Fedora Security Advisories

exim-4.100.1-1.el8

1 day 22 hours ago
FEDORA-EPEL-2026-71b80f48fa Packages in this update:
  • exim-4.100.1-1.el8
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el9

1 day 22 hours ago
FEDORA-EPEL-2026-61a5ea9fcd Packages in this update:
  • exim-4.100.1-1.el9
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el10_4

1 day 22 hours ago
FEDORA-EPEL-2026-15b5988543 Packages in this update:
  • exim-4.100.1-1.el10_4
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc43

1 day 22 hours ago
FEDORA-2026-d202b74c6a Packages in this update:
  • exim-4.100.1-1.fc43
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc44

1 day 22 hours ago
FEDORA-2026-4f9e436ed5 Packages in this update:
  • exim-4.100.1-1.fc44
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc45

1 day 23 hours ago
FEDORA-2026-3f88ddbd83 Packages in this update:
  • exim-4.100.1-1.fc45
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

curl-8.18.0-12.fc44

2 days ago
FEDORA-2026-8efcd7a2a0 Packages in this update:
  • curl-8.18.0-12.fc44
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)
  • Fix HTTP/2 server push UAF (CVE-2026-18924)

curl-8.21.0-7.fc45

2 days 5 hours ago
FEDORA-2026-c2d4a9aa16 Packages in this update:
  • curl-8.21.0-7.fc45
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

chromium-154.0.8037.97-1.el10_4

2 days 7 hours ago
FEDORA-EPEL-2026-d1c26f4ffd Packages in this update:
  • chromium-154.0.8037.97-1.el10_4
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el9

2 days 7 hours ago
FEDORA-EPEL-2026-923ac1e238 Packages in this update:
  • chromium-154.0.8037.97-1.el9
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_3

2 days 7 hours ago
FEDORA-EPEL-2026-b3497ed039 Packages in this update:
  • chromium-154.0.8037.97-1.el10_3
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_2

2 days 7 hours ago
FEDORA-EPEL-2026-421dd4a529 Packages in this update:
  • chromium-154.0.8037.97-1.el10_2
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc43

2 days 7 hours ago
FEDORA-2026-02902c2fa0 Packages in this update:
  • chromium-154.0.8037.97-1.fc43
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc45

2 days 7 hours ago
FEDORA-2026-53c8aca50a Packages in this update:
  • chromium-154.0.8037.97-1.fc45
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc44

2 days 7 hours ago
FEDORA-2026-bcdfa4c7db Packages in this update:
  • chromium-154.0.8037.97-1.fc44
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

flocq-4.2.2-3.fc44 gappalib-coq-1.11.0-1.fc44 rocq-9.3.0-1.fc44 rocq-stdlib-9.2.0-1.fc44 why3-1.8.2-11.fc44 zenon-0.8.5-41.fc44

2 days 16 hours ago
FEDORA-2026-62bbabcf11 Packages in this update:
  • flocq-4.2.2-3.fc44
  • gappalib-coq-1.11.0-1.fc44
  • rocq-9.3.0-1.fc44
  • rocq-stdlib-9.2.0-1.fc44
  • why3-1.8.2-11.fc44
  • zenon-0.8.5-41.fc44
Update description:

See https://rocq-prover.org/doc/v9.3/refman/changes.html#version-9-3 for changes in rocq 9.3.0.

See https://rocq-prover.org/doc/v9.2/refman-stdlib/changes.html for changes in rocq-stdlib 9.2.0.

See https://gitlab.inria.fr/gappa/coq/-/blob/master/NEWS.md for changes in gappalib-coq 1.11.0.

The other builds are rebuilds due to the above changes.

python-jupytext-1.19.6-1.fc43

2 days 18 hours ago
FEDORA-2026-3942ab86fd Packages in this update:
  • python-jupytext-1.19.6-1.fc43
Update description:

See https://github.com/jupytext/jupytext/blob/main/CHANGELOG.md for changes in versions 1.19.5 and 1.19.6. For this update, a patch has been applied that reverses the jupyterlab → jupyter-builder change for Fedora releases ≤ 45, since jupyter-builder is only available in F46 and later. Many CVEs have been fixed in this release.

aegisub-3.5.0-1.fc43

2 days 23 hours ago
FEDORA-2026-78a11da997 Packages in this update:
  • aegisub-3.5.0-1.fc43
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-2.fc44

2 days 23 hours ago
FEDORA-2026-0c6d4471fc Packages in this update:
  • aegisub-3.5.0-2.fc44
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

aegisub-3.5.0-1.fc45

2 days 23 hours ago
FEDORA-2026-d296db490c Packages in this update:
  • aegisub-3.5.0-1.fc45
Update description:

Update to Aegisub 3.5.0, fixing CVE-2026-92705: arbitrary code execution when opening crafted ASS subtitle files containing associated Automation script references. The fix requires confirmation before loading associated scripts, makes extension validation consistent with filesystem path interpretation, and sanitizes embedded NUL characters in project metadata. Upstream advisory: https://github.com/TypesettingTools/Aegisub/security/advisories/GHSA-67hq-5vgg-6f23

Checked
35 minutes 45 seconds ago