Fedora 43 Update: rust-libgit2-sys-0.18.7-1.fc43
Fedora 43 Update: libgit2-1.9.6-1.fc43
Fedora 43 Update: nextcloud-34.0.2-1.fc43
Fedora 43 Update: exim-4.99.5-1.fc43
Fedora 43 Update: GitPython-3.1.55-1.fc43
Fedora 43 Update: lemonldap-ng-2.23.2-1.fc43
Fedora 43 Update: postgresql16-16.14-1.fc43
Fedora 43 Update: coturn-4.15.0-1.fc43
Fedora 44 Update: curl-8.18.0-8.fc44
Fedora 44 Update: gh-2.97.0-2.fc44
Fedora 44 Update: xen-4.21.2-1.fc44
Fedora 44 Update: lemonldap-ng-2.23.2-1.fc44
Fedora 44 Update: coturn-4.15.0-1.fc44
[SECURITY] Fedora 43 Update: rust-libgit2-sys-0.18.7-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-61dffcfbe9
2026-08-01 16:03:27.806085+00:00
--------------------------------------------------------------------------------
Name : rust-libgit2-sys
Product : Fedora 43
Version : 0.18.7
Release : 1.fc43
URL : https://crates.io/crates/libgit2-sys
Summary : Native bindings to the libgit2 library
Description :
Native bindings to the libgit2 library.
--------------------------------------------------------------------------------
Update Information:
Update libgit2 to version 1.9.6.
Update the libgit2-sys Rust crate to the corresponding version 0.18.7.
This includes fixes for various security issues, including - but not limited to:
CVE-2026-53583
CVE-2026-53584
CVE-2026-53585
CVE-2026-53586
CVE-2026-53587
The Fedora package is not affected by GHSA-wfx7-g85r-q6vw since Fedora packages
always linked the system PCRE2 and did not use the bundled PCRE.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 23 2026 Fabio Valentini [decathorpe@gmail.com] - 0.18.7-1
- Update to version 0.18.7; Fixes RHBZ#2506308
* Fri Jul 17 2026 Fedora Release Engineering [releng@fedoraproject.org] - 0.18.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-61dffcfbe9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: libgit2-1.9.6-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-61dffcfbe9
2026-08-01 16:03:27.806085+00:00
--------------------------------------------------------------------------------
Name : libgit2
Product : Fedora 43
Version : 1.9.6
Release : 1.fc43
URL : https://libgit2.org/
Summary : C implementation of the Git core methods as a library with a solid API
Description :
libgit2 is a portable, pure C implementation of the Git core methods
provided as a re-entrant linkable library with a solid API, allowing
you to write native speed custom Git applications in any language
with bindings.
--------------------------------------------------------------------------------
Update Information:
Update libgit2 to version 1.9.6.
Update the libgit2-sys Rust crate to the corresponding version 0.18.7.
This includes fixes for various security issues, including - but not limited to:
CVE-2026-53583
CVE-2026-53584
CVE-2026-53585
CVE-2026-53586
CVE-2026-53587
The Fedora package is not affected by GHSA-wfx7-g85r-q6vw since Fedora packages
always linked the system PCRE2 and did not use the bundled PCRE.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 23 2026 Fabio Valentini [decathorpe@gmail.com] - 1.9.6-1
- Update to version 1.9.6
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-61dffcfbe9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: nextcloud-34.0.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-51116fe081
2026-08-01 16:03:27.806083+00:00
--------------------------------------------------------------------------------
Name : nextcloud
Product : Fedora 43
Version : 34.0.2
Release : 1.fc43
URL : http://nextcloud.com
Summary : Private file sync and share server
Description :
NextCloud gives you universal access to your files through a web interface or
WebDAV. It also provides a platform to easily view & sync your contacts,
calendars and bookmarks across all your devices and enables basic editing right
on the web. NextCloud is extendable via a simple but powerful API for
applications and plugins.
