Fedora Linux 9174 Published by

New security updates have been made available for Fedora Linux, specifically for versions 42 and 41. For Fedora 42, updates include new versions of firefox, mingw-qt6-qtsvg, mingw-python3, runc, fetchmail, and possibly others. Meanwhile, Fedora 41 has also received updates for mingw-qt6-qtsvg, mingw-qt5-qtsvg, mingw-python3, runc, and fetchmail.

Fedora 42 Update: firefox-144.0-3.fc42
Fedora 42 Update: mingw-qt6-qtsvg-6.9.2-2.fc42
Fedora 42 Update: mingw-qt5-qtsvg-5.15.17-3.fc42
Fedora 42 Update: mingw-python3-3.11.14-1.fc42
Fedora 42 Update: runc-1.3.2-1.fc42
Fedora 42 Update: fetchmail-6.5.6-1.fc42
Fedora 41 Update: mingw-qt6-qtsvg-6.8.3-2.fc41
Fedora 41 Update: mingw-qt5-qtsvg-5.15.17-3.fc41
Fedora 41 Update: mingw-python3-3.11.14-1.fc41
Fedora 41 Update: runc-1.3.2-1.fc41
Fedora 41 Update: fetchmail-6.5.6-1.fc41



[SECURITY] Fedora 42 Update: firefox-144.0-3.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-64d57de006
2025-10-18 01:16:41.291847+00:00
--------------------------------------------------------------------------------

Name : firefox
Product : Fedora 42
Version : 144.0
Release : 3.fc42
URL : https://www.mozilla.org/firefox/
Summary : Mozilla Firefox Web browser
Description :
Mozilla Firefox is an open-source web browser, designed for standards
compliance, performance and portability.

--------------------------------------------------------------------------------
Update Information:

Added fix for mzbz#1990430 (crashes)
Updated to latest upstream (144.0)
--------------------------------------------------------------------------------
ChangeLog:

* Wed Oct 15 2025 Martin Stransky [stransky@redhat.com] - 144.0-3
- Add fix for mzbz#1990430
* Mon Oct 13 2025 Martin Stransky [stransky@redhat.com] - 144.0-2
- Updated to 144.0 (b2)
* Thu Oct 9 2025 Martin Stransky [stransky@redhat.com] - 144.0-1
- Updated to 144.0
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-64d57de006' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: mingw-qt6-qtsvg-6.9.2-2.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-d96ebe72de
2025-10-18 01:16:41.291834+00:00
--------------------------------------------------------------------------------

Name : mingw-qt6-qtsvg
Product : Fedora 42
Version : 6.9.2
Release : 2.fc42
URL : http://qt.io/
Summary : Qt6 for Windows - QtSvg component
Description :
This package contains the Qt software toolkit for developing
cross-platform applications.

This is the Windows version of Qt, for use in conjunction with the
Fedora Windows cross-compiler.

--------------------------------------------------------------------------------
Update Information:

Backport fix for CVE-2025-10729.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 6.9.2-2
- Backport fix for CVE-2025-10729
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402373 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402373
[ 2 ] Bug #2402374 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402374
[ 3 ] Bug #2402377 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402377
[ 4 ] Bug #2402378 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402378
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-d96ebe72de' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: mingw-qt5-qtsvg-5.15.17-3.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-d96ebe72de
2025-10-18 01:16:41.291834+00:00
--------------------------------------------------------------------------------

Name : mingw-qt5-qtsvg
Product : Fedora 42
Version : 5.15.17
Release : 3.fc42
URL : http://qt.io/
Summary : Qt5 for Windows - QtSvg component
Description :
This package contains the Qt software toolkit for developing
cross-platform applications.

This is the Windows version of Qt, for use in conjunction with the
Fedora Windows cross-compiler.

