Fedora 43 Update: chromium-150.0.7871.186-1.fc43
Fedora 43 Update: restic-0.19.1-1.fc43
Fedora 43 Update: kronosnet-1.35-1.fc43
Fedora 43 Update: btrbk-0.32.7-1.fc43
Fedora 43 Update: gpsd-3.26.1-7.fc43
Fedora 44 Update: chromium-150.0.7871.186-1.fc44
Fedora 44 Update: kronosnet-1.35-1.fc44
Fedora 44 Update: restic-0.19.1-1.fc44
[SECURITY] Fedora 43 Update: chromium-150.0.7871.186-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8a09a7af63
2026-07-29 01:08:23.879814+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 43
Version : 150.0.7871.186
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Than Ngo [than@redhat.com] - 150.0.7871.186-1
- Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506679 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506679
[ 2 ] Bug #2506680 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506680
[ 3 ] Bug #2506681 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506681
[ 4 ] Bug #2506682 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506682
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8a09a7af63' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: restic-0.19.1-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a006788209
2026-07-29 01:08:23.879759+00:00
--------------------------------------------------------------------------------
Name : restic
Product : Fedora 43
Version : 0.19.1
Release : 1.fc43
URL : https://github.com/restic/restic
Summary : Fast, secure, efficient backup program
Description :
Fast, secure, efficient backup program.
restic supports the following backends for storing backups natively:
* Local directory
* sftp server (via SSH)
* HTTP REST server (protocol, rest-server)
* Amazon S3 (either from Amazon or using the Minio server)
* OpenStack Swift
* BackBlaze B2
* Microsoft Azure Blob Storage
* Google Cloud Storage
* And many other services via the rclone Backend
--------------------------------------------------------------------------------
Update Information:
Update to 0.19.1
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Packit [hello@packit.dev] - 0.19.1-1
- Update to 0.19.1 upstream release
- Resolves: rhbz#2497130
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489947 - CVE-2026-39828 restic: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489947
[ 2 ] Bug #2490058 - CVE-2026-39829 restic: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490058
[ 3 ] Bug #2490417 - CVE-2026-39830 restic: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490417
[ 4 ] Bug #2492926 - CVE-2026-49980 restic: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2492926
[ 5 ] Bug #2493524 - CVE-2026-39835 restic: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493524
[ 6 ] Bug #2494239 - CVE-2026-27145 restic: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494239
[ 7 ] Bug #2494460 - CVE-2026-39833 restic: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494460
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a006788209' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: kronosnet-1.35-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-56568b6fe8
2026-07-29 01:08:23.879762+00:00
--------------------------------------------------------------------------------
Name : kronosnet
Product : Fedora 43
Version : 1.35
Release : 1.fc43
URL : https://kronosnet.org
Summary : Multipoint-to-Multipoint VPN daemon
Description :
The kronosnet source
--------------------------------------------------------------------------------
Update Information:
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic
configuration changes. Wipe cryptographic keys with explicit_bzero() before
freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves
rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on
unencrypted dynamic links. Validate source address against claimed link_id and
enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via
malformed network packet defragmentation. Validate fragment sequence numbers
before accessing defragmentation buffers. (Resolves rhbz#2500864)
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Fabio M. Di Nitto [fdinitto@redhat.com] - 1.35-1
- New upstream release
- CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
- CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
- CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
- tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets
- libnozzle: Introduce test macros similar to libknet
- docs: convert README to markdown format
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-56568b6fe8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: btrbk-0.32.7-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1528cb06a7
2026-07-29 01:08:23.879755+00:00
--------------------------------------------------------------------------------
Name : btrbk
Product : Fedora 43
Version : 0.32.7
Release : 1.fc43
URL : https://digint.ch/btrbk/
Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes
Description :
Backup tool for btrfs sub-volumes, using a configuration file, allows
creation of backups from multiple sources to multiple destinations,
with ssh and flexible retention policy support (hourly, daily,
weekly, monthly)
--------------------------------------------------------------------------------
Update Information:
Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Juan Orti Alcaine [jortialc@redhat.com] - 0.32.7-1
- Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Sun Oct 5 2025 Juan Orti Alcaine [jortialc@redhat.com] - 0.32.6-9
- Add logrotate file (RHBZ#2385266)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2502632 - btrbk-0.32.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502632
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1528cb06a7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: gpsd-3.26.1-7.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d61fcb86ed
2026-07-29 01:08:23.879722+00:00
--------------------------------------------------------------------------------
Name : gpsd
Product : Fedora 43
Version : 3.26.1
Release : 7.fc43
URL : https://gpsd.gitlab.io/gpsd/index.html
Summary : Service daemon for mediating access to a GPS
Description :
gpsd is a service daemon that mediates access to a GPS sensor
connected to the host computer by serial or USB interface, making its
data on the location/course/velocity of the sensor available to be
queried on TCP port 2947 of the host computer. With gpsd, multiple
GPS client applications (such as navigational and war-driving software)
can share access to a GPS without contention or loss of data. Also,
gpsd responds to queries with a format that is substantially easier to
parse than NMEA 0183.
