Fedora Security Advisories

baresip-4.12.0-1.el8 libre-4.12.0-1.el8

57 minutes 28 seconds ago
FEDORA-EPEL-2026-0b2b7eab8b Packages in this update:
  • baresip-4.12.0-1.el8
  • libre-4.12.0-1.el8
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.el9 libre-4.12.0-1.el9

57 minutes 49 seconds ago
FEDORA-EPEL-2026-9b46dea8e0 Packages in this update:
  • baresip-4.12.0-1.el9
  • libre-4.12.0-1.el9
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.el10_2 libre-4.12.0-1.el10_2

58 minutes 11 seconds ago
FEDORA-EPEL-2026-a918489cff Packages in this update:
  • baresip-4.12.0-1.el10_2
  • libre-4.12.0-1.el10_2
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.el10_3 libre-4.12.0-1.el10_3

58 minutes 27 seconds ago
FEDORA-EPEL-2026-48c2e2c10b Packages in this update:
  • baresip-4.12.0-1.el10_3
  • libre-4.12.0-1.el10_3
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.el10_4 libre-4.12.0-1.el10_4

58 minutes 45 seconds ago
FEDORA-EPEL-2026-45c2ca66b6 Packages in this update:
  • baresip-4.12.0-1.el10_4
  • libre-4.12.0-1.el10_4
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.fc43 libre-4.12.0-1.fc43

59 minutes 3 seconds ago
FEDORA-2026-ff2a4f31ce Packages in this update:
  • baresip-4.12.0-1.fc43
  • libre-4.12.0-1.fc43
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.fc44 libre-4.12.0-1.fc44

59 minutes 21 seconds ago
FEDORA-2026-9931bf2b85 Packages in this update:
  • baresip-4.12.0-1.fc44
  • libre-4.12.0-1.fc44
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.fc45 libre-4.12.0-1.fc45

59 minutes 40 seconds ago
FEDORA-2026-563e1454d9 Packages in this update:
  • baresip-4.12.0-1.fc45
  • libre-4.12.0-1.fc45
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

baresip-4.12.0-1.fc46 libre-4.12.0-1.fc46

1 hour ago
FEDORA-2026-b8539090fe Packages in this update:
  • baresip-4.12.0-1.fc46
  • libre-4.12.0-1.fc46
Update description: Baresip v4.12.0 (2026-09-30)
  • Feature: Send Custom X-Headers on Outbound Calls
  • audio: thread-safe usage of psize and ptime in tx_thread()
  • jbuf: safer jbuf_set_id
  • audio: add mutex lock for aubuf statistics
  • test: add testing of peerconn and vidfilt
  • audio: fix format name in ausrc format mismatch warning
  • ci: remove brew fdk-aac package (discontinued)
  • test: fix peerconn and vidfilt
  • cmake: use variable for libdir libbaresip.pc.in
  • aureceiver: stats cleanup
  • rtprecv: tiny cleanup for startup
  • rtprecv: add stop flag fixes race condition
  • auresamp: alloc for implicit format conversion
  • aureceiver: fix decoder sample format and cleanup
  • audio: use RE_ATOMIC for muted flag
  • gst,play: fix err handling
libre v4.12.0 (2026-09-30)

0install-2.18-16.fc45 alt-ergo-2.4.3-5.fc45 apron-0.9.15-21.fc45 brltty-6.9.1-9.fc45 coccinelle-1.3.3-2.fc45 emacs-common-tuareg-3.0.1-17.fc45 flocq-4.2.2-7.fc45 frama-c-33.0-3.fc45 freetennis-0.4.8-69.fc45 gappalib-coq-1.11.0-5.fc45 guestfs-tools-1.57.3…

