Fedora Security Advisories

ceph-20.2.4-1.fc44

7 hours 1 minute ago
FEDORA-2026-7de7d03796 Packages in this update:
  • ceph-20.2.4-1.fc44
Update description: Ceph 20.2.4 GA

ceph-19.2.6-1.fc43

7 hours 39 minutes ago
FEDORA-2026-ebffec502b Packages in this update:
  • ceph-19.2.6-1.fc43
Update description: Ceph 19.2.6 GA

bluez-5.87-4.fc43

16 hours 13 minutes ago
FEDORA-2026-a1cdcc1604 Packages in this update:
  • bluez-5.87-4.fc43
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

bluez-5.87-4.fc44

16 hours 13 minutes ago
FEDORA-2026-1bbec06c4d Packages in this update:
  • bluez-5.87-4.fc44
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

openssh-10.2p1-14.fc44

17 hours 23 minutes ago
FEDORA-2026-752aa3ff05 Packages in this update:
  • openssh-10.2p1-14.fc44
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

openssh-10.0p1-12.fc43

18 hours 2 minutes ago
FEDORA-2026-535a408db5 Packages in this update:
  • openssh-10.0p1-12.fc43
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

opkssh-0.16.0-2.el10_3

21 hours 56 minutes ago
FEDORA-EPEL-2026-f45034028f Packages in this update:
  • opkssh-0.16.0-2.el10_3
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.el10_2

21 hours 58 minutes ago
FEDORA-EPEL-2026-8d8aa891da Packages in this update:
  • opkssh-0.16.0-2.el10_2
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc43

21 hours 58 minutes ago
FEDORA-2026-8d9ba295e0 Packages in this update:
  • opkssh-0.16.0-2.fc43
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc44

21 hours 59 minutes ago
FEDORA-2026-f5a5073561 Packages in this update:
  • opkssh-0.16.0-2.fc44
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

firefox-154.0-3.fc44

23 hours 44 minutes ago
FEDORA-2026-fc11919789 Packages in this update:
  • firefox-154.0-3.fc44
Update description:

Implement buffer stride support for PipeWire camera.

  • Update to latest upstream (154.0)
  • Enabled Wayland session restore on KDE.

openbao-2.6.2-1.el8

1 day 7 hours ago
FEDORA-EPEL-2026-f78a6b3cf2 Packages in this update:
  • openbao-2.6.2-1.el8
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_3

1 day 7 hours ago
FEDORA-EPEL-2026-0194a75a00 Packages in this update:
  • openbao-2.6.2-1.el10_3
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

Checked
21 minutes 57 seconds ago