Aggregator
DSA-6354-1 libconfig-inifiles-perl - security update
yt-dlp-2026.06.09-1.fc43
- yt-dlp-2026.06.09-1.fc43
- Update to 2026.06.09. Fixes rhbz#2487407.
- Mitigates CVE-2026-50019, CVE-2026-50023, CVE-2026-50574
yt-dlp-2026.06.09-1.fc44
- yt-dlp-2026.06.09-1.fc44
- Update to 2026.06.09. Fixes rhbz#2487407.
- Mitigates CVE-2026-50019, CVE-2026-50023, CVE-2026-50574
haveged-1.9.23-2.el8
- haveged-1.9.23-2.el8
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
haveged-1.9.23-2.el10_3
- haveged-1.9.23-2.el10_3
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
haveged-1.9.23-2.el10_2
- haveged-1.9.23-2.el10_2
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
haveged-1.9.23-2.el9
- haveged-1.9.23-2.el9
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
haveged-1.9.23-2.fc43
- haveged-1.9.23-2.fc43
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
Update to 1.9.23 — security hardening: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
haveged-1.9.23-3.fc44
- haveged-1.9.23-3.fc44
Update to 1.9.23-2: - Add SELinux policy module to allow semaphore creation in /dev/shm - Add rpminspect.yaml to waive pre-existing annocheck false positive
Security fixes in 1.9.23-1: - Use O_EXCL with sem_open to prevent semaphore pre-planting attacks - Fix OOB memory access in safein()/safeout() on socket errors - Reject command socket connections from different user namespaces - Use O_NOFOLLOW for PID file to prevent symlink attacks - Open random device with O_CLOEXEC, restrict semaphore to 0600 - Fix stale semaphore recovery after SIGKILL - Fix compilation when NO_COMMAND_MODE is defined
pacemaker-3.0.2-3.fc44
- pacemaker-3.0.2-3.fc44
tinyproxy-1.11.2-8.el10_3
- tinyproxy-1.11.2-8.el10_3
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
tinyproxy-1.11.2-8.el10_2
- tinyproxy-1.11.2-8.el10_2
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
tinyproxy-1.11.2-8.el8
- tinyproxy-1.11.2-8.el8
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
tinyproxy-1.11.2-8.el9
- tinyproxy-1.11.2-8.el9
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
tinyproxy-1.11.2-8.fc44
- tinyproxy-1.11.2-8.fc44
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
tinyproxy-1.11.2-8.fc43
- tinyproxy-1.11.2-8.fc43
Backport upstream fixes for CVE-2026-54387 and CVE-2026-54388.
python-mistune-3.2.1-1.fc45
- python-mistune-3.2.1-1.fc45
Automatic update for python-mistune-3.2.1-1.fc45.
Changelog * Thu Jun 18 2026 Miro Hrončok <miro@hroncok.cz> - 3.2.1-1 - Update to 3.2.1 - Security fix for CVE-2026-44898 - Fixes: rhbz#2424578 - Fixes: rhbz#2489782USN-8447-2: LXD vulnerabilities
rust-bon-3.9.3-1.fc45 rust-bon-macros-3.9.3-1.fc45 rust-openssl-0.10.81-1.fc45 rust-openssl-sys-0.9.117-1.fc45 rust-zeroize-1.9.0-1.fc45 rust-zeroize_derive-1.5.0-1.fc45
- rust-bon-3.9.3-1.fc45
- rust-bon-macros-3.9.3-1.fc45
- rust-openssl-0.10.81-1.fc45
- rust-openssl-sys-0.9.117-1.fc45
- rust-zeroize-1.9.0-1.fc45
- rust-zeroize_derive-1.5.0-1.fc45
- Update the openssl crate to version 0.10.81 and the openssl-sys crate to version 0.9.117.
- Update the zeroize crate to version 1.9.0 and the zeroize_derive crate to version 1.5.0.
- Update the bon and bon-macros crates to version 3.9.3.