Fedora Security Advisories

python-aiohttp-3.14.3-3.fc45

1 hour 25 minutes ago
FEDORA-2026-e76e1f737b Packages in this update:
  • python-aiohttp-3.14.3-3.fc45
Update description:

Automatic update for python-aiohttp-3.14.3-3.fc45.

Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystem

python-aiohttp-3.14.3-3.fc46

1 hour 46 minutes ago
FEDORA-2026-84f7af8f97 Packages in this update:
  • python-aiohttp-3.14.3-3.fc46
Update description:

Automatic update for python-aiohttp-3.14.3-3.fc46.

Changelog * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-3 - Preemptively patch for Cython 3.3 compatibility * Mon Aug 24 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-2 - Remove a test skip that’s no longer needed * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.14.3-1 - Update to 3.14.3 - Security fix for CVE-2026-34993; fixes RHBZ#2511060 - Security fix for CVE-2026-59881; fixes RHBZ#2509739 - Security fix for CVE-2026-69243; fixes RHBZ#2519530 - Security fix for CVE-2026-69244; fixes RHBZ#2519529 * Thu Aug 20 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 3.13.5-13 - Use the provisional pyproject declarative buildsystem

rpki-client-9.9-1.el10_2

10 hours 18 minutes ago
FEDORA-EPEL-2026-f7b19f60e3 Packages in this update:
  • rpki-client-9.9-1.el10_2
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

rpki-client-9.9-1.el10_3

10 hours 18 minutes ago
FEDORA-EPEL-2026-07a9b752f7 Packages in this update:
  • rpki-client-9.9-1.el10_3
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

rpki-client-9.9-1.el8

10 hours 18 minutes ago
FEDORA-EPEL-2026-2af0a88013 Packages in this update:
  • rpki-client-9.9-1.el8
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

rpki-client-9.9-1.fc43

10 hours 18 minutes ago
FEDORA-2026-52e9ee2c4d Packages in this update:
  • rpki-client-9.9-1.fc43
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

rpki-client-9.9-1.el9

10 hours 18 minutes ago
FEDORA-EPEL-2026-48389f1eca Packages in this update:
  • rpki-client-9.9-1.el9
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

rpki-client-9.9-1.fc44

10 hours 18 minutes ago
FEDORA-2026-fb17adc9de Packages in this update:
  • rpki-client-9.9-1.fc44
Update description: rpki-client 9.9
  • Introduce a backoff retry mechanism for non-functional CAs, eventually settling on retrying broken CAs only once per day. Backoff helps reduce load on both the RP itself and the publication points. It reduces log clutter and improves RP run duration.
  • Support for OpenSSL 4.
  • Add additional fail safe: only output config files on successful run.
  • In Rsync mode, include .gbr files in transfer for backwards compatibility.
  • Exclude hidden files and directories (/.*) when synchronizing via Rsync.
  • Limit the length of filenames as they appear in various ASN.1 fields to 255.
  • Improve readability by printing CCR ManifestState sorted by AKI.
  • Improve warnings related to malformed CCRs.
  • Limit the range of deltas added to the queue.
  • Rework error handling in rrdp_handle_file.
  • Ensure consistent states in persistent HTTP connections.
  • Tighten well-formedness checks on AIA & SIA extensions in certs.
  • Clear last_modified after each response on a persistent HTTP connection.
  • ASPAs with too many providers are no longer included in CCR output.
  • Replace assert() with a graceful failure by aborting the http request.
  • Fix a off-by-one in the internal IP address overlap checker.

kernel-7.1.10-200.fc44

11 hours 47 minutes ago
FEDORA-2026-73acdf12db Packages in this update:
  • kernel-7.1.10-200.fc44
Update description:

The 7.1.10 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.10-100.fc43

11 hours 47 minutes ago
FEDORA-2026-6d18f005f1 Packages in this update:
  • kernel-7.1.10-100.fc43
Update description:

The 7.1.10 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

pyOpenSSL-26.4.0-2.fc44 python-cryptography-50.0.0-1.fc44 python-pynitrokey-0.12.3-4.fc44

2 days 16 hours ago
FEDORA-2026-9f07e6bc2b Packages in this update:
  • pyOpenSSL-26.4.0-2.fc44
  • python-cryptography-50.0.0-1.fc44
  • python-pynitrokey-0.12.3-4.fc44
Update description:

Includes a fix for CVE-2026-69247, refer to https://github.com/pyca/cryptography/security/advisories/GHSA-g6cj-pr64-35w5 for a more detailed description.

Full changelog: https://github.com/pyca/cryptography/blob/50.0.0/CHANGELOG.rst

apache-ivy-2.6.0-2.fc44

2 days 20 hours ago
FEDORA-2026-c02768c662 Packages in this update:
  • apache-ivy-2.6.0-2.fc44
Update description:

IMPROVEMENT: ivy:retrieve and the 'post resolve tasks' now support the override child element. (IVY-1664)

IMPROVEMENT: ivy:makepom will now add override elements of the ivy.xml to the dependencyManagement section of the generated pom. (IVY-1663) (Thanks to Eric Milles)

IMPROVEMENT: ivy:deliver and ivy:publish now writes inherited dependencies first to preserve resolve order (IVY-1656) (Thanks to Eric Milles)

IMPROVEMENT: ModuleRevisionId.encodeToString now returns a deterministic string that doesn’t rely on a implmentation of HashMap (Thanks to Arnout Engelen)

FIX: improved Maven dependencyManagement matching for dependencies with a non-default type or classifier (IVY-1654) (Thanks to Mark Kittisopikul)

FIX: the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660)

FIX: when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency resolution, especially when multiple configurations are used. It also fixes issues where the dynamic revisions were replaced by versions from other configurations. (IVY-1485, IVY-1661)

FIX: the ivy:deliver task didn’t replace dynamic revision from inherited dependencies. (IVY-1410) (Thanks to Eric Milles)

FIX: the ivy:install task didn’t take the from resolver into account when resolving Maven parent modules or source/javadoc artifacts. (Thanks to Colin Chambers)

FIX: the ivy:checkdepsupdate task could suggest a lesser version as update. (IVY-1665) (Thanks to Eric Milles)

FIX: the ivy:makepom task no longer adds a dependency to the <dependencyManagement> section. (IVY-1667) (Thanks to Eric Milles)

FIX: the ivy:deliver task didn’t include XML namespaces from a parent ivy module when merging the descriptors. (IVY-1658) (Thanks to Eric Milles)

FIX: the ivy:checkdepsupdate task no longer shows evicted versions. (IVY-1662) (Thanks to Eric Milles)

Checked
2 minutes 31 seconds ago