Aggregator

USN-8725-1: Linux kernel vulnerabilities

3 days 18 hours ago
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - NVIDIA Tegra memory controller driver; - File systems infrastructure; - Network file system (NFS) server daemon; - OCFS2 file system; - B.A.T.M.A.N. meshing protocol; - Netfilter; - SCTP protocol; (CVE-2022-50401, CVE-2026-43071, CVE-2026-52914, CVE-2026-53002, CVE-2026-53043, CVE-2026-53045, CVE-2026-53224, CVE-2026-53309)

php-pecl-mongodb2-2.5.2-1.fc45

4 days 3 hours ago
FEDORA-2026-1576c48cce Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.fc45
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 2.5.0
  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
Version 2.4.1

php-pecl-mongodb2-2.5.2-1.el10_4

4 days 3 hours ago
FEDORA-EPEL-2026-b4364ba946 Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.el10_4
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 2.5.0
  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
Version 2.4.1 Version 2.4.0

Release Highlights

  • Add support for stringOpts in ClientEncryption::encrypt() in #2033 by @GromNaN
  • Support object cloning for ReadConcern, ReadPreference, and WriteConcern in #2002 by @GromNaN

php-pecl-mongodb2-2.5.2-1.el10_3

4 days 3 hours ago
FEDORA-EPEL-2026-bb3aac9602 Packages in this update:
  • php-pecl-mongodb2-2.5.2-1.el10_3
Update description: Version 2.5.2
  • PHPC-2744 Fix out-of-bounds read when building BSON field path by @paulinevos & @GromNaN in #2081 CVE-2026-84968
Version 2.5.0
  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
Version 2.4.1 Version 2.4.0

Release Highlights

  • Add support for stringOpts in ClientEncryption::encrypt() in #2033 by @GromNaN
  • Support object cloning for ReadConcern, ReadPreference, and WriteConcern in #2002 by @GromNaN

perl-Protocol-HTTP2-1.14-1.fc43

4 days 3 hours ago
FEDORA-2026-06b545f607 Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc43
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

perl-Protocol-HTTP2-1.14-1.fc44

4 days 3 hours ago
FEDORA-2026-e06691a7c4 Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc44
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

perl-Protocol-HTTP2-1.14-1.fc45

4 days 3 hours ago
FEDORA-2026-038229756e Packages in this update:
  • perl-Protocol-HTTP2-1.14-1.fc45
Update description:

This release fixes CVE-2026-16028 (a memory exhaustion causing a denial of service) and a license wording.

mongo-c-driver-1.30.9-1.el10_2

4 days 4 hours ago
FEDORA-EPEL-2026-ef4ca1433b Packages in this update:
  • mongo-c-driver-1.30.9-1.el10_2
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.el9

4 days 4 hours ago
FEDORA-EPEL-2026-942d98e619 Packages in this update:
  • mongo-c-driver-1.30.9-1.el9
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.fc44

4 days 4 hours ago
FEDORA-2026-8ed63cce6b Packages in this update:
  • mongo-c-driver-1.30.9-1.fc44
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.fc43

4 days 4 hours ago
FEDORA-2026-f74926c622 Packages in this update:
  • mongo-c-driver-1.30.9-1.fc43
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-1.30.9-1.el8

4 days 4 hours ago
FEDORA-EPEL-2026-4f2d0d5209 Packages in this update:
  • mongo-c-driver-1.30.9-1.el8
Update description: libmongoc 1.30.9

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963

mongo-c-driver-2.5.2-1.el10_3

4 days 4 hours ago
FEDORA-EPEL-2026-03de7cc5de Packages in this update:
  • mongo-c-driver-2.5.2-1.el10_3
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.2-1.el10_4

4 days 4 hours ago
FEDORA-EPEL-2026-9df5c5ffc2 Packages in this update:
  • mongo-c-driver-2.5.2-1.el10_4
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)
libmongoc 2.5.0

New Features

  • Honor the server-supplied baseBackoffMS on responses labeled SystemOverloadedError, using it in place of the driver's default base delay when calculating how long to wait before retrying.
  • Add collection bulk write getters.

mongo-c-driver-2.5.2-1.fc45

4 days 4 hours ago
FEDORA-2026-83792d666c Packages in this update:
  • mongo-c-driver-2.5.2-1.fc45
Update description: libmongoc 2.5.2

Fixes

  • Fix OCSP error handling. CVE-2026-84964
  • Fix unsafe casts during JSON parsing. CVE-2026-84965
  • Fix possible unsafe truncation when logging base64. CVE-2026-84969
  • Fix unsafe calls to bson_next_power_of_two. CVE-2026-84963
libmongoc 2.5.1

Fixes

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81524)

libmongocrypt-1.20.4-1.el10_3

4 days 5 hours ago
FEDORA-EPEL-2026-52df07119c Packages in this update:
  • libmongocrypt-1.20.4-1.el10_3
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).

libmongocrypt-1.20.4-1.el10_4

4 days 5 hours ago
FEDORA-EPEL-2026-20b328f827 Packages in this update:
  • libmongocrypt-1.20.4-1.el10_4
Update description: Version 1.20.4

Fixed

  • Reject undersized decryption payloads. CVE-2026-84971
Version 1.20.3

Fixed

  • Validate database and collection name arguments against "." and NUL bytes (CVE-2026-81523).