Fedora 44 Update: kernel-7.1.4-204.fc44
Fedora 44 Update: llvm-22.1.8-4.fc44
Fedora 44 Update: fractal-14.1-1.fc44
Fedora 44 Update: srt-1.5.6-1.fc44
Fedora 44 Update: libssh-0.12.1-1.fc44
Fedora 44 Update: chromium-150.0.7871.128-1.fc44
Fedora 44 Update: nginx-mod-vts-0.2.4-13.fc44
Fedora 44 Update: perl-DBI-1.651-1.fc44
Fedora 44 Update: nginx-mod-headers-more-0.40-3.fc44
Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
Fedora 44 Update: nginx-mod-naxsi-1.6-21.fc44
Fedora 44 Update: nginx-mod-fancyindex-0.6.0-8.fc44
Fedora 44 Update: nginx-mod-modsecurity-1.0.4-16.fc44
Fedora 44 Update: nginx-1.30.4-1.fc44
Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-13.fc44
Fedora 44 Update: perl-YAML-Syck-1.47-1.fc44
Fedora 44 Update: collectl-4.3.20.3-1.fc44
Fedora 43 Update: kernel-7.1.4-104.fc43
Fedora 43 Update: fractal-14.1-1.fc43
Fedora 43 Update: libssh-0.11.5-1.fc43
Fedora 43 Update: srt-1.5.6-1.fc43
Fedora 43 Update: chromium-150.0.7871.128-1.fc43
Fedora 43 Update: perl-DBI-1.651-1.fc43
Fedora 43 Update: perl-YAML-Syck-1.47-1.fc43
Fedora 43 Update: collectl-4.3.20.3-1.fc43
[SECURITY] Fedora 44 Update: kernel-7.1.4-204.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2b94d8d05c
2026-07-23 01:18:29.467256+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 44
Version : 7.1.4
Release : 204.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for
issues with exploits in the wild.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-4]
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-3]
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim)
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2b94d8d05c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: llvm-22.1.8-4.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-597e8f9de1
2026-07-23 01:18:29.467240+00:00
--------------------------------------------------------------------------------
Name : llvm
Product : Fedora 44
Version : 22.1.8
Release : 4.fc44
URL : http://llvm.org
Summary : The Low Level Virtual Machine
Description :
LLVM is a compiler infrastructure designed for compile-time, link-time,
runtime, and idle-time optimization of programs from arbitrary programming
languages. The compiler infrastructure includes mirror sets of programming
tools as well as libraries with equivalent functionality.
--------------------------------------------------------------------------------
Update Information:
Backport fixes from LLVM 23
Fix an issue that could cause a buffer overflow when reading a corrupted bitcode
file.
Fix a miscompilation known to affect rust applications.
Fix a miscompilation in x86 vectorized code.
Fix 2 issues in LLD.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-4
- More backported fixes
* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-3
- Fix miscompilation
* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-2
- Fix buffer overflow
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2496390 - CVE-2026-13574 llvm: LLVM: Denial of service via heap-based buffer overflow in Bitcode File Handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496390
[ 2 ] Bug #2499684 - miscompilation that leads to segfaults with Rust 1.97.0
https://bugzilla.redhat.com/show_bug.cgi?id=2499684
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-597e8f9de1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: fractal-14.1-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-600530ae91
2026-07-23 01:18:29.467244+00:00
--------------------------------------------------------------------------------
Name : fractal
Product : Fedora 44
Version : 14.1
Release : 1.fc44
URL : https://gitlab.gnome.org/World/fractal
Summary : Matrix group messaging app
Description :
Fractal is a Matrix messaging app for GNOME written in Rust. Its interface is
optimized for collaboration in large groups, such as free software projects.
