Fedora Security Advisories

chromium-150.0.7871.128-1.el10_3

1 hour 44 minutes ago
FEDORA-EPEL-2026-80f5d69973 Packages in this update:
  • chromium-150.0.7871.128-1.el10_3
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.fc44

1 hour 44 minutes ago
FEDORA-2026-310f620a68 Packages in this update:
  • chromium-150.0.7871.128-1.fc44
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.el9

1 hour 44 minutes ago
FEDORA-EPEL-2026-a72ac31b48 Packages in this update:
  • chromium-150.0.7871.128-1.el9
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.el10_2

1 hour 44 minutes ago
FEDORA-EPEL-2026-81064cea8f Packages in this update:
  • chromium-150.0.7871.128-1.el10_2
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

chromium-150.0.7871.128-1.fc43

1 hour 44 minutes ago
FEDORA-2026-ac712bf651 Packages in this update:
  • chromium-150.0.7871.128-1.fc43
Update description:

Update to 150.0.7871.128

* CVE-2026-15899: Use after free in CameraCapture * CVE-2026-15900: Use after free in GPU * CVE-2026-15901: Use after free in Network * CVE-2026-15902: Use after free in Cast * CVE-2026-15903: Out of bounds read and write in V8 * CVE-2026-15904: Use after free in Ozone * CVE-2026-15905: Use after free in Aura

wordpress-6.9.5-1.el9

3 hours 59 minutes ago
FEDORA-EPEL-2026-b847a0b309 Packages in this update:
  • wordpress-6.9.5-1.el9
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.el10_2

3 hours 59 minutes ago
FEDORA-EPEL-2026-224c06e2c7 Packages in this update:
  • wordpress-6.9.5-1.el10_2
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.fc43

3 hours 59 minutes ago
FEDORA-2026-46346e9637 Packages in this update:
  • wordpress-6.9.5-1.fc43
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-6.9.5-1.fc44

3 hours 59 minutes ago
FEDORA-2026-2b8250197a Packages in this update:
  • wordpress-6.9.5-1.fc44
Update description: Version 6.9.5

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

wordpress-7.0.2-1.el10_3

4 hours 27 minutes ago
FEDORA-EPEL-2026-604236f7b8 Packages in this update:
  • wordpress-7.0.2-1.el10_3
Update description: Version 7.0.2

Security updates

  • A facilitated SQL injection issue
  • A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

kernel-7.1.4-101.fc43

8 hours 47 minutes ago
FEDORA-2026-336f10ee31 Packages in this update:
  • kernel-7.1.4-101.fc43
Update description:

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

kernel-7.1.4-201.fc44

8 hours 47 minutes ago
FEDORA-2026-eb0b86b6f9 Packages in this update:
  • kernel-7.1.4-201.fc44
Update description:

The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.

nginx-1.30.4-1.fc45 nginx-mod-brotli-1.0.0~rc-13.fc45 nginx-mod-fancyindex-0.6.0-8.fc45 nginx-mod-headers-more-0.40-3.fc45 nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc45 nginx-mod-modsecurity-1.0.4-16.fc45 nginx-mod-naxsi-1.6-21.fc45 nginx-mod-vts…

12 hours 33 minutes ago
FEDORA-2026-d1cd8e3d25 Packages in this update:
  • nginx-1.30.4-1.fc45
  • nginx-mod-brotli-1.0.0~rc-13.fc45
  • nginx-mod-fancyindex-0.6.0-8.fc45
  • nginx-mod-headers-more-0.40-3.fc45
  • nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc45
  • nginx-mod-modsecurity-1.0.4-16.fc45
  • nginx-mod-naxsi-1.6-21.fc45
  • nginx-mod-vts-0.2.4-13.fc45
Update description:

nginx-mod-fancyindex:

Rebuild for 1.30.4

nginx-mod-modsecurity:

Rebuild for 1.30.4

nginx-mod-naxsi:

Rebuild for 1.30.4

nginx-mod-headers-more:

Rebuild for 1.30.4

nginx-mod-brotli:

Rebuild for 1.30.4

nginx-mod-js-challenge:

Rebuild for 1.30.4

nginx-mod-vts:

Rebuild for 1.30.4

nginx:

update to 1.30.4 fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434

perl-DBI-1.651-1.fc44

16 hours 35 minutes ago
FEDORA-2026-1c5ffc6018 Packages in this update:
  • perl-DBI-1.651-1.fc44
Update description:

1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081

perl-DBI-1.651-1.fc43

16 hours 35 minutes ago
FEDORA-2026-c0abcba354 Packages in this update:
  • perl-DBI-1.651-1.fc43
Update description:

1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081

kronosnet-1.35-1.fc44

18 hours 49 minutes ago
FEDORA-2026-db53330c8f Packages in this update:
  • kronosnet-1.35-1.fc44
Update description:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)

CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)

CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)

kronosnet-1.35-1.fc43

18 hours 49 minutes ago
FEDORA-2026-56568b6fe8 Packages in this update:
  • kronosnet-1.35-1.fc43
Update description:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)

CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)

CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)

Checked
37 minutes 15 seconds ago