Fedora Linux 9448 Published by

Fedora published security updates for versions 43 and 44 on August 12, 2026, addressing critical vulnerabilities in the ClamAV antivirus toolkit, the libidn internationalized domain name library, and the Domoticz home automation system. The ClamAV updates to version 1.4.6 resolve multiple denial-of-service risks stemming from crafted InstallShield, 7z, PESpin, FSG, and DMG files, alongside an error handling flaw in the HTML CSS module related to UTF-8 string splitting. The libidn release fixes a CVE that allows out-of-bounds reads within the ToUnicode APIs, while the Domoticz version 2026.3 update patches significant security weaknesses in its web server and API infrastructure.

Fedora 43 Update: clamav-1.4.6-1.fc43
Fedora 43 Update: libidn-1.44-1.fc43
Fedora 44 Update: clamav-1.4.6-1.fc44
Fedora 44 Update: libidn-1.44-1.fc44
Fedora 44 Update: domoticz-2026.3-1.fc44




[SECURITY] Fedora 43 Update: clamav-1.4.6-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a9beec8485
2026-08-12 01:10:02.714660+00:00
--------------------------------------------------------------------------------

Name : clamav
Product : Fedora 43
Version : 1.4.6
Release : 1.fc43
URL : https://www.clamav.net/
Summary : End-user tools for the Clam Antivirus scanner
Description :
Clam AntiVirus is an anti-virus toolkit for UNIX. The main purpose of this
software is the integration with mail servers (attachment scanning). The
package provides a flexible and scalable multi-threaded daemon, a command
line scanner, and a tool for automatic updating via Internet. The programs
are based on a shared library distributed with the Clam AntiVirus package,
which you can use with your own software. The virus database is based on
the virus database from OpenAntiVirus, but contains additional signatures
(including signatures for popular polymorphic viruses, too) and is KEPT UP
TO DATE.

--------------------------------------------------------------------------------
Update Information:

1.4.6
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 10 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.4.6-1
- Update to 1.4.6
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.4.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jul 10 2026 Jerry James [loganjerry@gmail.com] - 1.4.5-2
- Remove unused ocaml BuildRequires
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2444609 - CVE-2026-20031 clamav: improper error handling when splitting UTF-8 strings in the HTML Cascading Style Sheets (CSS) module [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444609
[ 2 ] Bug #2444610 - CVE-2026-20031 clamav: improper error handling when splitting UTF-8 strings in the HTML Cascading Style Sheets (CSS) module [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444610
[ 3 ] Bug #2496742 - CVE-2026-20216 clamav: ClamAV: Denial of Service via crafted InstallShield file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496742
[ 4 ] Bug #2496743 - CVE-2026-20216 clamav: ClamAV: Denial of Service via crafted InstallShield file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496743
[ 5 ] Bug #2496819 - CVE-2026-20215 clamav: ClamAV: Denial of Service via crafted 7z file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496819
[ 6 ] Bug #2496820 - CVE-2026-20215 clamav: ClamAV: Denial of Service via crafted 7z file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496820
[ 7 ] Bug #2496827 - CVE-2026-20217 clamav: ClamAV: Denial of Service via crafted PESpin file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496827
[ 8 ] Bug #2496828 - CVE-2026-20217 clamav: ClamAV: Denial of Service via crafted PESpin file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496828
[ 9 ] Bug #2496834 - CVE-2026-20214 clamav: ClamAV: Denial of Service via crafted FSG file parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496834
[ 10 ] Bug #2496835 - CVE-2026-20214 clamav: ClamAV: Denial of Service via crafted FSG file parsing [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496835
[ 11 ] Bug #2496842 - CVE-2026-20244 clamav: ClamAV: Denial of Service via crafted DMG file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496842
[ 12 ] Bug #2496843 - CVE-2026-20244 clamav: ClamAV: Denial of Service via crafted DMG file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496843
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a9beec8485' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: libidn-1.44-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-acf66846ee
2026-08-12 01:10:02.714629+00:00
--------------------------------------------------------------------------------

Name : libidn
Product : Fedora 43
Version : 1.44
Release : 1.fc43
URL : http://www.gnu.org/software/libidn/
Summary : Internationalized Domain Name support library
Description :
GNU Libidn is an implementation of the Stringprep, Punycode and
IDNA specifications defined by the IETF Internationalized Domain
Names (IDN) working group, used for internationalized domain
names.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2026-57053.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 22 2026 Miroslav Lichvar [mlichvar@redhat.com] - 1.44-1
- update to 1.44
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.43-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Wed Oct 1 2025 Yaakov Selkowitz [yselkowi@redhat.com] - 1.43-3
- Rebuilt for java-25-openjdk as system jdk
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509779 - CVE-2026-57053 libidn: GNU libidn: Out-of-bounds read in ToUnicode APIs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509779
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-acf66846ee' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: clamav-1.4.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ecf6fe868f
2026-08-12 00:46:57.036805+00:00
--------------------------------------------------------------------------------

