Fedora Security Advisories

php-pecl-mongodb2-2.5.2-1.fc45

53 minutes 55 seconds ago
FEDORA-2026-1576c48cce Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.fc45
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 2.5.0
  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
Version 2.4.1

php-pecl-mongodb2-2.5.2-1.el10_4

53 minutes 57 seconds ago
FEDORA-EPEL-2026-b4364ba946 Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.el10_4
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 2.5.0
  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
Version 2.4.1 Version 2.4.0

Release Highlights

  • Add support for stringOpts in ClientEncryption::encrypt() in #2033 by @GromNaN
  • Support object cloning for ReadConcern, ReadPreference, and WriteConcern in #2002 by @GromNaN

php-pecl-mongodb2-2.5.2-1.el10_3

53 minutes 59 seconds ago
FEDORA-EPEL-2026-bb3aac9602 Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.el10_3
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

perl-Protocol-HTTP2-1.14-1.fc43

1 hour 3 minutes ago
FEDORA-2026-06b545f607 Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc43
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

perl-Protocol-HTTP2-1.14-1.fc44

1 hour 3 minutes ago
FEDORA-2026-e06691a7c4 Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc44
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

perl-Protocol-HTTP2-1.14-1.fc45

1 hour 4 minutes ago
FEDORA-2026-038229756e Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc45
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

mongo-c-driver-1.30.9-1.el10_2

1 hour 22 minutes ago
FEDORA-EPEL-2026-ef4ca1433b Packages in this update:
  • mongo-c-driver-1.30.9-1.el10_2
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.el9

1 hour 42 minutes ago
FEDORA-EPEL-2026-942d98e619 Packages in this update:
  • mongo-c-driver-1.30.9-1.el9
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.fc44

1 hour 42 minutes ago
FEDORA-2026-8ed63cce6b Packages in this update:
  • mongo-c-driver-1.30.9-1.fc44
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.fc43

1 hour 42 minutes ago
FEDORA-2026-f74926c622 Packages in this update:
  • mongo-c-driver-1.30.9-1.fc43
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.el8

1 hour 42 minutes ago
FEDORA-EPEL-2026-4f2d0d5209 Packages in this update:
  • mongo-c-driver-1.30.9-1.el8
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-2.5.2-1.el10_3

2 hours 9 minutes ago
FEDORA-EPEL-2026-03de7cc5de Packages in this update:
  • mongo-c-driver-2.5.2-1.el10_3
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.2-1.el10_4

2 hours 9 minutes ago
FEDORA-EPEL-2026-9df5c5ffc2 Packages in this update:
  • mongo-c-driver-2.5.2-1.el10_4
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.2-1.fc45

2 hours 9 minutes ago
FEDORA-2026-83792d666c Packages in this update:
  • mongo-c-driver-2.5.2-1.fc45
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)

libmongocrypt-1.20.4-1.el10_3

2 hours 35 minutes ago
FEDORA-EPEL-2026-52df07119c Packages in this update:
  • libmongocrypt-1.20.4-1.el10_3
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.4-1.el10_4

2 hours 35 minutes ago
FEDORA-EPEL-2026-20b328f827 Packages in this update:
  • libmongocrypt-1.20.4-1.el10_4
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.4-1.fc45

2 hours 35 minutes ago
FEDORA-2026-0664f1b41b Packages in this update:
  • libmongocrypt-1.20.4-1.fc45
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

chromium-152.0.7977.75-1.el10_3

9 hours 21 minutes ago
FEDORA-EPEL-2026-75f4754ad0 Packages in this update:
  • chromium-152.0.7977.75-1.el10_3
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.el10_2

9 hours 21 minutes ago
FEDORA-EPEL-2026-8b6c578bd3 Packages in this update:
  • chromium-152.0.7977.75-1.el10_2
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.fc44

9 hours 21 minutes ago
FEDORA-2026-d805461e31 Packages in this update:
  • chromium-152.0.7977.75-1.fc44
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor
Checked
2 minutes 21 seconds ago