Fedora Linux 9443 Published by

Fedora 43 and Fedora 44 both received a broad security push this week, with advisories covering Chromium, Samba, PHP, Traffic Server, and the Linux kernel. The Chromium release alone ships 370 patched vulnerabilities, while server components like Samba and PHP address critical issues ranging from LDAP domain takeovers to out-of-bounds memory writes. Core system utilities including curl, coreutils, ABRT, and ImageMagick also received targeted fixes for authentication leaks, race conditions, and buffer overflows. Users can apply all approved patches immediately by running the standard DNF upgrade command with the corresponding Fedora advisory identifiers.

Fedora 44 Update: libXfont2-2.0.9-1.fc44
Fedora 44 Update: samba-4.24.5-1.fc44
Fedora 44 Update: freeipa-4.13.2-1.fc44
Fedora 44 Update: chromium-151.0.7922.71-1.fc44
Fedora 44 Update: trafficserver-10.1.4-1.fc44
Fedora 44 Update: tcpreplay-4.6.0-2.fc44
Fedora 43 Update: kernel-7.1.6-101.fc43
Fedora 43 Update: chromium-151.0.7922.71-1.fc43
Fedora 43 Update: trafficserver-10.1.4-1.fc43
Fedora 43 Update: tcpreplay-4.6.0-2.fc43
Fedora 43 Update: ImageMagick-7.1.2.27-1.fc43
Fedora 43 Update: libXfont2-2.0.9-1.fc43
Fedora 43 Update: samba-4.23.10-1.fc43
Fedora 43 Update: freeipa-4.13.2-1.fc43
Fedora 43 Update: curl-8.15.0-8.fc43
Fedora 43 Update: coreutils-9.7-10.fc43
Fedora 43 Update: abrt-2.17.9-1.fc43
Fedora 43 Update: php-8.4.24-1.fc43
Fedora 44 Update: gstreamer1-plugins-bad-free-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-plugins-good-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-rtsp-server-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-plugin-libav-1.28.6-1.fc44
Fedora 44 Update: gst-editing-services-1.28.6-1.fc44
Fedora 44 Update: python-gstreamer1-1.28.6-1.fc44
Fedora 44 Update: gst-devtools-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-plugins-ugly-free-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-plugins-base-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-doc-1.28.6-1.fc44
Fedora 44 Update: gstreamer1-1.28.6-1.fc44



[SECURITY] Fedora 44 Update: libXfont2-2.0.9-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c864897d56
2026-08-06 17:15:39.889686+00:00
--------------------------------------------------------------------------------

Name : libXfont2
Product : Fedora 44
Version : 2.0.9
Release : 1.fc44
URL : http://www.x.org
Summary : X.Org X11 libXfont2 runtime library
Description :
X.Org X11 libXfont2 runtime library

--------------------------------------------------------------------------------
Update Information:

libXfont2 2.0.9 (CVE-2026-59679, CVE-2026-44950)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Peter Hutterer [peter.hutterer@redhat.com] - 2.0.9-1
- libXfont2 2.0.9 (CVE-2026-59679, CVE-2026-44950)
* Thu Jul 23 2026 Peter Hutterer [peter.hutterer@redhat.com] - 2.0.8-3
- Disable X fontserver support. Deprecated for decades and this rules out a set
of potential vulnerabilities.
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.0.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c864897d56' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: samba-4.24.5-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-fcd4630c0d
2026-08-06 17:15:39.889663+00:00
--------------------------------------------------------------------------------

Name : samba
Product : Fedora 44
Version : 4.24.5
Release : 1.fc44
URL : https://www.samba.org
Summary : Server and Client software to interoperate with Windows machines
Description :
Samba is the standard Windows interoperability suite of programs for Linux and
Unix.

--------------------------------------------------------------------------------
Update Information:

Update to Samba 4.24.5 (and rebuild of FreeIPA)
Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Günther Deschner [gd@samba.org] - 2:4.24.5-1
- Update to Samba 4.24.5
- resolves: rhbz#2509257 - Security fix for CVE-2026-6949
- resolves: rhbz#2509266 - Security fix for CVE-2026-58218
- resolves: rhbz#2509280 - Security fix for CVE-2026-58221
- resolves: rhbz#2509502 - Security fix for CVE-2026-58222
- resolves: Security fix for CVE-2026-58216
- resolves: Security fix for CVE-2026-58224
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509257 - CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09257
[ 2 ] Bug #2509266 - CVE-2026-58218 samba: DNS signing DoS via TKEY name cache exhaustion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09266
[ 3 ] Bug #2509280 - CVE-2026-58221 samba: authenticated LDAP access to internal LDB special DNs permits domain takeover [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09280
[ 4 ] Bug #2509502 - CVE-2026-58222 samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09502
[ 5 ] Bug #2510787 - samba-4.24.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id%10787
[ 6 ] Bug #2510884 - CVE-2026-58216 samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%10884
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-fcd4630c0d' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: freeipa-4.13.2-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-fcd4630c0d
2026-08-06 17:15:39.889663+00:00
--------------------------------------------------------------------------------

Name : freeipa
Product : Fedora 44
Version : 4.13.2
Release : 1.fc44
URL : http://www.freeipa.org/
Summary : The Identity, Policy and Audit system
Description :
IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).

--------------------------------------------------------------------------------
Update Information:

Update to Samba 4.24.5 (and rebuild of FreeIPA)
Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Alexander Bokovoy [abokovoy@redhat.com] - 4.13.2-1
- FreeIPA 4.13.2
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509257 - CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509257
[ 2 ] Bug #2509266 - CVE-2026-58218 samba: DNS signing DoS via TKEY name cache exhaustion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509266
[ 3 ] Bug #2509280 - CVE-2026-58221 samba: authenticated LDAP access to internal LDB special DNs permits domain takeover [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509280
[ 4 ] Bug #2509502 - CVE-2026-58222 samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509502
[ 5 ] Bug #2510787 - samba-4.24.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2510787
[ 6 ] Bug #2510884 - CVE-2026-58216 samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510884
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-fcd4630c0d' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: chromium-151.0.7922.71-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-976bbbc661
2026-08-06 17:15:39.889658+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 44
Version : 151.0.7922.71
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

