Fedora 43 Update: chromium-150.0.7871.181-1.fc43
Fedora 43 Update: python-django5-5.2.16-1.fc43
Fedora 43 Update: dotnet10.0-10.0.110-1.fc43
Fedora 43 Update: mupdf-1.27.2-2.fc43
Fedora 43 Update: sssd-2.12.0-3.fc43
Fedora 43 Update: wget1-1.25.0-3.fc43
Fedora 43 Update: mbedtls-3.6.7-1.fc43
Fedora 44 Update: chromium-150.0.7871.181-1.fc44
Fedora 44 Update: dotnet10.0-10.0.110-1.fc44
Fedora 44 Update: skopeo-1.22.2-2.fc44
Fedora 44 Update: netatalk-4.5.1-1.fc44
[SECURITY] Fedora 43 Update: chromium-150.0.7871.181-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-acf674bc6a
2026-07-25 01:17:32.017887+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 43
Version : 150.0.7871.181
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.181
* CVE-2026-16413: Out of bounds write in ANGLE
* CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
* CVE-2026-16415: Insufficient validation of untrusted input in Extensions
* CVE-2026-16416: Integer overflow in Chromecast
* CVE-2026-16417: Uninitialized Use in Skia
* CVE-2026-16418: Stack buffer overflow in V8
* CVE-2026-16419: Out of bounds read and write in ANGLE
* CVE-2026-16420: Type Confusion in WebAudio
* CVE-2026-16421: Inappropriate implementation in WebAudio
* CVE-2026-16422: Insufficient validation of untrusted input in Certificate
* CVE-2026-16423: Use after free in UI
* CVE-2026-16424: Use after free in GPU
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Than Ngo [than@redhat.com] - 150.0.7871.181-1
- Update to 150.0.7871.181
* CVE-2026-16413: Out of bounds write in ANGLE
* CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
* CVE-2026-16415: Insufficient validation of untrusted input in Extensions
* CVE-2026-16416: Integer overflow in Chromecast
* CVE-2026-16417: Uninitialized Use in Skia
* CVE-2026-16418: Stack buffer overflow in V8
* CVE-2026-16419: Out of bounds read and write in ANGLE
* CVE-2026-16420: Type Confusion in WebAudio
* CVE-2026-16421: Inappropriate implementation in WebAudio
* CVE-2026-16422: Insufficient validation of untrusted input in Certificate
* CVE-2026-16423: Use after free in UI
* CVE-2026-16424: Use after free in GPU
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506058 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506058
[ 2 ] Bug #2506059 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506059
[ 3 ] Bug #2506110 - CVE-2026-13022 chromium: From CVEorg collector [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506110
[ 4 ] Bug #2506111 - CVE-2026-13022 chromium: From CVEorg collector [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506111
[ 5 ] Bug #2506114 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506114
[ 6 ] Bug #2506115 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506115
[ 7 ] Bug #2506116 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506116
[ 8 ] Bug #2506117 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506117
[ 9 ] Bug #2506118 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506118
[ 10 ] Bug #2506119 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506119
[ 11 ] Bug #2506124 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506124
[ 12 ] Bug #2506125 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506125
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-acf674bc6a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: python-django5-5.2.16-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-fbb9501b22
2026-07-25 01:17:32.017879+00:00
--------------------------------------------------------------------------------
Name : python-django5
Product : Fedora 43
Version : 5.2.16
Release : 1.fc43
URL : https://www.djangoproject.com/
Summary : A high-level Python Web framework
Description :
Django is a high-level Python Web framework that encourages rapid
development and a clean, pragmatic design. It focuses on automating as
much as possible and adhering to the DRY (Don't Repeat Yourself)
principle.
