Fedora 43 Update: chromium-151.0.7922.108-1.fc43
Fedora 43 Update: kernel-7.1.8-100.fc43
Fedora 43 Update: nghttp2-1.66.0-3.fc43
Fedora 43 Update: p11-kit-0.26.5-1.fc43
Fedora 43 Update: libcupsfilters-2.1.1-9.fc43
Fedora 43 Update: python-webob-1.8.11-1.fc43
Fedora 43 Update: mingw-gstreamer1-plugins-good-1.26.11-2.fc43
Fedora 43 Update: mingw-python-pip-26.2-1.fc43
Fedora 43 Update: mingw-libidn-1.44-1.fc43
Fedora 43 Update: suricata-7.0.17-1.fc43
Fedora 43 Update: xen-4.20.4-1.fc43
Fedora 44 Update: kernel-7.1.8-200.fc44
Fedora 44 Update: emacs-30.2-27.fc44
Fedora 44 Update: chromium-151.0.7922.108-1.fc44
Fedora 44 Update: chezmoi-2.72.0-1.fc44
Fedora 44 Update: python-webob-1.8.11-1.fc44
Fedora 44 Update: mingw-python-pip-26.2-1.fc44
Fedora 44 Update: knot-3.5.6-1.fc44
Fedora 44 Update: suricata-8.0.6-1.fc44
[SECURITY] Fedora 43 Update: chromium-151.0.7922.108-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-06d89684d6
2026-08-11 01:13:04.336416+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 43
Version : 151.0.7922.108
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
chromium-151.0.7922.108 security release fix 41 CVE
CVE-2026-19137: Use after free in WebGL
CVE-2026-19138: Heap buffer overflow in CrashReporting
CVE-2026-19139: Race in CredentialProvider
CVE-2026-19140: Use after free in GPU
CVE-2026-19141: Use after free in Resources
CVE-2026-19142: Use after free in Views
CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
CVE-2026-19144: Use after free in HTML
CVE-2026-19145: Use after free in Translate
CVE-2026-19146: Uninitialized Use in GPU
CVE-2026-19147: Use after free in Aura
CVE-2026-19148: Out of bounds write in GPU
CVE-2026-19149: Use after free in Aura
CVE-2026-19150: Inappropriate implementation in V8
CVE-2026-19151: Use after free in V8
CVE-2026-19152: Inappropriate implementation in Navigation
CVE-2026-19153: Insufficient validation of untrusted input in Workers
CVE-2026-19154: Use after free in Skia
CVE-2026-19155: Use after free in Payments
CVE-2026-19156: Heap buffer overflow in Base
CVE-2026-19157: Out of bounds write in ANGLE
CVE-2026-19158: Use after free in Views
CVE-2026-19159: Use after free in Views
CVE-2026-19160: Uninitialized Use in Skia
CVE-2026-19161: Uninitialized Use in Skia
CVE-2026-19162: Out of bounds write in V8
CVE-2026-19163: Use after free in Media
CVE-2026-19164: Insufficient validation of untrusted input in Codecs
CVE-2026-19165: Use after free in Extensions
CVE-2026-19166: Use after free in Web Authentication
CVE-2026-19167: Integer overflow in GPU
CVE-2026-19168: Inappropriate implementation in V8
CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
CVE-2026-19170: Use after free in WebGL
CVE-2026-19171: Use after free in Media
CVE-2026-19172: Use after free in Views
CVE-2026-19173: Out of bounds write in Skia
CVE-2026-19174: Integer overflow in V8
CVE-2026-19175: Use after free in Payments
CVE-2026-19176: Use after free in Skia
CVE-2026-19177: Insufficient validation of untrusted input in UI
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 7 2026 Than Ngo [than@redhat.com] - 151.0.7922.108-1
- Update to 151.0.7922.108
* CVE-2026-19137: Use after free in WebGL
* CVE-2026-19138: Heap buffer overflow in CrashReporting
* CVE-2026-19139: Race in CredentialProvider
* CVE-2026-19140: Use after free in GPU
* CVE-2026-19141: Use after free in Resources
* CVE-2026-19142: Use after free in Views
* CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
* CVE-2026-19144: Use after free in HTML
* CVE-2026-19145: Use after free in Translate
* CVE-2026-19146: Uninitialized Use in GPU
* CVE-2026-19147: Use after free in Aura
* CVE-2026-19148: Out of bounds write in GPU
* CVE-2026-19149: Use after free in Aura
* CVE-2026-19150: Inappropriate implementation in V8
* CVE-2026-19151: Use after free in V8
* CVE-2026-19152: Inappropriate implementation in Navigation
