Fedora Security Advisories

coturn-4.15.0-1.fc44

1 hour 29 minutes ago
FEDORA-2026-8856c5be6f Packages in this update:
  • coturn-4.15.0-1.fc44
Update description: Coturn 4.15.0 Security
  • Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
  • Bind mobility session-resume to the original allocation owner — a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
  • Reject ACME requests via signed 400 response instead of silently dropping them.
  • Reset the reused UDP receive-buffer offset in the DTLS listener.
  • Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire.
  • Fixed a uint16_t truncation overflow when computing STUN message length.
  • Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
  • Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP subnegotiation parsing to the buffer end.
  • NULL-terminated the HTTP request buffer before it is logged verbatim; switched apputils.c to bounded snprintf.
New features
  • RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peer→client traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
  • --drain-min-allocations — a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
  • --log-min-level (log_min_level in the config file) — a real minimum-log-level filter, since -v/--verbose had little effect on turnserver logging.
  • Alternate-server TCP/UDP distinction — alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
  • Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.
Reliability and correctness fixes
  • Fixed the remaining misaligned wire-buffer accesses and added alignment-safe turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
  • Fixed uint32_t counter wraparound in the relay port allocator.
  • Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
  • Released the alternate-server list mutex when del_alt_server removes the last entry, fixing a deadlock.
  • setgroups is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
  • Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
  • Cast to unsigned char before isspace() in config-file parsing.
  • Log an explicit error when a configured tls-listening-port cannot start.
  • Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure build.
Metrics
  • Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
  • turnutils_uclient now sends the SNI host name on TLS connections.
  • heap-allocates its STUN message buffers instead of using large stack buffers.

coturn-4.15.0-1.el10_2

1 hour 29 minutes ago
FEDORA-EPEL-2026-7f3012c375 Packages in this update:
  • coturn-4.15.0-1.el10_2
Update description: Coturn 4.15.0 Security
  • Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
  • Bind mobility session-resume to the original allocation owner — a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
  • Reject ACME requests via signed 400 response instead of silently dropping them.
  • Reset the reused UDP receive-buffer offset in the DTLS listener.
  • Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire.
  • Fixed a uint16_t truncation overflow when computing STUN message length.
  • Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
  • Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP subnegotiation parsing to the buffer end.
  • NULL-terminated the HTTP request buffer before it is logged verbatim; switched apputils.c to bounded snprintf.
New features
  • RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peer→client traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
  • --drain-min-allocations — a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
  • --log-min-level (log_min_level in the config file) — a real minimum-log-level filter, since -v/--verbose had little effect on turnserver logging.
  • Alternate-server TCP/UDP distinction — alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
  • Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.
Reliability and correctness fixes
  • Fixed the remaining misaligned wire-buffer accesses and added alignment-safe turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
  • Fixed uint32_t counter wraparound in the relay port allocator.
  • Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
  • Released the alternate-server list mutex when del_alt_server removes the last entry, fixing a deadlock.
  • setgroups is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
  • Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
  • Cast to unsigned char before isspace() in config-file parsing.
  • Log an explicit error when a configured tls-listening-port cannot start.
  • Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure build.
Metrics
  • Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
  • turnutils_uclient now sends the SNI host name on TLS connections.
  • heap-allocates its STUN message buffers instead of using large stack buffers.

coturn-4.15.0-1.el10_3

1 hour 29 minutes ago
FEDORA-EPEL-2026-bd9fc0a600 Packages in this update:
  • coturn-4.15.0-1.el10_3
Update description: Coturn 4.15.0 Security
  • Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
  • Bind mobility session-resume to the original allocation owner — a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
  • Reject ACME requests via signed 400 response instead of silently dropping them.
  • Reset the reused UDP receive-buffer offset in the DTLS listener.
  • Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire.
  • Fixed a uint16_t truncation overflow when computing STUN message length.
  • Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
  • Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP subnegotiation parsing to the buffer end.
  • NULL-terminated the HTTP request buffer before it is logged verbatim; switched apputils.c to bounded snprintf.
New features
  • RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peer→client traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
  • --drain-min-allocations — a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
  • --log-min-level (log_min_level in the config file) — a real minimum-log-level filter, since -v/--verbose had little effect on turnserver logging.
  • Alternate-server TCP/UDP distinction — alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
  • Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.
Reliability and correctness fixes
  • Fixed the remaining misaligned wire-buffer accesses and added alignment-safe turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
  • Fixed uint32_t counter wraparound in the relay port allocator.
  • Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
  • Released the alternate-server list mutex when del_alt_server removes the last entry, fixing a deadlock.
  • setgroups is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
  • Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
  • Cast to unsigned char before isspace() in config-file parsing.
  • Log an explicit error when a configured tls-listening-port cannot start.
  • Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure build.
Metrics
  • Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
  • turnutils_uclient now sends the SNI host name on TLS connections.
  • heap-allocates its STUN message buffers instead of using large stack buffers.