--------------------------------------------------------------------------------
Update Information:
14.1
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Gwyn Ciesla [gwync@protonmail.com] - 14.1-1
- 14.1
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 14-0.beta.2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 14-0.beta.1
- Rebuilt for openssl 4.0
* Wed Apr 1 2026 Gwyn Ciesla [gwync@protonmail.com] - 14-0.beta
- 14 beta
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2420427 - CVE-2025-66622 fractal: matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420427
[ 2 ] Bug #2423493 - fractal: webp crate may expose memory contents [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2423493
[ 3 ] Bug #2438128 - CVE-2026-25727 fractal: time affected by a stack exhaustion denial of service attack [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2438128
[ 4 ] Bug #2502176 - fractal-14.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502176
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-600530ae91' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: srt-1.5.6-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-45ce54d51e
2026-07-23 01:18:29.467242+00:00
--------------------------------------------------------------------------------
Name : srt
Product : Fedora 44
Version : 1.5.6
Release : 1.fc44
URL : https://www.srtalliance.org
Summary : Secure Reliable Transport protocol tools
Description :
Secure Reliable Transport (SRT) is an open source transport technology that
optimizes streaming performance across unpredictable networks, such as
the Internet.
--------------------------------------------------------------------------------
Update Information:
Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 21 2026 Yanko Kaneti [yaneti@declera.com] - 1.5.6-1
- Update to 1.5.6
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-45ce54d51e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: libssh-0.12.1-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0e46c91ccf
2026-07-23 01:18:29.467232+00:00
--------------------------------------------------------------------------------
Name : libssh
Product : Fedora 44
Version : 0.12.1
Release : 1.fc44
URL : http://www.libssh.org
Summary : A library implementing the SSH protocol
Description :
The ssh library was designed to be used by programmers needing a working SSH
implementation by the mean of a library. The complete control of the client is
made by the programmer. With libssh, you can remotely execute programs, transfer
files, use a secure and transparent tunnel for your remote programs. With its
Secure FTP implementation, you can play with remote files easily, without
third-party programs others than libcrypto (from openssl).
--------------------------------------------------------------------------------
Update Information:
New upstream security release
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 21 2026 Jakub Jelen [jjelen@redhat.com] - 0.12.1-1
- New upstream security release
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.12.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 0.12.0-3
- Rebuilt for openssl 4.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2503148 - libssh-0.12.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2503148
[ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503651
[ 3 ] Bug #2503656 - CVE-2026-59842 libssh: libssh: information disclosure via short GSSAPI Curve25519 public key [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503656
[ 4 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503657
[ 5 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503658
[ 6 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503668
[ 7 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503669
[ 8 ] Bug #2503671 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503671
[ 9 ] Bug #2503673 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503673
[ 10 ] Bug #2503674 - CVE-2026-59849 libssh: libssh: denial of service via automatic certificate authentication loop [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503674
[ 11 ] Bug #2503675 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503675
[ 12 ] Bug #2503676 - CVE-2026-59851 libssh: libssh: authentication bypass via missing GSSAPI principal check [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503676
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0e46c91ccf' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: chromium-150.0.7871.128-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-310f620a68
2026-07-23 01:18:29.467228+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 44
Version : 150.0.7871.128
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Than Ngo [than@redhat.com] - 150.0.7871.128-1
- Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
- Fix rhbz#2501811, Drop AI policy which breaks DoH settings
- Improve auto darkmode
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-310f620a68' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-vts-0.2.4-13.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-vts
Product : Fedora 44
Version : 0.2.4
Release : 13.fc44
URL : https://github.com/vozlt/nginx-module-vts
Summary : Nginx virtual host traffic status module
Description :
Nginx virtual host traffic status module.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.2.4-13
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.2.4-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: perl-DBI-1.651-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1c5ffc6018
2026-07-23 01:18:29.467220+00:00
--------------------------------------------------------------------------------
Name : perl-DBI
Product : Fedora 44
Version : 1.651
Release : 1.fc44
URL : http://dbi.perl.org/
Summary : A database access API for perl
Description :
DBI is a database access Application Programming Interface (API) for
the Perl Language. The DBI API Specification defines a set of
functions, variables and conventions that provide a consistent
database interface independent of the actual database being used.
