Aggregator
flocq-4.2.2-3.fc44 gappalib-coq-1.11.0-1.fc44 rocq-9.3.0-1.fc44 rocq-stdlib-9.2.0-1.fc44 why3-1.8.2-11.fc44 zenon-0.8.5-41.fc44
- flocq-4.2.2-3.fc44
- gappalib-coq-1.11.0-1.fc44
- rocq-9.3.0-1.fc44
- rocq-stdlib-9.2.0-1.fc44
- why3-1.8.2-11.fc44
- zenon-0.8.5-41.fc44
See https://rocq-prover.org/doc/v9.3/refman/changes.html#version-9-3 for changes in rocq 9.3.0.
See https://rocq-prover.org/doc/v9.2/refman-stdlib/changes.html for changes in rocq-stdlib 9.2.0.
See https://gitlab.inria.fr/gappa/coq/-/blob/master/NEWS.md for changes in gappalib-coq 1.11.0.
The other builds are rebuilds due to the above changes.
python-jupytext-1.19.6-1.fc43
- python-jupytext-1.19.6-1.fc43
See https://github.com/jupytext/jupytext/blob/main/CHANGELOG.md for changes in versions 1.19.5 and 1.19.6. For this update, a patch has been applied that reverses the jupyterlab → jupyter-builder change for Fedora releases ≤ 45, since jupyter-builder is only available in F46 and later. Many CVEs have been fixed in this release.
USN-8870-1: OpenStack Aodh and Watcher vulnerability
USN-8871-1: Linux kernel (Raspberry Pi) vulnerabilities
USN-8851-3: Linux kernel (Azure) vulnerabilities
aegisub-3.5.0-1.fc43
- aegisub-3.5.0-1.fc43
Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23
aegisub-3.5.0-2.fc44
- aegisub-3.5.0-2.fc44
Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23
aegisub-3.5.0-1.fc45
- aegisub-3.5.0-1.fc45
Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23
zabbix7.0-7.0.31-1.el10_3
- zabbix7.0-7.0.31-1.el10_3
Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)
zabbix7.0-7.0.31-1.el10_4
- zabbix7.0-7.0.31-1.el10_4
Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)
zabbix7.0-7.0.31-1.el9
- zabbix7.0-7.0.31-1.el9
Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)
zabbix7.0-7.0.31-1.el8
- zabbix7.0-7.0.31-1.el8
Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)
Update to 7.0.28
zabbix7.0-7.0.31-1.el10_2
- zabbix7.0-7.0.31-1.el10_2
Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)
zabbix-6.0.48-1.el9
- zabbix-6.0.48-1.el9
Update to 6.0.48 (CVE-2026-59782, CVE-2026-59785, CVE-2026-59787)
zabbix6.0-6.0.48-1.el8
- zabbix6.0-6.0.48-1.el8
Update to 6.0.48 (CVE-2026-59782, CVE-2026-59785, CVE-2026-59787)
curl-8.18.0-11.fc44
- curl-8.18.0-11.fc44
- Fix HTTP/2 server push UAF (CVE-2026-18924)
USN-8868-1: LibreOffice vulnerabilities
next-20261005: linux-next
arm-none-eabi-binutils-cs-2.45-5.fc45
- arm-none-eabi-binutils-cs-2.45-5.fc45
- fix CVE-2026-19582: a potential buffer overflow in rsrc_resource_name (rhbz#2519352)