Aggregator

jq-1.8.2-4.fc45

4 days 1 hour ago
FEDORA-2026-b43264dedb Packages in this update:
  • jq-1.8.2-4.fc45
Update description:

Automatic update for jq-1.8.2-4.fc45.

Changelog * Sat Jun 20 2026 Filipe Rosset <filiperosset@fedoraproject.org> - 1.8.2-4 - removed old upstreamed patches * Sat Jun 20 2026 Filipe Rosset <filiperosset@fedoraproject.org> - 1.8.2-3 - opt-in to packit for rawhide * Sat Jun 20 2026 Filipe Rosset <filiperosset@fedoraproject.org> - 1.8.2-2 - simplify .gitignore file * Sat Jun 20 2026 Filipe Rosset <filiperosset@fedoraproject.org> - 1.8.2-1 - update to 1.8.2 fixes rhbz#2458354 rhbz#2477179 rhbz#2477180 rhbz#2477235 rhbz#2477236 rhbz#2477522 rhbz#2477523

USN-8487-1: curl vulnerabilities

4 days 2 hours ago
Andrew Nesbitt discovered that curl could reuse an existing live connection during STARTTLS-based connection upgrades even when the TLS configuration did not match. A remote attacker could possibly use this issue to cause curl to use an unintended TLS configuration. (CVE-2026-8286) Muhamad Arga Reksapati discovered that curl incorrectly reused connections for Negotiate-authenticated requests when different services were involved. A remote attacker could possibly use this issue to access resources authenticated for another service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458) It was discovered that curl incorrectly handled cookie parsing in certain circumstances. A remote attacker could possibly use this issue to set cookies that would be transmitted to unrelated third-party domains. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8924) Joshua Rogers discovered that curl could double-free a GSASL context when handling SASL authentication. A remote attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8925) Joshua Rogers discovered that curl could select the wrong password from a .netrc file when a username was specified in the URL without a password. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-8926) Ady Elouej discovered that curl did not clear proxy authentication state between requests when reusing a handle with environment-variable proxy configuration. A remote attacker could possibly use this issue to obtain sensitive credentials. (CVE-2026-8927) Guannan Wang, Zhanpeng Liu, Jiashuo Liang, and Guancheng Li discovered that curl did not properly clear proxy authentication credentials when instructed to do so. A remote attacker could possibly use this issue to obtain sensitive credentials. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9079) Joshua Rogers discovered that curl contained a use-after-free when curl_easy_pause() was called within the event-based socket callback. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9080) Eunsoo Kim discovered that curl could send early data on a resumed TLS session before enforcing certificate verification failure. A machine-in-the-middle attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-9545) Joshua Rogers discovered that curl did not properly reject host key type mismatches when using the SSH key callback for SCP and SFTP transfers. A machine-in-the-middle attacker could possibly use this issue to impersonate a trusted server. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-9547)

transmission-4.1.3-1.fc43

4 days 8 hours ago
FEDORA-2026-0ed2011b62 Packages in this update:
  • transmission-4.1.3-1.fc43
Update description:

Fixed a CORS bug that leaked the anti-CSRF nonce. (#8938) Fixed a use-after-free bug in peer code. (#8921) Fixed build error when compiling with fmt 12.2.0. (#8942)

Fix qt icon

transmission-4.1.3-1.fc44

4 days 8 hours ago
FEDORA-2026-0c067e5040 Packages in this update:
  • transmission-4.1.3-1.fc44
Update description:

Fixed a CORS bug that leaked the anti-CSRF nonce. (#8938) Fixed a use-after-free bug in peer code. (#8921) Fixed build error when compiling with fmt 12.2.0. (#8942)

ipp-usb-0.9.34-2.fc45

4 days 9 hours ago
FEDORA-2026-7eaf5e3510 Packages in this update:
  • ipp-usb-0.9.34-2.fc45
Update description:

Automatic update for ipp-usb-0.9.34-2.fc45.

Changelog * Tue Jun 30 2026 Zdenek Dohnal <zdohnal@redhat.com> - 0.9.34-2 - ipp-usb-0.9.34 is available (fedora#2463247, fedora#2484207, fedora#2494316)

USN-8486-1: libssh2 vulnerabilities

4 days 11 hours ago
It was discovered that libssh2 incorrectly handled the sftp_symlink() function. A malicious SSH server or machine-in-the-middle attacker could possibly use this issue to obtain sensitive information or cause a denial of service. (CVE-2025-15661) It was discovered that libssh2 had a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler. A malicious SSH server could possibly use this issue to cause a client CPU exhaustion loop, resulting in a denial of service. (CVE-2026-55199) It was discovered that libssh2 incorrectly handled packet length fields. A remote attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-55200)

USN-8485-1: libyang vulnerability

4 days 12 hours ago
It was discovered that libyang incorrectly handled certain metadata list pointers. An attacker could use this issue to cause libyang to crash, resulting in a denial of service, or possibly execute arbitrary code.

USN-8483-1: HPLIP vulnerabilities

4 days 12 hours ago
It was discovered that HPLIP incorrectly handled certain print data. An attacker could possibly use this issue to cause HPLIP to execute arbitrary code. (CVE-2026-8631) It was discovered that HPLIP incorrectly handled certain inputs. A local attacker could possibly use this issue to execute arbitrary code. (CVE-2026-8632)

python-nh3-0.3.6-1.fc44

4 days 13 hours ago
FEDORA-2026-5ebb12f543 Packages in this update:
  • python-nh3-0.3.6-1.fc44
Update description:

Update to 0.3.6; this includes an update to PyO3 0.29, which fixes RUSTSEC-2026-0176 and RUSTSEC-2026-0177.