Fedora Linux 9425 Published by

The Fedora Project released security updates for Fedora 43 and 44 addressing multiple vulnerabilities across nuclei, the Linux kernel, routinator dependencies, perl-Crypt-OpenSSL-X509, btrbk, and mupdf. The nuclei update to version 3.11.0 resolves over a dozen CVEs including cross-site scripting flaws and unauthorized command execution risks, while kernel releases fix critical issues in net/can and KVM subsystems alongside btrbk patches for CVE-2026-62943 and mupdf corrections for an out-of-bounds read disclosure. Updates to the rust-routinator ecosystem address path traversal vulnerabilities in rsync URI parsing, panics during AS number handling, and XML regression issues discovered through a security audit.

Fedora 43 Update: nuclei-3.11.0-1.fc43
Fedora 43 Update: kernel-7.1.4-102.fc43
Fedora 43 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc43
Fedora 43 Update: rust-syslog-7.0.0-2.fc43
Fedora 43 Update: rust-rpki-0.19.3-2.fc43
Fedora 43 Update: rust-fern-0.7.1-6.fc43
Fedora 43 Update: rust-routinator-0.15.2-1.fc43
Fedora 44 Update: kernel-7.1.4-202.fc44
Fedora 44 Update: btrbk-0.32.7-1.fc44
Fedora 44 Update: mupdf-1.27.2-2.fc44
Fedora 44 Update: nuclei-3.11.0-1.fc44
Fedora 44 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc44
Fedora 44 Update: rust-rpki-0.19.3-2.fc44
Fedora 44 Update: rust-fern-0.7.1-6.fc44
Fedora 44 Update: rust-ifcfg-devname-1.1.1-5.fc44
Fedora 44 Update: rust-syslog-7.0.0-2.fc44
Fedora 44 Update: rust-routinator-0.15.2-1.fc44




[SECURITY] Fedora 43 Update: nuclei-3.11.0-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d36ca2dd19
2026-07-22 01:14:14.597338+00:00
--------------------------------------------------------------------------------

Name : nuclei
Product : Fedora 43
Version : 3.11.0
Release : 1.fc43
URL : https://github.com/projectdiscovery/nuclei
Summary : Fast, customizable YAML-based vulnerability scanner
Description :
Nuclei is a fast, customizable vulnerability scanner powered by the global
security community and built on a simple YAML-based DSL, enabling collaboration
to tackle trending vulnerabilities on the internet. It helps you find
vulnerabilities in your applications, APIs, networks, DNS, and cloud
configurations.

--------------------------------------------------------------------------------
Update Information:

Update to 3.11.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 13 2026 Emir Akdag [infraw.linux@proton.me] - 3.11.0-1
- Update to 3.11.0
* Mon Apr 20 2026 Emir Akdag [infraw.linux@proton.me] - 3.8.0-1
- Update to 3.8.0
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2458978 - CVE-2026-5160 nuclei: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2458978
[ 2 ] Bug #2458996 - CVE-2026-5160 nuclei: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2458996
[ 3 ] Bug #2459399 - nuclei-3.8.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2459399
[ 4 ] Bug #2476565 - CVE-2026-41646 nuclei: Nuclei: Information disclosure via JavaScript template local file access bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2476565
[ 5 ] Bug #2476566 - CVE-2026-41646 nuclei: Nuclei: Information disclosure via JavaScript template local file access bypass [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2476566
[ 6 ] Bug #2486214 - CVE-2026-45287 nuclei: OpenTelemetry-Go: Denial of Service due to file descriptor leak [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486214
[ 7 ] Bug #2486232 - CVE-2026-45287 nuclei: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486232
[ 8 ] Bug #2487471 - nuclei-3.11.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2487471
[ 9 ] Bug #2489899 - CVE-2026-39828 nuclei: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489899
[ 10 ] Bug #2489934 - CVE-2026-39828 nuclei: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489934
[ 11 ] Bug #2490042 - CVE-2026-39829 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490042
[ 12 ] Bug #2490112 - CVE-2026-39829 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490112
[ 13 ] Bug #2490438 - CVE-2026-39830 nuclei: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490438
[ 14 ] Bug #2490462 - CVE-2026-39830 nuclei: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490462
[ 15 ] Bug #2493069 - CVE-2026-39832 nuclei: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493069
[ 16 ] Bug #2493085 - CVE-2026-39832 nuclei: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493085
[ 17 ] Bug #2493471 - CVE-2026-39835 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493471
[ 18 ] Bug #2493525 - CVE-2026-39835 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493525
[ 19 ] Bug #2493562 - CVE-2026-41567 nuclei: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493562
[ 20 ] Bug #2493610 - CVE-2026-41567 nuclei: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493610
[ 21 ] Bug #2495247 - CVE-2026-25681 nuclei: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495247
[ 22 ] Bug #2495316 - CVE-2026-25681 nuclei: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495316
[ 23 ] Bug #2496503 - CVE-2026-44740 nuclei: Billy: Denial of Service via crafted input due to insufficient validation [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496503
[ 24 ] Bug #2496506 - CVE-2026-44740 nuclei: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496506
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d36ca2dd19' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: kernel-7.1.4-102.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f1fc7772c3
2026-07-22 01:14:14.597340+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 43
Version : 7.1.4
Release : 102.fc43
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.4-102/202 stable kernel updates contain a few important fixes across the
tree.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important
security issue with net/can.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-2]
- Revert "PCI/MSI: Unmap MSI-X region on error" (Yuanhe Shu)
- Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" (Matthew Wilcox (Oracle))
- drm/amdkfd: always resume_all after suspend_all (Alex Deucher)
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim)
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal)
- KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (Hyunwoo Kim)
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson)
* Mon Jul 20 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-1]
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f1fc7772c3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7b98f6d033
2026-07-22 01:14:14.597330+00:00
--------------------------------------------------------------------------------

Name : perl-Crypt-OpenSSL-X509
Product : Fedora 43
Version : 2.1.3
Release : 1.fc43
URL : https://metacpan.org/release/Crypt-OpenSSL-X509
Summary : Perl interface to OpenSSL for X509
Description :
Crypt::OpenSSL::X509 - Perl extension to OpenSSL's X509 API.

--------------------------------------------------------------------------------
Update Information:

Fixes CVE-2026-58101 and CVE-2026-58102
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 12 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.3-1
- Update to 2.1.3 (RHBZ#2499481)
- Fixes CVE-2026-58101 and CVE-2026-58102
* Thu Jun 25 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.2-1
- Update to 2.1.2 (RHBZ#2492657)
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 2.1.1-2
- Rebuilt for openssl 4.0
* Mon Jun 8 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.1-1
- Update to 2.1.1 (RHBZ#2484541)
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.0.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7b98f6d033' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: rust-syslog-7.0.0-2.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-659cb50390
2026-07-22 01:14:14.597278+00:00
--------------------------------------------------------------------------------

Name : rust-syslog
Product : Fedora 43
Version : 7.0.0
Release : 2.fc43
URL : https://crates.io/crates/syslog
Summary : Syslog message formatter and writer
Description :
Syslog message formatter and writer, supporting unix sockets, UDP and
TCP exporters.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 7.0.0-2
- Commit rust2rpm.toml
* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 7.0.0-1
- Update to version 7.0.0; Resolves RHBZ#2300127
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-659cb50390' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: rust-rpki-0.19.3-2.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-659cb50390
2026-07-22 01:14:14.597278+00:00
--------------------------------------------------------------------------------

Name : rust-rpki
Product : Fedora 43
Version : 0.19.3
Release : 2.fc43
URL : https://crates.io/crates/rpki
Summary : Library for validating and creating RPKI data
Description :
A library for validating and creating RPKI data.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 6 2026 Michel Lind [salimma@fedoraproject.org] - 0.19.3-2
- Allow building against quick-xml 0.41
* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.19.3-1
- Update to version 0.19.3; Resolves RHBZ#2396345
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-659cb50390' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: rust-fern-0.7.1-6.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-659cb50390
2026-07-22 01:14:14.597278+00:00
--------------------------------------------------------------------------------

