Fedora 43 Update: perl-Mojolicious-9.48-1.fc43
Fedora 43 Update: rpm-6.0.2-1.fc43
Fedora 43 Update: opkssh-0.16.0-1.fc43
Fedora 44 Update: opkssh-0.16.0-1.fc44
Fedora 44 Update: perl-Mojolicious-9.48-1.fc44
Fedora 44 Update: rpm-6.0.2-1.fc44
[SECURITY] Fedora 43 Update: perl-Mojolicious-9.48-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-6f12b08313
2026-07-28 01:18:17.119958+00:00
--------------------------------------------------------------------------------
Name : perl-Mojolicious
Product : Fedora 43
Version : 9.48
Release : 1.fc43
URL : https://metacpan.org/release/Mojolicious
Summary : A next generation web framework for Perl
Description :
Back in the early days of the web there was this wonderful Perl library
called CGI, many people only learned Perl because of it. It was simple
enough to get started without knowing much about the language and powerful
enough to keep you going, learning by doing was much fun. While most of the
techniques used are outdated now, the idea behind it is not. Mojolicious is
a new attempt at implementing this idea using state of the art technology.
--------------------------------------------------------------------------------
Update Information:
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to
BREACH attacks. Tokens are now masked with a fresh random value on every
request, instead of being reused for the whole lifetime of a session.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Emmanuel Seyman [emmanuel@seyman.fr] - 9.48-1
- Update to 9.48
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2500953
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-6f12b08313' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: rpm-6.0.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a9f0d5370e
2026-07-28 01:18:17.119933+00:00
--------------------------------------------------------------------------------
Name : rpm
Product : Fedora 43
Version : 6.0.2
Release : 1.fc43
URL : https://rpm.org/
Summary : The RPM package management system
Description :
The RPM Package Manager (RPM) is a powerful command line driven
package management system capable of installing, uninstalling,
verifying, querying, and updating software packages. Each software
package consists of an archive of files along with information about
the package like its version, a description, etc.
--------------------------------------------------------------------------------
Update Information:
Rebase to 6.0.2 ( https://rpm.org/releases/6.0.2)
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Michal Domonkos [mdomonko@redhat.com] - 6.0.2-1
- Rebase to 6.0.2 ( https://rpm.org/releases/6.0.2)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482483 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2482483
[ 2 ] Bug #2482484 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2482484
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a9f0d5370e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: opkssh-0.16.0-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-168280f3c4
2026-07-28 01:18:17.119965+00:00
--------------------------------------------------------------------------------
Name : opkssh
Product : Fedora 43
Version : 0.16.0
Release : 1.fc43
URL : https://github.com/openpubkey/opkssh
Summary : OpenPubkey SSH
Description :
OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect
allowing SSH access to be managed via identities like alice@example.com instead
of long-lived SSH keys.
--------------------------------------------------------------------------------
Update Information:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Till Hofmann [thofmann@fedoraproject.org] - 0.16.0-1
- Update to 0.16.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500487 - opkssh-0.16.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2500487
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-168280f3c4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: opkssh-0.16.0-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-a0bf40ecfe
2026-07-28 01:00:27.224333+00:00
--------------------------------------------------------------------------------
Name : opkssh
Product : Fedora 44
Version : 0.16.0
Release : 1.fc44
URL : https://github.com/openpubkey/opkssh
Summary : OpenPubkey SSH
Description :
OpenPubkey SSH is a tool which enables ssh to be used with OpenID Connect
allowing SSH access to be managed via identities like alice@example.com instead
of long-lived SSH keys.
--------------------------------------------------------------------------------
Update Information:
Update to 0.16.0.
This release includes a security fix for GQ-commitment PK Tokens
(upgrades the openpubkey dependency to v0.25.0), addressing a
vulnerability affecting GitLab-CI GQ-commitment PK Tokens. Note that
opkssh currently only supports GitLab user OP (not GitLab-CI), so the
vulnerable code path is not reachable through opkssh; severity is set
low accordingly. Also drops the now-obsolete go-jose
dependency_overrides pin, since upstream now requires go-jose v4.1.4
natively.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Jul 19 2026 Till Hofmann [thofmann@fedoraproject.org] - 0.16.0-1
- Update to 0.16.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500487 - opkssh-0.16.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2500487
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-a0bf40ecfe' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: perl-Mojolicious-9.48-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4334fd85bc
2026-07-28 01:00:27.224317+00:00
--------------------------------------------------------------------------------
Name : perl-Mojolicious
Product : Fedora 44
Version : 9.48
Release : 1.fc44
URL : https://metacpan.org/release/Mojolicious
Summary : A next generation web framework for Perl
Description :
Back in the early days of the web there was this wonderful Perl library
called CGI, many people only learned Perl because of it. It was simple
enough to get started without knowing much about the language and powerful
enough to keep you going, learning by doing was much fun. While most of the
techniques used are outdated now, the idea behind it is not. Mojolicious is
a new attempt at implementing this idea using state of the art technology.
--------------------------------------------------------------------------------
Update Information:
Mojolicious 9.48 fixes a security issue where CSRF tokens were vulnerable to
BREACH attacks. Tokens are now masked with a fresh random value on every
request, instead of being reused for the whole lifetime of a session.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 14 2026 Emmanuel Seyman [emmanuel@seyman.fr] - 9.48-1
- Update to 9.48
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500953 - CVE-2026-15747 perl-Mojolicious: Mojolicious: Information disclosure via BREACH compression oracle [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2500953
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4334fd85bc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: rpm-6.0.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9985882270
2026-07-28 01:00:27.224294+00:00
--------------------------------------------------------------------------------
Name : rpm
Product : Fedora 44
Version : 6.0.2
Release : 1.fc44
URL : https://rpm.org/
Summary : The RPM package management system
Description :
The RPM Package Manager (RPM) is a powerful command line driven
package management system capable of installing, uninstalling,
verifying, querying, and updating software packages. Each software
package consists of an archive of files along with information about
the package like its version, a description, etc.
--------------------------------------------------------------------------------
Update Information:
Rebase to 6.0.2 ( https://rpm.org/releases/6.0.2)
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 16 2026 Michal Domonkos [mdomonko@redhat.com] - 6.0.2-1
- Rebase to 6.0.2 ( https://rpm.org/releases/6.0.2)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482482 - CVE-2026-44605 rpm: heap buffer overflow in NDB slot table parsing [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2482482
[ 2 ] Bug #2482485 - CVE-2026-44604 rpm: Command injection in rpmuncompress doUntar() via unescaped archive top-level directory name in popen() shell command [fedora-44]
https://bugzilla.redhat.com/show_bug.cgi?id=2482485
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9985882270' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new