Fedora Linux 9432 Published by

Fedora released a batch of security patches for versions 43 and 44 on July 29, 2026. The update addresses critical flaws in five packages: Chromium, restic, kronosnet, btrbk, and gpsd. System administrators should apply these fixes to resolve sandbox escapes, command injection risks, memory corruption bugs, and multiple cryptographic vulnerabilities tracked under specific CVE identifiers. Users can install the patches by running dnf upgrade --advisory [update-ID] from their terminal.

Fedora 43 Update: chromium-150.0.7871.186-1.fc43
Fedora 43 Update: restic-0.19.1-1.fc43
Fedora 43 Update: kronosnet-1.35-1.fc43
Fedora 43 Update: btrbk-0.32.7-1.fc43
Fedora 43 Update: gpsd-3.26.1-7.fc43
Fedora 44 Update: chromium-150.0.7871.186-1.fc44
Fedora 44 Update: kronosnet-1.35-1.fc44
Fedora 44 Update: restic-0.19.1-1.fc44




[SECURITY] Fedora 43 Update: chromium-150.0.7871.186-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8a09a7af63
2026-07-29 01:08:23.879814+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 43
Version : 150.0.7871.186
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 24 2026 Than Ngo [than@redhat.com] - 150.0.7871.186-1
- Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2506679 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506679
[ 2 ] Bug #2506680 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506680
[ 3 ] Bug #2506681 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506681
[ 4 ] Bug #2506682 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506682
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8a09a7af63' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: restic-0.19.1-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a006788209
2026-07-29 01:08:23.879759+00:00
--------------------------------------------------------------------------------

Name : restic
Product : Fedora 43
Version : 0.19.1
Release : 1.fc43
URL : https://github.com/restic/restic
Summary : Fast, secure, efficient backup program
Description :
Fast, secure, efficient backup program.

restic supports the following backends for storing backups natively:

* Local directory
* sftp server (via SSH)
* HTTP REST server (protocol, rest-server)
* Amazon S3 (either from Amazon or using the Minio server)
* OpenStack Swift
* BackBlaze B2
* Microsoft Azure Blob Storage
* Google Cloud Storage
* And many other services via the rclone Backend

--------------------------------------------------------------------------------
Update Information:

Update to 0.19.1
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Packit [hello@packit.dev] - 0.19.1-1
- Update to 0.19.1 upstream release
- Resolves: rhbz#2497130
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489947 - CVE-2026-39828 restic: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489947
[ 2 ] Bug #2490058 - CVE-2026-39829 restic: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490058
[ 3 ] Bug #2490417 - CVE-2026-39830 restic: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490417
[ 4 ] Bug #2492926 - CVE-2026-49980 restic: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2492926
[ 5 ] Bug #2493524 - CVE-2026-39835 restic: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493524
[ 6 ] Bug #2494239 - CVE-2026-27145 restic: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494239
[ 7 ] Bug #2494460 - CVE-2026-39833 restic: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494460
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a006788209' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: kronosnet-1.35-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-56568b6fe8
2026-07-29 01:08:23.879762+00:00
--------------------------------------------------------------------------------

Name : kronosnet
Product : Fedora 43
Version : 1.35
Release : 1.fc43
URL : https://kronosnet.org
Summary : Multipoint-to-Multipoint VPN daemon
Description :
The kronosnet source

--------------------------------------------------------------------------------
Update Information:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic
configuration changes. Wipe cryptographic keys with explicit_bzero() before
freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves
rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on
unencrypted dynamic links. Validate source address against claimed link_id and
enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via
malformed network packet defragmentation. Validate fragment sequence numbers
before accessing defragmentation buffers. (Resolves rhbz#2500864)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Fabio M. Di Nitto [fdinitto@redhat.com] - 1.35-1
- New upstream release
- CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
- CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
- CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
- tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets
- libnozzle: Introduce test macros similar to libknet
- docs: convert README to markdown format
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-56568b6fe8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: btrbk-0.32.7-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1528cb06a7
2026-07-29 01:08:23.879755+00:00
--------------------------------------------------------------------------------

Name : btrbk
Product : Fedora 43
Version : 0.32.7
Release : 1.fc43
URL : https://digint.ch/btrbk/
Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes
Description :
Backup tool for btrfs sub-volumes, using a configuration file, allows
creation of backups from multiple sources to multiple destinations,
with ssh and flexible retention policy support (hourly, daily,
weekly, monthly)

