Fedora Security Advisories

chromium-151.0.7922.108-1.el9

4 days 17 hours ago
FEDORA-EPEL-2026-59f5c53ffc Packages in this update:
  • chromium-151.0.7922.108-1.el9
Update description:

chromium-151.0.7922.108 security release fix 41 CVE

  • CVE-2026-19137: Use after free in WebGL
  • CVE-2026-19138: Heap buffer overflow in CrashReporting
  • CVE-2026-19139: Race in CredentialProvider
  • CVE-2026-19140: Use after free in GPU
  • CVE-2026-19141: Use after free in Resources
  • CVE-2026-19142: Use after free in Views
  • CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
  • CVE-2026-19144: Use after free in HTML
  • CVE-2026-19145: Use after free in Translate
  • CVE-2026-19146: Uninitialized Use in GPU
  • CVE-2026-19147: Use after free in Aura
  • CVE-2026-19148: Out of bounds write in GPU
  • CVE-2026-19149: Use after free in Aura
  • CVE-2026-19150: Inappropriate implementation in V8
  • CVE-2026-19151: Use after free in V8
  • CVE-2026-19152: Inappropriate implementation in Navigation
  • CVE-2026-19153: Insufficient validation of untrusted input in Workers
  • CVE-2026-19154: Use after free in Skia
  • CVE-2026-19155: Use after free in Payments
  • CVE-2026-19156: Heap buffer overflow in Base
  • CVE-2026-19157: Out of bounds write in ANGLE
  • CVE-2026-19158: Use after free in Views
  • CVE-2026-19159: Use after free in Views
  • CVE-2026-19160: Uninitialized Use in Skia
  • CVE-2026-19161: Uninitialized Use in Skia
  • CVE-2026-19162: Out of bounds write in V8
  • CVE-2026-19163: Use after free in Media
  • CVE-2026-19164: Insufficient validation of untrusted input in Codecs
  • CVE-2026-19165: Use after free in Extensions
  • CVE-2026-19166: Use after free in Web Authentication
  • CVE-2026-19167: Integer overflow in GPU
  • CVE-2026-19168: Inappropriate implementation in V8
  • CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
  • CVE-2026-19170: Use after free in WebGL
  • CVE-2026-19171: Use after free in Media
  • CVE-2026-19172: Use after free in Views
  • CVE-2026-19173: Out of bounds write in Skia
  • CVE-2026-19174: Integer overflow in V8
  • CVE-2026-19175: Use after free in Payments
  • CVE-2026-19176: Use after free in Skia
  • CVE-2026-19177: Insufficient validation of untrusted input in UI

chromium-151.0.7922.108-1.fc44

4 days 17 hours ago
FEDORA-2026-eebdfdf5ba Packages in this update:
  • chromium-151.0.7922.108-1.fc44
Update description:

chromium-151.0.7922.108 security release fix 41 CVE

  • CVE-2026-19137: Use after free in WebGL
  • CVE-2026-19138: Heap buffer overflow in CrashReporting
  • CVE-2026-19139: Race in CredentialProvider
  • CVE-2026-19140: Use after free in GPU
  • CVE-2026-19141: Use after free in Resources
  • CVE-2026-19142: Use after free in Views
  • CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
  • CVE-2026-19144: Use after free in HTML
  • CVE-2026-19145: Use after free in Translate
  • CVE-2026-19146: Uninitialized Use in GPU
  • CVE-2026-19147: Use after free in Aura
  • CVE-2026-19148: Out of bounds write in GPU
  • CVE-2026-19149: Use after free in Aura
  • CVE-2026-19150: Inappropriate implementation in V8
  • CVE-2026-19151: Use after free in V8
  • CVE-2026-19152: Inappropriate implementation in Navigation
  • CVE-2026-19153: Insufficient validation of untrusted input in Workers
  • CVE-2026-19154: Use after free in Skia
  • CVE-2026-19155: Use after free in Payments
  • CVE-2026-19156: Heap buffer overflow in Base
  • CVE-2026-19157: Out of bounds write in ANGLE
  • CVE-2026-19158: Use after free in Views
  • CVE-2026-19159: Use after free in Views
  • CVE-2026-19160: Uninitialized Use in Skia
  • CVE-2026-19161: Uninitialized Use in Skia
  • CVE-2026-19162: Out of bounds write in V8
  • CVE-2026-19163: Use after free in Media
  • CVE-2026-19164: Insufficient validation of untrusted input in Codecs
  • CVE-2026-19165: Use after free in Extensions
  • CVE-2026-19166: Use after free in Web Authentication
  • CVE-2026-19167: Integer overflow in GPU
  • CVE-2026-19168: Inappropriate implementation in V8
  • CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
  • CVE-2026-19170: Use after free in WebGL
  • CVE-2026-19171: Use after free in Media
  • CVE-2026-19172: Use after free in Views
  • CVE-2026-19173: Out of bounds write in Skia
  • CVE-2026-19174: Integer overflow in V8
  • CVE-2026-19175: Use after free in Payments
  • CVE-2026-19176: Use after free in Skia
  • CVE-2026-19177: Insufficient validation of untrusted input in UI