coturn-4.15.0-1.fc43

1 hour 29 minutes ago
FEDORA-2026-02d5b68472 Packages in this update:
  • coturn-4.15.0-1.fc43
Update description: Coturn 4.15.0 Security
  • Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
  • Bind mobility session-resume to the original allocation owner — a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
  • Reject ACME requests via signed 400 response instead of silently dropping them.
  • Reset the reused UDP receive-buffer offset in the DTLS listener.
  • Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire.
  • Fixed a uint16_t truncation overflow when computing STUN message length.
  • Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
  • Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP subnegotiation parsing to the buffer end.
  • NULL-terminated the HTTP request buffer before it is logged verbatim; switched apputils.c to bounded snprintf.
New features
  • RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peer→client traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
  • --drain-min-allocations — a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
  • --log-min-level (log_min_level in the config file) — a real minimum-log-level filter, since -v/--verbose had little effect on turnserver logging.
  • Alternate-server TCP/UDP distinction — alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
  • Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.
Reliability and correctness fixes
  • Fixed the remaining misaligned wire-buffer accesses and added alignment-safe turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
  • Fixed uint32_t counter wraparound in the relay port allocator.
  • Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
  • Released the alternate-server list mutex when del_alt_server removes the last entry, fixing a deadlock.
  • setgroups is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
  • Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
  • Cast to unsigned char before isspace() in config-file parsing.
  • Log an explicit error when a configured tls-listening-port cannot start.
  • Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure build.
Metrics
  • Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
  • turnutils_uclient now sends the SNI host name on TLS connections.
  • heap-allocates its STUN message buffers instead of using large stack buffers.

coturn-4.15.0-1.el8

1 hour 29 minutes ago
FEDORA-EPEL-2026-eb0c816bcd Packages in this update:
  • coturn-4.15.0-1.el8
Update description: Coturn 4.15.0 Security
  • Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC 8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than FINGERPRINT) must be ignored, but coturn processed the full attribute list. This also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
  • Bind mobility session-resume to the original allocation owner — a MOBILITY-TICKET resume is now only accepted from the user that created the allocation.
  • Reject ACME requests via signed 400 response instead of silently dropping them.
  • Reset the reused UDP receive-buffer offset in the DTLS listener.
  • Zeroed channel-data padding in stun_init_channel_message_str so uninitialized stack bytes never reach the wire.
  • Fixed a uint16_t truncation overflow when computing STUN message length.
  • Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
  • Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP subnegotiation parsing to the buffer end.
  • NULL-terminated the HTTP request buffer before it is logged verbatim; switched apputils.c to bounded snprintf.
New features
  • RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no longer hard-switches the allocation at REFRESH time. The server now does a make-before-break transition: peer→client traffic stays on the old 5-tuple until the client's first packet arrives on the new one, and only then is the old socket discarded.
  • --drain-min-allocations — a shutdown threshold for drain mode: the server exits once the live allocation count falls to the configured value instead of waiting for zero.
  • --log-min-level (log_min_level in the config file) — a real minimum-log-level filter, since -v/--verbose had little effect on turnserver logging.
  • Alternate-server TCP/UDP distinction — alternate servers are now tracked per transport, so TCP and UDP clients can be redirected to different alternate servers.
  • Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call site and abort on OOM rather than risking NULL-dereference or silent degradation in a long-running server.
Reliability and correctness fixes
  • Fixed the remaining misaligned wire-buffer accesses and added alignment-safe turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN attribute values were undefined behavior and a SIGBUS on strict-alignment targets.
  • Fixed uint32_t counter wraparound in the relay port allocator.
  • Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race; OpenSSL atexit cleanup is disabled in turnserver.
  • Released the alternate-server list mutex when del_alt_server removes the last entry, fixing a deadlock.
  • setgroups is no longer called unconditionally in mainrelay, fixing startup under environments where it's not permitted.
  • Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided leaks on realloc failure in TCP relay allocation.
  • Cast to unsigned char before isspace() in config-file parsing.
  • Log an explicit error when a configured tls-listening-port cannot start.
  • Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure build.
Metrics
  • Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
  • turnutils_uclient now sends the SNI host name on TLS connections.
  • heap-allocates its STUN message buffers instead of using large stack buffers.

