Fedora 44 Update: udisks2-2.11.2-1.fc44
Fedora 44 Update: kernel-7.1.7-200.fc44
Fedora 44 Update: p11-kit-0.26.5-1.fc44
Fedora 44 Update: erlang-26.2.5.21-5.fc44
Fedora 44 Update: mingw-glib2-2.88.3-1.fc44
Fedora 43 Update: kernel-7.1.7-100.fc43
Fedora 43 Update: perl-PAR-Packer-1.064-5.fc43
Fedora 43 Update: polymake-4.15-6.fc43
Fedora 43 Update: perl-5.42.3-524.fc43
Fedora 43 Update: perl-Devel-Cover-1.51-4.fc43
Fedora 43 Update: seamonkey-2.53.24-1.fc43
Fedora 43 Update: erlang-26.2.5.21-5.fc43
Fedora 43 Update: python3.12-3.12.13-6.fc43
Fedora 43 Update: rabbitmq-server-4.0.9-5.fc43
Fedora 43 Update: python-nh3-0.2.21-9.fc43
Fedora 43 Update: rust-ammonia-4.1.4-1.fc43
[SECURITY] Fedora 44 Update: udisks2-2.11.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ae4aff6b6f
2026-08-08 01:36:59.012590+00:00
--------------------------------------------------------------------------------
Name : udisks2
Product : Fedora 44
Version : 2.11.2
Release : 1.fc44
URL : https://github.com/storaged-project/udisks
Summary : Disk Manager
Description :
The Udisks project provides a daemon, tools and libraries to access and
manipulate disks, storage devices and technologies.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release 2.11.2
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Tomas Bzatek [tbzatek@redhat.com] - 2.11.2-1
- Version 2.11.2
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ae4aff6b6f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: kernel-7.1.7-200.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c3d9971785
2026-08-08 01:36:59.012595+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 44
Version : 7.1.7
Release : 200.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.7 stable kernel update contains a fix for CVE-2026-68480
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.7-0]
- Linux v7.1.7
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c3d9971785' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: p11-kit-0.26.5-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-110c1a7742
2026-08-08 01:36:59.012587+00:00
--------------------------------------------------------------------------------
Name : p11-kit
Product : Fedora 44
Version : 0.26.5
Release : 1.fc44
URL : http://p11-glue.freedesktop.org/p11-kit.html
Summary : Library for loading and sharing PKCS#11 modules
Description :
p11-kit provides a way to load and enumerate PKCS#11 modules, as well
as a standard configuration setup for installing PKCS#11 modules in
such a way that they're discoverable.
--------------------------------------------------------------------------------
Update Information:
rpc: guard against overflow when decoding nested attributes (CVE-2026-18938)
Only affects 32 bit systems
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Packit [hello@packit.dev] - 0.26.5-1
- Update to 0.26.5 upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2511987 - p11-kit-0.26.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2511987
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-110c1a7742' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: erlang-26.2.5.21-5.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7a3db128e8
2026-08-08 01:36:59.012547+00:00
--------------------------------------------------------------------------------
Name : erlang
Product : Fedora 44
Version : 26.2.5.21
Release : 5.fc44
URL : https://www.erlang.org
Summary : General-purpose programming language and runtime environment
Description :
Erlang is a general-purpose programming language and runtime
environment. Erlang has built-in support for concurrency, distribution
and fault tolerance. Erlang is used in several large telecommunication
systems from Ericsson.
--------------------------------------------------------------------------------
Update Information:
CVE-2026-55953
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Peter Lemenkov [lemenkov@gmail.com] - 26.2.5.21-5
- Backport fix for CVE-2026-55953
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509268 - CVE-2026-55953 erlang: Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509268
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7a3db128e8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: mingw-glib2-2.88.3-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2dfeac0818
2026-08-08 01:36:59.012521+00:00
--------------------------------------------------------------------------------
Name : mingw-glib2
Product : Fedora 44
Version : 2.88.3
Release : 1.fc44
URL : http://www.gtk.org
Summary : MinGW Windows GLib2 library
Description :
MinGW Windows Glib2 library.
