Fedora Security Advisories

php-pecl-mongodb-1.20.1-3.el9

21 hours 36 minutes ago
FEDORA-EPEL-2026-d6aefc999f Packages in this update:
  • php-pecl-mongodb-1.20.1-3.el9
Update description: Backported from 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Backported from 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb-1.21.9-1.el10_2

21 hours 59 minutes ago
FEDORA-EPEL-2026-99ac8d2816 Packages in this update:
  • php-pecl-mongodb-1.21.9-1.el10_2
Update description: Version 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb2-2.1.9-1.fc44

22 hours 19 minutes ago
FEDORA-2026-358d3ccdfe Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc44
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-2.el10_2

22 hours 19 minutes ago
FEDORA-EPEL-2026-7d7ac5f0f9 Packages in this update:
  • php-pecl-mongodb2-2.1.9-2.el10_2
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-1.fc43

22 hours 19 minutes ago
FEDORA-2026-caf49a7828 Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc43
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

roundcubemail-1.7.4-1.fc44

22 hours 50 minutes ago
FEDORA-2026-38c637be37 Packages in this update:
  • roundcubemail-1.7.4-1.fc44
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.7.4-1.fc45

22 hours 50 minutes ago
FEDORA-2026-6ab831c1c5 Packages in this update:
  • roundcubemail-1.7.4-1.fc45
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_2

23 hours 1 minute ago
FEDORA-EPEL-2026-78f8bcff8a Packages in this update:
  • roundcubemail-1.6.19-1.el10_2
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.fc43

23 hours 1 minute ago
FEDORA-2026-821349f438 Packages in this update:
  • roundcubemail-1.6.19-1.fc43
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_4

23 hours 1 minute ago
FEDORA-EPEL-2026-37f493ad5e Packages in this update:
  • roundcubemail-1.6.19-1.el10_4
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_3

23 hours 1 minute ago
FEDORA-EPEL-2026-d623f0849b Packages in this update:
  • roundcubemail-1.6.19-1.el10_3
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

kernel-7.2.4-300.fc45 kernel-headers-7.2.4-300.fc45

1 day 4 hours ago
FEDORA-2026-a0019f8ab9 Packages in this update:
  • kernel-7.2.4-300.fc45
  • kernel-headers-7.2.4-300.fc45
Update description:

The 7.2.4 stable kernel update contains a number of important fixes across the tree.

The 7.2.3 stable kernel update contains a number of important fixes across the tree.

The 7.2.2 stable kernel update contains a single fix for CVE-2026-80590

The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

Checked
54 minutes 17 seconds ago