1 hour 7 minutes ago
FEDORA-2026-403bcf6fd8 Packages in this update:
  • 0install-2.18-16.fc45
  • alt-ergo-2.4.3-5.fc45
  • apron-0.9.15-21.fc45
  • brltty-6.9.1-9.fc45
  • coccinelle-1.3.3-2.fc45
  • emacs-common-tuareg-3.0.1-17.fc45
  • flocq-4.2.2-7.fc45
  • frama-c-33.0-3.fc45
  • freetennis-0.4.8-69.fc45
  • gappalib-coq-1.11.0-5.fc45
  • guestfs-tools-1.57.3-3.fc45
  • haxe-4.3.7-9.fc45
  • hevea-2.38-6.fc45
  • hivex-1.3.24-23.fc45
  • lem-2026.05.01-4.fc45
  • libguestfs-1.61.4-2.fc45
  • libnbd-1.25.7-4.fc45
  • nbdkit-1.48.1-2.fc45
  • not-ocamlfind-0.15-2.fc45
  • ocaml-5.5.1-1.fc45
  • ocaml-afl-persistent-1.4-12.fc45
  • ocaml-alcotest-1.9.1-10.fc45
  • ocaml-astring-0.8.5-38.fc45
  • ocaml-atd-4.2.0-7.fc45
  • ocaml-augeas-0.7-10.fc45
  • ocaml-b0-0.0.6-3.fc45
  • ocaml-base-0.17.3-10.fc45
  • ocaml-base64-3.5.2-7.fc45
  • ocaml-benchmark-1.7-10.fc45
  • ocaml-biniou-1.2.2-21.fc45
  • ocaml-bin-prot-0.17.0-14.fc45
  • ocaml-bisect-ppx-2.8.3-25.fc45
  • ocaml-bos-0.3.0-5.fc45
  • ocaml-cairo-0.6.5-11.fc45
  • ocaml-calendar-3.0.0-24.fc45
  • ocaml-camlbz2-0.8.0-15.fc45
  • ocaml-camlidl-1.13-9.fc45
  • ocaml-camlimages-5.0.5-14.fc45
  • ocaml-camlp5-8.05.02-3.fc45
  • ocaml-camlp5-buildscripts-0.07-4.fc45
  • ocaml-camlpdf-2.9-6.fc45
  • ocaml-camlp-streams-5.0.1-26.fc45
  • ocaml-camomile-2.1.0-1.fc45
  • ocaml-capitalization-0.17.0-5.fc45
  • ocaml-cinaps-0.15.1-32.fc45
  • ocaml-cmdliner-2.1.1-4.fc45
  • ocaml-compiler-libs-janestreet-0.17.0-14.fc45
  • ocaml-cpdf-2.9-4.fc45
  • ocaml-cppo-1.8.0-10.fc45
  • ocaml-crowbar-0.2.2-7.fc45
  • ocaml-cryptokit-1.21.1-3.fc45
  • ocaml-csexp-1.5.2-22.fc45
  • ocaml-csv-2.4-34.fc45
  • ocaml-ctypes-0.24.0-9.fc45
  • ocaml-cudf-0.10-21.fc45
  • ocaml-curl-0.10.0-9.fc45
  • ocaml-curses-1.0.12-3.fc45
  • ocaml-dbus-0.30-67.fc45
  • ocaml-domain-name-0.5.0-4.fc45
  • ocaml-dose3-7.0.0-43.fc45
  • ocaml-dune-3.24.2-2.fc45
  • ocaml-easy-format-1.3.4-21.fc45
  • ocaml-expat-1.3.0-21.fc45
  • ocaml-extlib-1.8.0-10.fc45
  • ocaml-facile-1.1.4-22.fc45
  • ocaml-fieldslib-0.17.0-14.fc45
  • ocaml-fileutils-0.6.6-10.fc45
  • ocaml-findlib-1.9.8-11.fc45
  • ocaml-fmt-0.11.0-11.fc45
  • ocaml-fpath-0.7.3-34.fc45
  • ocaml-gen-1.1-22.fc45
  • ocaml-gettext-0.5.0-15.fc45
  • ocaml-graphics-5.2.0-9.fc45
  • ocaml-gsl-1.25.1-11.fc45
  • ocamlify-0.1.0-9.fc45
  • ocaml-integers-0.8.0-4.fc45
  • ocaml-intrinsics-kernel-0.17.2-4.fc45
  • ocaml-jane-street-headers-0.17.0-13.fc45
  • ocaml-jsonm-1.0.2-16.fc45
  • ocaml-jst-config-0.17.0-13.fc45
  • ocaml-lablgl-1.07-24.fc45
  • ocaml-lablgtk-2.18.14-9.fc45
  • ocaml-lablgtk3-3.1.5-14.fc45
  • ocaml-labltk-8.06.16-3.fc45
  • ocaml-lacaml-11.1.1-10.fc45
  • ocaml-lambda-term-3.4.1-3.fc45
  • ocaml-libvirt-0.6.1.7-22.fc45
  • ocaml-linenoise-1.5.1-9.fc45
  • ocaml-logs-0.10.0-10.fc45
  • ocaml-luv-0.5.14-12.fc45
  • ocaml-lwt-6.1.2-3.fc45
  • ocaml-mccs-1.1.19-10.fc45
  • ocaml-mdx-2.6.0-3.fc45
  • ocaml-menhir-20260209-5.fc45
  • ocaml-merlin-5.8.1-2.fc45
  • ocaml-mew-0.1.0-39.fc45
  • ocaml-mew-vi-0.5.0-39.fc45
  • ocaml-mlgmpidl-1.3.0-23.fc45
  • ocaml-mlmpfr-4.2.1-16.fc45
  • ocamlmod-0.1.1-7.fc45
  • ocaml-monolith-20250922-8.fc45
  • ocaml-mtime-2.2.0-2.fc45
  • ocaml-mysql-1.2.4-24.fc45
  • ocaml-num-1.6-8.fc45
  • ocaml-obuild-0.3.0-3.fc45
  • ocaml-ocamlbuild-0.16.1-8.fc45