security release chromium-151.0.7922.71 includes 370 security fixes:
CVE-2026-17650 - CVE-2026-18019
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 30 2026 Than Ngo [than@redhat.com] - 151.0.7922.71-1
- Update to 151.0.7922.71
* CVE-2026-17650: Use after free in Compositing
* CVE-2026-17651: Insufficient validation of untrusted input in Dawn
* CVE-2026-17652: Use after free in Views
* CVE-2026-17653: Use after free in Skia
* CVE-2026-17654: Race in Updater
* CVE-2026-17655: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17656: Use after free in Ozone
* CVE-2026-17657: Use after free in Navigation
* CVE-2026-17658: Use after free in V8
* CVE-2026-17659: Inappropriate implementation in SiteIsolation
* CVE-2026-17660: Insufficient validation of untrusted input in Network
* CVE-2026-17661: Use after free in Loader
* CVE-2026-17662: Insufficient policy enforcement in Prefetch
* CVE-2026-17663: Insufficient validation of untrusted input in GPU
* CVE-2026-17664: Insufficient validation of untrusted input in Loader
* CVE-2026-17665: Use after free in V8
* CVE-2026-17666: Cryptographic Flaw in Enterprise
* CVE-2026-17667: Uninitialized Use in ANGLE
* CVE-2026-17668: Uninitialized Use in ANGLE
* CVE-2026-17669: Inappropriate implementation in Chrome for iOS
* CVE-2026-17670: Use after free in Views
* CVE-2026-17671: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17672: Insufficient validation of untrusted input in Chromecast
* CVE-2026-17673: Integer overflow in QUIC
* CVE-2026-17674: Inappropriate implementation in HTML
* CVE-2026-17675: Out of bounds write in ANGLE
* CVE-2026-17676: Inappropriate implementation in ANGLE
* CVE-2026-17677: Inappropriate implementation in ANGLE
* CVE-2026-17678: Out of bounds read in ANGLE
* CVE-2026-17679: Insufficient validation of untrusted input in Print Preview
* CVE-2026-17680: Heap buffer overflow in Color
* CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication
* CVE-2026-17682: Integer overflow in ANGLE
* CVE-2026-17683: Inappropriate implementation in ANGLE
* CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17685: Use after free in Autofill
* CVE-2026-17686: Insufficient validation of untrusted input in Passwords
* CVE-2026-17687: Type Confusion in ANGLE
* CVE-2026-17688: Use after free in Input
* CVE-2026-17689: Uninitialized Use in ANGLE
* CVE-2026-17690: Insufficient validation of untrusted input in PDF
* CVE-2026-17691: Out of bounds write in ANGLE
* CVE-2026-17692: Use after free in DataTransfer
* CVE-2026-17693: Inappropriate implementation in FileSystem
* CVE-2026-17694: Use after free in DOM
* CVE-2026-17695: Inappropriate implementation in ANGLE
* CVE-2026-17696: Side-channel information leakage in Media
* CVE-2026-17697: Type Confusion in ANGLE
* CVE-2026-17698: Insufficient validation of untrusted input in UI
* CVE-2026-17699: Use after free in Views
* CVE-2026-17700: Insufficient validation of untrusted input in Actor
* CVE-2026-17701: Out of bounds read in ANGLE
* CVE-2026-17702: Inappropriate implementation in Skia
* CVE-2026-17703: Policy bypass in Chrome for iOS
* CVE-2026-17704: Use after free in ANGLE
* CVE-2026-17705: Integer overflow in libxml
* CVE-2026-17706: Insufficient validation of untrusted input in Media
* CVE-2026-17707: Uninitialized Use in Media
* CVE-2026-17708: Use after free in Audio
* CVE-2026-17709: Race in Downloads
* CVE-2026-17710: Inappropriate implementation in MHTML
* CVE-2026-17711: Race in Downloads
* CVE-2026-17712: Race in Skia
* CVE-2026-17713: Insufficient validation of untrusted input in Accessibility
* CVE-2026-17714: Uninitialized Use in ANGLE
* CVE-2026-17715: Inappropriate implementation in Passwords
* CVE-2026-17716: Use after free in Updater
* CVE-2026-17717: Integer overflow in ANGLE
* CVE-2026-17718: Use after free in ANGLE
* CVE-2026-17719: Use after free in Input
* CVE-2026-17720: Insufficient policy enforcement in Passwords
* CVE-2026-17721: Out of bounds write in ANGLE
* CVE-2026-17722: Object lifecycle issue in WebView
* CVE-2026-17723: Use after free in Media
* CVE-2026-17724: Race in Chrome for iOS
* CVE-2026-17725: Type Confusion in V8
* CVE-2026-17726: Integer overflow in WebGL
* CVE-2026-17727: Out of bounds write in WebGL
* CVE-2026-17728: Inappropriate implementation in Extensions
* CVE-2026-17758: Heap buffer overflow in Dawn
* CVE-2026-17732: Inappropriate implementation in SVG
* CVE-2026-17729: Use after free in V8
* CVE-2026-17730: Side-channel information leakage in Autofill
* CVE-2026-17731: Inappropriate implementation in Autofill
* CVE-2026-17733: Inappropriate implementation in QUIC
* CVE-2026-17734: Inappropriate implementation in Autofill
* CVE-2026-17735: Insufficient validation of untrusted input in BFCache
* CVE-2026-17736: Insufficient validation of untrusted input in WebView
* CVE-2026-17737: Use after free in Bluetooth
* CVE-2026-17738: Insufficient validation of untrusted input in Payments
* CVE-2026-17739: Insufficient policy enforcement in Extensions
* CVE-2026-17740: Uninitialized Use in ANGLE
* CVE-2026-17741: Insufficient validation of untrusted input in WebView
* CVE-2026-17742: Insufficient policy enforcement in Payments
* CVE-2026-17743: Insufficient policy enforcement in ControlledFrame
* CVE-2026-17744: Inappropriate implementation in File Input
* CVE-2026-17745: Out of bounds read in Skia
* CVE-2026-17746: Use after free in GPU
* CVE-2026-17747: Insufficient validation of untrusted input in Payments
* CVE-2026-17748: Inappropriate implementation in Extensions
* CVE-2026-17749: Insufficient validation of untrusted input in Extensions
* CVE-2026-17750: Use after free in ANGLE
* CVE-2026-17751: Inappropriate implementation in AdFilter
* CVE-2026-17752: Use after free in Views
* CVE-2026-17753: Inappropriate implementation in Autofill
* CVE-2026-17754: Inappropriate implementation in Blink
* CVE-2026-17755: Incorrect security UI in Extensions
* CVE-2026-17756: Insufficient policy enforcement in Presentation
* CVE-2026-17757: Uninitialized Use in Skia
* CVE-2026-17759: Uninitialized Use in Codecs
* CVE-2026-17760: Side-channel information leakage in NoStatePrefetch
* CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17762: Inappropriate implementation in Chrome for iOS
* CVE-2026-17763: Inappropriate implementation in GPU
* CVE-2026-17764: Inappropriate implementation in FedCM
* CVE-2026-17765: Inappropriate implementation in WebProtect
* CVE-2026-17766: Insufficient validation of untrusted input in Clipboard
* CVE-2026-17767: Insufficient validation of untrusted input in WebView
* CVE-2026-17768: Insufficient validation of untrusted input in WebSockets
* CVE-2026-17769: Insufficient validation of untrusted input in Cast
* CVE-2026-17770: Out of bounds read in Media
* CVE-2026-17771: Uninitialized Use in Skia
* CVE-2026-17772: Out of bounds read in WebGL
* CVE-2026-17773: Insufficient validation of untrusted input in Cast
* CVE-2026-17774: Insufficient validation of untrusted input in Variations
* CVE-2026-17775: Inappropriate implementation in PresentationAPI
* CVE-2026-17776: Policy bypass in Receiver
* CVE-2026-17777: Inappropriate implementation in Autofill
* CVE-2026-17778: Use after free in Extensions
* CVE-2026-17779: Inappropriate implementation in Site Isolation
* CVE-2026-17780: Inappropriate implementation in Isolated Web Apps
* CVE-2026-17781: Inappropriate implementation in Extensions
* CVE-2026-17782: Incorrect security UI in Chrome for iOS
* CVE-2026-17783: Inappropriate implementation in Loader
* CVE-2026-17784: Use after free in Audio
* CVE-2026-17785: Uninitialized Use in ANGLE
* CVE-2026-17786: Insufficient validation of untrusted input in DevTools
* CVE-2026-17787: Inappropriate implementation in DevTools
* CVE-2026-17788: Inappropriate implementation in Blink
* CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17790: Uninitialized Use in ANGLE
* CVE-2026-17791: Insufficient validation of untrusted input in Payments
* CVE-2026-17792: Inappropriate implementation in Credential Management
* CVE-2026-17793: Inappropriate implementation in Messages
* CVE-2026-17794: Insufficient validation of untrusted input in Mobile
* CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia
* CVE-2026-17796: Side-channel information leakage in WebXR
* CVE-2026-17797: Inappropriate implementation in CSS
* CVE-2026-17798: Inappropriate implementation in Cast
* CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing
* CVE-2026-17800: Side-channel information leakage in MediaRecording
* CVE-2026-17801: Out of bounds memory access in ANGLE
* CVE-2026-17802: Side-channel information leakage in GPU
* CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive
* CVE-2026-17804: Use after free in Media
* CVE-2026-17805: Insufficient policy enforcement in Glic
* CVE-2026-17806: Insufficient validation of untrusted input in Extensions
* CVE-2026-17807: Use after free in V8
* CVE-2026-17808: Uninitialized Use in WebGL
* CVE-2026-17809: Insufficient validation of untrusted input in Extensions
* CVE-2026-17810: Uninitialized Use in Dawn
* CVE-2026-17811: Use after free in ANGLE
* CVE-2026-17812: Inappropriate implementation in DigitalCredentials
* CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17815: Insufficient policy enforcement in GuestView
* CVE-2026-17816: Inappropriate implementation in Speech
* CVE-2026-17817: Inappropriate implementation in ReportingAndNEL
* CVE-2026-17818: Inappropriate implementation in Network
* CVE-2026-17819: Inappropriate implementation in WebAppInstalls
* CVE-2026-17820: Insufficient policy enforcement in Autofill
* CVE-2026-17821: Insufficient policy enforcement in Extensions
* CVE-2026-17822: Inappropriate implementation in Chrome for iOS
* CVE-2026-17823: Insufficient policy enforcement in WebXR
* CVE-2026-17824: Insufficient policy enforcement in ServiceWorker
* CVE-2026-17825: Insufficient policy enforcement in Passwords
* CVE-2026-17826: Inappropriate implementation in Chrome for iOS
* CVE-2026-17827: Inappropriate implementation in CSS
* CVE-2026-17828: Inappropriate implementation in Chrome for iOS
* CVE-2026-17829: Insufficient policy enforcement in Passwords
* CVE-2026-17830: Inappropriate implementation in Chrome for iOS
* CVE-2026-17831: Insufficient validation of untrusted input in Passwords
* CVE-2026-17832: Use after free in ANGLE
* CVE-2026-17833: Inappropriate implementation in Passwords
* CVE-2026-17834: Inappropriate implementation in Passwords
* CVE-2026-17835: Inappropriate implementation in Chrome for iOS
* CVE-2026-17836: Use after free in V8
* CVE-2026-17837: Insufficient validation of untrusted input in DevTools
* CVE-2026-17838: Incorrect security UI in Chrome for iOS
* CVE-2026-17839: Inappropriate implementation in Chrome for iOS
* CVE-2026-17840: Incorrect security UI in Passwords
* CVE-2026-17841: Race in Chrome for iOS
* CVE-2026-17842: Inappropriate implementation in Chrome for iOS
* CVE-2026-17843: Inappropriate implementation in CSS
* CVE-2026-17844: Insufficient validation of untrusted input in Cast
* CVE-2026-17845: Inappropriate implementation in CSS
* CVE-2026-17846: Inappropriate implementation in Media
* CVE-2026-17847: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17848: Insufficient validation of untrusted input in Codecs
* CVE-2026-17849: Inappropriate implementation in Chrome for iOS
* CVE-2026-17850: Inappropriate implementation in Permissions
* CVE-2026-17851: Side-channel information leakage in Autofill
* CVE-2026-17852: Inappropriate implementation in Media Router
* CVE-2026-17853: Inappropriate implementation in DevTools
* CVE-2026-17854: Insufficient policy enforcement in WebMCP
* CVE-2026-17855: Race in DevTools
* CVE-2026-17856: Inappropriate implementation in Network
* CVE-2026-17857: Inappropriate implementation in Network
* CVE-2026-17858: Uninitialized Use in WebNN
* CVE-2026-17859: Side-channel information leakage in Favicons
* CVE-2026-17860: Insufficient validation of untrusted input in Mobile
* CVE-2026-17861: Insufficient validation of untrusted input in Updater
* CVE-2026-17862: Use after free in Tracing
* CVE-2026-17863: Inappropriate implementation in Browser
* CVE-2026-17864: Inappropriate implementation in Updater
* CVE-2026-17865: Inappropriate implementation in Crypto
* CVE-2026-17866: Type Confusion in Tab
* CVE-2026-17867: Insufficient validation of untrusted input in Dawn
* CVE-2026-17868: Insufficient policy enforcement in USB
* CVE-2026-17869: Out of bounds read in WebXR
* CVE-2026-17870: Insufficient validation of untrusted input in Cast
* CVE-2026-17871: Inappropriate implementation in Passwords
* CVE-2026-17872: Cryptographic Flaw in WebAppInstalls
* CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-17874: Inappropriate implementation in Chrome for iOS
* CVE-2026-17875: Use after free in PDFium
* CVE-2026-17876: Inappropriate implementation in Payments
* CVE-2026-17877: Inappropriate implementation in Chromoting
* CVE-2026-17878: Inappropriate implementation in CSS
* CVE-2026-17879: Inappropriate implementation in Autofill
* CVE-2026-17880: Inappropriate implementation in Autofill
* CVE-2026-17881: Use after free in WebXR
* CVE-2026-17882: Policy bypass in Extensions
* CVE-2026-17883: Inappropriate implementation in Headless
* CVE-2026-17884: Object lifecycle issue in WebRTC
* CVE-2026-17885: Inappropriate implementation in Paint
* CVE-2026-17886: Use after free in Enterprise
* CVE-2026-17887: Use after free in TabStrip
* CVE-2026-17888: Insufficient validation of untrusted input in WebUI
* CVE-2026-17889: Uninitialized Use in WebXR
* CVE-2026-17890: Insufficient validation of untrusted input in DevTools
* CVE-2026-17891: Use after free in ANGLE
* CVE-2026-17892: Inappropriate implementation in WebXR
* CVE-2026-17893: Insufficient validation of untrusted input in Updater
* CVE-2026-17894: Use after free in Views
* CVE-2026-17895: Inappropriate implementation in DataTransfer
* CVE-2026-17896: Use after free in DevTools
* CVE-2026-17897: Inappropriate implementation in ORB
* CVE-2026-17898: Use after free in DevTools
* CVE-2026-17899: Insufficient policy enforcement in DevTools
* CVE-2026-17900: Inappropriate implementation in Enterprise
* CVE-2026-17901: Inappropriate implementation in Sharing
* CVE-2026-17902: Inappropriate implementation in Editing
* CVE-2026-17903: Insufficient policy enforcement in Chromecast
* CVE-2026-17904: Insufficient policy enforcement in NFC
* CVE-2026-17905: Inappropriate implementation in SurfaceCapture
* CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth
* CVE-2026-17907: Side-channel information leakage in Network
* CVE-2026-17908: Insufficient validation of untrusted input in Printing
* CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps
* CVE-2026-17910: Insufficient policy enforcement in NFC
* CVE-2026-17911: Insufficient policy enforcement in SVG
* CVE-2026-17912: Inappropriate implementation in Chrome for iOS
* CVE-2026-17913: Inappropriate implementation in Chrome for iOS
* CVE-2026-17914: Side-channel information leakage in Skia
* CVE-2026-17915: Inappropriate implementation in WebView
* CVE-2026-17916: Insufficient policy enforcement in Settings
* CVE-2026-17917: Policy bypass in Chrome for iOS
* CVE-2026-17918: Use after free in Sync
* CVE-2026-17919: Insufficient policy enforcement in Enterprise
* CVE-2026-17920: Use after free in V8
* CVE-2026-17921: Insufficient validation of untrusted input in Navigation
* CVE-2026-17922: Inappropriate implementation in Enterprise
* CVE-2026-17923: Policy bypass in Enterprise
* CVE-2026-17924: Use after free in DNS
* CVE-2026-17925: Inappropriate implementation in Cast
* CVE-2026-17926: Insufficient validation of untrusted input in DevTools
* CVE-2026-17927: Insufficient policy enforcement in DevTools
* CVE-2026-17928: Inappropriate implementation in DataTransfer
* CVE-2026-17929: Insufficient validation of untrusted input in DevTools
* CVE-2026-17930: Insufficient validation of untrusted input in Extensions
* CVE-2026-17931: Inappropriate implementation in DevTools
* CVE-2026-17932: Use after free in DataTransfer
* CVE-2026-17933: Inappropriate implementation in DOMStorage
* CVE-2026-17934: Insufficient validation of untrusted input in DevTools
* CVE-2026-17935: Heap buffer overflow in Codecs
* CVE-2026-17936: Inappropriate implementation in DevTools
* CVE-2026-17937: Inappropriate implementation in DevTools
* CVE-2026-17938: Inappropriate implementation in FullScreen
* CVE-2026-17939: Inappropriate implementation in Passwords
* CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture
* CVE-2026-17941: Inappropriate implementation in Chrome for iOS
* CVE-2026-17942: Side-channel information leakage in SVG
* CVE-2026-17943: Inappropriate implementation in Parser
* CVE-2026-17944: Inappropriate implementation in Chrome for iOS
* CVE-2026-17945: Inappropriate implementation in Navigation
* CVE-2026-17946: Uninitialized Use in Dawn
* CVE-2026-17947: Use after free in WebSockets
* CVE-2026-17948: Type Confusion in V8
* CVE-2026-17949: Uninitialized Use in GPU
* CVE-2026-17950: Policy bypass in Safebrowsing
* CVE-2026-17951: Heap buffer overflow in WebRTC
* CVE-2026-17952: Inappropriate implementation in V8
* CVE-2026-17953: Insufficient policy enforcement in WebView
* CVE-2026-17954: Policy bypass in MHTML
* CVE-2026-17955: Insufficient validation of untrusted input in Payments
* CVE-2026-17956: Inappropriate implementation in Scheduling
* CVE-2026-17957: Inappropriate implementation in CORS
* CVE-2026-17958: Inappropriate implementation in Views
* CVE-2026-17959: Inappropriate implementation in Network
* CVE-2026-17960: Inappropriate implementation in Chrome for iOS
* CVE-2026-17961: Inappropriate implementation in Session
* CVE-2026-17962: Inappropriate implementation in Blink
* CVE-2026-17963: Inappropriate implementation in SVG
* CVE-2026-17964: Incorrect security UI in UI
* CVE-2026-17965: Incorrect security UI in Chrome for iOS
* CVE-2026-17966: Inappropriate implementation in Views
* CVE-2026-17967: Use after free in Chrome for iOS
* CVE-2026-17968: Uninitialized Use in WebXR
* CVE-2026-17969: Inappropriate implementation in Passwords
* CVE-2026-17970: Insufficient validation of untrusted input in Passwords
* CVE-2026-17971: Inappropriate implementation in Frame
* CVE-2026-17972: Inappropriate implementation in Chrome for iOS
* CVE-2026-17973: Inappropriate implementation in Views
* CVE-2026-17974: Insufficient policy enforcement in DevTools
* CVE-2026-17975: Inappropriate implementation in IME
* CVE-2026-17976: Policy bypass in Extensions
* CVE-2026-17977: Policy bypass in CSS
* CVE-2026-17978: Side-channel information leakage in WebCodecs
* CVE-2026-17979: Race in V8
* CVE-2026-17980: Inappropriate implementation in UI
* CVE-2026-17981: Inappropriate implementation in Blink
* CVE-2026-17982: Insufficient validation of untrusted input in Cast
* CVE-2026-17983: Incorrect security UI in Global Media Controls
* CVE-2026-17984: Inappropriate implementation in Browser
* CVE-2026-17985: Insufficient policy enforcement in Speech
* CVE-2026-17986: Insufficient policy enforcement in Bluetooth
* CVE-2026-17987: Insufficient validation of untrusted input in Notifications
* CVE-2026-17988: Insufficient validation of untrusted input in Navigation
* CVE-2026-17989: Type Confusion in V8
* CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn
* CVE-2026-17991: Insufficient validation of untrusted input in AI
* CVE-2026-17992: Uninitialized Use in Skia
* CVE-2026-17993: Race in Updater
* CVE-2026-17994: Inappropriate implementation in Media
* CVE-2026-17995: Out of bounds read in Dawn
* CVE-2026-17996: Inappropriate implementation in Browser
* CVE-2026-17997: Inappropriate implementation in Passwords
* CVE-2026-17998: Incorrect security UI in Extensions
* CVE-2026-17999: Incorrect security UI in PictureInPicture
* CVE-2026-18000: Insufficient policy enforcement in USB
* CVE-2026-18001: Inappropriate implementation in WebGL
* CVE-2026-18002: Insufficient validation of untrusted input in Google Lens
* CVE-2026-18003: Inappropriate implementation in Chrome for iOS
* CVE-2026-18004: Insufficient policy enforcement in Speech
* CVE-2026-18005: Inappropriate implementation in WebXR
* CVE-2026-18006: Inappropriate implementation in Google Lens
* CVE-2026-18007: Inappropriate implementation in Input
* CVE-2026-18008: Inappropriate implementation in Settings
* CVE-2026-18009: Insufficient validation of untrusted input in Passwords
* CVE-2026-18010: Inappropriate implementation in Passwords
* CVE-2026-18011: Inappropriate implementation in Chrome for iOS
* CVE-2026-18012: Use after free in PDFium
* CVE-2026-18013: Inappropriate implementation in Chrome for iOS
* CVE-2026-18014: Insufficient validation of untrusted input in DevTools
* CVE-2026-18015: Inappropriate implementation in Tint
* CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-18017: Use after free in Dawn
* CVE-2026-18018: Inappropriate implementation in Updater
* CVE-2026-18019: Side-channel information leakage in Media
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509039 - CVE-2026-17735 chromium: Chromium: Sandbox escape via crafted HTML page in BFCache [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509039
[ 2 ] Bug #2509040 - CVE-2026-17735 chromium: Chromium: Sandbox escape via crafted HTML page in BFCache [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509040
[ 3 ] Bug #2509041 - CVE-2026-17928 chromium: Chromium: Cross-origin data leakage via DataTransfer [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509041
[ 4 ] Bug #2509042 - CVE-2026-17928 chromium: Chromium: Cross-origin data leakage via DataTransfer [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509042
[ 5 ] Bug #2509043 - CVE-2026-17858 chromium: chromium-browser: Uninitialized Use in WebNN [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509043
[ 6 ] Bug #2509044 - CVE-2026-17858 chromium: chromium-browser: Uninitialized Use in WebNN [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509044
[ 7 ] Bug #2509045 - CVE-2026-17865 chromium: chromium-browser: Inappropriate implementation in Crypto [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509045
[ 8 ] Bug #2509046 - CVE-2026-17865 chromium: chromium-browser: Inappropriate implementation in Crypto [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509046
[ 9 ] Bug #2509047 - CVE-2026-17823 chromium: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509047
[ 10 ] Bug #2509048 - CVE-2026-17823 chromium: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509048
[ 11 ] Bug #2509049 - CVE-2026-17778 chromium: Google Chrome: Arbitrary code execution via crafted Chrome Extension [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509049
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-976bbbc661' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: trafficserver-10.1.4-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-5bec7441bb
2026-08-06 17:15:39.889640+00:00
--------------------------------------------------------------------------------