--------------------------------------------------------------------------------
Update Information:
34.0.2 Release
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 23 2026 Andrew Bauer [zonexpertconsulting@outlook.com] - 34.0.2-1
- 34.0.2 release RHBZ#2506423
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 33.0.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2499191 - CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499191
[ 2 ] Bug #2499193 - CVE-2026-59882 nextcloud: guzzlehttp/psr7: URI host validation flaw can lead to security bypass or misrouting [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2499193
[ 3 ] Bug #2506423 - nextcloud-34.0.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2506423
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-51116fe081' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: exim-4.99.5-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-d6839a7c95
2026-08-01 16:03:27.806055+00:00
--------------------------------------------------------------------------------
Name : exim
Product : Fedora 43
Version : 4.99.5
Release : 1.fc43
URL : https://www.exim.org/
Summary : The exim mail transfer agent
Description :
Exim is a message transfer agent (MTA) developed at the University of
Cambridge for use on Unix systems connected to the Internet. It is
freely available under the terms of the GNU General Public Licence. In
style it is similar to Smail 3, but its facilities are more
general. There is a great deal of flexibility in the way mail can be
routed, and there are extensive facilities for checking incoming
mail. Exim can be installed in place of sendmail, although the
configuration of exim is quite different to that of sendmail.
--------------------------------------------------------------------------------
Update Information:
This is new version fixing command execution with alternate privilege.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 23 2026 Jaroslav Škarvada [jskarvad@redhat.com] - 4.99.5-1
- New version
Resolves: rhbz#2506152
* Wed Jul 22 2026 Jitka Plesnikova [jplesnik@redhat.com] - 4.99.4-4
- Perl 5.44 rebuild
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.99.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Fri Jun 12 2026 Yaakov Selkowitz [yselkowi@redhat.com] - 4.99.4-2
- Rebuilt for openssl 4.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506152 - exim-4.99.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id%06152
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-d6839a7c95' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 43 Update: GitPython-3.1.55-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-7dfa949ea9
2026-08-01 16:03:27.806019+00:00
--------------------------------------------------------------------------------
Name : GitPython
Product : Fedora 43
Version : 3.1.55
Release : 1.fc43
URL : https://github.com/gitpython-developers/GitPython
Summary : Python Git Library
Description :
GitPython is a python library used to interact with git repositories,
high-level like git-porcelain, or low-level like git-plumbing.
It provides abstractions of git objects for easy access of repository data, and
additionally allows you to access the git repository more directly using either
a pure python implementation, or the faster, but more resource intensive git
command implementation.
The object database implementation is optimized for handling large quantities
of objects and large datasets, which is achieved by using low-level structures
and data streaming.
--------------------------------------------------------------------------------
Update Information:
Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj,
GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2,
GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and
GHSA-94p4-4cq8-9g67.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 23 2026 Benjamin A. Beasley [code@musicinmybrain.net] - 3.1.55-1
- Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj,
GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2,
GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and
GHSA-94p4-4cq8-9g67
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 3.1.50-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Wed Jun 3 2026 Python Maint - 3.1.50-2
- Rebuilt for Python 3.15
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-7dfa949ea9' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: lemonldap-ng-2.23.2-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-1f595e8eb4
2026-08-02 01:14:06.983050+00:00
--------------------------------------------------------------------------------
Name : lemonldap-ng
Product : Fedora 43
Version : 2.23.2
Release : 1.fc43
URL : https://lemonldap-ng.org
Summary : Web Single Sign On (SSO) and Access Management
Description :
LemonLdap::NG is a modular Web-SSO based on Apache::Session modules. It
simplifies the build of a protected area with a few changes in the
application. It manages both authentication and authorization and provides
headers for accounting.
So you can have a full AAA protection for your web space as described below.
--------------------------------------------------------------------------------
Update Information:
Update to 2.23.2
Update to 2.23.1, fixes CVE-2026-12804
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Clement Oudot [clement.oudot@worteks.com] - 2.23.2-1
- Update to 2.23.2
* Wed Jul 22 2026 Clement Oudot [clement.oudot@worteks.com] - 2.23.1-1
- Update to 2.23.1
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.23.0-1.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2491282 - CVE-2026-12804 lemonldap-ng: Lemonldap-NG: Open Redirect via URL manipulation in SAML Common Domain Cookie Endpoint [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491282
[ 2 ] Bug #2491283 - CVE-2026-12804 lemonldap-ng: Lemonldap-NG: Open Redirect via URL manipulation in SAML Common Domain Cookie Endpoint [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491283
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-1f595e8eb4' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: postgresql16-16.14-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-821de6e6a6
2026-08-02 01:14:06.983038+00:00
--------------------------------------------------------------------------------
Name : postgresql16
Product : Fedora 43
Version : 16.14
Release : 1.fc43
URL : http://www.postgresql.org/
Summary : PostgreSQL client programs
Description :
PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you'll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system. These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection. The PostgreSQL server can be found in the
postgresql-server sub-package.
