Fedora Linux 9429 Published by

Fedora released a batch of security patches on July 26, 2026, targeting both Fedora 43 and Fedora 44 distributions. The advisories address multiple critical vulnerabilities across core applications like Firefox, the Moby container engine, xrdp remote desktop server, Libreswan VPN daemon, PAM authentication modules, and WebKitGTK rendering libraries. Attackers could exploit these flaws to trigger denial-of-service crashes, bypass authentication through timing side-channels, or leak sensitive data via buffer overflows and unvalidated input parsing.

Fedora 43 Update: firefox-153.0-3.fc43
Fedora 43 Update: google-osconfig-agent-20260717.00-1.fc43
Fedora 43 Update: moby-engine-29.6.2-1.fc43
Fedora 43 Update: xrdp-0.10.6.1-3.fc43
Fedora 43 Update: libreswan-5.3.2-2.fc43
Fedora 43 Update: webkitgtk-2.52.5-1.fc43
Fedora 43 Update: python-idna-3.18-1.fc43
Fedora 43 Update: p11-kit-0.26.4-1.fc43
Fedora 43 Update: pam-1.7.1-5.fc43
Fedora 44 Update: GitPython-3.1.55-1.fc44
Fedora 44 Update: google-osconfig-agent-20260717.00-1.fc44
Fedora 44 Update: xrdp-0.10.6.1-3.fc44
Fedora 44 Update: moby-engine-29.6.2-1.fc44




[SECURITY] Fedora 43 Update: firefox-153.0-3.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6dab7a3eff
2026-07-26 01:15:59.915605+00:00
--------------------------------------------------------------------------------

Name : firefox
Product : Fedora 43
Version : 153.0
Release : 3.fc43
URL : https://www.mozilla.org/firefox/
Summary : Mozilla Firefox Web browser
Description :
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.

--------------------------------------------------------------------------------
Update Information:

Update to latest upstream (153.0)
New upstream release (153.0)
Updated to latest upstream (153.0)
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6dab7a3eff' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: google-osconfig-agent-20260717.00-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4a2d23b470
2026-07-26 01:15:59.915589+00:00
--------------------------------------------------------------------------------

Name : google-osconfig-agent
Product : Fedora 43
Version : 20260717.00
Release : 1.fc43
URL : https://github.com/GoogleCloudPlatform/osconfig
Summary : Google OS Config Agent
Description :
Google OS Config Agent

--------------------------------------------------------------------------------
Update Information:

Update to 20260717
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 17 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 20260717.00-1
- Update to 200260717 - Closes rhbz#2336973
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Tue Feb 3 2026 Maxwell G [maxwell@gtmx.me] - 20241029.01-8
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Sun Oct 12 2025 Maxwell G [maxwell@gtmx.me] - 20241029.01-6
- Rebuild for golang 1.25.2
* Fri Oct 10 2025 Alejandro Sáez [asm@redhat.com] - 20241029.01-5
- rebuild
* Fri Aug 15 2025 Maxwell G [maxwell@gtmx.me] - 20241029.01-4
- Rebuild for golang-1.25.0
* Thu Jul 24 2025 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Jan 17 2025 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2385031 - google-osconfig-agent: FTBFS in Fedora rawhide/f43
https://bugzilla.redhat.com/show_bug.cgi?id#85031
[ 2 ] Bug #2408286 - CVE-2025-58189 google-osconfig-agent: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$08286
[ 3 ] Bug #2409759 - CVE-2025-61723 google-osconfig-agent: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$09759
[ 4 ] Bug #2410709 - CVE-2025-58185 google-osconfig-agent: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$10709
[ 5 ] Bug #2411605 - CVE-2025-58188 google-osconfig-agent: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$11605
[ 6 ] Bug #2412705 - CVE-2025-58183 google-osconfig-agent: Unbounded allocation when parsing GNU sparse map [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$12705
[ 7 ] Bug #2422203 - CVE-2025-65637 google-osconfig-agent: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id$22203
[ 8 ] Bug #2486287 - CVE-2026-45287 google-osconfig-agent: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$86287
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4a2d23b470' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: moby-engine-29.6.2-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-64ca3441c3
2026-07-26 01:15:59.915575+00:00
--------------------------------------------------------------------------------

Name : moby-engine
Product : Fedora 43
Version : 29.6.2
Release : 1.fc43
URL : https://github.com/moby/moby
Summary : The open-source application container engine
Description :
Docker is an open source project to build, ship and run any application as a
lightweight container.

