Fedora 43 Update: udisks2-2.11.2-1.fc43
Fedora 43 Update: pgadmin4-9.17-1.fc43
Fedora 43 Update: bird-3.3.2-1.fc43
Fedora 44 Update: nghttp2-1.68.0-5.fc44
Fedora 44 Update: pgadmin4-9.17-1.fc44
Fedora 44 Update: bird-3.3.2-1.fc44
[SECURITY] Fedora 43 Update: udisks2-2.11.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1925a10b0b
2026-08-09 01:17:20.193645+00:00
--------------------------------------------------------------------------------
Name : udisks2
Product : Fedora 43
Version : 2.11.2
Release : 1.fc43
URL : https://github.com/storaged-project/udisks
Summary : Disk Manager
Description :
The Udisks project provides a daemon, tools and libraries to access and
manipulate disks, storage devices and technologies.
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release 2.11.2
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 6 2026 Tomas Bzatek [tbzatek@redhat.com] - 2.11.2-1
- Version 2.11.2
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1925a10b0b' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: pgadmin4-9.17-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-bacb14f76f
2026-08-09 01:17:20.193623+00:00
--------------------------------------------------------------------------------
Name : pgadmin4
Product : Fedora 43
Version : 9.17
Release : 1.fc43
URL : https://www.pgadmin.org/
Summary : Administration tool for PostgreSQL
Description :
pgAdmin is the most popular and feature rich Open Source administration and development
platform for PostgreSQL, the most advanced Open Source database in the world.
--------------------------------------------------------------------------------
Update Information:
Update to pgadmin-9.17.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 31 2026 Sandro Mani [manisandro@gmail.com] - 9.17-1
- Update to 9.17
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 9.16-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509742 - pgadmin4-9.17 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2509742
[ 2 ] Bug #2509859 - CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509859
[ 3 ] Bug #2509867 - CVE-2026-17566 pgadmin4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509867
[ 4 ] Bug #2510676 - CVE-2026-17351 pgadmin4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510676
[ 5 ] Bug #2510678 - CVE-2026-17347 pgadmin4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510678
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-bacb14f76f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: bird-3.3.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-3521e54a27
2026-08-09 01:17:20.193590+00:00
--------------------------------------------------------------------------------
Name : bird
Product : Fedora 43
Version : 3.3.2
Release : 1.fc43
URL : https://bird.nic.cz/
Summary : BIRD Internet Routing Daemon
Description :
BIRD is a dynamic IP routing daemon supporting both, IPv4 and IPv6, Border
Gateway Protocol (BGPv4), Routing Information Protocol (RIPv2, RIPng), Open
Shortest Path First protocol (OSPFv2, OSPFv3), Babel Routing Protocol (Babel),
Bidirectional Forwarding Detection (BFD), IPv6 router advertisements, static
routes, inter-table protocol, command-line interface allowing on-line control
and inspection of the status of the daemon, soft reconfiguration as well as a
powerful language for route filtering.
--------------------------------------------------------------------------------
Update Information:
BIRD 3.3.2 (2026-07-30)
BGP: Fix stack buffer overflow in Flowspec NLRI decoder
BGP: Minor improvements in Flowspec parsing
BGP: Fix minor issues with send hold timer
Fix null byte handling in authentication keys
Pipe, L3VPN: Fix hostentry stripping
Filter: Fix zero arg handling
Logging: Fix use-after-free on failed rotation
CLI: Fix crashes in show route
Allocator: Pre-fill hot pages when entering RCU critical section
Fix obstacle cleanup
Update bird-users mailing list links
See also: https://trubka.network.cz/archives/list/bird-
users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 31 2026 Robert Scheck [robert@fedoraproject.org] - 3.3.2-1
- Upgrade to 3.3.2
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.3.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-3521e54a27' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: nghttp2-1.68.0-5.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-084c991d17
2026-08-09 00:58:50.095755+00:00
--------------------------------------------------------------------------------
Name : nghttp2
Product : Fedora 44
Version : 1.68.0
Release : 5.fc44
URL : https://nghttp2.org/
Summary : Experimental HTTP/2 client, server and proxy
Description :
This package contains the HTTP/2 client, server and proxy programs.