--------------------------------------------------------------------------------
Update Information:
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and
CVE-2026-60081
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.651-1
- 1.651 bump (rhbz#2499925) - Fix CVE-2026-15043, CVE-2026-15392,
CVE-2026-60082 and CVE-2026-60081
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499925 - perl-DBI-1.651 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2499925
[ 2 ] Bug #2501259 - CVE-2026-14380 perl-DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501259
[ 3 ] Bug #2501286 - CVE-2026-15392 perl-DBI: DBD::File: Arbitrary file read/write via symlink vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501286
[ 4 ] Bug #2501292 - CVE-2026-15043 perl-DBI: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501292
[ 5 ] Bug #2501293 - CVE-2026-60081 perl-DBI: DBI::ProfileData: Denial of Service due to unbounded path index [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501293
[ 6 ] Bug #2501294 - CVE-2026-60082 perl-DBI: perl-DBI: Denial of Service via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501294
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1c5ffc6018' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-headers-more-0.40-3.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-headers-more
Product : Fedora 44
Version : 0.40
Release : 3.fc44
URL : https://github.com/openresty/headers-more-nginx-module
Summary : This module allows adding, setting, or clearing specified input/output headers
Description :
This module allows adding, setting, or clearing specified input/output headers.
This is an enhanced version of the standard headers module because it provides
more utilities like resetting or clearing "builtin headers" like Content-Type,
Content-Length, and Server.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.40-3
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.40-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-js-challenge
Product : Fedora 44
Version : 0^20230517.gitda6852d
Release : 11.fc44
URL : https://github.com/simon987/ngx_http_js_challenge_module
Summary : Simple JavaScript proof-of-work based access for Nginx with virtually no overhead
Description :
Simple JavaScript proof-of-work based access for Nginx with virtually no overhead.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0^20230517.gitda6852d-11
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0^20230517.gitda6852d-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-naxsi-1.6-21.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-naxsi
Product : Fedora 44
Version : 1.6
Release : 21.fc44
URL : https://github.com/wargio/naxsi
Summary : nginx web application firewall module
Description :
naxsi is an nginx module that provides score based Web Application Firewall
(WAF) abilities in a highly granular fashion.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.6-21
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.6-20
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-fancyindex-0.6.0-8.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-fancyindex
Product : Fedora 44
Version : 0.6.0
Release : 8.fc44
URL : https://github.com/aperezdc/ngx-fancyindex
Summary : Nginx FancyIndex module
Description :
The Fancy Index module makes possible the generation of file listings,
like the built-in autoindex module does, but adding a touch of style.
This is possible because the module allows a certain degree of
customization of the generated content:
* Custom headers. Either local or stored remotely.
* Custom footers. Either local or stored remotely.
* Add you own CSS style rules.
* Allow choosing to sort elements by name (default),
modification time, or size; both ascending (default),
or descending.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.6.0-8
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.6.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-modsecurity-1.0.4-16.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-modsecurity
Product : Fedora 44
Version : 1.0.4
Release : 16.fc44
URL : https://github.com/SpiderLabs/ModSecurity-nginx
Summary : ModSecurity v3 nginx connector
Description :
The ModSecurity-nginx connector is the connection point between nginx and
libmodsecurity (ModSecurity v3). Said another way, this project provides a
communication channel between nginx and libmodsecurity. This connector is
required to use LibModSecurity with nginx.
The ModSecurity-nginx connector takes the form of an nginx module. The module
simply serves as a layer of communication between nginx and ModSecurity
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.0.4-16
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.0.4-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jul 8 2026 Joe Orton [jorton@redhat.com] - 1.0.4-14
- Rebuild.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-1.30.4-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx
Product : Fedora 44
Version : 1.30.4
Release : 1.fc44
URL : https://nginx.org
Summary : A high performance web server and reverse proxy server
Description :
Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and
IMAP protocols, with a strong focus on high concurrency, performance and low
memory usage.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 2:1.30.4-1
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2:1.30.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-13.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------
Name : nginx-mod-brotli
Product : Fedora 44
Version : 1.0.0~rc
Release : 13.fc44
URL : https://github.com/google/ngx_brotli
Summary : NGINX module for Brotli compression
Description :
NGINX module for Brotli compression.
