Aggregator
DSA-6434-1 lemonldap-ng - security update
botan3-3.12.0-1.fc46
FEDORA-2026-c5ca310459
Packages in this update:
- botan3-3.12.0-1.fc46
Automatic update for botan3-3.12.0-1.fc46.
Changelog * Wed Aug 12 2026 Carlos Rodriguez-Fernandez <carlosrodrifernandez@gmail.com> - 3.12.0-1 - Update to 3.12.0 (rhbz#2483287)domoticz-2026.3-1.fc43
FEDORA-2026-cda155613e
Packages in this update:
- domoticz-2026.3-1.fc43
Version 2026.3 (August 2nd 2026)
This release contains important security fixes in the web server and API, upgrading is strongly recommended.
https://github.com/domoticz/domoticz/blob/2026.3/History.txt
USN-8627-1: Yelp vulnerability
It was discovered that Yelp incorrectly handled certain crafted help
documents due to an overly permissive Content Security Policy. An
attacker could trick a user into opening a specially crafted document,
possibly resulting in the disclosure of sensitive information.
next-20260811: linux-next
Version:next-20260811 (linux-next)
Released:2026-08-11
sqlite-3.50.2-3.fc43
FEDORA-2026-344515cf47
Packages in this update:
- sqlite-3.50.2-3.fc43
Fix CVE-2026-11822 and CVE-2026-11824
sqlite-3.51.2-2.fc44
FEDORA-2026-4bc86fb6d0
Packages in this update:
- sqlite-3.51.2-2.fc44
Fix CVE-2026-11822 and CVE-2026-11824
linux-firmware-20260810-1.fc43
FEDORA-2026-e82e06fcae
Packages in this update:
- linux-firmware-20260810-1.fc43
Update to 20260810:
- amdgpu: numerous firmware updates
- update firmware for MT7922 WiFi device
- morsemicro: add firmware for mm8108 support
- ath10k: WCN3990 hw1.0: update board-2.bin
- Update firmware for an8811hb 2.5G ethernet phy
- xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S
- mediatek MT7922: update bluetooth firmware to 20260724143815
- airoha: update AN7583 NPU firmwares to version 0.5
- qcom: Add gpu firmwares for Eliza chipset
- cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
- rtw89: 8922d: add fw 0.35.113.2
- qcom: venus-5.4: fix vp9 decoder assertion failure
- qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
- qcom: Update qdsp6sw firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- intel_vpu: Update NPU firmware
- qcom: Update DSP firmware for qcs8300 platform
- tas2783: Add firmware for new soundwire devices
- rtw88: add firmware v41.0.0 for RTL8723B
- Update AMD cpu microcode
- Add firmware file for Intel BlazarIW
- Update firmware file for Intel BlazarI/BlazarU/Scorpius core
- amdgpu: DMCUB updates for various ASICs
- qcom: add ADSP firmware for hawi platform
- powervr: add firmware for Imagination Technologies BXM-4-64 GPU
- qcom: Update DSP firmware for sa8775p platform
- xe: Release GuC firmware for NVL-S
- cirrus: cs35l56: Update firmware for the ASUS UX5406SA
- qcom: vpu: add Gen2 firmware binary for Purwa
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
- iwlwifi: add Bz/Sc/Hr/Gf FW for core24.60-33 release
- iwlwifi: update ty/So/Ma/cc/Qu/QuZ firmwares for core24.60-33 release
- cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
- ueagle-atm: sadly drop unlicensed files
- qcom: sync audioreach firmwares from v1.0.4 build
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
- amdgpu: DMCUB updates for various ASICs
- tas2781: Add firmware for new HP projects
- rtw89: 8852a: add TX power track R34
- Update AMD SEV firmware
linux-firmware-20260810-1.fc44
FEDORA-2026-c53019ed4f
Packages in this update:
- linux-firmware-20260810-1.fc44
Update to 20260810:
- amdgpu: numerous firmware updates
- update firmware for MT7922 WiFi device
- morsemicro: add firmware for mm8108 support
- ath10k: WCN3990 hw1.0: update board-2.bin
- Update firmware for an8811hb 2.5G ethernet phy
- xe: Update GUC to v70.72.1 for BMG, LNL, PTL, NVL-S
- mediatek MT7922: update bluetooth firmware to 20260724143815
- airoha: update AN7583 NPU firmwares to version 0.5
- qcom: Add gpu firmwares for Eliza chipset
- cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
- rtw89: 8922d: add fw 0.35.113.2
- qcom: venus-5.4: fix vp9 decoder assertion failure
- qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
- qcom: Update qdsp6sw firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- intel_vpu: Update NPU firmware
- qcom: Update DSP firmware for qcs8300 platform
- tas2783: Add firmware for new soundwire devices
- rtw88: add firmware v41.0.0 for RTL8723B
- Update AMD cpu microcode
- Add firmware file for Intel BlazarIW
- Update firmware file for Intel BlazarI/BlazarU/Scorpius core
- amdgpu: DMCUB updates for various ASICs
- qcom: add ADSP firmware for hawi platform
- powervr: add firmware for Imagination Technologies BXM-4-64 GPU
- qcom: Update DSP firmware for sa8775p platform
- xe: Release GuC firmware for NVL-S