--------------------------------------------------------------------------------
Update Information:
Automatic update for postgresql16-16.14-1.fc43.
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 14 2026 Packit [hello@packit.dev] - 16.14-1
- Update to version 16.14
- Resolves: rhbz#2477451
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-821de6e6a6' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 43 Update: coturn-4.15.0-1.fc43
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-02d5b68472
2026-08-02 01:14:06.983029+00:00
--------------------------------------------------------------------------------
Name : coturn
Product : Fedora 43
Version : 4.15.0
Release : 1.fc43
URL : https://github.com/coturn/coturn/
Summary : TURN/STUN & ICE Server
Description :
The Coturn TURN Server is a VoIP media traffic NAT traversal server and gateway.
It can be used as a general-purpose network traffic TURN server/gateway, too.
This implementation also includes some extra features. Supported RFCs:
TURN specs:
- RFC 5766 - base TURN specs
- RFC 6062 - TCP relaying TURN extension
- RFC 6156 - IPv6 extension for TURN
- Experimental DTLS support as client protocol.
STUN specs:
- RFC 3489 - "classic" STUN
- RFC 5389 - base "new" STUN specs
- RFC 5769 - test vectors for STUN protocol testing
- RFC 5780 - NAT behavior discovery support
The implementation fully supports the following client-to-TURN-server protocols:
- UDP (per RFC 5766)
- TCP (per RFC 5766 and RFC 6062)
- TLS (per RFC 5766 and RFC 6062); TLS1.0/TLS1.1/TLS1.2
- DTLS (experimental non-standard feature)
Supported relay protocols:
- UDP (per RFC 5766)
- TCP (per RFC 6062)
Supported user databases (for user repository, with passwords or keys, if
authentication is required):
- SQLite
- MySQL
- PostgreSQL
- Redis
Redis can also be used for status and statistics storage and notification.
Supported TURN authentication mechanisms:
- long-term
- TURN REST API (a modification of the long-term mechanism, for time-limited
secret-based authentication, for WebRTC applications)
The load balancing can be implemented with the following tools (either one or a
combination of them):
- network load-balancer server
- DNS-based load balancing
- built-in ALTERNATE-SERVER mechanism.
--------------------------------------------------------------------------------
Update Information:
Coturn 4.15.0
Security
Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC
8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than
FINGERPRINT) must be ignored, but coturn processed the full attribute list. This
also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-
SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
Bind mobility session-resume to the original allocation owner — a MOBILITY-
TICKET resume is now only accepted from the user that created the allocation.
Reject ACME requests via signed 400 response instead of silently dropping them.
Reset the reused UDP receive-buffer offset in the DTLS listener.
Zeroed channel-data padding in stun_init_channel_message_str so uninitialized
stack bytes never reach the wire.
Fixed a uint16_t truncation overflow when computing STUN message length.
Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP
subnegotiation parsing to the buffer end.
NULL-terminated the HTTP request buffer before it is logged verbatim; switched
apputils.c to bounded snprintf.
New features
RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no
longer hard-switches the allocation at REFRESH time. The server now does a make-
before-break transition: peer→client traffic stays on the old 5-tuple until the
client's first packet arrives on the new one, and only then is the old socket
discarded.
--drain-min-allocations — a shutdown threshold for drain mode: the server exits
once the live allocation count falls to the configured value instead of waiting
for zero.
--log-min-level (log_min_level in the config file) — a real minimum-log-level
filter, since -v/--verbose had little effect on turnserver logging.
Alternate-server TCP/UDP distinction — alternate servers are now tracked per
transport, so TCP and UDP clients can be redirected to different alternate
servers.
Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes
through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call
site and abort on OOM rather than risking NULL-dereference or silent degradation
in a long-running server.
