Fedora Security Advisories

7zip-26.04-1.el9

2 hours 5 minutes ago
FEDORA-EPEL-2026-29947f7caa Packages in this update:
  • 7zip-26.04-1.el9
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_3

2 hours 5 minutes ago
FEDORA-EPEL-2026-e527d77d36 Packages in this update:
  • 7zip-26.04-1.el10_3
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_4

2 hours 5 minutes ago
FEDORA-EPEL-2026-7b07dd12c9 Packages in this update:
  • 7zip-26.04-1.el10_4
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

exim-4.100.1-1.el8

6 hours 11 minutes ago
FEDORA-EPEL-2026-71b80f48fa Packages in this update:
  • exim-4.100.1-1.el8
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el9

6 hours 18 minutes ago
FEDORA-EPEL-2026-61a5ea9fcd Packages in this update:
  • exim-4.100.1-1.el9
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el10_4

6 hours 22 minutes ago
FEDORA-EPEL-2026-15b5988543 Packages in this update:
  • exim-4.100.1-1.el10_4
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc43

6 hours 29 minutes ago
FEDORA-2026-d202b74c6a Packages in this update:
  • exim-4.100.1-1.fc43
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc44

6 hours 30 minutes ago
FEDORA-2026-4f9e436ed5 Packages in this update:
  • exim-4.100.1-1.fc44
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc45

6 hours 45 minutes ago
FEDORA-2026-3f88ddbd83 Packages in this update:
  • exim-4.100.1-1.fc45
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

curl-8.18.0-12.fc44

8 hours 14 minutes ago
FEDORA-2026-8efcd7a2a0 Packages in this update:
  • curl-8.18.0-12.fc44
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)
  • Fix HTTP/2 server push UAF (CVE-2026-18924)

curl-8.21.0-7.fc45

13 hours 12 minutes ago
FEDORA-2026-c2d4a9aa16 Packages in this update:
  • curl-8.21.0-7.fc45
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

chromium-154.0.8037.97-1.el10_4

14 hours 49 minutes ago
FEDORA-EPEL-2026-d1c26f4ffd Packages in this update:
  • chromium-154.0.8037.97-1.el10_4
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el9

14 hours 49 minutes ago
FEDORA-EPEL-2026-923ac1e238 Packages in this update:
  • chromium-154.0.8037.97-1.el9
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_3

14 hours 49 minutes ago
FEDORA-EPEL-2026-b3497ed039 Packages in this update:
  • chromium-154.0.8037.97-1.el10_3
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_2

14 hours 49 minutes ago
FEDORA-EPEL-2026-421dd4a529 Packages in this update:
  • chromium-154.0.8037.97-1.el10_2
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc43

14 hours 50 minutes ago
FEDORA-2026-02902c2fa0 Packages in this update:
  • chromium-154.0.8037.97-1.fc43
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC
Checked
28 minutes 7 seconds ago