Fedora Security Advisories

xen-4.19.5-2.fc42

3 hours 7 minutes ago
FEDORA-2026-0c9aff64a5 Packages in this update:
  • xen-4.19.5-2.fc42
Update description:

oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]

xen-4.20.3-2.fc43

3 hours 42 minutes ago
FEDORA-2026-78cd69d9ae Packages in this update:
  • xen-4.20.3-2.fc43
Update description:

oxenstored keeps quota related use counts across domain destruction [XSA-483, CVE-2026-23556] Xenstored DoS via XS_RESET_WATCHES command [XSA-484, CVE-2026-23557] grant table v2 race in status page mapping [XSA-486, CVE-2026-23558] x86: Floating Point Divider State Sampling [XSA-488, CVE-2025-54505]

perl-Starman-0.4018-1.fc44

3 hours 48 minutes ago
FEDORA-2026-5bb108e1b7 Packages in this update:
  • perl-Starman-0.4018-1.fc44
Update description:

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length.

perl-Starman-0.4018-1.fc43

3 hours 48 minutes ago
FEDORA-2026-b94aad33a5 Packages in this update:
  • perl-Starman-0.4018-1.fc43
Update description:

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length.

perl-Starman-0.4018-1.fc42

3 hours 48 minutes ago
FEDORA-2026-4cca750484 Packages in this update:
  • perl-Starman-0.4018-1.fc42
Update description:

Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both headers are present in an HTTP request. Per RFC 7230 3.3.3, Transfer-Encoding must take precedence. An attacker could exploit this to smuggle malicious HTTP requests via a front-end reverse proxy.

This package updates Starman to 0.4018 where Transfer-Encoding now takes precedence over Content-Length.

pyOpenSSL-26.1.0-1.fc44

4 hours 8 minutes ago
FEDORA-2026-05d463c932 Packages in this update:
  • pyOpenSSL-26.1.0-1.fc44
Update description:

Update to pyOpenSSL 26.1.0

This update adds support for cryptography v47 and fixes a single security issue:

  • Fixed X509Name field setters to correctly pass the value length to OpenSSL. Previously, values containing NUL bytes would be silently truncated, causing a divergence between the stored ASN.1 value and the value visible from Python. Credit to BudongJW for reporting the issue. CVE-2026-40475

pyOpenSSL-26.1.0-1.fc43

4 hours 8 minutes ago
FEDORA-2026-bc62ef0a6a Packages in this update:
  • pyOpenSSL-26.1.0-1.fc43
Update description:

Update to pyOpenSSL 26.1.0

This update adds support for cryptography v47 and fixes a single security issue:

  • Fixed X509Name field setters to correctly pass the value length to OpenSSL. Previously, values containing NUL bytes would be silently truncated, causing a divergence between the stored ASN.1 value and the value visible from Python. Credit to BudongJW for reporting the issue. CVE-2026-40475

kryoptic-1.5.0-2.fc45 pyOpenSSL-26.1.0-1.fc45 python-cryptography-47.0.0-1.fc45 rust-asn1-0.24.1-1.fc45 rust-asn1_derive-0.24.1-1.fc45

5 hours 47 minutes ago
FEDORA-2026-13a0c86ba1 Packages in this update:
  • kryoptic-1.5.0-2.fc45
  • pyOpenSSL-26.1.0-1.fc45
  • python-cryptography-47.0.0-1.fc45
  • rust-asn1-0.24.1-1.fc45
  • rust-asn1_derive-0.24.1-1.fc45
Update description:

Update python-cryptography to 47.0.0

As a result, rust-asn1 is bumped to 0.24, and pyOpenSSL is bumped to 26.1. kryoptic is rebuilt with a patch to support asn1 0.24.

pyOpenSSL 26.1 contains a fix for CVE-2026-40475

krb5-1.21.3-7.fc42

8 hours 45 minutes ago
FEDORA-2026-6c99aaa6d3 Packages in this update:
  • krb5-1.21.3-7.fc42
Update description:
  • Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)

krb5-1.22.2-4.fc43

9 hours 45 minutes ago
FEDORA-2026-684396998a Packages in this update:
  • krb5-1.22.2-4.fc43
Update description:
  • Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)
  • Add upstream patches to build against openssl 4.0
  • Make configure.ac work with autoconf 2.73

krb5-1.22.2-4.fc44

9 hours 47 minutes ago
FEDORA-2026-8b43ea2f82 Packages in this update:
  • krb5-1.22.2-4.fc44
Update description:
  • Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356)
  • Add upstream patches to build against openssl 4.0
  • Make configure.ac work with autoconf 2.73

krb5-1.22.2-7.fc45

10 hours 24 minutes ago
FEDORA-2026-2e9fe57a46 Packages in this update:
  • krb5-1.22.2-7.fc45
Update description:

Automatic update for krb5-1.22.2-7.fc45.

Changelog * Tue Apr 28 2026 Julien Rische <jrische@redhat.com> - 1.22.2-7 - Fix NegoEx parsing vulnerabilities (CVE-2026-40355, CVE-2026-40356) - resolves: rhbz#2463398 - resolves: rhbz#2463395
Checked
41 minutes 45 seconds ago