Aggregator
USN-8644-3: Linux kernel (Azure) vulnerabilities
USN-8661-3: Linux kernel vulnerabilities
USN-8658-4: Linux kernel (Azure CVM) vulnerabilities
USN-8643-5: Linux kernel vulnerabilities
kernel-7.2.1-300.fc45
- kernel-7.2.1-300.fc45
The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
kernel-7.1.11-200.fc44
- kernel-7.1.11-200.fc44
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
kernel-7.1.11-100.fc43
- kernel-7.1.11-100.fc43
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
tkimg-2.1.1-1.fc44
- tkimg-2.1.1-1.fc44
Update to 2.1.1, update bundled libtiff to 4.7.2.
tkimg-2.1.1-1.fc45
- tkimg-2.1.1-1.fc45
Update to 2.1.1, update bundled libtiff to 4.7.2.
tkimg-2.1.1-1.fc43
- tkimg-2.1.1-1.fc43
Update to 2.1.1, update bundled libtiff to 4.7.2.
USN-8688-1: PAM vulnerability
curl-8.15.0-9.fc43
- curl-8.15.0-9.fc43
- fix proto-default skips SSH verification (CVE-2026-12064)
- fix wrong STARTTLS connection reuse (CVE-2026-8286)
- fix SASL double-free (CVE-2026-8925)
- fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
- fix exposing HTTP/3 early data (CVE-2026-9545)
- fix UAF after pause in socket callback (CVE-2026-9080)
USN-8687-1: p11-kit vulnerabilities
next-20260827: linux-next
USN-8686-1: openCryptoki vulnerabilities
composer-2.10.3-1.el10_3
- composer-2.10.3-1.el10_3
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
composer-2.10.3-1.el9
- composer-2.10.3-1.el9
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
composer-2.10.3-1.fc44
- composer-2.10.3-1.fc44
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
composer-2.10.3-1.fc45
- composer-2.10.3-1.fc45
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)