Fedora Security Advisories

kronosnet-1.35-1.fc45

3 days 2 hours ago
FEDORA-2026-3e85d87212 Packages in this update:
  • kronosnet-1.35-1.fc45
Update description:

Automatic update for kronosnet-1.35-1.fc45.

Changelog * Mon Jul 20 2026 Fabio M. Di Nitto <fdinitto@redhat.com> - 1.35-1 - New upstream release - CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850) - CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852) - CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864) - tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets - libnozzle: Introduce test macros similar to libknet - docs: convert README to markdown format * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1.34-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

nodejs22-22.23.1-2.fc45

3 days 4 hours ago
FEDORA-2026-3298e71891 Packages in this update:
  • nodejs22-22.23.1-2.fc45
Update description:

Automatic update for nodejs22-22.23.1-2.fc45.

Changelog * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-2 - CVE-2026-42338 ip-address HTML escaping fix (rhbz#2487625) * Mon Jul 20 2026 tjuhasz <tjuhasz@redhat.com> - 1:22.23.1-1 - Update to version 22.23.1 (rhbz#2477273). * Thu Jul 16 2026 Fedora Release Engineering <releng@fedoraproject.org> - 1:22.22.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

btrbk-0.32.7-1.fc43

3 days 6 hours ago
FEDORA-2026-1528cb06a7 Packages in this update:
  • btrbk-0.32.7-1.fc43
Update description:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943

btrbk-0.32.7-1.fc44

3 days 6 hours ago
FEDORA-2026-131c82812a Packages in this update:
  • btrbk-0.32.7-1.fc44
Update description:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943

nginx-1.30.4-1.fc43 nginx-mod-brotli-1.0.0~rc-13.fc43 nginx-mod-fancyindex-0.6.0-8.fc43 nginx-mod-headers-more-0.40-3.fc43 nginx-mod-modsecurity-1.0.4-16.fc43 nginx-mod-naxsi-1.6-21.fc43 nginx-mod-vts-0.2.4-13.fc43

3 days 15 hours ago
FEDORA-2026-3b93aae2d6 Packages in this update:
  • nginx-1.30.4-1.fc43
  • nginx-mod-brotli-1.0.0~rc-13.fc43
  • nginx-mod-fancyindex-0.6.0-8.fc43
  • nginx-mod-headers-more-0.40-3.fc43
  • nginx-mod-modsecurity-1.0.4-16.fc43
  • nginx-mod-naxsi-1.6-21.fc43
  • nginx-mod-vts-0.2.4-13.fc43
Update description:

nginx-mod-vts:

  • Rebuild for 1.30.4

nginx-mod-brotli:

  • Rebuild for 1.30.4

nginx-mod-fancyindex:

  • Rebuild for 1.30.4

nginx-mod-headers-more:

  • Rebuild for 1.30.4

nginx-mod-modsecurity:

  • Rebuild for 1.30.4

nginx-mod-naxsi:

  • Rebuild for 1.30.4

nginx:

  • update to 1.30.4
  • fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434

nginx-1.30.4-1.fc44 nginx-mod-brotli-1.0.0~rc-13.fc44 nginx-mod-fancyindex-0.6.0-8.fc44 nginx-mod-headers-more-0.40-3.fc44 nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44 nginx-mod-modsecurity-1.0.4-16.fc44 nginx-mod-naxsi-1.6-21.fc44 nginx-mod-vts…

3 days 16 hours ago
FEDORA-2026-60fc198d3b Packages in this update:
  • nginx-1.30.4-1.fc44
  • nginx-mod-brotli-1.0.0~rc-13.fc44
  • nginx-mod-fancyindex-0.6.0-8.fc44
  • nginx-mod-headers-more-0.40-3.fc44
  • nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
  • nginx-mod-modsecurity-1.0.4-16.fc44
  • nginx-mod-naxsi-1.6-21.fc44
  • nginx-mod-vts-0.2.4-13.fc44
Update description:

nginx-mod-fancyindex:

  • Rebuild for 1.30.4

nginx-mod-modsecurity:

  • Rebuild for 1.30.4

nginx-mod-naxsi:

  • Rebuild for 1.30.4

nginx-mod-headers-more:

  • Rebuild for 1.30.4

nginx-mod-brotli:

