Fedora Linux 9426 Published by

Fedora released a coordinated set of security advisories covering both Fedora 43 and Fedora 44 distributions. The updates upgrade core infrastructure and popular applications including the Linux kernel, Nginx web server stack, Chromium browser, libssh library, LLVM compiler tools, Fractal messaging client, Perl DBI and YAML::Syck packages, along with collectl system monitoring utilities. Each advisory contains patches for multiple actively exploited or high-risk vulnerabilities spanning memory corruption flaws, remote code execution pathways, denial-of-service conditions, and sensitive information exposure vectors.

Fedora 44 Update: kernel-7.1.4-204.fc44
Fedora 44 Update: llvm-22.1.8-4.fc44
Fedora 44 Update: fractal-14.1-1.fc44
Fedora 44 Update: srt-1.5.6-1.fc44
Fedora 44 Update: libssh-0.12.1-1.fc44
Fedora 44 Update: chromium-150.0.7871.128-1.fc44
Fedora 44 Update: nginx-mod-vts-0.2.4-13.fc44
Fedora 44 Update: perl-DBI-1.651-1.fc44
Fedora 44 Update: nginx-mod-headers-more-0.40-3.fc44
Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44
Fedora 44 Update: nginx-mod-naxsi-1.6-21.fc44
Fedora 44 Update: nginx-mod-fancyindex-0.6.0-8.fc44
Fedora 44 Update: nginx-mod-modsecurity-1.0.4-16.fc44
Fedora 44 Update: nginx-1.30.4-1.fc44
Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-13.fc44
Fedora 44 Update: perl-YAML-Syck-1.47-1.fc44
Fedora 44 Update: collectl-4.3.20.3-1.fc44
Fedora 43 Update: kernel-7.1.4-104.fc43
Fedora 43 Update: fractal-14.1-1.fc43
Fedora 43 Update: libssh-0.11.5-1.fc43
Fedora 43 Update: srt-1.5.6-1.fc43
Fedora 43 Update: chromium-150.0.7871.128-1.fc43
Fedora 43 Update: perl-DBI-1.651-1.fc43
Fedora 43 Update: perl-YAML-Syck-1.47-1.fc43
Fedora 43 Update: collectl-4.3.20.3-1.fc43



[SECURITY] Fedora 44 Update: kernel-7.1.4-204.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2b94d8d05c
2026-07-23 01:18:29.467256+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 44
Version : 7.1.4
Release : 204.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for
issues with exploits in the wild.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-4]
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-3]
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2b94d8d05c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: llvm-22.1.8-4.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-597e8f9de1
2026-07-23 01:18:29.467240+00:00
--------------------------------------------------------------------------------

Name : llvm
Product : Fedora 44
Version : 22.1.8
Release : 4.fc44
URL : http://llvm.org
Summary : The Low Level Virtual Machine
Description :
LLVM is a compiler infrastructure designed for compile-time, link-time,
runtime, and idle-time optimization of programs from arbitrary programming
languages. The compiler infrastructure includes mirror sets of programming
tools as well as libraries with equivalent functionality.

--------------------------------------------------------------------------------
Update Information:

Backport fixes from LLVM 23
Fix an issue that could cause a buffer overflow when reading a corrupted bitcode
file.
Fix a miscompilation known to affect rust applications.
Fix a miscompilation in x86 vectorized code.
Fix 2 issues in LLD.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-4
- More backported fixes
* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-3
- Fix miscompilation
* Thu Jul 16 2026 Tulio Magno Quites Machado Filho [tuliom@redhat.com] - 22.1.8-2
- Fix buffer overflow
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2496390 - CVE-2026-13574 llvm: LLVM: Denial of service via heap-based buffer overflow in Bitcode File Handler [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496390
[ 2 ] Bug #2499684 - miscompilation that leads to segfaults with Rust 1.97.0
https://bugzilla.redhat.com/show_bug.cgi?id=2499684
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-597e8f9de1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: fractal-14.1-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-600530ae91
2026-07-23 01:18:29.467244+00:00
--------------------------------------------------------------------------------

Name : fractal
Product : Fedora 44
Version : 14.1
Release : 1.fc44
URL : https://gitlab.gnome.org/World/fractal
Summary : Matrix group messaging app
Description :
Fractal is a Matrix messaging app for GNOME written in Rust. Its interface is
optimized for collaboration in large groups, such as free software projects.

