4 days 20 hours ago
FEDORA-2026-993b0ea146
Packages in this update:
Update description:
Update to 2.1.1, update bundled libtiff to 4.7.2.
4 days 21 hours ago
Juthawong Naisanguansee discovered that PAM incorrectly cleared failed
login attempt records when certain services invoked the account phase
without first performing authentication. An attacker could possibly use
this issue to reset failed login counters, resulting in authentication
lockout restrictions being bypassed.
5 days 1 hour ago
FEDORA-2026-f903f9ff11
Packages in this update:
Update description:
- fix proto-default skips SSH verification (CVE-2026-12064)
- fix wrong STARTTLS connection reuse (CVE-2026-8286)
- fix SASL double-free (CVE-2026-8925)
- fix env-set cross-proxy Digest auth state leak (CVE-2026-8927)
- fix exposing HTTP/3 early data (CVE-2026-9545)
- fix UAF after pause in socket callback (CVE-2026-9080)
5 days 1 hour ago
It was discovered that p11-kit incorrectly handled certain RPC messages. A
local attacker could use this issue to cause p11-kit to crash, resulting in
a denial of service. (CVE-2026-13757)
It was discovered that p11-kit incorrectly handled nested attribute
decoding on 32-bit systems. A local attacker could use this issue to cause
p11-kit to crash, resulting in a denial of service. (CVE-2026-18938)
5 days 2 hours ago
Version:next-20260827 (linux-next)
Released:2026-08-27
5 days 2 hours ago
It was discovered that primitive decoders in openCryptoki produced integer
underflows when the encoded length was zero. An attacker could possibly use
this issue to trigger out-of-bounds reads. (CVE-2026-40253)
It was discovered that openCryptoki incorrectly handled symlinks. An
attacker in the token-group could possibly use this issue to achieve
privilege escalation or access sensitive information. (CVE-2026-23893)
5 days 4 hours ago
FEDORA-EPEL-2026-9a4c6ee5c5
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-EPEL-2026-bf7afd5dc2
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-2026-5995821369
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-2026-249d41312c
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-EPEL-2026-f1fcb9cda6
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-2026-0425df0537
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
FEDORA-EPEL-2026-d1590297ab
Packages in this update:
Update description:
Version 2.10.3 - 2026-08-27
- Security: Validate package bin paths against path traversal using symlinks (GHSA-96h3-5x6v-m776, CVE-2026-59944)
- Security: Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3)
- Security: Sanitize URL-embedded usernames/token in a few more places (#13044)
- Security: Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#12988)
- Fixed PHP 8.6 deprecation warnings (#12967, #13028)
- Fixed error output when a policy blocks a package version to be clearer (#12993)
- Fixed the lock file's content-hash with a conflict marker ending up breaking at runtime (#13048)
- Fixed possible race condition while creating directories like the cache dir when running multiple Composer processes in parallel (#12977)
- Fixed forgejo support to handle empty repositories better (#12968)
- Fixed FilterListApiClient not forwarding transport options (#13040)
5 days 4 hours ago
5 days 4 hours ago
5 days 4 hours ago
5 days 4 hours ago
5 days 4 hours ago
5 days 4 hours ago
5 days 4 hours ago