Fedora Security Advisories

bluez-5.87-4.fc43

2 hours 6 minutes ago
FEDORA-2026-a1cdcc1604 Packages in this update:
  • bluez-5.87-4.fc43
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

bluez-5.87-4.fc44

2 hours 6 minutes ago
FEDORA-2026-1bbec06c4d Packages in this update:
  • bluez-5.87-4.fc44
Update description:

An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.

This update fixes this issue (CVE-2026-75032)

openssh-10.2p1-14.fc44

3 hours 16 minutes ago
FEDORA-2026-752aa3ff05 Packages in this update:
  • openssh-10.2p1-14.fc44
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

openssh-10.0p1-12.fc43

3 hours 55 minutes ago
FEDORA-2026-535a408db5 Packages in this update:
  • openssh-10.0p1-12.fc43
Update description:

Fix CVE-2026-59995 OpenSSH: sftp client allows attacker to control downloaded

opkssh-0.16.0-2.el10_3

7 hours 49 minutes ago
FEDORA-EPEL-2026-f45034028f Packages in this update:
  • opkssh-0.16.0-2.el10_3
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.el10_2

7 hours 51 minutes ago
FEDORA-EPEL-2026-8d8aa891da Packages in this update:
  • opkssh-0.16.0-2.el10_2
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc43

7 hours 52 minutes ago
FEDORA-2026-8d9ba295e0 Packages in this update:
  • opkssh-0.16.0-2.fc43
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

opkssh-0.16.0-2.fc44

7 hours 52 minutes ago
FEDORA-2026-f5a5073561 Packages in this update:
  • opkssh-0.16.0-2.fc44
Update description:

Update the bundled github.com/go-chi/chi/v5 to v5.3.1, which is outside the range affected by CVE-2026-72815, CVE-2026-72816 and CVE-2026-72817 (IP spoofing via chi's RealIP middleware).

opkssh bundles only chi's root router package and never the affected middleware package, so the vulnerable code was not actually shipped in any opkssh build.

firefox-154.0-3.fc44

9 hours 37 minutes ago
FEDORA-2026-fc11919789 Packages in this update:
  • firefox-154.0-3.fc44
Update description:

Implement buffer stride support for PipeWire camera.

  • Update to latest upstream (154.0)
  • Enabled Wayland session restore on KDE.

openbao-2.6.2-1.el8

17 hours 22 minutes ago
FEDORA-EPEL-2026-f78a6b3cf2 Packages in this update:
  • openbao-2.6.2-1.el8
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_3

17 hours 22 minutes ago
FEDORA-EPEL-2026-0194a75a00 Packages in this update:
  • openbao-2.6.2-1.el10_3
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc44

17 hours 22 minutes ago
FEDORA-2026-73f5dc988f Packages in this update:
  • openbao-2.6.2-1.fc44
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el10_2

17 hours 22 minutes ago
FEDORA-EPEL-2026-56bfe89982 Packages in this update:
  • openbao-2.6.2-1.el10_2
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.fc43

17 hours 22 minutes ago
FEDORA-2026-ba51600ab3 Packages in this update:
  • openbao-2.6.2-1.fc43
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

openbao-2.6.2-1.el9

17 hours 22 minutes ago
FEDORA-EPEL-2026-cba2df79a1 Packages in this update:
  • openbao-2.6.2-1.el9
Update description:

Update to upstream 2.6.2, including security fixes for GHSA-rh46-vc3j-w2w3 and GHSA-g892-p242-8g86.

libkcapi-1.5.1-1.fc46

21 hours 36 minutes ago
FEDORA-2026-6a1526575a Packages in this update:
  • libkcapi-1.5.1-1.fc46
Update description:

Automatic update for libkcapi-1.5.1-1.fc46.

Changelog * Tue Aug 18 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-1 - Update to version 1.5.1 (fedora#2512793) - Fix CVE-2026-71225 (fedora#2511445) - Fix CVE-2026-71226 (fedora#2511484) - Fix CVE-2026-71227 (fedora#2511487)

libkcapi-1.5.1-1.fc45

21 hours 38 minutes ago
FEDORA-2026-4ba4b4f139 Packages in this update:
  • libkcapi-1.5.1-1.fc45
Update description:

Automatic update for libkcapi-1.5.1-1.fc45.

Changelog * Tue Aug 18 2026 Ondrej Mosnáček <omosnacek@gmail.com> - 1.5.1-1 - Update to version 1.5.1 (fedora#2512793) - Fix CVE-2026-71225 (fedora#2511445) - Fix CVE-2026-71226 (fedora#2511484) - Fix CVE-2026-71227 (fedora#2511487)
Checked
22 minutes 51 seconds ago