--------------------------------------------------------------------------------
Update Information:

14.1
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Gwyn Ciesla [gwync@protonmail.com] - 14.1-1
- 14.1
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 14-0.beta.2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 14-0.beta.1
- Rebuilt for openssl 4.0
* Wed Apr 1 2026 Gwyn Ciesla [gwync@protonmail.com] - 14-0.beta
- 14 beta
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2420427 - CVE-2025-66622 fractal: matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420427
[ 2 ] Bug #2423493 - fractal: webp crate may expose memory contents [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2423493
[ 3 ] Bug #2438128 - CVE-2026-25727 fractal: time affected by a stack exhaustion denial of service attack [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2438128
[ 4 ] Bug #2502176 - fractal-14.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502176
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-600530ae91' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: srt-1.5.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-45ce54d51e
2026-07-23 01:18:29.467242+00:00
--------------------------------------------------------------------------------

Name : srt
Product : Fedora 44
Version : 1.5.6
Release : 1.fc44
URL : https://www.srtalliance.org
Summary : Secure Reliable Transport protocol tools
Description :
Secure Reliable Transport (SRT) is an open source transport technology that
optimizes streaming performance across unpredictable networks, such as
the Internet.

--------------------------------------------------------------------------------
Update Information:

Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Yanko Kaneti [yaneti@declera.com] - 1.5.6-1
- Update to 1.5.6
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-45ce54d51e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: libssh-0.12.1-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0e46c91ccf
2026-07-23 01:18:29.467232+00:00
--------------------------------------------------------------------------------

Name : libssh
Product : Fedora 44
Version : 0.12.1
Release : 1.fc44
URL : http://www.libssh.org
Summary : A library implementing the SSH protocol
Description :
The ssh library was designed to be used by programmers needing a working SSH
implementation by the mean of a library. The complete control of the client is
made by the programmer. With libssh, you can remotely execute programs, transfer
files, use a secure and transparent tunnel for your remote programs. With its
Secure FTP implementation, you can play with remote files easily, without
third-party programs others than libcrypto (from openssl).

--------------------------------------------------------------------------------
Update Information:

New upstream security release
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Jakub Jelen [jjelen@redhat.com] - 0.12.1-1
- New upstream security release
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.12.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 0.12.0-3
- Rebuilt for openssl 4.0
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2503148 - libssh-0.12.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2503148
[ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503651
[ 3 ] Bug #2503656 - CVE-2026-59842 libssh: libssh: information disclosure via short GSSAPI Curve25519 public key [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503656
[ 4 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503657
[ 5 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503658
[ 6 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503668
[ 7 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503669
[ 8 ] Bug #2503671 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503671
[ 9 ] Bug #2503673 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503673
[ 10 ] Bug #2503674 - CVE-2026-59849 libssh: libssh: denial of service via automatic certificate authentication loop [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503674
[ 11 ] Bug #2503675 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503675
[ 12 ] Bug #2503676 - CVE-2026-59851 libssh: libssh: authentication bypass via missing GSSAPI principal check [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503676
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0e46c91ccf' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: chromium-150.0.7871.128-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-310f620a68
2026-07-23 01:18:29.467228+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 44
Version : 150.0.7871.128
Release : 1.fc44
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Than Ngo [than@redhat.com] - 150.0.7871.128-1
- Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
- Fix rhbz#2501811, Drop AI policy which breaks DoH settings
- Improve auto darkmode
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-310f620a68' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-vts-0.2.4-13.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-vts
Product : Fedora 44
Version : 0.2.4
Release : 13.fc44
URL : https://github.com/vozlt/nginx-module-vts
Summary : Nginx virtual host traffic status module
Description :
Nginx virtual host traffic status module.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.2.4-13
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.2.4-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-DBI-1.651-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1c5ffc6018
2026-07-23 01:18:29.467220+00:00
--------------------------------------------------------------------------------

Name : perl-DBI
Product : Fedora 44
Version : 1.651
Release : 1.fc44
URL : http://dbi.perl.org/
Summary : A database access API for perl
Description :
DBI is a database access Application Programming Interface (API) for
the Perl Language. The DBI API Specification defines a set of
functions, variables and conventions that provide a consistent
database interface independent of the actual database being used.

