Fedora Security Advisories

GitPython-3.1.60-1.fc45

2 hours 5 minutes ago
FEDORA-2026-63e7132525 Packages in this update:
  • GitPython-3.1.60-1.fc45
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

bluez-5.87-6.fc43

2 hours 15 minutes ago
FEDORA-2026-d4eec45564 Packages in this update:
  • bluez-5.87-6.fc43
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc44

2 hours 16 minutes ago
FEDORA-2026-1fba3f22c9 Packages in this update:
  • bluez-5.87-6.fc44
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-7.fc45

2 hours 17 minutes ago
FEDORA-2026-84b4f1c43a Packages in this update:
  • bluez-5.87-7.fc45
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc43

4 hours 8 minutes ago
FEDORA-2026-432a1ef311 Packages in this update:
  • bluez-5.87-5.fc43
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-5.fc44

4 hours 9 minutes ago
FEDORA-2026-01488a5766 Packages in this update:
  • bluez-5.87-5.fc44
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc45

4 hours 11 minutes ago
FEDORA-2026-f4d10955d6 Packages in this update:
  • bluez-5.87-6.fc45
Update description:

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bind-9.18.50-2.fc43

7 hours 27 minutes ago
FEDORA-2026-875d2a5154 Packages in this update:
  • bind-9.18.50-2.fc43
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-2.fc44

7 hours 52 minutes ago
FEDORA-2026-d87e7f498a Packages in this update:
  • bind-9.18.50-2.fc44
Update description:

Fixes multiple CVEs

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

bind-9.18.50-34.fc45

7 hours 52 minutes ago
FEDORA-2026-0adbf9c133 Packages in this update:
  • bind-9.18.50-34.fc45
Update description:

Fixes multiple CVEs, without a rebase to newer version

  • Potential wildcard CNAME RPZ policy bypass (CVE-2026-11331)
  • Key Record using PRIVATEDNS algorithm may lead to exit (CVE-2026-10822)
  • Record ordering based unexpected exit with CNAME or DNAME (CVE-2026-12617)
  • Potential memory usage beyond configured limits (CVE-2026-11622)
  • Cache poisoning via label count discrepancy, RRSIG, wildcards (CVE-2026-11721)
  • Incorrect acceptance of NSEC3 records (CVE-2026-10723)
  • Unexpected exit with NSEC and NSEC3 both present (CVE-2026-13204)
  • DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (CVE-2026-13321)

mrtg-2.17.10-15.fc45

9 hours 22 minutes ago
FEDORA-2026-c2dba9f29d Packages in this update:
  • mrtg-2.17.10-15.fc45
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-13.fc43

10 hours 2 minutes ago
FEDORA-2026-4522f50b2c Packages in this update:
  • mrtg-2.17.10-13.fc43
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

mrtg-2.17.10-14.fc44

10 hours 33 minutes ago
FEDORA-2026-d05b77001f Packages in this update:
  • mrtg-2.17.10-14.fc44
Update description:

Fix CVE-2026-72694: symlink-following privilege escalation in PID file handling

Checked
8 minutes 20 seconds ago