Fedora Security Advisories

emacs-30.2-28.fc44

2 days 22 hours ago
FEDORA-2026-60eff202e7 Packages in this update:
  • emacs-30.2-28.fc44
Update description:

Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.

emacs-30.2-10.fc43

2 days 22 hours ago
FEDORA-2026-8894da1406 Packages in this update:
  • emacs-30.2-10.fc43
Update description:

Fix CVE-2026-77219: Integer overflow in PBM/PPM/PGM image loader.

curl-8.18.0-9.fc44

3 days 3 hours ago
FEDORA-2026-2f88b83676 Packages in this update:
  • curl-8.18.0-9.fc44
Update description:
  • Fix QUIC zero-length UDP datagrams busy-loop (CVE-2026-11352)
  • Fix WS Auto-PONG memory exhaustion (CVE-2026-11586)
  • Fix proto-default skips SSH verification (CVE-2026-12064)
  • Fix wrong STARTTLS connection reuse (CVE-2026-8286)
  • Fix SASL double-free (CVE-2026-8925)
  • Fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
  • Fix sending old referer (CVE-2026-9546)
  • Fix exposing HTTP/3 early data (CVE-2026-9545)
  • Fix UAF after pause in socket callback (CVE-2026-9080)

proftpd-1.3.9d-2.el10_4

3 days 4 hours ago
FEDORA-EPEL-2026-37261f4ecd Packages in this update:
  • proftpd-1.3.9d-2.el10_4
Update description:

Current upstream maintenance release, with a handful of potentially security-related bugfixes.

python-linkify-it-py-2.1.1-1.fc44

3 days 17 hours ago
FEDORA-2026-7c23b06d74 Packages in this update:
  • python-linkify-it-py-2.1.1-1.fc44
Update description:

Security release: LinkifyIt.match() was quadratic on untrusted input when linkify is enabled (GHSA-8m2q-wq3r-6hq8).

  • Fix quadratic complexity in LinkifyIt.match(), port of linkify-it 5.0.1 and 5.0.2 (upstream CVE-2026-48801, CVE-2026-59887) (#82)
  • Match validators at a position instead of slicing the tail, needed because Python 3.10 does not optimize the ^ anchor (#82)
  • Allow ; in the email name, matching linkify-it. Behavior change: a;b@example.com is now linkified (#82)
  • Update port.yml (linkify-it v5.0.2) (#82)

perl-DBD-Pg-3.21.1-2.fc44

3 days 22 hours ago
FEDORA-2026-bef4b3d7a3 Packages in this update:
  • perl-DBD-Pg-3.21.1-2.fc44
Update description:

Fix missing closing double-quote in su -c commands in dbdpg_test_setup.pl

3.21.0m 3.21.1: - New features: non-blocking async COPY FROM support (pg_putcopydata_async, pg_putcopyend_async, pg_flush); new string-buffer system replacing linked lists with arrays (faster) - Bug fixes: memory leaks fixed (PQclosePrepared cleanup path, bind_param, statement handles); float quoting fixes (NaN); $sth->rows() returns 0 for no-row updates/deletes; safer NUL checking in _dequote_bytea_hex(); allocation fixes in quote_float() / pg_destringify_array() - Fix CVE-2026-78183

Checked
23 minutes 37 seconds ago