Fedora Security Advisories

perl-Net-OAuth-0.33-1.fc44

1 hour 28 minutes ago
FEDORA-2026-e33554bf9f Packages in this update:
  • perl-Net-OAuth-0.33-1.fc44
Update description:

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.

perl-Net-OAuth-0.33-1.fc43

1 hour 28 minutes ago
FEDORA-2026-370bd8b5f0 Packages in this update:
  • perl-Net-OAuth-0.33-1.fc43
Update description:

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.

perl-Net-OAuth-0.33-2.fc45

1 hour 28 minutes ago
FEDORA-2026-27bab0e213 Packages in this update:
  • perl-Net-OAuth-0.33-2.fc45
Update description:

Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. This update fixes the issue.

perl-XML-Bare-0.53-45.fc44

4 hours 8 minutes ago
FEDORA-2026-5c3f4c8337 Packages in this update:
  • perl-XML-Bare-0.53-45.fc44
Update description:

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.

Fixes CVE-2026-57074 and CVE-2026-13401.

perl-XML-Bare-0.53-44.fc43

4 hours 8 minutes ago
FEDORA-2026-14e358a2a2 Packages in this update:
  • perl-XML-Bare-0.53-44.fc43
Update description:

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.

Fixes CVE-2026-57074 and CVE-2026-13401.

perl-XML-Bare-0.53-47.fc45

4 hours 8 minutes ago
FEDORA-2026-3a2db4368a Packages in this update:
  • perl-XML-Bare-0.53-47.fc45
Update description:

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.

Fixes CVE-2026-57074 and CVE-2026-13401.

perl-XML-Bare-0.53-40.el9

4 hours 8 minutes ago
FEDORA-EPEL-2026-e2adb4a954 Packages in this update:
  • perl-XML-Bare-0.53-40.el9
Update description:

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. This packages fixes this issue.

Fixes CVE-2026-57074 and CVE-2026-13401.

emacs-30.2-11.fc43

1 day 19 hours ago
FEDORA-2026-6b1a89dfe6 Packages in this update:
  • emacs-30.2-11.fc43
Update description:

Fix CVE-2026-79992: Local shell command injection through the user field in emacs tramp

kernel-7.1.12-200.fc44

1 day 21 hours ago
FEDORA-2026-92c9a5d8bc Packages in this update:
  • kernel-7.1.12-200.fc44
Update description:

The 7.1.12 stable kernel update contains a single fix for CVE-2026-80590.

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.12-100.fc43

1 day 21 hours ago
FEDORA-2026-f04e0d4d9d Packages in this update:
  • kernel-7.1.12-100.fc43
Update description:

The 7.1.12 stable kernel update contains a single fix for CVE-2026-80590.

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

emacs-30.2-29.fc44

2 days ago
FEDORA-2026-e47f5a0b84 Packages in this update:
  • emacs-30.2-29.fc44
Update description:

Fix CVE-2026-79992: Local shell command injection through the user field in emacs tramp

nsd-4.15.1-1.el10_3

2 days 6 hours ago
FEDORA-EPEL-2026-b69054a78f Packages in this update:
  • nsd-4.15.1-1.el10_3
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt
Checked
28 minutes 5 seconds ago