--------------------------------------------------------------------------------
Update Information:
Update python-django5 to version 5.2.16
Fixes three low-severity CVEs
CVE-2026-48588: Potential exposure of private data via cached Set-Cookie
response
CVE-2026-53877: Heap buffer over-read in GDALRaster
CVE-2026-53878: Header injection possibility since DomainNameValidator accepted
newlines in input
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Michel Lind [salimma@fedoraproject.org] - 5.2.16-1
- Update to version 5.2.16; Resolves RHBZ#2497734
- Fixes three low-severity CVEs
- CVE-2026-48588: Potential exposure of private data via cached Set-Cookie
response
- CVE-2026-53877: Heap buffer over-read in GDALRaster
- CVE-2026-53878: Header injection possibility since DomainNameValidator
accepted newlines in input
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 5.2.15-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 19 2026 Miro Hrončok [miro@hroncok.cz] - 5.2.15-5
- Heavily reduce the list of skipped tests
* Sat Jun 6 2026 Michel Lind [salimma@fedoraproject.org] - 5.2.15-4
- Remove dump of disabled tests from the end of the spec
* Sat Jun 6 2026 Michel Lind [salimma@fedoraproject.org] - 5.2.15-3
- Disable failing tests on Python 3.15
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2497734 - python-django5-5.2.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id$97734
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-fbb9501b22' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: dotnet10.0-10.0.110-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d9817786d6
2026-07-25 01:17:32.017877+00:00
--------------------------------------------------------------------------------
Name : dotnet10.0
Product : Fedora 43
Version : 10.0.110
Release : 1.fc43
URL : https://github.com/dotnet/
Summary : .NET 10.0 Runtime and SDK
Description :
.NET is a fast, lightweight and modular platform for creating
cross platform applications that work on Linux, macOS and Windows.
It particularly focuses on creating console applications, web
applications and micro-services.
.NET contains a runtime conforming to .NET Standards a set of
framework libraries, an SDK containing compilers and a 'dotnet'
application to drive everything.
--------------------------------------------------------------------------------
Update Information:
Update to .NET SDK 10.0.110 and Runtime 10.0.10
Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-
50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-
50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-
50659,CVE-2026-56158,CVE-2026-57108
Release Notes:
SDK: https://github.com/dotnet/core/blob/main/release-
notes/10.0/10.0.10/10.0.110.md
Runtime: https://github.com/dotnet/core/blob/main/release-
notes/10.0/10.0.10/10.0.10.md
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Omair Majid [omajid@redhat.com] - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d9817786d6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: mupdf-1.27.2-2.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8870088088
2026-07-25 01:17:32.017872+00:00
--------------------------------------------------------------------------------
Name : mupdf
Product : Fedora 43
Version : 1.27.2
Release : 2.fc43
URL : http://mupdf.com/
Summary : A lightweight PDF viewer and toolkit
Description :
MuPDF is a lightweight PDF viewer and toolkit written in portable C.
The renderer in MuPDF is tailored for high quality anti-aliased
graphics. MuPDF renders text with metrics and spacing accurate to
within fractions of a pixel for the highest fidelity in reproducing
the look of a printed page on screen.
MuPDF has a small footprint. A binary that includes the standard
Roman fonts is only one megabyte. A build with full CJK support
(including an Asian font) is approximately seven megabytes.
MuPDF has support for all non-interactive PDF 1.7 features, and the
toolkit provides a simple API for accessing the internal structures of
the PDF document. Example code for navigating interactive links and
bookmarks, encrypting PDF files, extracting fonts, images, and
searchable text, and rendering pages to image files is provided.
--------------------------------------------------------------------------------
Update Information:
fix CVE-2026-7233 (rhbz#2463402)
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Michael J Gruber [mjg@fedoraproject.org] - 1.27.2-2
- fix CVE-2026-7233 (rhbz#2463402)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2463402 - CVE-2026-7233 mupdf: Artifex MuPDF: Information disclosure due to out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2463402
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8870088088' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: sssd-2.12.0-3.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9ab663dcd4
2026-07-25 01:17:32.017844+00:00
--------------------------------------------------------------------------------
Name : sssd
Product : Fedora 43
Version : 2.12.0
Release : 3.fc43
URL : https://github.com/SSSD/sssd/
Summary : System Security Services Daemon
Description :
Provides a set of daemons to manage access to remote directories and
authentication mechanisms. It provides an NSS and PAM interface toward
the system and a pluggable back end system to connect to multiple different
account sources. It is also the basis to provide client auditing and policy
services for projects like FreeIPA.
