kernel-7.1.4-101.fc43
- kernel-7.1.4-101.fc43
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important security issue with net/can.
nginx-mod-fancyindex:
Rebuild for 1.30.4nginx-mod-modsecurity:
Rebuild for 1.30.4nginx-mod-naxsi:
Rebuild for 1.30.4nginx-mod-headers-more:
Rebuild for 1.30.4nginx-mod-brotli:
Rebuild for 1.30.4nginx-mod-js-challenge:
Rebuild for 1.30.4nginx-mod-vts:
Rebuild for 1.30.4nginx:
update to 1.30.4 fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-564341.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and CVE-2026-60081
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
Update to 0.19.1
Update to 0.19.1
Update to 0.19.1
Automatic update for kronosnet-1.35-1.fc45.
Changelog * Mon Jul 20 2026 Fabio M. Di Nitto <fdinitto@redhat.com> - 1.35-1 - New upstream release - CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850) - CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852) - CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864) - tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets - libnozzle: Introduce test macros similar to libknet - docs: convert README to markdown format * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_RebuildUpdate to 0.19.1
Update to 0.19.1
Automatic update for nodejs22-22.23.1-2.fc45.
Changelog * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-2 - CVE-2026-42338 ip-address HTML escaping fix (rhbz#2487625) * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-1 - Update to version 22.23.1 (rhbz#2477273). * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:22.22.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_RebuildUpdate to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
nginx-mod-vts:
nginx-mod-brotli:
nginx-mod-fancyindex:
nginx-mod-headers-more:
nginx-mod-modsecurity:
nginx-mod-naxsi:
nginx:
nginx-mod-fancyindex:
nginx-mod-modsecurity:
nginx-mod-naxsi:
nginx-mod-headers-more:
nginx-mod-brotli:
nginx-mod-js-challenge:
nginx-mod-vts:
nginx:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.