Fedora Linux 9251 Published by

Fedora has released an update for the fvwm3 package to fix a Denial-of-Service vulnerability (CVE-2025-65637) caused by large single-line payloads. The updated version is 1.1.4-4.fc42 and 1.1.4-4.fc43 for Fedora 42 and 43, respectively. Users are recommended to upgrade their fvwm3 packages using the "dnf" update program with the command su -c 'dnf upgrade --advisory FEDORA-2026-439af2cc95' or su -c 'dnf upgrade --advisory FEDORA-2026-adbfebd04b'.

Fedora 42 Update: fvwm3-1.1.4-4.fc42
Fedora 43 Update: fvwm3-1.1.4-4.fc43




[SECURITY] Fedora 42 Update: fvwm3-1.1.4-4.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-439af2cc95
2026-02-19 01:32:15.376833+00:00
--------------------------------------------------------------------------------

Name : fvwm3
Product : Fedora 42
Version : 1.1.4
Release : 4.fc42
URL : https://www.fvwm.org/
Summary : Highly configurable multiple virtual desktop window manager
Description :
Fvwm is a window manager for X11. It is designed to minimize memory
consumption, provide a 3D look to window frames, and implement a virtual
desktop.

--------------------------------------------------------------------------------
Update Information:

Fix CVE-2025-65637.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb 10 2026 Peter Lemenkov [lemenkov@gmail.com] - 1.1.4-4
- Fix for CVE-2025-65637
* Mon Feb 2 2026 Maxwell G [maxwell@gtmx.me] - 1.1.4-3
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.1.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2422175 - CVE-2025-65637 fvwm3: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2422175
[ 2 ] Bug #2422195 - CVE-2025-65637 fvwm3: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2422195
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-439af2cc95' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: fvwm3-1.1.4-4.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-adbfebd04b
2026-02-19 01:11:53.711612+00:00
--------------------------------------------------------------------------------

Name : fvwm3
Product : Fedora 43
Version : 1.1.4
Release : 4.fc43
URL : https://www.fvwm.org/
Summary : Highly configurable multiple virtual desktop window manager
Description :
Fvwm is a window manager for X11. It is designed to minimize memory
consumption, provide a 3D look to window frames, and implement a virtual
desktop.

--------------------------------------------------------------------------------
Update Information:

Fix CVE-2025-65637.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Feb 10 2026 Peter Lemenkov [lemenkov@gmail.com] - 1.1.4-4
- Fix for CVE-2025-65637
* Mon Feb 2 2026 Maxwell G [maxwell@gtmx.me] - 1.1.4-3
- Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.1.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2422175 - CVE-2025-65637 fvwm3: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2422175
[ 2 ] Bug #2422195 - CVE-2025-65637 fvwm3: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2422195
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-adbfebd04b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new