Fedora Linux 9423 Published by

Fedora 43 and Fedora 44 administrators must install new security patches for python-asyncssh, libseccomp, and mbedtls. The python-asyncssh packages resolve CVE-2026-54590 and CVE-2026-54591, which allow unauthorized file modifications and arbitrary writes through SCP path traversal. Fedora 44 received a libseccomp upgrade to version 2.6.1 that enables Python bindings and fixes memory corruption bugs alongside flawed syscall filter merging logic. The mbedtls library advanced to version 3.6.7 to patch seventeen separate cryptographic flaws involving buffer overflows, parsing errors, and TLS negotiation failures.

Fedora 43 Update: python-asyncssh-2.23.1-1.fc43
Fedora 44 Update: libseccomp-2.6.1-2.fc44
Fedora 44 Update: python-asyncssh-2.24.0-1.fc44
Fedora 44 Update: mbedtls-3.6.7-1.fc44




[SECURITY] Fedora 43 Update: python-asyncssh-2.23.1-1.fc43


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-574496d9ae
2026-07-20 01:10:43.961032+00:00
--------------------------------------------------------------------------------

Name : python-asyncssh
Product : Fedora 43
Version : 2.23.1
Release : 1.fc43
URL : https://github.com/ronf/asyncssh
Summary : Asynchronous SSH for Python
Description :
Python 3 library for asynchronous client and
server-side SSH communication. It uses the Python asyncio module and
implements many SSH protocol features such as the various channels,
SFTP, SCP, forwarding, session multiplexing over a connection and more.

--------------------------------------------------------------------------------
Update Information:

import asyncssh 2.23.1
Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory
escape
Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 11 2026 Georg Sauthoff [mail@gms.tf] - 2.23.1-1
- import asyncssh 2.23.1
- fix CVE-2026-54590: Unauthorized file modification via authorized-keys
directory escape (fixes fedora#2498421, fixes fedora#2498423)
- fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client
(fixes fedora#2498488)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498421
[ 2 ] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498423
[ 3 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498488
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-574496d9ae' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: libseccomp-2.6.1-2.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-752186819e
2026-07-20 00:53:11.635413+00:00
--------------------------------------------------------------------------------

Name : libseccomp
Product : Fedora 44
Version : 2.6.1
Release : 2.fc44
URL : https://github.com/seccomp/libseccomp
Summary : Enhanced seccomp library
Description :
The libseccomp library provides an easy to use interface to the Linux Kernel's
syscall filtering mechanism, seccomp. The libseccomp API allows an application
to specify which syscalls, and optionally which syscall arguments, the
application is allowed to execute, all of which are enforced by the Linux
Kernel.

--------------------------------------------------------------------------------
Update Information:

libseccomp 2.6.1
packaging changes
Enable Python bindings on Fedora 44+
upstream changes - July 1, 2026
Update the syscall table for Linux v7.1.0-rc4
Fix incorrect 64-bit comparison merge that can weaken libseccomp filters.
See GitHub Advisory GHSA-4q85-33p6-j5g6
Fix issue where oversized libseccomp filters can trigger a double free.
See GitHub Advisory GHSA-46fr-jh49-xvhx
Fix issue where oversized libseccomp filters can trigger a heap corruption.
See GitHub Advisory GHSA-2hqh-5c36-grrm
Fix struct aliasing undefined behavior in the internal libseccomp hash
algorithm
Fix issue where extraneous bytes were being copied to the destination
buffer in seccomp_export_bpf_mem()
Fix a bug where merged libseccomp filters failed to merge the notify_used
flag, leading to no listener file descriptor being generated
Update python shebang to point to python3
Add documentation for seccomp_transaction_start()
Since support for s390 has been removed from the upstream Linux kernel,
freeze libseccomp's s390 syscall table at Linux v6.18
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 18 2026 Michel Lind [salimma@fedoraproject.org] - 2.6.1-2
- Only enable Python subpackage on Fedora 44 and up
* Sat Jul 18 2026 Michel Lind [salimma@fedoraproject.org] - 2.6.1-1
- Update to version 2.6.1; Resolves: rhbz#2341880
- Build Python bindings; Resolves: rhbz#2437438
- Enable Packit
- Support disabling tests for iterating on spec changes
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.6.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2341880 - libseccomp-2.6.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2341880
[ 2 ] Bug #2437438 - build libseccomp's Python bindings
https://bugzilla.redhat.com/show_bug.cgi?id=2437438
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-752186819e' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new



