Fedora Security Advisories

pyOpenSSL-26.4.0-2.fc44 python-cryptography-50.0.0-1.fc44 python-pynitrokey-0.12.3-4.fc44

4 hours 27 minutes ago
FEDORA-2026-9f07e6bc2b Packages in this update:
  • pyOpenSSL-26.4.0-2.fc44
  • python-cryptography-50.0.0-1.fc44
  • python-pynitrokey-0.12.3-4.fc44
Update description:

Includes a fix for CVE-2026-69247, refer to https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5 for a more detailed description.

Full changelog: https://github.com/pyca/cryptography/blob/50.0.0/CHANGELOG.rst

apache-ivy-2.6.0-2.fc44

8 hours 20 minutes ago
FEDORA-2026-c02768c662 Packages in this update:
  • apache-ivy-2.6.0-2.fc44
Update description:

IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)

IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)

IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)

IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen)

FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)

FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)

FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)

FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)

FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)

FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)

FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)

FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)

FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)

apache-ivy-2.6.0-2.fc43

8 hours 20 minutes ago
FEDORA-2026-d0535bed52 Packages in this update:
  • apache-ivy-2.6.0-2.fc43
Update description:

IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)

IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)

IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)

IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen)

FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)

FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)

FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)

FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)

FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)

FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)

FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)

FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)

FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)

chromium-151.0.7922.169-1.fc44

8 hours 39 minutes ago
FEDORA-2026-295354c8a1 Packages in this update:
  • chromium-151.0.7922.169-1.fc44
Update description:

chromium security release 151.0.7922.169

* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL

chromium-151.0.7922.169-1.el10_3

8 hours 39 minutes ago
FEDORA-EPEL-2026-0900171011 Packages in this update:
  • chromium-151.0.7922.169-1.el10_3
Update description:

chromium security release 151.0.7922.169

* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL

chromium-151.0.7922.169-1.el10_2

8 hours 39 minutes ago
FEDORA-EPEL-2026-bb07e73593 Packages in this update:
  • chromium-151.0.7922.169-1.el10_2
Update description:

chromium security release 151.0.7922.169

* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL

chromium-151.0.7922.169-1.el9

8 hours 39 minutes ago
FEDORA-EPEL-2026-65879e30b4 Packages in this update:
  • chromium-151.0.7922.169-1.el9
Update description:

chromium security release 151.0.7922.169

* CVE-2026-76034: Buffer overflow in WebGL * CVE-2026-76036: Buffer overflow in Dawn * CVE-2026-76033: Inappropriate implementation in CORS * CVE-2026-76037: Link following in CredentialProvider * CVE-2026-76044: Race condition in USB * CVE-2026-76039: Incorrect reference resolution in Core * CVE-2026-76040: Use after free in Browser * CVE-2026-76035: Inappropriate implementation in Media * CVE-2026-76042: Use of uninitialized resource in GPU * CVE-2026-76046: Buffer overflow in ANGLE * CVE-2026-76043: Incorrect calculation in V8 * CVE-2026-76041: Information leak in Skia * CVE-2026-76047: Type confusion in V8 * CVE-2026-76038: Type confusion in V8 * CVE-2026-76045: Use after free in WebGL

python-mkdocs-git-revision-date-localized-plugin-1.5.4-1.fc44

8 hours 51 minutes ago
FEDORA-2026-c10d41473a Packages in this update:
  • python-mkdocs-git-revision-date-localized-plugin-1.5.4-1.fc44
Update description:

Update to v1.5.4 a2313a3 Security Raises the gitpython floor from >=3.1.44 to >=3.1.59.

Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI environment and nothing else. Downstream users installing from PyPI resolved against pyproject.toml, so they could still land on a GitPython carrying the 2026 option-injection advisories — GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr among them, all patched by 3.1.58, with further option hardening in 3.1.59.

This plugin never passes user input as git options, so it was not exploitable through those. The floor bump forces the upgrade in environments that already hold an older GitPython, and clears the warnings downstream scanners report.

Thanks to @nucleus-ffm for reporting it in #222.

Maintenance Harden test git repos against flaky "Error building trees" failures by @timvink in #212 ci: update GitHub Actions to Node 24 compatible versions by @timvink in #213 deps: bump idna and pymdown-extensions to patch security alerts by @timvink in #214 Bump gitpython from 3.1.50 to 3.1.58 in #217, #219, #220 Bump pymdown-extensions from 10.21.3 to 11.0.1 in #218, #221

python-mkdocs-git-revision-date-localized-plugin-1.5.4-1.el10_3

8 hours 51 minutes ago
FEDORA-EPEL-2026-178a9a974c Packages in this update:
  • python-mkdocs-git-revision-date-localized-plugin-1.5.4-1.el10_3
Update description:

Update to v1.5.4 a2313a3 Security Raises the gitpython floor from >=3.1.44 to >=3.1.59.