  • ocaml-ocamlgraph-2.2.0-10.fc45
  • ocaml-ocamlnet-4.1.9-36.fc45
  • ocaml-ocp-indent-1.10.0-2.fc45
  • ocaml-ocplib-endian-1.2-28.fc45
  • ocaml-ocplib-simplex-0.4.1-19.fc45
  • ocaml-omake-0.10.7-11.fc45
  • ocaml-omd-1.3.2-9.fc45
  • ocaml-opam-0install-cudf-0.5.0-11.fc45
  • ocaml-opam-file-format-2.2.0-11.fc45
  • ocaml-ounit-2.2.7-23.fc45
  • ocaml-parmap-1.2.5-24.fc45
  • ocaml-parsexp-0.17.0-13.fc45
  • ocaml-patch-3.1.2-3.fc45
  • ocaml-pcre2-8.0.4-7.fc45
  • ocaml-perl4caml-0.9.5-123.fc45
  • ocaml-postgresql-5.4.0-3.fc45
  • ocaml-pp-2.0.0-11.fc45
  • ocaml-pprint-20230830-9.fc45
  • ocaml-ppx-assert-0.17.0-17.fc45
  • ocaml-ppx-base-0.17.0-15.fc45
  • ocaml-ppx-bench-0.17.1-6.fc45
  • ocaml-ppx-bin-prot-0.17.1-2.fc45
  • ocaml-ppx-cold-0.17.0-17.fc45
  • ocaml-ppx-compare-0.17.0-17.fc45
  • ocaml-ppx-custom-printf-0.17.0-17.fc45
  • ocaml-ppx-derivers-1.2.1-48.fc45
  • ocaml-ppx-deriving-6.2.0-1.fc45
  • ocaml-ppx-deriving-yaml-0.5.0-1.fc45
  • ocaml-ppx-deriving-yojson-3.10.0-11.fc45
  • ocaml-ppx-enumerate-0.17.0-17.fc45
  • ocaml-ppx-expect-0.17.3-10.fc45
  • ocaml-ppx-fields-conv-0.17.0-17.fc45
  • ocaml-ppx-globalize-0.17.2-10.fc45
  • ocaml-ppx-hash-0.17.0-17.fc45
  • ocaml-ppx-here-0.17.0-17.fc45
  • ocaml-ppx-inline-test-0.17.1-10.fc45
  • ocaml-ppx-let-0.17.1-10.fc45
  • ocaml-ppxlib-0.38.0-5.fc45
  • ocaml-ppxlib-jane-0.17.4-10.fc45
  • ocaml-ppx-optcomp-0.17.1-10.fc45
  • ocaml-ppx-sexp-conv-0.17.1-10.fc45
  • ocaml-ppx-stable-witness-0.17.0-17.fc45
  • ocaml-ppx-variants-conv-0.17.1-10.fc45
  • ocaml-psmt2-frontend-0.4.0-33.fc45
  • ocaml-ptmap-2.0.5-32.fc45
  • ocaml-pyml-20250807-8.fc45
  • ocaml-qcheck-0.91-7.fc45
  • ocaml-qtest-2.11.2-33.fc45
  • ocaml-re-1.14.0-7.fc45
  • ocaml-react-1.2.2-23.fc45
  • ocaml-res-5.0.2-10.fc45
  • ocaml-result-1.5-36.fc45
  • ocaml-rresult-0.7.0-30.fc45
  • ocaml-SDL-0.9.1-80.fc45
  • ocaml-sedlex-3.7-8.fc45
  • ocaml-sexplib0-0.17.0-13.fc45
  • ocaml-sexplib-0.17.0-13.fc45
  • ocaml-sha-1.15.4-21.fc45
  • ocaml-spdx-licenses-1.5.0-2.fc45
  • ocaml-sqlite-5.4.2-1.fc45
  • ocaml-ssl-0.7.0-21.20230714gitffc634d.fc45
  • ocaml-stdcompat-22.0-1.fc45
  • ocaml-stdio-0.17.0-15.fc45
  • ocaml-stdlib-random-1.2.0-16.fc45
  • ocaml-store-0.2-5.fc45
  • ocaml-swhid-core-0.1-13.fc45
  • ocaml-testo-0.5.0-5.fc45
  • ocaml-time-now-0.17.0-15.fc45
  • ocaml-topkg-1.1.1-7.fc45
  • ocaml-trie-1.0.0-37.fc45
  • ocaml-unionfind-20260226-5.fc45
  • ocaml-uucd-18.0.0-1.fc45
  • ocaml-uucp-18.0.0-1.fc45
  • ocaml-uunf-18.0.0-2.fc45
  • ocaml-uuseg-18.0.0-2.fc45
  • ocaml-uutf-1.0.4-11.fc45
  • ocaml-variantslib-0.17.0-14.fc45
  • ocaml-version-4.1.4-1.fc45
  • ocaml-xml-light-2.5-22.fc45
  • ocaml-xmlm-1.4.0-21.fc45
  • ocaml-xmlrpc-light-0.6.1-92.fc45
  • ocaml-yaml-3.2.0-33.fc45
  • ocaml-yamlx-0.5.0-2.fc45
  • ocaml-yojson-3.0.0-14.fc45
  • ocaml-zarith-1.14-15.fc45
  • ocaml-zed-3.2.3-25.fc45
  • ocaml-zip-1.14-5.fc45
  • ocaml-zmq-5.3.0-16.fc45
  • opam-2.5.2-5.fc45
  • planets-0.1.13-55.fc45
  • plplot-5.15.0-117.fc45
  • prooftree-0.14-14.fc45
  • rocq-9.3.0-2.fc45
  • rocq-stdlib-9.2.0-1.fc45
  • supermin-5.3.5-12.fc45
  • unison-2.54.0-4.fc45
  • utop-2.17.0-5.fc45
  • virt-top-1.1.3-4.fc45
  • virt-v2v-2.13.7-2.fc45
  • why3-1.8.2-15.fc45
  • xen-4.21.1-11.fc45
  • z3-5.1.0-2.fc45
  • zenon-0.8.5-45.fc45
Update description:

