Fedora Linux 9174 Published by

Fedora has released security updates for the linenoise library, which is a replacement for readline. The update addresses CVE-2025-9810, a TOCTOU (time-of-check to time-of-use) race in Linenoise that enables arbitrary file overwrite and permission changes. Updates are available for Fedora 41 and Fedora 42, with version 1.0-9.20200312git97d2850.fc41 and 1.0-12.20200312git97d2850.fc42 respectively.

Fedora 41 Update: linenoise-1.0-9.20200312git97d2850.fc41
Fedora 42 Update: linenoise-1.0-12.20200312git97d2850.fc42




[SECURITY] Fedora 41 Update: linenoise-1.0-9.20200312git97d2850.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-cbe2e6c8ce
2025-09-15 01:30:13.647571+00:00
--------------------------------------------------------------------------------

Name : linenoise
Product : Fedora 41
Version : 1.0
Release : 9.20200312git97d2850.fc41
URL : https://github.com/antirez/linenoise
Summary : Minimal replacement for readline
Description :
Linenoise is a replacement for the readline line-editing library with the goal
of being smaller.

--------------------------------------------------------------------------------
Update Information:

CVE-2025-9810
--------------------------------------------------------------------------------
ChangeLog:

* Fri Sep 5 2025 Garry T. Williams [gtwilliams@gmail.com] - 1.0-9.20200312git97d2850
- Fix CVE-2025-9810
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2392583 - CVE-2025-9810 linenoise: TOCTOU race in Linenoise enables arbitrary file overwrite and permission changes [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2392583
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-cbe2e6c8ce' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 42 Update: linenoise-1.0-12.20200312git97d2850.fc42


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-b83972992e
2025-09-15 00:46:54.505247+00:00
--------------------------------------------------------------------------------

Name : linenoise
Product : Fedora 42
Version : 1.0
Release : 12.20200312git97d2850.fc42
URL : https://github.com/antirez/linenoise
Summary : Minimal replacement for readline
Description :
Linenoise is a replacement for the readline line-editing library with the goal
of being smaller.

--------------------------------------------------------------------------------
Update Information:

CVE-2025-9810
--------------------------------------------------------------------------------
ChangeLog:

* Fri Sep 5 2025 Garry T. Williams [gtwilliams@gmail.com] 1.0-12.20200312git97d2850
- Fix CVE-2025-9810
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2392589 - CVE-2025-9810 linenoise: TOCTOU race in Linenoise enables arbitrary file overwrite and permission changes [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2392589
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-b83972992e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--