FEDORA-2026-de8630b736
Packages in this update:
Update description:
* Security bugfixes
- CVE-2026-70368: Fixed an out-of-bounds memory access triggered by
logging attacker-controlled protocol messages longer than 1,024 bytes
(thanks to AISLE Research and Clemens Lang).
- CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost
destination filter using alternate local-address encodings and
interface-scoped IPv6 destinations (thanks to AISLE Research and
Clemens Lang).
- Restricted Windows GUI/service control pipes to local clients.
* Bugfixes
- Fixed concurrent DTLS handshakes from clients sharing an IP address.
- Fixed version reporting in builds from source.
- Rejected stream-oriented protocol negotiation with the UDP transport
during configuration validation.
- Fixed a TCP stream truncation (thanks to Solomon Jacobs).
- Fixed a transfer() loop (thanks to Solomon Jacobs).
- Fixed log reopening logs without a configured log file.
- Fixed some logged values (thanks to Jose Alf.).
- Fixed some error handling and cleanup issues (thanks to Jose Alf.).
- Fixed OpenSSL applink detection and MSYS2 MinGW builds.
* Features
- Added the "CRLcheckChain" service-level option for opt-in full-chain
CRL verification.
- Added the new 'transport' service-level option to choose between TLS
over TCP and DTLS over UDP.