1 hour 14 minutes ago
FEDORA-2026-f3ca65c0c9
Packages in this update:
Update description:
Fix for several CVEs
11 hours 13 minutes ago
11 hours 13 minutes ago
17 hours 25 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
17 hours 28 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- GPU drivers;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- STMicroelectronics network drivers;
- NVME drivers;
- Ext4 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2021-47354, CVE-2021-47378, CVE-2024-38612, CVE-2026-31405,
CVE-2026-31414, CVE-2026-31448, CVE-2026-31649, CVE-2026-31657,
CVE-2026-31668, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499,
CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52982, CVE-2026-52986, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53225, CVE-2026-53228, CVE-2026-53359)
17 hours 53 minutes ago
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- InfiniBand drivers;
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)
18 hours 1 minute ago
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- File systems infrastructure;
- Ext4 file system;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47117, CVE-2021-47202, CVE-2023-52646, CVE-2024-56643,
CVE-2026-23455, CVE-2026-31402, CVE-2026-31607, CVE-2026-31637,
CVE-2026-31659, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46119, CVE-2026-46243)
18 hours 2 minutes ago
It was discovered that the Linux kernel did not properly handle shared page
fragments during socket buffer operations, collectively known as Dirty
Frag. A logic flaw existed in the XFRM ESP-in-TCP subsystem and in the
RxRPC networking subsystem when processing paged fragments. A local
attacker could use this to escalate privileges, or possibly escape a
container. (CVE-2026-43284)
It was discovered that a logic flaw existed in the XFRM ESP-in-TCP
subsystem in the Linux kernel when handling socket buffer fragments. This
flaw is known as Fragnesia. A local attacker could use this to escalate
privileges, or possibly escape a container. (CVE-2026-43503)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- InfiniBand drivers;
- SCSI subsystem;
- Thermal drivers;
- USB over IP driver;
- Network file system (NFS) server daemon;
- SMB network file system;
- Tracing infrastructure;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Ceph Core library;
- DCCP (Datagram Congestion Control Protocol);
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- X.25 network layer;
(CVE-2021-47202, CVE-2024-56643, CVE-2026-23272, CVE-2026-23455,
CVE-2026-31402, CVE-2026-31607, CVE-2026-31637, CVE-2026-31659,
CVE-2026-31682, CVE-2026-31685, CVE-2026-43011, CVE-2026-43037,
CVE-2026-43038, CVE-2026-43383, CVE-2026-43407, CVE-2026-43414,
CVE-2026-45988, CVE-2026-46043, CVE-2026-46119, CVE-2026-46243)
18 hours 33 minutes ago
FEDORA-EPEL-2026-df0e6e2699
Packages in this update:
Update description:
Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)
18 hours 33 minutes ago
FEDORA-EPEL-2026-0af8f5893c
Packages in this update:
Update description:
Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)
18 hours 33 minutes ago
FEDORA-2026-70dd9b4fc0
Packages in this update:
Update description:
Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)
18 hours 33 minutes ago
FEDORA-2026-14ebd38fea
Packages in this update:
Update description:
Update to 0.40.9 - fixes CVE-2026-41178 (DoS via oversized OpenTelemetry baggage headers)
19 hours 42 minutes ago
Ameer Assadi discovered that Axios did not properly handle certain
hostnames when applying NO_PROXY rules. An attacker could possibly use
this issue to bypass proxy restrictions and access internal services,
resulting in server-side request forgery. (CVE-2025-62718)
It was discovered that Axios did not properly protect certain HTTP
header values from prototype pollution. An attacker could possibly use
this issue to inject malicious values into outbound requests, resulting
in HTTP header injection. (CVE-2026-40175)
Sachin Patil and Amol Patil discovered that Axios did not properly apply
NO_PROXY rules to certain loopback addresses. An attacker could possibly
use this issue to bypass proxy restrictions and access internal
services, resulting in server-side request forgery. (CVE-2026-42043)
Yu Bao discovered that Axios did not properly protect JSON response
processing from prototype pollution. An attacker could possibly use this
issue to modify values in application responses, resulting in
authorization bypass or privilege escalation. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-42044)
It was discovered that Axios did not properly protect certain request
configuration options from prototype pollution. An attacker could
possibly use this issue to modify outbound HTTP requests, resulting in
security restrictions being bypassed. This issue only affected Ubuntu
24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-42264)
20 hours 44 minutes ago
FEDORA-2026-c8cfd2f2f9
Packages in this update:
Update description:
Patches for several CVEs
20 hours 51 minutes ago
FEDORA-2026-7cfd54a4c1
Packages in this update:
Update description:
Update to .NET SDK 9.0.120 and Runtime 9.0.19
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
21 hours ago
FEDORA-2026-9c8770dffb
Packages in this update:
Update description:
Update to .NET SDK 9.0.120 and Runtime 9.0.19
Fixes: CVE-2026-62871,CVE-2026-62886,CVE-2026-62897,CVE-2026-62898,CVE-2026-62899,CVE-2026-62900,CVE-2026-62901,CVE-2026-62902,CVE-2026-62909,CVE-2026-70354
Release Notes:
21 hours 13 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Thunderbolt and USB4 drivers;
- Network traffic control;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
(CVE-2026-46331, CVE-2026-52924, CVE-2026-53131, CVE-2026-53146,
CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150,
CVE-2026-53151, CVE-2026-53175, CVE-2026-53176, CVE-2026-53186,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246,
CVE-2026-53247, CVE-2026-53260, CVE-2026-53359)
21 hours 18 minutes ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
21 hours 35 minutes ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- Mellanox network drivers;
- File systems infrastructure;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- B.A.T.M.A.N. meshing protocol;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- RxRPC session sockets;
- SCTP protocol;
- SMC sockets;
(CVE-2026-43083, CVE-2026-43197, CVE-2026-43198, CVE-2026-43465,
CVE-2026-46242, CVE-2026-46325, CVE-2026-46331, CVE-2026-52914,
CVE-2026-52924, CVE-2026-52931, CVE-2026-53151, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53225, CVE-2026-53228,
CVE-2026-53359)
23 hours 28 minutes ago
Version:next-20260813 (linux-next)
Released:2026-08-13