libgit2-1.9.2-1.fc42
- libgit2-1.9.2-1.fc42
Update to version 1.9.2.
Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2
Update to version 1.9.2.
Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.9.2
x86: buffer overrun with shadow paging + tracing [XSA-477, CVE-2025-58150] x86: incomplete IBPB for vCPU isolation [XSA-479, CVE-2026-23553]
Release notes for xrdp v0.10.5 (2026/01/27)
Security fixes
New features
Bug fixes
Internal changes
Release notes for xorgxrdp v0.10.5 (2026/01/28)
Bug fixes
Internal changes
Release notes for xrdp v0.10.5 (2026/01/27)
Security fixes
New features
Bug fixes
Internal changes
Release notes for xorgxrdp v0.10.5 (2026/01/28)
Bug fixes
Internal changes
Release notes for xrdp v0.10.5 (2026/01/27)
Security fixes
New features
Bug fixes
Internal changes
Release notes for xorgxrdp v0.10.5 (2026/01/28)
Bug fixes
Internal changes
Release notes for xrdp v0.10.5 (2026/01/27)
Security fixes
New features
Bug fixes
Internal changes
Release notes for xorgxrdp v0.10.5 (2026/01/28)
Bug fixes
Internal changes
Backport the fix for CVE-2026-24486 / GHSA-wp53-j4wj-2cfg: drop directory path from filename in File.
This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don't believe the vulnerable codepaths were exposed by openQA's use of lodash.
Don't crash on parsing PKCS#12 without MAC Resolves: CVE-2025-11187 Resolves: CVE-2025-15467 Resolves: CVE-2025-69419
Resolves: CVE-2025-15467 Resolves: CVE-2025-15468 Resolves: CVE-2025-15469 Resolves: CVE-2025-66199 Resolves: CVE-2025-68160 Resolves: CVE-2025-69418 Resolves: CVE-2025-69420 Resolves: CVE-2025-69421 Resolves: CVE-2025-69419 Resolves: CVE-2026-22795 Resolves: CVE-2026-22796 Resolves: CVE-2025-11187
January 2026 annual updates
January 2026 annual updates
January 2026 annual updates
January 2026 annual updates
January 2026 security update
January 2026 annual updates
January 2026 security update
Security fix for CVE-2026-24486 / GHSA-wp53-j4wj-2cfg.
0.0.22 (2026-01-25)Update vendor bundle, fixes CVE-2025-13465.
Update vendor bundle, fixes CVE-2025-13465.
Regenerate vendor tarball. Fixes CVE-2025-13465.
Regenerate vendor tarball. Fixes CVE-2025-13465.