Fedora Security Advisories

python-scitokens-1.9.6-1.fc44

41 minutes 51 seconds ago
FEDORA-2026-88c19a9021 Packages in this update:
  • python-scitokens-1.9.6-1.fc44
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el10_3

41 minutes 52 seconds ago
FEDORA-EPEL-2026-111290d799 Packages in this update:
  • python-scitokens-1.9.6-1.el10_3
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el9

41 minutes 52 seconds ago
FEDORA-EPEL-2026-78ae7c544d Packages in this update:
  • python-scitokens-1.9.6-1.el9
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el8

41 minutes 52 seconds ago
FEDORA-EPEL-2026-7d2cb4f270 Packages in this update:
  • python-scitokens-1.9.6-1.el8
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.fc42

41 minutes 53 seconds ago
FEDORA-2026-488d5c2f3a Packages in this update:
  • python-scitokens-1.9.6-1.fc42
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.fc43

41 minutes 53 seconds ago
FEDORA-2026-31c056f844 Packages in this update:
  • python-scitokens-1.9.6-1.fc43
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-ujson-5.12.0-1.el10_1

3 hours 41 minutes ago
FEDORA-EPEL-2026-fcc952d28d Packages in this update:
  • python-ujson-5.12.0-1.el10_1
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

python-ujson-5.12.0-1.el10_2

3 hours 52 minutes ago
FEDORA-EPEL-2026-c1187798e7 Packages in this update:
  • python-ujson-5.12.0-1.el10_2
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

vim-9.2.148-1.fc42

6 hours 1 minute ago
FEDORA-2026-1885157e34 Packages in this update:
  • vim-9.2.148-1.fc42
Update description:

patchlevel 148

Security fixes for CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422

vim-9.2.148-1.fc44

6 hours 51 minutes ago
FEDORA-2026-f5d072060b Packages in this update:
  • vim-9.2.148-1.fc44
Update description:

patchlevel 148

Security fixes for CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422

Security fixes for CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422

chromium-146.0.7680.71-1.el10_2

8 hours 32 minutes ago
FEDORA-EPEL-2026-004b05bae9 Packages in this update:
  • chromium-146.0.7680.71-1.el10_2
Update description:

Update to 146.0.7680.71

* CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech * CVE-2026-3917: Use after free in Agents * CVE-2026-3918: Use after free in WebMCP * CVE-2026-3919: Use after free in Extensions * CVE-2026-3920: Out of bounds memory access in WebML * CVE-2026-3921: Use after free in TextEncoding * CVE-2026-3922: Use after free in MediaStream * CVE-2026-3923: Use after free in WebMIDI * CVE-2026-3924: Use after free in WindowDialog * CVE-2026-3925: Incorrect security UI in LookalikeChecks * CVE-2026-3926: Out of bounds read in V8 * CVE-2026-3927: Incorrect security UI in PictureInPicture * CVE-2026-3928: Insufficient policy enforcement in Extensions * CVE-2026-3929: Side-channel information leakage in ResourceTiming * CVE-2026-3930: Unsafe navigation in Navigation * CVE-2026-3931: Heap buffer overflow in Skia * CVE-2026-3932: Insufficient policy enforcement in PDF * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver * CVE-2026-3935: Incorrect security UI in WebAppInstalls * CVE-2026-3936: Use after free in WebView * CVE-2026-3937: Incorrect security UI in Downloads * CVE-2026-3938: Insufficient policy enforcement in Clipboard * CVE-2026-3939: Insufficient policy enforcement in PDF * CVE-2026-3940: Insufficient policy enforcement in DevTools * CVE-2026-3941: Insufficient policy enforcement in DevTools * CVE-2026-3942: Incorrect security UI in PictureInPicture

chromium-146.0.7680.71-1.el10_3

8 hours 32 minutes ago
FEDORA-EPEL-2026-4ecb36d14c Packages in this update:
  • chromium-146.0.7680.71-1.el10_3
Update description:

Update to 146.0.7680.71

* CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech * CVE-2026-3917: Use after free in Agents * CVE-2026-3918: Use after free in WebMCP * CVE-2026-3919: Use after free in Extensions * CVE-2026-3920: Out of bounds memory access in WebML * CVE-2026-3921: Use after free in TextEncoding * CVE-2026-3922: Use after free in MediaStream * CVE-2026-3923: Use after free in WebMIDI * CVE-2026-3924: Use after free in WindowDialog * CVE-2026-3925: Incorrect security UI in LookalikeChecks * CVE-2026-3926: Out of bounds read in V8 * CVE-2026-3927: Incorrect security UI in PictureInPicture * CVE-2026-3928: Insufficient policy enforcement in Extensions * CVE-2026-3929: Side-channel information leakage in ResourceTiming * CVE-2026-3930: Unsafe navigation in Navigation * CVE-2026-3931: Heap buffer overflow in Skia * CVE-2026-3932: Insufficient policy enforcement in PDF * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver * CVE-2026-3935: Incorrect security UI in WebAppInstalls * CVE-2026-3936: Use after free in WebView * CVE-2026-3937: Incorrect security UI in Downloads * CVE-2026-3938: Insufficient policy enforcement in Clipboard * CVE-2026-3939: Insufficient policy enforcement in PDF * CVE-2026-3940: Insufficient policy enforcement in DevTools * CVE-2026-3941: Insufficient policy enforcement in DevTools * CVE-2026-3942: Incorrect security UI in PictureInPicture

chromium-146.0.7680.71-1.fc43

8 hours 32 minutes ago
FEDORA-2026-0dc0c88f83 Packages in this update:
  • chromium-146.0.7680.71-1.fc43
Update description:

