Fedora Security Advisories

pack-0.40.8-1.el9

5 hours 24 minutes ago
FEDORA-EPEL-2026-75bd5ec746 Packages in this update:
  • pack-0.40.8-1.el9
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.el10_2

5 hours 24 minutes ago
FEDORA-EPEL-2026-394b18b263 Packages in this update:
  • pack-0.40.8-1.el10_2
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc43

5 hours 25 minutes ago
FEDORA-2026-e6e0368149 Packages in this update:
  • pack-0.40.8-1.fc43
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

pack-0.40.8-1.fc44

5 hours 25 minutes ago
FEDORA-2026-8729dce4b8 Packages in this update:
  • pack-0.40.8-1.fc44
Update description:

Security update to pack 0.40.8

Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution via discarded SSH permissions Fixes GO-2026-4970: Root escape via symlink plus trailing slash in os package Fixes GO-2026-5856: Encrypted Client Hello privacy leak in crypto/tls

skopeo-1.22.2-2.fc44

6 hours 39 minutes ago
FEDORA-2026-9b2e56edf5 Packages in this update:
  • skopeo-1.22.2-2.fc44
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.26.5 which includes the fix.

skopeo-1.22.2-2.fc43

6 hours 39 minutes ago
FEDORA-2026-4d9a2870e5 Packages in this update:
  • skopeo-1.22.2-2.fc43
Update description:

Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.25.12 which includes the fix.

kernel-7.1.4-204.fc44

7 hours 20 minutes ago
FEDORA-2026-2b94d8d05c Packages in this update:
  • kernel-7.1.4-204.fc44
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

kernel-7.1.4-104.fc43

7 hours 20 minutes ago
FEDORA-2026-6503a6a639 Packages in this update:
  • kernel-7.1.4-104.fc43
Update description:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for issues with exploits in the wild.

bpfman-0.5.4-13.fc45

12 hours 26 minutes ago
FEDORA-2026-fa34dc95e6 Packages in this update:
  • bpfman-0.5.4-13.fc45
Update description:

Automatic update for bpfman-0.5.4-13.fc45.

Changelog * Wed Jul 22 2026 Daniel Mellado <dmellado@fedoraproject.org> - 0.5.4-13 - Bump vendored openssl to 0.10.78 / openssl-sys to 0.9.117 for OpenSSL 4.0 support * Wed Jul 15 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.5.4-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 12 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 0.5.4-11 - Rebuilt for openssl 4.0 * Tue Apr 28 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-10 - update sources and spec * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-9 - add source vendor * Tue Apr 7 2026 Mario Fernandez <mariofer@redhat.com> - 0.5.4-8 - Fix CVE-2026-25727: Bump time to 0.3.47 - closes rhbz#2438107

ImageMagick-6.9.13.52-2.el8

17 hours 6 minutes ago
FEDORA-EPEL-2026-c4fcc3f6fd Packages in this update:
  • ImageMagick-6.9.13.52-2.el8
Update description:

