Fedora 43 Update: unbound-1.25.2-1.fc43
Fedora 43 Update: dokuwiki-20250514b-4.fc43
Fedora 43 Update: pack-0.40.8-1.fc43
Fedora 43 Update: nasm-2.16.03-5.fc43
Fedora 43 Update: valkey-8.1.9-1.fc43
Fedora 43 Update: lego-5.3.1-2.fc43
Fedora 43 Update: libnbd-1.24.3-1.fc43
Fedora 44 Update: dokuwiki-20250514b-6.fc44
Fedora 44 Update: pack-0.40.8-1.fc44
Fedora 44 Update: valkey-9.0.5-1.fc44
[SECURITY] Fedora 43 Update: unbound-1.25.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-3170ee6a1c
2026-07-31 01:13:00.179901+00:00
--------------------------------------------------------------------------------
Name : unbound
Product : Fedora 43
Version : 1.25.2
Release : 1.fc43
URL : https://nlnetlabs.nl/projects/unbound/
Summary : Validating, recursive, and caching DNS(SEC) resolver
Description :
Unbound is a validating, recursive, and caching DNS(SEC) resolver.
The C implementation of Unbound is developed and maintained by NLnet
Labs. It is based on ideas and algorithms taken from a java prototype
developed by Verisign labs, Nominet, Kirei and ep.net.
Unbound is designed as a set of modular components, so that also
DNSSEC (secure DNS) validation and stub-resolvers (that do not run
as a server, but are linked into an application) are easily possible.
--------------------------------------------------------------------------------
Update Information:
Update to 1.25.2 (rhbz#2506061)
Security fixes:
Fix CVE-2026-14586, Assertion in libngtcp2 when under pressure in high
concurrency DNS-over-QUIC environments. Thanks to Kunta Chu, Kaihua Wang, and
Jianjun Chen from Tsinghua University, for the report.
Fix CVE-2026-32665, Remote DNS-over-QUIC denial of service due to quic-size
budget bypass. Thanks to N0zoM1z0 ( https://github.com/N0zoM1z0) for the report.
In addition, thanks to Kunta Chu, Kaihua Wang, and Jianjun Chen from Tsinghua
University, for also reporting this issue. In addition, thanks to Qifan Zhang,
Palo Alto Networks, for also reporting this issue. In addition, thanks to
Xuanchao Xie, for also reporting this issue.
Fix CVE-2026-40691, Packet of death for DNSCrypt over TCP. Thanks to Qifan
Zhang, Palo Alto Networks, for the report. In addition, thanks to Trung Nguyen
(@everping) of CyStack, for also reporting this issue.
Fix CVE-2026-41637, Degradation of resolution service from improperly accounted
client-terminated DNS-over-QUIC queries. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA
records disallowing a one-time 'ghost domain' delegation renewal via glue
records. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-44621, Libunbound applications configured with 'unwanted-reply-
threshold' could eventually be abruptly terminated. Thanks to Qifan Zhang, Palo
Alto Networks, for the report.
Fix CVE-2026-44687, Off-by-one error in 'harden-below-nxdomain' logic can shadow
a stub/forward zone by a legitimate parent's NXDOMAIN. Thanks to Qifan Zhang,
Palo Alto Networks, for the report.
Fix CVE-2026-44690, Cross-zone wildcard cache poisoning via RRSIG.labels
manipulation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-46582, A wildcard replay, as another piece of data, triggers
poisoning in the serve expired reply path. Thanks to Qifan Zhang, Palo Alto
Networks, for the report.
Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC validation restarts.
Thanks to Kunjie Shang, University of Science and Technology of China, for the
report.
Fix CVE-2026-50046, Possible heap use-after-free in an error path when a DoT
forwarded query is jostled out. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS answers instead of
returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-50248, BOGUS configured primary hostname accepted for XFR in
auth/rpz zones. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-50251, Attacker supplied 0.0.0.0/:: glue triggers defensive full-
cache flush. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-50252, Possible cache poisoning attack by mapping source port
population per thread. Thanks to Inbal Schussheim and Amit Klein, Hebrew
University, for the report.
Fix CVE-2026-52863, Memory corruption could lead to crash and denial of service.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-54478, DNS Cookie bypass when combined with proxy-protocol use.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-55708, Privacy/configuration issue when adding local data in views
through 'unbound-control'. Thanks to Qifan Zhang, Palo Alto Networks, for the
report.
