Fedora Linux 9440 Published by

Fedora distributed security updates for goaccess, NSD, and BorgBackup across the Fedora 43 and 44 platforms. The goaccess release jumps to version 1.11, delivering a roughly 20 percent drop in memory consumption, a 35 percent parsing speed increase, and patches for heap overflows alongside visitor tracking inaccuracies. NSD advanced to version 4.15.0 with hardening against several critical vulnerabilities, including client certificate verification bypasses over TLS and multiple buffer overflow flaws triggered by malformed DNS records. BorgBackup received its 1.4.5 release specifically to resolve CVE-2026-62268 for the deduplicating backup utility.

Fedora 43 Update: goaccess-1.11-1.fc43
Fedora 43 Update: nsd-4.15.0-1.fc43
Fedora 44 Update: borgbackup-1.4.5-1.fc44
Fedora 44 Update: goaccess-1.11-1.fc44




[SECURITY] Fedora 43 Update: goaccess-1.11-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a488a993d1
2026-08-03 01:04:56.884873+00:00
--------------------------------------------------------------------------------

Name : goaccess
Product : Fedora 43
Version : 1.11
Release : 1.fc43
URL : https://goaccess.io/
Summary : Real-time web log analyzer and interactive viewer
Description :
GoAccess is a real-time web log analyzer and interactive viewer that runs in a
terminal in *nix systems. It provides fast and valuable HTTP statistics for
system administrators that require a visual server report on the fly.

Features:
GoAccess parses the specified web log file and outputs the data to terminal.

* General statistics, bandwidth, etc.
* Time taken to serve the request (useful to track pages that are slowing down
your site).
* Metrics for cumulative, average and slowest running requests.
* Top visitors.
* Requested files & static files.
* 404 or Not Found.
* Hosts, Reverse DNS, IP Location.
* Operating Systems.
* Browsers and Spiders.
* Referring Sites & URLs.
* Keyphrases.
* Geo Location - Continent/Country/City.
* Visitors Time Distribution.
* HTTP Status Codes.
* Ability to output JSON and CSV.
* Tailor GoAccess to suit your own color taste/schemes.
* Support for large datasets + data persistence.
* Support for IPv6.
* Output statistics to HTML.
and more...

GoAccess allows any custom log format string. Predefined options include, but
not limited to:

* Amazon CloudFront (Download Distribution).
* AWS Elastic Load Balancing.
* Apache/Nginx Common/Combined + VHosts.
* Google Cloud Storage.
* W3C format (IIS).

--------------------------------------------------------------------------------
Update Information:

Update to goaccess 1.11.
Notable fixes:
- Fixed a heap buffer overflow when parsing malformed Opera user agents
- Fixed an infinite loop while writing log parsing errors from multiple input
files
- Fixed unique visitor undercounting caused by key collisions
- Fixed city lookups ignoring the City database when Country was listed first
Also includes: automatic crash-safe migration to storage format v3, ~20% lower
storage memory usage and ~35% faster parsing, fullscreen geolocation map
controls in the HTML report, and Traditional Chinese translation.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 25 2026 Eduardo Echeverria [echevemaster@gmail.com] - 1.11-1
- Update to 1.11. Fixes rhbz#2502800
- Added automatic, crash-safe migration of persisted databases to storage
format version 3
- Added configured zlib and AddressSanitizer options to the version output
- Added fullscreen expand and collapse controls to geolocation maps in the
HTML report
- Added Traditional Chinese translation
- Expanded Debian package builds to Ubuntu 26.04 and additional
architectures, and updated the packaging workflow actions
- Fixed a heap buffer overflow when parsing malformed Opera user agents
- Fixed an infinite loop while writing log parsing errors from multiple
input files
- Fixed city lookups ignoring the City database when a Country database was
listed first
- Fixed geolocation maps appearing grey after restoring persisted city data
- Fixed .gz file extensions being interpreted as macros in the man page
- Fixed iOS version parsing from user-agent strings
- Fixed unique visitor undercounting caused by collisions between reversed
data and visitor key pairs
- Fixed WebSocket payload size checks for large and fragmented messages
- Grouped Lynx, Links, ELinks, w3m and Chawan under a new "Text-based"
browser category
- Reduced storage memory usage by about 20% and parsing time by about 35%
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502800 - goaccess-1.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502800
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a488a993d1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: nsd-4.15.0-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0b77a23312
2026-08-03 01:04:56.884850+00:00
--------------------------------------------------------------------------------

Name : nsd
Product : Fedora 43
Version : 4.15.0
Release : 1.fc43
URL : http://www.nlnetlabs.nl/nsd/
Summary : Fast and lean authoritative DNS Name Server
Description :
NSD is a complete implementation of an authoritative DNS name server.
For further information about what NSD is and what NSD is not please
consult the REQUIREMENTS document which is a part of this distribution.

