3 weeks 5 days ago
FEDORA-EPEL-2026-e25dddef14
Packages in this update:
- libsodium-1.0.21-2.el10_1
Update description:
Version 1.0.21
This point release includes all the changes from 1.0.20-stable, which
include a security fix for the crypto_core_ed25519_is_valid_point()
function, as well as two new sets of functions:
- The new crypto_ipcrypt_* functions implement mechanisms for securely
encrypting and anonymizing IP addresses as specified in https://ipcrypt-std.github.io
- The sodium_bin2ip and sodium_ip2bin helper functions have been added
to complement the crypto_ipcrypt_* functions and easily convert addresses
between bytes and strings.
- XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions
are standard extendable output functions. From input of any length, they can
derive output of any length with the same properties as hash functions. These
primitives are required by many post-quantum mechanisms, but can also be used
for a wide range of applications, including key derivation, session encryption
and more.
Version 1.0.20-stable
- XCFramework: cross-compilation is now forced on Apple Silicon to
avoid Rosetta-related build issues
- The Fil-C compiler is supported out of the box
- The CompCert compiler is supported out of the box
- MSVC 2026 (Visual Studio 2026) is now supported
- Zig builds now support FreeBSD targets
- Performance of AES256-GCM and AEGIS on ARM has been improved
with some compilers
- Android binaries have been added to the NuGet package
- Windows ARM binaries have been added to the NuGet package
- The Android build script has been improved. The base SDK is
now 27c, and the default platform is 21, supporting 16 KB page sizes.
- The library can now be compiled with Zig 0.15 and Zig 0.16
- Zig builds now generate position-independent static libraries by
default on targets that support PIC
- arm64e builds have been added to the XCFramework packages
- XCFramework packages are now full builds instead of minimal
builds
- MSVC builds have been enabled for ARM64
- iOS 32-bit (armv7/armv7s) support has been removed from the
XCFramework build script
- Security: optblockers have been introduced in critical code paths
to prevent compilers from introducing unwanted side channels via
conditional jumps. This was observed on RISC-V targets with specific
compilers and options.
- Security: crypto_core_ed25519_is_valid_point() now properly
rejects small-order points that are not in the main subgroup
- ((nonnull)) attributes have been relaxed on some crypto_stream*
functions to allow NULL output buffers when the output length is zero
- A cross-compilation issue with old clang versions has been
fixed
- JavaScript: support for Cloudflare Workers has been added
- JavaScript: WASM_BIGINT is forcibly disabled to retain
compatibility with older runtimes
- A compilation issue with old toolchains on Solaris has been
fixed
- crypto_aead_aes256gcm_is_available is exported to JavaScript
- libsodium is now compatible with Emscripten 4.x
- Security: memory fences have been added after MAC verification in
AEAD to prevent speculative access to plaintext before authentication
is complete
- Assembly files now include .gnu.property notes for proper IBT and
Shadow Stack support when building with CET instrumentation
3 weeks 5 days ago
FEDORA-2026-cb424f8aa2
Packages in this update:
Update description:
Version 1.0.21
This point release includes all the changes from 1.0.20-stable, which
include a security fix for the crypto_core_ed25519_is_valid_point()
function, as well as two new sets of functions:
- The new crypto_ipcrypt_* functions implement mechanisms for securely
encrypting and anonymizing IP addresses as specified in https://ipcrypt-std.github.io
- The sodium_bin2ip and sodium_ip2bin helper functions have been added
to complement the crypto_ipcrypt_* functions and easily convert addresses
between bytes and strings.
- XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions
are standard extendable output functions. From input of any length, they can
derive output of any length with the same properties as hash functions. These
primitives are required by many post-quantum mechanisms, but can also be used
for a wide range of applications, including key derivation, session encryption
and more.
Version 1.0.20-stable
- XCFramework: cross-compilation is now forced on Apple Silicon to
avoid Rosetta-related build issues
- The Fil-C compiler is supported out of the box
- The CompCert compiler is supported out of the box
- MSVC 2026 (Visual Studio 2026) is now supported
- Zig builds now support FreeBSD targets
- Performance of AES256-GCM and AEGIS on ARM has been improved
with some compilers
- Android binaries have been added to the NuGet package
- Windows ARM binaries have been added to the NuGet package
- The Android build script has been improved. The base SDK is
now 27c, and the default platform is 21, supporting 16 KB page sizes.
- The library can now be compiled with Zig 0.15 and Zig 0.16
- Zig builds now generate position-independent static libraries by
default on targets that support PIC
- arm64e builds have been added to the XCFramework packages
- XCFramework packages are now full builds instead of minimal
builds
- MSVC builds have been enabled for ARM64
- iOS 32-bit (armv7/armv7s) support has been removed from the
XCFramework build script
- Security: optblockers have been introduced in critical code paths
to prevent compilers from introducing unwanted side channels via
conditional jumps. This was observed on RISC-V targets with specific
compilers and options.
