Fedora Security Advisories

ceph-19.2.6-1.fc43

18 minutes 4 seconds ago
FEDORA-2026-ebffec502b Packages in this update:
  • ceph-19.2.6-1.fc43
Update description: Ceph 19.2.6 GA

bluez-5.87-4.fc43

8 hours 51 minutes ago
FEDORA-2026-a1cdcc1604 Packages in this update:
  • bluez-5.87-4.fc43
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

bluez-5.87-4.fc44

8 hours 51 minutes ago
FEDORA-2026-1bbec06c4d Packages in this update:
  • bluez-5.87-4.fc44
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

openssh-10.2p1-14.fc44

10 hours 1 minute ago
FEDORA-2026-752aa3ff05 Packages in this update:
  • openssh-10.2p1-14.fc44
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

openssh-10.0p1-12.fc43

10 hours 40 minutes ago
FEDORA-2026-535a408db5 Packages in this update:
  • openssh-10.0p1-12.fc43
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

opkssh-0.16.0-2.el10_3

14 hours 34 minutes ago
FEDORA-EPEL-2026-f45034028f Packages in this update:
  • opkssh-0.16.0-2.el10_3
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.el10_2

14 hours 36 minutes ago
FEDORA-EPEL-2026-8d8aa891da Packages in this update:
  • opkssh-0.16.0-2.el10_2
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc43

14 hours 36 minutes ago
FEDORA-2026-8d9ba295e0 Packages in this update:
  • opkssh-0.16.0-2.fc43
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc44

14 hours 37 minutes ago
FEDORA-2026-f5a5073561 Packages in this update:
  • opkssh-0.16.0-2.fc44
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

firefox-154.0-3.fc44

16 hours 22 minutes ago
FEDORA-2026-fc11919789 Packages in this update:
  • firefox-154.0-3.fc44
Update description:

Implement buffer stride support for PipeWire camera.

  • Update to latest upstream (154.0)
  • Enabled Wayland session restore on KDE.

openbao-2.6.2-1.el8

1 day ago
FEDORA-EPEL-2026-f78a6b3cf2 Packages in this update:
  • openbao-2.6.2-1.el8
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_3

1 day ago
FEDORA-EPEL-2026-0194a75a00 Packages in this update:
  • openbao-2.6.2-1.el10_3
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc44

1 day ago
FEDORA-2026-73f5dc988f Packages in this update:
  • openbao-2.6.2-1.fc44
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_2

1 day ago
FEDORA-EPEL-2026-56bfe89982 Packages in this update:
  • openbao-2.6.2-1.el10_2
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc43

1 day ago
FEDORA-2026-ba51600ab3 Packages in this update:
  • openbao-2.6.2-1.fc43
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el9

1 day ago
FEDORA-EPEL-2026-cba2df79a1 Packages in this update:
  • openbao-2.6.2-1.el9
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

Checked
4 minutes 12 seconds ago