The sssd subpackage is a meta-package that contains the daemon as well as all
the existing back ends.
--------------------------------------------------------------------------------
Update Information:
CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476
- rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam'
process
- rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via
unsanitized
gPCFileSysPath allows Kerberos authentication bypass
- rhbz#2497651: CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire
directory
tree for sudoRole objects by default, enabling privilege escalation
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 8 2026 Sumit Bose [sbose@redhat.com] - 2.12.0-3
- CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476
- rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD'
'sssd_pam' process
- rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via
unsanitized gPCFileSysPath allows Kerberos authentication bypass
- rhbz#2497651: CVE-2026-14474 sssd: sssd: sudo LDAP provider searches
entire directory tree for sudoRole objects by default, enabling privilege
escalation
* Tue Apr 28 2026 Pavel Březina [pbrezina@redhat.com] - 2.12.0-2
- spec: add default value for samba_package_version
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2494777 - CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$94777
[ 2 ] Bug #2497650 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97650
[ 3 ] Bug #2497651 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97651
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9ab663dcd4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: wget1-1.25.0-3.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7bbb52b49d
2026-07-25 01:17:32.017870+00:00
--------------------------------------------------------------------------------
Name : wget1
Product : Fedora 43
Version : 1.25.0
Release : 3.fc43
URL : http://www.gnu.org/software/wget/
Summary : A utility for retrieving files using the HTTP or FTP protocols
Description :
GNU Wget is a file retrieval utility which can use either the HTTP or
FTP protocols. Wget features include the ability to work in the
background while you are logged out, recursive retrieval of
directories, file name wildcard matching, remote file timestamp
storage and comparison, use of Rest with FTP servers and Range with
HTTP servers to retrieve files over slow or unstable connections,
support for Proxy servers, and configurability.
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Michal Ruprich [mruprich@redhat.com] - 1.25.0-3
- Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499188 - CVE-2026-15146 wget1: Wget: Server-Side Request Forgery via FTP PASV response IP address validation bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499188
[ 2 ] Bug #2499583 - CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499583
[ 3 ] Bug #2499957 - CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499957
[ 4 ] Bug #2499971 - CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499971
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7bbb52b49d' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: mbedtls-3.6.7-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0bb141710c
2026-07-25 01:17:32.017863+00:00
--------------------------------------------------------------------------------
Name : mbedtls
Product : Fedora 43
Version : 3.6.7
Release : 1.fc43
URL : https://www.trustedfirmware.org/projects/mbed-tls
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.