* CVE-2026-19153: Insufficient validation of untrusted input in Workers
* CVE-2026-19154: Use after free in Skia
* CVE-2026-19155: Use after free in Payments
* CVE-2026-19156: Heap buffer overflow in Base
* CVE-2026-19157: Out of bounds write in ANGLE
* CVE-2026-19158: Use after free in Views
* CVE-2026-19159: Use after free in Views
* CVE-2026-19160: Uninitialized Use in Skia
* CVE-2026-19161: Uninitialized Use in Skia
* CVE-2026-19162: Out of bounds write in V8
* CVE-2026-19163: Use after free in Media
* CVE-2026-19164: Insufficient validation of untrusted input in Codecs
* CVE-2026-19165: Use after free in Extensions
* CVE-2026-19166: Use after free in Web Authentication
* CVE-2026-19167: Integer overflow in GPU
* CVE-2026-19168: Inappropriate implementation in V8
* CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
* CVE-2026-19170: Use after free in WebGL
* CVE-2026-19171: Use after free in Media
* CVE-2026-19172: Use after free in Views
* CVE-2026-19173: Out of bounds write in Skia
* CVE-2026-19174: Integer overflow in V8
* CVE-2026-19175: Use after free in Payments
* CVE-2026-19176: Use after free in Skia
* CVE-2026-19177: Insufficient validation of untrusted input in UI
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-06d89684d6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: kernel-7.1.8-100.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b54e45f108
2026-08-11 01:13:04.336421+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 43
Version : 7.1.8
Release : 100.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.8 stable kernel updates contain a number of important fixes across the
tree. We are now specifying all kernel updates as security because upstream will
assign CVEs, but we will not know what those are until a bit after this update
ships.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 9 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.8-0]
- Config updates for 7.1.8 (Justin M. Forbes)
- Add to BugsFixed (Justin M. Forbes)
- smb/client: return EOPNOTSUPP for unsupported O_TMPFILE (ChenXiaoSong)
- Linux v7.1.8
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499750 - CIFS driver: openat with O_TMPFILE returns -1 ENOENT for existing directories
https://bugzilla.redhat.com/show_bug.cgi?id=2499750
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b54e45f108' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: nghttp2-1.66.0-3.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-91dd0c29d6
2026-08-11 01:13:04.336413+00:00
--------------------------------------------------------------------------------
Name : nghttp2
Product : Fedora 43
Version : 1.66.0
Release : 3.fc43
URL : https://nghttp2.org/
Summary : Experimental HTTP/2 client, server and proxy
Description :
This package contains the HTTP/2 client, server and proxy programs.
--------------------------------------------------------------------------------
Update Information:
fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous
HTTP/1.1 Upgrade requests (CVE-2026-58055)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 7 2026 Jan Macku [jamacku@redhat.com] - 1.66.0-3
- fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2502788 - CVE-2026-58055 nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502788
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-91dd0c29d6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: p11-kit-0.26.5-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e281fdcb69
2026-08-11 01:13:04.336405+00:00
--------------------------------------------------------------------------------
Name : p11-kit
Product : Fedora 43
Version : 0.26.5
Release : 1.fc43
URL : http://p11-glue.freedesktop.org/p11-kit.html
Summary : Library for loading and sharing PKCS#11 modules
Description :
p11-kit provides a way to load and enumerate PKCS#11 modules, as well
as a standard configuration setup for installing PKCS#11 modules in
such a way that they're discoverable.