Fix CVE-2026-55717, 'serve-expired-client-timeout' and 'response-ip' CNAME
redirect could lead to a crash. Thanks to Qifan Zhang, Palo Alto Networks, for
the report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu,
Northwestern Polytechnical University, for also reporting this issue.
Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to stack buffer overflow.
Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-55990, Packet of death for a DNSCrypt misconfigured Unbound. Thanks
to Qifan Zhang, Palo Alto Networks, for the report.
Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control assertion failure in
libngtcp2. Thanks to Qifan Zhang, Palo Alto Networks, for the report. In
addition, thanks to Xuanchao Xie, for also reporting this issue.
Fix CVE-2026-56416, Possible heap buffer overflow when validator canonicalizes
RDATA that contains domain name. Thanks to Qifan Zhang, Palo Alto Networks, for
the report.
Fix CVE-2026-56444, Degradation of resolution service when 'discard-timeout' and
'serve-expired-client-timeout' are combined in unusual configuration. Thanks to
Qifan Zhang, Palo Alto Networks, for the report. In addition, thanks to Xin
Wang, Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for
also reporting this issue. In addition, thanks to Haruki Oyama (Waseda
University), for also reporting this issue.
Source: https://nlnetlabs.nl/projects/unbound/download/#unbound-1-25-2
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jul 27 2026 Fedor Vorobev [fvorobev@redhat.com] - 1.25.2-1
- Update to 1.25.2 (rhbz#2506061)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2491434 - CVE-2026-44390 unbound: Unbound: Denial of Service due to excessive resource consumption with large DNS Resource Record Sets [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491434
[ 2 ] Bug #2491795 - CVE-2026-42534 unbound: Unbound: Denial of Service due to degraded resolution performance in jostle logic [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491795
[ 3 ] Bug #2491930 - CVE-2026-41292 unbound: Unbound: Denial of Service via excessive EDNS options [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491930
[ 4 ] Bug #2491940 - CVE-2026-41292 unbound: Unbound: Denial of Service via excessive EDNS options [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2491940
[ 5 ] Bug #2506061 - unbound-1.25.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2506061
[ 6 ] Bug #2506178 - CVE-2026-40691 unbound: Unbound: Denial of Service via crafted DNSCrypt query [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506178
[ 7 ] Bug #2506420 - CVE-2026-56416 unbound: Unbound: Heap buffer overflow via malformed DNSSEC record [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506420
[ 8 ] Bug #2506834 - CVE-2026-14586 unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2506834
[ 9 ] Bug #2507425 - CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507425
[ 10 ] Bug #2507454 - CVE-2026-54478 unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507454
[ 11 ] Bug #2507649 - CVE-2026-55973 unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507649
[ 12 ] Bug #2507650 - CVE-2026-44690 unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507650
[ 13 ] Bug #2507651 - CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507651
[ 14 ] Bug #2507955 - CVE-2026-50251 unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2507955
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-3170ee6a1c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: dokuwiki-20250514b-4.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-68853bb50c
2026-07-31 01:13:00.179882+00:00
--------------------------------------------------------------------------------
Name : dokuwiki
Product : Fedora 43
Version : 20250514b
Release : 4.fc43
URL : https://www.dokuwiki.org/dokuwiki
Summary : Standards compliant simple to use wiki
Description :
DokuWiki is a standards compliant, simple to use Wiki, mainly aimed at creating
documentation of any kind. It has a simple but powerful syntax which makes sure
the data-files remain readable outside the Wiki and eases the creation of
structured texts.
All data is stored in plain text files no database is required.
--------------------------------------------------------------------------------
Update Information:
Backport some security fixes
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Artur Frenszek-Iwicki [fedora@svgames.pl] - 20250514b-4
- Backport some more security patches
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-68853bb50c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: pack-0.40.8-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e6e0368149
2026-07-31 01:13:00.179886+00:00
--------------------------------------------------------------------------------
Name : pack
Product : Fedora 43
Version : 0.40.8
Release : 1.fc43
URL : https://github.com/buildpacks/pack
Summary : Convert code into runnable images
Description :
pack is a CLI implementation of the Platform Interface Specification
for Cloud Native Buildpacks.
