Fedora Linux 9386 Published by

Fedora administrators must apply these urgent security advisories right away to safeguard systems running versions 43 or 44. The release bundles critical patches for essential utilities including 7zip Hugo Mojo JWT and ack across both distribution branches. Engineers tackled a wide array of dangerous flaws that span from arbitrary code execution vulnerabilities in NTFS handlers to severe information disclosure bugs inside UEFI parsers and markdown link processors. You can install the corrected packages without delay using the standard dnf upgrade command paired with each advisory identifier.

Fedora 43 Update: 7zip-26.01-1.fc43
Fedora 43 Update: hugo-0.162.1-1.fc43
Fedora 43 Update: perl-Mojo-JWT-1.02-1.fc43
Fedora 44 Update: 7zip-26.01-1.fc44
Fedora 44 Update: hugo-0.162.1-1.fc44
Fedora 44 Update: ack-3.10.0-1.fc44
Fedora 44 Update: perl-Mojo-JWT-1.02-1.fc44




[SECURITY] Fedora 43 Update: 7zip-26.01-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f36864b408
2026-06-16 01:10:28.203233+00:00
--------------------------------------------------------------------------------

Name : 7zip
Product : Fedora 43
Version : 26.01
Release : 1.fc43
URL : https://7-zip.org
Summary : A file archiver
Description :
7-Zip is a file archiver with a high compression ratio. The main features
of 7-Zip are:

* High compression ratio in 7z format with LZMA and LZMA2 compression
* Supported formats:
* Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM
* Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT,
GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2,
RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z.
* For ZIP and GZIP formats, 7-Zip provides a compression ratio that is
2-10 % better than the ratio provided by PKZip and WinZip
* Strong AES-256 encryption in 7z and ZIP formats
* Powerful command line version

--------------------------------------------------------------------------------
Update Information:

Fixes CVE-2026-48092: Information disclosure in 32-bit builds
Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler
Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser
Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF
image
Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive
handler
Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive
handler
Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image
parser
Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD
SYMDEF parser
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 15 2026 Michel Lind [salimma@fedoraproject.org] - 26.01-1
- Update to 26.01; Resolves: rhbz#2440915
- Fixes CVE-2026-48092: Information disclosure in 32-bit builds
- Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler
- Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser
- Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF
image
- Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler
- Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler
- Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser
- Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD
SYMDEF parser
* Sun May 17 2026 Byoungchan Lee [byoungchan.lee@gmx.com] - 25.01-6
- Handle /bin/7z when locating the libexec plugin
* Wed Feb 11 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 25.01-5
- Respect %_prefix
* Wed Feb 11 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 25.01-4
- Fix build with GCC 16
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 25.01-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 25.01-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2373874 - 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory
https://bugzilla.redhat.com/show_bug.cgi?id=2373874
[ 2 ] Bug #2433842 - 7zip: FTBFS in Fedora rawhide/f44
https://bugzilla.redhat.com/show_bug.cgi?id=2433842
[ 3 ] Bug #2478240 - 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin`
https://bugzilla.redhat.com/show_bug.cgi?id=2478240
[ 4 ] Bug #2485479 - CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485479
[ 5 ] Bug #2485481 - CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485481
[ 6 ] Bug #2485489 - CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485489
[ 7 ] Bug #2485492 - CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485492
[ 8 ] Bug #2486337 - CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486337
[ 9 ] Bug #2486339 - CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486339
[ 10 ] Bug #2486344 - CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486344
[ 11 ] Bug #2486347 - CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486347
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f36864b408' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: hugo-0.162.1-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6f3d11bdc6
2026-06-16 01:10:28.203225+00:00
--------------------------------------------------------------------------------

Name : hugo
Product : Fedora 43
Version : 0.162.1
Release : 1.fc43
URL : https://github.com/gohugoio/hugo
Summary : The world???s fastest framework for building websites
Description :
The world???s fastest framework for building websites.

