Aggregator

python-alembic-1.19.1-1.fc43 python-asyncmy-0.2.14-1.fc43 python-sqlalchemy-2.0.52-1.fc43

1 hour 3 minutes ago
FEDORA-2026-7d816931eb Packages in this update:
  • python-alembic-1.19.1-1.fc43
  • python-asyncmy-0.2.14-1.fc43
  • python-sqlalchemy-2.0.52-1.fc43
Update description:

This update contains new upstream releases for python-sqlalchemy (bugfixes), python-alembic (bugfixes) and python-asyncmy (bugfixes, security fixes and enhancements).

Please refer to upstream release notes and changelogs for details:

python-alembic-1.19.1-1.fc44 python-asyncmy-0.2.14-1.fc44 python-sqlalchemy-2.0.52-1.fc44

1 hour 3 minutes ago
FEDORA-2026-6f7b906353 Packages in this update:
  • python-alembic-1.19.1-1.fc44
  • python-asyncmy-0.2.14-1.fc44
  • python-sqlalchemy-2.0.52-1.fc44
Update description:

This update contains new upstream releases for python-sqlalchemy (bugfixes), python-alembic (bugfixes) and python-asyncmy (bugfixes, security fixes and enhancements).

Please refer to upstream release notes and changelogs for details:

USN-8636-1: Linux kernel vulnerabilities

3 hours 7 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Media drivers; - Network drivers; - Mellanox network drivers; - Texas Instruments network drivers; - NVME drivers; - File systems infrastructure; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - Memory management; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-31405, CVE-2026-31414, CVE-2026-31501, CVE-2026-31589, CVE-2026-31633, CVE-2026-31636, CVE-2026-31705, CVE-2026-43198, CVE-2026-43379, CVE-2026-43465, CVE-2026-43499, CVE-2026-46113, CVE-2026-46137, CVE-2026-46242, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53131, CVE-2026-53176, CVE-2026-53212, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8635-1: Linux kernel (Azure) vulnerabilities

3 hours 11 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) It was discovered that a logic flaw existed in the XFRM ESP-in-TCP subsystem in the Linux kernel when handling socket buffer fragments. This flaw is known as Fragnesia. A local attacker could use this to escalate privileges, or possibly escape a container. (CVE-2026-43503) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - SCSI subsystem; - Thermal drivers; - USB over IP driver; - Ext4 file system; - Network file system (NFS) server daemon; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Tracing infrastructure; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ethernet bridge; - Ceph Core library; - DCCP (Datagram Congestion Control Protocol); - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; - X.25 network layer; (CVE-2021-47202, CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455, CVE-2026-31402, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31607, CVE-2026-31637, CVE-2026-31649, CVE-2026-31657, CVE-2026-31659, CVE-2026-31668, CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037, CVE-2026-43038, CVE-2026-43198, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414, CVE-2026-43493, CVE-2026-43499, CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8634-1: Linux kernel vulnerabilities

3 hours 18 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - InfiniBand drivers; - Media drivers; - STMicroelectronics network drivers; - Network drivers; - Ext4 file system; - IPv4 networking; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31659, CVE-2026-31685, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53176, CVE-2026-53225, CVE-2026-53359)

USN-8633-1: Linux kernel vulnerabilities

3 hours 19 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - Cryptographic API; - GPU drivers; - InfiniBand drivers; - Media drivers; - NVIDIA Tegra memory controller driver; - Network drivers; - STMicroelectronics network drivers; - NVME drivers; - Ext4 file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - B.A.T.M.A.N. meshing protocol; - Ceph Core library; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657, CVE-2026-31668, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002, CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8631-1: Linux kernel vulnerabilities

3 hours 23 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A physically proximate attacker could use this issue to inject packets. (CVE-2025-27558) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - NVME drivers; - Ext4 file system; - SMB network file system; - IPv4 networking; - Network traffic control; - TCP network protocol; - Locking primitives; - IPv6 networking; - Multipath TCP; - Netfilter; - SCTP protocol; - SMC sockets; (CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

USN-8630-1: Linux kernel vulnerabilities

3 hours 30 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Mellanox network drivers; - File systems infrastructure; - IPv4 networking; - Network traffic control; - TCP network protocol; - B.A.T.M.A.N. meshing protocol; - IPv6 networking; - Multipath TCP; - Netfilter; - RxRPC session sockets; - SCTP protocol; - SMC sockets; (CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465, CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)

GraphicsMagick-1.3.45-10.fc46 ImageMagick-7.1.2.29-2.fc46 OpenImageIO-3.1.15.0-4.fc46 OpenImageIO2.5-2.5.19.1-17.fc46 darktable-5.4.1-12.fc46 digikam-9.1.0-3.fc46 ffmpeg-8.1.2-10.fc46 geeqie-2.7-6.fc46 gimp-3.2.4-4.fc46 gthumb-4.0~beta-4.fc46 imlib2-1.12…