nghttp2-1.66.0-3.fc43

5 days 12 hours ago
FEDORA-2026-91dd0c29d6 Packages in this update:
  • nghttp2-1.66.0-3.fc43
Update description:
  • fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

nghttp2-1.68.0-5.fc44

5 days 12 hours ago
FEDORA-2026-084c991d17 Packages in this update:
  • nghttp2-1.68.0-5.fc44
Update description:
  • fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)

stunnel-5.80-1.fc43

5 days 14 hours ago
FEDORA-2026-de8630b736 Packages in this update:
  • stunnel-5.80-1.fc43
Update description: * Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. - Fixed a TCP stream truncation (thanks to Solomon Jacobs). - Fixed a transfer() loop (thanks to Solomon Jacobs). - Fixed log reopening logs without a configured log file. - Fixed some logged values (thanks to Jose Alf.). - Fixed some error handling and cleanup issues (thanks to Jose Alf.). - Fixed OpenSSL applink detection and MSYS2 MinGW builds. * Features - Added the "CRLcheckChain" service-level option for opt-in full-chain CRL verification. - Added the new 'transport' service-level option to choose between TLS over TCP and DTLS over UDP.

stunnel-5.80-1.fc44

5 days 14 hours ago
FEDORA-2026-67c2201ad8 Packages in this update:
  • stunnel-5.80-1.fc44
Update description: * Security bugfixes - CVE-2026-70368: Fixed an out-of-bounds memory access triggered by logging attacker-controlled protocol messages longer than 1,024 bytes (thanks to AISLE Research and Clemens Lang). - CVE-2026-70367: Fixed a SOCKS server mode bypass of the localhost destination filter using alternate local-address encodings and interface-scoped IPv6 destinations (thanks to AISLE Research and Clemens Lang). - Restricted Windows GUI/service control pipes to local clients. * Bugfixes - Fixed concurrent DTLS handshakes from clients sharing an IP address. - Fixed version reporting in builds from source. - Rejected stream-oriented protocol negotiation with the UDP transport during configuration validation. - Fixed a TCP stream truncation (thanks to Solomon Jacobs). - Fixed a transfer() loop (thanks to Solomon Jacobs). - Fixed log reopening logs without a configured log file. - Fixed some logged values (thanks to Jose Alf.). - Fixed some error handling and cleanup issues (thanks to Jose Alf.). - Fixed OpenSSL applink detection and MSYS2 MinGW builds. * Features - Added the "CRLcheckChain" service-level option for opt-in full-chain CRL verification. - Added the new 'transport' service-level option to choose between TLS over TCP and DTLS over UDP.

wordpress-6.9.6-1.fc43

5 days 19 hours ago
FEDORA-2026-35a50f466b Packages in this update:
  • wordpress-6.9.6-1.fc43
Update description: Security updates included in this release
  • Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai. CVE-2026-64638
  • Contributor+ stored cross-site scripting (XSS) in posts via the emoji settings element reported by Asaf Mozes (amosec)
  • Contributor+ stored cross-site scripting (XSS) in the Post Content block reported by n05ec
  • Contributor+ stored cross-site scripting (XSS) in Quick Edit on sites with a large number of users reported by Naveen S and Ajmal Moochingal
  • Contributor+ stored cross-site scripting (XSS) in the Post Date block reported by Alex Concha of the WordPress Security Team
  • A privilege escalation issue on multisite networks with user registration enabled, allowing a user to create a new site reported by Aikido Security
  • An information disclosure issue in the Latest Comments block exposing comments on password-protected posts reported by Ehtisham Siddiqui of the WordPress Security Team
  • Enumeration of post slugs reported by HDWSec
  • Disclosure of notes in comment feeds reported by Elio Gubser
  • Author+ CSS injection via a bypass of the safe CSS attribute filter reported by Anthropic
  • Bypass of the email address confirmation flow reported by 0ways
  • A server-side request forgery (SSRF) issue in URL validation allowing requests to link-local ranges reported by Andrew Mohawk and multiple independent reporters
Checked
14 minutes 59 seconds ago