--------------------------------------------------------------------------------
Update Information:
Security update to pack 0.40.8
Fixes CVE-2024-25621: containerd - local privilege escalation
Fixes CVE-2025-47913: golang.org/x/crypto/ssh/agent - SSH client panic
Fixes CVE-2025-47914: golang.org/x/crypto/ssh/agent - SSH Agent server DoS
Fixes CVE-2025-52881: container escape and denial of service
Fixes CVE-2026-27145: crypto/x509 - DoS via excessive DNS SAN processing
Fixes CVE-2026-33762: go-git - DoS via crafted Git index file
Fixes CVE-2026-34165: go-git - DoS via crafted .idx file
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution
Fixes CVE-2026-39829: golang.org/x/crypto/ssh - DoS via crafted public key
Fixes CVE-2026-39830: golang.org/x/crypto/ssh - Resource leak DoS
Fixes CVE-2026-39832: golang.org/x/crypto/ssh/agent - Key restrictions bypass
Fixes CVE-2026-39833: golang.org/x/crypto/ssh/agent - Key confirmation bypass
Fixes CVE-2026-39835: golang.org/x/crypto/ssh - Certificate DoS
Fixes CVE-2026-44740: go-billy - DoS via symlink cycle
Fixes GO-2026-4970: Root escape via symlink plus trailing slash
Fixes GO-2026-5856: Encrypted Client Hello privacy leak
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Lokesh Mandvekar [lsm5@redhat.com] - 0.40.8-1
- Update to 0.40.8
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.40.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2419047 - CVE-2024-25621 pack: containerd local privilege escalation [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2419047
[ 2 ] Bug #2420625 - CVE-2025-47913 pack: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420625
[ 3 ] Bug #2424069 - [Minor Incident] CVE-2025-52881 pack: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2424069
[ 4 ] Bug #2454569 - CVE-2026-34165 pack: go-git: Denial of Service via crafted .idx file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2454569
[ 5 ] Bug #2454570 - CVE-2026-33762 pack: go-git: Denial of Service via crafted Git index file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2454570
[ 6 ] Bug #2478228 - pack-0.40.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2478228
[ 7 ] Bug #2490496 - CVE-2026-39830 pack: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490496
[ 8 ] Bug #2493089 - CVE-2026-39832 pack: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493089
[ 9 ] Bug #2493535 - CVE-2026-39835 pack: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493535
[ 10 ] Bug #2494334 - CVE-2026-27145 pack: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494334
[ 11 ] Bug #2494451 - CVE-2026-39833 pack: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494451
[ 12 ] Bug #2496516 - CVE-2026-44740 pack: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496516
[ 13 ] Bug #2503325 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503325
[ 14 ] Bug #2503623 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503623
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e6e0368149' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: nasm-2.16.03-5.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9af234bcd6
2026-07-31 01:13:00.179875+00:00
--------------------------------------------------------------------------------
Name : nasm
Product : Fedora 43
Version : 2.16.03
Release : 5.fc43
URL : http://www.nasm.us
Summary : A portable x86 assembler which uses Intel-like syntax
Description :
NASM is the Netwide Assembler, a free portable assembler for the Intel
80x86 microprocessor series, using primarily the traditional Intel
instruction mnemonics and syntax.
--------------------------------------------------------------------------------
Update Information:
Fixes for CVE-2026-6067 and CVE-2026-6068.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Dominik Mierzejewski [rpm@greysector.net] - 2.16.03-5
- fix CVE-2026-6067 (resolves rhbz#2458087, rhbz#2458089)
patch by Nick Clifton
- backport fix for CVE-2026-6068 (resolves rhbz#2458090)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2458089 - CVE-2026-6067 nasm: Netwide Assembler (NASM): Arbitrary code execution via malicious assembly file processing [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2458089
[ 2 ] Bug #2458090 - CVE-2026-6068 nasm: NASM: Heap use after free vulnerability in response file processing [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2458090
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9af234bcd6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: valkey-8.1.9-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-9de44775c7
2026-07-31 01:13:00.179858+00:00
--------------------------------------------------------------------------------
Name : valkey
Product : Fedora 43
Version : 8.1.9
Release : 1.fc43
URL : https://valkey.io
Summary : A persistent key-value database
Description :
Valkey is an advanced key-value store. It is often referred to as a data
structure server since keys can contain strings, hashes, lists, sets and
sorted sets.
