Aggregator

USN-8708-1: sudo-rs vulnerability

1 week ago
It was discovered that sudo-rs incorrectly handled time-of-check vs time- of-use conditions in sudoedit. A local attacker with permission to edit specific files using sudoedit could use this issue to place files in arbitrary directories, and possibly escalate their privileges. This issue only affected systems configured to grant fine-grained sudoedit file editing permissions, which is not the default configuration.

perl-Net-DNS-1.56-1.el10_3

1 week ago
FEDORA-EPEL-2026-9d8de529df Packages in this update:
  • perl-Net-DNS-1.56-1.el10_3
Update description:

Security fixes (main reason to update) - Remote code injection via EDNS EXTENDED ERROR (rt.cpan #179945) - 1.56 - DoS via long DNS compression chains (rt.cpan #179946) - 1.56 - UNIX.pm no longer relies on shell for uname (rt.cpan #176900) -1.55

Notable bug fixes across the range - TCP AXFR corruption from 1-byte 0x30 treated as EOF (#177003) - IPv4 loopback disabled in IPv6-only config — Fedora41 (#158714) - Multiple "uninitialized value" fixes in UDP/TCP paths (#158706, #157700) - Nameserver: SOA missing in NODATA response (#157669)

perl-Net-DNS-1.56-1.el10_4

1 week ago
FEDORA-EPEL-2026-8249fe4a72 Packages in this update:
  • perl-Net-DNS-1.56-1.el10_4
Update description:

1.56 bump

Security fixes (main reason to update) - Remote code injection via EDNS EXTENDED ERROR (rt.cpan #179945) — 1.56 - DoS via long DNS compression chains (rt.cpan #179946) — 1.56 - UNIX.pm no longer relies on shell for uname (rt.cpan #176900) — 1.55

Notable bug fixes across the range

  • TCP AXFR corruption from 1-byte 0x30 treated as EOF (#177003)
  • IPv4 loopback disabled in IPv6-only config — Fedora41 (#158714)
  • Multiple "uninitialized value" fixes in UDP/TCP paths (#158706, #157700)
  • Nameserver: SOA missing in NODATA response (#157669)
  • Resolver base selection bug on non-Unix platforms (#168433)

perl-Net-DNS-1.56-1.fc43

1 week ago
FEDORA-2026-1237afef8a Packages in this update:
  • perl-Net-DNS-1.56-1.fc43
Update description:

Update to Net-DNS 1.56 (from 1.53).

Security fixes: - CVE-worthy: Remote code injection via EDNS EXTENDED ERROR (rt.cpan #179945) - Denial of Service via long DNS compression chains (rt.cpan #179946) - Resolver/UNIX.pm no longer relies on shell for uname (rt.cpan #176900)

Bug fixes: - Fix TCP read loop treating 1-byte recv() of "0" (0x30) as EOF, which corrupted AXFRs (rt.cpan #177003) - Fix unhelpful TAINT error (rt.cpan #178183) - Fix unreachable-code warning under Apache/mod_perl (rt.cpan #179692/#176900) - Documentation fix for Net::DNS::RR::RRSIG::verify() (rt.cpan #180088).

Other: - Resync with IANA DNS parameters and DNSSEC algorithm registries - New DNSKEY adt() accessor; DELEG parser backported to SVCB

perl-Net-DNS-1.56-1.fc44

1 week ago
FEDORA-2026-a0607111e6 Packages in this update:
  • perl-Net-DNS-1.56-1.fc44
Update description:

Update to Net-DNS 1.56 (from 1.53).

Security fixes: - CVE-worthy: Remote code injection via EDNS EXTENDED ERROR (rt.cpan #179945) - Denial of Service via long DNS compression chains (rt.cpan #179946) - Resolver/UNIX.pm no longer relies on shell for uname (rt.cpan #176900)

Bug fixes: - Fix TCP read loop treating 1-byte recv() of "0" (0x30) as EOF, which corrupted AXFRs (rt.cpan #177003) - Fix unhelpful TAINT error (rt.cpan #178183) - Fix unreachable-code warning under Apache/mod_perl (rt.cpan #179692/#176900) - Documentation fix for Net::DNS::RR::RRSIG::verify() (rt.cpan #180088).

Other: - Resync with IANA DNS parameters and DNSSEC algorithm registries - New DNSKEY adt() accessor; DELEG parser backported to SVCB

mongo-c-driver-2.5.1-1.fc45

1 week ago
FEDORA-2026-fec1bd0e65 Packages in this update:
  • mongo-c-driver-2.5.1-1.fc45
Update description: libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)

mongo-c-driver-2.5.1-1.el10_3

1 week ago
FEDORA-EPEL-2026-4c8991a29d Packages in this update:
  • mongo-c-driver-2.5.1-1.el10_3
Update description: libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libbson 2.5.0

No changes since 2.4.0. Version incremented to match the libmongoc version.

libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.1-1.el10_4

1 week ago
FEDORA-EPEL-2026-92974d6ab3 Packages in this update:
  • mongo-c-driver-2.5.1-1.el10_4
Update description: libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libbson 2.5.0

No changes since 2.4.0. Version incremented to match the libmongoc version.

libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

libmongocrypt-1.20.3-1.el10_3

1 week ago
FEDORA-EPEL-2026-2210b463dc Packages in this update:
  • libmongocrypt-1.20.3-1.el10_3
Update description: Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.3-1.fc45

1 week ago
FEDORA-2026-276ef95c83 Packages in this update:
  • libmongocrypt-1.20.3-1.fc45
Update description: Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.3-1.el10_4

1 week ago
FEDORA-EPEL-2026-eac81454b1 Packages in this update:
  • libmongocrypt-1.20.3-1.el10_4
Update description: Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).