opensc-0.27.1-1.fc42
- opensc-0.27.1-1.fc42
New upstream release (#2442363) fixing various security issues
New upstream release (#2442363) fixing various security issues
Update to latest release
Update to latest release
Update to latest release
Update to latest upstream
Update to latest upstream
Update to latest upstream
upstream update, fixes security-related bugs
CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files.
CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0.
upstream update, fixes security-related bugs
CVE-2026-27456 - mount(8) TOCTOU symlink attack via loop device. The SUID mount follows symlinks when resolving loop backing file paths. On systems where non-root users are permitted to mount loop devices (via 'user' option in fstab), this allows access to arbitrary files.
CWE-190 - Integer overflow in libblkid parse_dos_extended(). A crafted MBR disk image can cause uint32_t wraparound in EBR chain processing, causing reported partitions to not match the on-disk layout. Tools like udisks may then register a partition at logical sector 0.
update to 1.154.0
update to 1.154.0
update to 1.154.0
Automatic update for fido-device-onboard-0.5.5-8.fc44.
Changelog for fido-device-onboard * Wed Apr 01 2026 Peter Robinson <pbrobinson@fedoraproject.org> - 0.5.5-8 - Rebuild for CVE-2026-25727, CVE-2026-33056 * Sun Mar 15 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0.5.5-7 - In Fedora, update nix dependency from 0.26 to 0.31Automatic update for fido-device-onboard-0.5.5-8.fc43.
Changelog for fido-device-onboard * Wed Apr 01 2026 Peter Robinson <pbrobinson@fedoraproject.org> - 0.5.5-8 - Rebuild for CVE-2026-25727, CVE-2026-33056 * Sun Mar 15 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 0.5.5-7 - In Fedora, update nix dependency from 0.26 to 0.31 * Mon Feb 02 2026 Maxwell G <maxwell@gtmx.me> - 0.5.5-6 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.5.5-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Oct 10 2025 Maxwell G <maxwell@gtmx.me> - 0.5.5-4 - Rebuild for golang 1.25.2fix CVE-2026-25646: heap buffer overflow in png_set_quantize
fix CVE-2026-25646: heap buffer overflow in png_set_quantize
fix CVE-2026-25646: heap buffer overflow in png_set_quantize
fix CVE-2026-25646: heap buffer overflow in png_set_quantize
fix CVE-2026-25646: heap buffer overflow in png_set_quantize
fix CVE-2026-25646: heap buffer overflow in png_set_quantize