Name : rust-fern
Product : Fedora 43
Version : 0.7.1
Release : 6.fc43
URL : https://crates.io/crates/fern
Summary : Simple, efficient logging
Description :
Simple, efficient logging.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.7.1-6
- Switch to building against syslog 7
* Sat Jan 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.7.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-659cb50390' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 43 Update: rust-routinator-0.15.2-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-659cb50390
2026-07-22 01:14:14.597278+00:00
--------------------------------------------------------------------------------

Name : rust-routinator
Product : Fedora 43
Version : 0.15.2
Release : 1.fc43
URL : https://crates.io/crates/routinator
Summary : RPKI relying party software
Description :
An RPKI relying party software.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.15.2-1
- Update to version 0.15.2; Resolves RHBZ#2400457
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-659cb50390' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: kernel-7.1.4-202.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-2dd8b600bb
2026-07-22 00:56:39.194581+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 44
Version : 7.1.4
Release : 202.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.4-102/202 stable kernel updates contain a few important fixes across the
tree.
The 7.1.4-101/201 stable kernel update contains a fix for a rather important
security issue with net/can.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 21 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-2]
- Revert "PCI/MSI: Unmap MSI-X region on error" (Yuanhe Shu)
- Revert "btrfs: fix the file offset calculation inside btrfs_decompress_buf2page()" (Matthew Wilcox (Oracle))
- drm/amdkfd: always resume_all after suspend_all (Alex Deucher)
- KVM: nVMX: Hide shadow VMCS right after VMCLEAR (Hyunwoo Kim)
- KVM: x86: Only reset TSC Deadline Timer in apic_timer_expired on KVM_RUN (Venkatesh Srinivas)
- KVM: x86/mmu: Fix use-after-free on vendor module reload (Phil Rosenthal)
- KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (Hyunwoo Kim)
- KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Sean Christopherson)
* Mon Jul 20 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.4-1]
- can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (Lee Jones)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-2dd8b600bb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: btrbk-0.32.7-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-131c82812a
2026-07-22 00:56:39.194560+00:00
--------------------------------------------------------------------------------

Name : btrbk
Product : Fedora 44
Version : 0.32.7
Release : 1.fc44
URL : https://digint.ch/btrbk/
Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes
Description :
Backup tool for btrfs sub-volumes, using a configuration file, allows
creation of backups from multiple sources to multiple destinations,
with ssh and flexible retention policy support (hourly, daily,
weekly, monthly)

--------------------------------------------------------------------------------
Update Information:

Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 20 2026 Juan Orti Alcaine [jortialc@redhat.com] - 0.32.7-1
- Update to 0.32.7 (RHBZ#2502632) which includes fix for CVE-2026-62943
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.32.6-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2502632 - btrbk-0.32.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2502632
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-131c82812a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: mupdf-1.27.2-2.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d815916e2c
2026-07-22 00:56:39.194551+00:00
--------------------------------------------------------------------------------

Name : mupdf
Product : Fedora 44
Version : 1.27.2
Release : 2.fc44
URL : http://mupdf.com/
Summary : A lightweight PDF viewer and toolkit
Description :
MuPDF is a lightweight PDF viewer and toolkit written in portable C.
The renderer in MuPDF is tailored for high quality anti-aliased
graphics. MuPDF renders text with metrics and spacing accurate to
within fractions of a pixel for the highest fidelity in reproducing
the look of a printed page on screen.
MuPDF has a small footprint. A binary that includes the standard
Roman fonts is only one megabyte. A build with full CJK support
(including an Asian font) is approximately seven megabytes.
MuPDF has support for all non-interactive PDF 1.7 features, and the
toolkit provides a simple API for accessing the internal structures of
the PDF document. Example code for navigating interactive links and
bookmarks, encrypting PDF files, extracting fonts, images, and
searchable text, and rendering pages to image files is provided.

