Fedora Security Advisories

curl-8.18.0-8.fc44

8 hours 14 minutes ago
FEDORA-2026-e691fbbfe7 Packages in this update:
  • curl-8.18.0-8.fc44
Update description:
  • Fix trailing dot domain super cookie (CVE-2026-8924)
  • Fix SSH improper host validation (CVE-2026-9547)
  • Fix password leak with netrc and user in URL (CVE-2026-8926)
  • Fix cross-origin Digest auth state leak (CVE-2026-11856)
  • Fix cross-proxy Digest auth state leak (CVE-2026-7168)
  • Fix OCSP stapling bypass with Apple SecTrust (CVE-2026-7009)

bird-3.3.2-1.el8

18 hours 33 minutes ago
FEDORA-EPEL-2026-67968fb664 Packages in this update:
  • bird-3.3.2-1.el8
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.fc43

18 hours 33 minutes ago
FEDORA-2026-3521e54a27 Packages in this update:
  • bird-3.3.2-1.fc43
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.el10_3

18 hours 33 minutes ago
FEDORA-EPEL-2026-77d4fb7557 Packages in this update:
  • bird-3.3.2-1.el10_3
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.el9

18 hours 33 minutes ago
FEDORA-EPEL-2026-ed091aeef8 Packages in this update:
  • bird-3.3.2-1.el9
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.fc44

18 hours 33 minutes ago
FEDORA-2026-c2b9288d46 Packages in this update:
  • bird-3.3.2-1.fc44
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.el10_2

18 hours 33 minutes ago
FEDORA-EPEL-2026-126e6ee1bd Packages in this update:
  • bird-3.3.2-1.el10_2
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

xen-4.20.4-1.fc43

22 hours 53 minutes ago
FEDORA-2026-9b1af4c793 Packages in this update:
  • xen-4.20.4-1.fc43
Update description:

update to xen 4.20.4 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508] x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]

python3.12-3.12.13-6.fc45

1 day 3 hours ago
FEDORA-2026-05338c2e02 Packages in this update:
  • python3.12-3.12.13-6.fc45
Update description:

Automatic update for python3.12-3.12.13-6.fc45.

Changelog * Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6 - Security fix for CVE-2026-15308 Resolves: rhbz#2498688 * Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5 - Skip UDP Lite tests if it's not supported - Fixes FTBFS on Linux kernel 7.1 and newer * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.12.13-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
Checked
4 minutes 13 seconds ago