perl-DBI-1.651-1.fc44
- perl-DBI-1.651-1.fc44
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
Update to 0.19.1
Update to 0.19.1
Update to 0.19.1
Automatic update for kronosnet-1.35-1.fc45.
Changelog * Mon Jul 20 2026 Fabio M. Di Nitto <fdinitto@redhat.com> - 1.35-1 - New upstream release - CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850) - CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852) - CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864) - tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets - libnozzle: Introduce test macros similar to libknet - docs: convert README to markdown format * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_RebuildUpdate to 0.19.1
Update to 0.19.1
Automatic update for nodejs22-22.23.1-2.fc45.
Changelog * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-2 - CVE-2026-42338 ip-address HTML escaping fix (rhbz#2487625) * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-1 - Update to version 22.23.1 (rhbz#2477273). * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:22.22.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_RebuildUpdate to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
Backport fixes for CVE-2026-59197 and CVE-2026-54058.
Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.