[SECURITY] Fedora 44 Update: python-asyncssh-2.24.0-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1f248487e4
2026-07-20 00:53:11.635396+00:00
--------------------------------------------------------------------------------

Name : python-asyncssh
Product : Fedora 44
Version : 2.24.0
Release : 1.fc44
URL : https://github.com/ronf/asyncssh
Summary : Asynchronous SSH for Python
Description :
Python 3 library for asynchronous client and
server-side SSH communication. It uses the Python asyncio module and
implements many SSH protocol features such as the various channels,
SFTP, SCP, forwarding, session multiplexing over a connection and more.

--------------------------------------------------------------------------------
Update Information:

update to version 2.24.0
Fix CVE-2026-54590: Unauthorized file modification via authorized-keys directory
escape
Fix CVE-2026-54591: Arbitrary file write via path traversal in SCP client
--------------------------------------------------------------------------------
ChangeLog:

* Sun Jun 28 2026 Georg Sauthoff [mail@gms.tf] - 2.24.0-1
- update to version 2.24.0 (fixes fedora#2468438)
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 2.22.0-6
- Rebuilt for openssl 4.0
* Thu Jun 4 2026 Python Maint - 2.22.0-5
- Rebuilt for Python 3.15
* Wed May 6 2026 Miro HronĨok [miro@hroncok.cz] - 2.22.0-4
- Properly filter out test dependency on uvloop and python-pkcs11
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2468438 - python-asyncssh-2.24.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id$68438
[ 2 ] Bug #2498421 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$98421
[ 3 ] Bug #2498423 - CVE-2026-54590 python-asyncssh: AsyncSSH: Unauthorized file modification via authorized-keys directory escape [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$98423
[ 4 ] Bug #2498488 - CVE-2026-54591 python-asyncssh: AsyncSSH: Arbitrary file write via path traversal in SCP client [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id$98488
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1f248487e4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------



[SECURITY] Fedora 44 Update: mbedtls-3.6.7-1.fc44


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8d954936a5
2026-07-20 00:53:11.635367+00:00
--------------------------------------------------------------------------------

Name : mbedtls
Product : Fedora 44
Version : 3.6.7
Release : 1.fc44
URL : https://www.trustedfirmware.org/projects/mbed-tls
Summary : Light-weight cryptographic and SSL/TLS library
Description :
Mbed TLS is a light-weight open source cryptographic and SSL/TLS
library written in C. Mbed TLS makes it easy for developers to include
cryptographic and SSL/TLS capabilities in their (embedded)
applications with as little hassle as possible.

--------------------------------------------------------------------------------
Update Information:

Update to 3.6.7
Fixes CVE-2026-25832, CVE-2026-35336, CVE-2026-49300, CVE-2026-50579,
CVE-2026-50580, CVE-2026-50581, CVE-2026-50583, CVE-2026-50584, CVE-2026-50585,
CVE-2026-50586, CVE-2026-50587, CVE-2026-50588, CVE-2026-50640, CVE-2026-50713,
CVE-2026-54435, CVE-2026-54441
Release notes: https://github.com/Mbed-TLS/mbedtls/releases#release-
mbedtls-3.6.7
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 11 2026 Morten Stevens [mstevens@fedoraproject.org] - 3.6.7-1
- Update to 3.6.7
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8d954936a5' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new