Aggregator
USN-7804-1: Squid vulnerability
next-20251006: linux-next
USN-7803-1: poppler vulnerability
USN-7691-2: MySQL vulnerabilities
openssl-3.2.6-2.fc41
- openssl-3.2.6-2.fc41
Resolves: CVE-2025-9230, CVE-2025-9231, CVE-2025-9232
openssl-3.2.6-2.fc42
- openssl-3.2.6-2.fc42
Resolves: CVE-2025-9230, CVE-2025-9231, CVE-2025-9232
valkey-8.0.6-1.el8
- valkey-8.0.6-1.el8
Valkey 8.0.6 - Released Fri 03 October 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security fixes
- CVE-2025-49844 A Lua script may lead to remote code execution
- CVE-2025-46817 A Lua script may lead to integer overflow and potential RCE
- CVE-2025-46818 A Lua script can be executed in the context of another user
- CVE-2025-46819 LUA out-of-bound read
Bug fixes
- Fix accounting for dual channel RDB bytes in replication stats (#2616)
- Minor fix for dual rdb channel connection conn error log (#2658)
- Fix unsigned difference expression compared to zero (#2101)
Valkey 8.0.5 - Released Thu 22 Aug 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Bug fixes
- Fix clients remaining blocked when reprocessing commands after certain blocking operations (#2109)
- Fix a memory corruption issue in the sharded pub/sub unsubscribe logic (#2137)
- Fix potential memory leak by ensuring module context is freed when aux_save2 callback writes no data (#2132)
- Fix CLIENT UNBLOCK triggering unexpected errors when used on paused clients (#2117)
- Fix missing NULL check on SSL_new() when creating outgoing TLS connections (#2140)
- Fix incorrect casting of ping extension lengths to prevent silent packet drops (#2144)
- Fix replica failover stall due to outdated config epoch (#2178)
- Fix incorrect port/tls-port info in CLUSTER SLOTS/CLUSTER NODES after dynamic config change (#2186)
- Ensure empty error tables in Lua scripts don't crash Valkey (#2229)
- Fix client tracking memory overhead calculation (#2360)
- Handle divergent shard-id from nodes.conf and reconcile to the primary node's shard-id (#2174)
- Fix pre-size hashtables per slot when reading RDB files (#2466)
Behavior changes
- Trigger election immediately during a forced manual failover (CLUSTER FAILOVER FORCE) to avoid delay (#1067)
- Reset ongoing election state when initiating a new manual failover (#1274)
Logging and Tooling Improvements
- Add support to drop all cluster packets (#1252)
- Improve log clarity in failover auth denial message (#1341)
Security fixes
- CVE-2025-27151: Check length of AOF file name in valkey-check-aof and reject paths longer than PATH_MAX (#2146)
valkey-8.0.6-1.el9
- valkey-8.0.6-1.el9
Valkey 8.0.6 - Released Fri 03 October 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Security fixes
- CVE-2025-49844 A Lua script may lead to remote code execution
- CVE-2025-46817 A Lua script may lead to integer overflow and potential RCE
- CVE-2025-46818 A Lua script can be executed in the context of another user
- CVE-2025-46819 LUA out-of-bound read
Bug fixes
- Fix accounting for dual channel RDB bytes in replication stats (#2616)
- Minor fix for dual rdb channel connection conn error log (#2658)
- Fix unsigned difference expression compared to zero (#2101)
Valkey 8.0.5 - Released Thu 22 Aug 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.
Bug fixes
- Fix clients remaining blocked when reprocessing commands after certain blocking operations (#2109)
- Fix a memory corruption issue in the sharded pub/sub unsubscribe logic (#2137)
- Fix potential memory leak by ensuring module context is freed when aux_save2 callback writes no data (#2132)
- Fix CLIENT UNBLOCK triggering unexpected errors when used on paused clients (#2117)
- Fix missing NULL check on SSL_new() when creating outgoing TLS connections (#2140)
- Fix incorrect casting of ping extension lengths to prevent silent packet drops (#2144)
- Fix replica failover stall due to outdated config epoch (#2178)
- Fix incorrect port/tls-port info in CLUSTER SLOTS/CLUSTER NODES after dynamic config change (#2186)
- Ensure empty error tables in Lua scripts don't crash Valkey (#2229)
- Fix client tracking memory overhead calculation (#2360)
- Handle divergent shard-id from nodes.conf and reconcile to the primary node's shard-id (#2174)
- Fix pre-size hashtables per slot when reading RDB files (#2466)
Behavior changes
- Trigger election immediately during a forced manual failover (CLUSTER FAILOVER FORCE) to avoid delay (#1067)
- Reset ongoing election state when initiating a new manual failover (#1274)
Logging and Tooling Improvements
- Add support to drop all cluster packets (#1252)
- Improve log clarity in failover auth denial message (#1341)
Security fixes
- CVE-2025-27151: Check length of AOF file name in valkey-check-aof and reject paths longer than PATH_MAX (#2146)
6.17.1: stable
6.16.11: stable
6.12.51: longterm
6.6.110: longterm
mod_http2-2.0.35-1.fc41
- mod_http2-2.0.35-1.fc41
- version update
mod_http2-2.0.35-1.fc42
- mod_http2-2.0.35-1.fc42
- version update
DSA-6019-1 dovecot - security update
mingw-poppler-24.08.0-6.fc42
- mingw-poppler-24.08.0-6.fc42
Backport fix for CVE-2025-43718.
mingw-poppler-24.02.0-6.fc41
- mingw-poppler-24.02.0-6.fc41
Backport fix for CVE-2025-43718.
chromium-141.0.7390.54-1.el10_2
- chromium-141.0.7390.54-1.el10_2
Update to 141.0.7390.54
* High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8chromium-141.0.7390.54-1.fc43
- chromium-141.0.7390.54-1.fc43
Update to 141.0.7390.54
* High CVE-2025-11205: Heap buffer overflow in WebGPU * High CVE-2025-11206: Heap buffer overflow in Video * Medium CVE-2025-11207: Side-channel information leakage in Storage * Medium CVE-2025-11208: Inappropriate implementation in Media * Medium CVE-2025-11209: Inappropriate implementation in Omnibox * Medium CVE-2025-11210: Side-channel information leakage in Tab * Medium CVE-2025-11211: Out of bounds read in Media * Medium CVE-2025-11212: Inappropriate implementation in Media * Medium CVE-2025-11213: Inappropriate implementation in Omnibox * Medium CVE-2025-11215: Off by one error in V8 * Low CVE-2025-11216: Inappropriate implementation in Storage * Low CVE-2025-11219: Use after free in V8