--------------------------------------------------------------------------------
Update Information:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Juan Orti Alcaine [jortialc@redhat.com] - 0.32.7-1
- Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Sun Oct 5 2025 Juan Orti Alcaine [jortialc@redhat.com] - 0.32.6-9
- Add logrotate file (RHBZ#2385266)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502632 - btrbk-0.32.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502632
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1528cb06a7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: gpsd-3.26.1-7.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d61fcb86ed
2026-07-29 01:08:23.879722+00:00
--------------------------------------------------------------------------------

Name : gpsd
Product : Fedora 43
Version : 3.26.1
Release : 7.fc43
URL : https://gpsd.gitlab.io/gpsd/index.html
Summary : Service daemon for mediating access to a GPS
Description :
gpsd is a service daemon that mediates access to a GPS sensor
connected to the host computer by serial or USB interface, making its
data on the location/course/velocity of the sensor available to be
queried on TCP port 2947 of the host computer. With gpsd, multiple
GPS client applications (such as navigational and war-driving software)
can share access to a GPS without contention or loss of data. Also,
gpsd responds to queries with a format that is substantially easier to
parse than NMEA 0183.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2026-58459
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 13 2026 Miroslav Lichvar [mlichvar@redhat.com] - 1:3.26.1-7
- fix command injection in gpsprof (CVE-2026-58459)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2498940 - CVE-2026-58459 gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498940
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d61fcb86ed' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: chromium-150.0.7871.186-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e48156418f
2026-07-29 00:59:33.776051+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 44
Version : 150.0.7871.186
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 24 2026 Than Ngo [than@redhat.com] - 150.0.7871.186-1
- Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2506679 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506679
[ 2 ] Bug #2506680 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506680
[ 3 ] Bug #2506681 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506681
[ 4 ] Bug #2506682 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506682
[ 5 ] Bug #2507418 - CVE-2026-16807 chromium: Google Chrome Codecs: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507418
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e48156418f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: kronosnet-1.35-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-db53330c8f
2026-07-29 00:59:33.775989+00:00
--------------------------------------------------------------------------------

Name : kronosnet
Product : Fedora 44
Version : 1.35
Release : 1.fc44
URL : https://kronosnet.org
Summary : Multipoint-to-Multipoint VPN daemon
Description :
The kronosnet source

--------------------------------------------------------------------------------
Update Information:

CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic
configuration changes. Wipe cryptographic keys with explicit_bzero() before
freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves
rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on
unencrypted dynamic links. Validate source address against claimed link_id and
enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via
malformed network packet defragmentation. Validate fragment sequence numbers
before accessing defragmentation buffers. (Resolves rhbz#2500864)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Fabio M. Di Nitto [fdinitto@redhat.com] - 1.35-1
- New upstream release
- CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
- CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
- CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
- tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets
- libnozzle: Introduce test macros similar to libknet
- docs: convert README to markdown format
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-db53330c8f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: restic-0.19.1-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c87cc5b948
2026-07-29 00:59:33.775987+00:00
--------------------------------------------------------------------------------

Name : restic
Product : Fedora 44
Version : 0.19.1
Release : 1.fc44
URL : https://github.com/restic/restic
Summary : Fast, secure, efficient backup program
Description :
Fast, secure, efficient backup program.

restic supports the following backends for storing backups natively:

* Local directory
* sftp server (via SSH)
* HTTP REST server (protocol, rest-server)
* Amazon S3 (either from Amazon or using the Minio server)
* OpenStack Swift
* BackBlaze B2
* Microsoft Azure Blob Storage
* Google Cloud Storage
* And many other services via the rclone Backend

--------------------------------------------------------------------------------
Update Information:

Update to 0.19.1
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Packit [hello@packit.dev] - 0.19.1-1
- Update to 0.19.1 upstream release
- Resolves: rhbz#2497130
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489947 - CVE-2026-39828 restic: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489947
[ 2 ] Bug #2490058 - CVE-2026-39829 restic: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490058
[ 3 ] Bug #2490417 - CVE-2026-39830 restic: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490417
[ 4 ] Bug #2492926 - CVE-2026-49980 restic: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2492926
[ 5 ] Bug #2493524 - CVE-2026-39835 restic: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493524
[ 6 ] Bug #2494239 - CVE-2026-27145 restic: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494239
[ 7 ] Bug #2494460 - CVE-2026-39833 restic: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494460
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c87cc5b948' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new