--------------------------------------------------------------------------------
Update Information:
rpc: guard against overflow when decoding nested attributes (CVE-2026-18938)
Only affects 32 bit systems
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Packit [hello@packit.dev] - 0.26.5-1
- Update to 0.26.5 upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2511987 - p11-kit-0.26.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2511987
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e281fdcb69' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: libcupsfilters-2.1.1-9.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1ed9130cea
2026-08-11 01:13:04.336402+00:00
--------------------------------------------------------------------------------
Name : libcupsfilters
Product : Fedora 43
Version : 2.1.1
Release : 9.fc43
URL : https://github.com/OpenPrinting/libcupsfilters
Summary : Library for developing printing filters
Description :
Libcupsfilters provides a library, which implements common functions used
in cups-browsed daemon and printing filters, and additional files
as banner templates and character sets. The filters are used in CUPS daemon
and in printer applications.
--------------------------------------------------------------------------------
Update Information:
fixes CVE-2026-64611 and CVE-2026-64612 (fedora#2506364)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 5 2026 Zdenek Dohnal [zdohnal@redhat.com] - 1:2.1.1-9
- fixes CVE-2026-64611 and CVE-2026-64612 (fedora#2506364)
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1:2.1.1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Tue Jan 20 2026 Zdenek Dohnal [zdohnal@redhat.com] - 1:2.1.1-7
- Rebuilt with new poppler 26.01.0
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1:2.1.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2502799 - CVE-2026-64611 libcupsfilters: cups-filters: libcupsfilters: CPU exhaustion via infinite loop in cfIEEE1284NormalizeMakeModel()
https://bugzilla.redhat.com/show_bug.cgi?id=2502799
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1ed9130cea' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: python-webob-1.8.11-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-cd35233572
2026-08-11 01:13:04.336392+00:00
--------------------------------------------------------------------------------
Name : python-webob
Product : Fedora 43
Version : 1.8.11
Release : 1.fc43
URL : https://webob.org
Summary : WSGI request and response object
Description :
WebOb provides wrappers around the WSGI request environment, and an object to
help create WSGI responses. The objects map much of the specified behavior of
HTTP, including header parsing and accessors for other standard parts of the
environment.
--------------------------------------------------------------------------------
Update Information:
Update to upstream - CVE-2024-42353.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Ján ONDREJ (SAL) - 1.8.11-1
- Update to upstream - CVE-2024-42353.
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.8.10-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jun 3 2026 Python Maint - 1.8.10-3
- Rebuilt for Python 3.15
* Wed Jun 3 2026 Ján ONDREJ (SAL) - 1.8.10-2
- Enable test_client_cookies again.
* Wed Jun 3 2026 Ján ONDREJ (SAL) - 1.8.10-1
- Update to upstream.
* Sat Feb 21 2026 Ján ONDREJ (SAL) - 1.8.9-8
- Skip test_client_cookies test too to unblock python3.15 build
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.8.9-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2510112 - python-webob-1.8.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id%10112
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-cd35233572' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: mingw-gstreamer1-plugins-good-1.26.11-2.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1e22d3b0bf
2026-08-11 01:13:04.336380+00:00
--------------------------------------------------------------------------------
Name : mingw-gstreamer1-plugins-good
Product : Fedora 43
Version : 1.26.11
Release : 2.fc43
URL : http://gstreamer.freedesktop.org/
Summary : Cross compiled GStreamer1 plug-ins good
Description :
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. Applications using this library can do anything
from real-time sound processing to playing videos, and just about anything
else media-related. Its plugin-based architecture means that new data
types or processing capabilities can be added simply by installing new
plugins.
GStreamer Good Plugins is a collection of well-supported plugins of
good quality and under the LGPL license.