--------------------------------------------------------------------------------
Update Information:

fix CVE-2026-7233 (rhbz#2463402)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 16 2026 Michael J Gruber [mjg@fedoraproject.org] - 1.27.2-2
- fix CVE-2026-7233 (rhbz#2463402)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2463402 - CVE-2026-7233 mupdf: Artifex MuPDF: Information disclosure due to out-of-bounds read [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2463402
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d815916e2c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: nuclei-3.11.0-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-3a8abe43fb
2026-07-22 00:56:39.194542+00:00
--------------------------------------------------------------------------------

Name : nuclei
Product : Fedora 44
Version : 3.11.0
Release : 1.fc44
URL : https://github.com/projectdiscovery/nuclei
Summary : Fast, customizable YAML-based vulnerability scanner
Description :
Nuclei is a fast, customizable vulnerability scanner powered by the global
security community and built on a simple YAML-based DSL, enabling collaboration
to tackle trending vulnerabilities on the internet. It helps you find
vulnerabilities in your applications, APIs, networks, DNS, and cloud
configurations.

--------------------------------------------------------------------------------
Update Information:

Update to 3.11.0
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 13 2026 Emir Akdag [infraw.linux@proton.me] - 3.11.0-1
- Update to 3.11.0
* Mon Apr 20 2026 Emir Akdag [infraw.linux@proton.me] - 3.8.0-1
- Update to 3.8.0
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2458978 - CVE-2026-5160 nuclei: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2458978
[ 2 ] Bug #2458996 - CVE-2026-5160 nuclei: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2458996
[ 3 ] Bug #2459399 - nuclei-3.8.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2459399
[ 4 ] Bug #2476565 - CVE-2026-41646 nuclei: Nuclei: Information disclosure via JavaScript template local file access bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2476565
[ 5 ] Bug #2476566 - CVE-2026-41646 nuclei: Nuclei: Information disclosure via JavaScript template local file access bypass [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2476566
[ 6 ] Bug #2486214 - CVE-2026-45287 nuclei: OpenTelemetry-Go: Denial of Service due to file descriptor leak [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486214
[ 7 ] Bug #2486232 - CVE-2026-45287 nuclei: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486232
[ 8 ] Bug #2487471 - nuclei-3.11.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2487471
[ 9 ] Bug #2489899 - CVE-2026-39828 nuclei: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489899
[ 10 ] Bug #2489934 - CVE-2026-39828 nuclei: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489934
[ 11 ] Bug #2490042 - CVE-2026-39829 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490042
[ 12 ] Bug #2490112 - CVE-2026-39829 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490112
[ 13 ] Bug #2490438 - CVE-2026-39830 nuclei: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490438
[ 14 ] Bug #2490462 - CVE-2026-39830 nuclei: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490462
[ 15 ] Bug #2493069 - CVE-2026-39832 nuclei: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493069
[ 16 ] Bug #2493085 - CVE-2026-39832 nuclei: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493085
[ 17 ] Bug #2493471 - CVE-2026-39835 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493471
[ 18 ] Bug #2493525 - CVE-2026-39835 nuclei: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493525
[ 19 ] Bug #2493562 - CVE-2026-41567 nuclei: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493562
[ 20 ] Bug #2493610 - CVE-2026-41567 nuclei: Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493610
[ 21 ] Bug #2495247 - CVE-2026-25681 nuclei: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495247
[ 22 ] Bug #2495316 - CVE-2026-25681 nuclei: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495316
[ 23 ] Bug #2496503 - CVE-2026-44740 nuclei: Billy: Denial of Service via crafted input due to insufficient validation [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496503
[ 24 ] Bug #2496506 - CVE-2026-44740 nuclei: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496506
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-3a8abe43fb' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-Crypt-OpenSSL-X509-2.1.3-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-df7ecb3577
2026-07-22 00:56:39.194525+00:00
--------------------------------------------------------------------------------

Name : perl-Crypt-OpenSSL-X509
Product : Fedora 44
Version : 2.1.3
Release : 1.fc44
URL : https://metacpan.org/release/Crypt-OpenSSL-X509
Summary : Perl interface to OpenSSL for X509
Description :
Crypt::OpenSSL::X509 - Perl extension to OpenSSL's X509 API.