--------------------------------------------------------------------------------
Update Information:

1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and
CVE-2026-60081
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.651-1
- 1.651 bump (rhbz#2499925) - Fix CVE-2026-15043, CVE-2026-15392,
CVE-2026-60082 and CVE-2026-60081
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2499925 - perl-DBI-1.651 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2499925
[ 2 ] Bug #2501259 - CVE-2026-14380 perl-DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501259
[ 3 ] Bug #2501286 - CVE-2026-15392 perl-DBI: DBD::File: Arbitrary file read/write via symlink vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501286
[ 4 ] Bug #2501292 - CVE-2026-15043 perl-DBI: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501292
[ 5 ] Bug #2501293 - CVE-2026-60081 perl-DBI: DBI::ProfileData: Denial of Service due to unbounded path index [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501293
[ 6 ] Bug #2501294 - CVE-2026-60082 perl-DBI: perl-DBI: Denial of Service via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501294
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1c5ffc6018' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-headers-more-0.40-3.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-headers-more
Product : Fedora 44
Version : 0.40
Release : 3.fc44
URL : https://github.com/openresty/headers-more-nginx-module
Summary : This module allows adding, setting, or clearing specified input/output headers
Description :
This module allows adding, setting, or clearing specified input/output headers.

This is an enhanced version of the standard headers module because it provides
more utilities like resetting or clearing "builtin headers" like Content-Type,
Content-Length, and Server.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.40-3
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.40-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-js-challenge-0^20230517.gitda6852d-11.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-js-challenge
Product : Fedora 44
Version : 0^20230517.gitda6852d
Release : 11.fc44
URL : https://github.com/simon987/ngx_http_js_challenge_module
Summary : Simple JavaScript proof-of-work based access for Nginx with virtually no overhead
Description :
Simple JavaScript proof-of-work based access for Nginx with virtually no overhead.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0^20230517.gitda6852d-11
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0^20230517.gitda6852d-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-naxsi-1.6-21.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-naxsi
Product : Fedora 44
Version : 1.6
Release : 21.fc44
URL : https://github.com/wargio/naxsi
Summary : nginx web application firewall module
Description :
naxsi is an nginx module that provides score based Web Application Firewall
(WAF) abilities in a highly granular fashion.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.6-21
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.6-20
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-fancyindex-0.6.0-8.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-fancyindex
Product : Fedora 44
Version : 0.6.0
Release : 8.fc44
URL : https://github.com/aperezdc/ngx-fancyindex
Summary : Nginx FancyIndex module
Description :
The Fancy Index module makes possible the generation of file listings,
like the built-in autoindex module does, but adding a touch of style.
This is possible because the module allows a certain degree of
customization of the generated content:

* Custom headers. Either local or stored remotely.
* Custom footers. Either local or stored remotely.
* Add you own CSS style rules.
* Allow choosing to sort elements by name (default),
modification time, or size; both ascending (default),
or descending.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 0.6.0-8
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.6.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-modsecurity-1.0.4-16.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-modsecurity
Product : Fedora 44
Version : 1.0.4
Release : 16.fc44
URL : https://github.com/SpiderLabs/ModSecurity-nginx
Summary : ModSecurity v3 nginx connector
Description :
The ModSecurity-nginx connector is the connection point between nginx and
libmodsecurity (ModSecurity v3). Said another way, this project provides a
communication channel between nginx and libmodsecurity. This connector is
required to use LibModSecurity with nginx.

The ModSecurity-nginx connector takes the form of an nginx module. The module
simply serves as a layer of communication between nginx and ModSecurity

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.0.4-16
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.0.4-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jul 8 2026 Joe Orton [jorton@redhat.com] - 1.0.4-14
- Rebuild.
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-1.30.4-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx
Product : Fedora 44
Version : 1.30.4
Release : 1.fc44
URL : https://nginx.org
Summary : A high performance web server and reverse proxy server
Description :
Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and
IMAP protocols, with a strong focus on high concurrency, performance and low
memory usage.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 2:1.30.4-1
- update to 1.30.4
- fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2:1.30.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nginx-mod-brotli-1.0.0~rc-13.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-60fc198d3b
2026-07-23 01:18:29.467215+00:00
--------------------------------------------------------------------------------

Name : nginx-mod-brotli
Product : Fedora 44
Version : 1.0.0~rc
Release : 13.fc44
URL : https://github.com/google/ngx_brotli
Summary : NGINX module for Brotli compression
Description :
NGINX module for Brotli compression.

