Fedora Security Advisories

strongswan-6.1.0-1.fc45

2 days 11 hours ago
FEDORA-2026-5db1745c4f Packages in this update:
  • strongswan-6.1.0-1.fc45
Update description:
  • Update to 6.1.0 for CVE-2026-78123, CVE-2026-78124, CVE-2026-78126, CVE-2026-78127, CVE-2026-78129, CVE-2026-78130, CVE-2026-78131, CVE-2026-78132, CVE-2026-78133, CVE-2026-78134 and CVE-2026-78135

rootlesskit-3.2.0-1.fc43

2 days 17 hours ago
FEDORA-2026-f5733c1dd0 Packages in this update:
  • rootlesskit-3.2.0-1.fc43
Update description:
  • Update to release v3.2.0
  • Resolves: rhbz#2530874
  • Resolves CVE-2026-56855: rhbz#2530631
  • Resolves CVE-2026-78662: rhbz#2530678
  • Upstream enhancements and fixes

perl-Imager-1.036-1.fc45

2 days 20 hours ago
FEDORA-2026-8e3688d489 Packages in this update:
  • perl-Imager-1.036-1.fc45
Update description:

1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)

perl-Imager-1.036-1.fc44

2 days 20 hours ago
FEDORA-2026-12f0a70554 Packages in this update:
  • perl-Imager-1.036-1.fc44
Update description:

1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)

perl-Imager-1.036-1.fc43

2 days 20 hours ago
FEDORA-2026-625ab5c382 Packages in this update:
  • perl-Imager-1.036-1.fc43
Update description:

1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)

rootlesskit-3.2.0-1.fc44

3 days 3 hours ago
FEDORA-2026-3e60aed77e Packages in this update:
  • rootlesskit-3.2.0-1.fc44
Update description:
  • Update to release v3.2.0
  • Resolves: rhbz#2530874
  • Resolves CVE-2026-56855: rhbz#2530631
  • Resolves CVE-2026-78662: rhbz#2530678
  • Upstream enhancements and fixes

rootlesskit-3.2.0-1.fc45

3 days 6 hours ago
FEDORA-2026-6b8872b8ac Packages in this update:
  • rootlesskit-3.2.0-1.fc45
Update description:
  • Update to release v3.2.0
  • Resolves: rhbz#2530874
  • Resolves CVE-2026-56855: rhbz#2530631
  • Resolves CVE-2026-78662: rhbz#2530678
  • Upstream enhancements and fixes

rootlesskit-3.2.0-1.fc46

3 days 8 hours ago
FEDORA-2026-ec725c24c1 Packages in this update:
  • rootlesskit-3.2.0-1.fc46
Update description:

Automatic update for rootlesskit-3.2.0-1.fc46.

Changelog * Sun Sep 20 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 3.2.0-1 - Update to release v3.2.0 - Resolves: rhbz#2530874 - Resolves CVE-2026-56855: rhbz#2530631 - Resolves CVE-2026-78662: rhbz#2530678 - Upstream enhancements and fixes

freeipmi-1.6.19-1.fc43

3 days 12 hours ago
FEDORA-2026-66894499b7 Packages in this update:
  • freeipmi-1.6.19-1.fc43
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

perl-Dancer2-2.2.1-1.fc44

3 days 12 hours ago
FEDORA-2026-3b893ccf2d Packages in this update:
  • perl-Dancer2-2.2.1-1.fc44
Update description:

Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.

deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.

perl-Dancer2-2.2.1-1.fc45

3 days 12 hours ago
FEDORA-2026-5e3eab9a07 Packages in this update:
  • perl-Dancer2-2.2.1-1.fc45
Update description:

Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.

deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.

Checked
24 minutes 39 seconds ago