3 weeks 1 day ago
FEDORA-2025-99f0d93d68
Packages in this update:
- rust-hickory-proto-0.24.4-1.fc42
Update description:
Update to version 0.24.4.
Also contains fixes for RUSTSEC-2025-0006.
3 weeks 1 day ago
FEDORA-EPEL-2025-fac458e143
Packages in this update:
- rust-hickory-proto-0.24.4-1.el9
Update description:
Update to version 0.24.4.
Also contains fixes for RUSTSEC-2025-0006.
3 weeks 1 day ago
FEDORA-2025-def79f4594
Packages in this update:
- rust-hickory-proto-0.24.4-1.fc41
Update description:
Update to version 0.24.4.
Also contains fixes for RUSTSEC-2025-0006.
3 weeks 1 day ago
FEDORA-EPEL-2025-0a14976263
Packages in this update:
- rust-hickory-proto-0.24.4-1.el10_1
Update description:
Update to version 0.24.4.
Also contains fixes for RUSTSEC-2025-0006.
3 weeks 1 day ago
Fabien Potencier discovered that Twig did not run sandbox security checks
in some circumstances. An attacker could possibly use this issue to cause
a denial of service or execute arbitrary commands. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-45411)
Jamie Schouten discovered that Twig could bypass the security policy for
an object call. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2024-51754)
3 weeks 1 day ago
Jann Horn discovered that the watch_queue event notification subsystem in
the Linux kernel contained an out-of-bounds write vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
escalate their privileges. (CVE-2022-0995)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- File systems infrastructure;
- NTFS3 file system;
- Ethernet bridge;
- Ethtool driver;
- IPv6 networking;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-56651, CVE-2025-21756, CVE-2024-26837, CVE-2025-21700,
CVE-2024-46826, CVE-2024-50256, CVE-2024-50248, CVE-2025-21993,
CVE-2025-21702, CVE-2025-21701, CVE-2025-21703)
3 weeks 1 day ago
3 weeks 1 day ago
3 weeks 1 day ago
3 weeks 1 day ago
Jann Horn discovered that the watch_queue event notification subsystem in
the Linux kernel contained an out-of-bounds write vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
escalate their privileges. (CVE-2022-0995)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- File systems infrastructure;
- NTFS3 file system;
- Ethernet bridge;
- Ethtool driver;
- IPv6 networking;
- Network traffic control;
- VMware vSockets driver;
(CVE-2024-26837, CVE-2025-21993, CVE-2025-21702, CVE-2025-21700,
CVE-2025-21701, CVE-2024-50248, CVE-2024-56651, CVE-2024-46826,
CVE-2024-50256, CVE-2025-21756, CVE-2025-21703)
3 weeks 1 day ago
Jann Horn discovered that the watch_queue event notification subsystem in
the Linux kernel contained an out-of-bounds write vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
escalate their privileges. (CVE-2022-0995)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- File systems infrastructure;
- NTFS3 file system;
- Ethernet bridge;
- Ethtool driver;
- IPv6 networking;
- Network traffic control;
- VMware vSockets driver;
(CVE-2025-21703, CVE-2024-56651, CVE-2024-50248, CVE-2025-21701,
CVE-2024-26837, CVE-2024-46826, CVE-2025-21993, CVE-2025-21702,
CVE-2024-50256, CVE-2025-21756, CVE-2025-21700)
3 weeks 2 days ago
FEDORA-2025-f68a9b835d
Packages in this update:
- nodejs-bash-language-server-5.6.0-1.fc40
- nodejs-pnpm-10.9.0-1.fc40
Update description:
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language-server to version 5.6.0
3 weeks 2 days ago
FEDORA-2025-d4cc30bdfb
Packages in this update:
- nodejs-bash-language-server-5.6.0-1.fc41
- nodejs-pnpm-10.9.0-1.fc41
Update description:
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language-server to version 5.6.0
3 weeks 2 days ago
FEDORA-2025-69a1acbbc0
Packages in this update:
- nodejs-bash-language-server-5.6.0-2.fc42
- nodejs-pnpm-10.9.0-1.fc42
Update description:
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language-server to version 5.6.0
3 weeks 2 days ago
FEDORA-2025-d191ee2f9a
Packages in this update:
Update description:
Valkey 8.0.3 - Released Wed 23 Apr 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Bug fixes
- Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
- Fix memory leak in forgotten node ping ext code path (#1574)
- Fix cluster info sent stats for message with light header (#1563)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix temp file leak druing replication error handling (#1721)
- Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix cluster slot stats assertion during promotion of replica (#1950)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Ignore stale gossip packets that arrive out of order (#1777)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