--------------------------------------------------------------------------------
Update Information:
Update to 2.88.3.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 29 2026 Sandro Mani [manisandro@gmail.com] - 2.88.3-1
- Update to 2.88.3
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500600 - CVE-2026-15588 mingw-glib2: GDBusServer pre-authentication DoS via unbounded SASL line buffering [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2500600
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2dfeac0818' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: kernel-7.1.7-100.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b79a5390a7
2026-08-08 01:26:58.637180+00:00
--------------------------------------------------------------------------------
Name : kernel
Product : Fedora 43
Version : 7.1.7
Release : 100.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package
--------------------------------------------------------------------------------
Update Information:
The 7.1.7 stable kernel update contains a fix for CVE-2026-68480
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.7-0]
- Linux v7.1.7
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b79a5390a7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: perl-PAR-Packer-1.064-5.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b2e2c26935
2026-08-08 01:26:58.637166+00:00
--------------------------------------------------------------------------------
Name : perl-PAR-Packer
Product : Fedora 43
Version : 1.064
Release : 5.fc43
URL : https://metacpan.org/release/PAR-Packer
Summary : PAR Packager
Description :
This module implements the App::Packer::Backend interface, for generating
stand-alone executables, perl scripts and PAR files.
--------------------------------------------------------------------------------
Update Information:
Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.064-5
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b2e2c26935' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: polymake-4.15-6.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b2e2c26935
2026-08-08 01:26:58.637166+00:00
--------------------------------------------------------------------------------
Name : polymake
Product : Fedora 43
Version : 4.15
Release : 6.fc43
URL : https://polymake.org/
Summary : Algorithms on convex polytopes and polyhedra
Description :
Polymake is a tool to study the combinatorics and the geometry of convex
polytopes and polyhedra. It is also capable of dealing with simplicial
complexes, matroids, polyhedral fans, graphs, tropical objects, and so forth.
Polymake can use various computational packages if they are installed. Those
available from Fedora are: 4ti2, azove, gfan, latte-integrale, normaliz,
qhull, Singular, TOPCOM, and vinci.
Polymake can interface with various visualization packages if they are
installed. Install one or more of the tools from the following list: evince,
geomview, graphviz, gv, and okular.
--------------------------------------------------------------------------------
Update Information:
Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 4.15-6
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b2e2c26935' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: perl-5.42.3-524.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b2e2c26935
2026-08-08 01:26:58.637166+00:00
--------------------------------------------------------------------------------
Name : perl
Product : Fedora 43
Version : 5.42.3
Release : 524.fc43
URL : https://www.perl.org/
Summary : Practical Extraction and Report Language
Description :
Perl is a high-level programming language with roots in C, sed, awk and shell
scripting. Perl is good at handling processes and files, and is especially
good at handling text. Perl's hallmarks are practicality and efficiency.
While it is used to do a lot of different things, Perl's most common
applications are system administration utilities and web programming.
This is a metapackage with all the Perl bits and core modules that can be
found in the upstream tarball from perl.org.
If you need only a specific feature, you can install a specific package
instead. E.g. to handle Perl scripts with /usr/bin/perl interpreter,
install perl-interpreter package. See perl-interpreter description for more
details on the Perl decomposition into packages.
--------------------------------------------------------------------------------
Update Information:
Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 4:5.42.3-524
- 5.42.3 bump (see https://metacpan.org/release/SHAY/perl-5.42.3/view/pod/perldelta.pod>)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b2e2c26935' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: perl-Devel-Cover-1.51-4.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-b2e2c26935
2026-08-08 01:26:58.637166+00:00
--------------------------------------------------------------------------------
Name : perl-Devel-Cover
Product : Fedora 43
Version : 1.51
Release : 4.fc43
URL : https://metacpan.org/release/Devel-Cover
Summary : Code coverage metrics for Perl
Description :
This module provides code coverage metrics for Perl. Code coverage metrics
describe how thoroughly tests exercise code. By using Devel::Cover you can
discover areas of code not exercised by your tests and determine which
tests to create to increase coverage. Code coverage can be considered as an
indirect measure of quality.