  • Rebuild for 1.30.4

nginx-mod-js-challenge:

  • Rebuild for 1.30.4

nginx-mod-vts:

  • Rebuild for 1.30.4

nginx:

  • update to 1.30.4
  • fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434

opkssh-0.16.0-1.el10_3

3 days 22 hours ago
FEDORA-EPEL-2026-881ac51c15 Packages in this update:
  • opkssh-0.16.0-1.el10_3
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.el10_2

3 days 22 hours ago
FEDORA-EPEL-2026-cb5a2d1e66 Packages in this update:
  • opkssh-0.16.0-1.el10_2
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.fc43

3 days 22 hours ago
FEDORA-2026-168280f3c4 Packages in this update:
  • opkssh-0.16.0-1.fc43
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

opkssh-0.16.0-1.fc44

3 days 22 hours ago
FEDORA-2026-a0bf40ecfe Packages in this update:
  • opkssh-0.16.0-1.fc44
Update description:

Update to 0.16.0.

This release includes a security fix for GQ-commitment PK Tokens (upgrades the openpubkey dependency to v0.25.0), addressing a vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that opkssh currently only supports GitLab user OP (not GitLab-CI), so the vulnerable code path is not reachable through opkssh; severity is set low accordingly. Also drops the now-obsolete go-jose dependency_overrides pin, since upstream now requires go-jose v4.1.4 natively.

python-pillow-11.3.0-10.fc43

4 days 8 hours ago
FEDORA-2026-fc2ded926e Packages in this update:
  • python-pillow-11.3.0-10.fc43
Update description:

Backport fixes for CVE-2026-59197 and CVE-2026-54058.

Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798

perl-Mojolicious-9.48-1.fc43

4 days 8 hours ago
FEDORA-2026-6f12b08313 Packages in this update:
  • perl-Mojolicious-9.48-1.fc43
Update description:

Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.

perl-Mojolicious-9.48-1.fc44

4 days 8 hours ago
FEDORA-2026-4334fd85bc Packages in this update:
  • perl-Mojolicious-9.48-1.fc44
Update description:

Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to BREACH attacks. Tokens are now masked with a fresh random value on every request, instead of being reused for the whole lifetime of a session.

trafficserver-10.1.3-1.fc43

4 days 17 hours ago
FEDORA-2026-ddaabe38ab Packages in this update:
  • trafficserver-10.1.3-1.fc43
Update description:

Resolves CVE-2026-59173 - DoS vulnerability in HTTP/2 via stalled flow-control

Additional Changes with Apache Traffic Server 9.2.14 #12910 - Fix connection-level window mismatch causing 408/504 timeouts #13266 - Add Claude Code project guide for the 9.2.x branch #13267 - [9.2.x] Backport format scripts fixes #13377 - 9.2.x: http2: Track scheduled events

Additional Changes with Apache Traffic Server 10.1.3 #12192 - Return a 400 on chunk parse errors #12733 - Fix retry logic for TSHttpTxnServerAddrSet (issue #12611) #12854 - Fix LoadedPlugins::remove crash during static destruction #12855 - Fix header_rewrite run-plugin relative path resolution #12857 - Fix autest compatibility with Fedora 43 / Python 3.14 #12943 - Address incompatibility with BoringSSL #12959 - Fix crash in HttpSM::tunnel_handler on unhandled VC events #12972 - Fix cache retry assert on ServerAddrSet #12990 - Update to Proxy Verifier v3.0.0 #13008 - cmake: limit GENERAL_NAME bssl probe #13020 - Align AuTests with latest proxy-verifier checks (#12986) #13025 - hrw: Refix loading geodb files #13033 - tests/gold_tests/headers tests: use ATSReplayTest #13113 - slice: Fix crash caused by use-after-free #13114 - Fix bg fill teardown crash in update_size_and_time_stats #13138 - Remove cache alternate vector detach #13144 - Fix XPACK relative index underflow #13162 - hrw: Fix an index bug in run plugin operator #13177 - Correct records.yaml record drift #13178 - 10.1.x: proxy.config.dns.search_default_domains: allow 2 #13182 - Stabilize parallel AuTest helpers #13192 - yaml-cpp-0.9.0 #13193 - GCC 16: Regex header integer includes #13198 - Fedora 44 test fixes #13200 - Single source of truth for Proxy Verifier metadata #13217 - Proxy Verifier v3.1.3 #13218 - Fix hdrHeap/hdrStrHeap allocator inuse metric underflow #13220 - Fix flaky Fedora 44 AuTest helpers #13223 - Fix mismatched sINT/dINT log field types #13252 - cache: apply per-volume settings on first start after clear #13256 - Fix mismatched log field types more #13261 - header_rewrite: Improve URL Error messages #13263 - Fix bounds check in CacheVC::scanObject #13264 - Handle OpenSSL without dynamic ENGINE #13280 - Enable probes in Fedora C++20 CI #13293 - ProxyProtocol: free pp_info heap on NetVConnection recycle #13294 - Fix pending HostDB DNS queue removal race #13295 - Fix server entry cleanup after request tunnel setup #13297 - 10.1.x: Add sni.yaml session ticket overrides (#13006) #13303 - header_rewrite: Fix a leak and truncation in set-body-from #13307 - dns: destruct HostEnt on free to fix SRV vector leak #13318 - TLS: Fix memory leaks in cert load and OCSP stapling #13325 - HttpSM.cc: fix cache read end milestone order #13336 - 10.1.x: Fix redirected cache write without write VC #13365 - 10.1.x: USDT: normalize names for STATE_ENTER #13366 - 10.1.x: Fix set-status crash inside if/endif at remap time #13387 - Hard-enforce max_active_streams_in at HTTP/2 stream creation