Name : trafficserver
Product : Fedora 44
Version : 10.1.4
Release : 1.fc44
URL : https://trafficserver.apache.org/
Summary : Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server
Description :
Traffic Server is a high-performance building block for cloud services.
It's more than just a caching proxy server; it also has support for
plugins to build large scale web applications. Key features:

Caching - Improve your response time, while reducing server load and
bandwidth needs by caching and reusing frequently-requested web pages,
images, and web service calls.

Proxying - Easily add keep-alive, filter or anonymize content
requests, or add load balancing by adding a proxy layer.

Fast - Scales well on modern SMP hardware, handling 10s of thousands
of requests per second.

Extensible - APIs to write your own plug-ins to do anything from
modifying HTTP headers to handling ESI requests to writing your own
cache algorithm.

Proven - Handling over 400TB a day at Yahoo! both as forward and
reverse proxies, Apache Traffic Server is battle hardened.

--------------------------------------------------------------------------------
Update Information:

Update to upstream 10.1.4
Resolves:
- CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy
bypass
- CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not
stripped
- CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected,
allowing request smuggling
- CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the
server
- CVE-2026-58154 - Memory-safety errors in MIME and header parsing
- CVE-2026-58155 - Header-name length truncation enables header aliasing and
request smuggling
- CVE-2026-58157 - Improper server-session reuse can expose data across client
connections
- CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the
server
- CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts
framework
- CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap,
allowing memory exhaustion
- CVE-2026-24033 - Chunked extension quoted-string parsing allows request
smuggling
- CVE-2026-33930 - Buffer overflow via Host field that has a long string value
- CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing
host-SNI policy bypass
- CVE-2026-57834 - Malformed chunked message body allows request smuggling
- CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt
memory
- CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to
clients unsafely
- CVE-2026-58156 - URL and port parsing errors allow access-control bypass
- CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack
overflow
- CVE-2026-58159 - Listener and ACL handling allow access-control bypass
- CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses
- CVE-2026-58162 - Certifier plugin trusts client SNI when generating
certificates
- CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state
or crash the server
- CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-
after-free
- CVE-2026-58175 - HostDB SRV handling leaks memory
- CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side
request forgery
- CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input
- CVE-2026-58180 - txn_box plugin overflows the stack from attacker input
- CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or
crash
- CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors
- CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input
- CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory
- CVE-2026-58185 - Use-after-free in the intercept plugin
- CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded
responses
- CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service
- CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental
plugins
- CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF
amplification
- CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed
header encode
- CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without
certificate re-verification
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 28 2026 Jered Floyd [jered@redhat.com] - 10.1.4-1
- Update to upstream 10.1.4
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2508381 - CVE-2026-33930 trafficserver: Apache Traffic Server: Denial of Service via over-long Host header [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508381
[ 2 ] Bug #2508532 - CVE-2026-58159 trafficserver: listener and ACL handling allow access-control bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508532
[ 3 ] Bug #2508534 - CVE-2026-58180 trafficserver: txn_box plugin overflows the stack from attacker input [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508534
[ 4 ] Bug #2508535 - CVE-2026-58178 trafficserver: ESI plugin allows uncontrolled recursion and server-side request forgery [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508535
[ 5 ] Bug #2508537 - CVE-2026-58162 trafficserver: certifier plugin trusts client SNI when generating certificates [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508537
[ 6 ] Bug #2508540 - CVE-2026-58188 trafficserver: memory-safety and limit-bypass errors across experimental plugins [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508540
[ 7 ] Bug #2508541 - CVE-2026-58175 trafficserver: HostDB SRV handling leaks memory [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508541
[ 8 ] Bug #2508544 - CVE-2026-65100 trafficserver: HPACK encoder desynchronizes from the decoder after a failed header encode [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508544
[ 9 ] Bug #2508545 - CVE-2026-58177 trafficserver: memory-safety and path-traversal errors in the Cripts framework [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2508545
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-5bec7441bb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: tcpreplay-4.6.0-2.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7bf4deefef
2026-08-06 17:15:39.889588+00:00
--------------------------------------------------------------------------------

Name : tcpreplay
Product : Fedora 44
Version : 4.6.0
Release : 2.fc44
URL : http://tcpreplay.appneta.com/
Summary : Replay captured network traffic
Description :
Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay
supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep
a tool to pre-process capture files to allow increased performance under
certain conditions as well as capinfo which provides basic information about
capture files.

--------------------------------------------------------------------------------
Update Information:

Release notes:
https://github.com/appneta/tcpreplay/releases/tag/v4.5.3
https://github.com/appneta/tcpreplay/releases/tag/v4.5.4
https://github.com/appneta/tcpreplay/releases/tag/v4.5.5
https://github.com/appneta/tcpreplay/releases/tag/v4.6.0
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 28 2026 Bojan Smojver [bojan@rexursive.com] - 4.6.0-2
- Add -pthreads for EPEL8/9
* Tue Jul 28 2026 Bojan Smojver [bojan@rexursive.com] - 4.6.0-1
- Update to 4.6.0
- Add -devel and -static for headers, pkgconfig file and static library
* Fri Jul 24 2026 Bojan Smojver - 4.5.5-1
- Update to 4.5.5
* Thu Jul 23 2026 Bojan Smojver - 4.5.4-1
- Update to 4.5.4
* Mon Jul 20 2026 Bojan Smojver - 4.5.3-1
- Update to 4.5.3
* Fri Jul 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.5.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7bf4deefef' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: kernel-7.1.6-101.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-edefd5c974
2026-08-06 16:46:14.138315+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 43
Version : 7.1.6
Release : 101.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.6 stable kernel updates contain a number of important fixes across the
tree. We are now specifying all kernel updates as security because upstream
will assign CVEs, but we will not know what those are until a bit after this
update ships.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.6-1]
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
* Mon Aug 3 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.6-1]
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
* Mon Aug 3 2026 Augusto Caringi [acaringi@redhat.com] [7.1.6-0]
- New config for stable (Justin M. Forbes)
- acpi: battery: Sanitise model_number by dropping unprintable characters (Kate Hsuan)
- redhat: configs: Enable AMD ISP4 MIPI camera solution (Kate Hsuan)
- media: platform: amd: add DRM_AMDGPU dependency (Arnd Bergmann)
- media: platform: amd: isp4: drop stale list reinit before free (Bin Du)
- media: platform: amd: isp4 debug fs logging and more descriptive errors (Bin Du)
- media: platform: amd: isp4 video node and buffers handling added (Bin Du)
- media: platform: amd: isp4 subdev and firmware loading handling added (Bin Du)
- media: platform: amd: Add isp4 fw and hw interface (Bin Du)
- media: platform: amd: low level support for isp4 firmware (Bin Du)
- media: platform: amd: Introduce amd isp4 capture driver (Bin Du)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi)
- Linux v7.1.6
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-edefd5c974' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: chromium-151.0.7922.71-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2c6aeb3b06
2026-08-06 16:46:14.138310+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 43
Version : 151.0.7922.71
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

