56003)
5 days ago
It was discovered that rlottie incorrectly handled certain shift
operations. An attacker could possibly use this issue to cause rlottie
to read out of bounds, resulting in a denial of service or exposing
sensitive information. (CVE-2026-10305)
It was discovered that rlottie did not properly limit recursion when
processing certain Lottie animations. An attacker could possibly use
this issue to cause rlottie to crash, resulting in a denial of service.
(CVE-2026-47306)
It was discovered that rlottie incorrectly handled certain span
coordinates. An attacker could possibly use this issue to cause a
stack-based buffer overflow, resulting in a denial of service or
possibly the execution of arbitrary code. (CVE-2026-47318)
It was discovered that rlottie incorrectly handled certain path data.
An attacker could possibly use this issue to cause rlottie to allocate
an excessive amount of memory, resulting in a denial of service.
(CVE-2026-47319)
It was discovered that rlottie did not properly limit recursion and
could access an uninitialized pointer when processing certain Lottie
animations. An attacker could possibly use this issue to cause rlottie
to crash, resulting in a denial of service. (CVE-2026-47320)
It was discovered that rlottie incorrectly handled certain array
lengths in the bundled FreeType raster code. An attacker could possibly
use this issue to cause an out-of-bounds write, resulting in a denial
of service or possibly the execution of arbitrary code. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-8916)
5 days ago
It was discovered that nginx incorrectly handled certain map directives
using regex matching and capture variables. A remote attacker could use
this issue to cause nginx to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-42533)
It was discovered that nginx had a use-after-free vulnerability in the
ngx_http_ssi_module module when configured with Server-Side Includes,
proxy_pass, and proxy buffering disabled directives. An attacker able to
intercept traffic and control responses from an upstream server could
possibly use this issue to cause nginx to crash, resulting in a denial of
service. (CVE-2026-56434)
It was discovered that nginx incorrectly handled certain requests in the
ngx_http_slice_module module. A remote attacker could possibly use this
issue to obtain sensitive information or cause nginx to crash, resulting
in a denial of service. (CVE-2026-60005)
5 days 1 hour ago
5 days 2 hours ago
FEDORA-2026-1528cb06a7
Packages in this update:
Update description:
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
5 days 2 hours ago
FEDORA-2026-131c82812a
Packages in this update:
Update description:
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
5 days 12 hours ago
FEDORA-2026-3b93aae2d6
Packages in this update:
- nginx-1.30.4-1.fc43
- nginx-mod-brotli-1.0.0~rc-13.fc43
- nginx-mod-fancyindex-0.6.0-8.fc43
- nginx-mod-headers-more-0.40-3.fc43
- nginx-mod-modsecurity-1.0.4-16.fc43
- nginx-mod-naxsi-1.6-21.fc43
- nginx-mod-vts-0.2.4-13.fc43
Update description:
nginx-mod-vts:
nginx-mod-brotli:
nginx-mod-fancyindex:
nginx-mod-headers-more:
nginx-mod-modsecurity:
nginx-mod-naxsi:
nginx:
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
5 days 13 hours ago
FEDORA-2026-60fc198d3b
Packages in this update:
- nginx-1.30.4-1.fc44
- nginx-mod-brotli-1.0.0~rc-13.fc44
- nginx-mod-fancyindex-0.6.0-8.fc44
- nginx-mod-headers-more-0.40-3.fc44
- nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
- nginx-mod-modsecurity-1.0.4-16.fc44
- nginx-mod-naxsi-1.6-21.fc44
- nginx-mod-vts-0.2.4-13.fc44
Update description:
nginx-mod-fancyindex:
nginx-mod-modsecurity:
nginx-mod-naxsi:
nginx-mod-headers-more:
nginx-mod-brotli:
nginx-mod-js-challenge:
nginx-mod-vts:
nginx:
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
5 days 16 hours ago
5 days 19 hours ago
FEDORA-EPEL-2026-881ac51c15
Packages in this update:
Update description:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
5 days 19 hours ago
FEDORA-EPEL-2026-cb5a2d1e66
Packages in this update:
Update description:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
5 days 19 hours ago
FEDORA-2026-168280f3c4
Packages in this update:
Update description:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
5 days 19 hours ago
FEDORA-2026-a0bf40ecfe
Packages in this update:
Update description:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
6 days 5 hours ago
FEDORA-2026-fc2ded926e
Packages in this update:
- python-pillow-11.3.0-10.fc43
Update description:
Backport fixes for CVE-2026-59197 and CVE-2026-54058.
Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798
6 days 5 hours ago
FEDORA-2026-6f12b08313
Packages in this update:
- perl-Mojolicious-9.48-1.fc43
Update description:
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.