Fedora Security Advisories

containernetworking-plugins-1.9.0-1.fc44

3 hours 48 minutes ago
FEDORA-2025-c67591d0a2 Packages in this update:
  • containernetworking-plugins-1.9.0-1.fc44
Update description:

Automatic update for containernetworking-plugins-1.9.0-1.fc44.

Changelog * Tue Dec 9 2025 Bradley G Smith <bradley.g.smith@gmail.com> - 1.9.0-1 - Update to release v1.9.0 - Resolves: rhbz#2420515 - Resolves CVE-2025-58188: rhbz#2411454, rhbz#2411189, rhbz#2410923 - Resolves CVE-2025-58185: rhbz#2410556, rhbz#2410277, rhbz#2409991 - Resolves CVE-2025-61723: rhbz#2409605, rhbz#2409325, rhbz#2409043 - Resolves CVE-2025-58189: rhbz#2408135, rhbz#2407858, rhbz#2407588 - Fixes CVE-2025-67499, a bug in the nftables backend for the portmap plugin - Additional changes

python-django4.2-4.2.27-1.fc42

1 day 1 hour ago
FEDORA-2025-b1379d950d Packages in this update:
  • python-django4.2-4.2.27-1.fc42
Update description:
  • Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer
  • Fixes CVE-2025-64459: Potential SQL injection via _connector keyword argument (4.2.26)
  • Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (4.2.25)
  • Fixes CVE-2025-59682: Potential partial directory-traversal via archive.extract() (4.2.25)
  • Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases (4.2.24)

python-django4.2-4.2.27-1.fc41

1 day 1 hour ago
FEDORA-2025-c08e0795c0 Packages in this update:
  • python-django4.2-4.2.27-1.fc41
Update description:
  • Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer
  • Fixes CVE-2025-64459: Potential SQL injection via _connector keyword argument (4.2.26)
  • Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (4.2.25)
  • Fixes CVE-2025-59682: Potential partial directory-traversal via archive.extract() (4.2.25)
  • Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases (4.2.24)

python-django4.2-4.2.27-1.el9

1 day 1 hour ago
FEDORA-EPEL-2025-f43c018f46 Packages in this update:
  • python-django4.2-4.2.27-1.el9
Update description:
  • Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer
  • Fixes CVE-2025-64459: Potential SQL injection via _connector keyword argument (4.2.26)
  • Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (4.2.25)
  • Fixes CVE-2025-59682: Potential partial directory-traversal via archive.extract() (4.2.25)
  • Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases (4.2.24)

python-django5-5.2.9-1.fc43

1 day 3 hours ago
FEDORA-2025-24dfd3b072 Packages in this update:
  • python-django5-5.2.9-1.fc43
Update description:
  • Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer
  • Fixes CVE-2025-64459: Potential SQL injection via _connector keyword argument (5.2.8)
  • Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (5.2.7)
  • Fixes CVE-2025-59682: Potential partial directory-traversal via archive.extract() (5.2.7)
  • Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases (5.2.6)

python-django5-5.2.9-1.fc42

1 day 3 hours ago
FEDORA-2025-45ee190318 Packages in this update:
  • python-django5-5.2.9-1.fc42
Update description:
  • Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL
  • Fixes CVE-2025-64460: Potential denial-of-service vulnerability in XML Deserializer
  • Fixes CVE-2025-64459: Potential SQL injection via _connector keyword argument (5.2.8)
  • Fixes CVE-2025-59681: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB (5.2.7)
  • Fixes CVE-2025-59682: Potential partial directory-traversal via archive.extract() (5.2.7)
  • Fixes CVE-2025-57833: Potential SQL injection in FilteredRelation column aliases (5.2.6)
Checked
59 minutes 27 seconds ago