Fedora Security Advisories

exim-4.100.1-1.fc44

16 minutes 39 seconds ago
FEDORA-2026-4f9e436ed5 Packages in this update:
  • exim-4.100.1-1.fc44
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc45

30 minutes 48 seconds ago
FEDORA-2026-3f88ddbd83 Packages in this update:
  • exim-4.100.1-1.fc45
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

curl-8.18.0-12.fc44

2 hours ago
FEDORA-2026-8efcd7a2a0 Packages in this update:
  • curl-8.18.0-12.fc44
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)
  • Fix HTTP/2 server push UAF (CVE-2026-18924)

curl-8.21.0-7.fc45

6 hours 57 minutes ago
FEDORA-2026-c2d4a9aa16 Packages in this update:
  • curl-8.21.0-7.fc45
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

chromium-154.0.8037.97-1.el10_4

8 hours 35 minutes ago
FEDORA-EPEL-2026-d1c26f4ffd Packages in this update:
  • chromium-154.0.8037.97-1.el10_4
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el9

8 hours 35 minutes ago
FEDORA-EPEL-2026-923ac1e238 Packages in this update:
  • chromium-154.0.8037.97-1.el9
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_3

8 hours 35 minutes ago
FEDORA-EPEL-2026-b3497ed039 Packages in this update:
  • chromium-154.0.8037.97-1.el10_3
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_2

8 hours 35 minutes ago
FEDORA-EPEL-2026-421dd4a529 Packages in this update:
  • chromium-154.0.8037.97-1.el10_2
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc43

8 hours 35 minutes ago
FEDORA-2026-02902c2fa0 Packages in this update:
  • chromium-154.0.8037.97-1.fc43
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc45

8 hours 35 minutes ago
FEDORA-2026-53c8aca50a Packages in this update:
  • chromium-154.0.8037.97-1.fc45
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc44

8 hours 35 minutes ago
FEDORA-2026-bcdfa4c7db Packages in this update:
  • chromium-154.0.8037.97-1.fc44
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

flocq-4.2.2-3.fc44 gappalib-coq-1.11.0-1.fc44 rocq-9.3.0-1.fc44 rocq-stdlib-9.2.0-1.fc44 why3-1.8.2-11.fc44 zenon-0.8.5-41.fc44

17 hours 32 minutes ago
FEDORA-2026-62bbabcf11 Packages in this update:
  • flocq-4.2.2-3.fc44
  • gappalib-coq-1.11.0-1.fc44
  • rocq-9.3.0-1.fc44
  • rocq-stdlib-9.2.0-1.fc44
  • why3-1.8.2-11.fc44
  • zenon-0.8.5-41.fc44
Update description:

See https://rocq-prover.org/doc/v9.3/refman/changes.html#version-9-3 for changes in rocq 9.3.0.

See https://rocq-prover.org/doc/v9.2/refman-stdlib/changes.html for changes in rocq-stdlib 9.2.0.

See https://gitlab.inria.fr/gappa/coq/-/blob/master/NEWS.md for changes in gappalib-coq 1.11.0.

The other builds are rebuilds due to the above changes.

python-jupytext-1.19.6-1.fc43

20 hours 9 minutes ago
FEDORA-2026-3942ab86fd Packages in this update:
  • python-jupytext-1.19.6-1.fc43
Update description:

See https://github.com/jupytext/jupytext/blob/main/CHANGELOG.md for changes in versions 1.19.5 and 1.19.6. For this update, a patch has been applied that reverses the jupyterlab → jupyter-builder change for Fedora releases ≤ 45, since jupyter-builder is only available in F46 and later. Many CVEs have been fixed in this release.

aegisub-3.5.0-1.fc43

1 day 1 hour ago
FEDORA-2026-78a11da997 Packages in this update:
  • aegisub-3.5.0-1.fc43
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-2.fc44

1 day 1 hour ago
FEDORA-2026-0c6d4471fc Packages in this update:
  • aegisub-3.5.0-2.fc44
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-1.fc45

1 day 1 hour ago
FEDORA-2026-d296db490c Packages in this update:
  • aegisub-3.5.0-1.fc45
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

zabbix7.0-7.0.31-1.el10_3

1 day 1 hour ago
FEDORA-EPEL-2026-042a8bf4e4 Packages in this update:
  • zabbix7.0-7.0.31-1.el10_3
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el10_4

1 day 1 hour ago
FEDORA-EPEL-2026-3e248bfcbd Packages in this update:
  • zabbix7.0-7.0.31-1.el10_4
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el9

1 day 1 hour ago
FEDORA-EPEL-2026-0879abafaa Packages in this update:
  • zabbix7.0-7.0.31-1.el9
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

zabbix7.0-7.0.31-1.el8

1 day 1 hour ago
FEDORA-EPEL-2026-367fe24aeb Packages in this update:
  • zabbix7.0-7.0.31-1.el8
Update description:

Update to 7.0.31 (CVE-2026-59782, CVE-2026-59783, CVE-2026-59785, CVE-2026-59786, CVE-2026-59787)

Update to 7.0.28

Checked
16 minutes 31 seconds ago