--------------------------------------------------------------------------------
Update Information:
Backport fix for CVE-2026-5056.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Sandro Mani [manisandro@gmail.com] - 1.26.11-2
- Backport fix for CVE-2026-5056
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509699 - CVE-2026-5056 mingw-gstreamer1: GStreamer: Arbitrary code execution via stack-based buffer overflow in qtdemux [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509699
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1e22d3b0bf' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: mingw-python-pip-26.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f7dddb6162
2026-08-11 01:13:04.336383+00:00
--------------------------------------------------------------------------------
Name : mingw-python-pip
Product : Fedora 43
Version : 26.2
Release : 1.fc43
URL : https://pypi.python.org/pypi/pip
Summary : MinGW Windows Python pip library
Description :
MinGW Windows Python pip library.
--------------------------------------------------------------------------------
Update Information:
Update to pip-26.2.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Sandro Mani [manisandro@gmail.com] - 26.2-1
- Update to 26.2
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 26.1.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509216 - CVE-2026-13346 mingw-python-pip: pip: Arbitrary file installation via malicious package indexes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509216
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f7dddb6162' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: mingw-libidn-1.44-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7ddafb24a3
2026-08-11 01:13:04.336377+00:00
--------------------------------------------------------------------------------
Name : mingw-libidn
Product : Fedora 43
Version : 1.44
Release : 1.fc43
URL : http://www.gnu.org/software/libidn/
Summary : MinGW Windows Internationalized Domain Name support library
Description :
GNU Libidn is an implementation of the Stringprep, Punycode and
IDNA specifications defined by the IETF Internationalized Domain
Names (IDN) working group, used for internationalized domain
names.
--------------------------------------------------------------------------------
Update Information:
Update to 1.44.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jun 23 2026 Sandro Mani [manisandro@gmail.com] - 1.44-1
- Update to 1.44
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.43-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509781 - CVE-2026-57053 mingw-libidn: GNU libidn: Out-of-bounds read in ToUnicode APIs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509781
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7ddafb24a3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: suricata-7.0.17-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d2a3477900
2026-08-11 01:13:04.336367+00:00
--------------------------------------------------------------------------------
Name : suricata
Product : Fedora 43
Version : 7.0.17
Release : 1.fc43
URL : https://suricata.io/
Summary : Intrusion Detection System
Description :
The Suricata Engine is an Open Source Next Generation Intrusion
Detection and Prevention Engine. This engine is not intended to
just replace or emulate the existing tools in the industry, but
will bring new ideas and technologies to the field. This new Engine
supports Multi-threading, Automatic Protocol Detection (IP, TCP,
UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP
Matching, and GeoIP identification.
--------------------------------------------------------------------------------
Update Information:
Upstream security/bugfix release
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 1 2026 Jason Taylor [jtfas90@proton.me] 7.0.17-1
- Upstream bugfix/security release
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d2a3477900' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: xen-4.20.4-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9b1af4c793
2026-08-11 01:13:04.336330+00:00
--------------------------------------------------------------------------------
Name : xen
Product : Fedora 43
Version : 4.20.4
Release : 1.fc43
URL : http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor
--------------------------------------------------------------------------------
Update Information:
update to xen 4.20.4
includes security fixes
x86 shadow paging is deprecated [XSA-495, CVE-2026-42493]
vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492]
buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494,
CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425]
sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426,