--------------------------------------------------------------------------------
Update Information:
Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:
* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.51-4
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-b2e2c26935' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: seamonkey-2.53.24-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8d2a3de7da
2026-08-08 01:26:58.637160+00:00
--------------------------------------------------------------------------------
Name : seamonkey
Product : Fedora 43
Version : 2.53.24
Release : 1.fc43
URL : http://www.seamonkey-project.org
Summary : Web browser, e-mail, news, IRC client, HTML editor
Description :
SeaMonkey is an all-in-one Internet application suite (previously made
popular by Netscape and Mozilla). It includes an Internet browser,
advanced e-mail, newsgroup and feed client, a calendar, IRC client,
HTML editor and a tool to inspect the DOM for web pages. It is derived
from the application formerly known as Mozilla Application Suite.
--------------------------------------------------------------------------------
Update Information:
Update to 2.53.24
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Dmitry Butskoy [Dmitry@Butskoy.name] 2.53.24-1
- update to 2.53.24
* Wed Apr 15 2026 Nicolas Chauvet [kwizart@gmail.com] - 2.53.23-4
- Rebuilt for vmaf-3.1.0
* Thu Mar 19 2026 Nicolas Chauvet [kwizart@gmail.com] - 2.53.23-3
- Rebuilt for libvpx-1.16.0
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.53.23-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8d2a3de7da' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: erlang-26.2.5.21-5.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4220305a93
2026-08-08 01:26:58.637149+00:00
--------------------------------------------------------------------------------
Name : erlang
Product : Fedora 43
Version : 26.2.5.21
Release : 5.fc43
URL : https://www.erlang.org
Summary : General-purpose programming language and runtime environment
Description :
Erlang is a general-purpose programming language and runtime
environment. Erlang has built-in support for concurrency, distribution
and fault tolerance. Erlang is used in several large telecommunication
systems from Ericsson.
--------------------------------------------------------------------------------
Update Information:
CVE-2026-55953
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Peter Lemenkov [lemenkov@gmail.com] - 26.2.5.21-5
- Backport fix for CVE-2026-55953
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509268 - CVE-2026-55953 erlang: Erlang/OTP ssl client: Authentication bypass via unoffered anonymous cipher suite acceptance [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509268
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4220305a93' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: python3.12-3.12.13-6.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-0c91e22488
2026-08-08 01:26:58.637154+00:00
--------------------------------------------------------------------------------
Name : python3.12
Product : Fedora 43
Version : 3.12.13
Release : 6.fc43
URL : https://www.python.org/
Summary : Version 3.12 of the Python interpreter
Description :
Python 3.12 is an accessible, high-level, dynamically typed, interpreted
programming language, designed with an emphasis on code readability.
It includes an extensive standard library, and has a vast ecosystem of
third-party libraries.
The python3.12 package provides the "python3.12" executable: the reference
interpreter for the Python language, version 3.
The majority of its standard library is provided in the python3.12-libs package,
which should be installed automatically along with python3.12.
The remaining parts of the Python standard library are broken out into the
python3.12-tkinter and python3.12-test packages, which may need to be installed
separately.
Documentation for Python is provided in the python3.12-docs package.
Packages containing additional libraries for Python are generally named with
the "python3.12-" prefix.
