Fedora Linux 9442 Published by

Fedora issued a coordinated set of security advisories for versions 43 and 44 that close active vulnerability gaps across essential system packages. The release updates open62541 to 1.5.6, pushes doctl to 1.164.0, ships Linux kernel 7.1.6 with upstream stability fixes, rebuilds Perl 5.42.3 dependencies, and resolves multiple flaw codes in ABRT, Coreutils, and related utilities. Each notification details specific CVE remediations that neutralize denial of service vectors, memory corruption flaws, file injection risks, and race conditions threatening system integrity.

Fedora 43 Update: open62541-1.5.6-1.fc43
Fedora 43 Update: doctl-1.164.0-1.fc43
Fedora 44 Update: kernel-7.1.6-201.fc44
Fedora 44 Update: perl-PAR-Packer-1.064-6.fc44
Fedora 44 Update: polymake-4.15-11.fc44
Fedora 44 Update: perl-5.42.3-525.fc44
Fedora 44 Update: perl-Devel-Cover-1.52-4.fc44
Fedora 44 Update: abrt-2.17.9-1.fc44
Fedora 44 Update: coreutils-9.10-5.fc44
Fedora 44 Update: open62541-1.5.6-1.fc44
Fedora 44 Update: doctl-1.164.0-1.fc44




[SECURITY] Fedora 43 Update: open62541-1.5.6-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1435f05fde
2026-08-05 01:09:53.664458+00:00
--------------------------------------------------------------------------------

Name : open62541
Product : Fedora 43
Version : 1.5.6
Release : 1.fc43
URL : http://open62541.org
Summary : OPC UA implementation
Description :
open62541 is a C-based library (linking with C++ projects is possible)
with all necessary tools to implement dedicated OPC UA clients and servers,
or to integrate OPC UA-based communication into existing applications.

--------------------------------------------------------------------------------
Update Information:

Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 27 2026 Peter Robinson [pbrobinson@fedoraproject.org] - 1.5.6-1
- Update to 1.5.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.5.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2494014 - open62541-1.5.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2494014
[ 2 ] Bug #2496477 - CVE-2026-33592 open62541: open62541: Remote attacker can cause Denial of Service via FindServers Discovery Service [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496477
[ 3 ] Bug #2496524 - CVE-2026-11946 open62541: open62541: Denial of Service via unvalidated endpoint URL length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496524
[ 4 ] Bug #2502803 - CVE-2026-15690 open62541: open62541: Denial of Service via crafted request [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502803
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1435f05fde' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 43 Update: doctl-1.164.0-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a36bdff8d7
2026-08-05 01:09:53.664434+00:00
--------------------------------------------------------------------------------

Name : doctl
Product : Fedora 43
Version : 1.164.0
Release : 1.fc43
URL : https://github.com/digitalocean/doctl
Summary : The official command line interface for the DigitalOcean API
Description :
The official command line interface for the DigitalOcean API.

--------------------------------------------------------------------------------
Update Information:

Update to 1.164.0
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 26 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 1.164.0-1
- Update to 1.164.0 - Closes rhbz#2486990
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.160.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2486226 - CVE-2026-45287 doctl: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486226
[ 2 ] Bug #2489942 - CVE-2026-39828 doctl: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489942
[ 3 ] Bug #2490084 - CVE-2026-39829 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490084
[ 4 ] Bug #2490454 - CVE-2026-39830 doctl: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490454
[ 5 ] Bug #2493503 - CVE-2026-39835 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493503
[ 6 ] Bug #2496442 - CVE-2026-47262 doctl: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496442
[ 7 ] Bug #2496562 - CVE-2026-53492 doctl: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496562
[ 8 ] Bug #2503225 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2503225
[ 9 ] Bug #2503289 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503289
[ 10 ] Bug #2503520 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2503520
[ 11 ] Bug #2503587 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503587
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a36bdff8d7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: kernel-7.1.6-201.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-864f36550e
2026-08-05 00:54:07.585296+00:00
--------------------------------------------------------------------------------

