Fedora Security Advisories

curl-8.21.0-7.fc45

57 minutes 32 seconds ago
FEDORA-2026-c2d4a9aa16 Packages in this update:
  • curl-8.21.0-7.fc45
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

chromium-154.0.8037.97-1.el10_4

2 hours 35 minutes ago
FEDORA-EPEL-2026-d1c26f4ffd Packages in this update:
  • chromium-154.0.8037.97-1.el10_4
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el9

2 hours 35 minutes ago
FEDORA-EPEL-2026-923ac1e238 Packages in this update:
  • chromium-154.0.8037.97-1.el9
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_3

2 hours 35 minutes ago
FEDORA-EPEL-2026-b3497ed039 Packages in this update:
  • chromium-154.0.8037.97-1.el10_3
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_2

2 hours 35 minutes ago
FEDORA-EPEL-2026-421dd4a529 Packages in this update:
  • chromium-154.0.8037.97-1.el10_2
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc43

2 hours 35 minutes ago
FEDORA-2026-02902c2fa0 Packages in this update:
  • chromium-154.0.8037.97-1.fc43
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc45

2 hours 35 minutes ago
FEDORA-2026-53c8aca50a Packages in this update:
  • chromium-154.0.8037.97-1.fc45
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc44

2 hours 35 minutes ago
FEDORA-2026-bcdfa4c7db Packages in this update:
  • chromium-154.0.8037.97-1.fc44
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

flocq-4.2.2-3.fc44 gappalib-coq-1.11.0-1.fc44 rocq-9.3.0-1.fc44 rocq-stdlib-9.2.0-1.fc44 why3-1.8.2-11.fc44 zenon-0.8.5-41.fc44

11 hours 32 minutes ago
FEDORA-2026-62bbabcf11 Packages in this update:
  • flocq-4.2.2-3.fc44
  • gappalib-coq-1.11.0-1.fc44
  • rocq-9.3.0-1.fc44
  • rocq-stdlib-9.2.0-1.fc44
  • why3-1.8.2-11.fc44
  • zenon-0.8.5-41.fc44
Update description:

See https://rocq-prover.org/doc/v9.3/refman/changes.html#version-9-3 for changes in rocq 9.3.0.

See https://rocq-prover.org/doc/v9.2/refman-stdlib/changes.html for changes in rocq-stdlib 9.2.0.

See https://gitlab.inria.fr/gappa/coq/-/blob/master/NEWS.md for changes in gappalib-coq 1.11.0.

The other builds are rebuilds due to the above changes.

python-jupytext-1.19.6-1.fc43

14 hours 9 minutes ago
FEDORA-2026-3942ab86fd Packages in this update:
  • python-jupytext-1.19.6-1.fc43
Update description:

See https://github.com/jupytext/jupytext/blob/main/CHANGELOG.md for changes in versions 1.19.5 and 1.19.6. For this update, a patch has been applied that reverses the jupyterlab → jupyter-builder change for Fedora releases ≤ 45, since jupyter-builder is only available in F46 and later. Many CVEs have been fixed in this release.

aegisub-3.5.0-1.fc43

19 hours 23 minutes ago
FEDORA-2026-78a11da997 Packages in this update:
  • aegisub-3.5.0-1.fc43
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-2.fc44

19 hours 24 minutes ago
FEDORA-2026-0c6d4471fc Packages in this update:
  • aegisub-3.5.0-2.fc44
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-1.fc45

19 hours 24 minutes ago
FEDORA-2026-d296db490c Packages in this update:
  • aegisub-3.5.0-1.fc45
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

zabbix7.0-7.0.31-1.el10_3

19 hours 24 minutes ago
FEDORA-EPEL-2026-042a8bf4e4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_3
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el10_4

19 hours 24 minutes ago
FEDORA-EPEL-2026-3e248bfcbd Packages in this update:
  • zabbix7.0-7.0.31-1.el10_4
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el9

19 hours 24 minutes ago
FEDORA-EPEL-2026-0879abafaa Packages in this update:
  • zabbix7.0-7.0.31-1.el9
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el8

19 hours 24 minutes ago
FEDORA-EPEL-2026-367fe24aeb Packages in this update:
  • zabbix7.0-7.0.31-1.el8
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

Update to 7.0.28

zabbix7.0-7.0.31-1.el10_2

19 hours 24 minutes ago
FEDORA-EPEL-2026-6aaa054bb4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_2
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix-6.0.48-1.el9

19 hours 26 minutes ago
FEDORA-EPEL-2026-d82469a549 Packages in this update:
  • zabbix-6.0.48-1.el9
Update description:

Update to 6.0.48 (CVE-2026-59782, CVE-2026-59785, CVE-2026-59787)

Checked
17 minutes 7 seconds ago