--------------------------------------------------------------------------------
Update Information:

Update to 0.162.1 (rhbz#2455512)
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.162.1-1
- Update to 0.162.1 (rhbz#2455512)
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.160.1-2
- Remove obsolete patches
* Sun Jun 7 2026 Packit [hello@packit.dev] - 0.160.1-1
- Update to 0.160.1 upstream release
- Resolves: rhbz#2451668
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.159.0-3
- Skip check that fails on ppc64le
* Sun Jun 7 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 0.159.0-2
- Update spec
- Update to go2rpm 1.19.0 template
- Set `askalono` as license detector
- Drop invopop/yaml to oasdiff/yaml module change
- Use GO_BUILDTAGS & GO_LDFLAGS
- Use gocheck2 and skip individual tests
- Drop extra documentation
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.159.0-1
- Update to 0.159.0 (rhbz#2434652)
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.154.3-1
- Update to 0.154.3
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.153.2-1
- Update to 0.153.2
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.153.1-1
- Update to 0.153.1
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2455512 - CVE-2026-35166 hugo: github.com/gohugoio/hugo: Hugo: Information disclosure and content manipulation via improper markdown link escaping
https://bugzilla.redhat.com/show_bug.cgi?id=2455512
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6f3d11bdc6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: perl-Mojo-JWT-1.02-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1da54e6cb8
2026-06-16 01:10:28.203205+00:00
--------------------------------------------------------------------------------

Name : perl-Mojo-JWT
Product : Fedora 43
Version : 1.02
Release : 1.fc43
URL : https://metacpan.org/release/Mojo-JWT
Summary : JSON Web Token the Mojo way
Description :
JSON Web Token is described in https://tools.ietf.org/html/rfc7519.
Mojo::JWT implements that standard with an API that should feel familiar to
Mojolicious users (though of course it is useful elsewhere). Indeed, JWT is
much like Mojolicious::Sessions except that the result is a URL-safe text
string rather than a cookie.

--------------------------------------------------------------------------------
Update Information:

This release of Mojo::JWT Improves the security of decode to prevent timing
side-channel attacks in symmetric signatures
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 7 2026 Emmanuel Seyman [emmanuel@seyman.fr] - 1.02-1
- Update to 1.02
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1da54e6cb8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: 7zip-26.01-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4be7569210
2026-06-16 01:01:54.934669+00:00
--------------------------------------------------------------------------------

Name : 7zip
Product : Fedora 44
Version : 26.01
Release : 1.fc44
URL : https://7-zip.org
Summary : A file archiver
Description :
7-Zip is a file archiver with a high compression ratio. The main features
of 7-Zip are:

* High compression ratio in 7z format with LZMA and LZMA2 compression
* Supported formats:
* Packing / unpacking: 7z, XZ, BZIP2, GZIP, TAR, ZIP and WIM
* Unpacking only: AR, ARJ, CAB, CHM, CPIO, CramFS, DMG, EXT, FAT,
GPT, HFS, IHEX, ISO, LZH, LZMA, MBR, MSI, NSIS, NTFS, QCOW2,
RPM, SquashFS, UDF, UEFI, VDI, VHD, VMDK, WIM, XAR and Z.
* For ZIP and GZIP formats, 7-Zip provides a compression ratio that is
2-10 % better than the ratio provided by PKZip and WinZip
* Strong AES-256 encryption in 7z and ZIP formats
* Powerful command line version

--------------------------------------------------------------------------------
Update Information:

Fixes CVE-2026-48092: Information disclosure in 32-bit builds
Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler
Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser
Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF
image
Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive
handler
Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive
handler
Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image
parser
Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD
SYMDEF parser
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 15 2026 Michel Lind [salimma@fedoraproject.org] - 26.01-1
- Update to 26.01; Resolves: rhbz#2440915
- Fixes CVE-2026-48092: Information disclosure in 32-bit builds
- Fixes CVE-2026-48095: Arbitrary code execution in NTFS handler
- Fixes CVE-2026-48101: Information disclosure in UEFI capsule parser
- Fixes CVE-2026-48102: Information disclosure and DOS via crafted UDF
image
- Fixes CVE-2026-48103: Off-by-one buffer over-read in WIM archive handler
- Fixes CVE-2026-48104: Uninitialized heap read in SquashFS archive handler
- Fixes CVE-2026-48111: Off-by-one OOB read in UEFI firmware image parser
- Fixes CVE-2026-48112: Heap-based buffer over-read in Ar handler BSD
SYMDEF parser
* Sun May 17 2026 Byoungchan Lee [byoungchan.lee@gmx.com] - 25.01-6
- Handle /bin/7z when locating the libexec plugin
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2373874 - 7z cannot find library when invoked with full path: Codec Load Error: /usr/bin/7z.so : errno=2 : No such file or directory
https://bugzilla.redhat.com/show_bug.cgi?id=2373874
[ 2 ] Bug #2433842 - 7zip: FTBFS in Fedora rawhide/f44
https://bugzilla.redhat.com/show_bug.cgi?id=2433842
[ 3 ] Bug #2478240 - 7zip: `/bin/7z` fails to load codecs when `/bin` is a symlink to `/usr/bin`
https://bugzilla.redhat.com/show_bug.cgi?id=2478240
[ 4 ] Bug #2485479 - CVE-2026-48092 7zip: 7-Zip: Information disclosure in 32-bit builds due to heap memory disclosure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485479
[ 5 ] Bug #2485481 - CVE-2026-48095 7zip: 7-Zip: Arbitrary code execution via heap buffer overflow in NTFS handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485481
[ 6 ] Bug #2485489 - CVE-2026-48102 7zip: 7-Zip: Information disclosure and denial of service via crafted UDF image [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485489
[ 7 ] Bug #2485492 - CVE-2026-48101 7zip: 7-Zip: Information Disclosure via uninitialized memory in UEFI capsule parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2485492
[ 8 ] Bug #2486337 - CVE-2026-48103 7zip: off-by-one heap-based buffer over-read in the WIM archive handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486337
[ 9 ] Bug #2486339 - CVE-2026-48104 7zip: uninitialized heap read in the SquashFS archive handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486339
[ 10 ] Bug #2486344 - CVE-2026-48111 7zip: off-by-one out-of-bounds read in the UEFI firmware image parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486344
[ 11 ] Bug #2486347 - CVE-2026-48112 7zip: heap-based buffer over-read in the Ar handler BSD SYMDEF parser [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486347
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4be7569210' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: hugo-0.162.1-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7fe2bb8a08
2026-06-16 01:01:54.934648+00:00
--------------------------------------------------------------------------------