- Avoid shard id update of replica if not matching with primary shard id (#573)
Security fixes
- CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)
3 weeks 2 days ago
FEDORA-EPEL-2025-eb3543f6b8
Packages in this update:
Update description:
Valkey 8.0.3 - Released Wed 23 Apr 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Bug fixes
- Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
- Fix memory leak in forgotten node ping ext code path (#1574)
- Fix cluster info sent stats for message with light header (#1563)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix temp file leak druing replication error handling (#1721)
- Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix cluster slot stats assertion during promotion of replica (#1950)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Ignore stale gossip packets that arrive out of order (#1777)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
- Avoid shard id update of replica if not matching with primary shard id (#573)
Security fixes
- CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)
3 weeks 2 days ago
FEDORA-2025-59ebc165fc
Packages in this update:
Update description:
Valkey 8.0.3 - Released Wed 23 Apr 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Bug fixes
- Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
- Fix memory leak in forgotten node ping ext code path (#1574)
- Fix cluster info sent stats for message with light header (#1563)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix temp file leak druing replication error handling (#1721)
- Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix cluster slot stats assertion during promotion of replica (#1950)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Ignore stale gossip packets that arrive out of order (#1777)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
- Avoid shard id update of replica if not matching with primary shard id (#573)
Security fixes
- CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)
3 weeks 2 days ago
FEDORA-2025-2ccc1f4ed9
Packages in this update:
Update description:
Valkey 8.0.3 - Released Wed 23 Apr 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Bug fixes
- Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
- Fix memory leak in forgotten node ping ext code path (#1574)
- Fix cluster info sent stats for message with light header (#1563)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix temp file leak druing replication error handling (#1721)
- Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix cluster slot stats assertion during promotion of replica (#1950)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Ignore stale gossip packets that arrive out of order (#1777)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
- Avoid shard id update of replica if not matching with primary shard id (#573)
Security fixes
- CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)
3 weeks 2 days ago
FEDORA-EPEL-2025-a73f52377d
Packages in this update:
Update description:
Valkey 8.0.3 - Released Wed 23 Apr 2025
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Bug fixes
- Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
- Fix memory leak in forgotten node ping ext code path (#1574)
- Fix cluster info sent stats for message with light header (#1563)
- Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
- Fix potential crash in radix tree recompression of huge keys (#1722)
- Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
- Fix temp file leak druing replication error handling (#1721)
- Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
- Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
- fix: add samples to stream object consumer trees (#1825)
- Fix cluster slot stats assertion during promotion of replica (#1950)
- Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
- Ignore stale gossip packets that arrive out of order (#1777)
- Fix incorrect lag reported in XINFO GROUPS (#1952)
- Avoid shard id update of replica if not matching with primary shard id (#573)
Security fixes
- CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)
3 weeks 2 days ago
FEDORA-2025-290b0c6e2b
Packages in this update:
Update description:
Redis 7.2.8 Released Wed 23 Apr 2025 12:00:00 IST
Update urgency: SECURITY: There are security fixes in the release.
Security fixes
- (CVE-2025-21605) An unauthenticated client can cause an unlimited growth of output buffers
Bug fixes
- Fix race condition issues between the main thread and module threads
- RANDOMKEY - infinite loop during client pause
- ShardID inconsistency when both primary and replica support it