You can run atomic operations on these types, like appending to a string;
incrementing the value in a hash; pushing to a list; computing set
intersection, union and difference; or getting the member with highest
ranking in a sorted set.
In order to achieve its outstanding performance, Valkey works with an
in-memory dataset. Depending on your use case, you can persist it either
by dumping the dataset to disk every once in a while, or by appending
each command to a log.
Valkey also supports trivial-to-setup master-slave replication, with very
fast non-blocking first synchronization, auto-reconnection on net split
and so forth.
Other features include Transactions, Pub/Sub, Lua scripting, Keys with a
limited time-to-live, and configuration settings to make Valkey behave like
a cache.
You can use Valkey from most programming languages also.
See https://valkey.io/topics/
--------------------------------------------------------------------------------
Update Information:
Valkey 8.1.9 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security Fixes
CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow
an authenticated client to achieve remote code execution using CLIENT KILL
(#4234)
CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across
consumers, which could allow remote code execution. Reported by @z0v3r1n and
@lifip. (#4073)
Bug Fixes
Fix clients being left on the wrong database after module keyspace notifications
from commands like MOVE and COPY by @enjoy-binbin (#4024)
Fix an I/O thread job queue memory-ordering race that could trigger an assertion
crash on ARM/aarch64 by @jjuleslasarte (#3878)
Reject zipmap RESTORE payloads with overflowing length fields that could cause
out-of-bounds access on 32-bit builds by @madolson (#3920)
Reject NAN scores when loading listpack/ziplist-encoded sorted sets, preventing
a crash from crafted RESTORE payloads by @madolson (#3921)
Fix a startup crash when generating INFO output on 32-bit systems where time_t
is 64-bit (e.g. Alpine time64) by @chenshi5012 (#3787)
Fix COMMAND INFO in RESP3 to reply with an empty Array instead of a Set for
commands without subcommands by @rickrams (#3939)
Reject invalid characters in cluster AUX fields and cluster-announce-ip to
prevent nodes.conf corruption and injection by @eifrah-aws (#3848)
Fix lua-enable-insecure-api having no effect when enabled at startup via config
file or command line by @enjoy-binbin (#3548)
Increase the maximum process title length from 255 to 1024 characters to avoid
truncation with long installation paths by @pkhartsk (#3843)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Remi Collet [remi@remirepo.net] - 8.1.9-1
- Valkey 8.1.9 - Released Tue 21 July 2026
- Upgrade urgency SECURITY: This release includes security fixes
CVE-2026-56684 CVE-2026-63639
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-9de44775c7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: lego-5.3.1-2.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-256592dfe7
2026-07-31 01:13:00.179868+00:00
--------------------------------------------------------------------------------
Name : lego
Product : Fedora 43
Version : 5.3.1
Release : 2.fc43
URL : https://github.com/go-acme/lego
Summary : Let's Encrypt/ACME client written in Go
Description :
Let's Encrypt/ACME client written in Go.
--------------------------------------------------------------------------------
Update Information:
Update to 5.3.1
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jul 21 2026 Packit [hello@packit.dev] - 5.3.1-1
- Update to 5.3.1 upstream release
- Resolves: rhbz#2504092
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 5.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2500376 - CVE-2026-10846 lego: ldns: Off-path poisoning attacks due to insufficient query-response matching [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2500376
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-256592dfe7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: libnbd-1.24.3-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-045e6f85c6
2026-07-31 01:13:00.179832+00:00
--------------------------------------------------------------------------------
Name : libnbd
Product : Fedora 43
Version : 1.24.3
Release : 1.fc43
URL : https://gitlab.com/nbdkit/libnbd
Summary : NBD client library in userspace
Description :
NBD — Network Block Device — is a protocol for accessing Block Devices
(hard disks and disk-like things) over a Network.
This is the NBD client library in userspace, a simple library for
writing NBD clients.
The key features are:
* Synchronous and asynchronous APIs, both for ease of use and for
writing non-blocking, multithreaded clients.
* High performance.
* Minimal dependencies for the basic library.
* Well-documented, stable API.
* Bindings in several programming languages.
