Fedora Security Advisories

kbd-2.9.0-4.fc44

48 minutes 58 seconds ago
FEDORA-2026-71a5fbb962 Packages in this update:
  • kbd-2.9.0-4.fc44
Update description:

Fix openvt -u process matching to be more conservative (CVE-2026-72693)

perl-Net-OAuth-0.33-1.fc46

53 minutes 56 seconds ago
FEDORA-2026-96404091a4 Packages in this update:
  • perl-Net-OAuth-0.33-1.fc46
Update description:

Automatic update for perl-Net-OAuth-0.33-1.fc46.

Changelog * Thu Aug 27 2026 Xavier Bachelot <xacier@bachelot.org> - 0.33-1 - Update to 0.32 (RHBZ#2517683) - Fixes CVE-2026-72889 (RHBZ#2519409)

GitPython-3.1.60-1.el9

1 hour 30 minutes ago
FEDORA-EPEL-2026-42bb8a7265 Packages in this update:
  • GitPython-3.1.60-1.el9
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

GitPython-3.1.60-1.el10_3

1 hour 47 minutes ago
FEDORA-EPEL-2026-32e94b4cef Packages in this update:
  • GitPython-3.1.60-1.el10_3
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

GitPython-3.1.60-1.el10_4

2 hours 3 minutes ago
FEDORA-EPEL-2026-14e82d176b Packages in this update:
  • GitPython-3.1.60-1.el10_4
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

GitPython-3.1.60-1.fc43

2 hours 32 minutes ago
FEDORA-2026-e6bd4d25ab Packages in this update:
  • GitPython-3.1.60-1.fc43
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

bubblewrap-0.12.0-1.fc43

12 hours 51 minutes ago
FEDORA-2026-96e0765328 Packages in this update:
  • bubblewrap-0.12.0-1.fc43
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

bubblewrap-0.12.0-1.fc44

12 hours 52 minutes ago
FEDORA-2026-3d9bd126ce Packages in this update:
  • bubblewrap-0.12.0-1.fc44
Update description:
  • Update to 0.12.0
  • Fixes GHSA-pxhw-h44j-8pfx
  • Reset disposition of SIGCHLD, restoring normal subprocess management if bwrap(1) was run from a process that was ignoring that signal, such as Erlang or volumeicon

GitPython-3.1.60-1.fc44

12 hours 59 minutes ago
FEDORA-2026-32054fb87a Packages in this update:
  • GitPython-3.1.60-1.fc44
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

GitPython-3.1.60-1.fc45

17 hours 45 minutes ago
FEDORA-2026-63e7132525 Packages in this update:
  • GitPython-3.1.60-1.fc45
Update description:

Update to 3.1.60.

Fixes GHSA-g5vv-9gxw-82hx, GHSA-whh4-5q6c-9v3x, and GHSA-239g-whfq-7xj9.

bluez-5.87-6.fc43

17 hours 55 minutes ago
FEDORA-2026-d4eec45564 Packages in this update:
  • bluez-5.87-6.fc43
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-6.fc44

17 hours 56 minutes ago
FEDORA-2026-1fba3f22c9 Packages in this update:
  • bluez-5.87-6.fc44
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

bluez-5.87-7.fc45

17 hours 57 minutes ago
FEDORA-2026-84b4f1c43a Packages in this update:
  • bluez-5.87-7.fc45
Update description:

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.

Checked
40 minutes 38 seconds ago