Fedora Security Advisories

xen-4.20.4-1.fc43

38 minutes 32 seconds ago
FEDORA-2026-9b1af4c793 Packages in this update:
  • xen-4.20.4-1.fc43
Update description:

update to xen 4.20.4 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508] x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]

python3.12-3.12.13-6.fc45

5 hours 38 minutes ago
FEDORA-2026-05338c2e02 Packages in this update:
  • python3.12-3.12.13-6.fc45
Update description:

Automatic update for python3.12-3.12.13-6.fc45.

Changelog * Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6 - Security fix for CVE-2026-15308 Resolves: rhbz#2498688 * Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5 - Skip UDP Lite tests if it's not supported - Fixes FTBFS on Linux kernel 7.1 and newer * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.12.13-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

xen-4.21.2-1.fc44

6 hours 17 minutes ago
FEDORA-2026-bf1da84dfc Packages in this update:
  • xen-4.21.2-1.fc44
Update description:

update to xen 4.21.2 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508]

fuse-overlayfs-1.17-1.fc43

6 hours 58 minutes ago
FEDORA-2026-40ce06e46e Packages in this update:
  • fuse-overlayfs-1.17-1.fc43
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

fuse-overlayfs-1.17-1.fc44

6 hours 58 minutes ago
FEDORA-2026-4e0490640f Packages in this update:
  • fuse-overlayfs-1.17-1.fc44
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

docker-buildx-0.36.0-1.fc45

21 hours 54 minutes ago
FEDORA-2026-c37317fdde Packages in this update:
  • docker-buildx-0.36.0-1.fc45
Update description:

Automatic update for docker-buildx-0.36.0-1.fc45.

Changelog * Wed Jul 29 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 0.36.0-1 - Update to release v0.36.0 - Resolves: rhbz#2506339 - Upstream new features and fixes - Resolves CVE-2026-53492 - rhbz#2496553 - Resolves CVE-2026-47262 - rhbz#2496436

isns-utils-0.103-8.fc45

22 hours 16 minutes ago
FEDORA-2026-c1c3dda3cd Packages in this update:
  • isns-utils-0.103-8.fc45
Update description:

Automatic update for isns-utils-0.103-8.fc45.

Changelog * Wed Jul 29 2026 Chris Leech <cleech@redhat.com> - 0.103-8 - CVE-2026-55995: Denial of Service via double-free in iSNS attribute decoder (rhbz#2508456)

iscsi-initiator-utils-6.2.1.12-1.fc45

22 hours 16 minutes ago
FEDORA-2026-004b11bc1e Packages in this update:
  • iscsi-initiator-utils-6.2.1.12-1.fc45
Update description:

Automatic update for iscsi-initiator-utils-6.2.1.12-1.fc45.

Changelog * Wed Jul 29 2026 Chris Leech <cleech@redhat.com> - 6.2.1.12-1 - rebase to Open-iSCSI 2.1.12 - CVE-2026-44943: Privilege Escalation via Path Traversal (rhbz#2508458) - CVE-2026-44944: Authentication bypass in iscsiuio control socket (rhbz#2508457)
Checked
45 seconds ago