Docker containers are both hardware-agnostic and platform-agnostic. This means
they can run anywhere, from your laptop to the largest EC2 compute instance and
everything in between — and they do not require you to use a particular
language, framework or packaging system. That makes them great building blocks
for deploying and scaling web apps, databases, and backend services without
depending on a particular stack or provider.

--------------------------------------------------------------------------------
Update Information:

Update to release v29.6.2
Resolves: rhbz#2496437
Upstream security fixes
GHSA-hw3h-2gp9-cxpv
GHSA-qx3x-mv6r-52p6
GHSA-32pv-7hq5-qhwq
GHSA-g2h8-426c-7976
GHSA-388v-wmr2-g2v2
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 16 2026 Bradley G Smith [bradley.g.smith@gmail.com] - 29.6.2-1
- Update to release v29.6.2
- Resolves: rhbz#2496437
- Upstream security fixes
- - GHSA-hw3h-2gp9-cxpv
- - GHSA-qx3x-mv6r-52p6
- - GHSA-32pv-7hq5-qhwq
- - GHSA-g2h8-426c-7976
- - GHSA-388v-wmr2-g2v2
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 29.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 26 2026 Bradley G Smith [bradley.g.smith@gmail.com] - 29.6.1-1
- Update to release v29.6.1
- Resolves: rhbz#2493405
- Upstream security fixes for: GHSA-mjcv-p78q-w5fw GHSA-jpcc-p29g-p8mq
GHSA-72x6-4j93-7w86 GHSA-7236-3392-c5c6
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2496437 - CVE-2026-47262 moby-engine: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$96437
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-64ca3441c3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: xrdp-0.10.6.1-3.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-952a486b39
2026-07-26 01:15:59.915570+00:00
--------------------------------------------------------------------------------

Name : xrdp
Product : Fedora 43
Version : 0.10.6.1
Release : 3.fc43
URL : http://www.xrdp.org/
Summary : Open source remote desktop protocol (RDP) server
Description :
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.

--------------------------------------------------------------------------------
Update Information:

Update PAM file to better match modern reality.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 18 2026 Bojan Smojver [bojan@rexursive.com] - 1:0.10.6.1-3
- Fix bug #2499948
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502969 - CVE-2026-54538 xrdp: infinite loop denial-of-service vulnerability during RDP packet processing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502969
[ 2 ] Bug #2502971 - CVE-2026-41521 xrdp: integer overflow leads to out-of-bounds read in vnc-any mode [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502971
[ 3 ] Bug #2502973 - CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502973
[ 4 ] Bug #2502974 - CVE-2026-55639 xrdp: improper input validation in MCS data processing leads to potential information leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502974
[ 5 ] Bug #2502977 - CVE-2026-55626 xrdp: missing authentication when xrdp launches Xvnc in UNIX domain socket mode [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502977
[ 6 ] Bug #2502978 - CVE-2026-55645 xrdp: out-of-bounds read in client control PDU processing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502978
[ 7 ] Bug #2502981 - CVE-2026-44978 xrdp: heap out-of-bounds read in non-TLS FIPS receive paths [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502981
[ 8 ] Bug #2502983 - CVE-2026-55238 xrdp: improper input validation in capability negotiation leads to denial of service [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502983
[ 9 ] Bug #2502985 - CVE-2026-42218 xrdp: timing side-channel allows username enumeration [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502985
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-952a486b39' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: libreswan-5.3.2-2.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-146b86f436
2026-07-26 01:15:59.915573+00:00
--------------------------------------------------------------------------------

Name : libreswan
Product : Fedora 43
Version : 5.3.2
Release : 2.fc43
URL : https://libreswan.org/
Summary : Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec
Description :
Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is
the Internet Protocol Security and uses strong cryptography to provide
both authentication and encryption services. These services allow you
to build secure tunnels through untrusted networks. Everything passing
through the untrusted net is encrypted by the ipsec gateway machine and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network or VPN.

