Aggregator

znc-1.10.3-1.fc44

3 hours 9 minutes ago
FEDORA-2026-855d5949d1 Packages in this update:
  • znc-1.10.3-1.fc44
Update description:

Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023

znc-1.10.3-1.fc45

3 hours 13 minutes ago
FEDORA-2026-3135766c09 Packages in this update:
  • znc-1.10.3-1.fc45
Update description:

Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023

perl-HTML-FormHandler-0.410002-1.fc44

8 hours 31 minutes ago
FEDORA-2026-21850d7df0 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc44
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc43

8 hours 31 minutes ago
FEDORA-2026-167a356523 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc43
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc45

8 hours 31 minutes ago
FEDORA-2026-406a152d49 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc45
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

patool-4.1.0-1.fc46

13 hours 26 minutes ago
FEDORA-2026-d38857d084 Packages in this update:
  • patool-4.1.0-1.fc46
Update description:

Automatic update for patool-4.1.0-1.fc46.

Changelog * Sun Sep 13 2026 Federico Pellegrin <fede@evolware.org> - 4.1.0-1 - Bump to 4.1.0 (rhbz#2421500 and rhbz#2508373)

asterisk-23.5.0-4.fc45

23 hours 39 minutes ago
FEDORA-2026-9949becb18 Packages in this update:
  • asterisk-23.5.0-4.fc45
Update description:

Disable outdated functionality which requires outdated SDL1.

Fix for CVE-2026-57160

opkssh-0.16.0-3.el10_3

1 day 9 hours ago
FEDORA-EPEL-2026-9f73888869 Packages in this update:
  • opkssh-0.16.0-3.el10_3
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.el10_2

1 day 9 hours ago
FEDORA-EPEL-2026-878ec4ee25 Packages in this update:
  • opkssh-0.16.0-3.el10_2
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc45

1 day 9 hours ago
FEDORA-2026-559bbb39f5 Packages in this update:
  • opkssh-0.16.0-3.fc45
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc44

1 day 9 hours ago
FEDORA-2026-f7b73f165d Packages in this update:
  • opkssh-0.16.0-3.fc44
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

opkssh-0.16.0-3.fc43

1 day 9 hours ago
FEDORA-2026-38b019a0f0 Packages in this update:
  • opkssh-0.16.0-3.fc43
Update description:

Update the bundled golang.org/x/crypto to v0.56.0, which fixes CVE-2026-56855 and CVE-2026-78662 (denial of service via crafted channel messages in golang.org/x/crypto/ssh's connection multiplexer).

opkssh only uses golang.org/x/crypto/ssh for key and certificate handling and never establishes SSH connections through it, so the vulnerable code is not reachable in any opkssh build (confirmed with govulncheck).

PackageKit-1.4.0-1.fc45

1 day 19 hours ago
FEDORA-2026-95d69295a4 Packages in this update:
  • PackageKit-1.4.0-1.fc45
Update description:

Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9

PackageKit-1.4.0-1.fc44

1 day 19 hours ago
FEDORA-2026-6cf9691266 Packages in this update:
  • PackageKit-1.4.0-1.fc44
Update description:

Update to 1.4.0 to fix CVE-2026-19816, GHSA-pwvr-2q5v-xvw4, GHSA-6759-8c43-4xrv, GHSA-6695-qjj5-533m, GHSA-gmhf-fxfx-m2w9