--------------------------------------------------------------------------------
Update Information:

FEATURES:
Merge #483 from ruuda: Improve Prometheus metrics: Move zonestats from metric
name to label
BUG FIXES:
Fix #478: Feature request: reduce syslog noise from frequent read-only control
commands (e.g. stats_noreset). It logs the verbosity command always, and others
at 2 and higher.
Fix XDP cleanup code being executed even if xdp is not configured
Merge #481 from jaredmauch: Fix pedantic/CodeQL warning in sources
Merge #484 from orlitzky: OpenRC: fix network deps and support both supervisors
Fix PROXYv2 header read and consume, it checks the header size.
Thanks to Qifan Zhang, Palo Alto Networks for the report.
Fix notify relay ipc to check for large size. This stops desync of the internal
notify pipe.
Thanks to Qifan Zhang, Palo Alto Networks for the report.
Fix print of malformed HIP records.
Thanks to Qifan Zhang, Palo Alto Networks, for the report, and Haruki Oyama
(Waseda University) for also reporting this issue.
Fix to not fail on NSEC3 records with a bad owner name.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix print of NXT RR without bitmap
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix overflow for NSEC3 zones with 255-octet name
Thanks to Haruki Oyama (Waseda University) for the report, and Qifan Zhang, Palo
Alto Networks, for also reporting this issue.
Fix to update github ci actions/checkout to v7.
Fix notify and zone transfer processing for malformed SOA records, with a short
rdata content. It stops an assertion failure.
Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report.
Fix that wrong buffer position in IXFR for the first SOA causes the storage to
retrieve wrong information. Later data would overwrite it so it did not cause
observable trouble.
Thanks to Tristan Madani (@TristanInSec) from Talence Security for the report.
More robust removing of RRs from an IXFR processing.
Thanks zhangph for reporting this issue
Fix unit test for stopmany for process role logs.
Fix nsd-control assoc_tsig, if that interrupts a zone transfer in progress, to
not crash. It restarts the transfer from the primary.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix nsd-control del_tsig, if that interrupts a zone transfer in progress, to not
crash. It does not delete the key, if in use.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix catalog producer zone with long name, so that it does not crash on that.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix catalog consumer zone with long name for member unique label that is long,
so that it does not crash on that.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix that non-IN-class records cause a zone transfer to be rejected. Also such
records are not added from a transfer. This stops an assertion failure.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix to disallow a SOA record in the middle of an AXFR. This stops an assertion
failure.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix to set zone is_secure to false when IXFR removes RRSIG DNSKEY.
This stops an assertion failure. Also fix soa and ns rrset change in IXFR when
packed rrsets are disabled.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix to handle NSEC3 zones without space for hashes. Zones with a apex domain
name length >= 223 bytes, that have a NSEC3PARAM must not be prehashed, since
the hashed owner name would not fit.
Thanks Qifan Zhang, Palo Alto Networks, for the report
Fix to add hardening to zone_ixfr_remove_oldest, for IXFR processing.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix for xfrd crash with too short response to a UDP SOA query Only for release
builds and only when configured for XFR over UDP
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix that out-of-zone records are skipped from zone transfers.
Otherwise such records could stick around after zone deletion and cause failures
for DS queries.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 25 2026 Fabio Alessandro Locati [mail@fale.io] - 4.15.0-1
- Update to 4.15.0. Fixes rhbz#2497645
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.14.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2494181 - CVE-2026-12490 nsd: Bypass of client certificate verification with transfer over TLS [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494181
[ 2 ] Bug #2494182 - CVE-2026-12490 nsd: Bypass of client certificate verification with transfer over TLS [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494182
[ 3 ] Bug #2494183 - CVE-2026-12246 nsd: Out of bounds stack write with crafted APL RR [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494183
[ 4 ] Bug #2494184 - CVE-2026-12246 nsd: Out of bounds stack write with crafted APL RR [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494184
[ 5 ] Bug #2494185 - CVE-2026-12245 nsd: Denial of DNS over TLS service by any DoT client [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494185
[ 6 ] Bug #2494186 - CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494186
[ 7 ] Bug #2494187 - CVE-2026-12245 nsd: Denial of DNS over TLS service by any DoT client [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494187
[ 8 ] Bug #2494188 - CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494188
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0b77a23312' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: borgbackup-1.4.5-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-5cc233b0ea
2026-08-03 00:44:39.405490+00:00
--------------------------------------------------------------------------------

