Fedora 43 Update: erlang-cowlib-2.19.0-1.fc43
Fedora 43 Update: erlang-cowboy-2.18.0-1.fc43
Fedora 44 Update: flatpak-1.18.1-1.fc44
Fedora 44 Update: libnfs-6.0.2-9.fc44
Fedora 44 Update: erlang-cowlib-2.19.0-1.fc44
Fedora 44 Update: erlang-cowboy-2.18.0-1.fc44
[SECURITY] Fedora 43 Update: erlang-cowlib-2.19.0-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ce97d80dae
2026-08-14 01:36:33.297025+00:00
--------------------------------------------------------------------------------
Name : erlang-cowlib
Product : Fedora 43
Version : 2.19.0
Release : 1.fc43
URL : https://github.com/ninenines/cowlib
Summary : Support library for manipulating Web protocols
Description :
Support library for manipulating Web protocols.
--------------------------------------------------------------------------------
Update Information:
Coordinated security update of cowlib and cowboy, released together upstream on
2026-07-27.
cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer
decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION
frames and NUL bytes in multipart headers, validates cookie domain and path,
limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket-
Version limits to response headers, and enforces a custom max_concurrent_streams
immediately.
cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR
in HTTP/1.1 header values, rejects requests containing a fragment component,
rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies
option to the cowboy_req cookie functions, fixes max_headers handling with
duplicate headers, and fixes the websocket max_inflate_size calculation.
Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1
requests. Applications relying on that behaviour may see different throughput
characteristics.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 5 2026 Peter Lemenkov [lemenkov@gmail.com] - 2.19.0-1
- Cowlib ver. 2.19.0
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.18.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2508040 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2508040
[ 2 ] Bug #2508041 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2508041
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ce97d80dae' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: erlang-cowboy-2.18.0-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ce97d80dae
2026-08-14 01:36:33.297025+00:00
--------------------------------------------------------------------------------
Name : erlang-cowboy
Product : Fedora 43
Version : 2.18.0
Release : 1.fc43
URL : https://github.com/ninenines/cowboy
Summary : Small, fast, modular HTTP server written in Erlang
Description :
Small, fast, modular HTTP server written in Erlang.
--------------------------------------------------------------------------------
Update Information:
Coordinated security update of cowlib and cowboy, released together upstream on
2026-07-27.
cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer
decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION
frames and NUL bytes in multipart headers, validates cookie domain and path,
limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket-
Version limits to response headers, and enforces a custom max_concurrent_streams
immediately.
cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR
in HTTP/1.1 header values, rejects requests containing a fragment component,
rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies
option to the cowboy_req cookie functions, fixes max_headers handling with
duplicate headers, and fixes the websocket max_inflate_size calculation.
Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1
requests. Applications relying on that behaviour may see different throughput
characteristics.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 5 2026 Peter Lemenkov [lemenkov@gmail.com] - 2.18.0-1
- Cowboy ver. 2.18.0
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2508040 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2508040
[ 2 ] Bug #2508041 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2508041
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ce97d80dae' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: flatpak-1.18.1-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6b83471b0e
2026-08-14 01:17:35.635288+00:00
--------------------------------------------------------------------------------
Name : flatpak
Product : Fedora 44
Version : 1.18.1
Release : 1.fc44
URL : https://flatpak.org/
Summary : Application deployment framework for desktop apps
Description :
flatpak is a system for building, distributing and running sandboxed desktop
applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for
more information.
--------------------------------------------------------------------------------
Update Information:
Update to 1.18.1
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 12 2026 David King [amigadave@amigadave.com] - 1.18.1-1
- Update to 1.18.1
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6b83471b0e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: libnfs-6.0.2-9.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8ae1795f2b
2026-08-14 01:17:35.635270+00:00
--------------------------------------------------------------------------------
Name : libnfs
Product : Fedora 44
Version : 6.0.2
Release : 9.fc44
URL : https://github.com/sahlberg/libnfs
Summary : Client library for accessing NFS shares over a network
Description :
The libnfs package contains a library of functions for accessing NFSv2
and NFSv3 servers from user space. It provides a low-level, asynchronous
RPC library for accessing NFS protocols, an asynchronous library with
POSIX-like VFS functions, and a synchronous library with POSIX-like VFS
functions.