This package contains the daemons and userland tools for setting up
Libreswan.

Libreswan also supports IKEv2 (RFC7296) and Secure Labeling

Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04

--------------------------------------------------------------------------------
Update Information:

Update to 5.3.2 for CVE-2026-14957 (with newsources)
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 17 2026 Paul Wouters [paul.wouters@aiven.io] - 5.3.2-2
- Update to 5.3.2 for CVE-2026-14957 (with newsources)
* Fri Jul 17 2026 Paul Wouters [paul.wouters@aiven.io] - 5.3.2-1
- Update to 5.3.2 for CVE-2026-14957
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 5.3.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jun 24 2026 Paul Wouters [paul.wouters@aiven.io] - 5.3.1-1
- Update to libreswan-5.3.1
* Thu Jan 29 2026 Daiki Ueno [dueno@redhat.com] - 5.3-5
- Fix compilation error on Fedora 44
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 5.3-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-146b86f436' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: webkitgtk-2.52.5-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec8e535c6e
2026-07-26 01:15:59.915548+00:00
--------------------------------------------------------------------------------

Name : webkitgtk
Product : Fedora 43
Version : 2.52.5
Release : 1.fc43
URL : https://www.webkitgtk.org/
Summary : GTK web content engine library
Description :
WebKitGTK is the port of the WebKit web rendering engine to the
GTK platform.

--------------------------------------------------------------------------------
Update Information:

Fire scrollend event for instant programmatic scrolls.
Increase network idle connection timeout to 115 seconds.
Fix several crashes and rendering issues.
Fix CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676,
CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712,
CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721,
CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732,
CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 9 2026 Michael Catanzaro [mcatanzaro@gnome.org] - 2.52.5-1
- Update to 2.52.5
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec8e535c6e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: python-idna-3.18-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6215e65f6c
2026-07-26 01:15:59.915545+00:00
--------------------------------------------------------------------------------

Name : python-idna
Product : Fedora 43
Version : 3.18
Release : 1.fc43
URL : https://github.com/kjd/idna
Summary : Internationalized Domain Names in Applications (IDNA)
Description :
A library to support the Internationalised Domain Names in Applications (IDNA)
protocol as specified in RFC 5891 http://tools.ietf.org/html/rfc5891>. This
version of the protocol is often referred to as "IDNA2008" and can produce
different results from the earlier standard from 2003.

The library is also intended to act as a suitable drop-in replacement for the
"encodings.idna" module that comes with the Python standard library but
currently only supports the older 2003 specification.

--------------------------------------------------------------------------------
Update Information:

Update to the latest version to bring fixes for CVE-2026-45409 and CVE-2024-3651
into the stable releases.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jun 9 2026 Lumir Balhar [lbalhar@redhat.com] - 3.18-1
- Update to 3.18 (rhbz#2483976)
* Wed Jun 3 2026 Python Maint - 3.17-2
- Rebuilt for Python 3.15
* Sun May 31 2026 Lumir Balhar [lbalhar@redhat.com] - 3.17-1
- Update to 3.17 (rhbz#2480667)
* Wed May 13 2026 Lumir Balhar [lbalhar@redhat.com] - 3.15-1
- Update to 3.15 (rhbz#2476912)
* Mon May 11 2026 Lumir Balhar [lbalhar@redhat.com] - 3.14-1
- Update to 3.14 (rhbz#2468686)
* Thu Apr 23 2026 Lumir Balhar [lbalhar@redhat.com] - 3.13-1
- Update to 3.13 (rhbz#2460821)
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.11-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Sun Oct 12 2025 Lumir Balhar [lbalhar@redhat.com] - 3.11-1
- Update to 3.11 (rhbz#2403375)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2498560 - CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498560
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6215e65f6c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: p11-kit-0.26.4-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-566791181a
2026-07-26 01:15:59.915550+00:00
--------------------------------------------------------------------------------

Name : p11-kit
Product : Fedora 43
Version : 0.26.4
Release : 1.fc43
URL : http://p11-glue.freedesktop.org/p11-kit.html
Summary : Library for loading and sharing PKCS#11 modules
Description :
p11-kit provides a way to load and enumerate PKCS#11 modules, as well
as a standard configuration setup for installing PKCS#11 modules in
such a way that they're discoverable.