--------------------------------------------------------------------------------
Update Information:

nginx-mod-fancyindex:
Rebuild for 1.30.4
nginx-mod-modsecurity:
Rebuild for 1.30.4
nginx-mod-naxsi:
Rebuild for 1.30.4
nginx-mod-headers-more:
Rebuild for 1.30.4
nginx-mod-brotli:
Rebuild for 1.30.4
nginx-mod-js-challenge:
Rebuild for 1.30.4
nginx-mod-vts:
Rebuild for 1.30.4
nginx:
update to 1.30.4
fixes CVE-2026-42533, CVE-2026-60005, CVE-2026-56434
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 19 2026 Felix Kaechele [felix@kaechele.ca] - 1.0.0~rc-13
- Rebuild for 1.30.4
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.0.0~rc-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501307 - CVE-2026-42533 nginx: NGINX: Arbitrary code execution via crafted HTTP requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501307
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-60fc198d3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-YAML-Syck-1.47-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2139aa7dce
2026-07-23 01:18:29.467144+00:00
--------------------------------------------------------------------------------

Name : perl-YAML-Syck
Product : Fedora 44
Version : 1.47
Release : 1.fc44
URL : https://metacpan.org/release/YAML-Syck
Summary : Fast, lightweight YAML loader and dumper
Description :
This module provides a Perl interface to the libsyck data serialization
library. It exports the Dump and Load functions for converting Perl data
structures to YAML strings, and the other way around.

--------------------------------------------------------------------------------
Update Information:

This update addresses four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags:
CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder caused by
signed-char indexing of the decode table on !!binary input
CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared between
the node and the anchors table
CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer newline scan
during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683)
CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an anchor node
on anchor redefinition, a remote-crash DoS from a 7-byte input
There are also a few other bug-fixes included.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 14 2026 Paul Howarth - 1.47-1
- Update to 1.47
Security:
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags (GH#213)
- CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
- CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared
between the node and the anchors table
- CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on
to CVE-2025-11683)
- CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an
anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input
- Harden syck_base64dec() to bounds-check each read so it cannot run past a
non-NUL-terminated input buffer (defense-in-depth for callers passing raw
buffers; GH#213)
Bug Fixes:
- Fix: Enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply
nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512,
matching Dump (GH#204)
- Fix: Emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in
Dump so they roundtrip with ImplicitTyping instead of reloading as plain
strings (GH#201)
Maintenance:
- CI: add an AddressSanitizer job that builds the XS with
-fsanitize=address and runs the suite plus the CVE trigger inputs to catch
libsyck memory-safety defects; de-pin the libasan version so it tracks the
runner's GCC (GH#213)
* Mon May 25 2026 Paul Howarth - 1.46-1
- Update to 1.46
Bug Fixes:
- Preserve string nature of numeric-looking values in Dump; pure strings (POK
only, no IOK/NOK) are now quoted to maintain roundtrip fidelity
(GH#199, GH#200)
- Accept trailing commas in flow sequences and mappings ([a, b,] and
{a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH#195, GH#196)
Maintenance:
- CI: upgrade install-with-cpm to v2 for compatibility with Perl versions
prior to 5.24 in perldocker containers (GH#197, GH#198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries,
exclude .claude/ from distribution
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501651 - CVE-2026-57075 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read in base64 decoder [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501651
[ 2 ] Bug #2501653 - CVE-2026-57077 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501653
[ 3 ] Bug #2501654 - CVE-2026-57076 perl-YAML-Syck: YAML::Syck: Heap use-after-free via anchor name reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501654
[ 4 ] Bug #2501656 - CVE-2026-13713 perl-YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501656
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2139aa7dce' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: collectl-4.3.20.3-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-71a9784a57
2026-07-23 01:18:29.467136+00:00
--------------------------------------------------------------------------------