- Security: crypto_core_ed25519_is_valid_point() now properly
rejects small-order points that are not in the main subgroup
- ((nonnull)) attributes have been relaxed on some crypto_stream*
functions to allow NULL output buffers when the output length is zero
- A cross-compilation issue with old clang versions has been
fixed
- JavaScript: support for Cloudflare Workers has been added
- JavaScript: WASM_BIGINT is forcibly disabled to retain
compatibility with older runtimes
- A compilation issue with old toolchains on Solaris has been
fixed
- crypto_aead_aes256gcm_is_available is exported to JavaScript
- libsodium is now compatible with Emscripten 4.x
- Security: memory fences have been added after MAC verification in
AEAD to prevent speculative access to plaintext before authentication
is complete
- Assembly files now include .gnu.property notes for proper IBT and
Shadow Stack support when building with CET instrumentation
3 weeks 5 days ago
FEDORA-EPEL-2026-c60f76437d
Packages in this update:
- libsodium-1.0.21-2.el10_2
Update description:
Version 1.0.21
This point release includes all the changes from 1.0.20-stable, which
include a security fix for the crypto_core_ed25519_is_valid_point()
function, as well as two new sets of functions:
- The new crypto_ipcrypt_* functions implement mechanisms for securely
encrypting and anonymizing IP addresses as specified in https://ipcrypt-std.github.io
- The sodium_bin2ip and sodium_ip2bin helper functions have been added
to complement the crypto_ipcrypt_* functions and easily convert addresses
between bytes and strings.
- XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions
are standard extendable output functions. From input of any length, they can
derive output of any length with the same properties as hash functions. These
primitives are required by many post-quantum mechanisms, but can also be used
for a wide range of applications, including key derivation, session encryption
and more.
Version 1.0.20-stable
- XCFramework: cross-compilation is now forced on Apple Silicon to
avoid Rosetta-related build issues
- The Fil-C compiler is supported out of the box
- The CompCert compiler is supported out of the box
- MSVC 2026 (Visual Studio 2026) is now supported
- Zig builds now support FreeBSD targets
- Performance of AES256-GCM and AEGIS on ARM has been improved
with some compilers
- Android binaries have been added to the NuGet package
- Windows ARM binaries have been added to the NuGet package
- The Android build script has been improved. The base SDK is
now 27c, and the default platform is 21, supporting 16 KB page sizes.
- The library can now be compiled with Zig 0.15 and Zig 0.16
- Zig builds now generate position-independent static libraries by
default on targets that support PIC
- arm64e builds have been added to the XCFramework packages
- XCFramework packages are now full builds instead of minimal
builds
- MSVC builds have been enabled for ARM64
- iOS 32-bit (armv7/armv7s) support has been removed from the
XCFramework build script
- Security: optblockers have been introduced in critical code paths
to prevent compilers from introducing unwanted side channels via
conditional jumps. This was observed on RISC-V targets with specific
compilers and options.
- Security: crypto_core_ed25519_is_valid_point() now properly
rejects small-order points that are not in the main subgroup
- ((nonnull)) attributes have been relaxed on some crypto_stream*
functions to allow NULL output buffers when the output length is zero
- A cross-compilation issue with old clang versions has been
fixed
- JavaScript: support for Cloudflare Workers has been added
- JavaScript: WASM_BIGINT is forcibly disabled to retain
compatibility with older runtimes
- A compilation issue with old toolchains on Solaris has been
fixed
- crypto_aead_aes256gcm_is_available is exported to JavaScript
- libsodium is now compatible with Emscripten 4.x
- Security: memory fences have been added after MAC verification in
AEAD to prevent speculative access to plaintext before authentication
is complete
- Assembly files now include .gnu.property notes for proper IBT and
Shadow Stack support when building with CET instrumentation
3 weeks 5 days ago
FEDORA-2026-b7217393db
Packages in this update:
Update description:
Version 1.0.21
This point release includes all the changes from 1.0.20-stable, which
include a security fix for the crypto_core_ed25519_is_valid_point()
function, as well as two new sets of functions:
- The new crypto_ipcrypt_* functions implement mechanisms for securely
encrypting and anonymizing IP addresses as specified in https://ipcrypt-std.github.io
- The sodium_bin2ip and sodium_ip2bin helper functions have been added
to complement the crypto_ipcrypt_* functions and easily convert addresses
between bytes and strings.
- XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions
are standard extendable output functions. From input of any length, they can
derive output of any length with the same properties as hash functions. These
primitives are required by many post-quantum mechanisms, but can also be used
for a wide range of applications, including key derivation, session encryption
and more.