security release chromium-151.0.7922.71 includes 370 security fixes:
CVE-2026-17650 - CVE-2026-18019
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 30 2026 Than Ngo [than@redhat.com] - 151.0.7922.71-1
- Update to 151.0.7922.71
* CVE-2026-17650: Use after free in Compositing
* CVE-2026-17651: Insufficient validation of untrusted input in Dawn
* CVE-2026-17652: Use after free in Views
* CVE-2026-17653: Use after free in Skia
* CVE-2026-17654: Race in Updater
* CVE-2026-17655: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17656: Use after free in Ozone
* CVE-2026-17657: Use after free in Navigation
* CVE-2026-17658: Use after free in V8
* CVE-2026-17659: Inappropriate implementation in SiteIsolation
* CVE-2026-17660: Insufficient validation of untrusted input in Network
* CVE-2026-17661: Use after free in Loader
* CVE-2026-17662: Insufficient policy enforcement in Prefetch
* CVE-2026-17663: Insufficient validation of untrusted input in GPU
* CVE-2026-17664: Insufficient validation of untrusted input in Loader
* CVE-2026-17665: Use after free in V8
* CVE-2026-17666: Cryptographic Flaw in Enterprise
* CVE-2026-17667: Uninitialized Use in ANGLE
* CVE-2026-17668: Uninitialized Use in ANGLE
* CVE-2026-17669: Inappropriate implementation in Chrome for iOS
* CVE-2026-17670: Use after free in Views
* CVE-2026-17671: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17672: Insufficient validation of untrusted input in Chromecast
* CVE-2026-17673: Integer overflow in QUIC
* CVE-2026-17674: Inappropriate implementation in HTML
* CVE-2026-17675: Out of bounds write in ANGLE
* CVE-2026-17676: Inappropriate implementation in ANGLE
* CVE-2026-17677: Inappropriate implementation in ANGLE
* CVE-2026-17678: Out of bounds read in ANGLE
* CVE-2026-17679: Insufficient validation of untrusted input in Print Preview
* CVE-2026-17680: Heap buffer overflow in Color
* CVE-2026-17681: Insufficient validation of untrusted input in Web Authentication
* CVE-2026-17682: Integer overflow in ANGLE
* CVE-2026-17683: Inappropriate implementation in ANGLE
* CVE-2026-17684: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17685: Use after free in Autofill
* CVE-2026-17686: Insufficient validation of untrusted input in Passwords
* CVE-2026-17687: Type Confusion in ANGLE
* CVE-2026-17688: Use after free in Input
* CVE-2026-17689: Uninitialized Use in ANGLE
* CVE-2026-17690: Insufficient validation of untrusted input in PDF
* CVE-2026-17691: Out of bounds write in ANGLE
* CVE-2026-17692: Use after free in DataTransfer
* CVE-2026-17693: Inappropriate implementation in FileSystem
* CVE-2026-17694: Use after free in DOM
* CVE-2026-17695: Inappropriate implementation in ANGLE
* CVE-2026-17696: Side-channel information leakage in Media
* CVE-2026-17697: Type Confusion in ANGLE
* CVE-2026-17698: Insufficient validation of untrusted input in UI
* CVE-2026-17699: Use after free in Views
* CVE-2026-17700: Insufficient validation of untrusted input in Actor
* CVE-2026-17701: Out of bounds read in ANGLE
* CVE-2026-17702: Inappropriate implementation in Skia
* CVE-2026-17703: Policy bypass in Chrome for iOS
* CVE-2026-17704: Use after free in ANGLE
* CVE-2026-17705: Integer overflow in libxml
* CVE-2026-17706: Insufficient validation of untrusted input in Media
* CVE-2026-17707: Uninitialized Use in Media
* CVE-2026-17708: Use after free in Audio
* CVE-2026-17709: Race in Downloads
* CVE-2026-17710: Inappropriate implementation in MHTML
* CVE-2026-17711: Race in Downloads
* CVE-2026-17712: Race in Skia
* CVE-2026-17713: Insufficient validation of untrusted input in Accessibility
* CVE-2026-17714: Uninitialized Use in ANGLE
* CVE-2026-17715: Inappropriate implementation in Passwords
* CVE-2026-17716: Use after free in Updater
* CVE-2026-17717: Integer overflow in ANGLE
* CVE-2026-17718: Use after free in ANGLE
* CVE-2026-17719: Use after free in Input
* CVE-2026-17720: Insufficient policy enforcement in Passwords
* CVE-2026-17721: Out of bounds write in ANGLE
* CVE-2026-17722: Object lifecycle issue in WebView
* CVE-2026-17723: Use after free in Media
* CVE-2026-17724: Race in Chrome for iOS
* CVE-2026-17725: Type Confusion in V8
* CVE-2026-17726: Integer overflow in WebGL
* CVE-2026-17727: Out of bounds write in WebGL
* CVE-2026-17728: Inappropriate implementation in Extensions
* CVE-2026-17758: Heap buffer overflow in Dawn
* CVE-2026-17732: Inappropriate implementation in SVG
* CVE-2026-17729: Use after free in V8
* CVE-2026-17730: Side-channel information leakage in Autofill
* CVE-2026-17731: Inappropriate implementation in Autofill
* CVE-2026-17733: Inappropriate implementation in QUIC
* CVE-2026-17734: Inappropriate implementation in Autofill
* CVE-2026-17735: Insufficient validation of untrusted input in BFCache
* CVE-2026-17736: Insufficient validation of untrusted input in WebView
* CVE-2026-17737: Use after free in Bluetooth
* CVE-2026-17738: Insufficient validation of untrusted input in Payments
* CVE-2026-17739: Insufficient policy enforcement in Extensions
* CVE-2026-17740: Uninitialized Use in ANGLE
* CVE-2026-17741: Insufficient validation of untrusted input in WebView
* CVE-2026-17742: Insufficient policy enforcement in Payments
* CVE-2026-17743: Insufficient policy enforcement in ControlledFrame
* CVE-2026-17744: Inappropriate implementation in File Input
* CVE-2026-17745: Out of bounds read in Skia
* CVE-2026-17746: Use after free in GPU
* CVE-2026-17747: Insufficient validation of untrusted input in Payments
* CVE-2026-17748: Inappropriate implementation in Extensions
* CVE-2026-17749: Insufficient validation of untrusted input in Extensions
* CVE-2026-17750: Use after free in ANGLE
* CVE-2026-17751: Inappropriate implementation in AdFilter
* CVE-2026-17752: Use after free in Views
* CVE-2026-17753: Inappropriate implementation in Autofill
* CVE-2026-17754: Inappropriate implementation in Blink
* CVE-2026-17755: Incorrect security UI in Extensions
* CVE-2026-17756: Insufficient policy enforcement in Presentation
* CVE-2026-17757: Uninitialized Use in Skia
* CVE-2026-17759: Uninitialized Use in Codecs
* CVE-2026-17760: Side-channel information leakage in NoStatePrefetch
* CVE-2026-17761: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17762: Inappropriate implementation in Chrome for iOS
* CVE-2026-17763: Inappropriate implementation in GPU
* CVE-2026-17764: Inappropriate implementation in FedCM
* CVE-2026-17765: Inappropriate implementation in WebProtect
* CVE-2026-17766: Insufficient validation of untrusted input in Clipboard
* CVE-2026-17767: Insufficient validation of untrusted input in WebView
* CVE-2026-17768: Insufficient validation of untrusted input in WebSockets
* CVE-2026-17769: Insufficient validation of untrusted input in Cast
* CVE-2026-17770: Out of bounds read in Media
* CVE-2026-17771: Uninitialized Use in Skia
* CVE-2026-17772: Out of bounds read in WebGL
* CVE-2026-17773: Insufficient validation of untrusted input in Cast
* CVE-2026-17774: Insufficient validation of untrusted input in Variations
* CVE-2026-17775: Inappropriate implementation in PresentationAPI
* CVE-2026-17776: Policy bypass in Receiver
* CVE-2026-17777: Inappropriate implementation in Autofill
* CVE-2026-17778: Use after free in Extensions
* CVE-2026-17779: Inappropriate implementation in Site Isolation
* CVE-2026-17780: Inappropriate implementation in Isolated Web Apps
* CVE-2026-17781: Inappropriate implementation in Extensions
* CVE-2026-17782: Incorrect security UI in Chrome for iOS
* CVE-2026-17783: Inappropriate implementation in Loader
* CVE-2026-17784: Use after free in Audio
* CVE-2026-17785: Uninitialized Use in ANGLE
* CVE-2026-17786: Insufficient validation of untrusted input in DevTools
* CVE-2026-17787: Inappropriate implementation in DevTools
* CVE-2026-17788: Inappropriate implementation in Blink
* CVE-2026-17789: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17790: Uninitialized Use in ANGLE
* CVE-2026-17791: Insufficient validation of untrusted input in Payments
* CVE-2026-17792: Inappropriate implementation in Credential Management
* CVE-2026-17793: Inappropriate implementation in Messages
* CVE-2026-17794: Insufficient validation of untrusted input in Mobile
* CVE-2026-17795: Insufficient validation of untrusted input in GetUserMedia
* CVE-2026-17796: Side-channel information leakage in WebXR
* CVE-2026-17797: Inappropriate implementation in CSS
* CVE-2026-17798: Inappropriate implementation in Cast
* CVE-2026-17799: Insufficient validation of untrusted input in Safe Browsing
* CVE-2026-17800: Side-channel information leakage in MediaRecording
* CVE-2026-17801: Out of bounds memory access in ANGLE
* CVE-2026-17802: Side-channel information leakage in GPU
* CVE-2026-17803: Insufficient validation of untrusted input in Save to Drive
* CVE-2026-17804: Use after free in Media
* CVE-2026-17805: Insufficient policy enforcement in Glic
* CVE-2026-17806: Insufficient validation of untrusted input in Extensions
* CVE-2026-17807: Use after free in V8
* CVE-2026-17808: Uninitialized Use in WebGL
* CVE-2026-17809: Insufficient validation of untrusted input in Extensions
* CVE-2026-17810: Uninitialized Use in Dawn
* CVE-2026-17811: Use after free in ANGLE
* CVE-2026-17812: Inappropriate implementation in DigitalCredentials
* CVE-2026-17813: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-17814: Insufficient validation of untrusted input in Chrome for iOS
* CVE-2026-17815: Insufficient policy enforcement in GuestView
* CVE-2026-17816: Inappropriate implementation in Speech
* CVE-2026-17817: Inappropriate implementation in ReportingAndNEL
* CVE-2026-17818: Inappropriate implementation in Network
* CVE-2026-17819: Inappropriate implementation in WebAppInstalls
* CVE-2026-17820: Insufficient policy enforcement in Autofill
* CVE-2026-17821: Insufficient policy enforcement in Extensions
* CVE-2026-17822: Inappropriate implementation in Chrome for iOS
* CVE-2026-17823: Insufficient policy enforcement in WebXR
* CVE-2026-17824: Insufficient policy enforcement in ServiceWorker
* CVE-2026-17825: Insufficient policy enforcement in Passwords
* CVE-2026-17826: Inappropriate implementation in Chrome for iOS
* CVE-2026-17827: Inappropriate implementation in CSS
* CVE-2026-17828: Inappropriate implementation in Chrome for iOS
* CVE-2026-17829: Insufficient policy enforcement in Passwords
* CVE-2026-17830: Inappropriate implementation in Chrome for iOS
* CVE-2026-17831: Insufficient validation of untrusted input in Passwords
* CVE-2026-17832: Use after free in ANGLE
* CVE-2026-17833: Inappropriate implementation in Passwords
* CVE-2026-17834: Inappropriate implementation in Passwords
* CVE-2026-17835: Inappropriate implementation in Chrome for iOS
* CVE-2026-17836: Use after free in V8
* CVE-2026-17837: Insufficient validation of untrusted input in DevTools
* CVE-2026-17838: Incorrect security UI in Chrome for iOS
* CVE-2026-17839: Inappropriate implementation in Chrome for iOS
* CVE-2026-17840: Incorrect security UI in Passwords
* CVE-2026-17841: Race in Chrome for iOS
* CVE-2026-17842: Inappropriate implementation in Chrome for iOS
* CVE-2026-17843: Inappropriate implementation in CSS
* CVE-2026-17844: Insufficient validation of untrusted input in Cast
* CVE-2026-17845: Inappropriate implementation in CSS
* CVE-2026-17846: Inappropriate implementation in Media
* CVE-2026-17847: Insufficient validation of untrusted input in ANGLE
* CVE-2026-17848: Insufficient validation of untrusted input in Codecs
* CVE-2026-17849: Inappropriate implementation in Chrome for iOS
* CVE-2026-17850: Inappropriate implementation in Permissions
* CVE-2026-17851: Side-channel information leakage in Autofill