CVE-2026-62427]
grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428]
grant-table: version change racing with other operations [XSA-501,
CVE-2026-62435, CVE-2026-62436]
vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429]
x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430]
Viridian STIMER division by zero [XSA-504, CVE-2026-62431]
evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432]
correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433]
PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434]
pygrub is only supported in de-privileged mode [XSA-508]
x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487]
domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490]
Arm: Completion of memory accesses not guaranteed by completion of a TLBI
[XSA-493, CVE-2025-10263]
x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Michael Young [m.a.young@durham.ac.uk] - 4.20.4-1
- update to xen 4.20.4
- includes security fixes
x86 shadow paging is deprecated [XSA-495, CVE-2026-42493]
vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492]
buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494,
CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425]
sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426,
CVE-2026-62427]
grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428]
grant-table: version change racing with other operations [XSA-501,
CVE-2026-62435, CVE-2026-62436]
vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429]
x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430]
Viridian STIMER division by zero [XSA-504, CVE-2026-62431]
evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432]
correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433]
PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434]
pygrub is only supported in de-privileged mode [XSA-508]
* Thu Jun 18 2026 Michael Young [m.a.young@durham.ac.uk] - 4.20.3-4
[ never submitted as update ]
- x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487]
- domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490]
- Arm: Completion of memory accesses not guaranteed by completion of a TLBI
[XSA-493, CVE-2025-10263]
- x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9b1af4c793' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: kernel-7.1.8-200.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d232156d86
2026-08-11 00:59:34.387209+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 44
Version : 7.1.8
Release : 200.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.8 stable kernel updates contain a number of important fixes across the
tree. We are now specifying all kernel updates as security because upstream will
assign CVEs, but we will not know what those are until a bit after this update
ships.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 9 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.8-0]
- Config updates for 7.1.8 (Justin M. Forbes)
- Add to BugsFixed (Justin M. Forbes)
- smb/client: return EOPNOTSUPP for unsupported O_TMPFILE (ChenXiaoSong)
- Linux v7.1.8
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499750 - CIFS driver: openat with O_TMPFILE returns -1 ENOENT for existing directories
https://bugzilla.redhat.com/show_bug.cgi?id=2499750
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d232156d86' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: emacs-30.2-27.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b4d966ae0a
2026-08-11 00:59:34.387202+00:00
--------------------------------------------------------------------------------
Name : emacs
Product : Fedora 44
Version : 30.2
Release : 27.fc44
URL : https://www.gnu.org/software/emacs/
Summary : GNU Emacs text editor
Description :
GNU Emacs is a powerful, customizable, self-documenting, modeless text
editor. It contains special code editing features, a scripting language
(elisp), and the capability to read mail, news, and more without leaving
the editor.
--------------------------------------------------------------------------------
Update Information:
This mitigates a vulnerability that allowed a specially crafted file to trigger
execution of attacker-controlled arbitrary Emacs Lisp code immediately when the
file is visited in Emacs (before the file's malicious contents are even
displayed). https://debbugs.gnu.org/cgi/bugreport.cgi?bug=80574
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 7 2026 Peter Oliver [git@mavit.org.uk] - 1:30.2-27
- Remember to include patch.
* Fri Aug 7 2026 Peter Oliver [git@mavit.org.uk] - 1:30.2-26
- Mitigate arbitrary code execution vulnerability around risky 'intern'
calls.
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b4d966ae0a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: chromium-151.0.7922.108-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-eebdfdf5ba
