Fedora Security Advisories

goaccess-1.11-1.el10_2

2 hours 36 minutes ago
FEDORA-EPEL-2026-397d87e12c Packages in this update:
  • goaccess-1.11-1.el10_2
Update description:

Update to goaccess 1.11.

Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first

Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.

goaccess-1.11-1.el10_3

3 hours ago
FEDORA-EPEL-2026-93554d5ab9 Packages in this update:
  • goaccess-1.11-1.el10_3
Update description:

Update to goaccess 1.11.

Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first

Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.

goaccess-1.11-1.el9

3 hours 18 minutes ago
FEDORA-EPEL-2026-dd8a644630 Packages in this update:
  • goaccess-1.11-1.el9
Update description:

Update to goaccess 1.11.

Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first

Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.

goaccess-1.11-1.fc43

3 hours 54 minutes ago
FEDORA-2026-a488a993d1 Packages in this update:
  • goaccess-1.11-1.fc43
Update description:

Update to goaccess 1.11.

Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first

Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.

goaccess-1.11-1.fc44

4 hours 9 minutes ago
FEDORA-2026-b1c2d1af74 Packages in this update:
  • goaccess-1.11-1.fc44
Update description:

Update to goaccess 1.11.

Notable fixes: - Fixed a heap buffer overflow when parsing malformed Opera user agents - Fixed an infinite loop while writing log parsing errors from multiple input files - Fixed unique visitor undercounting caused by key collisions - Fixed city lookups ignoring the City database when Country was listed first

Also includes: automatic crash-safe migration to storage format v3, ~20% lower storage memory usage and ~35% faster parsing, fullscreen geolocation map controls in the HTML report, and Traditional Chinese translation.

nsd-4.15.0-1.fc43

12 hours 46 minutes ago
FEDORA-2026-0b77a23312 Packages in this update:
  • nsd-4.15.0-1.fc43
Update description:

FEATURES:

Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from metric name to label

BUG FIXES:

Fix #478: Feature request: reduce syslog noise from frequent read-only control commands (e.g. stats_noreset). It logs the verbosity command always, and others at 2 and higher. Fix XDP cleanup code being executed even if xdp is not configured Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources Merge #484 from orlitzky: OpenRC: fix network deps and support both supervisors Fix PROXYv2 header read and consume, it checks the header size. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix notify relay ipc to check for large size. This stops desync of the internal notify pipe. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix print of malformed HIP records. Thanks to Qifan Zhang, Palo Alto Networks, for the report, and Haruki Oyama (Waseda University) for also reporting this issue. Fix to not fail on NSEC3 records with a bad owner name. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix print of NXT RR without bitmap Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix overflow for NSEC3 zones with 255-octet name Thanks to Haruki Oyama (Waseda University) for the report, and Qifan Zhang, Palo Alto Networks, for also reporting this issue. Fix to update github ci actions/checkout to v7. Fix notify and zone transfer processing for malformed SOA records, with a short rdata content. It stops an assertion failure. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. Fix that wrong buffer position in IXFR for the first SOA causes the storage to retrieve wrong information. Later data would overwrite it so it did not cause observable trouble. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. More robust removing of RRs from an IXFR processing. Thanks zhangph for reporting this issue Fix unit test for stopmany for process role logs. Fix nsd-control assoc_tsig, if that interrupts a zone transfer in progress, to not crash. It restarts the transfer from the primary. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix nsd-control del_tsig, if that interrupts a zone transfer in progress, to not crash. It does not delete the key, if in use. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog producer zone with long name, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog consumer zone with long name for member unique label that is long, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that non-IN-class records cause a zone transfer to be rejected. Also such records are not added from a transfer. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to disallow a SOA record in the middle of an AXFR. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY. This stops an assertion failure. Also fix soa and ns rrset change in IXFR when packed rrsets are disabled. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to handle NSEC3 zones without space for hashes. Zones with a apex domain name length >= 223 bytes, that have a NSEC3PARAM must not be prehashed, since the hashed owner name would not fit. Thanks Qifan Zhang, Palo Alto Networks, for the report Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix for xfrd crash with too short response to a UDP SOA query Only for release builds and only when configured for XFR over UDP Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that out-of-zone records are skipped from zone transfers. Otherwise such records could stick around after zone deletion and cause failures for DS queries. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

nsd-4.15.0-1.el10_3

12 hours 46 minutes ago
FEDORA-EPEL-2026-484870f7f9 Packages in this update:
  • nsd-4.15.0-1.el10_3
Update description:

FEATURES:

Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from metric name to label

BUG FIXES:

