rust-h2-0.4.17-1.fc44
- rust-h2-0.4.17-1.fc44
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
First monthly cadence release candidate
An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.
This update fixes this issue (CVE-2026-75032)
An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.
This update fixes this issue (CVE-2026-75032)
Update to 3.1.3
Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded
Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded
Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).
opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.
Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).
opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.
Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).
opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.
Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).
opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.
Implement buffer stride support for PipeWire camera.
Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.
Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.