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2026-15308
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 28 2026 Lukáš Zachar [lzachar@redhat.com] - 3.12.13-6
- Security fix for CVE-2026-15308
Resolves: rhbz#2498688
* Tue Jul 28 2026 Miro Hrončok [mhroncok@redhat.com] - 3.12.13-5
- Skip UDP Lite tests if it's not supported
- Fixes FTBFS on Linux kernel 7.1 and newer
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.12.13-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2498688 - CVE-2026-15308 python3.12: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$98688
[ 2 ] Bug #2504605 - python3.12: FTBFS in Fedora rawhide/f45
https://bugzilla.redhat.com/show_bug.cgi?id%04605
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-0c91e22488' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: rabbitmq-server-4.0.9-5.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-548235ea3b
2026-08-08 01:26:58.637144+00:00
--------------------------------------------------------------------------------
Name : rabbitmq-server
Product : Fedora 43
Version : 4.0.9
Release : 5.fc43
URL : https://www.rabbitmq.com/
Summary : The RabbitMQ server
Description :
RabbitMQ is an implementation of AMQP, the emerging standard for high
performance enterprise messaging. The RabbitMQ server is a robust and
scalable implementation of an AMQP broker.
--------------------------------------------------------------------------------
Update Information:
More CVEs
Fixed CVE-2026-44839
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Peter Lemenkov [lemenkov@gmail.com] - 4.0.9-5
- Fixed CVE-2026-57212, CVE-2026-57213, CVE-2026-57215, CVE-2026-57217,
CVE-2026-57219, CVE-2026-57221
* Thu Jul 23 2026 Peter Lemenkov [lemenkov@gmail.com] - 4.0.9-4
- Fixed CVE-2026-44839
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489780 - CVE-2026-44839 rabbitmq-server: RabbitMQ: Unsanitized vhost names allow for XSS in management UI [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489780
[ 2 ] Bug #2507937 - CVE-2026-57215 rabbitmq-server: RabbitMQ: Persistent foreign bindings allow unauthorized message routing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507937
[ 3 ] Bug #2507939 - CVE-2026-57212 rabbitmq-server: RabbitMQ: Denial of Service via oversized JSON bodies in HTTP API [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507939
[ 4 ] Bug #2507940 - CVE-2026-57221 rabbitmq-server: RabbitMQ: Information disclosure via authorization bypass in AMQP 0-9-1 operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507940
[ 5 ] Bug #2507941 - CVE-2026-57219 rabbitmq-server: RabbitMQ: OAuth 2 client secret disclosure via obsolete API endpoint [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507941
[ 6 ] Bug #2507942 - CVE-2026-57213 rabbitmq-server: RabbitMQ: Information Disclosure via Cross-Site Scripting in Federation Management [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507942
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-548235ea3b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: python-nh3-0.2.21-9.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9324385c43
2026-08-08 01:26:58.637135+00:00
--------------------------------------------------------------------------------
Name : python-nh3
Product : Fedora 43
Version : 0.2.21
Release : 9.fc43
URL : https://github.com/messense/nh3
Summary : Python binding to Ammonia HTML sanitizer Rust crate
Description :
Python binding to Ammonia HTML sanitizer Rust crate.
--------------------------------------------------------------------------------
Update Information:
Update the ammonia crate to version 4.1.4.
Rebuild nh3 to apply fixes for RUSTSEC-2026-0193 and RUSTSEC-2026-0213.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Fabio Valentini [decathorpe@gmail.com] - 0.2.21-9
- Rebuild with ammonia 4.1.4 for RUSTSEC-2026-0193 and RUSTSEC-2026-0213
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9324385c43' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: rust-ammonia-4.1.4-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9324385c43
2026-08-08 01:26:58.637135+00:00
--------------------------------------------------------------------------------
Name : rust-ammonia
Product : Fedora 43
Version : 4.1.4
Release : 1.fc43
URL : https://crates.io/crates/ammonia
Summary : HTML Sanitization
Description :
HTML Sanitization.
--------------------------------------------------------------------------------
Update Information:
Update the ammonia crate to version 4.1.4.
Rebuild nh3 to apply fixes for RUSTSEC-2026-0193 and RUSTSEC-2026-0213.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Fabio Valentini [decathorpe@gmail.com] - 4.1.4-1
- Update to version 4.1.4; Fixes RHBZ#2506006
* Fri Jul 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.1.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9324385c43' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new