trafficserver-10.1.3-1.fc44

4 days 17 hours ago
FEDORA-2026-bb8dc1e5b6 Packages in this update:
  • trafficserver-10.1.3-1.fc44
Update description:

Resolves CVE-2026-59173 - DoS vulnerability in HTTP/2 via stalled flow-control

Additional Changes with Apache Traffic Server 9.2.14 #12910 - Fix connection-level window mismatch causing 408/504 timeouts #13266 - Add Claude Code project guide for the 9.2.x branch #13267 - [9.2.x] Backport format scripts fixes #13377 - 9.2.x: http2: Track scheduled events

Additional Changes with Apache Traffic Server 10.1.3 #12192 - Return a 400 on chunk parse errors #12733 - Fix retry logic for TSHttpTxnServerAddrSet (issue #12611) #12854 - Fix LoadedPlugins::remove crash during static destruction #12855 - Fix header_rewrite run-plugin relative path resolution #12857 - Fix autest compatibility with Fedora 43 / Python 3.14 #12943 - Address incompatibility with BoringSSL #12959 - Fix crash in HttpSM::tunnel_handler on unhandled VC events #12972 - Fix cache retry assert on ServerAddrSet #12990 - Update to Proxy Verifier v3.0.0 #13008 - cmake: limit GENERAL_NAME bssl probe #13020 - Align AuTests with latest proxy-verifier checks (#12986) #13025 - hrw: Refix loading geodb files #13033 - tests/gold_tests/headers tests: use ATSReplayTest #13113 - slice: Fix crash caused by use-after-free #13114 - Fix bg fill teardown crash in update_size_and_time_stats #13138 - Remove cache alternate vector detach #13144 - Fix XPACK relative index underflow #13162 - hrw: Fix an index bug in run plugin operator #13177 - Correct records.yaml record drift #13178 - 10.1.x: proxy.config.dns.search_default_domains: allow 2 #13182 - Stabilize parallel AuTest helpers #13192 - yaml-cpp-0.9.0 #13193 - GCC 16: Regex header integer includes #13198 - Fedora 44 test fixes #13200 - Single source of truth for Proxy Verifier metadata #13217 - Proxy Verifier v3.1.3 #13218 - Fix hdrHeap/hdrStrHeap allocator inuse metric underflow #13220 - Fix flaky Fedora 44 AuTest helpers #13223 - Fix mismatched sINT/dINT log field types #13252 - cache: apply per-volume settings on first start after clear #13256 - Fix mismatched log field types more #13261 - header_rewrite: Improve URL Error messages #13263 - Fix bounds check in CacheVC::scanObject #13264 - Handle OpenSSL without dynamic ENGINE #13280 - Enable probes in Fedora C++20 CI #13293 - ProxyProtocol: free pp_info heap on NetVConnection recycle #13294 - Fix pending HostDB DNS queue removal race #13295 - Fix server entry cleanup after request tunnel setup #13297 - 10.1.x: Add sni.yaml session ticket overrides (#13006) #13303 - header_rewrite: Fix a leak and truncation in set-body-from #13307 - dns: destruct HostEnt on free to fix SRV vector leak #13318 - TLS: Fix memory leaks in cert load and OCSP stapling #13325 - HttpSM.cc: fix cache read end milestone order #13336 - 10.1.x: Fix redirected cache write without write VC #13365 - 10.1.x: USDT: normalize names for STATE_ENTER #13366 - 10.1.x: Fix set-status crash inside if/endif at remap time #13387 - Hard-enforce max_active_streams_in at HTTP/2 stream creation