--------------------------------------------------------------------------------
Update Information:

Fixes CVE-2026-58101 and CVE-2026-58102
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 12 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.3-1
- Update to 2.1.3 (RHBZ#2499481)
- Fixes CVE-2026-58101 and CVE-2026-58102
* Thu Jun 25 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.2-1
- Update to 2.1.2 (RHBZ#2492657)
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 2.1.1-2
- Rebuilt for openssl 4.0
* Mon Jun 8 2026 Xavier Bachelot [xavier@bachelot.org] - 2.1.1-1
- Update to 2.1.1 (RHBZ#2484541)
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-df7ecb3577' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: rust-rpki-0.19.3-2.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec9f1ca21a
2026-07-22 00:56:39.194459+00:00
--------------------------------------------------------------------------------

Name : rust-rpki
Product : Fedora 44
Version : 0.19.3
Release : 2.fc44
URL : https://crates.io/crates/rpki
Summary : Library for validating and creating RPKI data
Description :
A library for validating and creating RPKI data.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 6 2026 Michel Lind [salimma@fedoraproject.org] - 0.19.3-2
- Allow building against quick-xml 0.41
* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.19.3-1
- Update to version 0.19.3; Resolves RHBZ#2396345
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: rust-fern-0.7.1-6.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec9f1ca21a
2026-07-22 00:56:39.194459+00:00
--------------------------------------------------------------------------------

Name : rust-fern
Product : Fedora 44
Version : 0.7.1
Release : 6.fc44
URL : https://crates.io/crates/fern
Summary : Simple, efficient logging
Description :
Simple, efficient logging.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.7.1-6
- Switch to building against syslog 7
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: rust-ifcfg-devname-1.1.1-5.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec9f1ca21a
2026-07-22 00:56:39.194459+00:00
--------------------------------------------------------------------------------

Name : rust-ifcfg-devname
Product : Fedora 44
Version : 1.1.1
Release : 5.fc44
URL : https://crates.io/crates/ifcfg-devname
Summary : Udev helper utility that provides network interface naming
Description :
Udev helper utility that provides network interface naming.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 1.1.1-5
- Allow building against syslog 7
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: rust-syslog-7.0.0-2.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec9f1ca21a
2026-07-22 00:56:39.194459+00:00
--------------------------------------------------------------------------------

Name : rust-syslog
Product : Fedora 44
Version : 7.0.0
Release : 2.fc44
URL : https://crates.io/crates/syslog
Summary : Syslog message formatter and writer
Description :
Syslog message formatter and writer, supporting unix sockets, UDP and
TCP exporters.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 7.0.0-2
- Commit rust2rpm.toml
* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 7.0.0-1
- Update to version 7.0.0; Resolves RHBZ#2300127
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: rust-routinator-0.15.2-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-ec9f1ca21a
2026-07-22 00:56:39.194459+00:00
--------------------------------------------------------------------------------

Name : rust-routinator
Product : Fedora 44
Version : 0.15.2
Release : 1.fc44
URL : https://crates.io/crates/routinator
Summary : RPKI relying party software
Description :
An RPKI relying party software.