Name : borgbackup
Product : Fedora 44
Version : 1.4.5
Release : 1.fc44
URL : https://borgbackup.readthedocs.org
Summary : A deduplicating backup program with compression and authenticated encryption
Description :
BorgBackup (short: Borg) is a deduplicating backup program. Optionally, it
supports compression and authenticated encryption.

--------------------------------------------------------------------------------
Update Information:

new bugfix release, contains a fix for CVE-2026-62268
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 25 2026 Felix Schwarz [fschwarz@fedoraproject.org] - 1.4.5-1
- update to 1.4.5
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502134 - borgbackup-1.4.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502134
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-5cc233b0ea' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: goaccess-1.11-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b1c2d1af74
2026-08-03 00:44:39.405482+00:00
--------------------------------------------------------------------------------

Name : goaccess
Product : Fedora 44
Version : 1.11
Release : 1.fc44
URL : https://goaccess.io/
Summary : Real-time web log analyzer and interactive viewer
Description :
GoAccess is a real-time web log analyzer and interactive viewer that runs in a
terminal in *nix systems. It provides fast and valuable HTTP statistics for
system administrators that require a visual server report on the fly.

Features:
GoAccess parses the specified web log file and outputs the data to terminal.

* General statistics, bandwidth, etc.
* Time taken to serve the request (useful to track pages that are slowing down
your site).
* Metrics for cumulative, average and slowest running requests.
* Top visitors.
* Requested files & static files.
* 404 or Not Found.
* Hosts, Reverse DNS, IP Location.
* Operating Systems.
* Browsers and Spiders.
* Referring Sites & URLs.
* Keyphrases.
* Geo Location - Continent/Country/City.
* Visitors Time Distribution.
* HTTP Status Codes.
* Ability to output JSON and CSV.
* Tailor GoAccess to suit your own color taste/schemes.
* Support for large datasets + data persistence.
* Support for IPv6.
* Output statistics to HTML.
and more...

GoAccess allows any custom log format string. Predefined options include, but
not limited to:

* Amazon CloudFront (Download Distribution).
* AWS Elastic Load Balancing.
* Apache/Nginx Common/Combined + VHosts.
* Google Cloud Storage.
* W3C format (IIS).

--------------------------------------------------------------------------------
Update Information:

Update to goaccess 1.11.
Notable fixes:
- Fixed a heap buffer overflow when parsing malformed Opera user agents
- Fixed an infinite loop while writing log parsing errors from multiple input
files
- Fixed unique visitor undercounting caused by key collisions
- Fixed city lookups ignoring the City database when Country was listed first
Also includes: automatic crash-safe migration to storage format v3, ~20% lower
storage memory usage and ~35% faster parsing, fullscreen geolocation map
controls in the HTML report, and Traditional Chinese translation.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 25 2026 Eduardo Echeverria [echevemaster@gmail.com] - 1.11-1
- Update to 1.11. Fixes rhbz#2502800
- Added automatic, crash-safe migration of persisted databases to storage
format version 3
- Added configured zlib and AddressSanitizer options to the version output
- Added fullscreen expand and collapse controls to geolocation maps in the
HTML report
- Added Traditional Chinese translation
- Expanded Debian package builds to Ubuntu 26.04 and additional
architectures, and updated the packaging workflow actions
- Fixed a heap buffer overflow when parsing malformed Opera user agents
- Fixed an infinite loop while writing log parsing errors from multiple
input files
- Fixed city lookups ignoring the City database when a Country database was
listed first
- Fixed geolocation maps appearing grey after restoring persisted city data
- Fixed .gz file extensions being interpreted as macros in the man page
- Fixed iOS version parsing from user-agent strings
- Fixed unique visitor undercounting caused by collisions between reversed
data and visitor key pairs
- Fixed WebSocket payload size checks for large and fragmented messages
- Grouped Lynx, Links, ELinks, w3m and Chawan under a new "Text-based"
browser category
- Reduced storage memory usage by about 20% and parsing time by about 35%
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502800 - goaccess-1.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502800
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b1c2d1af74' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new