--------------------------------------------------------------------------------
Update Information:

Backport fix for CVE-2025-10729.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 5.15.17-3
- Backport patch for CVE-2025-10729
* Thu Jul 24 2025 Fedora Release Engineering [releng@fedoraproject.org] - 5.15.17-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402373 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402373
[ 2 ] Bug #2402374 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402374
[ 3 ] Bug #2402377 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402377
[ 4 ] Bug #2402378 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402378
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-d96ebe72de' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: mingw-python3-3.11.14-1.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-ccc3e0a219
2025-10-18 01:16:41.291829+00:00
--------------------------------------------------------------------------------

Name : mingw-python3
Product : Fedora 42
Version : 3.11.14
Release : 1.fc42
URL : https://www.python.org/
Summary : MinGW Windows python3
Description :
MinGW Windows python3

--------------------------------------------------------------------------------
Update Information:

Update to python-3.11.14, fixes CVE-2025-8291.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 3.11.14-1
- Update to 3.11.14
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402860 - CVE-2025-8291 mingw-python3: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402860
[ 2 ] Bug #2402870 - CVE-2025-8291 mingw-python3: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402870
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-ccc3e0a219' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: runc-1.3.2-1.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-c4d00e29b7
2025-10-18 01:16:41.291815+00:00
--------------------------------------------------------------------------------

Name : runc
Product : Fedora 42
Version : 1.3.2
Release : 1.fc42
URL : https://github.com/opencontainers/runc
Summary : CLI for running Open Containers
Description :
The runc command can be used to start containers which are packaged
in accordance with the Open Container Initiative's specifications,
and to manage containers running under runc.

--------------------------------------------------------------------------------
Update Information:

Update to release v1.3.2
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Bradley G Smith [bradley.g.smith@gmail.com] - 2:1.3.2-1
- Update to release v1.3.2
- Resolves: rhbz#2399284, rhbz#2399563
- Upstream fixes
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2399284 - CVE-2025-47906 runc: Unexpected paths returned from LookPath in os/exec [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2399284
[ 2 ] Bug #2399563 - CVE-2025-47906 runc: Unexpected paths returned from LookPath in os/exec [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2399563
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-c4d00e29b7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: fetchmail-6.5.6-1.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-ab3c40c1f4
2025-10-18 01:16:41.291788+00:00
--------------------------------------------------------------------------------

Name : fetchmail
Product : Fedora 42
Version : 6.5.6
Release : 1.fc42
URL : http://www.fetchmail.info/
Summary : A remote mail retrieval and forwarding utility
Description :
Fetchmail is a remote mail retrieval and forwarding utility intended
for use over on-demand TCP/IP links, like SLIP or PPP connections.
Fetchmail supports every remote-mail protocol currently in use on the
Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6,
and IPSEC) for retrieval. Then Fetchmail forwards the mail through
SMTP so you can read it through your favorite mail client.

Install fetchmail if you need to retrieve mail over SLIP or PPP
connections.

--------------------------------------------------------------------------------
Update Information:

Update to fetchmail-6.5.6 (CVE-2025-61962)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Vitezslav Crhonek [vcrhonek@redhat.com] - 6.5.6-1
- Update to fetchmail-6.5.6 (CVE-2025-61962)
Resolves: #2402010
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402010 - CVE-2025-61962 fetchmail: Fetchmail denial of service [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402010
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-ab3c40c1f4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: mingw-qt6-qtsvg-6.8.3-2.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-324c3261b1
2025-10-18 00:58:49.259055+00:00
--------------------------------------------------------------------------------

Name : mingw-qt6-qtsvg
Product : Fedora 41
Version : 6.8.3
Release : 2.fc41
URL : http://qt.io/
Summary : Qt6 for Windows - QtSvg component
Description :
This package contains the Qt software toolkit for developing
cross-platform applications.

This is the Windows version of Qt, for use in conjunction with the
Fedora Windows cross-compiler.

--------------------------------------------------------------------------------
Update Information:

Backport fix for CVE-2025-10729.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 6.8.3-2
- Backport fix for CVE-2025-10729
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402373 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402373
[ 2 ] Bug #2402374 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402374
[ 3 ] Bug #2402377 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402377
[ 4 ] Bug #2402378 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402378
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-324c3261b1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: mingw-qt5-qtsvg-5.15.17-3.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-324c3261b1
2025-10-18 00:58:49.259055+00:00
--------------------------------------------------------------------------------

Name : mingw-qt5-qtsvg
Product : Fedora 41
Version : 5.15.17
Release : 3.fc41
URL : http://qt.io/
Summary : Qt5 for Windows - QtSvg component
Description :
This package contains the Qt software toolkit for developing
cross-platform applications.

