Fedora Security Advisories

php-pecl-mongodb-1.20.1-3.el9

8 hours 43 minutes ago
FEDORA-EPEL-2026-d6aefc999f Packages in this update:
  • php-pecl-mongodb-1.20.1-3.el9
Update description: Backported from 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Backported from 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb-1.21.9-1.el10_2

9 hours 7 minutes ago
FEDORA-EPEL-2026-99ac8d2816 Packages in this update:
  • php-pecl-mongodb-1.21.9-1.el10_2
Update description: Version 1.21.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 1.21.7
  • PHPC-2745: Reject null bytes in namespaces and periods in database names [v1.21] by @GromNaN in #2059

php-pecl-mongodb2-2.1.9-1.fc44

9 hours 27 minutes ago
FEDORA-2026-358d3ccdfe Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc44
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-2.el10_2

9 hours 27 minutes ago
FEDORA-EPEL-2026-7d7ac5f0f9 Packages in this update:
  • php-pecl-mongodb2-2.1.9-2.el10_2
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

php-pecl-mongodb2-2.1.9-1.fc43

9 hours 27 minutes ago
FEDORA-2026-caf49a7828 Packages in this update:
  • php-pecl-mongodb2-2.1.9-1.fc43
Update description: Version 2.1.9
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968

roundcubemail-1.7.4-1.fc44

9 hours 57 minutes ago
FEDORA-2026-38c637be37 Packages in this update:
  • roundcubemail-1.7.4-1.fc44
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.7.4-1.fc45

9 hours 57 minutes ago
FEDORA-2026-6ab831c1c5 Packages in this update:
  • roundcubemail-1.7.4-1.fc45
Update description: Release 1.7.4
  • Use X-Content-Type-Options:nosniff for attachment previews and downloads (#10308)
  • zipdownload: Fix attachment filename sanitisation of backslash and control characters (#10325)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_2

10 hours 8 minutes ago
FEDORA-EPEL-2026-78f8bcff8a Packages in this update:
  • roundcubemail-1.6.19-1.el10_2
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.fc43

10 hours 8 minutes ago
FEDORA-2026-821349f438 Packages in this update:
  • roundcubemail-1.6.19-1.fc43
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_4

10 hours 8 minutes ago
FEDORA-EPEL-2026-37f493ad5e Packages in this update:
  • roundcubemail-1.6.19-1.el10_4
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

roundcubemail-1.6.19-1.el10_3

10 hours 8 minutes ago
FEDORA-EPEL-2026-d623f0849b Packages in this update:
  • roundcubemail-1.6.19-1.el10_3
Update description: Release 1.6.19
  • Fix PHP Warning: Undefined variable $tmp_command in .../plugins/markasjunk/drivers/cmd_learn.php (#10294)
  • Security: Fix CSS declaration smuggling via un-encoded ampersand emission
  • Security: Fix CSS property injection via body background attribute
  • Security: Fix email header injection via bare CR in the subject field
  • Security: Fix email header injection via C-escape \r in the recipient display name
  • Security: Fix email header injection via identity's organization field
  • Security: Fix zero-click stored XSS via TNEF MIME tag injection in the attachment URL
  • Security: Fix XSS in the HTML editor using text/enriched part content
  • Security: Fix cross-user access in contact group membership (add/remove) in the SQL address book
  • Security: Fix is_local_url() bypass via trailing-dot FQDN in stylesheet URL
  • Security: Fix remote content blocking bypass via CSS escapes in FuncIRI attributes
  • Security: Fix remote-content blocker bypass via SVG SMIL src animation
  • Security: Fix SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses

kernel-7.2.4-300.fc45 kernel-headers-7.2.4-300.fc45

15 hours 21 minutes ago
FEDORA-2026-a0019f8ab9 Packages in this update:
  • kernel-7.2.4-300.fc45
  • kernel-headers-7.2.4-300.fc45
Update description:

The 7.2.4 stable kernel update contains a number of important fixes across the tree.

The 7.2.3 stable kernel update contains a number of important fixes across the tree.

