Fedora Security Advisories

python-configargparse-1.7.7-1.fc43

2 days 23 hours ago
FEDORA-2026-2e605e01a6 Packages in this update:
  • python-configargparse-1.7.7-1.fc43
Update description:

Update to 1.7.7.

Version 1.7.6 is a security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.

Version 1.7.7 contains a bug fix: args with a custom argparse.Action and nargs can now be set from a config file.

python-configargparse-1.7.7-1.fc44

2 days 23 hours ago
FEDORA-2026-e3b2220f12 Packages in this update:
  • python-configargparse-1.7.7-1.fc44
Update description:

Update to 1.7.7.

Version 1.7.6 is a security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.

Version 1.7.7 contains a bug fix: args with a custom argparse.Action and nargs can now be set from a config file.

python-configargparse-1.7.7-1.fc45

2 days 23 hours ago
FEDORA-2026-d40fc39b57 Packages in this update:
  • python-configargparse-1.7.7-1.fc45
Update description:

Update to 1.7.7.

Version 1.7.6 is a security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.

Version 1.7.7 contains a bug fix: args with a custom argparse.Action and nargs can now be set from a config file.

perl-Data-Entropy-0.010-1.fc44

3 days 4 hours ago
FEDORA-2026-2c6e5be623 Packages in this update:
  • perl-Data-Entropy-0.010-1.fc44
Update description:

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).

perl-Data-Entropy-0.010-1.fc43

3 days 4 hours ago
FEDORA-2026-8924ee53fe Packages in this update:
  • perl-Data-Entropy-0.010-1.fc43
Update description:

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).

perl-Data-Entropy-0.010-1.fc45

3 days 4 hours ago
FEDORA-2026-f234be41fe Packages in this update:
  • perl-Data-Entropy-0.010-1.fc45
Update description:

Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).

perl-HTML-FormHandler-0.410001-1.fc45

3 days 6 hours ago
FEDORA-2026-5b1ed32d6c Packages in this update:
  • perl-HTML-FormHandler-0.410001-1.fc45
Update description:

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410001-1.fc43

3 days 6 hours ago
FEDORA-2026-ab25ac7ee2 Packages in this update:
  • perl-HTML-FormHandler-0.410001-1.fc43
Update description:

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410001-1.fc44

3 days 6 hours ago
FEDORA-2026-ad7d80deb9 Packages in this update:
  • perl-HTML-FormHandler-0.410001-1.fc44
Update description:

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

chromium-152.0.7977.82-1.fc45

3 days 20 hours ago
FEDORA-2026-07ab59f891 Packages in this update:
  • chromium-152.0.7977.82-1.fc45
Update description:

Update to 152.0.7977.82

  • CVE-2026-85046: Type confusion in V8
  • CVE-2026-85052: Out of bounds read in CrashReporting
  • CVE-2026-85043: Incomplete cleanup in Network
  • CVE-2026-85048: Use after free in Compositing
  • CVE-2026-85045: Race condition in V8
  • CVE-2026-85050: Out of bounds write in WebGL
  • CVE-2026-85053: Improper resource exposure in CacheStorage
  • CVE-2026-85042: Use after free in DevTools
  • CVE-2026-85049: Use after free in Skia
  • CVE-2026-85051: Type confusion in Compositing
  • CVE-2026-85047: Improper input validation in Transactions Platform
  • CVE-2026-85044: Use of released resource in Mobile
  • Update to 152.0.7977.75

  • CVE-2026-84353: Use after free in Shared Tab Groups

  • CVE-2026-84352: Use after free in WebGL
  • CVE-2026-84354: Incorrect authorization in FileSystem
  • CVE-2026-84359: Information leak in Skia
  • CVE-2026-84357: Improper input validation in Omnibox
  • CVE-2026-84324: Use after free in Proxy
  • CVE-2026-84349: Use after free in Browser
  • CVE-2026-84326: Uninitialized resource in V8
  • CVE-2026-84333: Use after free in Dawn
  • CVE-2026-84351: Buffer overflow in GPU
  • CVE-2026-84325: Improper input validation in DataTransfer
  • CVE-2026-84328: Missing authorization in FileSystem
  • CVE-2026-84347: Use after free in WebRTC
  • CVE-2026-84323: Missing authorization in FileSystem
  • CVE-2026-84355: Incorrect authorization in Navigation
  • CVE-2026-84358: Improper privilege management in Downloads
  • CVE-2026-84332: Incorrect authorization in SiteSettings
  • CVE-2026-84330: UI misrepresentation in FullScreen
  • CVE-2026-84334: Incorrect authorization in Chromoting
  • CVE-2026-84348: Information leak in MediaCapture
  • CVE-2026-84335: Incorrect authorization in TabStrip
  • CVE-2026-84327: Incorrect authorization in Autofill
  • CVE-2026-84329: Confused deputy in CredentialProvider
  • CVE-2026-84356: UI misrepresentation in FullScreen
  • CVE-2026-84350: Use after free in TabStrip
  • CVE-2026-84331: Incorrect authorization in Actor

chromium-152.0.7977.82-1.el9

3 days 20 hours ago
FEDORA-EPEL-2026-6319210a9a Packages in this update:
  • chromium-152.0.7977.82-1.el9
Update description:

Update to 152.0.7977.82

  • CVE-2026-85046: Type confusion in V8
  • CVE-2026-85052: Out of bounds read in CrashReporting
  • CVE-2026-85043: Incomplete cleanup in Network
  • CVE-2026-85048: Use after free in Compositing
  • CVE-2026-85045: Race condition in V8
  • CVE-2026-85050: Out of bounds write in WebGL
  • CVE-2026-85053: Improper resource exposure in CacheStorage
  • CVE-2026-85042: Use after free in DevTools
  • CVE-2026-85049: Use after free in Skia
  • CVE-2026-85051: Type confusion in Compositing
  • CVE-2026-85047: Improper input validation in Transactions Platform
  • CVE-2026-85044: Use of released resource in Mobile

chromium-152.0.7977.82-1.el10_3

3 days 20 hours ago
FEDORA-EPEL-2026-3efc5eb835 Packages in this update:
  • chromium-152.0.7977.82-1.el10_3
Update description:

Update to 152.0.7977.82

  • CVE-2026-85046: Type confusion in V8
  • CVE-2026-85052: Out of bounds read in CrashReporting
  • CVE-2026-85043: Incomplete cleanup in Network
  • CVE-2026-85048: Use after free in Compositing
  • CVE-2026-85045: Race condition in V8
  • CVE-2026-85050: Out of bounds write in WebGL
  • CVE-2026-85053: Improper resource exposure in CacheStorage
  • CVE-2026-85042: Use after free in DevTools
  • CVE-2026-85049: Use after free in Skia
  • CVE-2026-85051: Type confusion in Compositing
  • CVE-2026-85047: Improper input validation in Transactions Platform
  • CVE-2026-85044: Use of released resource in Mobile
Checked
18 minutes 57 seconds ago