Fedora Security Advisories

bird-3.3.2-1.fc44

5 days 21 hours ago
FEDORA-2026-c2b9288d46 Packages in this update:
  • bird-3.3.2-1.fc44
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

bird-3.3.2-1.el10_2

5 days 21 hours ago
FEDORA-EPEL-2026-126e6ee1bd Packages in this update:
  • bird-3.3.2-1.el10_2
Update description: BIRD 3.3.2 (2026-07-30)
  • BGP: Fix stack buffer overflow in Flowspec NLRI decoder
  • BGP: Minor improvements in Flowspec parsing
  • BGP: Fix minor issues with send hold timer
  • Fix null byte handling in authentication keys
  • Pipe, L3VPN: Fix hostentry stripping
  • Filter: Fix zero arg handling
  • Logging: Fix use-after-free on failed rotation
  • CLI: Fix crashes in show route
  • Allocator: Pre-fill hot pages when entering RCU critical section
  • Fix obstacle cleanup
  • Update bird-users mailing list links

See also: https://trubka.network.cz/archives/list/bird-users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/

xen-4.20.4-1.fc43

6 days 2 hours ago
FEDORA-2026-9b1af4c793 Packages in this update:
  • xen-4.20.4-1.fc43
Update description:

update to xen 4.20.4 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508] x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]

python3.12-3.12.13-6.fc45

6 days 7 hours ago
FEDORA-2026-05338c2e02 Packages in this update:
  • python3.12-3.12.13-6.fc45
Update description:

Automatic update for python3.12-3.12.13-6.fc45.

Changelog * Tue Jul 28 2026 Lukáš Zachar <lzachar@redhat.com> - 3.12.13-6 - Security fix for CVE-2026-15308 Resolves: rhbz#2498688 * Tue Jul 28 2026 Miro Hrončok <mhroncok@redhat.com> - 3.12.13-5 - Skip UDP Lite tests if it's not supported - Fixes FTBFS on Linux kernel 7.1 and newer * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 3.12.13-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

xen-4.21.2-1.fc44

6 days 7 hours ago
FEDORA-2026-bf1da84dfc Packages in this update:
  • xen-4.21.2-1.fc44
Update description:

update to xen 4.21.2 includes security fixes x86 shadow paging is deprecated [XSA-495, CVE-2026-42493] vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492] buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494, CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425] sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426, CVE-2026-62427] grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428] grant-table: version change racing with other operations [XSA-501, CVE-2026-62435, CVE-2026-62436] vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429] x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430] Viridian STIMER division by zero [XSA-504, CVE-2026-62431] evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432] correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433] PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434] pygrub is only supported in de-privileged mode [XSA-508]

fuse-overlayfs-1.17-1.fc43

6 days 8 hours ago
FEDORA-2026-40ce06e46e Packages in this update:
  • fuse-overlayfs-1.17-1.fc43
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

fuse-overlayfs-1.17-1.fc44

6 days 8 hours ago
FEDORA-2026-4e0490640f Packages in this update:
  • fuse-overlayfs-1.17-1.fc44
Update description:

Update to fuse-overlayfs 1.17 to fix CVE-2026-52791: privilege escalation via SUID/SGID bit preservation on file truncation. When a file with SUID/SGID bits is truncated, those privilege bits should be cleared but were not in versions prior to 1.17, allowing potential privilege escalation in rootless containers.

Checked
42 minutes 26 seconds ago