--------------------------------------------------------------------------------
Update Information:

server: fixed stack exhaustion via unbounded recursion in RPC attribute parsing
by enforcing a recursion depth limit (CVE-2026-13757)
fixed confusing error message when trying to store an existing cert with trust
anchor
fixed assert when parsing p11-kit files with value (")
fixed numerous memory management issues
Build and test fixes
Updated translations
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 10 2026 Packit [hello@packit.dev] - 0.26.4-1
- Update to 0.26.4 upstream release
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2494560 - CVE-2026-13757 p11-kit: Stack exhaustion via unbounded recursion in RPC attribute parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494560
[ 2 ] Bug #2498946 - p11-kit-0.26.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2498946
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-566791181a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: pam-1.7.1-5.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-adc8ddbeaa
2026-07-26 01:15:59.915520+00:00
--------------------------------------------------------------------------------

Name : pam
Product : Fedora 43
Version : 1.7.1
Release : 5.fc43
URL : http://www.linux-pam.org/
Summary : An extensible library which provides authentication for applications
Description :
PAM (Pluggable Authentication Modules) is a system security tool that
allows system administrators to set authentication policy without
having to recompile programs that handle authentication.

--------------------------------------------------------------------------------
Update Information:

pam_userdb: fix password comparison timing leak
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 10 2026 Iker Pedrosa [ipedrosa@redhat.com] - 1.7.1-5
- pam_userdb: fix password comparison timing leak
Resolves: #2496416
Resolves: CVE-2026-54411
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2496416 - CVE-2026-54411 pam: Plaintext password recovery via timing discrepancy in pam_userdb module [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496416
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-adc8ddbeaa' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: GitPython-3.1.55-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8e8273f18f
2026-07-26 00:57:16.867310+00:00
--------------------------------------------------------------------------------

Name : GitPython
Product : Fedora 44
Version : 3.1.55
Release : 1.fc44
URL : https://github.com/gitpython-developers/GitPython
Summary : Python Git Library
Description :
GitPython is a python library used to interact with git repositories,
high-level like git-porcelain, or low-level like git-plumbing.

It provides abstractions of git objects for easy access of repository data, and
additionally allows you to access the git repository more directly using either
a pure python implementation, or the faster, but more resource intensive git
command implementation.

The object database implementation is optimized for handling large quantities
of objects and large datasets, which is achieved by using low-level structures
and data streaming.

--------------------------------------------------------------------------------
Update Information:

Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj,
GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2,
GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and
GHSA-94p4-4cq8-9g67.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 23 2026 Benjamin A. Beasley [code@musicinmybrain.net] - 3.1.55-1
- Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj,
GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2,
GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and
GHSA-94p4-4cq8-9g67
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.1.50-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jun 3 2026 Python Maint - 3.1.50-2
- Rebuilt for Python 3.15
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8e8273f18f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: google-osconfig-agent-20260717.00-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9781489c3a
2026-07-26 00:57:16.867286+00:00
--------------------------------------------------------------------------------

Name : google-osconfig-agent
Product : Fedora 44
Version : 20260717.00
Release : 1.fc44
URL : https://github.com/GoogleCloudPlatform/osconfig
Summary : Google OS Config Agent
Description :
Google OS Config Agent

--------------------------------------------------------------------------------
Update Information:

Update to 20260717
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 17 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 20260717.00-1
- Update to 200260717 - Closes rhbz#2336973
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Tue Feb 3 2026 Maxwell G [maxwell@gtmx.me] - 20241029.01-8
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Sun Oct 12 2025 Maxwell G [maxwell@gtmx.me] - 20241029.01-6
- Rebuild for golang 1.25.2
* Fri Oct 10 2025 Alejandro Sáez [asm@redhat.com] - 20241029.01-5
- rebuild
* Fri Aug 15 2025 Maxwell G [maxwell@gtmx.me] - 20241029.01-4
- Rebuild for golang-1.25.0
* Thu Jul 24 2025 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Jan 17 2025 Fedora Release Engineering [releng@fedoraproject.org] - 20241029.01-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2434630 - google-osconfig-agent: FTBFS in Fedora rawhide/f44
https://bugzilla.redhat.com/show_bug.cgi?id$34630
[ 2 ] Bug #2486287 - CVE-2026-45287 google-osconfig-agent: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$86287
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9781489c3a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: xrdp-0.10.6.1-3.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9d3c766833
2026-07-26 00:57:16.867274+00:00
--------------------------------------------------------------------------------

