Aggregator

python3.12-3.12.13-6.fc45

2 hours 50 minutes ago
FEDORA-2026-05338c2e02 Packages in this update:
  • python3.12-3.12.13-6.fc45
Update description:

Automatic update for python3.12-3.12.13-6.fc45.

Changelog * Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6 - Security fix for CVE-2026-15308 Resolves: rhbz#2498688 * Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5 - Skip UDP Lite tests if it's not supported - Fixes FTBFS on Linux kernel 7.1 and newer * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.12.13-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

xen-4.21.2-1.fc44

3 hours 29 minutes ago
FEDORA-2026-bf1da84dfc Packages in this update:
  • xen-4.21.2-1.fc44
Update description:

update to xen 4.21.2 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508]

fuse-overlayfs-1.17-1.fc43

4 hours 10 minutes ago
FEDORA-2026-40ce06e46e Packages in this update:
  • fuse-overlayfs-1.17-1.fc43
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

fuse-overlayfs-1.17-1.fc44

4 hours 10 minutes ago
FEDORA-2026-4e0490640f Packages in this update:
  • fuse-overlayfs-1.17-1.fc44
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

USN-8625-1: OpenSSL vulnerability

5 hours 35 minutes ago
It was discovered that OpenSSL incorrectly allocated memory buffers in the SSL/TLS state machine when receiving handshake data. A remote attacker could possibly use this issue to cause OpenSSL to consume excessive memory, leading to a denial of service. This issue is known as the "HollowByte" denial of service.