Name : hugo
Product : Fedora 44
Version : 0.162.1
Release : 1.fc44
URL : https://github.com/gohugoio/hugo
Summary : The world???s fastest framework for building websites
Description :
The world???s fastest framework for building websites.

--------------------------------------------------------------------------------
Update Information:

Update to 0.162.1 (rhbz#2455512)
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.162.1-1
- Update to 0.162.1 (rhbz#2455512)
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.160.1-2
- Remove obsolete patches
* Sun Jun 7 2026 Packit [hello@packit.dev] - 0.160.1-1
- Update to 0.160.1 upstream release
- Resolves: rhbz#2451668
* Sun Jun 7 2026 W. Michael Petullo [mike@flyn.org] - 0.159.0-3
- Skip check that fails on ppc64le
* Sun Jun 7 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 0.159.0-2
- Update spec
- Update to go2rpm 1.19.0 template
- Set `askalono` as license detector
- Drop invopop/yaml to oasdiff/yaml module change
- Use GO_BUILDTAGS & GO_LDFLAGS
- Use gocheck2 and skip individual tests
- Drop extra documentation
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2455512 - CVE-2026-35166 hugo: github.com/gohugoio/hugo: Hugo: Information disclosure and content manipulation via improper markdown link escaping
https://bugzilla.redhat.com/show_bug.cgi?id=2455512
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7fe2bb8a08' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: ack-3.10.0-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-bb708e11d7
2026-06-16 01:01:54.934656+00:00
--------------------------------------------------------------------------------

Name : ack
Product : Fedora 44
Version : 3.10.0
Release : 1.fc44
URL : http://beyondgrep.com/
Summary : A Grep-like source code search tool
Description :
Ack is a grep-like search tool designed for use with large heterogeneous
trees of source code. It searchs recursively and ignores common version
control directories.

--------------------------------------------------------------------------------
Update Information:

Update to version 3.10.0
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 7 2026 Bill Pemberton [wfp5p@worldbroken.com] - 3.10.0-1
- Update to version 3.10.0
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2486102 - ack-3.10.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2486102
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-bb708e11d7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-Mojo-JWT-1.02-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-80333f8f56
2026-06-16 01:01:54.934620+00:00
--------------------------------------------------------------------------------

Name : perl-Mojo-JWT
Product : Fedora 44
Version : 1.02
Release : 1.fc44
URL : https://metacpan.org/release/Mojo-JWT
Summary : JSON Web Token the Mojo way
Description :
JSON Web Token is described in https://tools.ietf.org/html/rfc7519.
Mojo::JWT implements that standard with an API that should feel familiar to
Mojolicious users (though of course it is useful elsewhere). Indeed, JWT is
much like Mojolicious::Sessions except that the result is a URL-safe text
string rather than a cookie.

--------------------------------------------------------------------------------
Update Information:

This release of Mojo::JWT Improves the security of decode to prevent timing
side-channel attacks in symmetric signatures
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 7 2026 Emmanuel Seyman [emmanuel@seyman.fr] - 1.02-1
- Update to 1.02
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-80333f8f56' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new