Fedora Security Advisories

chromium-152.0.7977.75-1.el9

1 week 3 days ago
FEDORA-EPEL-2026-8b1140c82b Packages in this update:
  • chromium-152.0.7977.75-1.el9
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.el10_4

1 week 3 days ago
FEDORA-EPEL-2026-d2ab47ea82 Packages in this update:
  • chromium-152.0.7977.75-1.el10_4
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.75-1.fc45

1 week 3 days ago
FEDORA-2026-865fdc3e81 Packages in this update:
  • chromium-152.0.7977.75-1.fc45
Update description:
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

nagios-plugins-2.5-2.el9

1 week 4 days ago
FEDORA-EPEL-2026-b3ba209e5d Packages in this update:
  • nagios-plugins-2.5-2.el9
Update description:

Update to upstream (bz#2453492). check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

nagios-plugins-2.5-2.el10_4

1 week 4 days ago
FEDORA-EPEL-2026-df80b78e8b Packages in this update:
  • nagios-plugins-2.5-2.el10_4
Update description:

Update to upstream (bz#2453492). check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

nagios-plugins-2.5-2.fc43

1 week 4 days ago
FEDORA-2026-7ac5fb031f Packages in this update:
  • nagios-plugins-2.5-2.fc43
Update description:

Update to upstream (bz#2453492). check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

nagios-plugins-2.5-2.fc44

1 week 4 days ago
FEDORA-2026-c2fbd942bc Packages in this update:
  • nagios-plugins-2.5-2.fc44
Update description:

Update to upstream (bz#2453492). check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

kernel-7.2.3-300.fc45

1 week 5 days ago
FEDORA-2026-628af192f5 Packages in this update:
  • kernel-7.2.3-300.fc45
Update description:

The 7.2.3 stable kernel update contains a number of important fixes across the tree.

The 7.2.2 stable kernel update contains a single fix for CVE-2026-80590

The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.13-200.fc44

1 week 5 days ago
FEDORA-2026-0d885c0533 Packages in this update:
  • kernel-7.1.13-200.fc44
Update description:

The 7.1.13 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.13-100.fc43

1 week 5 days ago
FEDORA-2026-a7b1ccd14c Packages in this update:
  • kernel-7.1.13-100.fc43
Update description:

The 7.1.13 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

complyctl-1.0.0-1.fc44

1 week 5 days ago
FEDORA-2026-f33ade2ba6 Packages in this update:
  • complyctl-1.0.0-1.fc44
Update description:

This update aligns the package to the latest Upstream release, which is also the first stable version of complyctl.

It introduced the core redesign from OSCAL to Gemara. The project has gone through three pre-release milestones (alpha, beta, RC) with contributions from 11 people across 200+ commits. This release marks the point where the CLI surface, configuration format, provider gRPC API, and output formats are considered stable under semantic versioning. More information in https://github.com/complytime/complyctl/releases/tag/v1.0.0

The providers, formerly plugins, were also moved to their own repository and are no longer delivered in the same package of complyctl. A new package called complytime-providers is being introduced to Fedora repositories via https://bugzilla.redhat.com/show_bug.cgi?id=2526823

Checked
54 minutes 53 seconds ago