Fedora Security Advisories

erlang-cowboy-2.18.0-1.fc43 erlang-cowlib-2.19.0-1.fc43

5 days 4 hours ago
FEDORA-2026-ce97d80dae Packages in this update:
  • erlang-cowboy-2.18.0-1.fc43
  • erlang-cowlib-2.19.0-1.fc43
Update description:

Coordinated security update of cowlib and cowboy, released together upstream on 2026-07-27.

cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION frames and NUL bytes in multipart headers, validates cookie domain and path, limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket-Version limits to response headers, and enforces a custom max_concurrent_streams immediately.

cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR in HTTP/1.1 header values, rejects requests containing a fragment component, rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies option to the cowboy_req cookie functions, fixes max_headers handling with duplicate headers, and fixes the websocket max_inflate_size calculation.

Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1 requests. Applications relying on that behaviour may see different throughput characteristics.

cri-o1.34-1.34.11-1.fc43

6 days ago
FEDORA-2026-7e85920dc5 Packages in this update:
  • cri-o1.34-1.34.11-1.fc43
Update description:
  • Update to release v1.34.11
  • Resolves: rhbz#2510870
  • Resolves CVE-2026-34986: rhbz#2455652
  • Upstream fixes

cri-o1.34-1.34.11-1.fc44

6 days ago
FEDORA-2026-8ce4ffda9c Packages in this update:
  • cri-o1.34-1.34.11-1.fc44
Update description:
  • Update to release v1.34.11
  • Resolves: rhbz#2510870
  • Resolves CVE-2026-34986: rhbz#2455652
  • Upstream fixes

cri-o1.36-1.36.3-1.fc45

6 days 1 hour ago
FEDORA-2026-e58c82fdeb Packages in this update:
  • cri-o1.36-1.36.3-1.fc45
Update description:

Automatic update for cri-o1.36-1.36.3-1.fc45.

Changelog * Tue Aug 4 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.3-1 - Update to release v1.36.3 - Resolves: rhbz#2510870 - Resolves CVE-2026-15809: rhbz#2500983 - Upstream fixes

cri-o1.34-1.34.11-1.fc45

6 days 1 hour ago
FEDORA-2026-16d1ad771a Packages in this update:
  • cri-o1.34-1.34.11-1.fc45
Update description:

Automatic update for cri-o1.34-1.34.11-1.fc45.

Changelog * Tue Aug 4 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.34.11-1 - Update to release v1.34.11 - Resolves: rhbz#2510870 - Resolves CVE-2026-34986: rhbz#2455652 - Upstream fixes

kernel-7.1.6-101.fc43

6 days 5 hours ago
FEDORA-2026-edefd5c974 Packages in this update:
  • kernel-7.1.6-101.fc43
Update description:

The 7.1.6 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

kernel-7.1.6-201.fc44

6 days 5 hours ago
FEDORA-2026-864f36550e Packages in this update:
  • kernel-7.1.6-201.fc44
Update description:

The 7.1.6 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.

freeipa-4.13.2-1.fc43 samba-4.23.10-1.fc43

6 days 7 hours ago
FEDORA-2026-8e7fa96cf3 Packages in this update:
  • freeipa-4.13.2-1.fc43
  • samba-4.23.10-1.fc43
Update description:

Update to Samba 4.23.10 (and rebuild of FreeIPA). Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224

freeipa-4.13.2-1.fc44 samba-4.24.5-1.fc44

6 days 7 hours ago
FEDORA-2026-fcd4630c0d Packages in this update:
  • freeipa-4.13.2-1.fc44
  • samba-4.24.5-1.fc44
Update description:

Update to Samba 4.24.5 (and rebuild of FreeIPA) Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224

freeipa-4.13.2-1.fc45 samba-4.24.5-1.fc45

6 days 7 hours ago
FEDORA-2026-3be8175017 Packages in this update:
  • freeipa-4.13.2-1.fc45
  • samba-4.24.5-1.fc45
Update description:

Update to Samba 4.24.5 (and rebuild of FreeIPA) Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221, CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224

chromium-151.0.7922.71-1.fc44

6 days 9 hours ago
FEDORA-2026-976bbbc661 Packages in this update:
  • chromium-151.0.7922.71-1.fc44
Update description:

security release chromium-151.0.7922.71 includes 370 security fixes: CVE-2026-17650 - CVE-2026-18019

chromium-151.0.7922.71-1.el10_3

6 days 9 hours ago
FEDORA-EPEL-2026-b5ec63afe6 Packages in this update:
  • chromium-151.0.7922.71-1.el10_3
Update description:

security release chromium-151.0.7922.71 includes 370 security fixes: CVE-2026-17650 - CVE-2026-18019

chromium-151.0.7922.71-1.el9

6 days 9 hours ago
FEDORA-EPEL-2026-f3e21f8f08 Packages in this update:
  • chromium-151.0.7922.71-1.el9
Update description:

security release chromium-151.0.7922.71 includes 370 security fixes: CVE-2026-17650 - CVE-2026-18019

chromium-151.0.7922.71-1.el10_2

6 days 9 hours ago
FEDORA-EPEL-2026-72e908c2d7 Packages in this update:
  • chromium-151.0.7922.71-1.el10_2
Update description:

security release chromium-151.0.7922.71 includes 370 security fixes: CVE-2026-17650 - CVE-2026-18019

chromium-151.0.7922.71-1.fc43

6 days 9 hours ago
FEDORA-2026-2c6aeb3b06 Packages in this update:
  • chromium-151.0.7922.71-1.fc43
Update description:

security release chromium-151.0.7922.71 includes 370 security fixes: CVE-2026-17650 - CVE-2026-18019

curl-8.15.0-8.fc43

6 days 9 hours ago
FEDORA-2026-097fb2e7e9 Packages in this update:
  • curl-8.15.0-8.fc43
Update description:
  • fix cross-proxy Digest auth state leak (CVE-2026-7168)
  • fix cross-origin Digest auth state leak (CVE-2026-11856)
  • fix password leak with netrc and user in URL (CVE-2026-8926)
  • fix SSH improper host validation (CVE-2026-9547)
  • fix trailing dot domain super cookie (CVE-2026-8924)

vaultwarden-1.37.1-1.fc44

6 days 16 hours ago
FEDORA-2026-c28185613c Packages in this update:
  • vaultwarden-1.37.1-1.fc44
Update description:

update to 1.37.1 fixes several cves, and some undisclosed vulnerabilities patched by upstream that will be published later

vaultwarden-1.37.1-1.el10_3

6 days 16 hours ago
FEDORA-EPEL-2026-ad59021631 Packages in this update:
  • vaultwarden-1.37.1-1.el10_3
Update description:

update to 1.37.1 fixes several cves, and some undisclosed vulnerabilities patched by upstream that will be published later

Checked
5 minutes 39 seconds ago