2026-08-11 00:59:34.387204+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 44
Version : 151.0.7922.108
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
chromium-151.0.7922.108 security release fix 41 CVE
CVE-2026-19137: Use after free in WebGL
CVE-2026-19138: Heap buffer overflow in CrashReporting
CVE-2026-19139: Race in CredentialProvider
CVE-2026-19140: Use after free in GPU
CVE-2026-19141: Use after free in Resources
CVE-2026-19142: Use after free in Views
CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
CVE-2026-19144: Use after free in HTML
CVE-2026-19145: Use after free in Translate
CVE-2026-19146: Uninitialized Use in GPU
CVE-2026-19147: Use after free in Aura
CVE-2026-19148: Out of bounds write in GPU
CVE-2026-19149: Use after free in Aura
CVE-2026-19150: Inappropriate implementation in V8
CVE-2026-19151: Use after free in V8
CVE-2026-19152: Inappropriate implementation in Navigation
CVE-2026-19153: Insufficient validation of untrusted input in Workers
CVE-2026-19154: Use after free in Skia
CVE-2026-19155: Use after free in Payments
CVE-2026-19156: Heap buffer overflow in Base
CVE-2026-19157: Out of bounds write in ANGLE
CVE-2026-19158: Use after free in Views
CVE-2026-19159: Use after free in Views
CVE-2026-19160: Uninitialized Use in Skia
CVE-2026-19161: Uninitialized Use in Skia
CVE-2026-19162: Out of bounds write in V8
CVE-2026-19163: Use after free in Media
CVE-2026-19164: Insufficient validation of untrusted input in Codecs
CVE-2026-19165: Use after free in Extensions
CVE-2026-19166: Use after free in Web Authentication
CVE-2026-19167: Integer overflow in GPU
CVE-2026-19168: Inappropriate implementation in V8
CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
CVE-2026-19170: Use after free in WebGL
CVE-2026-19171: Use after free in Media
CVE-2026-19172: Use after free in Views
CVE-2026-19173: Out of bounds write in Skia
CVE-2026-19174: Integer overflow in V8
CVE-2026-19175: Use after free in Payments
CVE-2026-19176: Use after free in Skia
CVE-2026-19177: Insufficient validation of untrusted input in UI
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 7 2026 Than Ngo [than@redhat.com] - 151.0.7922.108-1
- Update to 151.0.7922.108
* CVE-2026-19137: Use after free in WebGL
* CVE-2026-19138: Heap buffer overflow in CrashReporting
* CVE-2026-19139: Race in CredentialProvider
* CVE-2026-19140: Use after free in GPU
* CVE-2026-19141: Use after free in Resources
* CVE-2026-19142: Use after free in Views
* CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs
* CVE-2026-19144: Use after free in HTML
* CVE-2026-19145: Use after free in Translate
* CVE-2026-19146: Uninitialized Use in GPU
* CVE-2026-19147: Use after free in Aura
* CVE-2026-19148: Out of bounds write in GPU
* CVE-2026-19149: Use after free in Aura
* CVE-2026-19150: Inappropriate implementation in V8
* CVE-2026-19151: Use after free in V8
* CVE-2026-19152: Inappropriate implementation in Navigation
* CVE-2026-19153: Insufficient validation of untrusted input in Workers
* CVE-2026-19154: Use after free in Skia
* CVE-2026-19155: Use after free in Payments
* CVE-2026-19156: Heap buffer overflow in Base
* CVE-2026-19157: Out of bounds write in ANGLE
* CVE-2026-19158: Use after free in Views
* CVE-2026-19159: Use after free in Views
* CVE-2026-19160: Uninitialized Use in Skia
* CVE-2026-19161: Uninitialized Use in Skia
* CVE-2026-19162: Out of bounds write in V8
* CVE-2026-19163: Use after free in Media
* CVE-2026-19164: Insufficient validation of untrusted input in Codecs
* CVE-2026-19165: Use after free in Extensions
* CVE-2026-19166: Use after free in Web Authentication
* CVE-2026-19167: Integer overflow in GPU
* CVE-2026-19168: Inappropriate implementation in V8
* CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks
* CVE-2026-19170: Use after free in WebGL
* CVE-2026-19171: Use after free in Media
* CVE-2026-19172: Use after free in Views
* CVE-2026-19173: Out of bounds write in Skia
* CVE-2026-19174: Integer overflow in V8
* CVE-2026-19175: Use after free in Payments
* CVE-2026-19176: Use after free in Skia
* CVE-2026-19177: Insufficient validation of untrusted input in UI
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-eebdfdf5ba' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: chezmoi-2.72.0-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4ca48be67c
2026-08-11 00:59:34.387189+00:00
--------------------------------------------------------------------------------
Name : chezmoi
Product : Fedora 44
Version : 2.72.0
Release : 1.fc44
URL : https://github.com/twpayne/chezmoi
Summary : Manage your dotfiles across multiple diverse machines
Description :
Manage your dotfiles across multiple diverse machines, securely.