Name : collectl
Product : Fedora 44
Version : 4.3.20.3
Release : 1.fc44
URL : https://github.com/sharkcz/collectl
Summary : A utility to collect various Linux performance data
Description :
A utility to collect Linux performance data

--------------------------------------------------------------------------------
Update Information:

handle insecure code properly in colmux
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 14 2026 Dan HorĂ¡k - 4.3.20.3-1
- upgrade to upstream version 4.3.20.3 (rhbz#2438007)
* Fri Feb 6 2026 Carl George [carlwgeorge@fedoraproject.org] - 4.3.20.1-1
- Update to version 4.3.20.1 rhbz#2149728
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2438007 - collectl-4.3.20.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id$38007
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-71a9784a57' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: kernel-7.1.4-104.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6503a6a639
2026-07-23 01:01:59.493964+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 43
Version : 7.1.4
Release : 104.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.4-104/204 stable kennel updates contain a couple of security fixes for
issues with exploits in the wild.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-4]
- net/packet: avoid fanout hook re-registration after unregister (David Lee)
* Wed Jul 22 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-3]
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (Jamal Hadi Salim)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6503a6a639' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: fractal-14.1-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9630be304f
2026-07-23 01:01:59.493962+00:00
--------------------------------------------------------------------------------

Name : fractal
Product : Fedora 43
Version : 14.1
Release : 1.fc43
URL : https://gitlab.gnome.org/World/fractal
Summary : Matrix group messaging app
Description :
Fractal is a Matrix messaging app for GNOME written in Rust. Its interface is
optimized for collaboration in large groups, such as free software projects.

--------------------------------------------------------------------------------
Update Information:

14.1
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Gwyn Ciesla [gwync@protonmail.com] - 14.1-1
- 14.1
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 14-0.beta.2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 14-0.beta.1
- Rebuilt for openssl 4.0
* Wed Apr 1 2026 Gwyn Ciesla [gwync@protonmail.com] - 14-0.beta
- 14 beta
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2420427 - CVE-2025-66622 fractal: matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420427
[ 2 ] Bug #2423493 - fractal: webp crate may expose memory contents [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2423493
[ 3 ] Bug #2438128 - CVE-2026-25727 fractal: time affected by a stack exhaustion denial of service attack [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2438128
[ 4 ] Bug #2502176 - fractal-14.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502176
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9630be304f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: libssh-0.11.5-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-063caa9112
2026-07-23 01:01:59.493955+00:00
--------------------------------------------------------------------------------

Name : libssh
Product : Fedora 43
Version : 0.11.5
Release : 1.fc43
URL : http://www.libssh.org
Summary : A library implementing the SSH protocol
Description :
The ssh library was designed to be used by programmers needing a working SSH
implementation by the mean of a library. The complete control of the client is
made by the programmer. With libssh, you can remotely execute programs, transfer
files, use a secure and transparent tunnel for your remote programs. With its
Secure FTP implementation, you can play with remote files easily, without
third-party programs others than libcrypto (from openssl).

--------------------------------------------------------------------------------
Update Information:

New upstream security release (#2503148)
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Jakub Jelen [jjelen@redhat.com] - 0.11.5-1
- New upstream security release (#2503148)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2503148 - libssh-0.12.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2503148
[ 2 ] Bug #2503651 - CVE-2026-15370 libssh: libssh: stack buffer overflow in SFTP server longname construction [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503651
[ 3 ] Bug #2503657 - CVE-2026-59843 libssh: libssh: denial of service via zero advertised channel packet size [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503657
[ 4 ] Bug #2503658 - CVE-2026-59844 libssh: libssh: denial of service via oversized SFTP read length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503658
[ 5 ] Bug #2503668 - CVE-2026-59845 libssh: libssh: denial of service via unchecked ProxyCommand fork() failure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503668
[ 6 ] Bug #2503669 - CVE-2026-59846 libssh: libssh: information disclosure via ProxyCommand %r username expansion [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503669
[ 7 ] Bug #2503671 - CVE-2026-59847 libssh: libssh: integrity downgrade via OpenSSL AES-GCM tag verification [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503671
[ 8 ] Bug #2503673 - CVE-2026-59848 libssh: libssh: denial of service via SFTP responses with unknown request IDs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503673
[ 9 ] Bug #2503674 - CVE-2026-59849 libssh: libssh: denial of service via automatic certificate authentication loop [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503674
[ 10 ] Bug #2503675 - CVE-2026-59850 libssh: libssh: use-after-free via data callbacks on closed channels [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2503675
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-063caa9112' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: srt-1.5.6-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-51628b98a8
2026-07-23 01:01:59.493959+00:00
--------------------------------------------------------------------------------