--------------------------------------------------------------------------------
Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and
syslog), and switch fern to using syslog 7 instead of 6 for this update, and
loosen the syslog version bound for ifcfg-devname.
v0.15.2
This release fixes a number of vulnerabilities and security issues identified by
a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency.
We advise all users to upgrade at their earliest convenience.
Security fixes
Changed how transient errors when accepting incoming HTTP and RTR connections
are handled: instead of exiting, a warning is printed and the error is ignored.
([#1099])
This issue was assigned CVE-2026-49232.
Extended the check for illegal path components in rsync URIs to also include the
authority and module parts. (via rpki-rs#370)
This fixes a path traversal vulnerability that has been assigned CVE-2026-49233.
Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373)
This fixes a vulnerability that has been assigned CVE-2026-49234.
Upgraded quick-xml to at least 0.39.4 to fix a regression in XML parsing that
may lead a panic on certain crated XML files. (via rpki-rs#372)
This fixes a vulnerability that has been assigned CVE-2026-49235.
Improvements
Restricted trust anchor certificates downloaded via HTTP to the size given via
the max_object_size config option. (#1090)
The -e and --rsh options will now be rejected in the rsync-args config option.
Similarly, Routinator will not start if the equivalent evironment variable
RSYNC_RSH is set. (#1091)
Bug fixes
Set an RTR listener socket received via systemd to non-blocking. This fixes a
panic in Tokio. (#1081 by @MaxHearnden)
Fixed the --rrdp-tcp-keepalive to be a command line option rather than a command
line argument. ([1085])
Other changes
Support for Ubuntu Resolute Raccoon (26.04). (#1095)
v0.15.1
Bug fixes
Abort the optimistic initial run if there are no stored TA certificates for a
TAL instead of succeeding with an empty data set. (#1071)
Undo PrivateUsers restriction in systemd unit files to allow user to run
Routinator on privileged ports. (#1068)
v0.15.0
Breaking changes
Removed the rrdp-keep-responses feature. We suggest the use of an HTTP proxy
such as mitmproxy instead.
This once and for all fixes CVE-2023-39916 which returned again in release
0.14.0. (#1055)
* Messages about issues with repositories and publication points are now logged
separately and by default are only visible in the status HTTP server endpoints.
The new log-repository-issues option can be used to have these messages also
written to the log. ([#1054])
* Changed how server mode deals with broken or missing local exception files.
Previously, Routinator would just stop updating until they are fixed, leading to
updates being stalled if the operator misses the error messages. Now it will log
a warning and keep using the previous set of local exceptions. When starting, it
will exit with an error message if there are broken or missing local exception
files. (#1060)
* Changed the RRDP timeouts: introduced a new config variable rrdp-read-timeout
that provides a timeout for individual network operations (primarily: read from
the server). Its default is 10 seconds. This timeout is also used for connecting
of no specific value is given, significantly speeding up validation runs.
In addition, the RRDP timeout was increased from 300 to 600 seconds to better
deal with slow transmission of large snapshots of some repositories. (#1061)
New
Added a quick initial run after starting the server which only uses stored data
and aborts if any required data hasn’t been requested before to deal with
configuration changes. This will shorten the wait time for an initial data set
when restarting Routinator. (#1057)
Added support for SLURM v2 as output format which includes ASPA payload. (#1021)
Changed refresh behaviour to better cope with short-lived objects. By default,
Routinator will now wait for the time defined by refresh even if objects expire
earlier. The new min-refresh option can be used to specify a short minimum
refresh time if objects expire before the refresh time. If this value is set to
0, the old behaviour is restored. (#1027)
The order in which manifest entries are processed is now randomized. (#1041)
Reduced the overhead of storing RRDP snapshot downloads, significantly improving
the snapshot update times. (#1035)
The dump command now prints the source directories of the data it dumps. (#1045)
Added a --update-after option to the vrps subcommand that skips updating the
local cache if the last successful validation run was known to be less than a
given number of minutes ago. (#1049)
Error responses for API-related HTTP endpoints now contain JSON bodies.
([#1050])
The /validity HTTP server endpoint now accepts POST requests with a JSON body
containing multiple routes to be checked all at once. (#1053)
Better protect against corrupted stored publication points by double checking
cached manifest properties against the actual manifest and discard the stored
publication point if they mismatch.
This fixes an issue where an accidentally or maliciously manipulated locally
stored manifest could block update of a legitimate new manifest which was
reported by Zizhi Shang, Zhechao Lin, Jiahao Cao, Yangyang Wang, Mingwei Xu of
the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University.
Bug fixes
Fixed a crash if certain invalid character appear in a manifest file name by
limiting the name to the rules defined in RFC9286. This issue was reported by
Niklas Vogel of Goethe University Frankfurt and ATHENE. (rpki-rs#342)
Re-implemented RRDP client metrics based on the much simpler model used by RTRTR
to fix recurring errors in the metrics. (#1039)
Changed the message logged when an RRDP update times out to actually say that.
(#1052)
Other changes
Improved performance of file system operations on validate subcommand. (#1043 by
@kawaemon)
Add package.homepage to Cargo.toml (#1024)
Added building packages for RHEL 10 and Debian 13. (#1034, #1047)
Added building packages for ARMv6 and ARM64 for Debian Bookworm. (#1036)
Added additional restrictions to the systemd unit files used in the various
binary packages. (#1056)
Upgrades various dependencies. (#1004, #1005, #1006)
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 2 2026 Michel Lind [salimma@fedoraproject.org] - 0.15.2-1
- Update to version 0.15.2; Resolves RHBZ#2400457
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id#00127
[ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id#96345
[ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id$00457
[ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$97975
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------