--------------------------------------------------------------------------------
Update Information:
nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.0.0~rc-13
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.0.0~rc-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: perl-YAML-Syck-1.47-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2139aa7dce
2026-07-23 01:18:29.467144+00:00
--------------------------------------------------------------------------------
Name : perl-YAML-Syck
Product : Fedora 44
Version : 1.47
Release : 1.fc44
URL : https://metacpan.org/release/YAML-Syck
Summary : Fast, lightweight YAML loader and dumper
Description :
This module provides a Perl interface to the libsyck data serialization
library. It exports the Dump and Load functions for converting Perl data
structures to YAML strings, and the other way around.
--------------------------------------------------------------------------------
Update Information:
This update addresses four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags:
CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder caused by
signed-char indexing of the decode table on !!binary input
CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared between
the node and the anchors table
CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer newline scan
during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683)
CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an anchor node
on anchor redefinition, a remote-crash DoS from a 7-byte input
There are also a few other bug-fixes included.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Paul Howarth - 1.47-1
- Update to 1.47
Security:
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags (GH#213)
- CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
- CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared
between the node and the anchors table
- CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on
to CVE-2025-11683)
- CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an
anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input
- Harden syck_base64dec() to bounds-check each read so it cannot run past a
non-NUL-terminated input buffer (defense-in-depth for callers passing raw
buffers; GH#213)
Bug Fixes:
- Fix: Enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply
nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512,
matching Dump (GH#204)
- Fix: Emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in
Dump so they roundtrip with ImplicitTyping instead of reloading as plain
strings (GH#201)
Maintenance:
- CI: add an AddressSanitizer job that builds the XS with
-fsanitize=address and runs the suite plus the CVE trigger inputs to catch
libsyck memory-safety defects; de-pin the libasan version so it tracks the
runner's GCC (GH#213)
* Mon May 25 2026 Paul Howarth - 1.46-1
- Update to 1.46
Bug Fixes:
- Preserve string nature of numeric-looking values in Dump; pure strings (POK
only, no IOK/NOK) are now quoted to maintain roundtrip fidelity
(GH#199, GH#200)
- Accept trailing commas in flow sequences and mappings ([a, b,] and
{a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH#195, GH#196)
Maintenance:
- CI: upgrade install-with-cpm to v2 for compatibility with Perl versions
prior to 5.24 in perldocker containers (GH#197, GH#198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries,
exclude .claude/ from distribution
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501651 - CVE-2026-57075 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read in base64 decoder [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501651
[ 2 ] Bug #2501653 - CVE-2026-57077 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501653
[ 3 ] Bug #2501654 - CVE-2026-57076 perl-YAML-Syck: YAML::Syck: Heap use-after-free via anchor name reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501654
[ 4 ] Bug #2501656 - CVE-2026-13713 perl-YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501656
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2139aa7dce' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: collectl-4.3.20.3-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-71a9784a57
2026-07-23 01:18:29.467136+00:00
--------------------------------------------------------------------------------
Name : collectl
Product : Fedora 44
Version : 4.3.20.3
Release : 1.fc44
URL : https://github.com/sharkcz/collectl
Summary : A utility to collect various Linux performance data
Description :
A utility to collect Linux performance data
--------------------------------------------------------------------------------
Update Information:
handle insecure code properly in colmux
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Dan HorĂ¡k - 4.3.20.3-1
- upgrade to upstream version 4.3.20.3 (rhbz#2438007)
* Fri Feb 6 2026 Carl George [carlwgeorge@fedoraproject.org] - 4.3.20.1-1
- Update to version 4.3.20.1 rhbz#2149728
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2438007 - collectl-4.3.20.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id$38007
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-71a9784a57' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: kernel-7.1.4-104.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6503a6a639
2026-07-23 01:01:59.493964+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 43
Version : 7.1.4
Release : 104.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for
issues with exploits in the wild.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-4]
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-3]
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim)
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6503a6a639' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: fractal-14.1-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9630be304f
2026-07-23 01:01:59.493962+00:00
--------------------------------------------------------------------------------
Name : fractal
Product : Fedora 43
Version : 14.1
Release : 1.fc43
URL : https://gitlab.gnome.org/World/fractal
Summary : Matrix group messaging app
Description :
Fractal is a Matrix messaging app for GNOME written in Rust. Its interface is
optimized for collaboration in large groups, such as free software projects.