This is the Windows version of Qt, for use in conjunction with the
Fedora Windows cross-compiler.

--------------------------------------------------------------------------------
Update Information:

Backport fix for CVE-2025-10729.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 5.15.17-3
- Backport patch for CVE-2025-10729
* Thu Jul 24 2025 Fedora Release Engineering [releng@fedoraproject.org] - 5.15.17-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402373 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402373
[ 2 ] Bug #2402374 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402374
[ 3 ] Bug #2402377 - CVE-2025-10729 mingw-qt5-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402377
[ 4 ] Bug #2402378 - CVE-2025-10729 mingw-qt6-qtsvg: Use-after-free vulnerability in Qt SVG [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402378
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-324c3261b1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: mingw-python3-3.11.14-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-d94c21c98f
2025-10-18 00:58:49.259053+00:00
--------------------------------------------------------------------------------

Name : mingw-python3
Product : Fedora 41
Version : 3.11.14
Release : 1.fc41
URL : https://www.python.org/
Summary : MinGW Windows python3
Description :
MinGW Windows python3

--------------------------------------------------------------------------------
Update Information:

Update to python-3.11.14, fixes CVE-2025-8291.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Sandro Mani [manisandro@gmail.com] - 3.11.14-1
- Update to 3.11.14
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402860 - CVE-2025-8291 mingw-python3: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402860
[ 2 ] Bug #2402870 - CVE-2025-8291 mingw-python3: Python zipfile End of Central Directory (EOCD) Locator record offset not checked [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2402870
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-d94c21c98f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: runc-1.3.2-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-c2fa2eb17c
2025-10-18 00:58:49.259047+00:00
--------------------------------------------------------------------------------

Name : runc
Product : Fedora 41
Version : 1.3.2
Release : 1.fc41
URL : https://github.com/opencontainers/runc
Summary : CLI for running Open Containers
Description :
The runc command can be used to start containers which are packaged
in accordance with the Open Container Initiative's specifications,
and to manage containers running under runc.

--------------------------------------------------------------------------------
Update Information:

Update to release v1.3.2
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Bradley G Smith [bradley.g.smith@gmail.com] - 2:1.3.2-1
- Update to release v1.3.2
- Resolves: rhbz#2399284, rhbz#2399563
- Upstream fixes
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2399284 - CVE-2025-47906 runc: Unexpected paths returned from LookPath in os/exec [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2399284
[ 2 ] Bug #2399563 - CVE-2025-47906 runc: Unexpected paths returned from LookPath in os/exec [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2399563
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-c2fa2eb17c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: fetchmail-6.5.6-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-fa8d0fb866
2025-10-18 00:58:49.259029+00:00
--------------------------------------------------------------------------------

Name : fetchmail
Product : Fedora 41
Version : 6.5.6
Release : 1.fc41
URL : http://www.fetchmail.info/
Summary : A remote mail retrieval and forwarding utility
Description :
Fetchmail is a remote mail retrieval and forwarding utility intended
for use over on-demand TCP/IP links, like SLIP or PPP connections.
Fetchmail supports every remote-mail protocol currently in use on the
Internet (POP2, POP3, RPOP, APOP, KPOP, all IMAPs, ESMTP ETRN, IPv6,
and IPSEC) for retrieval. Then Fetchmail forwards the mail through
SMTP so you can read it through your favorite mail client.

Install fetchmail if you need to retrieve mail over SLIP or PPP
connections.

--------------------------------------------------------------------------------
Update Information:

Update to fetchmail-6.5.6 (CVE-2025-61962)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 9 2025 Vitezslav Crhonek [vcrhonek@redhat.com] - 6.5.6-1
- Update to fetchmail-6.5.6 (CVE-2025-61962)
Resolves: #2402009
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2402009 - CVE-2025-61962 fetchmail: Fetchmail denial of service [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2402009
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-fa8d0fb866' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--