Earlier dependabot bumps only touched this repo's uv.lock, which pins the CI environment and nothing else. Downstream users installing from PyPI resolved against pyproject.toml, so they could still land on a GitPython carrying the 2026 option-injection advisories — GHSA-wvpp-8hx9-p66j and GHSA-jm78-9fvv-mhgr among them, all patched by 3.1.58, with further option hardening in 3.1.59.

This plugin never passes user input as git options, so it was not exploitable through those. The floor bump forces the upgrade in environments that already hold an older GitPython, and clears the warnings downstream scanners report.

Thanks to @nucleus-ffm for reporting it in #222.

Maintenance Harden test git repos against flaky "Error building trees" failures by @timvink in #212 ci: update GitHub Actions to Node 24 compatible versions by @timvink in #213 deps: bump idna and pymdown-extensions to patch security alerts by @timvink in #214 Bump gitpython from 3.1.50 to 3.1.58 in #217, #219, #220 Bump pymdown-extensions from 10.21.3 to 11.0.1 in #218, #221

perl-URI-5.36-1.fc43

14 hours 15 minutes ago
FEDORA-2026-09941e744b Packages in this update:
  • perl-URI-5.36-1.fc43
Update description:

5.36 - Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label [CVE-2026-19953]

perl-URI-5.36-1.fc44

14 hours 15 minutes ago
FEDORA-2026-32b0d26c4c Packages in this update:
  • perl-URI-5.36-1.fc44
Update description:

5.36 - Apply Unicode NFC normalization in URI::_idna nameprep so IDNA host encoding matches other clients instead of emitting a non-standard, non-round-tripping A-label [CVE-2026-19953]

rust-anstyle-hyperlink-1.0.2-1.fc43 rust-anstyle-progress-0.1.4-1.fc43 rust-cargo-0.98.0-1.fc43 rust-cargo-c-0.10.24-2.fc43 rust-cargo-credential-libsecret-0.5.8-1.fc43 rust-cargo-util-0.2.30-1.fc43 rust-cargo-util-schemas-0.14.1-1.fc43 rust-cargo-util…

1 day 4 hours ago
FEDORA-2026-ce685f40fe Packages in this update:
  • rust-anstyle-hyperlink-1.0.2-1.fc43
  • rust-anstyle-progress-0.1.4-1.fc43
  • rust-cargo-0.98.0-1.fc43
  • rust-cargo-c-0.10.24-2.fc43
  • rust-cargo-credential-libsecret-0.5.8-1.fc43
  • rust-cargo-util-0.2.30-1.fc43
  • rust-cargo-util-schemas-0.14.1-1.fc43
  • rust-cargo-util-terminal-0.1.0-1.fc43
  • rust-crates-io-0.41.0-1.fc43
  • rust-rustfix-0.9.7-1.fc43
Update description:
  • Update cargo-c to version 0.10.24 (plus dependency updates).
  • Initial packaging of the anstyle-hyperlink, anstyle-progress, and cargo-util-terminal crates.

yt-dlp-2026.08.19-1.fc45

1 day 6 hours ago
FEDORA-2026-c0410a0829 Packages in this update:
  • yt-dlp-2026.08.19-1.fc45
Update description:

Automatic update for yt-dlp-2026.08.19-1.fc45.

Changelog * Thu Aug 20 2026 Mikel Olasagasti Uranga <mikel@olasagasti.info> - 2026.08.19-1 - Update to 2026.08.19 - Closes rhbz#2497100 rhbz#2505367 rhbz#2491888 rhbz#2491889 rhbz#2491890 rhbz#2499189 * Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2026.06.09-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

yt-dlp-2026.08.19-1.fc46

1 day 6 hours ago
FEDORA-2026-139d3aad5f Packages in this update:
  • yt-dlp-2026.08.19-1.fc46
Update description:

Automatic update for yt-dlp-2026.08.19-1.fc46.

Changelog * Thu Aug 20 2026 Mikel Olasagasti Uranga <mikel@olasagasti.info> - 2026.08.19-1 - Update to 2026.08.19 - Closes rhbz#2497100 rhbz#2505367 rhbz#2491888 rhbz#2491889 rhbz#2491890 rhbz#2499189 * Fri Jul 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 2026.06.09-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
Checked
32 minutes 40 seconds ago