--------------------------------------------------------------------------------
Update Information:
Update to 2.72.0
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 3 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 2.72.0-1
- Update to 2.72.0 - Closes rhbz#2497951
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489891 - CVE-2026-39828 chezmoi: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489891
[ 2 ] Bug #2490088 - CVE-2026-39829 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490088
[ 3 ] Bug #2490398 - CVE-2026-39830 chezmoi: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490398
[ 4 ] Bug #2493053 - CVE-2026-39832 chezmoi: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493053
[ 5 ] Bug #2493488 - CVE-2026-39835 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493488
[ 6 ] Bug #2495261 - CVE-2026-25681 chezmoi: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495261
[ 7 ] Bug #2496497 - CVE-2026-44740 chezmoi: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496497
[ 8 ] Bug #2509311 - CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509311
[ 9 ] Bug #2509459 - CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509459
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4ca48be67c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: python-webob-1.8.11-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7aaa63dd24
2026-08-11 00:59:34.387166+00:00
--------------------------------------------------------------------------------
Name : python-webob
Product : Fedora 44
Version : 1.8.11
Release : 1.fc44
URL : https://webob.org
Summary : WSGI request and response object
Description :
WebOb provides wrappers around the WSGI request environment, and an object to
help create WSGI responses. The objects map much of the specified behavior of
HTTP, including header parsing and accessors for other standard parts of the
environment.
--------------------------------------------------------------------------------
Update Information:
Update to upstream - CVE-2024-42353.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Ján ONDREJ (SAL) - 1.8.11-1
- Update to upstream - CVE-2024-42353.
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.8.10-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jun 3 2026 Python Maint - 1.8.10-3
- Rebuilt for Python 3.15
* Wed Jun 3 2026 Ján ONDREJ (SAL) - 1.8.10-2
- Enable test_client_cookies again.
* Wed Jun 3 2026 Ján ONDREJ (SAL) - 1.8.10-1
- Update to upstream.
* Sat Feb 21 2026 Ján ONDREJ (SAL) - 1.8.9-8
- Skip test_client_cookies test too to unblock python3.15 build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2510112 - python-webob-1.8.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id%10112
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7aaa63dd24' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 44 Update: mingw-python-pip-26.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-676dfc2776
2026-08-11 00:59:34.387153+00:00
--------------------------------------------------------------------------------
Name : mingw-python-pip
Product : Fedora 44
Version : 26.2
Release : 1.fc44
URL : https://pypi.python.org/pypi/pip
Summary : MinGW Windows Python pip library
Description :
MinGW Windows Python pip library.
--------------------------------------------------------------------------------
Update Information:
Update to pip-26.2.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Sandro Mani [manisandro@gmail.com] - 26.2-1
- Update to 26.2
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 26.1.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509216 - CVE-2026-13346 mingw-python-pip: pip: Arbitrary file installation via malicious package indexes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509216
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-676dfc2776' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: knot-3.5.6-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6f4584d9b3
2026-08-11 00:59:34.387148+00:00
--------------------------------------------------------------------------------
Name : knot
Product : Fedora 44
Version : 3.5.6
Release : 1.fc44
URL : https://www.knot-dns.cz
Summary : High-performance authoritative DNS server
Description :
Knot DNS is a high-performance authoritative DNS server implementation.
--------------------------------------------------------------------------------
Update Information:
new upstream release including a security fix for ACL processing
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 2 2026 Jan Včelák [jvcelak@fedoraproject.org] - 3.5.6-1
- Update to 3.5.6 (security fix for ACL evaluation)
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6f4584d9b3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 44 Update: suricata-8.0.6-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-17bacbd575
2026-08-11 00:59:34.387137+00:00
--------------------------------------------------------------------------------
Name : suricata
Product : Fedora 44
Version : 8.0.6
Release : 1.fc44
URL : https://suricata.io/
Summary : Intrusion Detection System
Description :
The Suricata Engine is an Open Source Next Generation Intrusion
Detection and Prevention Engine. This engine is not intended to
just replace or emulate the existing tools in the industry, but
will bring new ideas and technologies to the field. This new Engine
supports Multi-threading, Automatic Protocol Detection (IP, TCP,
UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP
Matching, and GeoIP identification.
--------------------------------------------------------------------------------
Update Information:
Upstream security/bugfix release
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 1 2026 Jason Taylor [jtfas90@proton.me] - 8.0.6-1
- Upstream security/bugfix release
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-17bacbd575' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new