- cirrus: cs35l56: Update firmware for the ASUS UX5406SA
- qcom: vpu: add Gen2 firmware binary for Purwa
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
- iwlwifi: add Bz/Sc/Hr/Gf FW for core24.60-33 release
- iwlwifi: update ty/So/Ma/cc/Qu/QuZ firmwares for core24.60-33 release
- cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
- ueagle-atm: sadly drop unlicensed files
- qcom: sync audioreach firmwares from v1.0.4 build
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
- amdgpu: DMCUB updates for various ASICs
- tas2781: Add firmware for new HP projects
- rtw89: 8852a: add TX power track R34
- Update AMD SEV firmware
roundcubemail-1.6.18-1.el10_2
FEDORA-EPEL-2026-4e7b9eeb2b
Packages in this update:
- roundcubemail-1.6.18-1.el10_2
- Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
- Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
- Security: Add basic validation for content proxied by the css proxy
- Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
- Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
- Security: Fix RCE via cmd_learn driver of markasjunk plugin
- Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
- Security: Fix stored XSS in "Add to address book" action
- Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute
roundcubemail-1.6.18-1.el10_3
FEDORA-EPEL-2026-c09c342945
Packages in this update:
- roundcubemail-1.6.18-1.el10_3
- Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
- Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
- Security: Add basic validation for content proxied by the css proxy
- Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
- Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
- Security: Fix RCE via cmd_learn driver of markasjunk plugin
- Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
- Security: Fix stored XSS in "Add to address book" action
- Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute
roundcubemail-1.6.18-1.fc43
FEDORA-2026-914a40b4fd
Packages in this update:
- roundcubemail-1.6.18-1.fc43
- Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
- Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
- Security: Add basic validation for content proxied by the css proxy
- Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
- Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
- Security: Fix RCE via cmd_learn driver of markasjunk plugin
- Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
- Security: Fix stored XSS in "Add to address book" action
- Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute
roundcubemail-1.7.3-1.fc44
FEDORA-2026-2aa96a9ce5
Packages in this update:
- roundcubemail-1.7.3-1.fc44
- OAuth: Don't log an error when a refreshed token's TTL is below refresh_interval (#10213)
- Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
- Fix bug where searching in example_addressbook plugin was reporting zero results despite matches (#9022)
- Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593)
- Fix bug where the php session driver practically disabled session.lazy_write optimization (#9885, #10248)
- Fix bug where dates could get displayed shifted back one day in some places (#9403)
- Fix regression where it wasn't possible to hide a skin logo image anymore (#10254)
- Fix decoding of multi-segment RFC2231 extended attachment filenames (#10268)
- Fix vCard import silently dropping properties with a non-item group prefix (#10271)
- Fix so REQUEST_URI is used as a fallback if PATH_INFO is empty in static.php (#10181)
- Security: Add basic validation for content proxied by the css proxy
- Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
- Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
- Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
- Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
- Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
- Security: Fix RCE via cmd_learn driver of markasjunk plugin
- Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
- Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
- Security: Fix stored XSS in "Add to address book" action
- Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute
DSA-6431-1 openjdk-25 - security update
DSA-6430-1 postfix - security update
DSA-6429-1 caddy - security update
libnfs-6.0.2-9.fc43
FEDORA-2026-2e196b6fa5
Packages in this update:
- libnfs-6.0.2-9.fc43
Fixes CVE-2026-57918 and CVE-2026-53689
libnfs-6.0.2-9.fc44
FEDORA-2026-8ae1795f2b
Packages in this update:
- libnfs-6.0.2-9.fc44
Fixes CVE-2026-57918 and CVE-2026-53689
lemonldap-ng-2.23.3-1.el10_3
FEDORA-EPEL-2026-a89200828a
Packages in this update:
- lemonldap-ng-2.23.3-1.el10_3
Update to 2.23.3 Fixes CVE-2026-19349