libgit2_1.9-1.9.6-1.el9 rust-libgit2-sys-0.18.7-1.el9

10 hours 24 minutes ago
FEDORA-EPEL-2026-e57bda0a9c Packages in this update:
  • libgit2_1.9-1.9.6-1.el9
  • rust-libgit2-sys-0.18.7-1.el9
Update description:
  • Initial import of a package for libgit2 v1.9, in addition to v1.7 currently provided by the "libgit2" package.
  • Update the libgit2-sys Rust crate to version 0.18.7, corresponding to libgit2 v1.9.6.

The package for libgit2 v1.9 includes fixes for various security issues, including - but not limited to:

The EPEL package is not affected by GHSA-wfx7-g85r-q6vw since EPEL packages always linked the system PCRE2 and did not use the bundled PCRE.

libgit2_1.9-1.9.6-1.el10_2 rust-git2-0.20.4-3.el10_2 rust-libgit2-sys-0.18.7-1.el10_2

10 hours 26 minutes ago
FEDORA-EPEL-2026-94a24e8378 Packages in this update:
  • libgit2_1.9-1.9.6-1.el10_2
  • rust-git2-0.20.4-3.el10_2
  • rust-libgit2-sys-0.18.7-1.el10_2
Update description:
  • Update libgit2 to version 1.9.6.
  • Update the libgit2-sys Rust crate to the corresponding version 0.18.7.

This includes fixes for various security issues, including - but not limited to:

The EPEL package is not affected by GHSA-wfx7-g85r-q6vw since EPEL packages always linked the system PCRE2 and did not use the bundled PCRE.

libgit2_1.9-1.9.6-1.el10_3 rust-libgit2-sys-0.18.7-1.el10_3

10 hours 26 minutes ago
FEDORA-EPEL-2026-4ecdfe6003 Packages in this update:
  • libgit2_1.9-1.9.6-1.el10_3
  • rust-libgit2-sys-0.18.7-1.el10_3
Update description:
  • Update libgit2 to version 1.9.6.
  • Update the libgit2-sys Rust crate to the corresponding version 0.18.7.

This includes fixes for various security issues, including - but not limited to:

The EPEL package is not affected by GHSA-wfx7-g85r-q6vw since EPEL packages always linked the system PCRE2 and did not use the bundled PCRE.

libgit2-1.9.6-1.fc43 rust-libgit2-sys-0.18.7-1.fc43

10 hours 27 minutes ago
FEDORA-2026-61dffcfbe9 Packages in this update:
  • libgit2-1.9.6-1.fc43
  • rust-libgit2-sys-0.18.7-1.fc43
Update description:
  • Update libgit2 to version 1.9.6.
  • Update the libgit2-sys Rust crate to the corresponding version 0.18.7.

This includes fixes for various security issues, including - but not limited to:

The Fedora package is not affected by GHSA-wfx7-g85r-q6vw since Fedora packages always linked the system PCRE2 and did not use the bundled PCRE.

libgit2-1.9.6-1.fc44 rust-libgit2-sys-0.18.7-1.fc44

10 hours 27 minutes ago
FEDORA-2026-9d59721e9b Packages in this update:
  • libgit2-1.9.6-1.fc44
  • rust-libgit2-sys-0.18.7-1.fc44
Update description:
  • Update libgit2 to version 1.9.6.
  • Update the libgit2-sys Rust crate to the corresponding version 0.18.7.

This includes fixes for various security issues, including - but not limited to:

The Fedora package is not affected by GHSA-wfx7-g85r-q6vw since Fedora packages always linked the system PCRE2 and did not use the bundled PCRE.

libgit2_1.9-1.9.6-1.fc45 rust-libgit2-sys-0.18.7-1.fc45

10 hours 27 minutes ago
FEDORA-2026-7c3fc14617 Packages in this update:
  • libgit2_1.9-1.9.6-1.fc45
  • rust-libgit2-sys-0.18.7-1.fc45
Update description:
  • Update libgit2 to version 1.9.6.
  • Update the libgit2-sys Rust crate to the corresponding version 0.18.7.

This includes fixes for various security issues, including - but not limited to:

The Fedora package is not affected by GHSA-wfx7-g85r-q6vw since Fedora packages always linked the system PCRE2 and did not use the bundled PCRE.

Checked
31 minutes 40 seconds ago