--------------------------------------------------------------------------------
Update Information:
New upstream stable version 1.24.3
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 15 2026 Richard W.M. Jones [rjones@redhat.com] - 1.24.3-1
- New upstream stable version 1.24.3
- Fixes command injection in nbd+ssh URIs (RHEL-189057)
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-045e6f85c6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 44 Update: dokuwiki-20250514b-6.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d37b1b981a
2026-07-31 00:54:29.804789+00:00
--------------------------------------------------------------------------------
Name : dokuwiki
Product : Fedora 44
Version : 20250514b
Release : 6.fc44
URL : https://www.dokuwiki.org/dokuwiki
Summary : Standards compliant simple to use wiki
Description :
DokuWiki is a standards compliant, simple to use Wiki, mainly aimed at creating
documentation of any kind. It has a simple but powerful syntax which makes sure
the data-files remain readable outside the Wiki and eases the creation of
structured texts.
All data is stored in plain text files no database is required.
--------------------------------------------------------------------------------
Update Information:
Backport some security fixes
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Artur Frenszek-Iwicki [fedora@svgames.pl] - 20250514b-6
- Backport some more security patches
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d37b1b981a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: pack-0.40.8-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8729dce4b8
2026-07-31 00:54:29.804794+00:00
--------------------------------------------------------------------------------
Name : pack
Product : Fedora 44
Version : 0.40.8
Release : 1.fc44
URL : https://github.com/buildpacks/pack
Summary : Convert code into runnable images
Description :
pack is a CLI implementation of the Platform Interface Specification
for Cloud Native Buildpacks.
--------------------------------------------------------------------------------
Update Information:
Security update to pack 0.40.8
Fixes CVE-2024-25621: containerd - local privilege escalation
Fixes CVE-2025-47913: golang.org/x/crypto/ssh/agent - SSH client panic
Fixes CVE-2025-47914: golang.org/x/crypto/ssh/agent - SSH Agent server DoS
Fixes CVE-2025-52881: container escape and denial of service
Fixes CVE-2026-27145: crypto/x509 - DoS via excessive DNS SAN processing
Fixes CVE-2026-33762: go-git - DoS via crafted Git index file
Fixes CVE-2026-34165: go-git - DoS via crafted .idx file
Fixes CVE-2026-39828: golang.org/x/crypto/ssh - Unauthorized command execution
Fixes CVE-2026-39829: golang.org/x/crypto/ssh - DoS via crafted public key
Fixes CVE-2026-39830: golang.org/x/crypto/ssh - Resource leak DoS
Fixes CVE-2026-39832: golang.org/x/crypto/ssh/agent - Key restrictions bypass
Fixes CVE-2026-39833: golang.org/x/crypto/ssh/agent - Key confirmation bypass
Fixes CVE-2026-39835: golang.org/x/crypto/ssh - Certificate DoS
Fixes CVE-2026-44740: go-billy - DoS via symlink cycle
Fixes GO-2026-4970: Root escape via symlink plus trailing slash
Fixes GO-2026-5856: Encrypted Client Hello privacy leak
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Lokesh Mandvekar [lsm5@redhat.com] - 0.40.8-1
- Update to 0.40.8
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.40.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2419047 - CVE-2024-25621 pack: containerd local privilege escalation [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2419047
[ 2 ] Bug #2420625 - CVE-2025-47913 pack: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2420625
[ 3 ] Bug #2424069 - [Minor Incident] CVE-2025-52881 pack: container escape and denial of service due to arbitrary write gadgets and procfs write redirects [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2424069
[ 4 ] Bug #2454569 - CVE-2026-34165 pack: go-git: Denial of Service via crafted .idx file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2454569
[ 5 ] Bug #2454570 - CVE-2026-33762 pack: go-git: Denial of Service via crafted Git index file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2454570
[ 6 ] Bug #2478228 - pack-0.40.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2478228
[ 7 ] Bug #2489893 - CVE-2026-39828 pack: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489893
[ 8 ] Bug #2490092 - CVE-2026-39829 pack: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490092
[ 9 ] Bug #2490496 - CVE-2026-39830 pack: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490496
[ 10 ] Bug #2493089 - CVE-2026-39832 pack: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493089
[ 11 ] Bug #2493535 - CVE-2026-39835 pack: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493535
[ 12 ] Bug #2494334 - CVE-2026-27145 pack: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494334
[ 13 ] Bug #2494451 - CVE-2026-39833 pack: golang.org/x/crypto/ssh/agent: Security bypass due to unenforced key confirmation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2494451
[ 14 ] Bug #2496516 - CVE-2026-44740 pack: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496516
[ 15 ] Bug #2503325 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503325
[ 16 ] Bug #2503623 - CVE-2025-47914 pack: SSH Agent servers: Denial of Service due to malformed messages [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2503623
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8729dce4b8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: valkey-9.0.5-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-3d18a65cc4
2026-07-31 00:54:29.804769+00:00
--------------------------------------------------------------------------------
Name : valkey
Product : Fedora 44
Version : 9.0.5
Release : 1.fc44
URL : https://valkey.io
Summary : A persistent key-value database
Description :
Valkey is an advanced key-value store. It is often referred to as a data
structure server since keys can contain strings, hashes, lists, sets and
sorted sets.