* CVE-2026-17852: Inappropriate implementation in Media Router
* CVE-2026-17853: Inappropriate implementation in DevTools
* CVE-2026-17854: Insufficient policy enforcement in WebMCP
* CVE-2026-17855: Race in DevTools
* CVE-2026-17856: Inappropriate implementation in Network
* CVE-2026-17857: Inappropriate implementation in Network
* CVE-2026-17858: Uninitialized Use in WebNN
* CVE-2026-17859: Side-channel information leakage in Favicons
* CVE-2026-17860: Insufficient validation of untrusted input in Mobile
* CVE-2026-17861: Insufficient validation of untrusted input in Updater
* CVE-2026-17862: Use after free in Tracing
* CVE-2026-17863: Inappropriate implementation in Browser
* CVE-2026-17864: Inappropriate implementation in Updater
* CVE-2026-17865: Inappropriate implementation in Crypto
* CVE-2026-17866: Type Confusion in Tab
* CVE-2026-17867: Insufficient validation of untrusted input in Dawn
* CVE-2026-17868: Insufficient policy enforcement in USB
* CVE-2026-17869: Out of bounds read in WebXR
* CVE-2026-17870: Insufficient validation of untrusted input in Cast
* CVE-2026-17871: Inappropriate implementation in Passwords
* CVE-2026-17872: Cryptographic Flaw in WebAppInstalls
* CVE-2026-17873: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-17874: Inappropriate implementation in Chrome for iOS
* CVE-2026-17875: Use after free in PDFium
* CVE-2026-17876: Inappropriate implementation in Payments
* CVE-2026-17877: Inappropriate implementation in Chromoting
* CVE-2026-17878: Inappropriate implementation in CSS
* CVE-2026-17879: Inappropriate implementation in Autofill
* CVE-2026-17880: Inappropriate implementation in Autofill
* CVE-2026-17881: Use after free in WebXR
* CVE-2026-17882: Policy bypass in Extensions
* CVE-2026-17883: Inappropriate implementation in Headless
* CVE-2026-17884: Object lifecycle issue in WebRTC
* CVE-2026-17885: Inappropriate implementation in Paint
* CVE-2026-17886: Use after free in Enterprise
* CVE-2026-17887: Use after free in TabStrip
* CVE-2026-17888: Insufficient validation of untrusted input in WebUI
* CVE-2026-17889: Uninitialized Use in WebXR
* CVE-2026-17890: Insufficient validation of untrusted input in DevTools
* CVE-2026-17891: Use after free in ANGLE
* CVE-2026-17892: Inappropriate implementation in WebXR
* CVE-2026-17893: Insufficient validation of untrusted input in Updater
* CVE-2026-17894: Use after free in Views
* CVE-2026-17895: Inappropriate implementation in DataTransfer
* CVE-2026-17896: Use after free in DevTools
* CVE-2026-17897: Inappropriate implementation in ORB
* CVE-2026-17898: Use after free in DevTools
* CVE-2026-17899: Insufficient policy enforcement in DevTools
* CVE-2026-17900: Inappropriate implementation in Enterprise
* CVE-2026-17901: Inappropriate implementation in Sharing
* CVE-2026-17902: Inappropriate implementation in Editing
* CVE-2026-17903: Insufficient policy enforcement in Chromecast
* CVE-2026-17904: Insufficient policy enforcement in NFC
* CVE-2026-17905: Inappropriate implementation in SurfaceCapture
* CVE-2026-17906: Insufficient validation of untrusted input in Bluetooth
* CVE-2026-17907: Side-channel information leakage in Network
* CVE-2026-17908: Insufficient validation of untrusted input in Printing
* CVE-2026-17909: Insufficient validation of untrusted input in Isolated Web Apps
* CVE-2026-17910: Insufficient policy enforcement in NFC
* CVE-2026-17911: Insufficient policy enforcement in SVG
* CVE-2026-17912: Inappropriate implementation in Chrome for iOS
* CVE-2026-17913: Inappropriate implementation in Chrome for iOS
* CVE-2026-17914: Side-channel information leakage in Skia
* CVE-2026-17915: Inappropriate implementation in WebView
* CVE-2026-17916: Insufficient policy enforcement in Settings
* CVE-2026-17917: Policy bypass in Chrome for iOS
* CVE-2026-17918: Use after free in Sync
* CVE-2026-17919: Insufficient policy enforcement in Enterprise
* CVE-2026-17920: Use after free in V8
* CVE-2026-17921: Insufficient validation of untrusted input in Navigation
* CVE-2026-17922: Inappropriate implementation in Enterprise
* CVE-2026-17923: Policy bypass in Enterprise
* CVE-2026-17924: Use after free in DNS
* CVE-2026-17925: Inappropriate implementation in Cast
* CVE-2026-17926: Insufficient validation of untrusted input in DevTools
* CVE-2026-17927: Insufficient policy enforcement in DevTools
* CVE-2026-17928: Inappropriate implementation in DataTransfer
* CVE-2026-17929: Insufficient validation of untrusted input in DevTools
* CVE-2026-17930: Insufficient validation of untrusted input in Extensions
* CVE-2026-17931: Inappropriate implementation in DevTools
* CVE-2026-17932: Use after free in DataTransfer
* CVE-2026-17933: Inappropriate implementation in DOMStorage
* CVE-2026-17934: Insufficient validation of untrusted input in DevTools
* CVE-2026-17935: Heap buffer overflow in Codecs
* CVE-2026-17936: Inappropriate implementation in DevTools
* CVE-2026-17937: Inappropriate implementation in DevTools
* CVE-2026-17938: Inappropriate implementation in FullScreen
* CVE-2026-17939: Inappropriate implementation in Passwords
* CVE-2026-17940: Insufficient validation of untrusted input in Picture-in-Picture
* CVE-2026-17941: Inappropriate implementation in Chrome for iOS
* CVE-2026-17942: Side-channel information leakage in SVG
* CVE-2026-17943: Inappropriate implementation in Parser
* CVE-2026-17944: Inappropriate implementation in Chrome for iOS
* CVE-2026-17945: Inappropriate implementation in Navigation
* CVE-2026-17946: Uninitialized Use in Dawn
* CVE-2026-17947: Use after free in WebSockets
* CVE-2026-17948: Type Confusion in V8
* CVE-2026-17949: Uninitialized Use in GPU
* CVE-2026-17950: Policy bypass in Safebrowsing
* CVE-2026-17951: Heap buffer overflow in WebRTC
* CVE-2026-17952: Inappropriate implementation in V8
* CVE-2026-17953: Insufficient policy enforcement in WebView
* CVE-2026-17954: Policy bypass in MHTML
* CVE-2026-17955: Insufficient validation of untrusted input in Payments
* CVE-2026-17956: Inappropriate implementation in Scheduling
* CVE-2026-17957: Inappropriate implementation in CORS
* CVE-2026-17958: Inappropriate implementation in Views
* CVE-2026-17959: Inappropriate implementation in Network
* CVE-2026-17960: Inappropriate implementation in Chrome for iOS
* CVE-2026-17961: Inappropriate implementation in Session
* CVE-2026-17962: Inappropriate implementation in Blink
* CVE-2026-17963: Inappropriate implementation in SVG
* CVE-2026-17964: Incorrect security UI in UI
* CVE-2026-17965: Incorrect security UI in Chrome for iOS
* CVE-2026-17966: Inappropriate implementation in Views
* CVE-2026-17967: Use after free in Chrome for iOS
* CVE-2026-17968: Uninitialized Use in WebXR
* CVE-2026-17969: Inappropriate implementation in Passwords
* CVE-2026-17970: Insufficient validation of untrusted input in Passwords
* CVE-2026-17971: Inappropriate implementation in Frame
* CVE-2026-17972: Inappropriate implementation in Chrome for iOS
* CVE-2026-17973: Inappropriate implementation in Views
* CVE-2026-17974: Insufficient policy enforcement in DevTools
* CVE-2026-17975: Inappropriate implementation in IME
* CVE-2026-17976: Policy bypass in Extensions
* CVE-2026-17977: Policy bypass in CSS
* CVE-2026-17978: Side-channel information leakage in WebCodecs
* CVE-2026-17979: Race in V8
* CVE-2026-17980: Inappropriate implementation in UI
* CVE-2026-17981: Inappropriate implementation in Blink
* CVE-2026-17982: Insufficient validation of untrusted input in Cast
* CVE-2026-17983: Incorrect security UI in Global Media Controls
* CVE-2026-17984: Inappropriate implementation in Browser
* CVE-2026-17985: Insufficient policy enforcement in Speech
* CVE-2026-17986: Insufficient policy enforcement in Bluetooth
* CVE-2026-17987: Insufficient validation of untrusted input in Notifications
* CVE-2026-17988: Insufficient validation of untrusted input in Navigation
* CVE-2026-17989: Type Confusion in V8
* CVE-2026-17990: Insufficient validation of untrusted input in WebAuthn
* CVE-2026-17991: Insufficient validation of untrusted input in AI
* CVE-2026-17992: Uninitialized Use in Skia
* CVE-2026-17993: Race in Updater
* CVE-2026-17994: Inappropriate implementation in Media
* CVE-2026-17995: Out of bounds read in Dawn
* CVE-2026-17996: Inappropriate implementation in Browser
* CVE-2026-17997: Inappropriate implementation in Passwords
* CVE-2026-17998: Incorrect security UI in Extensions
* CVE-2026-17999: Incorrect security UI in PictureInPicture
* CVE-2026-18000: Insufficient policy enforcement in USB
* CVE-2026-18001: Inappropriate implementation in WebGL
* CVE-2026-18002: Insufficient validation of untrusted input in Google Lens
* CVE-2026-18003: Inappropriate implementation in Chrome for iOS
* CVE-2026-18004: Insufficient policy enforcement in Speech
* CVE-2026-18005: Inappropriate implementation in WebXR
* CVE-2026-18006: Inappropriate implementation in Google Lens
* CVE-2026-18007: Inappropriate implementation in Input
* CVE-2026-18008: Inappropriate implementation in Settings
* CVE-2026-18009: Insufficient validation of untrusted input in Passwords
* CVE-2026-18010: Inappropriate implementation in Passwords
* CVE-2026-18011: Inappropriate implementation in Chrome for iOS
* CVE-2026-18012: Use after free in PDFium
* CVE-2026-18013: Inappropriate implementation in Chrome for iOS
* CVE-2026-18014: Insufficient validation of untrusted input in DevTools
* CVE-2026-18015: Inappropriate implementation in Tint
* CVE-2026-18016: Insufficient policy enforcement in Chrome for iOS
* CVE-2026-18017: Use after free in Dawn
* CVE-2026-18018: Inappropriate implementation in Updater
* CVE-2026-18019: Side-channel information leakage in Media
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509039 - CVE-2026-17735 chromium: Chromium: Sandbox escape via crafted HTML page in BFCache [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509039
[ 2 ] Bug #2509040 - CVE-2026-17735 chromium: Chromium: Sandbox escape via crafted HTML page in BFCache [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509040
[ 3 ] Bug #2509041 - CVE-2026-17928 chromium: Chromium: Cross-origin data leakage via DataTransfer [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509041
[ 4 ] Bug #2509042 - CVE-2026-17928 chromium: Chromium: Cross-origin data leakage via DataTransfer [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509042
[ 5 ] Bug #2509043 - CVE-2026-17858 chromium: chromium-browser: Uninitialized Use in WebNN [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509043
[ 6 ] Bug #2509044 - CVE-2026-17858 chromium: chromium-browser: Uninitialized Use in WebNN [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509044
[ 7 ] Bug #2509045 - CVE-2026-17865 chromium: chromium-browser: Inappropriate implementation in Crypto [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509045
[ 8 ] Bug #2509046 - CVE-2026-17865 chromium: chromium-browser: Inappropriate implementation in Crypto [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509046
[ 9 ] Bug #2509047 - CVE-2026-17823 chromium: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509047
[ 10 ] Bug #2509048 - CVE-2026-17823 chromium: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509048
[ 11 ] Bug #2509049 - CVE-2026-17778 chromium: Google Chrome: Arbitrary code execution via crafted Chrome Extension [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509049
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2c6aeb3b06' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: trafficserver-10.1.4-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-144d6c9bcc
2026-08-06 16:46:14.138307+00:00
--------------------------------------------------------------------------------