Name : srt
Product : Fedora 43
Version : 1.5.6
Release : 1.fc43
URL : https://www.srtalliance.org
Summary : Secure Reliable Transport protocol tools
Description :
Secure Reliable Transport (SRT) is an open source transport technology that
optimizes streaming performance across unpredictable networks, such as
the Internet.

--------------------------------------------------------------------------------
Update Information:

Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Yanko Kaneti [yaneti@declera.com] - 1.5.6-1
- Update to 1.5.6
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-51628b98a8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: chromium-150.0.7871.128-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ac712bf651
2026-07-23 01:01:59.493948+00:00
--------------------------------------------------------------------------------

Name : chromium
Product : Fedora 43
Version : 150.0.7871.128
Release : 1.fc43
URL : http://www.chromium.org/Home
Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use
Description :
Chromium is an open-source web browser, powered by WebKit (Blink).

--------------------------------------------------------------------------------
Update Information:

Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Than Ngo [than@redhat.com] - 150.0.7871.128-1
- Update to 150.0.7871.128
* CVE-2026-15899: Use after free in CameraCapture
* CVE-2026-15900: Use after free in GPU
* CVE-2026-15901: Use after free in Network
* CVE-2026-15902: Use after free in Cast
* CVE-2026-15903: Out of bounds read and write in V8
* CVE-2026-15904: Use after free in Ozone
* CVE-2026-15905: Use after free in Aura
- Fix rhbz#2501811, Drop AI policy which breaks DoH settings
- Improve auto darkmode
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ac712bf651' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: perl-DBI-1.651-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c0abcba354
2026-07-23 01:01:59.493942+00:00
--------------------------------------------------------------------------------

Name : perl-DBI
Product : Fedora 43
Version : 1.651
Release : 1.fc43
URL : http://dbi.perl.org/
Summary : A database access API for perl
Description :
DBI is a database access Application Programming Interface (API) for
the Perl Language. The DBI API Specification defines a set of
functions, variables and conventions that provide a consistent
database interface independent of the actual database being used.

--------------------------------------------------------------------------------
Update Information:

1.651 bump - Fix CVE-2026-15043, CVE-2026-15392, CVE-2026-60082 and
CVE-2026-60081
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.651-1
- 1.651 bump (rhbz#2499925) - Fix CVE-2026-15043, CVE-2026-15392,
CVE-2026-60082 and CVE-2026-60081
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2499925 - perl-DBI-1.651 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2499925
[ 2 ] Bug #2501259 - CVE-2026-14380 perl-DBI: DBI: Arbitrary code execution via caller-influenced Profile attribute [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501259
[ 3 ] Bug #2501286 - CVE-2026-15392 perl-DBI: DBD::File: Arbitrary file read/write via symlink vulnerability [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501286
[ 4 ] Bug #2501292 - CVE-2026-15043 perl-DBI: DBI::SQL::Nano: Incorrect SQL operator evaluation can lead to incorrect data filtering. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501292
[ 5 ] Bug #2501293 - CVE-2026-60081 perl-DBI: DBI::ProfileData: Denial of Service due to unbounded path index [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501293
[ 6 ] Bug #2501294 - CVE-2026-60082 perl-DBI: perl-DBI: Denial of Service via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501294
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c0abcba354' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: perl-YAML-Syck-1.47-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c8484f1afb
2026-07-23 01:01:59.493878+00:00
--------------------------------------------------------------------------------

Name : perl-YAML-Syck
Product : Fedora 43
Version : 1.47
Release : 1.fc43
URL : https://metacpan.org/release/YAML-Syck
Summary : Fast, lightweight YAML loader and dumper
Description :
This module provides a Perl interface to the libsyck data serialization
library. It exports the Dump and Load functions for converting Perl data
structures to YAML strings, and the other way around.