Name : kernel
Product : Fedora 44
Version : 7.1.6
Release : 201.fc44
URL : https://www.kernel.org/
Summary : The Linux kernel
Description :
The kernel meta package

--------------------------------------------------------------------------------
Update Information:

The 7.1.6 stable kernel updates contain a number of important fixes across the
tree. We are now specifying all kernel updates as security because upstream
will assign CVEs, but we will not know what those are until a bit after this
update ships.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.6-1]
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
* Mon Aug 3 2026 Justin M. Forbes [jforbes@fedoraproject.org] [7.1.6-1]
- vhost: reset the vring metadata cache on vring reconfiguration (Jun Yang)
* Mon Aug 3 2026 Augusto Caringi [acaringi@redhat.com] [7.1.6-0]
- New config for stable (Justin M. Forbes)
- acpi: battery: Sanitise model_number by dropping unprintable characters (Kate Hsuan)
- redhat: configs: Enable AMD ISP4 MIPI camera solution (Kate Hsuan)
- media: platform: amd: add DRM_AMDGPU dependency (Arnd Bergmann)
- media: platform: amd: isp4: drop stale list reinit before free (Bin Du)
- media: platform: amd: isp4 debug fs logging and more descriptive errors (Bin Du)
- media: platform: amd: isp4 video node and buffers handling added (Bin Du)
- media: platform: amd: isp4 subdev and firmware loading handling added (Bin Du)
- media: platform: amd: Add isp4 fw and hw interface (Bin Du)
- media: platform: amd: low level support for isp4 firmware (Bin Du)
- media: platform: amd: Introduce amd isp4 capture driver (Bin Du)
- serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (Jiangshan Yi)
- Linux v7.1.6
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-864f36550e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-PAR-Packer-1.064-6.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-475559cbb9
2026-08-05 00:54:07.585289+00:00
--------------------------------------------------------------------------------

Name : perl-PAR-Packer
Product : Fedora 44
Version : 1.064
Release : 6.fc44
URL : https://metacpan.org/release/PAR-Packer
Summary : PAR Packager
Description :
This module implements the App::Packer::Backend interface, for generating
stand-alone executables, perl scripts and PAR files.

--------------------------------------------------------------------------------
Update Information:

Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.064-6
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-475559cbb9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: polymake-4.15-11.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-475559cbb9
2026-08-05 00:54:07.585289+00:00
--------------------------------------------------------------------------------

Name : polymake
Product : Fedora 44
Version : 4.15
Release : 11.fc44
URL : https://polymake.org/
Summary : Algorithms on convex polytopes and polyhedra
Description :
Polymake is a tool to study the combinatorics and the geometry of convex
polytopes and polyhedra. It is also capable of dealing with simplicial
complexes, matroids, polyhedral fans, graphs, tropical objects, and so forth.

Polymake can use various computational packages if they are installed. Those
available from Fedora are: 4ti2, azove, gfan, latte-integrale, normaliz,
qhull, Singular, TOPCOM, and vinci.

Polymake can interface with various visualization packages if they are
installed. Install one or more of the tools from the following list: evince,
geomview, graphviz, gv, and okular.

--------------------------------------------------------------------------------
Update Information:

Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 4.15-11
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-475559cbb9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-5.42.3-525.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-475559cbb9
2026-08-05 00:54:07.585289+00:00
--------------------------------------------------------------------------------

Name : perl
Product : Fedora 44
Version : 5.42.3
Release : 525.fc44
URL : https://www.perl.org/
Summary : Practical Extraction and Report Language
Description :
Perl is a high-level programming language with roots in C, sed, awk and shell
scripting. Perl is good at handling processes and files, and is especially
good at handling text. Perl's hallmarks are practicality and efficiency.
While it is used to do a lot of different things, Perl's most common
applications are system administration utilities and web programming.