This is a mass rebuild of the OCaml ecosystem with OCaml 5.5.1, which fixes two security bugs. See https://github.com/ocaml/ocaml/releases/tag/5.5.1 for details.

In addition, rocq has been updated to version 9.3.0, which also fixes several CVEs.

New upstream development version 1.61.4

New upstream development version 2.13.7

OpenImageIO-3.1.17.0-2.fc46 blender-5.2.2-5.fc46 luxcorerender-2.11.2-2.fc46 manifold-3.5.3-3.fc46 openvdb-13.1.0-3.fc46 usd-26.08-9.fc46

5 hours 11 minutes ago
FEDORA-2026-edf57cab54 Packages in this update:
  • blender-5.2.2-5.fc46
  • luxcorerender-2.11.2-2.fc46
  • manifold-3.5.3-3.fc46
  • OpenImageIO-3.1.17.0-2.fc46
  • openvdb-13.1.0-3.fc46
  • usd-26.08-9.fc46
Update description:

This update moves OpenVDB from:

libopenvdb.so.13.0

to:

libopenvdb.so.13.1

and includes coordinated rebuilds of:

openvdb OpenImageIO luxcorerender manifold openvkl usd blender

Side tag:

f46-build-side-151928

Tracker:

rhbz#2535782

Related bugs:

rhbz#2535783 rhbz#2535784 rhbz#2535787 rhbz#2535789 rhbz#2535790 rhbz#2535791 rhbz#2535792

Please test package installation/upgrades, dependency resolution against libopenvdb.so.13.1, and functionality in Blender, OpenImageIO, USD, LuxCoreRender, Manifold, and OpenVKL.

No affected package should retain a dependency on libopenvdb.so.13.0.

webkitgtk-2.54.1-1.fc43

9 hours 3 minutes ago
FEDORA-2026-9669c4bb36 Packages in this update:
  • webkitgtk-2.54.1-1.fc43
Update description:

Update to 2.54.1:

  • Allow pasting in-memory image data from clipboard.
  • Add User-Agent quirk for Amazon Luna.
  • Align the filter surface with the device pixel grid.
  • Fix rendering of scaled or transformed no-repeat background images.
  • Fix rendering of preserve-3d layers when a layer crosses the camera plane.
  • Fix SkiaCompositingLayer filter rendering under transforms.
  • Do not rasterize the part of a tile that the clip drops.
  • Skip non-composited frames when damage is empty.
  • Fix text deleted by input method delete-surrounding in contenteditable.
  • Fix several crashes and rendering issues.