--------------------------------------------------------------------------------
Update Information:
14.1
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Gwyn Ciesla [gwync@protonmail.com] - 14.1-1
- 14.1
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 14-0.beta.2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 14-0.beta.1
- Rebuilt for openssl 4.0
* Wed Apr 1 2026 Gwyn Ciesla [gwync@protonmail.com] - 14-0.beta
- 14 beta
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2420427 - CVE-2025-66622 fractal: matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420427
[ 2 ] Bug #2423493 - fractal: webp crate may expose memory contents [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2423493
[ 3 ] Bug #2438128 - CVE-2026-25727 fractal: time affected by a stack exhaustion denial of service attack [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2438128
[ 4 ] Bug #2502176 - fractal-14.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502176
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9630be304f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: libssh-0.11.5-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-063caa9112
2026-07-23 01:01:59.493955+00:00
--------------------------------------------------------------------------------
Name : libssh
Product : Fedora 43
Version : 0.11.5
Release : 1.fc43
URL : http://www.libssh.org
Summary : A library implementing the SSH protocol
Description :
The ssh library was designed to be used by programmers needing a working SSH
implementation by the mean of a library. The complete control of the client is
made by the programmer. With libssh, you can remotely execute programs, transfer
files, use a secure and transparent tunnel for your remote programs. With its
Secure FTP implementation, you can play with remote files easily, without
third-party programs others than libcrypto (from openssl).
--------------------------------------------------------------------------------
Update Information:
New upstream security release (#2503148)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 21 2026 Jakub Jelen [jjelen@redhat.com] - 0.11.5-1
- New upstream security release (#2503148)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2503148 - libssh-0.12.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2503148
[ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503651
[ 3 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503657
[ 4 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503658
[ 5 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503668
[ 6 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503669
[ 7 ] Bug #2503671 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503671
[ 8 ] Bug #2503673 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503673
[ 9 ] Bug #2503674 - CVE-2026-59849 libssh: libssh: denial of service via automatic certificate authentication loop [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503674
[ 10 ] Bug #2503675 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503675
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-063caa9112' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: srt-1.5.6-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-51628b98a8
2026-07-23 01:01:59.493959+00:00
--------------------------------------------------------------------------------
Name : srt
Product : Fedora 43
Version : 1.5.6
Release : 1.fc43
URL : https://www.srtalliance.org
Summary : Secure Reliable Transport protocol tools
Description :
Secure Reliable Transport (SRT) is an open source transport technology that
optimizes streaming performance across unpredictable networks, such as
the Internet.
--------------------------------------------------------------------------------
Update Information:
Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 21 2026 Yanko Kaneti [yaneti@declera.com] - 1.5.6-1
- Update to 1.5.6
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-51628b98a8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: chromium-150.0.7871.128-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ac712bf651
2026-07-23 01:01:59.493948+00:00
--------------------------------------------------------------------------------
Name : chromium
Product : Fedora 43
Version : 150.0.7871.128
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).
--------------------------------------------------------------------------------
Update Information:
Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Than Ngo [than@redhat.com] - 150.0.7871.128-1
- Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
- Fix rhbz#2501811, Drop AI policy which breaks DoH settings
- Improve auto darkmode
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ac712bf651' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: perl-DBI-1.651-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c0abcba354
2026-07-23 01:01:59.493942+00:00
--------------------------------------------------------------------------------
Name : perl-DBI
Product : Fedora 43
Version : 1.651
Release : 1.fc43
URL : http://dbi.perl.org/
Summary : A database access API for perl
Description :
DBI is a database access Application Programming Interface (API) for
the Perl Language. The DBI API Specification defines a set of
functions, variables and conventions that provide a consistent
database interface independent of the actual database being used.