Add upstream patch to revert the unexpected soname change

Update to upstream 6.9.13-52

valkey-9.0.5-1.fc44

22 hours 8 minutes ago
FEDORA-2026-3d18a65cc4 Packages in this update:
  • valkey-9.0.5-1.fc44
Update description: Valkey 9.0.5 - Released Tue 21 July 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security Fixes
  • CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow an authenticated client to achieve remote code execution using CLIENT KILL (#4234)
  • CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across consumers, which could allow remote code execution. Reported by @z0v3r1n and @lifip. (#4073)
Bug Fixes
  • Strictly validate CRLF terminators when parsing the RESP protocol; malformed requests now get a protocol error instead of being misparsed by @enjoy-binbin (#2872)
  • Fix a use-after-free crash when creating slot import jobs during manual slot migrations by @twooster (#3283)
  • Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty before all inputs are processed by @sarthakaggarwal97 (#3342)
  • Fix HPERSIST sending a malformed reply that desynchronized the connection when used on a key of the wrong type by @madolson (#3516)
  • Fix a crash from a race between IO threads and asynchronous client freeing by @deepakrn (#3458)
  • Fix a double free when loading a stream with corrupt consumer PEL data from RDB or RESTORE by @enjoy-binbin (#3498)
  • Fix listpack corruption and a subsequent crash when XTRIM marks the last entry of a stream listpack node as deleted by @smkher (#3591)
  • Fix malformed replies when module callbacks build deferred-length arrays while a client's deferred reply buffer is active by @eifrah-aws (#3578)
  • Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
  • Fix a server crash when multiple RDMA clients disconnect at the same time by @quanyeyang (#3448)
  • Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed immediately by @ranshid (#3800)
  • Fix a use-after-free when a module unregisters the first registered cluster message receiver for a message type by @eifrah-aws (#3846)
  • Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the requested count by @cjx-zar (#4047)
  • Fix clients being left on the wrong database after module keyspace notifications for commands like MOVE and COPY by @enjoy-binbin (#4024)
  • Fix a Sentinel crash during coordinated failover when the connection to the old primary is disconnected by @lukepalmer (#4068)
  • Fix underestimation of client output buffer memory when replies reference shared objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
  • Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job queue by @jjuleslasarte (#3878)
  • Fix a crash when active hash field expiration leaves a single entry in a large expiration time-bucket by @ranshid (#3950)
  • Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE to an unreachable host, times out by @madolson (#3541)
  • Fix a potential crash from a dangling slot migration job reference when the migration client is reset by @murphyjacob4 (#3554)
  • Remove cached EVAL scripts when their scripting engine is unregistered, preventing dangling engine references by @eifrah-aws (#3503)
  • Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on an invalid COUNT by @bandalgomsu (#3568)
  • Fix a crash when a slot migration target node is removed from the cluster before the migration connects by @chenshi5012 (#3596)
  • Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a NULL key by @yaronsananes (#3610)
  • Fix an assertion failure in hash field expiration commands when a module blocks the client in a keyspace notification by @enjoy-binbin (#3743)
  • Fix a cluster UPDATE log message reading shard IDs past their fixed-length buffer by @enjoy-binbin (#3942)
  • Fix undefined behavior in the failover delay calculation when cluster-node-timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
  • Reject zipmap RESTORE payloads with overflowing length fields that could cause out-of-bounds access on 32-bit builds by @madolson (#3920)
  • Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE load, preventing a later crash on skiplist conversion by @madolson (#3921)
  • Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23, caused by time value formatting mismatches by @chenshi5012 (#3787)
  • Fix corrupted client replies when IO threads are enabled, caused by a race between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
  • COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a Set for commands without subcommands by @rickrams (#3939)
  • The dual-channel replication RDB connection now announces the configured replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn (#2846)
  • Prevent replicas from processing stale cluster packets and incorrectly promoting themselves to an empty primary within a shard by @zhijun42 (#2811)
  • Send the replica version on the dual-channel RDB connection so full syncs of data like hash field TTLs no longer fail by @hpatro (#4105)
  • Fix slot migration failure handling running twice on ownership changes and an out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9 (#3723)
  • Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the limit, as documented by @enjoy-binbin (#3443)
  • Fix CONFIG REWRITE producing negative values for memory configs such as maxmemory when set to very large values by @enjoy-binbin (#3440)
  • Reject SENTINEL SET values containing control characters and safely quote Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
  • Reject control characters and delimiters in cluster AUX fields and validate cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws (#3848)
  • Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the option was set at startup by @enjoy-binbin (#4182)
  • Fix incorrect memory overhead reported for watched keys in client memory usage tracking by @enjoy-binbin (#3359)
  • Replica logs now report 'Connection reset by peer' instead of the misleading 'Success' when the primary closes the connection by @abmathur-ie (#3580)
  • Redact key names and user data from more log messages when hide-user-data-from-log is enabled by @zackcam (#3872)
  • Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds 2GB during disk-based sync by @chx9 (#3811)
  • Increase the maximum process title length from 255 to 1024 characters to avoid truncation with long installation paths by @pkhartsk (#3843)
  • valkey-cli --cluster del-node can now remove unreachable or failed nodes instead of failing with 'No such node ID' by @yang-z-o (#3209)
  • Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc builds by @bandalgomsu (#3281)
  • valkey-cli --cluster fix now spreads uncovered slots randomly across primaries instead of assigning them all to one node by @abmathur-ie (#3586)
Checked
19 minutes 37 seconds ago