Aggregator
gnutls-3.8.11-3.fc42
- gnutls-3.8.11-3.fc42
This backports fixes for a couple CVEs:
** libgnutls: Fix NULL pointer dereference in PSK binder verification A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server. The updated code guards against the problematic dereference. Reported by Jaehun Lee. [Fixes: GNUTLS-SA-2026-02-09-1, CVSS: high] [CVE-2026-1584]
** libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831]
gnutls-3.8.12-1.fc43
- gnutls-3.8.12-1.fc43
This fixes a couple CVEs:
** libgnutls: Fix NULL pointer dereference in PSK binder verification A TLS 1.3 resumption attempt with an invalid PSK binder value in ClientHello could lead to a denial of service attack via crashing the server. The updated code guards against the problematic dereference. Reported by Jaehun Lee. [Fixes: GNUTLS-SA-2026-02-09-1, CVSS: high] [CVE-2026-1584]
** libgnutls: Fix name constraint processing performance issue Verifying certificates with pathological amounts of name constraints could lead to a denial of service attack via resource exhaustion. Reworked processing algorithms exhibit better performance characteristics. Reported by Tim Scheckenbach. [Fixes: GNUTLS-SA-2026-02-09-2, CVSS: medium] [CVE-2025-14831]
USN-7942-2: GLib vulnerabilities
p11-kit-0.26.2-1.fc42
- p11-kit-0.26.2-1.fc42
Notable changes from the rebase: * pkcs11: Update PKCS11 headers to version 3.2 * rpc: fix NULL dereference via C_DeriveKey with specific NULL parameters (CVE-2026-2100) * trust: Lookup DNs in reverse order (RFC4514 section 2.1)
p11-kit-0.26.2-1.fc43
- p11-kit-0.26.2-1.fc43
Notable changes from the rebase: * pkcs11: Update PKCS11 headers to version 3.2 * rpc: fix NULL dereference via C_DeriveKey with specific NULL parameters (CVE-2026-2100) * trust: Lookup DNs in reverse order (RFC4514 section 2.1)
USN-8022-1: Expat vulnerabilities
libssh-0.11.4-1.fc42
- libssh-0.11.4-1.fc42
New upstream release fixing various security issues.
libssh-0.11.4-1.fc43
- libssh-0.11.4-1.fc43
New upstream release fixing several security issues
selenium-manager-4.34.0-6.fc45
- selenium-manager-4.34.0-6.fc45
Automatic update for selenium-manager-4.34.0-6.fc45.
Changelog * Tue Feb 10 2026 tjuhasz <tjuhasz@redhat.com> - 4.34.0-6 - Rebuild for CVE-2026-25727 (rhbz#2438154)USN-8021-1: ImageMagick vulnerability
DSA-6129-1 munge - security update
azure-cli-2.68.0-2.fc42 python-azure-core-1.38.0-2.fc42
- azure-cli-2.68.0-2.fc42
- python-azure-core-1.38.0-2.fc42
Update to 1.38.0 to address CVE-2026-21226
azure-cli-2.81.0-2.fc43 python-azure-core-1.38.0-2.fc43
- azure-cli-2.81.0-2.fc43
- python-azure-core-1.38.0-2.fc43
Update to 1.38.0 to address CVE-2026-21226
mingw-python3-3.11.14-7.fc43
- mingw-python3-3.11.14-7.fc43
Backport fixes for CVE-2025-11468, CVE-2026-0672, CVE-2026-0865, CVE-2025-15282, CVE-2026-1299
mingw-python3-3.11.14-7.fc42
- mingw-python3-3.11.14-7.fc42
Backport fixes for CVE-2025-11468, CVE-2026-0672, CVE-2026-0865, CVE-2025-15282, CVE-2026-1299
mingw-libsoup-2.74.3-17.fc43
- mingw-libsoup-2.74.3-17.fc43
Backport fixes for CVE-2026-0716, CVE-2026-0719.
mingw-libsoup-2.74.3-17.fc42
- mingw-libsoup-2.74.3-17.fc42
Backport fixes for CVE-2026-0716, CVE-2026-0719.
pgadmin4-9.12-1.fc42
- pgadmin4-9.12-1.fc42
Update to pgadmin-9.12.
pgadmin4-9.12-1.fc43
- pgadmin4-9.12-1.fc43
Update to pgadmin-9.12.