You can run atomic operations on these types, like appending to a string;
incrementing the value in a hash; pushing to a list; computing set
intersection, union and difference; or getting the member with highest
ranking in a sorted set.
In order to achieve its outstanding performance, Valkey works with an
in-memory dataset. Depending on your use case, you can persist it either
by dumping the dataset to disk every once in a while, or by appending
each command to a log.
Valkey also supports trivial-to-setup master-slave replication, with very
fast non-blocking first synchronization, auto-reconnection on net split
and so forth.
Other features include Transactions, Pub/Sub, Lua scripting, Keys with a
limited time-to-live, and configuration settings to make Valkey behave like
a cache.
You can use Valkey from most programming languages also.
See https://valkey.io/topics/
--------------------------------------------------------------------------------
Update Information:
Valkey 9.0.5 - Released Tue 21 July 2026
Upgrade urgency SECURITY: This release includes security fixes we recommend you
apply as soon as possible.
Security Fixes
CVE-2026-56684: Fix a use-after-free in TLS connection handling that could allow
an authenticated client to achieve remote code execution using CLIENT KILL
(#4234)
CVE-2026-63639: Reject corrupt stream RDB files containing a shared NACK across
consumers, which could allow remote code execution. Reported by @z0v3r1n and
@lifip. (#4073)
Bug Fixes
Strictly validate CRLF terminators when parsing the RESP protocol; malformed
requests now get a protocol error instead of being misparsed by @enjoy-binbin
(#2872)
Fix a use-after-free crash when creating slot import jobs during manual slot
migrations by @twooster (#3283)
Fix a memory leak in ZDIFF and ZDIFFSTORE when the result set becomes empty
before all inputs are processed by @sarthakaggarwal97 (#3342)
Fix HPERSIST sending a malformed reply that desynchronized the connection when
used on a key of the wrong type by @madolson (#3516)
Fix a crash from a race between IO threads and asynchronous client freeing by
@deepakrn (#3458)
Fix a double free when loading a stream with corrupt consumer PEL data from RDB
or RESTORE by @enjoy-binbin (#3498)
Fix listpack corruption and a subsequent crash when XTRIM marks the last entry
of a stream listpack node as deleted by @smkher (#3591)
Fix malformed replies when module callbacks build deferred-length arrays while a
client's deferred reply buffer is active by @eifrah-aws (#3578)
Fix a NULL pointer crash in TLS pending-data handling by @zuiderkwast (#3641)
Fix a server crash when multiple RDMA clients disconnect at the same time by
@quanyeyang (#3448)
Fix a use-after-free when ACL LOAD deletes a user whose clients cannot be freed
immediately by @ranshid (#3800)
Fix a use-after-free when a module unregisters the first registered cluster
message receiver for a message type by @eifrah-aws (#3846)
Fix HRANDFIELD looping forever when a hash has fewer non-expired fields than the
requested count by @cjx-zar (#4047)
Fix clients being left on the wrong database after module keyspace notifications
for commands like MOVE and COPY by @enjoy-binbin (#4024)
Fix a Sentinel crash during coordinated failover when the connection to the old
primary is disconnected by @lukepalmer (#4068)
Fix underestimation of client output buffer memory when replies reference shared
objects, so buffer limits are enforced correctly by @dvkashapov (#3306)
Fix a crash on ARM/aarch64 caused by memory-ordering races in the IO thread job
queue by @jjuleslasarte (#3878)
Fix a crash when active hash field expiration leaves a single entry in a large
expiration time-bucket by @ranshid (#3950)
Fix a file descriptor leak when a blocking connection attempt, such as MIGRATE
to an unreachable host, times out by @madolson (#3541)
Fix a potential crash from a dangling slot migration job reference when the
migration client is reset by @murphyjacob4 (#3554)
Remove cached EVAL scripts when their scripting engine is unregistered,
preventing dangling engine references by @eifrah-aws (#3503)