This is a metapackage with all the Perl bits and core modules that can be
found in the upstream tarball from perl.org.

If you need only a specific feature, you can install a specific package
instead. E.g. to handle Perl scripts with /usr/bin/perl interpreter,
install perl-interpreter package. See perl-interpreter description for more
details on the Perl decomposition into packages.

--------------------------------------------------------------------------------
Update Information:

Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 4:5.42.3-525
- 5.42.3 bump (see https://metacpan.org/release/SHAY/perl-5.42.3/view/pod/perldelta.pod>)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-475559cbb9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: perl-Devel-Cover-1.52-4.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-475559cbb9
2026-08-05 00:54:07.585289+00:00
--------------------------------------------------------------------------------

Name : perl-Devel-Cover
Product : Fedora 44
Version : 1.52
Release : 4.fc44
URL : https://metacpan.org/release/Devel-Cover
Summary : Code coverage metrics for Perl
Description :
This module provides code coverage metrics for Perl. Code coverage metrics
describe how thoroughly tests exercise code. By using Devel::Cover you can
discover areas of code not exercised by your tests and determine which
tests to create to increase coverage. Code coverage can be considered as an
indirect measure of quality.

--------------------------------------------------------------------------------
Update Information:

Update Perl to 5.42.3
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Jitka Plesnikova [jplesnik@redhat.com] - 1.52-4
- Rebuild for Perl 5.42.3
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2489785 - CVE-2026-8376 perl: Perl: Heap buffer overflow when compiling regular expressions on 32-bit builds [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489785
[ 2 ] Bug #2506204 - CVE-2026-57432 perl: Perl: Information disclosure via integer overflow in pack/unpack operations [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506204
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-475559cbb9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: abrt-2.17.9-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a7417466a1
2026-08-05 00:54:07.585287+00:00
--------------------------------------------------------------------------------

Name : abrt
Product : Fedora 44
Version : 2.17.9
Release : 1.fc44
URL : https://abrt.readthedocs.org/
Summary : Automatic bug detection and reporting tool
Description :
abrt is a tool to help users to detect defects in applications and
to create a bug report with all information needed by maintainer to fix it.
It uses plugin system to extend its functionality.

--------------------------------------------------------------------------------
Update Information:

Update to 2.17.9
Resolves: rhbz#2484614
Resolves: CVE-2026-54230
Resolves: CVE-2026-54231
Resolves: CVE-2026-54228
Resolves: CVE-2026-54229
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Michal Srb [michal@redhat.com] - 2.17.9-1
- Fix journal entry spoofing in journal dump services
- Resolves: rhbz#2484614
- Fix symlink following in event handler scripts
- Resolves: CVE-2026-54230
- Fix content injection in journal log collection
- Resolves: CVE-2026-54231
- Fix TOCTOU in SetElement/DeleteElement
- Resolves: CVE-2026-54228
- Fix race condition in ChownProblemDir
- Resolves: CVE-2026-54229
* Wed Jul 22 2026 Python Maint - 2.17.8-6
- Rebuilt for Python 3.15.0b4 ABI change
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.17.8-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu Jun 4 2026 Python Maint - 2.17.8-4
- Rebuilt for Python 3.15
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2484614 - ABRT abrt-dump-journal-core trusts spoofed systemd-coredump journal fields, allowing local root file disclosure
https://bugzilla.redhat.com/show_bug.cgi?id=2484614
[ 2 ] Bug #2488616 - CVE-2026-54228 abrt: TOCTOU race condition in abrt-dbus SetElement allows arbitrary file writes to dump directories [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488616
[ 3 ] Bug #2488617 - CVE-2026-54229 abrt: ChownProblemDir succeeds during active post-create event processing due to inadequate locking [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488617
[ 4 ] Bug #2488618 - CVE-2026-54231 abrt: unsanitized systemd journal content written to dump directory files enables content injection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488618
[ 5 ] Bug #2488619 - CVE-2026-54230 abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2488619
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a7417466a1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: coreutils-9.10-5.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-36041358b1
2026-08-05 00:54:07.585271+00:00
--------------------------------------------------------------------------------

Name : coreutils
Product : Fedora 44
Version : 9.10
Release : 5.fc44
URL : https://www.gnu.org/software/coreutils/
Summary : A set of basic GNU tools commonly used in shell scripts
Description :
These are the GNU core utilities. This package is the combination of
the old GNU fileutils, sh-utils, and textutils packages.