Name : trafficserver
Product : Fedora 43
Version : 10.1.4
Release : 1.fc43
URL : https://trafficserver.apache.org/
Summary : Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server
Description :
Traffic Server is a high-performance building block for cloud services.
It's more than just a caching proxy server; it also has support for
plugins to build large scale web applications. Key features:

Caching - Improve your response time, while reducing server load and
bandwidth needs by caching and reusing frequently-requested web pages,
images, and web service calls.

Proxying - Easily add keep-alive, filter or anonymize content
requests, or add load balancing by adding a proxy layer.

Fast - Scales well on modern SMP hardware, handling 10s of thousands
of requests per second.

Extensible - APIs to write your own plug-ins to do anything from
modifying HTTP headers to handling ESI requests to writing your own
cache algorithm.

Proven - Handling over 400TB a day at Yahoo! both as forward and
reverse proxies, Apache Traffic Server is battle hardened.

--------------------------------------------------------------------------------
Update Information:

Update to upstream 10.1.4
Resolves:
- CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy
bypass
- CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not
stripped
- CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected,
allowing request smuggling
- CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the
server
- CVE-2026-58154 - Memory-safety errors in MIME and header parsing
- CVE-2026-58155 - Header-name length truncation enables header aliasing and
request smuggling
- CVE-2026-58157 - Improper server-session reuse can expose data across client
connections
- CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the
server
- CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts
framework
- CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap,
allowing memory exhaustion
- CVE-2026-24033 - Chunked extension quoted-string parsing allows request
smuggling
- CVE-2026-33930 - Buffer overflow via Host field that has a long string value
- CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing
host-SNI policy bypass
- CVE-2026-57834 - Malformed chunked message body allows request smuggling
- CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt
memory
- CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to
clients unsafely
- CVE-2026-58156 - URL and port parsing errors allow access-control bypass
- CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack
overflow
- CVE-2026-58159 - Listener and ACL handling allow access-control bypass
- CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses
- CVE-2026-58162 - Certifier plugin trusts client SNI when generating
certificates
- CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state
or crash the server
- CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-
after-free
- CVE-2026-58175 - HostDB SRV handling leaks memory
- CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side
request forgery
- CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input
- CVE-2026-58180 - txn_box plugin overflows the stack from attacker input
- CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or
crash
- CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors
- CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input
- CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory
- CVE-2026-58185 - Use-after-free in the intercept plugin
- CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded
responses
- CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service
- CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental
plugins
- CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF
amplification
- CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed
header encode
- CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without
certificate re-verification
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 28 2026 Jered Floyd [jered@redhat.com] - 10.1.4-1
- Update to upstream 10.1.4
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-144d6c9bcc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: tcpreplay-4.6.0-2.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-838f697068
2026-08-06 16:46:14.138273+00:00
--------------------------------------------------------------------------------

Name : tcpreplay
Product : Fedora 43
Version : 4.6.0
Release : 2.fc43
URL : http://tcpreplay.appneta.com/
Summary : Replay captured network traffic
Description :
Tcpreplay is a tool to replay captured network traffic. Currently, tcpreplay
supports pcap (tcpdump) and snoop capture formats. Also included, is tcpprep
a tool to pre-process capture files to allow increased performance under
certain conditions as well as capinfo which provides basic information about
capture files.