--------------------------------------------------------------------------------
Update Information:
fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous
HTTP/1.1 Upgrade requests (CVE-2026-58055)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 7 2026 Jan Macku [jamacku@redhat.com] - 1.68.0-5
- fix HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests (CVE-2026-58055)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2502788 - CVE-2026-58055 nghttp2: nghttp2: HTTP Request/Response Smuggling and Response-Queue Poisoning via ambiguous HTTP/1.1 Upgrade requests [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2502788
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-084c991d17' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: pgadmin4-9.17-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f0550055a7
2026-08-09 00:58:50.095708+00:00
--------------------------------------------------------------------------------
Name : pgadmin4
Product : Fedora 44
Version : 9.17
Release : 1.fc44
URL : https://www.pgadmin.org/
Summary : Administration tool for PostgreSQL
Description :
pgAdmin is the most popular and feature rich Open Source administration and development
platform for PostgreSQL, the most advanced Open Source database in the world.
--------------------------------------------------------------------------------
Update Information:
Update to pgadmin-9.17.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 31 2026 Sandro Mani [manisandro@gmail.com] - 9.17-1
- Update to 9.17
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 9.16-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2509742 - pgadmin4-9.17 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2509742
[ 2 ] Bug #2509859 - CVE-2026-17348 pgadmin4: pgAdmin 4: Unauthenticated access allows data manipulation and information disclosure [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509859
[ 3 ] Bug #2509867 - CVE-2026-17566 pgadmin4: pgAdmin 4: Remote Code Execution via backslash-escape mismatch in Import/Export Data tool [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509867
[ 4 ] Bug #2510676 - CVE-2026-17351 pgadmin4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045) [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510676
[ 5 ] Bug #2510678 - CVE-2026-17347 pgadmin4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2510678
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f0550055a7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: bird-3.3.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-c2b9288d46
2026-08-09 00:58:50.095678+00:00
--------------------------------------------------------------------------------
Name : bird
Product : Fedora 44
Version : 3.3.2
Release : 1.fc44
URL : https://bird.nic.cz/
Summary : BIRD Internet Routing Daemon
Description :
BIRD is a dynamic IP routing daemon supporting both, IPv4 and IPv6, Border
Gateway Protocol (BGPv4), Routing Information Protocol (RIPv2, RIPng), Open
Shortest Path First protocol (OSPFv2, OSPFv3), Babel Routing Protocol (Babel),
Bidirectional Forwarding Detection (BFD), IPv6 router advertisements, static
routes, inter-table protocol, command-line interface allowing on-line control
and inspection of the status of the daemon, soft reconfiguration as well as a
powerful language for route filtering.
--------------------------------------------------------------------------------
Update Information:
BIRD 3.3.2 (2026-07-30)
BGP: Fix stack buffer overflow in Flowspec NLRI decoder
BGP: Minor improvements in Flowspec parsing
BGP: Fix minor issues with send hold timer
Fix null byte handling in authentication keys
Pipe, L3VPN: Fix hostentry stripping
Filter: Fix zero arg handling
Logging: Fix use-after-free on failed rotation
CLI: Fix crashes in show route
Allocator: Pre-fill hot pages when entering RCU critical section
Fix obstacle cleanup
Update bird-users mailing list links
See also: https://trubka.network.cz/archives/list/bird-
users@network.cz/thread/XOVK5DHDS4LXJ5HB5PZX7533T7JEZZ4U/
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 31 2026 Robert Scheck [robert@fedoraproject.org] - 3.3.2-1
- Upgrade to 3.3.2
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.3.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-c2b9288d46' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new