--------------------------------------------------------------------------------
Update Information:

fix CVE-2026-56391
--------------------------------------------------------------------------------
ChangeLog:

* Mon Aug 3 2026 Lukáš Zaoral [lzaoral@redhat.com] - 9.10-5
- CVE-2026-56391 - uniq: fix read overrun with -w (rhbz#2507449)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2507449 - CVE-2026-56391 coreutils: GNU coreutils uniq: Denial of Service and information disclosure via out-of-bounds read with multibyte input [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id%07449
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-36041358b1' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: open62541-1.5.6-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-23b21104ef
2026-08-05 00:54:07.585249+00:00
--------------------------------------------------------------------------------

Name : open62541
Product : Fedora 44
Version : 1.5.6
Release : 1.fc44
URL : http://open62541.org
Summary : OPC UA implementation
Description :
open62541 is a C-based library (linking with C++ projects is possible)
with all necessary tools to implement dedicated OPC UA clients and servers,
or to integrate OPC UA-based communication into existing applications.

--------------------------------------------------------------------------------
Update Information:

Update to 1.5.6
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 27 2026 Peter Robinson [pbrobinson@fedoraproject.org] - 1.5.6-1
- Update to 1.5.6
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.5.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2494014 - open62541-1.5.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2494014
[ 2 ] Bug #2496477 - CVE-2026-33592 open62541: open62541: Remote attacker can cause Denial of Service via FindServers Discovery Service [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496477
[ 3 ] Bug #2496524 - CVE-2026-11946 open62541: open62541: Denial of Service via unvalidated endpoint URL length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496524
[ 4 ] Bug #2502803 - CVE-2026-15690 open62541: open62541: Denial of Service via crafted request [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502803
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-23b21104ef' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: doctl-1.164.0-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7ca1b24b3c
2026-08-05 00:54:07.585227+00:00
--------------------------------------------------------------------------------

Name : doctl
Product : Fedora 44
Version : 1.164.0
Release : 1.fc44
URL : https://github.com/digitalocean/doctl
Summary : The official command line interface for the DigitalOcean API
Description :
The official command line interface for the DigitalOcean API.

--------------------------------------------------------------------------------
Update Information:

Update to 1.164.0
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jul 26 2026 Mikel Olasagasti Uranga [mikel@olasagasti.info] - 1.164.0-1
- Update to 1.164.0 - Closes rhbz#2486990
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 1.160.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2486226 - CVE-2026-45287 doctl: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2486226
[ 2 ] Bug #2489942 - CVE-2026-39828 doctl: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489942
[ 3 ] Bug #2490084 - CVE-2026-39829 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490084
[ 4 ] Bug #2490454 - CVE-2026-39830 doctl: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490454
[ 5 ] Bug #2493503 - CVE-2026-39835 doctl: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493503
[ 6 ] Bug #2496442 - CVE-2026-47262 doctl: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496442
[ 7 ] Bug #2496562 - CVE-2026-53492 doctl: containerd: Security bypass via Container Device Interface (CDI) annotation smuggling during checkpoint restoration. [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496562
[ 8 ] Bug #2503225 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2503225
[ 9 ] Bug #2503289 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503289
[ 10 ] Bug #2503520 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2503520
[ 11 ] Bug #2503587 - CVE-2025-47914 doctl: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503587
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7ca1b24b3c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new