Fedora Security Advisories

perl-DBI-1.651-1.fc44

59 minutes 56 seconds ago
FEDORA-2026-1c5ffc6018 Packages in this update:
  • perl-DBI-1.651-1.fc44
Update description:

1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081

kronosnet-1.35-1.fc44

3 hours 14 minutes ago
FEDORA-2026-db53330c8f Packages in this update:
  • kronosnet-1.35-1.fc44
Update description:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)

CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)

CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)

kronosnet-1.35-1.fc43

3 hours 14 minutes ago
FEDORA-2026-56568b6fe8 Packages in this update:
  • kronosnet-1.35-1.fc43
Update description:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)

CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)

CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)

kronosnet-1.35-1.fc45

3 hours 50 minutes ago
FEDORA-2026-3e85d87212 Packages in this update:
  • kronosnet-1.35-1.fc45
Update description:

Automatic update for kronosnet-1.35-1.fc45.

Changelog * Mon Jul 20 2026 Fabio M. Di Nitto <fdinitto@redhat.com> - 1.35-1 - New upstream release - CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850) - CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852) - CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864) - tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets - libnozzle: Introduce test macros similar to libknet - docs: convert README to markdown format * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

nodejs22-22.23.1-2.fc45

6 hours 12 minutes ago
FEDORA-2026-3298e71891 Packages in this update:
  • nodejs22-22.23.1-2.fc45
Update description:

Automatic update for nodejs22-22.23.1-2.fc45.

Changelog * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-2 - CVE-2026-42338 ip-address HTML escaping fix (rhbz#2487625) * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-1 - Update to version 22.23.1 (rhbz#2477273). * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:22.22.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

btrbk-0.32.7-1.fc43

7 hours 31 minutes ago
FEDORA-2026-1528cb06a7 Packages in this update:
  • btrbk-0.32.7-1.fc43
Update description:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943

btrbk-0.32.7-1.fc44

7 hours 32 minutes ago
FEDORA-2026-131c82812a Packages in this update:
  • btrbk-0.32.7-1.fc44
Update description:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943

opkssh-0.16.0-1.el10_3

23 hours 52 minutes ago
FEDORA-EPEL-2026-881ac51c15 Packages in this update:
  • opkssh-0.16.0-1.el10_3
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.el10_2

23 hours 53 minutes ago
FEDORA-EPEL-2026-cb5a2d1e66 Packages in this update:
  • opkssh-0.16.0-1.el10_2
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.fc43

23 hours 54 minutes ago
FEDORA-2026-168280f3c4 Packages in this update:
  • opkssh-0.16.0-1.fc43
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.fc44

23 hours 55 minutes ago
FEDORA-2026-a0bf40ecfe Packages in this update:
  • opkssh-0.16.0-1.fc44
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

python-pillow-11.3.0-10.fc43

1 day 10 hours ago
FEDORA-2026-fc2ded926e Packages in this update:
  • python-pillow-11.3.0-10.fc43
Update description:

Backport fixes for CVE-2026-59197 and CVE-2026-54058.

Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798

perl-Mojolicious-9.48-1.fc43

1 day 10 hours ago
FEDORA-2026-6f12b08313 Packages in this update:
  • perl-Mojolicious-9.48-1.fc43
Update description:

Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.

perl-Mojolicious-9.48-1.fc44

1 day 10 hours ago
FEDORA-2026-4334fd85bc Packages in this update:
  • perl-Mojolicious-9.48-1.fc44
Update description:

Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.

Checked
6 minutes 54 seconds ago