Reliability and correctness fixes
Fixed the remaining misaligned wire-buffer accesses and added alignment-safe
turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN
attribute values were undefined behavior and a SIGBUS on strict-alignment
targets.
Fixed uint32_t counter wraparound in the relay port allocator.
Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race;
OpenSSL atexit cleanup is disabled in turnserver.
Released the alternate-server list mutex when del_alt_server removes the last
entry, fixing a deadlock.
setgroups is no longer called unconditionally in mainrelay, fixing startup under
environments where it's not permitted.
Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided
leaks on realloc failure in TCP relay allocation.
Cast to unsigned char before isspace() in config-file parsing.
Log an explicit error when a configured tls-listening-port cannot start.
Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure
build.
Metrics
Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
turnutils_uclient now sends the SNI host name on TLS connections.
heap-allocates its STUN message buffers instead of using large stack buffers.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Robert Scheck [robert@fedoraproject.org] - 4.15.0-1
- Upgrade to 4.15.0 (#2506022)
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.14.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506022 - coturn-4.15.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id%06022
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-02d5b68472' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
[SECURITY] Fedora 44 Update: curl-8.18.0-8.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-e691fbbfe7
2026-08-02 00:53:39.370698+00:00
--------------------------------------------------------------------------------
Name : curl
Product : Fedora 44
Version : 8.18.0
Release : 8.fc44
URL : https://curl.se/
Summary : A utility for getting files from remote servers (FTP, HTTP, and others)
Description :
curl is a command line tool for transferring data with URL syntax, supporting
FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP,
SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP
uploading, HTTP form based upload, proxies, cookies, user+password
authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer
resume, proxy tunneling and a busload of other useful tricks.
--------------------------------------------------------------------------------
Update Information:
Fix trailing dot domain super cookie (CVE-2026-8924)
Fix SSH improper host validation (CVE-2026-9547)
Fix password leak with netrc and user in URL (CVE-2026-8926)
Fix cross-origin Digest auth state leak (CVE-2026-11856)
Fix cross-proxy Digest auth state leak (CVE-2026-7168)
Fix OCSP stapling bypass with Apple SecTrust (CVE-2026-7009)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jul 29 2026 Jan Macku [jamacku@redhat.com] - 8.18.0-8
- Fix trailing dot domain super cookie (CVE-2026-8924)
- Fix SSH improper host validation (CVE-2026-9547)
- Fix password leak with netrc and user in URL (CVE-2026-8926)
- Fix cross-origin Digest auth state leak (CVE-2026-11856)
- Fix cross-proxy Digest auth state leak (CVE-2026-7168)
- Fix OCSP stapling bypass with Apple SecTrust (CVE-2026-7009)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2480086 - CVE-2026-7168 curl: libcurl: Information disclosure via incorrect Proxy-Authorization header reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2480086
[ 2 ] Bug #2491327 - CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491327
[ 3 ] Bug #2497410 - CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497410
[ 4 ] Bug #2497475 - CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497475
[ 5 ] Bug #2497597 - CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2497597
[ 6 ] Bug #2498017 - CVE-2026-11856 curl: curl: Information disclosure via incorrect Digest authentication header reuse [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2498017
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-e691fbbfe7' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: gh-2.97.0-2.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-4e77362489
2026-08-02 00:53:39.370693+00:00
--------------------------------------------------------------------------------
Name : gh
Product : Fedora 44
Version : 2.97.0
Release : 2.fc44
URL : https://github.com/cli/cli
Summary : GitHub's official command line tool
Description :
A command-line interface to GitHub for use in your terminal or your scripts.
gh is a tool designed to enhance your workflow when working with GitHub. It
provides a seamless way to interact with GitHub repositories and perform various
actions right from the command line, eliminating the need to switch between your
terminal and the GitHub website.