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2026-57918 and CVE-2026-53689
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 10 2026 Xavier Bachelot [xavier@bachelot.org] - 6.0.2-9
- Add upstream patches for CVE-2026-53689 and CVE-2026-57918
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 6.0.2-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2493608 - CVE-2026-57918 libnfs: libnfs: Information disclosure and data manipulation vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493608
[ 2 ] Bug #2512002 - CVE-2026-53689 libnfs: libnfs: Information disclosure and data corruption via crafted NFS server connection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2512002
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8ae1795f2b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: erlang-cowlib-2.19.0-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7d233ad8b0
2026-08-14 01:17:35.635233+00:00
--------------------------------------------------------------------------------
Name : erlang-cowlib
Product : Fedora 44
Version : 2.19.0
Release : 1.fc44
URL : https://github.com/ninenines/cowlib
Summary : Support library for manipulating Web protocols
Description :
Support library for manipulating Web protocols.
--------------------------------------------------------------------------------
Update Information:
Coordinated security update of cowlib and cowboy, released together upstream on
2026-07-27.
cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer
decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION
frames and NUL bytes in multipart headers, validates cookie domain and path,
limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket-
Version limits to response headers, and enforces a custom max_concurrent_streams
immediately.
cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR
in HTTP/1.1 header values, rejects requests containing a fragment component,
rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies
option to the cowboy_req cookie functions, fixes max_headers handling with
duplicate headers, and fixes the websocket max_inflate_size calculation.
Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1
requests. Applications relying on that behaviour may see different throughput
characteristics.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 5 2026 Peter Lemenkov [lemenkov@gmail.com] - 2.19.0-1
- Cowlib ver. 2.19.0
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.18.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2508040 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2508040
[ 2 ] Bug #2508041 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2508041
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7d233ad8b0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: erlang-cowboy-2.18.0-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7d233ad8b0
2026-08-14 01:17:35.635233+00:00
--------------------------------------------------------------------------------
Name : erlang-cowboy
Product : Fedora 44
Version : 2.18.0
Release : 1.fc44
URL : https://github.com/ninenines/cowboy
Summary : Small, fast, modular HTTP server written in Erlang
Description :
Small, fast, modular HTTP server written in Erlang.
--------------------------------------------------------------------------------
Update Information:
Coordinated security update of cowlib and cowboy, released together upstream on
2026-07-27.
cowlib 2.19.0 fixes CVE-2026-59248: unbounded HPACK/QPACK prefixed-integer
decoding allowed a denial of service. It also rejects empty HTTP/2 CONTINUATION
frames and NUL bytes in multipart headers, validates cookie domain and path,
limits cow_cookie:parse_cookie to 100 cookies by default, applies Sec-Websocket-
Version limits to response headers, and enforces a custom max_concurrent_streams
immediately.
cowboy 2.18.0 is the matching release and requires cowlib 2.19.0. It rejects CR
in HTTP/1.1 header values, rejects requests containing a fragment component,
rejects HTTP/2 requests where host disagrees with :authority, adds a max_cookies
option to the cowboy_req cookie functions, fixes max_headers handling with
duplicate headers, and fixes the websocket max_inflate_size calculation.
Note that cowboy 2.18.0 removes concurrent processing of pipelined HTTP/1.1
requests. Applications relying on that behaviour may see different throughput
characteristics.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 5 2026 Peter Lemenkov [lemenkov@gmail.com] - 2.18.0-1
- Cowboy ver. 2.18.0
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2508040 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2508040
[ 2 ] Bug #2508041 - CVE-2026-59248 erlang-cowlib: Cowlib: Denial of Service due to unbounded HPACK/QPACK prefixed-integer decoding [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2508041
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7d233ad8b0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new