Version 1.0.20-stable
- XCFramework: cross-compilation is now forced on Apple Silicon to
avoid Rosetta-related build issues
- The Fil-C compiler is supported out of the box
- The CompCert compiler is supported out of the box
- MSVC 2026 (Visual Studio 2026) is now supported
- Zig builds now support FreeBSD targets
- Performance of AES256-GCM and AEGIS on ARM has been improved
with some compilers
- Android binaries have been added to the NuGet package
- Windows ARM binaries have been added to the NuGet package
- The Android build script has been improved. The base SDK is
now 27c, and the default platform is 21, supporting 16 KB page sizes.
- The library can now be compiled with Zig 0.15 and Zig 0.16
- Zig builds now generate position-independent static libraries by
default on targets that support PIC
- arm64e builds have been added to the XCFramework packages
- XCFramework packages are now full builds instead of minimal
builds
- MSVC builds have been enabled for ARM64
- iOS 32-bit (armv7/armv7s) support has been removed from the
XCFramework build script
- Security: optblockers have been introduced in critical code paths
to prevent compilers from introducing unwanted side channels via
conditional jumps. This was observed on RISC-V targets with specific
compilers and options.
- Security: crypto_core_ed25519_is_valid_point() now properly
rejects small-order points that are not in the main subgroup
- ((nonnull)) attributes have been relaxed on some crypto_stream*
functions to allow NULL output buffers when the output length is zero
- A cross-compilation issue with old clang versions has been
fixed
- JavaScript: support for Cloudflare Workers has been added
- JavaScript: WASM_BIGINT is forcibly disabled to retain
compatibility with older runtimes
- A compilation issue with old toolchains on Solaris has been
fixed
- crypto_aead_aes256gcm_is_available is exported to JavaScript
- libsodium is now compatible with Emscripten 4.x
- Security: memory fences have been added after MAC verification in
AEAD to prevent speculative access to plaintext before authentication
is complete
- Assembly files now include .gnu.property notes for proper IBT and
Shadow Stack support when building with CET instrumentation
3 weeks 5 days ago
Han Zheng discovered that libcaca incorrectly handled certain images.
An attacker could possibly use this issue to cause libcaca to crash.
3 weeks 5 days ago
Version:next-20260107 (linux-next)
Released:2026-01-07
3 weeks 5 days ago
3 weeks 5 days ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Cryptographic API;
- ACPI drivers;
- InfiniBand drivers;
- Media drivers;
- Network drivers;
- Pin controllers subsystem;
- AFS file system;
- F2FS file system;
- Tracing infrastructure;
- Memory management;
- Appletalk network protocol;
- Netfilter;
(CVE-2022-49026, CVE-2022-49390, CVE-2024-47691, CVE-2024-49935,
CVE-2024-50067, CVE-2024-50095, CVE-2024-50196, CVE-2024-53090,
CVE-2024-53218, CVE-2025-21855, CVE-2025-37958, CVE-2025-38666,
CVE-2025-39964, CVE-2025-39993, CVE-2025-40018)
3 weeks 5 days ago
3 weeks 5 days ago
FEDORA-2026-28b0f7bd35
Packages in this update:
Update description:
New version 2.2.1
3 weeks 5 days ago
FEDORA-2026-de1a91fe79
Packages in this update:
Update description:
New version 2.2.1
3 weeks 5 days ago
It was discovered that GLib incorrectly handled escaping URI strings. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-13601)
It was discovered that GLib incorrectly parsed certain GVariants. An
attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2025-14087)
It was discovered that GLib incorrectly parsed certain long invalid ISO
8601 timestamps. An attacker could possibly use this issue to cause GLib to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-3360)
It was discovered that GLib incorrectly handled GString memory operations.
An attacker could use this issue to cause GLib to crash, resulting in a
denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 24.04 LTS and Ubuntu 25.04. (CVE-2025-6052)
It was discovered that GLib incorrectly handled creating temporary files.
An attacker could possibly use this issue to access unauthorized data. This
issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.
(CVE-2025-7039)
3 weeks 5 days ago
FEDORA-EPEL-2026-cccbda720c
Packages in this update:
Update description:
Update to 2.53.23
3 weeks 5 days ago
FEDORA-EPEL-2026-cecc10e473
Packages in this update:
Update description:
Update to 2.53.23
3 weeks 5 days ago
FEDORA-2026-51d2cb6e19
Packages in this update:
Update description:
Update to 2.53.23
3 weeks 5 days ago
FEDORA-2026-f54e4ee85a
Packages in this update:
Update description:
Update to 2.53.23
3 weeks 6 days ago
FEDORA-2026-a9dc8509e9
Packages in this update:
Update description:
fixes several security issues
3 weeks 6 days ago
Version:next-20260106 (linux-next)
Released:2026-01-06
3 weeks 6 days ago
FEDORA-2026-1e3425e7ea
Packages in this update:
Update description:
New version 1.10.6
3 weeks 6 days ago
FEDORA-2026-274010c760
Packages in this update:
Update description:
New version 1.10.6