--------------------------------------------------------------------------------
Update Information:

Release notes:
https://github.com/appneta/tcpreplay/releases/tag/v4.5.3
https://github.com/appneta/tcpreplay/releases/tag/v4.5.4
https://github.com/appneta/tcpreplay/releases/tag/v4.5.5
https://github.com/appneta/tcpreplay/releases/tag/v4.6.0
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 28 2026 Bojan Smojver [bojan@rexursive.com] - 4.6.0-2
- Add -pthreads for EPEL8/9
* Tue Jul 28 2026 Bojan Smojver [bojan@rexursive.com] - 4.6.0-1
- Update to 4.6.0
- Add -devel and -static for headers, pkgconfig file and static library
* Fri Jul 24 2026 Bojan Smojver - 4.5.5-1
- Update to 4.5.5
* Thu Jul 23 2026 Bojan Smojver - 4.5.4-1
- Update to 4.5.4
* Mon Jul 20 2026 Bojan Smojver - 4.5.3-1
- Update to 4.5.3
* Fri Jul 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.5.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.5.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-838f697068' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: ImageMagick-7.1.2.27-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-63fca288d6
2026-08-06 16:46:14.138247+00:00
--------------------------------------------------------------------------------

Name : ImageMagick
Product : Fedora 43
Version : 7.1.2.27
Release : 1.fc43
URL : https://imagemagick.org/
Summary : An X application for displaying and manipulating images
Description :
ImageMagick is an image display and manipulation tool for the X
Window System. ImageMagick can read and write JPEG, TIFF, PNM, GIF,
and Photo CD image formats. It can resize, rotate, sharpen, color
reduce, or add special effects to an image, and when finished you can
either save the completed work in the original format or a different
one. ImageMagick also includes command line programs for creating
animated or transparent .gifs, creating composite images, creating
thumbnail images, and more.

ImageMagick is one of your choices if you need a program to manipulate
and display images. If you want to develop your own applications
which use ImageMagick code or APIs, you need to install
ImageMagick-devel as well.

--------------------------------------------------------------------------------
Update Information:

Update to 7.1.2.27
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2379980 - CVE-2025-53101 ImageMagick: ImageMagick Stack Buffer Overflow [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2379980
[ 2 ] Bug #2379981 - CVE-2025-53015 ImageMagick: ImageMagick unbounded loop [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2379981
[ 3 ] Bug #2379982 - CVE-2025-53019 ImageMagick: ImageMagick Memory Leak [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2379982
[ 4 ] Bug #2388308 - CVE-2025-55160 ImageMagick: ImageMagick: Undefined Behavior [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2388308
[ 5 ] Bug #2388309 - CVE-2025-55005 ImageMagick: ImageMagick: heap-buffer overflow [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2388309
[ 6 ] Bug #2388311 - CVE-2025-55154 ImageMagick: ImageMagick: integer overflows in MNG magnification [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2388311
[ 7 ] Bug #2388312 - CVE-2025-55004 ImageMagick: ImageMagick: heap-buffer overflow [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2388312
[ 8 ] Bug #2391120 - CVE-2025-55298 ImageMagick: ImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2391120
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-63fca288d6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: libXfont2-2.0.9-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4f471dd34a
2026-08-07 01:36:33.274488+00:00
--------------------------------------------------------------------------------

Name : libXfont2
Product : Fedora 43
Version : 2.0.9
Release : 1.fc43
URL : http://www.x.org
Summary : X.Org X11 libXfont2 runtime library
Description :
X.Org X11 libXfont2 runtime library

--------------------------------------------------------------------------------
Update Information:

libXfont2 2.0.9 (CVE-2026-59679, CVE-2026-44950)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Peter Hutterer [peter.hutterer@redhat.com] - 2.0.9-1
- libXfont2 2.0.9 (CVE-2026-59679, CVE-2026-44950)
* Thu Jul 23 2026 Peter Hutterer [peter.hutterer@redhat.com] - 2.0.8-3
- Disable X fontserver support. Deprecated for decades and this rules out a set
of potential vulnerabilities.
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.0.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4f471dd34a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: samba-4.23.10-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8e7fa96cf3
2026-08-07 01:36:33.274484+00:00
--------------------------------------------------------------------------------

Name : samba
Product : Fedora 43
Version : 4.23.10
Release : 1.fc43
URL : https://www.samba.org
Summary : Server and Client software to interoperate with Windows machines
Description :
Samba is the standard Windows interoperability suite of programs for Linux and
Unix.

--------------------------------------------------------------------------------
Update Information:

Update to Samba 4.23.10 (and rebuild of FreeIPA).
Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Günther Deschner [gd@samba.org] - 2:4.23.10-1
- Update to Samba 4.23.10
- resolves: rhbz#2509257 - Security fix for CVE-2026-6949
- resolves: rhbz#2509266 - Security fix for CVE-2026-58218
- resolves: rhbz#2509280 - Security fix for CVE-2026-58221
- resolves: rhbz#2509502 - Security fix for CVE-2026-58222
- resolves: Security fix for CVE-2026-58216
- resolves: Security fix for CVE-2026-58224
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509257 - CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09257
[ 2 ] Bug #2509266 - CVE-2026-58218 samba: DNS signing DoS via TKEY name cache exhaustion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09266
[ 3 ] Bug #2509280 - CVE-2026-58221 samba: authenticated LDAP access to internal LDB special DNs permits domain takeover [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09280
[ 4 ] Bug #2509502 - CVE-2026-58222 samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%09502
[ 5 ] Bug #2510884 - CVE-2026-58216 samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%10884
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8e7fa96cf3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: freeipa-4.13.2-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8e7fa96cf3
2026-08-07 01:36:33.274484+00:00
--------------------------------------------------------------------------------

Name : freeipa
Product : Fedora 43
Version : 4.13.2
Release : 1.fc43
URL : http://www.freeipa.org/
Summary : The Identity, Policy and Audit system
Description :
IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).

--------------------------------------------------------------------------------
Update Information:

Update to Samba 4.23.10 (and rebuild of FreeIPA).
Security fixes for CVE-2026-6949, CVE-2026-58218, CVE-2026-58221,
CVE-2026-58222, CVE-2026-58216 and CVE-2026-58224
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Alexander Bokovoy [abokovoy@redhat.com] - 4.13.2-1
- FreeIPA 4.13.2
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509257 - CVE-2026-6949 samba: TSIG packet with crafted name compression can crash DNS server [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509257
[ 2 ] Bug #2509266 - CVE-2026-58218 samba: DNS signing DoS via TKEY name cache exhaustion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509266
[ 3 ] Bug #2509280 - CVE-2026-58221 samba: authenticated LDAP access to internal LDB special DNs permits domain takeover [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509280
[ 4 ] Bug #2509502 - CVE-2026-58222 samba: Samba AD LDAP Compare filter injection and trusted-request confusion disclose protected attributes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509502
[ 5 ] Bug #2510884 - CVE-2026-58216 samba: kpasswd service: kpasswd packet that contains malformed ASN.1 might cause the server to access 6 bytes of unallocated memory leading server to crash [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510884
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8e7fa96cf3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: curl-8.15.0-8.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-097fb2e7e9
2026-08-07 01:36:33.274477+00:00
--------------------------------------------------------------------------------

Name : curl
Product : Fedora 43
Version : 8.15.0
Release : 8.fc43
URL : https://curl.se/
Summary : A utility for getting files from remote servers (FTP, HTTP, and others)
Description :
curl is a command line tool for transferring data with URL syntax, supporting
FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP,
SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP
uploading, HTTP form based upload, proxies, cookies, user+password
authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer
resume, proxy tunneling and a busload of other useful tricks.

--------------------------------------------------------------------------------
Update Information:

fix cross-proxy Digest auth state leak (CVE-2026-7168)
fix cross-origin Digest auth state leak (CVE-2026-11856)
fix password leak with netrc and user in URL (CVE-2026-8926)
fix SSH improper host validation (CVE-2026-9547)
fix trailing dot domain super cookie (CVE-2026-8924)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Jan Macku [jamacku@redhat.com] - 8.15.0-8
- fix cross-proxy Digest auth state leak (CVE-2026-7168)
- fix cross-origin Digest auth state leak (CVE-2026-11856)
- fix password leak with netrc and user in URL (CVE-2026-8926)
- fix SSH improper host validation (CVE-2026-9547)
- fix trailing dot domain super cookie (CVE-2026-8924)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2480086 - CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480086
[ 2 ] Bug #2497410 - CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497410
[ 3 ] Bug #2497475 - CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497475
[ 4 ] Bug #2497597 - CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497597
[ 5 ] Bug #2498017 - CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498017
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-097fb2e7e9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: coreutils-9.7-10.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-25427610bb
2026-08-07 01:36:33.274466+00:00
--------------------------------------------------------------------------------

Name : coreutils
Product : Fedora 43
Version : 9.7
Release : 10.fc43
URL : https://www.gnu.org/software/coreutils/
Summary : A set of basic GNU tools commonly used in shell scripts
Description :
These are the GNU core utilities. This package is the combination of
the old GNU fileutils, sh-utils, and textutils packages.

--------------------------------------------------------------------------------
Update Information:

fix CVE-2026-56391
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Lukáš Zaoral [lzaoral@redhat.com] - 9.7-10
- CVE-2026-56391 - uniq: fix read overrun with -w (rhbz#2507449)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2507449 - CVE-2026-56391 coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%07449
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-25427610bb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: abrt-2.17.9-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-cccf5985b5
2026-08-07 01:36:33.274470+00:00
--------------------------------------------------------------------------------

Name : abrt
Product : Fedora 43
Version : 2.17.9
Release : 1.fc43
URL : https://abrt.readthedocs.org/
Summary : Automatic bug detection and reporting tool
Description :
abrt is a tool to help users to detect defects in applications and
to create a bug report with all information needed by maintainer to fix it.
It uses plugin system to extend its functionality.

