Fedora Linux 9441 Published by

Fedora issued five security advisories, delivering patches for borgbackup, seamonkey, nebula, and the ammonia package ecosystem across Fedora 43 and Fedora 44. Fedora 43 administrators need to upgrade borgbackup to version 1.4.5 to close CVE-2026-62268, while Fedora 44 users must install seamonkey version 2.53.24 to secure the internet suite against reported vulnerabilities. The nebula update pushes version 1.11.0 on Fedora 44 and blocks six CVEs involving SSH denial of service attacks, unauthorized command execution via discarded permissions, and ECDSA signature malleability in the overlay networking tool. A joint advisory for Fedora 44 updates rust-ammonia to version 4.1.4 and rebuilds python-nh3 to fix RUSTSEC-2026-0193 and RUSTSEC-2026-0213, ensuring proper HTML sanitization across both the Rust crate and Python bindings.

Fedora 43 Update: borgbackup-1.4.5-1.fc43
Fedora 44 Update: seamonkey-2.53.24-1.fc44
Fedora 44 Update: python-nh3-0.3.6-4.fc44
Fedora 44 Update: rust-ammonia-4.1.4-1.fc44
Fedora 44 Update: nebula-1.11.0-1.fc44




[SECURITY] Fedora 43 Update: borgbackup-1.4.5-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-5a13ef79cc
2026-08-04 01:17:59.133908+00:00
--------------------------------------------------------------------------------

Name : borgbackup
Product : Fedora 43
Version : 1.4.5
Release : 1.fc43
URL : https://borgbackup.readthedocs.org
Summary : A deduplicating backup program with compression and authenticated encryption
Description :
BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it
supports compression and authenticated encryption.

--------------------------------------------------------------------------------
Update Information:

new bugfix release, contains a fix for CVE-2026-62268
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 25 2026 Felix Schwarz [fschwarz@fedoraproject.org] - 1.4.5-1
- update to 1.4.5
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-5a13ef79cc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: seamonkey-2.53.24-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e024c08cad
2026-08-04 00:56:07.601464+00:00
--------------------------------------------------------------------------------

Name : seamonkey
Product : Fedora 44
Version : 2.53.24
Release : 1.fc44
URL : http://www.seamonkey-project.org
Summary : Web browser, e-mail, news, IRC client, HTML editor
Description :
SeaMonkey is an all-in-one Internet application suite (previously made
popular by Netscape and Mozilla). It includes an Internet browser,
advanced e-mail, newsgroup and feed client, a calendar, IRC client,
HTML editor and a tool to inspect the DOM for web pages. It is derived
from the application formerly known as Mozilla Application Suite.

--------------------------------------------------------------------------------
Update Information:

Update to 2.53.24
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 30 2026 Dmitry Butskoy [Dmitry@Butskoy.name] 2.53.24-1
- update to 2.53.24
* Wed Apr 15 2026 Nicolas Chauvet [kwizart@gmail.com] - 2.53.23-4
- Rebuilt for vmaf-3.1.0
* Thu Mar 19 2026 Nicolas Chauvet [kwizart@gmail.com] - 2.53.23-3
- Rebuilt for libvpx-1.16.0
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e024c08cad' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: python-nh3-0.3.6-4.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-61f0d68398
2026-08-04 00:56:07.601461+00:00
--------------------------------------------------------------------------------

Name : python-nh3
Product : Fedora 44
Version : 0.3.6
Release : 4.fc44
URL : https://github.com/messense/nh3
Summary : Python binding to Ammonia HTML sanitizer Rust crate
Description :
Python binding to Ammonia HTML sanitizer Rust crate.

--------------------------------------------------------------------------------
Update Information:

Update the ammonia crate to version 4.1.4.
Rebuild nh3 to apply fixes for RUSTSEC-2026-0193 and RUSTSEC-2026-0213.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 30 2026 Fabio Valentini [decathorpe@gmail.com] - 0.3.6-4
- Rebuild with ammonia 4.1.4 for RUSTSEC-2026-0193 and RUSTSEC-2026-0213
* Wed Jul 22 2026 Python Maint - 0.3.6-3
- Rebuilt for Python 3.15.0b4 ABI change
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.3.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-61f0d68398' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: rust-ammonia-4.1.4-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-61f0d68398
2026-08-04 00:56:07.601461+00:00
--------------------------------------------------------------------------------

Name : rust-ammonia
Product : Fedora 44
Version : 4.1.4
Release : 1.fc44
URL : https://crates.io/crates/ammonia
Summary : HTML Sanitization
Description :
HTML Sanitization.

--------------------------------------------------------------------------------
Update Information:

Update the ammonia crate to version 4.1.4.
Rebuild nh3 to apply fixes for RUSTSEC-2026-0193 and RUSTSEC-2026-0213.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 30 2026 Fabio Valentini [decathorpe@gmail.com] - 4.1.4-1
- Update to version 4.1.4; Fixes RHBZ#2506006
* Fri Jul 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.1.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-61f0d68398' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nebula-1.11.0-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-12d6749851
2026-08-04 00:56:07.601419+00:00
--------------------------------------------------------------------------------

Name : nebula
Product : Fedora 44
Version : 1.11.0
Release : 1.fc44
URL : https://github.com/slackhq/nebula
Summary : A scalable overlay networking tool with a focus on performance, simplicity and security
Description :
A scalable overlay networking tool with a focus on performance, simplicity and
security.

--------------------------------------------------------------------------------
Update Information:

Update to 1.11.0
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 26 2026 Fabio Alessandro Locati [mail@fale.io] - 1.11.0-1
- Update to 1.11.0
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.10.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2438443 - CVE-2026-25793 nebula: Nebula: Blocklist evasion via ECDSA Signature Malleability [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2438443
[ 2 ] Bug #2489903 - CVE-2026-39828 nebula: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489903
[ 3 ] Bug #2490114 - CVE-2026-39829 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490114
[ 4 ] Bug #2490475 - CVE-2026-39830 nebula: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490475
[ 5 ] Bug #2493522 - CVE-2026-39835 nebula: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493522
[ 6 ] Bug #2494295 - CVE-2026-27145 nebula: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494295
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-12d6749851' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new