Fedora Security Advisories

nsd-4.15.1-1.el10_3

3 hours 57 minutes ago
FEDORA-EPEL-2026-b69054a78f Packages in this update:
  • nsd-4.15.1-1.el10_3
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.fc44

3 hours 57 minutes ago
FEDORA-2026-bf1539678e Packages in this update:
  • nsd-4.15.1-1.fc44
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.el10_2

3 hours 57 minutes ago
FEDORA-EPEL-2026-4a0c7835ec Packages in this update:
  • nsd-4.15.1-1.el10_2
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.el10_4

3 hours 57 minutes ago
FEDORA-EPEL-2026-c16f6b76bf Packages in this update:
  • nsd-4.15.1-1.el10_4
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.el9

3 hours 57 minutes ago
FEDORA-EPEL-2026-5064a05224 Packages in this update:
  • nsd-4.15.1-1.el9
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.fc45

3 hours 57 minutes ago
FEDORA-2026-c56ac69334 Packages in this update:
  • nsd-4.15.1-1.fc45
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

nsd-4.15.1-1.fc43

3 hours 57 minutes ago
FEDORA-2026-3ff003d397 Packages in this update:
  • nsd-4.15.1-1.fc43
Update description:

BUG FIXES:

Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to Claude and Ada Logics for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1). Thanks to Akhil Koul (https://github.com/akoul) for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options. Thanks to Qifan Zhang, Palo Alto Networks for the report Thanks to afldl zhangph@yandex.com for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items. Thanks to Qifan Zhang, Palo Alto Networks for the report https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt

squidclamav-7.5-1.el9

6 hours 18 minutes ago
FEDORA-EPEL-2026-1bc4040b98 Packages in this update:
  • squidclamav-7.5-1.el9
Update description:

Upgrade to new upstream version CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability

squidclamav-7.5-1.el8

6 hours 20 minutes ago
FEDORA-EPEL-2026-31efc13ba7 Packages in this update:
  • squidclamav-7.5-1.el8
Update description:

Upgrade to new upstream version CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability

kernel-7.2.1-300.fc45

14 hours 24 minutes ago
FEDORA-2026-b02404c8c0 Packages in this update:
  • kernel-7.2.1-300.fc45
Update description:

The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.11-200.fc44

14 hours 25 minutes ago
FEDORA-2026-fd4ffe7527 Packages in this update:
  • kernel-7.1.11-200.fc44
Update description:

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.11-100.fc43

14 hours 25 minutes ago
FEDORA-2026-25d7c1eb61 Packages in this update:
  • kernel-7.1.11-100.fc43
Update description:

The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

curl-8.15.0-9.fc43

19 hours 9 minutes ago
FEDORA-2026-f903f9ff11 Packages in this update:
  • curl-8.15.0-9.fc43
Update description:
  • fix proto-default skips SSH verification (CVE-2026-12064)
  • fix wrong STARTTLS connection reuse (CVE-2026-8286)
  • fix SASL double-free (CVE-2026-8925)
  • fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
  • fix exposing HTTP/3 early data (CVE-2026-9545)
  • fix UAF after pause in socket callback (CVE-2026-9080)

composer-2.10.3-1.el10_3

22 hours 30 minutes ago
FEDORA-EPEL-2026-9a4c6ee5c5 Packages in this update:
  • composer-2.10.3-1.el10_3
Update description: Version 2.10.3 - 2026-08-27
  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)

composer-2.10.3-1.el9

22 hours 30 minutes ago
FEDORA-EPEL-2026-bf7afd5dc2 Packages in this update:
  • composer-2.10.3-1.el9
Update description: Version 2.10.3 - 2026-08-27
  • Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
  • Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
  • Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
  • Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
  • Fixed PHP 8.6 deprecation warnings (#12967, #13028)
  • Fixed error output when a policy blocks a package version to be clearer (#12993)
  • Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
  • Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
  • Fixed forgejo support to handle empty repositories better (#12968)
  • Fixed FilterListApiClient not forwarding transport options (#13040)
Checked
56 minutes 37 seconds ago