Update to 146.0.7680.71

* CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech * CVE-2026-3917: Use after free in Agents * CVE-2026-3918: Use after free in WebMCP * CVE-2026-3919: Use after free in Extensions * CVE-2026-3920: Out of bounds memory access in WebML * CVE-2026-3921: Use after free in TextEncoding * CVE-2026-3922: Use after free in MediaStream * CVE-2026-3923: Use after free in WebMIDI * CVE-2026-3924: Use after free in WindowDialog * CVE-2026-3925: Incorrect security UI in LookalikeChecks * CVE-2026-3926: Out of bounds read in V8 * CVE-2026-3927: Incorrect security UI in PictureInPicture * CVE-2026-3928: Insufficient policy enforcement in Extensions * CVE-2026-3929: Side-channel information leakage in ResourceTiming * CVE-2026-3930: Unsafe navigation in Navigation * CVE-2026-3931: Heap buffer overflow in Skia * CVE-2026-3932: Insufficient policy enforcement in PDF * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver * CVE-2026-3935: Incorrect security UI in WebAppInstalls * CVE-2026-3936: Use after free in WebView * CVE-2026-3937: Incorrect security UI in Downloads * CVE-2026-3938: Insufficient policy enforcement in Clipboard * CVE-2026-3939: Insufficient policy enforcement in PDF * CVE-2026-3940: Insufficient policy enforcement in DevTools * CVE-2026-3941: Insufficient policy enforcement in DevTools * CVE-2026-3942: Incorrect security UI in PictureInPicture

chromium-146.0.7680.71-1.fc44

8 hours 32 minutes ago
FEDORA-2026-6e868c481c Packages in this update:
  • chromium-146.0.7680.71-1.fc44
Update description:

Update to 146.0.7680.71

* CVE-2026-3913: Heap buffer overflow in WebML * CVE-2026-3914: Integer overflow in WebML * CVE-2026-3915: Heap buffer overflow in WebML * CVE-2026-3916: Out of bounds read in Web Speech * CVE-2026-3917: Use after free in Agents * CVE-2026-3918: Use after free in WebMCP * CVE-2026-3919: Use after free in Extensions * CVE-2026-3920: Out of bounds memory access in WebML * CVE-2026-3921: Use after free in TextEncoding * CVE-2026-3922: Use after free in MediaStream * CVE-2026-3923: Use after free in WebMIDI * CVE-2026-3924: Use after free in WindowDialog * CVE-2026-3925: Incorrect security UI in LookalikeChecks * CVE-2026-3926: Out of bounds read in V8 * CVE-2026-3927: Incorrect security UI in PictureInPicture * CVE-2026-3928: Insufficient policy enforcement in Extensions * CVE-2026-3929: Side-channel information leakage in ResourceTiming * CVE-2026-3930: Unsafe navigation in Navigation * CVE-2026-3931: Heap buffer overflow in Skia * CVE-2026-3932: Insufficient policy enforcement in PDF * CVE-2026-3934: Insufficient policy enforcement in ChromeDriver * CVE-2026-3935: Incorrect security UI in WebAppInstalls * CVE-2026-3936: Use after free in WebView * CVE-2026-3937: Incorrect security UI in Downloads * CVE-2026-3938: Insufficient policy enforcement in Clipboard * CVE-2026-3939: Insufficient policy enforcement in PDF * CVE-2026-3940: Insufficient policy enforcement in DevTools * CVE-2026-3941: Insufficient policy enforcement in DevTools * CVE-2026-3942: Incorrect security UI in PictureInPicture

python-ujson-5.12.0-1.el10_3

10 hours 45 minutes ago
FEDORA-EPEL-2026-321e8e0d34 Packages in this update:
  • python-ujson-5.12.0-1.el10_3
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

python-ujson-5.12.0-1.fc42

10 hours 54 minutes ago
FEDORA-2026-0f099ed388 Packages in this update:
  • python-ujson-5.12.0-1.fc42
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

python-ujson-5.12.0-1.fc43

11 hours 8 minutes ago
FEDORA-2026-bf741e26e4 Packages in this update:
  • python-ujson-5.12.0-1.fc43
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

python-ujson-5.12.0-1.fc44

11 hours 26 minutes ago
FEDORA-2026-5725d633ec Packages in this update:
  • python-ujson-5.12.0-1.fc44
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

systemd-258.6-1.fc43

21 hours 36 minutes ago
FEDORA-2026-965f164001 Packages in this update:
  • systemd-258.6-1.fc43
Update description:
  • A bunch of bugfixes
  • More sanitization for invalid values received from hardware and firmware

systemd-259.4-1.fc44

21 hours 36 minutes ago
FEDORA-2026-0cde3e4697 Packages in this update:
  • systemd-259.4-1.fc44
Update description:
  • A bunch of bugfixes
  • More sanitization for invalid values received from hardware and firmware
Checked
7 minutes 14 seconds ago