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2026-58459
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 13 2026 Miroslav Lichvar [mlichvar@redhat.com] - 1:3.26.1-7
- fix command injection in gpsprof (CVE-2026-58459)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2498940 - CVE-2026-58459 gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498940
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d61fcb86ed' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: chromium-150.0.7871.186-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e48156418f
2026-07-29 00:59:33.776051+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 44
Version : 150.0.7871.186
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Than Ngo [than@redhat.com] - 150.0.7871.186-1
- Update to 150.0.7871.186
* CVE-2026-16807: Out of bounds write in Codecs
* CVE-2026-16806: Use after free in WebMCP
* CVE-2026-16805: Use after free in Blink
* CVE-2026-16804: Use after free in Input
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506679 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506679
[ 2 ] Bug #2506680 - CVE-2026-16804 chromium: Google Chrome: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506680
[ 3 ] Bug #2506681 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506681
[ 4 ] Bug #2506682 - CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506682
[ 5 ] Bug #2507418 - CVE-2026-16807 chromium: Google Chrome Codecs: Sandbox escape via crafted HTML page [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507418
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e48156418f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: kronosnet-1.35-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-db53330c8f
2026-07-29 00:59:33.775989+00:00
--------------------------------------------------------------------------------
Name : kronosnet
Product : Fedora 44
Version : 1.35
Release : 1.fc44
URL : https://kronosnet.org
Summary : Multipoint-to-Multipoint VPN daemon
Description :
The kronosnet source
--------------------------------------------------------------------------------
Update Information:
CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic
configuration changes. Wipe cryptographic keys with explicit_bzero() before
freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves
rhbz#2500850)
CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on
unencrypted dynamic links. Validate source address against claimed link_id and
enable ACL by default. (Resolves rhbz#2500852)
CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via
malformed network packet defragmentation. Validate fragment sequence numbers
before accessing defragmentation buffers. (Resolves rhbz#2500864)
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Fabio M. Di Nitto [fdinitto@redhat.com] - 1.35-1
- New upstream release
- CVE-2026-15811 (LOW): encryption key exposure in memory after cryptographic configuration changes. Wipe cryptographic keys with explicit_bzero() before freeing to prevent exposure through memory disclosure vulnerabilities. (Resolves rhbz#2500850)
- CVE-2026-15812 (LOW): access control list bypass via link ID spoofing on unencrypted dynamic links. Validate source address against claimed link_id and enable ACL by default. (Resolves rhbz#2500852)
- CVE-2026-15813 (MEDIUM): memory corruption and out-of-bounds access via malformed network packet defragmentation. Validate fragment sequence numbers before accessing defragmentation buffers. (Resolves rhbz#2500864)
- tests: add coverage for connected named AF_UNIX SOCK_STREAM sockets
- libnozzle: Introduce test macros similar to libknet
- docs: convert README to markdown format
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.34-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-db53330c8f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: restic-0.19.1-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c87cc5b948
2026-07-29 00:59:33.775987+00:00
--------------------------------------------------------------------------------
Name : restic
Product : Fedora 44
Version : 0.19.1
Release : 1.fc44
URL : https://github.com/restic/restic
Summary : Fast, secure, efficient backup program
Description :
Fast, secure, efficient backup program.
restic supports the following backends for storing backups natively:
* Local directory
* sftp server (via SSH)
* HTTP REST server (protocol, rest-server)
* Amazon S3 (either from Amazon or using the Minio server)
* OpenStack Swift
* BackBlaze B2
* Microsoft Azure Blob Storage
* Google Cloud Storage
* And many other services via the rclone Backend
--------------------------------------------------------------------------------
Update Information:
Update to 0.19.1
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Packit [hello@packit.dev] - 0.19.1-1
- Update to 0.19.1 upstream release
- Resolves: rhbz#2497130
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489947 - CVE-2026-39828 restic: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489947
[ 2 ] Bug #2490058 - CVE-2026-39829 restic: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490058
[ 3 ] Bug #2490417 - CVE-2026-39830 restic: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490417
[ 4 ] Bug #2492926 - CVE-2026-49980 restic: Rclone: Remote Code Execution via unauthenticated requests when `rcd --rc-serve` is enabled [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2492926
[ 5 ] Bug #2493524 - CVE-2026-39835 restic: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493524
[ 6 ] Bug #2494239 - CVE-2026-27145 restic: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494239
[ 7 ] Bug #2494460 - CVE-2026-39833 restic: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494460
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c87cc5b948' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new