php-phpseclib-2.0.55-1.fc43
- php-phpseclib-2.0.55-1.fc43
Update to v2.0.55 - contains fix for CVE-2026-44167
Update to v2.0.55 - contains fix for CVE-2026-44167
Update to v2.0.55 - contains fix for CVE-2026-44167
Three defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedThree defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedThree defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedThree defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedThree defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedThree defaults changed in this release. Read these before upgrading.
DTLS listeners are now opt-in. The server no longer starts DTLS listeners unless --dtls is given. A deployment that relied on DTLS being up by default will stop serving DTLS clients after the upgrade, without an error. The deprecated --no-dtls / --no-dtls=false spellings are still accepted and now warn.
Stateless nonce is on by default. Challenge nonces are authenticated timestamp cookies rather than a random value stored per session, so unauthenticated UDP requests are answered from the listener without allocating a session. Two consequences:
The default log line changed. Timestamps are ISO-8601 with millisecond precision, the thread id is gone, the field delimiter is a single space instead of :, and each record now occupies exactly one line. Log shippers and any downstream parsing will need updating; the default line is now:
2026-08-02T17:32:31.297-0700 INFO Listener address to use: 127.0.0.1--new-log-timestamp=false restores the legacy seconds-since-start counter.
Security fixesThree fixes in this release came through the private advisory process. Advisories are still in preparation; this section will be updated with their identifiers once they are published.
Upgrading is recommended for anyone running --mobility, DTLS, or accepting EVEN-PORT allocations.
What's ChangedUpdate to 2.119.0.
Update to 2.119.0.
Update to 2.119.0.
Update to 2.119.0.
chromium-151.0.7922.108 security release fix 41 CVE
chromium-151.0.7922.108 security release fix 41 CVE
chromium-151.0.7922.108 security release fix 41 CVE
chromium-151.0.7922.108 security release fix 41 CVE
chromium-151.0.7922.108 security release fix 41 CVE
This mitigates a vulnerability that allowed a specially crafted file to trigger execution of attacker-controlled arbitrary Emacs Lisp code immediately when the file is visited in Emacs (before the file's malicious contents are even displayed). https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574
Update to latest upstream version
Update to latest upstream version