Update to 2.54.0:

  • Switch web process compositor to use Skia instead of TextureMapper.
  • Improved damage handling that is now also used during the composition to limit the composited areas.
  • Implement GPU atlas creation and replay substitution for batched raster image uploads.
  • Media capability reporting is more accurate.
  • Video decoding limits are now respected in media capabilities queries.
  • Add new improved API for page favicons.
  • Add magnification property to WebKitWebView to handle visual scaling.
  • Add new API to allow setting a per-navigation custom User-Agent to WebKitWebsitePolicies.
  • Remove the option to use cairo for 2D rendering.

WebKit Security fixes from 2.54.0: CVE-2026-84635, CVE-2026-64753, CVE-2026-64715, CVE-2026-64778, CVE-2026-64779, CVE-2026-64780, CVE-2026-64782, CVE-2026-64784, CVE-2026-65331, CVE-2026-65332, CVE-2026-65333, CVE-2026-65334, CVE-2026-65335, CVE-2026-65336, CVE-2026-65337, CVE-2026-65338, CVE-2026-65340, CVE-2026-65341, CVE-2026-65351, CVE-2026-78376, CVE-2026-83596.

WebKit security fixes from 2.52.6: CVE-2026-43804, CVE-2026-64713, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783

This update also fixes a couple hundred or so ANGLE CVEs and several dozen Skia CVEs.

This update breaks some styles in Evolution. Sorry about that.

chromium-154.0.8037.92-1.fc45

13 hours 24 minutes ago
FEDORA-2026-0daef29dc3 Packages in this update:
  • chromium-154.0.8037.92-1.fc45
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.el10_2

13 hours 24 minutes ago
FEDORA-EPEL-2026-c0bda57b6d Packages in this update:
  • chromium-154.0.8037.92-1.el10_2
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.el10_4

13 hours 24 minutes ago
FEDORA-EPEL-2026-d31d4891d1 Packages in this update:
  • chromium-154.0.8037.92-1.el10_4
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.el9

13 hours 24 minutes ago
FEDORA-EPEL-2026-016a408698 Packages in this update:
  • chromium-154.0.8037.92-1.el9
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.el10_3

13 hours 24 minutes ago
FEDORA-EPEL-2026-bf22fee762 Packages in this update:
  • chromium-154.0.8037.92-1.el10_3
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.fc44

13 hours 24 minutes ago
FEDORA-2026-35b989661c Packages in this update:
  • chromium-154.0.8037.92-1.fc44
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE

chromium-154.0.8037.92-1.fc43

13 hours 24 minutes ago
FEDORA-2026-cd4e714c4e Packages in this update:
  • chromium-154.0.8037.92-1.fc43
Update description:

Update to 154.0.8037.92

* CVE-2026-102299: Type confusion in V8 * CVE-2026-102300: Uninitialized resource in WebGPU * CVE-2026-102301: Out of bounds write in GPU * CVE-2026-102302: Buffer overflow in V8 * CVE-2026-102303: Uninitialized resource in GPU * CVE-2026-102304: Use after free in Passwords * CVE-2026-102305: UI misrepresentation in SignIn * CVE-2026-102306: Use after free in Bluetooth * CVE-2026-102307: Uninitialized resource in Dawn * CVE-2026-102308: Use after free in Views * CVE-2026-102309: Use after free in FullScreen * CVE-2026-102310: Missing authorization in Payments * CVE-2026-102311: Uninitialized resource in GPU * CVE-2026-102312: UI misrepresentation in Omnibox * CVE-2026-102313: Uninitialized resource in ANGLE * CVE-2026-102314: UI misrepresentation in TabStrip * CVE-2026-102315: Uninitialized resource in Media * CVE-2026-102316: Use after free in Views * CVE-2026-102317: Improper privilege management in Mojo * CVE-2026-102318: Out of bounds read in WebGL * CVE-2026-102319: Uninitialized resource in GPU * CVE-2026-102320: Missing authorization in CORS * CVE-2026-102321: Type confusion in V8 * CVE-2026-102323: Type confusion in V8 * CVE-2026-102324: Use after free in PictureInPicture * CVE-2026-102325: Uninitialized resource in Skia * CVE-2026-102326: Type confusion in V8 * CVE-2026-102327: Incorrect authorization in WebView * CVE-2026-102328: Type confusion in V8 * CVE-2026-102329: Cross-site scripting in WebUI * CVE-2026-102330: Incorrect authorization in SiteIsolation * CVE-2026-102331: Buffer overflow in ANGLE
Checked
5 minutes 34 seconds ago