Name : xrdp
Product : Fedora 44
Version : 0.10.6.1
Release : 3.fc44
URL : http://www.xrdp.org/
Summary : Open source remote desktop protocol (RDP) server
Description :
xrdp provides a fully functional RDP server compatible with a wide range
of RDP clients, including FreeRDP and Microsoft RDP client.

--------------------------------------------------------------------------------
Update Information:

Update PAM file to better match modern reality.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 18 2026 Bojan Smojver [bojan@rexursive.com] - 1:0.10.6.1-3
- Fix bug #2499948
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502969 - CVE-2026-54538 xrdp: infinite loop denial-of-service vulnerability during RDP packet processing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502969
[ 2 ] Bug #2502971 - CVE-2026-41521 xrdp: integer overflow leads to out-of-bounds read in vnc-any mode [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502971
[ 3 ] Bug #2502973 - CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502973
[ 4 ] Bug #2502974 - CVE-2026-55639 xrdp: improper input validation in MCS data processing leads to potential information leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502974
[ 5 ] Bug #2502977 - CVE-2026-55626 xrdp: missing authentication when xrdp launches Xvnc in UNIX domain socket mode [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502977
[ 6 ] Bug #2502978 - CVE-2026-55645 xrdp: out-of-bounds read in client control PDU processing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502978
[ 7 ] Bug #2502981 - CVE-2026-44978 xrdp: heap out-of-bounds read in non-TLS FIPS receive paths [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502981
[ 8 ] Bug #2502983 - CVE-2026-55238 xrdp: improper input validation in capability negotiation leads to denial of service [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502983
[ 9 ] Bug #2502985 - CVE-2026-42218 xrdp: timing side-channel allows username enumeration [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502985
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9d3c766833' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: moby-engine-29.6.2-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-70a4eeeab8
2026-07-26 00:57:16.867258+00:00
--------------------------------------------------------------------------------

Name : moby-engine
Product : Fedora 44
Version : 29.6.2
Release : 1.fc44
URL : https://github.com/moby/moby
Summary : The open-source application container engine
Description :
Docker is an open source project to build, ship and run any application as a
lightweight container.

Docker containers are both hardware-agnostic and platform-agnostic. This means
they can run anywhere, from your laptop to the largest EC2 compute instance and
everything in between — and they do not require you to use a particular
language, framework or packaging system. That makes them great building blocks
for deploying and scaling web apps, databases, and backend services without
depending on a particular stack or provider.

--------------------------------------------------------------------------------
Update Information:

Update to release v29.6.2
Resolves: rhbz#2496437
Upstream security fixes
GHSA-hw3h-2gp9-cxpv
GHSA-qx3x-mv6r-52p6
GHSA-32pv-7hq5-qhwq
GHSA-g2h8-426c-7976
GHSA-388v-wmr2-g2v2
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 16 2026 Bradley G Smith [bradley.g.smith@gmail.com] - 29.6.2-1
- Update to release v29.6.2
- Resolves: rhbz#2496437
- Upstream security fixes
- - GHSA-hw3h-2gp9-cxpv
- - GHSA-qx3x-mv6r-52p6
- - GHSA-32pv-7hq5-qhwq
- - GHSA-g2h8-426c-7976
- - GHSA-388v-wmr2-g2v2
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 29.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 26 2026 Bradley G Smith [bradley.g.smith@gmail.com] - 29.6.1-1
- Update to release v29.6.1
- Resolves: rhbz#2493405
- Upstream security fixes for: GHSA-mjcv-p78q-w5fw GHSA-jpcc-p29g-p8mq
GHSA-72x6-4j93-7w86 GHSA-7236-3392-c5c6
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2496437 - CVE-2026-47262 moby-engine: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$96437
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-70a4eeeab8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------