Name : clamav
Product : Fedora 44
Version : 1.4.6
Release : 1.fc44
URL : https://www.clamav.net/
Summary : End-user tools for the Clam Antivirus scanner
Description :
Clam AntiVirus is an anti-virus toolkit for UNIX. The main purpose of this
software is the integration with mail servers (attachment scanning). The
package provides a flexible and scalable multi-threaded daemon, a command
line scanner, and a tool for automatic updating via Internet. The programs
are based on a shared library distributed with the Clam AntiVirus package,
which you can use with your own software. The virus database is based on
the virus database from OpenAntiVirus, but contains additional signatures
(including signatures for popular polymorphic viruses, too) and is KEPT UP
TO DATE.

--------------------------------------------------------------------------------
Update Information:

1.4.6
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 10 2026 Gwyn Ciesla [gwync@protonmail.com] - 1.4.6-1
- Update to 1.4.6
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.4.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jul 10 2026 Jerry James [loganjerry@gmail.com] - 1.4.5-2
- Remove unused ocaml BuildRequires
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2444609 - CVE-2026-20031 clamav: improper error handling when splitting UTF-8 strings in the HTML Cascading Style Sheets (CSS) module [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444609
[ 2 ] Bug #2444610 - CVE-2026-20031 clamav: improper error handling when splitting UTF-8 strings in the HTML Cascading Style Sheets (CSS) module [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2444610
[ 3 ] Bug #2496742 - CVE-2026-20216 clamav: ClamAV: Denial of Service via crafted InstallShield file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496742
[ 4 ] Bug #2496743 - CVE-2026-20216 clamav: ClamAV: Denial of Service via crafted InstallShield file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496743
[ 5 ] Bug #2496819 - CVE-2026-20215 clamav: ClamAV: Denial of Service via crafted 7z file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496819
[ 6 ] Bug #2496820 - CVE-2026-20215 clamav: ClamAV: Denial of Service via crafted 7z file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496820
[ 7 ] Bug #2496827 - CVE-2026-20217 clamav: ClamAV: Denial of Service via crafted PESpin file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496827
[ 8 ] Bug #2496828 - CVE-2026-20217 clamav: ClamAV: Denial of Service via crafted PESpin file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496828
[ 9 ] Bug #2496834 - CVE-2026-20214 clamav: ClamAV: Denial of Service via crafted FSG file parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496834
[ 10 ] Bug #2496835 - CVE-2026-20214 clamav: ClamAV: Denial of Service via crafted FSG file parsing [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496835
[ 11 ] Bug #2496842 - CVE-2026-20244 clamav: ClamAV: Denial of Service via crafted DMG file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496842
[ 12 ] Bug #2496843 - CVE-2026-20244 clamav: ClamAV: Denial of Service via crafted DMG file [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496843
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ecf6fe868f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: libidn-1.44-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2291be7d88
2026-08-12 00:46:57.036761+00:00
--------------------------------------------------------------------------------

Name : libidn
Product : Fedora 44
Version : 1.44
Release : 1.fc44
URL : http://www.gnu.org/software/libidn/
Summary : Internationalized Domain Name support library
Description :
GNU Libidn is an implementation of the Stringprep, Punycode and
IDNA specifications defined by the IETF Internationalized Domain
Names (IDN) working group, used for internationalized domain
names.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2026-57053.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 22 2026 Miroslav Lichvar [mlichvar@redhat.com] - 1.44-1
- update to 1.44
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2509779 - CVE-2026-57053 libidn: GNU libidn: Out-of-bounds read in ToUnicode APIs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509779
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2291be7d88' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: domoticz-2026.3-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-471f1abb1f
2026-08-12 00:46:57.036746+00:00
--------------------------------------------------------------------------------

Name : domoticz
Product : Fedora 44
Version : 2026.3
Release : 1.fc44
URL : http://www.domoticz.com
Summary : Open source Home Automation System
Description :
Domoticz is a Home Automation System that lets you monitor and configure various
devices like: Lights, Switches, various sensors/meters like Temperature, Rain,
Wind, UV, Electra, Gas, Water and much more. Notifications/Alerts can be sent to
any mobile device

--------------------------------------------------------------------------------
Update Information:

Version 2026.3 (August 2nd 2026)
This release contains important security fixes in the web server and API,
upgrading is strongly recommended.
https://github.com/domoticz/domoticz/blob/2026.3/History.txt
--------------------------------------------------------------------------------
ChangeLog:

* Sun Aug 2 2026 Michael Cronenworth [mike@cchtml.com] - 2026.3-1
- New stable release
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2026.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu Jun 25 2026 FrantiĊĦek Zatloukal [fzatlouk@redhat.com] - 2026.2-3
- Rebuilt for fmt/spdlog
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 2026.2-2
- Rebuilt for openssl 4.0
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2510133 - domoticz-2026.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id%10133
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-471f1abb1f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------