--------------------------------------------------------------------------------
Update Information:

Update to 2.17.9
Resolves: #2484614
Resolves: CVE-2026-54230
Resolves: CVE-2026-54231
Resolves: CVE-2026-54228
Resolves: CVE-2026-54229
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Michal Srb [michal@redhat.com] - 2.17.9-1
- Fix journal entry spoofing in journal dump services
- Resolves: rhbz#2484614
- Fix symlink following in event handler scripts
- Resolves: CVE-2026-54230
- Fix content injection in journal log collection
- Resolves: CVE-2026-54231
- Fix TOCTOU in SetElement/DeleteElement
- Resolves: CVE-2026-54228
- Fix race condition in ChownProblemDir
- Resolves: CVE-2026-54229
* Wed Jul 22 2026 Python Maint - 2.17.8-6
- Rebuilt for Python 3.15.0b4 ABI change
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.8-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu Jun 4 2026 Python Maint - 2.17.8-4
- Rebuilt for Python 3.15
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2484614 - ABRT abrt-dump-journal-core trusts spoofed systemd-coredump journal fields, allowing local root file disclosure
https://bugzilla.redhat.com/show_bug.cgi?id=2484614
[ 2 ] Bug #2488616 - CVE-2026-54228 abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488616
[ 3 ] Bug #2488617 - CVE-2026-54229 abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488617
[ 4 ] Bug #2488618 - CVE-2026-54231 abrt: unsanitized systemd journal content written to dump directory files enables content injection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488618
[ 5 ] Bug #2488619 - CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488619
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-cccf5985b5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: php-8.4.24-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d755ca77c4
2026-08-07 01:36:33.274407+00:00
--------------------------------------------------------------------------------

Name : php
Product : Fedora 43
Version : 8.4.24
Release : 1.fc43
URL : http://www.php.net/
Summary : PHP scripting language for creating dynamic web sites
Description :
PHP is an HTML-embedded scripting language. PHP attempts to make it
easy for developers to write dynamically generated web pages. PHP also
offers built-in database integration for several commercial and
non-commercial database management systems, so writing a
database-enabled webpage with PHP is fairly simple. The most common
use of PHP coding is probably as a replacement for CGI scripts.

--------------------------------------------------------------------------------
Update Information:

PHP version 8.4.24 (30 Jul 2026)
BCMath:
Fixed GHSA-x692-q9x7-8c3f (Out-of-bounds write in bccomp()). (CVE-2026-17544)
(Recep Asan)
Calendar:
Fixed bug GH-22602 (gregoriantojd() and juliantojd() integer overflow with
INT_MAX year). (arshidkv12)
Date:
Update timelib to 2022.17. (Derick)
Fixed bug GH-19803 (Parsing a string with a single white space does create an
error). (Derick)
Fixed Unix timestamps in February of the year 0 are misparsed with @-notation.
(LukasGelbmann)
Fixed bug GH-11310 (__debugInfo does nothing on userland classes extending Date
classes). (Derick)
DBA:
Fixed OOB read on malformed length field in dba flatfile handler. (alhudz)
DOM:
Fixed bug GH-22570 (Stack overflow when serializing a deeply nested
Dom\XMLDocument). (iliaal)
Exif:
Fixed bug GH-11020 (exif_read_data() emits a spurious "Illegal IFD size" warning
when an IFD is not followed by a next-IFD offset). (Eyüp Can Akman)
Hash:
Fixed bug GH-18173 (ext/hash relies on implementation-defined malloc alignment).
(iliaal)
Intl:
Fixed Locale::lookup() and locale_lookup() to return NULL instead of the
fallback locale when a language tag cannot be canonicalized. (Weilin Du)
Fixed memory leaks when calling Collator::__construct() or
Spoofchecker::__construct() twice. (Weilin Du)
Fixed IntlChar methods leaving stale global error state after successful calls.
(Xuyang Zhang)
ODBC:
Fixed bug GH-22668 (Heap buffer over-read when a column value exceeds the
driver-reported display size). (iliaal)
OpenSSL:
Fixed timeout for supplemental read at end of a blocking stream in SSL stream
wrapper. (ilutov)
PDO_ODBC:
Fixed bug GH-20726 (Crash with ODBC connection pooling when the DSN carries no
credentials). (iliaal)
Fixed bug GH-22667 (Heap buffer over-read when a column value exceeds the
driver-reported display size). (iliaal)
Fixed bug GH-22666 (Heap buffer overflow when an output parameter value is
longer than the declared maxlen). (iliaal)
Fixed bug GH-22665 (Out-of-bounds write when the ODBC driver reports a
diagnostic message length beyond the error buffer). (iliaal)
PGSQL:
Fixed GHSA-7qpv-r5mr-78m4 (SQL injection via E'...' backslash breakout).
(CVE-2026-17543) (ilutov)
Phar:
Fixed inconsistent handling of the magic ".phar" directory. Paths such as
"/.phar" remain protected, while non-magic paths that merely start with ".phar"
are handled consistently across file and directory creation, copying,
ArrayAccess, stream lookup, directory iteration and extraction. (Weilin Du)
Fixed GHSA-vc5h-9ppw-p5f3 (Crash via recursive symlinks). (CVE-2026-7260) (Jakub
Zelenka)
PHPDBG:
Fixed bug GH-17387 (Trivial crash in phpdbg lexer). (iliaal)
Fixed fleaked lowercased lookup keys in phpdbg_resolve_opline_break. (jorgsowa)
Fixed off-by-one in phpdbg_safe_class_lookup() causing class lookups to always
fail during phpdbg's signal-safe interruption path. (jorgsowa)
Reflection:
Fixed bug GH-22324 (Ignore leading namespace separator in
ReflectionParameter::__construct()). (jorgsowa)
Fixed bug GH-22441 (ReflectionClass::hasProperty() and getProperty() ignore
dynamic properties shadowing a private parent property). (iliaal)
Fixed bug GH-22658 (ReflectionConstant::__toString() with a string value with
null bytes truncates output). (DanielEScherzer)
Fixed bug GH-22681 (Reflection*::__toString() truncates on null bytes).
(DanielEScherzer)
Session:
Fixed bug GH-21314 (Different session garbage collector behavior between PHP 8.3
and PHP 8.5). (jorgsowa)
SPL:
Fix class_parents for classes with leading slash in non-autoload mode.
(jorgsowa)
Ignore leading back-slash in class_parents(), class_implements(), and
class_uses(). (jorgsowa)
Fixed bug GH-16217 (SplFileObject::fputcsv() on an uninitialized object
segfaults). (iliaal)
Standard:
Fixed bug GH-22360 (convert.base64-encode corruption on incremental flush).
(David Carlier)
Fixed bug GH-22395 (base_convert() outputs at most 64 characters). (Weilin Du)
Fixed integer overflow in getimagesize() and getimagesizefromstring() when
parsing an IFF chunk with a size of INT_MAX. (David Carlier, Weilin Du)
Fixed bug GH-22678 (Use-after-free in array_multisort() when the comparator
mutates the array being sorted). (azchin, iliaal)
Streams:
Fixed bug GH-22617 (persistent stream keys truncated at null bytes, causing
distinct abstract unix domain sockets to share a resource). (David Carlier)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 29 2026 Remi Collet [remi@remirepo.net] - 8.4.24-1
- Update to 8.4.24 - http://www.php.net/releases/8_4_24.php
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2511423 - CVE-2026-17544 php: PHP: Arbitrary code execution via out-of-bounds write in bccomp() [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%11423
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d755ca77c4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: gstreamer1-plugins-bad-free-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-plugins-bad-free
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer streaming media framework "bad" plugins
Description :
GStreamer is a streaming media framework, based on graphs of elements which
operate on media data.

This package contains plug-ins that aren't tested well enough, or the code
is not of good enough quality.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jul 15 2026 Carl George [carlwgeorge@gmail.com] - 1.28.5-2
- Rebuild for libonnxruntime.so.1(VERS_1.26.0)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-plugins-good-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-plugins-good
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer plugins with good code and licensing
Description :
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. Applications using this library can do anything
from real-time sound processing to playing videos, and just about anything
else media-related. Its plugin-based architecture means that new data
types or processing capabilities can be added simply by installing new
plugins.

GStreamer Good Plugins is a collection of well-supported plugins of
good quality and under the LGPL license.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-rtsp-server-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-rtsp-server
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer RTSP server library
Description :
A GStreamer-based RTSP server library.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-plugin-libav-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-plugin-libav
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : https://gstreamer.freedesktop.org/
Summary : GStreamer FFmpeg/LibAV plugin
Description :
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. Applications using this library can do anything
from real-time sound processing to playing videos, and just about anything
else media-related. Its plugin-based architecture means that new data
types or processing capabilities can be added simply by installing new
plugins.

This package provides FFmpeg/LibAV GStreamer plugin.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gst-editing-services-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gst-editing-services
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://cgit.freedesktop.org/gstreamer/gst-editing-services/
Summary : Gstreamer editing services
Description :
This is a high-level library for facilitating the creation of audio/video
non-linear editors.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Wed Jul 22 2026 Python Maint - 1.28.5-3
- Rebuilt for Python 3.15.0b4 ABI change
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: python-gstreamer1-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : python-gstreamer1
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : Python bindings for GStreamer
Description :
This module contains PyGObject overrides to make it easier to write
applications that use GStreamer 1.x in Python.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Wed Jul 22 2026 Python Maint - 1.28.5-3
- Rebuilt for Python 3.15.0b4 ABI change
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gst-devtools-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gst-devtools
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : https://gstreamer.freedesktop.org/src/gst-devtools
Summary : Development and debugging tools for GStreamer
Description :
Development and debugging tools for GStreamer.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-plugins-ugly-free-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-plugins-ugly-free
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer streaming media framework "ugly" plugins
Description :
GStreamer is a streaming media framework, based on graphs of elements which
operate on media data.

This package contains plug-ins whose license is not fully compatible with LGPL.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-plugins-base-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-plugins-base
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer streaming media framework base plugins
Description :
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. Applications using this library can do anything
from real-time sound processing to playing videos, and just about anything
else media-related. Its plugin-based architecture means that new data
types or processing capabilities can be added simply by installing new
plug-ins.

This package contains a set of well-maintained base plug-ins.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-doc-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1-doc
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer documentation
Description :
GStreamer documentation.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: gstreamer1-1.28.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d51eee8d48
2026-08-07 01:14:12.930647+00:00
--------------------------------------------------------------------------------

Name : gstreamer1
Product : Fedora 44
Version : 1.28.6
Release : 1.fc44
URL : http://gstreamer.freedesktop.org/
Summary : GStreamer streaming media framework runtime
Description :
GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. Applications using this library can do anything
from real-time sound processing to playing videos, and just about anything
else media-related. Its plugin-based architecture means that new data
types or processing capabilities can be added simply by installing new
plugins.

--------------------------------------------------------------------------------
Update Information:

1.28.6
https://gstreamer.freedesktop.org/releases/1.28/#1.28.6
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 5 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.28.6-1
- 1.28.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.28.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d51eee8d48' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new