--------------------------------------------------------------------------------
Update Information:

This update addresses four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags:
CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder caused by
signed-char indexing of the decode table on !!binary input
CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared between
the node and the anchors table
CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer newline scan
during block-scalar parsing (incomplete-fix follow-on to CVE-2025-11683)
CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an anchor node
on anchor redefinition, a remote-crash DoS from a 7-byte input
There are also a few other bug-fixes included.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 14 2026 Paul Howarth - 1.47-1
- Update to 1.47
Security:
- Fix four libsyck memory-safety CVEs reachable from the default
YAML::Syck::Load() path on untrusted input with no special flags (GH#213)
- CVE-2026-57075 (CWE-125): Out-of-bounds read in the base64 decoder
caused by signed-char indexing of the decode table on !!binary input
- CVE-2026-57076 (CWE-416): Use-after-free of an anchor key string shared
between the node and the anchors table
- CVE-2026-57077 (CWE-125): One-byte out-of-bounds read in the lexer
newline scan during block-scalar parsing (incomplete-fix follow-on
to CVE-2025-11683)
- CVE-2026-13713 (CWE-416/CWE-415): Use-after-free / double-free of an
anchor node on anchor redefinition, a remote-crash DoS from a 7-byte input
- Harden syck_base64dec() to bounds-check each read so it cannot run past a
non-NUL-terminated input buffer (defense-in-depth for callers passing raw
buffers; GH#213)
Bug Fixes:
- Fix: Enforce $MaxDepth on Load to prevent C-stack exhaustion from deeply
nested YAML/JSON input; YAML::Syck and JSON::Syck Load now default to 512,
matching Dump (GH#204)
- Fix: Emit YAML canonical forms (.nan, .inf, -.inf) for NaN/Inf values in
Dump so they roundtrip with ImplicitTyping instead of reloading as plain
strings (GH#201)
Maintenance:
- CI: add an AddressSanitizer job that builds the XS with
-fsanitize=address and runs the suite plus the CVE trigger inputs to catch
libsyck memory-safety defects; de-pin the libasan version so it tracks the
runner's GCC (GH#213)
* Mon May 25 2026 Paul Howarth - 1.46-1
- Update to 1.46
Bug Fixes:
- Preserve string nature of numeric-looking values in Dump; pure strings (POK
only, no IOK/NOK) are now quoted to maintain roundtrip fidelity
(GH#199, GH#200)
- Accept trailing commas in flow sequences and mappings ([a, b,] and
{a: 1,}), valid per YAML 1.0/1.1/1.2 spec (GH#195, GH#196)
Maintenance:
- CI: upgrade install-with-cpm to v2 for compatibility with Perl versions
prior to 5.24 in perldocker containers (GH#197, GH#198)
- Clean up MANIFEST.SKIP: add #!include_default, remove redundant entries,
exclude .claude/ from distribution
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2501651 - CVE-2026-57075 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read in base64 decoder [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501651
[ 2 ] Bug #2501653 - CVE-2026-57077 perl-YAML-Syck: YAML::Syck: Information disclosure via out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501653
[ 3 ] Bug #2501654 - CVE-2026-57076 perl-YAML-Syck: YAML::Syck: Heap use-after-free via anchor name reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501654
[ 4 ] Bug #2501656 - CVE-2026-13713 perl-YAML-Syck: YAML::Syck: Denial of Service via crafted YAML document [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2501656
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c8484f1afb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: collectl-4.3.20.3-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e2b3dd1ec0
2026-07-23 01:01:59.493864+00:00
--------------------------------------------------------------------------------

Name : collectl
Product : Fedora 43
Version : 4.3.20.3
Release : 1.fc43
URL : https://github.com/sharkcz/collectl
Summary : A utility to collect various Linux performance data
Description :
A utility to collect Linux performance data

--------------------------------------------------------------------------------
Update Information:

handle insecure code properly in colmux
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 14 2026 Dan HorĂ¡k - 4.3.20.3-1
- upgrade to upstream version 4.3.20.3 (rhbz#2438007)
* Fri Feb 6 2026 Carl George [carlwgeorge@fedoraproject.org] - 4.3.20.1-1
- Update to version 4.3.20.1 rhbz#2149728
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.3.5-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.3.5-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2438007 - collectl-4.3.20.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id$38007
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e2b3dd1ec0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------