The 7.2.2 stable kernel update contains a single fix for CVE-2026-80590

The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

389-ds-base-3.3.1-1.fc45

16 hours 57 minutes ago
FEDORA-2026-c1e25a4642 Packages in this update:
  • 389-ds-base-3.3.1-1.fc45
Update description:
  • Resolves: rhbz#2492927 CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow [fedora-all]
  • Resolves: rhbz#2497652 CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [fedora-all]
  • Resolves: rhbz#2511796 CVE-2026-69152 389-ds-base: brace-expansion: Denial of Service via unbounded intermediate arrays [fedora-all]
  • Resolves: rhbz#2529450 CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [fedora-all]
  • Resolves: rhbz#2529451 CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [fedora-all]
  • Resolves: rhbz#2529452 CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [fedora-all]
  • Resolves: rhbz#2494775 CVE-2026-11611 389-ds-base: 389-ds-base: Content Sync plugin unbounded queue growth and race conditions [fedora-all]
  • Resolves: rhbz#2494825 CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation [fedora-all]
  • Resolves: rhbz#2494894 CVE-2026-11790 389-ds-base: 389-ds-base: PBKDF2 password storage plugin unbounded iteration count denial of service [fedora-all]
  • Resolves: rhbz#2494895 CVE-2026-11789 389-ds-base: 389-ds-base: SMD5 password storage plugin salt length integer underflow crash [fedora-all]
  • Resolves: rhbz#2509729 CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [fedora-all]
  • Resolves: rhbz#2513063 CVE-2026-19404 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort CleanAllRUV replication maintenance [fedora-all]
  • Resolves: rhbz#2494827 CVE-2026-11793 389-ds-base: 389-ds-base: stack buffer overflow in checkPrefix() algorithm ID parsing [fedora-all]
  • Resolves: rhbz#2494830 CVE-2026-11792 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string) [fedora-all]
  • Resolves: rhbz#2498023 CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification [fedora-all]

389-ds-base-3.1.5-2.fc43

16 hours 57 minutes ago
FEDORA-2026-0b8bc362b1 Packages in this update:
  • 389-ds-base-3.1.5-2.fc43
Update description:
  • Resolves: rhbz#2492927 CVE-2026-11774 389-ds-base: 389-ds-base: integer overflow in SASL packet length bypasses size limit leading to heap buffer overflow [fedora-all]
  • Resolves: rhbz#2497652 CVE-2026-11610 389-ds-base: 389-ds-base: Heap buffer overflow in sasl_io_recv() via padded SASL UNBIND [fedora-all]
  • Resolves: rhbz#2511796 CVE-2026-69152 389-ds-base: brace-expansion: Denial of Service via unbounded intermediate arrays [fedora-all]
  • Resolves: rhbz#2529450 CVE-2026-76560 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN [fedora-all]
  • Resolves: rhbz#2529451 CVE-2026-18453 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search [fedora-all]
  • Resolves: rhbz#2529452 CVE-2026-18355 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() [fedora-all]
  • Resolves: rhbz#2494775 CVE-2026-11611 389-ds-base: 389-ds-base: Content Sync plugin unbounded queue growth and race conditions [fedora-all]
  • Resolves: rhbz#2494825 CVE-2026-11884 389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation [fedora-all]
  • Resolves: rhbz#2494894 CVE-2026-11790 389-ds-base: 389-ds-base: PBKDF2 password storage plugin unbounded iteration count denial of service [fedora-all]
  • Resolves: rhbz#2494895 CVE-2026-11789 389-ds-base: 389-ds-base: SMD5 password storage plugin salt length integer underflow crash [fedora-all]
  • Resolves: rhbz#2509729 CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check [fedora-all]
  • Resolves: rhbz#2513063 CVE-2026-19404 389-ds-base: 389-ds-base: missing authorization allows anonymous clients to start or abort CleanAllRUV replication maintenance [fedora-all]
  • Resolves: rhbz#2494827 CVE-2026-11793 389-ds-base: 389-ds-base: stack buffer overflow in checkPrefix() algorithm ID parsing [fedora-all]
  • Resolves: rhbz#2494830 CVE-2026-11792 389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string) [fedora-all]
  • Resolves: rhbz#2498023 CVE-2026-15041 389-ds-base: 389-ds-base: Non-constant-time comparison in PBKDF2-SHA256 password verification [fedora-all]
Checked
7 minutes 3 seconds ago