--------------------------------------------------------------------------------
Update Information:
Update to 2.97.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 31 2026 Packit [hello@packit.dev] - 2.97.0-1
- Update to 2.97.0 upstream release
- Resolves: rhbz#2509662
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.96.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
* Thu Jul 2 2026 Packit [hello@packit.dev] - 2.96.0-1
- Update to 2.96.0 upstream release
- Resolves: rhbz#2490177
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2489771 - CVE-2026-48501 gh: GitHub CLI: Information disclosure via incorrect authorization header handling [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489771
[ 2 ] Bug #2489959 - CVE-2026-39828 gh: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2489959
[ 3 ] Bug #2490059 - CVE-2026-39829 gh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490059
[ 4 ] Bug #2490424 - CVE-2026-39830 gh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2490424
[ 5 ] Bug #2493501 - CVE-2026-39835 gh: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2493501
[ 6 ] Bug #2495285 - CVE-2026-25681 gh: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2495285
[ 7 ] Bug #2496080 - CVE-2026-39823 gh: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2496080
[ 8 ] Bug #2509352 - CVE-2026-46597 gh: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509352
[ 9 ] Bug #2509475 - CVE-2026-39831 gh: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2509475
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-4e77362489' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: xen-4.21.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-bf1da84dfc
2026-08-02 00:53:39.370682+00:00
--------------------------------------------------------------------------------
Name : xen
Product : Fedora 44
Version : 4.21.2
Release : 1.fc44
URL : http://xen.org/
Summary : Xen is a virtual machine monitor
Description :
This package contains the XenD daemon and xm command line
tools, needed to manage virtual machines running under the
Xen hypervisor
--------------------------------------------------------------------------------
Update Information:
update to xen 4.21.2
includes security fixes
x86 shadow paging is deprecated [XSA-495, CVE-2026-42493]
vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492]
buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494,
CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425]
sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426,
CVE-2026-62427]
grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428]
grant-table: version change racing with other operations [XSA-501,
CVE-2026-62435, CVE-2026-62436]
vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429]
x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430]
Viridian STIMER division by zero [XSA-504, CVE-2026-62431]
evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432]
correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433]
PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434]
pygrub is only supported in de-privileged mode [XSA-508]
--------------------------------------------------------------------------------
ChangeLog:
* Thu Jul 30 2026 Michael Young [m.a.young@durham.ac.uk] - 4.21.2-1
- update to xen 4.21.2
- includes security fixes
x86 shadow paging is deprecated [XSA-495, CVE-2026-42493]
vIRQ event channel binding may break Xenstore [XSA-496, CVE-2026-42492]
buffer overruns in libfsimage iso9660 handling [XSA-497, CVE-2026-42494,
CVE-2026-42495, CVE-2026-62423, CVE-2026-62424, CVE-2026-62425]
sysctl and platform-op locks open to abuse [XSA-499, CVE-2026-62426,
CVE-2026-62427]
grant-table: type confusion in grant-copy [XSA-500, CVE-2026-62428]
grant-table: version change racing with other operations [XSA-501,
CVE-2026-62435, CVE-2026-62436]
vNUMA domain cleanup may race other operations [XSA-502, CVE-2026-62429]
x86: Out-of-bounds read in vRTC emulation [XSA-503, CVE-2026-62430]
Viridian STIMER division by zero [XSA-504, CVE-2026-62431]
evtchn: Race between FIFO expand and reset [XSA-505, CVE-2026-62432]
correct buffer checks for DM_OP hypercalls [XSA-506, CVE-2026-62433]
PoD: Don't try to reclaim special pages [XSA-507, CVE-2026-62434]
pygrub is only supported in de-privileged mode [XSA-508]
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-bf1da84dfc' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: lemonldap-ng-2.23.2-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-f9b48b47af
2026-08-02 00:53:39.370665+00:00
--------------------------------------------------------------------------------
Name : lemonldap-ng
Product : Fedora 44
Version : 2.23.2
Release : 1.fc44
URL : https://lemonldap-ng.org
Summary : Web Single Sign On (SSO) and Access Management
Description :
LemonLdap::NG is a modular Web-SSO based on Apache::Session modules. It
simplifies the build of a protected area with a few changes in the
application. It manages both authentication and authorization and provides
headers for accounting.
So you can have a full AAA protection for your web space as described below.
