4 days 19 hours ago
FEDORA-EPEL-2026-1bc4040b98
Packages in this update:
Update description:
Upgrade to new upstream version
CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability
CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability
4 days 19 hours ago
FEDORA-EPEL-2026-31efc13ba7
Packages in this update:
Update description:
Upgrade to new upstream version
CVE-2025-20260 squidclamav: ClamAV PDF Scanning Buffer Overflow Vulnerability
CVE-2025-20234 squidclamav: ClamAV Information Disclosure Vulnerability
5 days 2 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- Cryptographic API;
- InfiniBand drivers;
- Media drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- NVME drivers;
- File systems infrastructure;
- Ext4 file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- SCTP protocol;
- SMC sockets;
- TIPC protocol;
(CVE-2021-47378, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414,
CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071,
CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266,
CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931,
CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986,
CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002,
CVE-2026-53006, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53228, CVE-2026-53359)
5 days 2 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- File systems infrastructure;
- OCFS2 file system;
- B.A.T.M.A.N. meshing protocol;
- SCTP protocol;
- TIPC protocol;
(CVE-2026-43071, CVE-2026-52914, CVE-2026-52993, CVE-2026-53043,
CVE-2026-53224, CVE-2026-53246, CVE-2026-53309)
5 days 3 hours ago
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi
implementation in the Linux kernel did not properly handle aggregated
frames in mesh networks, due to an incorrect fix for CVE-2020-24588. A
physically proximate attacker could use this issue to inject packets.
(CVE-2025-27558)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- x86 architecture;
- InfiniBand drivers;
- Network drivers;
- NVME drivers;
- Ext4 file system;
- SMB network file system;
- IPv4 networking;
- Network traffic control;
- TCP network protocol;
- Locking primitives;
- IPv6 networking;
- Multipath TCP;
- Netfilter;
- Open vSwitch;
- SCTP protocol;
- SMC sockets;
(CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198,
CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331,
CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176,
CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225,
CVE-2026-53228, CVE-2026-53246, CVE-2026-53359, CVE-2026-64531)
5 days 3 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-64531)
5 days 3 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network drivers;
- Open vSwitch;
- SCTP protocol;
(CVE-2026-53224, CVE-2026-53246, CVE-2026-53247, CVE-2026-64531)
5 days 3 hours ago
FEDORA-2026-b02404c8c0
Packages in this update:
Update description:
The 7.2.1 stable kernel update contains a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
5 days 3 hours ago
FEDORA-2026-fd4ffe7527
Packages in this update:
Update description:
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
5 days 3 hours ago
FEDORA-2026-25d7c1eb61
Packages in this update:
Update description:
The 7.1.11 stable kernel updates contain a number of important fixes across the tree. We are now specifying all kernel updates as security because upstream will assign CVEs, but we will not know what those are until a bit after this update ships.
5 days 3 hours ago
FEDORA-2026-a6d01967c6
Packages in this update:
Update description:
Update to 2.1.1, update bundled libtiff to 4.7.2.
5 days 3 hours ago
FEDORA-2026-a23a377e11
Packages in this update:
Update description:
Update to 2.1.1, update bundled libtiff to 4.7.2.
5 days 3 hours ago
FEDORA-2026-993b0ea146
Packages in this update:
Update description:
Update to 2.1.1, update bundled libtiff to 4.7.2.
5 days 4 hours ago
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
5 days 8 hours ago
FEDORA-2026-f903f9ff11
Packages in this update:
Update description:
- fix proto-default skips SSH verification (CVE-2026-12064)
- fix wrong STARTTLS connection reuse (CVE-2026-8286)
- fix SASL double-free (CVE-2026-8925)
- fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
- fix exposing HTTP/3 early data (CVE-2026-9545)
- fix UAF after pause in socket callback (CVE-2026-9080)
5 days 9 hours ago
It was discovered that p11-kit incorrectly handled certain RPC messages. A
local attacker could use this issue to cause p11-kit to crash, resulting in
a denial of service. (CVE-2026-13757)
It was discovered that p11-kit incorrectly handled nested attribute
decoding on 32-bit systems. A local attacker could use this issue to cause
p11-kit to crash, resulting in a denial of service. (CVE-2026-18938)
5 days 9 hours ago
Version:next-20260827 (linux-next)
Released:2026-08-27
5 days 9 hours ago
It was discovered that primitive decoders in openCryptoki produced integer
underflows when the encoded length was zero. An attacker could possibly use
this issue to trigger out-of-bounds reads. (CVE-2026-40253)
It was discovered that openCryptoki incorrectly handled symlinks. An
attacker in the token-group could possibly use this issue to achieve
privilege escalation or access sensitive information. (CVE-2026-23893)
5 days 11 hours ago
FEDORA-EPEL-2026-9a4c6ee5c5
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 11 hours ago
FEDORA-EPEL-2026-bf7afd5dc2
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)