3 hours 33 minutes ago
FEDORA-2026-b8ff7153f1 Packages in this update:
  • darktable-5.4.1-12.fc46
  • digikam-9.1.0-3.fc46
  • ffmpeg-8.1.2-10.fc46
  • geeqie-2.7-6.fc46
  • gimp-3.2.4-4.fc46
  • GraphicsMagick-1.3.45-10.fc46
  • gthumb-4.0~beta-4.fc46
  • ImageMagick-7.1.2.29-2.fc46
  • imlib2-1.12.5-4.fc46
  • imv-5.0.1-4.fc46
  • kf5-kimageformats-5.116.0-12.fc46
  • kf6-kimageformats-6.29.0-2.fc46
  • libheif-1.23.1-9.fc46
  • mingw-openexr-3.4.13-3.fc46
  • mpv-0.41.0-8.fc46
  • openapv-0.3.0.0-1.fc46
  • OpenImageIO2.5-2.5.19.1-17.fc46
  • OpenImageIO-3.1.15.0-4.fc46
  • openjph-0.31.0-1.fc46
  • perl-Prima-1.77-6.fc46
  • python-imagecodecs-2025.8.2-7.fc46
  • siril-1.4.4-3.fc46
  • swayimg-5.5-2.fc46
  • vapoursynth-79-3.fc46
  • vips-8.18.3-4.fc46
  • xevd-0.7.0-2.fc46
  • xeve-0.7.0-2.fc46
Update description:

Updated xeve/xevd, updated openapv and updated vapoursynth.

GraphicsMagick-1.3.45-10.fc45 ImageMagick-7.1.2.29-2.fc45 OpenImageIO-3.1.15.0-4.fc45 OpenImageIO2.5-2.5.19.1-17.fc45 darktable-5.4.1-12.fc45 digikam-9.1.0-3.fc45 ffmpeg-8.1.2-10.fc45 geeqie-2.7-6.fc45 gimp-3.2.4-4.fc45 gthumb-4.0~beta-4.fc45 imlib2-1.12…

3 hours 35 minutes ago
FEDORA-2026-823e06dfcf Packages in this update:
  • darktable-5.4.1-12.fc45
  • digikam-9.1.0-3.fc45
  • ffmpeg-8.1.2-10.fc45
  • geeqie-2.7-6.fc45
  • gimp-3.2.4-4.fc45
  • GraphicsMagick-1.3.45-10.fc45
  • gthumb-4.0~beta-4.fc45
  • ImageMagick-7.1.2.29-2.fc45
  • imlib2-1.12.5-4.fc45
  • imv-5.0.1-4.fc45
  • kf5-kimageformats-5.116.0-12.fc45
  • kf6-kimageformats-6.29.0-2.fc45
  • libheif-1.23.1-9.fc45
  • mingw-openexr-3.4.13-3.fc45
  • mpv-0.41.0-8.fc45
  • openapv-0.3.0.0-1.fc45
  • OpenImageIO2.5-2.5.19.1-17.fc45
  • OpenImageIO-3.1.15.0-4.fc45
  • openjph-0.31.0-1.fc45
  • perl-Prima-1.77-6.fc45
  • python-imagecodecs-2025.8.2-7.fc45
  • siril-1.4.4-3.fc45
  • swayimg-5.5-2.fc45
  • vapoursynth-79-3.fc45
  • vips-8.18.3-4.fc45
  • xevd-0.7.0-2.fc45
  • xeve-0.7.0-2.fc45
Update description:

Updated xeve/xevd, updated openapv and updated vapoursynth.

USN-8629-1: Linux kernel vulnerabilities

3 hours 37 minutes ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - x86 architecture; - InfiniBand drivers; - Network drivers; - Network traffic control; - IPv4 networking; - IPv6 networking; - Netfilter; - RxRPC session sockets; - SCTP protocol; (CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186, CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53247, CVE-2026-53260, CVE-2026-53359)

python-watchfiles-1.2.0-3.el10_3

3 hours 53 minutes ago
FEDORA-EPEL-2026-24fd793296 Packages in this update:
  • python-watchfiles-1.2.0-3.el10_3
Update description:

Update from 1.0.4 to 1.2.0. This also updates the PyO3 build requirement to 0.29 to address two RUSTSEC advisories.

Relevant watchfiles release notes:

PyO3 advisories:

USN-8628-1: libgit2 vulnerabilities

4 hours ago
It was discovered that libgit2 incorrectly handled the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10128) It was discovered that libgit2 incorrectly handled empty packet lines in the Git Smart Protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10129) It was discovered that libgit2 incorrectly handled error reporting in the HTTP transport. A remote attacker could possibly use this issue to spoof servers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130) It was discovered that libgit2 incorrectly handled certain crafted "ng" packets. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-15501) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-8098) Krishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly handled certain repository index files. A local attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled submodule paths. A remote attacker could possibly use this issue to write files outside the working tree. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53584) Michał Majchrowicz and Marcin Wyczechowski discovered that libgit2 incorrectly handled delta object result-size headers. A remote attacker could possibly use this issue to cause libgit2 to consume excessive memory, leading to a denial of service. (CVE-2026-53585) Thai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects. A remote attacker could possibly use this issue to leak credentials to an offsite redirect target. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-53586) It was discovered that libgit2 incorrectly handled certain capability buffers in the smart protocol. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-53587)