Fix #478: Feature request: reduce syslog noise from frequent read-only control commands (e.g. stats_noreset). It logs the verbosity command always, and others at 2 and higher. Fix XDP cleanup code being executed even if xdp is not configured Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources Merge #484 from orlitzky: OpenRC: fix network deps and support both supervisors Fix PROXYv2 header read and consume, it checks the header size. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix notify relay ipc to check for large size. This stops desync of the internal notify pipe. Thanks to Qifan Zhang, Palo Alto Networks for the report. Fix print of malformed HIP records. Thanks to Qifan Zhang, Palo Alto Networks, for the report, and Haruki Oyama (Waseda University) for also reporting this issue. Fix to not fail on NSEC3 records with a bad owner name. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix print of NXT RR without bitmap Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix overflow for NSEC3 zones with 255-octet name Thanks to Haruki Oyama (Waseda University) for the report, and Qifan Zhang, Palo Alto Networks, for also reporting this issue. Fix to update github ci actions/checkout to v7. Fix notify and zone transfer processing for malformed SOA records, with a short rdata content. It stops an assertion failure. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. Fix that wrong buffer position in IXFR for the first SOA causes the storage to retrieve wrong information. Later data would overwrite it so it did not cause observable trouble. Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report. More robust removing of RRs from an IXFR processing. Thanks zhangph for reporting this issue Fix unit test for stopmany for process role logs. Fix nsd-control assoc_tsig, if that interrupts a zone transfer in progress, to not crash. It restarts the transfer from the primary. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix nsd-control del_tsig, if that interrupts a zone transfer in progress, to not crash. It does not delete the key, if in use. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog producer zone with long name, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix catalog consumer zone with long name for member unique label that is long, so that it does not crash on that. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that non-IN-class records cause a zone transfer to be rejected. Also such records are not added from a transfer. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to disallow a SOA record in the middle of an AXFR. This stops an assertion failure. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY. This stops an assertion failure. Also fix soa and ns rrset change in IXFR when packed rrsets are disabled. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix to handle NSEC3 zones without space for hashes. Zones with a apex domain name length >= 223 bytes, that have a NSEC3PARAM must not be prehashed, since the hashed owner name would not fit. Thanks Qifan Zhang, Palo Alto Networks, for the report Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing. Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix for xfrd crash with too short response to a UDP SOA query Only for release builds and only when configured for XFR over UDP Thanks to Qifan Zhang, Palo Alto Networks, for the report. Fix that out-of-zone records are skipped from zone transfers. Otherwise such records could stick around after zone deletion and cause failures for DS queries. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

pack-0.40.8-1.el8

1 day 3 hours ago
FEDORA-EPEL-2026-8513c30973 Packages in this update:
  • pack-0.40.8-1.el8
Update description:

Security update to pack 0.40.8

Fixes CVE-2025-47913: golang.org/x/crypto/ssh/agent - SSH client panic Fixes CVE-2025-47914: golang.org/x/crypto/ssh/agent - SSH Agent server DoS Fixes CVE-2025-65637: logrus - DoS via large single-line payload Fixes CVE-2026-27145: crypto/x509 - DoS via excessive DNS SAN processing Fixes CVE-2026-33747: BuildKit - Arbitrary file write Fixes CVE-2026-33748: BuildKit - Unauthorized file access Fixes CVE-2026-33762: go-git - DoS via crafted Git index Fixes CVE-2026-34165: go-git - DoS via crafted .idx file Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution Fixes CVE-2026-39829: golang.org/x/crypto/ssh - DoS via crafted public key Fixes CVE-2026-39830: golang.org/x/crypto/ssh - Resource leak DoS Fixes CVE-2026-39832: golang.org/x/crypto/ssh/agent - Key restrictions bypass Fixes CVE-2026-39833: golang.org/x/crypto/ssh/agent - Key confirmation bypass Fixes CVE-2026-39835: golang.org/x/crypto/ssh - Certificate DoS Fixes CVE-2026-44740: go-billy - DoS via symlink cycle Fixes GO-2026-4970: Root escape via symlink plus trailing slash Fixes GO-2026-5856: Encrypted Client Hello privacy leak

audit-4.2-2.fc45

1 day 4 hours ago
FEDORA-2026-ec653eca58 Packages in this update:
  • audit-4.2-2.fc45
Update description:

Automatic update for audit-4.2-2.fc45.

Changelog * Fri Jul 24 2026 Steve Grubb <sgrubb@redhat.com> 4.2-2 - Truncate comm instead of rejecting invalid length * Thu Jul 23 2026 Steve Grubb <sgrubb@redhat.com> 4.2-1 - New upstream release * Wed Jul 22 2026 Python Maint <python-maint@redhat.com> - 4.1.4-4 - Rebuilt for Python 3.15.0b4 ABI change

Automatic update for audit-4.2-1.fc45.

Checked
6 minutes 19 seconds ago