--------------------------------------------------------------------------------
Update Information:
Update to 3.6.7
Fixes CVE-2026-25832, CVE-2026-35336, CVE-2026-49300, CVE-2026-50579,
CVE-2026-50580, CVE-2026-50581, CVE-2026-50583, CVE-2026-50584, CVE-2026-50585,
CVE-2026-50586, CVE-2026-50587, CVE-2026-50588, CVE-2026-50640, CVE-2026-50713,
CVE-2026-54435, CVE-2026-54441
Release notes: https://github.com/Mbed-TLS/mbedtls/releases#release-
mbedtls-3.6.7
--------------------------------------------------------------------------------
ChangeLog:
* Sat Jul 11 2026 Morten Stevens [mstevens@fedoraproject.org] - 3.6.7-1
- Update to 3.6.7
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0bb141710c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: chromium-150.0.7871.181-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4870f59184
2026-07-25 00:54:36.250235+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 44
Version : 150.0.7871.181
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.181
* CVE-2026-16413: Out of bounds write in ANGLE
* CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
* CVE-2026-16415: Insufficient validation of untrusted input in Extensions
* CVE-2026-16416: Integer overflow in Chromecast
* CVE-2026-16417: Uninitialized Use in Skia
* CVE-2026-16418: Stack buffer overflow in V8
* CVE-2026-16419: Out of bounds read and write in ANGLE
* CVE-2026-16420: Type Confusion in WebAudio
* CVE-2026-16421: Inappropriate implementation in WebAudio
* CVE-2026-16422: Insufficient validation of untrusted input in Certificate
* CVE-2026-16423: Use after free in UI
* CVE-2026-16424: Use after free in GPU
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Than Ngo [than@redhat.com] - 150.0.7871.181-1
- Update to 150.0.7871.181
* CVE-2026-16413: Out of bounds write in ANGLE
* CVE-2026-16414: Insufficient validation of untrusted input in Chromecast
* CVE-2026-16415: Insufficient validation of untrusted input in Extensions
* CVE-2026-16416: Integer overflow in Chromecast
* CVE-2026-16417: Uninitialized Use in Skia
* CVE-2026-16418: Stack buffer overflow in V8
* CVE-2026-16419: Out of bounds read and write in ANGLE
* CVE-2026-16420: Type Confusion in WebAudio
* CVE-2026-16421: Inappropriate implementation in WebAudio
* CVE-2026-16422: Insufficient validation of untrusted input in Certificate
* CVE-2026-16423: Use after free in UI
* CVE-2026-16424: Use after free in GPU
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506058 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506058
[ 2 ] Bug #2506059 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506059
[ 3 ] Bug #2506110 - CVE-2026-13022 chromium: From CVEorg collector [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506110
[ 4 ] Bug #2506111 - CVE-2026-13022 chromium: From CVEorg collector [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506111
[ 5 ] Bug #2506114 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506114
[ 6 ] Bug #2506115 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506115
[ 7 ] Bug #2506116 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506116
[ 8 ] Bug #2506117 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506117
[ 9 ] Bug #2506118 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506118
[ 10 ] Bug #2506119 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506119
[ 11 ] Bug #2506124 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506124
[ 12 ] Bug #2506125 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506125
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4870f59184' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: dotnet10.0-10.0.110-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f738966fc9
2026-07-25 00:54:36.250213+00:00
--------------------------------------------------------------------------------
Name : dotnet10.0
Product : Fedora 44
Version : 10.0.110
Release : 1.fc44
URL : https://github.com/dotnet/
Summary : .NET 10.0 Runtime and SDK
Description :
.NET is a fast, lightweight and modular platform for creating
cross platform applications that work on Linux, macOS and Windows.
It particularly focuses on creating console applications, web
applications and micro-services.
.NET contains a runtime conforming to .NET Standards a set of
framework libraries, an SDK containing compilers and a 'dotnet'
application to drive everything.
--------------------------------------------------------------------------------
Update Information:
Update to .NET SDK 10.0.110 and Runtime 10.0.10
Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026-
50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026-
50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026-
50659,CVE-2026-56158,CVE-2026-57108
Release Notes:
SDK: https://github.com/dotnet/core/blob/main/release-
notes/10.0/10.0.10/10.0.110.md
Runtime: https://github.com/dotnet/core/blob/main/release-
notes/10.0/10.0.10/10.0.10.md
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Omair Majid [omajid@redhat.com] - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f738966fc9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: skopeo-1.22.2-2.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9b2e56edf5
2026-07-25 00:54:36.250222+00:00
--------------------------------------------------------------------------------
Name : skopeo
Product : Fedora 44
Version : 1.22.2
Release : 2.fc44
URL : https://github.com/containers/skopeo
Summary : Inspect container images and repositories on registries
Description :
Command line utility to inspect images and repositories directly on Docker
registries without the need to pull them.
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability).
