4 days ago
FEDORA-2026-7780decfc1
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.9
4 days ago
Version:next-20260930 (linux-next)
Released:2026-09-30
4 days ago
FEDORA-2026-13d0d9deee
Packages in this update:
Update description:
EPEL9 fixes
4 days ago
FEDORA-2026-f2d13d09d7
Packages in this update:
Update description:
Update to 3.2.0
Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239,
GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.
4 days 1 hour ago
FEDORA-2026-3fa772c573
Packages in this update:
Update description:
Update to 3.2.0
Fixes GHSA-gq48-pqfc-9p58, GHSA-23mf-xhv8-69c2, GHSA-f9j4-qggq-h239,
GHSA-w8jc-g24h-crhw, GHSA-m64x-33q8-m5h7, and GHSA-fx3j-rwgx-fr94.
4 days 1 hour ago
Grzegorz Grasza discovered that OpenStack Keystone did not consistently
enforce restrictions for delegated authentication tokens. An authenticated
attacker could possibly use this issue to create credentials or delegations
that outlasted the delegated token. (CVE-2026-80182)
It was discovered that OpenStack Keystone incorrectly handled role
assignment queries under certain circumstances. An authenticated attacker
could possibly use this issue to obtain sensitive information. This
issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-80183)
Tim Shephard discovered that OpenStack Keystone did not properly
restrict reauthentication using delegated tokens. An authenticated
attacker could possibly use this issue to escape their intended
project scope and obtain unauthorized access. (CVE-2026-80184)
4 days 1 hour ago
FEDORA-2026-12f3f3d569
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.9
4 days 1 hour ago
It was discovered that OpenSBI did not properly validate the counter index
mask in SBI PMU extension requests. An attacker could use this issue to
cause a denial of service.
4 days 1 hour ago
FEDORA-2026-93eed17997
Packages in this update:
Update description:
Rebase to OpenSSL 3.5.9
4 days 2 hours ago
FEDORA-2026-b7ad280cc1
Packages in this update:
- mstflint-4.37.0_1.1-2.fc45
Update description:
Update to upstream release v4.37.0-1.1.
Fix licensing issues.
For upstream release information, see:
https://github.com/Mellanox/mstflint/releases
4 days 2 hours ago
It was discovered that OpenVPN had a use-after-free vulnerability in
its TLS session handling. An attacker could possibly use this issue
to cause OpenVPN to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2026-84471)
It was discovered that OpenVPN incorrectly handled retransmissions of
ACK packet IDs, which could trigger a timeout integer overflow. A
remote attacker could possibly use this issue to cause a denial of
service. (CVE-2026-84732)
4 days 4 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)
4 days 4 hours ago
FEDORA-2026-0072911d9d
Packages in this update:
Update description:
xkb: Check the keysym range in _XkbReadKeyActions (CVE-2026-88806)
4 days 5 hours ago
FEDORA-2026-663a2d0ba4
Packages in this update:
Update description:
- fix HTTP/2 server push UAF (CVE-2026-18924)
- fix Negotiate ambient user conn reuse (CVE-2026-19931)
- remove test1701 - HTTP/2 Upgrade in a HTTP/1.1 POST request is no longer supported
4 days 6 hours ago
FEDORA-2026-7a31054ed6
Packages in this update:
Update description:
Update to 1.18.4
4 days 6 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- OCFS2 file system;
- IPv6 networking;
- Netfilter;
- SCTP protocol;
(CVE-2025-38724, CVE-2026-53043, CVE-2026-53131, CVE-2026-53221,
CVE-2026-53224, CVE-2026-53225, CVE-2026-53246, CVE-2026-53309)
4 days 6 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53221, CVE-2026-53354, CVE-2026-53355,
CVE-2026-53398, CVE-2026-63808, CVE-2026-63887, CVE-2026-63888,
CVE-2026-63912, CVE-2026-63922, CVE-2026-63924, CVE-2026-63984,
CVE-2026-63992, CVE-2026-63993, CVE-2026-63994, CVE-2026-64007,
CVE-2026-64091)
4 days 6 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- exFAT file system;
- Network file system (NFS) client;
- Network file system (NFS) server daemon;
- B.A.T.M.A.N. meshing protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53186, CVE-2026-53216, CVE-2026-53221, CVE-2026-53354,
CVE-2026-53355, CVE-2026-53398, CVE-2026-63800, CVE-2026-63808,
CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63922,
CVE-2026-63924, CVE-2026-63984, CVE-2026-63992, CVE-2026-63993,
CVE-2026-63994, CVE-2026-64007, CVE-2026-64091)
4 days 6 hours ago
It was discovered that some Arm processors could complete a broadcast
translation lookaside buffer (TLB) invalidation before memory writes made
through the invalidated translation were globally observed. A local
attacker could possibly use this to write to memory after permission to do
so had been revoked, bypassing memory protections or escalating privileges.
(CVE-2025-10263)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- InfiniBand drivers;
- Network drivers;
- TCM subsystem;
- B.A.T.M.A.N. meshing protocol;
- HSR network protocol;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- RDS protocol;
(CVE-2026-53131, CVE-2026-53186, CVE-2026-53216, CVE-2026-53221,
CVE-2026-53354, CVE-2026-53355, CVE-2026-63886, CVE-2026-63887,
CVE-2026-63888, CVE-2026-63912, CVE-2026-63922, CVE-2026-63924,
CVE-2026-63984, CVE-2026-63992, CVE-2026-63993, CVE-2026-63994,
CVE-2026-64000, CVE-2026-64007, CVE-2026-64091)
4 days 6 hours ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Network file system (NFS) server daemon;
- IPv6 networking;
- Netfilter;
(CVE-2025-38724, CVE-2026-53131, CVE-2026-53221)