trafficserver-9.2.14-1.el9

4 days 17 hours ago
FEDORA-EPEL-2026-5bcb271bee Packages in this update:
  • trafficserver-9.2.14-1.el9
Update description:

Resolves CVE-2026-59173 - DoS vulnerability in HTTP/2 via stalled flow-control

Additional Changes with Apache Traffic Server 9.2.14 #12910 - Fix connection-level window mismatch causing 408/504 timeouts #13266 - Add Claude Code project guide for the 9.2.x branch #13267 - [9.2.x] Backport format scripts fixes #13377 - 9.2.x: http2: Track scheduled events

Additional Changes with Apache Traffic Server 10.1.3 #12192 - Return a 400 on chunk parse errors #12733 - Fix retry logic for TSHttpTxnServerAddrSet (issue #12611) #12854 - Fix LoadedPlugins::remove crash during static destruction #12855 - Fix header_rewrite run-plugin relative path resolution #12857 - Fix autest compatibility with Fedora 43 / Python 3.14 #12943 - Address incompatibility with BoringSSL #12959 - Fix crash in HttpSM::tunnel_handler on unhandled VC events #12972 - Fix cache retry assert on ServerAddrSet #12990 - Update to Proxy Verifier v3.0.0 #13008 - cmake: limit GENERAL_NAME bssl probe #13020 - Align AuTests with latest proxy-verifier checks (#12986) #13025 - hrw: Refix loading geodb files #13033 - tests/gold_tests/headers tests: use ATSReplayTest #13113 - slice: Fix crash caused by use-after-free #13114 - Fix bg fill teardown crash in update_size_and_time_stats #13138 - Remove cache alternate vector detach #13144 - Fix XPACK relative index underflow #13162 - hrw: Fix an index bug in run plugin operator #13177 - Correct records.yaml record drift #13178 - 10.1.x: proxy.config.dns.search_default_domains: allow 2 #13182 - Stabilize parallel AuTest helpers #13192 - yaml-cpp-0.9.0 #13193 - GCC 16: Regex header integer includes #13198 - Fedora 44 test fixes #13200 - Single source of truth for Proxy Verifier metadata #13217 - Proxy Verifier v3.1.3 #13218 - Fix hdrHeap/hdrStrHeap allocator inuse metric underflow #13220 - Fix flaky Fedora 44 AuTest helpers #13223 - Fix mismatched sINT/dINT log field types #13252 - cache: apply per-volume settings on first start after clear #13256 - Fix mismatched log field types more #13261 - header_rewrite: Improve URL Error messages #13263 - Fix bounds check in CacheVC::scanObject #13264 - Handle OpenSSL without dynamic ENGINE #13280 - Enable probes in Fedora C++20 CI #13293 - ProxyProtocol: free pp_info heap on NetVConnection recycle #13294 - Fix pending HostDB DNS queue removal race #13295 - Fix server entry cleanup after request tunnel setup #13297 - 10.1.x: Add sni.yaml session ticket overrides (#13006) #13303 - header_rewrite: Fix a leak and truncation in set-body-from #13307 - dns: destruct HostEnt on free to fix SRV vector leak #13318 - TLS: Fix memory leaks in cert load and OCSP stapling #13325 - HttpSM.cc: fix cache read end milestone order #13336 - 10.1.x: Fix redirected cache write without write VC #13365 - 10.1.x: USDT: normalize names for STATE_ENTER #13366 - 10.1.x: Fix set-status crash inside if/endif at remap time #13387 - Hard-enforce max_active_streams_in at HTTP/2 stream creation

Checked
18 minutes 54 seconds ago