Rebuild with golang-1.26.5 which includes the fix.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Lokesh Mandvekar [lsm5@redhat.com] - 1:1.22.2-2
- Rebuild for CVE-2026-27145
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2494281 - CVE-2026-27145 skopeo: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494281
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9b2e56edf5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: netatalk-4.5.1-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d085110cf3
2026-07-25 00:54:36.250211+00:00
--------------------------------------------------------------------------------
Name : netatalk
Product : Fedora 44
Version : 4.5.1
Release : 1.fc44
URL : http://netatalk.sourceforge.net
Summary : Open Source Apple Filing Protocol(AFP) File Server
Description :
Netatalk is a freely-available Open Source AFP file server. A *NIX/*BSD
system running Netatalk is capable of serving many Macintosh clients
simultaneously as an AppleShare file server (AFP).
In addition to the AFP file server daemon, the following utility programs
are also included:
* ad - AppleDouble file utility suite
* afpldaptest - validate Netatalk LDAP parameters
* afppasswd - RandNum UAM password management
* afpstats - inquire AFP server usage stats
* asip-status - inquire AFP server capabilities
* dbd - CNID database maintenance
--------------------------------------------------------------------------------
Update Information:
4.5.1 Release
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Andrew Bauer [zonexpertconsulting@outlook.com] - 5:4.5.1-1
- 4.5.1 release
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 5:4.4.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 5:4.4.3-2
- Rebuilt for openssl 4.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2480442 - CVE-2026-44071 netatalk: Netatalk: Denial of Service due to missing buffer overflow detection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480442
[ 2 ] Bug #2480443 - CVE-2026-44074 netatalk: Netatalk: Service disruption due to incorrect error handling [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480443
[ 3 ] Bug #2480445 - CVE-2026-7837 netatalk: Netatalk: Limited data modification due to TOCTOU condition [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480445
[ 4 ] Bug #2480448 - CVE-2026-44075 netatalk: Netatalk: Minor service disruption via crafted DSI session options [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480448
[ 5 ] Bug #2480460 - CVE-2026-44059 netatalk: Netatalk: Privilege bypass due to non-reentrant privilege toggle [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480460
[ 6 ] Bug #2480463 - CVE-2026-7836 netatalk: Netatalk: Integrity impact due to hextoint macro uppercase bug [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480463
[ 7 ] Bug #2480464 - CVE-2026-44061 netatalk: Netatalk: Information disclosure via DES-ECB authentication timing side channel [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480464
[ 8 ] Bug #2480466 - CVE-2026-44069 netatalk: Netatalk: Integer underflow vulnerability in volxlate function [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480466
[ 9 ] Bug #2480469 - CVE-2026-44073 netatalk: Netatalk: Security bypass due to ignored seteuid failure in authentication modules [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480469
[ 10 ] Bug #2480475 - CVE-2026-44072 netatalk: Netatalk: Low impact to integrity and availability via unintended command execution after failed directory change [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480475
[ 11 ] Bug #2480477 - CVE-2026-44067 netatalk: Netatalk: Information disclosure or denial of service via heap over-read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480477
[ 12 ] Bug #2480482 - CVE-2026-44056 netatalk: Netatalk: Denial of Service via stack buffer overflow [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480482
[ 13 ] Bug #2480492 - CVE-2026-44070 netatalk: Netatalk: Denial of Service via unbounded realloc in charset conversion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480492
[ 14 ] Bug #2480495 - CVE-2026-44053 netatalk: Netatalk: Data compromise due to weak cryptography [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480495
[ 15 ] Bug #2480500 - CVE-2026-7835 netatalk: Netatalk: Denial of Service via format string argument mismatch [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480500
[ 16 ] Bug #2480504 - CVE-2026-44063 netatalk: Netatalk: Information disclosure and data modification via LDAP filter injection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480504
[ 17 ] Bug #2480630 - CVE-2026-44065 netatalk: off-by-two in papd lp_write() [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480630
[ 18 ] Bug #2480632 - CVE-2026-44058 netatalk: authentication bypass via admin auth user [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480632
[ 19 ] Bug #2483525 - netatalk-4.5.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2483525
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d085110cf3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new