Fix a memory leak in GEOSEARCH BYPOLYGON when argument parsing fails, such as on
an invalid COUNT by @bandalgomsu (#3568)
Fix a crash when a slot migration target node is removed from the cluster before
the migration connects by @chenshi5012 (#3596)
Fix a crash when the module GetLRU/SetLRU/GetLFU/SetLFU APIs are called with a
NULL key by @yaronsananes (#3610)
Fix an assertion failure in hash field expiration commands when a module blocks
the client in a keyspace notification by @enjoy-binbin (#3743)
Fix a cluster UPDATE log message reading shard IDs past their fixed-length
buffer by @enjoy-binbin (#3942)
Fix undefined behavior in the failover delay calculation when cluster-node-
timeout is set below 30 milliseconds by @enjoy-binbin (#3941)
Reject zipmap RESTORE payloads with overflowing length fields that could cause
out-of-bounds access on 32-bit builds by @madolson (#3920)
Reject NAN scores in listpack- and ziplist-encoded sorted sets on RDB/RESTORE
load, preventing a later crash on skiplist conversion by @madolson (#3921)
Fix a startup crash on 32-bit systems with 64-bit time_t, such as Alpine 3.23,
caused by time value formatting mismatches by @chenshi5012 (#3787)
Fix corrupted client replies when IO threads are enabled, caused by a race
between in-flight writes and reply buffer reuse by @nanyan0312 (#4060)
COMMAND INFO in RESP3 now returns the subcommands field as an Array instead of a
Set for commands without subcommands by @rickrams (#3939)
The dual-channel replication RDB connection now announces the configured
replica-announce-ip, avoiding stale replica entries behind NAT by @jdheyburn
(#2846)
Prevent replicas from processing stale cluster packets and incorrectly promoting
themselves to an empty primary within a shard by @zhijun42 (#2811)
Send the replica version on the dual-channel RDB connection so full syncs of
data like hash field TTLs no longer fail by @hpatro (#4105)
Fix slot migration failure handling running twice on ownership changes and an
out-of-order error reply in the internal SYNCSLOTS FINISH command by @chx9
(#3723)
Allow slot-migration-max-failover-repl-bytes to be set to -1 to disable the
limit, as documented by @enjoy-binbin (#3443)
Fix CONFIG REWRITE producing negative values for memory configs such as
maxmemory when set to very large values by @enjoy-binbin (#3440)
Reject SENTINEL SET values containing control characters and safely quote
Sentinel config values to prevent config file injection by @eifrah-aws (#3847)
Reject control characters and delimiters in cluster AUX fields and validate
cluster-announce-ip to prevent nodes.conf corruption or injection by @eifrah-aws
(#3848)
Fix changes to lua-enable-insecure-api via CONFIG SET not taking effect when the
option was set at startup by @enjoy-binbin (#4182)
Fix incorrect memory overhead reported for watched keys in client memory usage
tracking by @enjoy-binbin (#3359)
Replica logs now report 'Connection reset by peer' instead of the misleading
'Success' when the primary closes the connection by @abmathur-ie (#3580)
Redact key names and user data from more log messages when hide-user-data-from-
log is enabled by @zackcam (#3872)
Fix INFO replication reporting negative sync transfer sizes when the RDB exceeds
2GB during disk-based sync by @chx9 (#3811)
Increase the maximum process title length from 255 to 1024 characters to avoid
truncation with long installation paths by @pkhartsk (#3843)
valkey-cli --cluster del-node can now remove unreachable or failed nodes instead
of failing with 'No such node ID' by @yang-z-o (#3209)
Fix valkey-cli crashing after --eval script execution on jemalloc/tcmalloc
builds by @bandalgomsu (#3281)
valkey-cli --cluster fix now spreads uncovered slots randomly across primaries
instead of assigning them all to one node by @abmathur-ie (#3586)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 22 2026 Remi Collet [remi@remirepo.net] - 9.0.5-1
- Valkey 9.0.5 - Released Tue 21 July 2026
- Upgrade urgency SECURITY: This release includes security fixes
CVE-2026-56684 CVE-2026-63639
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-3d18a65cc4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new