Aggregator
rust-h2-0.4.17-1.fc44
- rust-h2-0.4.17-1.fc44
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
rust-h2-0.4.17-1.fc43
- rust-h2-0.4.17-1.fc43
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
rust-h2-0.4.17-1.el10_3
- rust-h2-0.4.17-1.el10_3
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
rust-h2-0.4.17-1.el9
- rust-h2-0.4.17-1.el9
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
rust-h2-0.4.17-1.el10_2
- rust-h2-0.4.17-1.el10_2
Update to version 0.4.17.
This includes a fix for a low-severity security vulnerability designated RUSTSEC-2026-0258 / GHSA-q83h-524g-xf6h.
ceph-20.2.4-1.fc44
- ceph-20.2.4-1.fc44
- CVE-2025-30156 is an authentication bypass in CephX caused by misuse of AES-CBC.
- CVE-2026-39944 shares the unauthenticated-encryption root cause of CVE-2025-30156
- CVE-2026-50152 is an improper authorization flaw in the Ceph Monitor subscription handler.
- CVE-2026-54330 is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.
ceph-19.2.6-1.fc43
- ceph-19.2.6-1.fc43
- CVE-2025-30156 is an authentication bypass in CephX caused by misuse of AES-CBC.
- CVE-2026-39944 shares the unauthenticated-encryption root cause of CVE-2025-30156
- CVE-2026-50152 is an improper authorization flaw in the Ceph Monitor subscription handler.
- CVE-2026-54330 is a flaw in RGW not properly verifying its SigV4 cryptographic signatures in RGW's SigV4 verifier.
USN-8563-4: nginx regression
java-21-openjdk-21.0.12.1.1-1.0.fc43 java-21-openjdk-portable-21.0.12.1.1-1.0.fc43
- java-21-openjdk-21.0.12.1.1-1.0.fc43
- java-21-openjdk-portable-21.0.12.1.1-1.0.fc43
First monthly cadence release candidate
USN-8651-1: curl vulnerability
7.1.9: stable
6.18.45: longterm
6.12.104: longterm
6.6.152: longterm
USN-8650-1: Cap'n Proto vulnerabilities
6.1.183: longterm
5.15.216: longterm
5.10.265: longterm
bluez-5.87-4.fc43
- bluez-5.87-4.fc43
An out-of-bounds read flaw was found in BlueZ in the AVRCP profile implementation. The vulnerability exists in the parse_media_element() and parse_media_folder() functions in profiles/audio/avrcp.c, where insufficient validation of packet length fields in GetFolderItems responses allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This can result in a crash of the bluetoothd daemon (denial of service) and potentially expose sensitive heap memory contents.
This update fixes this issue (CVE-2026-75032)