Fedora Security Advisories

wordpress-6.9.10-1.el9

1 hour 21 minutes ago
FEDORA-EPEL-2026-15d6637cee Packages in this update:
  • wordpress-6.9.10-1.el9
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.fc44

1 hour 21 minutes ago
FEDORA-2026-5ada1f2961 Packages in this update:
  • wordpress-6.9.10-1.fc44
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.fc43

1 hour 21 minutes ago
FEDORA-2026-e0ebe50146 Packages in this update:
  • wordpress-6.9.10-1.fc43
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-6.9.10-1.el10_2

1 hour 21 minutes ago
FEDORA-EPEL-2026-b799c5dced Packages in this update:
  • wordpress-6.9.10-1.el10_2
Update description: WordPress 6.9.10 Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.fc45

1 hour 29 minutes ago
FEDORA-2026-3c05ab9fa4 Packages in this update:
  • wordpress-7.1.3-1.fc45
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.el10_4

1 hour 29 minutes ago
FEDORA-EPEL-2026-0d5bab9c2d Packages in this update:
  • wordpress-7.1.3-1.el10_4
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

wordpress-7.1.3-1.el10_3

1 hour 29 minutes ago
FEDORA-EPEL-2026-98aa985c34 Packages in this update:
  • wordpress-7.1.3-1.el10_3
Update description: WordPress 7.1.3 Maintenance and Security Release

Security updates included in this release

  • A stored XSS on the Comments administration page, exploitable via pending comments, reported by Thomas Chauchefoin at Trail of Bits
  • A DoS issue in the WP_Http::make_absolute_url() method, reported by Anthropic
  • A second-Order SQL injection in WordPress WXR export, reported by Anthropic
  • A weakness allowing Author role users to sticky posts, reported by Anthropic
  • Unauthenticated disclosure of comments on private & unpublished posts, reported by Ananda Dhakal from Patchstack
  • Imgur embeds are vulnerable to XSS, reported by Zhengyu Liu, Jingcheng Yang, and Gavin Zhong
  • Forgeable parameters passed to the {status}_{type} hook can lead to action name collision, reported by Alex Concha of the WordPress security team

xorg-x11-server-21.1.25-1.fc44

1 hour 53 minutes ago
FEDORA-2026-013922e1cc Packages in this update:
  • xorg-x11-server-21.1.25-1.fc44
Update description:

Update to xserver 21.1.24, Security fixes for CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

socat-1.8.1.3-1.fc43

2 hours 35 minutes ago
FEDORA-2026-232ffc1325 Packages in this update:
  • socat-1.8.1.3-1.fc43
Update description:
  • Update to 1.8.1.3 (rhbz#2492929)
  • Fix for CVE-2026-56123 (rhbz#2535043)

socat-1.8.1.3-1.fc44

2 hours 35 minutes ago
FEDORA-2026-4172dae890 Packages in this update:
  • socat-1.8.1.3-1.fc44
Update description:
  • Update to 1.8.1.3 (rhbz#2492929)
  • Fix for CVE-2026-56123 (rhbz#2535043)

socat-1.8.1.3-1.fc45

2 hours 36 minutes ago
FEDORA-2026-ddab5501ea Packages in this update:
  • socat-1.8.1.3-1.fc45
Update description:
  • Update to 1.8.1.3 (rhbz#2492929)
  • Fix for CVE-2026-56123 (rhbz#2535043)

socat-1.8.1.3-1.fc46

2 hours 50 minutes ago
FEDORA-2026-3bb7b0bc5a Packages in this update:
  • socat-1.8.1.3-1.fc46
Update description:

Automatic update for socat-1.8.1.3-1.fc46.

Changelog * Tue Oct 6 2026 Martin Osvald <mosvald@redhat.com> - 1.8.1.3-1 - Update to 1.8.1.3 (rhbz#2492929) - Fix for CVE-2026-56123 (rhbz#2535043)

xorg-x11-server-21.1.25-1.fc45

3 hours 22 minutes ago
FEDORA-2026-11378d4ce0 Packages in this update:
  • xorg-x11-server-21.1.25-1.fc45
Update description:

Update to xserver 21.1.24, Security fixes for CVE-2026-88812, CVE-2026-93515, CVE-2026-93516, CVE-2026-93517, CVE-2026-93518, CVE-2026-93519, CVE-2026-93520, CVE-2026-93521, CVE-2026-93522, CVE-2026-93523, CVE-2026-93524, CVE-2026-93536

sudo-1.9.17-17.p2.fc46

3 hours 33 minutes ago
FEDORA-2026-da6797fbc8 Packages in this update:
  • sudo-1.9.17-17.p2.fc46
Update description:

Automatic update for sudo-1.9.17-17.p2.fc46.

Changelog * Tue Oct 6 2026 Alejandro López <allopez@redhat.com> - 1.9.17-17.p2 - Fix CVE-2026-96512 - Resolves: rhbz#2539401

7zip-26.04-1.el9

14 hours 51 minutes ago
FEDORA-EPEL-2026-29947f7caa Packages in this update:
  • 7zip-26.04-1.el9
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_3

14 hours 51 minutes ago
FEDORA-EPEL-2026-e527d77d36 Packages in this update:
  • 7zip-26.04-1.el10_3
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

Checked
11 minutes 11 seconds ago