--------------------------------------------------------------------------------
Update Information:
1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and
CVE-2026-60081
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 20 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.651-1
- 1.651 bump (rhbz#2499925) - Fix CVE-2026-15043, CVE-2026-15392,
CVE-2026-60082 and CVE-2026-60081
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499925 - perl-DBI-1.651 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2499925
[ 2 ] Bug #2501259 - CVE-2026-14380 perl-DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501259
[ 3 ] Bug #2501286 - CVE-2026-15392 perl-DBI: DBD::File: Arbitrary file read/write via symlink vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501286
[ 4 ] Bug #2501292 - CVE-2026-15043 perl-DBI: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501292
[ 5 ] Bug #2501293 - CVE-2026-60081 perl-DBI: DBI::ProfileData: Denial of Service due to unbounded path index [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501293
[ 6 ] Bug #2501294 - CVE-2026-60082 perl-DBI: perl-DBI: Denial of Service via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501294
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c0abcba354' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: perl-YAML-Syck-1.47-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c8484f1afb
2026-07-23 01:01:59.493878+00:00
--------------------------------------------------------------------------------
Name : perl-YAML-Syck
Product : Fedora 43
Version : 1.47
Release : 1.fc43
URL : https://metacpan.org/release/YAML-Syck
Summary : Fast, lightweight YAML loader and dumper
Description :
This module provides a Perl interface to the libsyck data serialization
library. It exports the Dump and Load functions for converting Perl data
structures to YAML strings, and the other way around.
--------------------------------------------------------------------------------
Update Information:
This update addresses four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags:
CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder caused by
signed-char indexing of the decode table on !!binary input
CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared between
the node and the anchors table
CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer newline scan
during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683)
CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an anchor node
on anchor redefinition, a remote-crash DoS from a 7-byte input
There are also a few other bug-fixes included.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Paul Howarth - 1.47-1
- Update to 1.47
Security:
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags (GH#213)
- CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
- CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared
between the node and the anchors table
- CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on
to CVE-2025-11683)
- CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an
anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input
- Harden syck_base64dec() to bounds-check each read so it cannot run past a
non-NUL-terminated input buffer (defense-in-depth for callers passing raw
buffers; GH#213)
Bug Fixes:
- Fix: Enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply
nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512,
matching Dump (GH#204)
- Fix: Emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in
Dump so they roundtrip with ImplicitTyping instead of reloading as plain
strings (GH#201)
Maintenance:
- CI: add an AddressSanitizer job that builds the XS with
-fsanitize=address and runs the suite plus the CVE trigger inputs to catch
libsyck memory-safety defects; de-pin the libasan version so it tracks the
runner's GCC (GH#213)
* Mon May 25 2026 Paul Howarth - 1.46-1
- Update to 1.46
Bug Fixes:
- Preserve string nature of numeric-looking values in Dump; pure strings (POK
only, no IOK/NOK) are now quoted to maintain roundtrip fidelity
(GH#199, GH#200)
- Accept trailing commas in flow sequences and mappings ([a, b,] and
{a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH#195, GH#196)
Maintenance:
- CI: upgrade install-with-cpm to v2 for compatibility with Perl versions
prior to 5.24 in perldocker containers (GH#197, GH#198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries,
exclude .claude/ from distribution
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2501651 - CVE-2026-57075 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read in base64 decoder [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501651
[ 2 ] Bug #2501653 - CVE-2026-57077 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501653
[ 3 ] Bug #2501654 - CVE-2026-57076 perl-YAML-Syck: YAML::Syck: Heap use-after-free via anchor name reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501654
[ 4 ] Bug #2501656 - CVE-2026-13713 perl-YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501656
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c8484f1afb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: collectl-4.3.20.3-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e2b3dd1ec0
2026-07-23 01:01:59.493864+00:00
--------------------------------------------------------------------------------
Name : collectl
Product : Fedora 43
Version : 4.3.20.3
Release : 1.fc43
URL : https://github.com/sharkcz/collectl
Summary : A utility to collect various Linux performance data
Description :
A utility to collect Linux performance data
--------------------------------------------------------------------------------
Update Information:
handle insecure code properly in colmux
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Dan HorĂ¡k - 4.3.20.3-1
- upgrade to upstream version 4.3.20.3 (rhbz#2438007)
* Fri Feb 6 2026 Carl George [carlwgeorge@fedoraproject.org] - 4.3.20.1-1
- Update to version 4.3.20.1 rhbz#2149728
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.3.5-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.3.5-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2438007 - collectl-4.3.20.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id$38007
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e2b3dd1ec0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------