--------------------------------------------------------------------------------
Update Information:
Update to 2.23.2
Update to 2.23.1, fixes CVE-2026-12804
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Clement Oudot [clement.oudot@worteks.com] - 2.23.2-1
- Update to 2.23.2
* Wed Jul 22 2026 Clement Oudot [clement.oudot@worteks.com] - 2.23.1-1
- Update to 2.23.1
* Thu Jul 16 2026 Fedora Release Engineering [releng@fedoraproject.org] - 2.23.0-1.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2491282 - CVE-2026-12804 lemonldap-ng: Lemonldap-NG: Open Redirect via URL manipulation in SAML Common Domain Cookie Endpoint [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491282
[ 2 ] Bug #2491283 - CVE-2026-12804 lemonldap-ng: Lemonldap-NG: Open Redirect via URL manipulation in SAML Common Domain Cookie Endpoint [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2491283
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-f9b48b47af' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
[SECURITY] Fedora 44 Update: coturn-4.15.0-1.fc44
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2026-8856c5be6f
2026-08-02 00:53:39.370641+00:00
--------------------------------------------------------------------------------
Name : coturn
Product : Fedora 44
Version : 4.15.0
Release : 1.fc44
URL : https://github.com/coturn/coturn/
Summary : TURN/STUN & ICE Server
Description :
The Coturn TURN Server is a VoIP media traffic NAT traversal server and gateway.
It can be used as a general-purpose network traffic TURN server/gateway, too.
This implementation also includes some extra features. Supported RFCs:
TURN specs:
- RFC 5766 - base TURN specs
- RFC 6062 - TCP relaying TURN extension
- RFC 6156 - IPv6 extension for TURN
- Experimental DTLS support as client protocol.
STUN specs:
- RFC 3489 - "classic" STUN
- RFC 5389 - base "new" STUN specs
- RFC 5769 - test vectors for STUN protocol testing
- RFC 5780 - NAT behavior discovery support
The implementation fully supports the following client-to-TURN-server protocols:
- UDP (per RFC 5766)
- TCP (per RFC 5766 and RFC 6062)
- TLS (per RFC 5766 and RFC 6062); TLS1.0/TLS1.1/TLS1.2
- DTLS (experimental non-standard feature)
Supported relay protocols:
- UDP (per RFC 5766)
- TCP (per RFC 6062)
Supported user databases (for user repository, with passwords or keys, if
authentication is required):
- SQLite
- MySQL
- PostgreSQL
- Redis
Redis can also be used for status and statistics storage and notification.
Supported TURN authentication mechanisms:
- long-term
- TURN REST API (a modification of the long-term mechanism, for time-limited
secret-based authentication, for WebRTC applications)
The load balancing can be implemented with the following tools (either one or a
combination of them):
- network load-balancer server
- DNS-based load balancing
- built-in ALTERNATE-SERVER mechanism.
--------------------------------------------------------------------------------
Update Information:
Coturn 4.15.0
Security
Ignore STUN attributes after MESSAGE-INTEGRITY (GHSA-5538-7cxj-5jcc). Per RFC
8489 §9 / RFC 5389 §15.4, attributes following MESSAGE-INTEGRITY (other than
FINGERPRINT) must be ignored, but coturn processed the full attribute list. This
also fixes an interop bug where an RFC 8489 client sending MESSAGE-INTEGRITY-
SHA256 after MESSAGE-INTEGRITY was wrongly answered with error 420.
Bind mobility session-resume to the original allocation owner — a MOBILITY-
TICKET resume is now only accepted from the user that created the allocation.
Reject ACME requests via signed 400 response instead of silently dropping them.
Reset the reused UDP receive-buffer offset in the DTLS listener.
Zeroed channel-data padding in stun_init_channel_message_str so uninitialized
stack bytes never reach the wire.
Fixed a uint16_t truncation overflow when computing STUN message length.
Fixed an off-by-one write past the realm buffer in redis_list_admin_users.
Fixed a size_t underflow in the telnet (CLI) _process data emit and bounded MSSP
subnegotiation parsing to the buffer end.
NULL-terminated the HTTP request buffer before it is logged verbatim; switched
apputils.c to bounded snprintf.
New features
RFC 8016 graceful dual-5-tuple mobility handoff. A MOBILITY-TICKET resume no
longer hard-switches the allocation at REFRESH time. The server now does a make-
before-break transition: peer→client traffic stays on the old 5-tuple until the
client's first packet arrives on the new one, and only then is the old socket
discarded.
--drain-min-allocations — a shutdown threshold for drain mode: the server exits
once the live allocation count falls to the configured value instead of waiting
for zero.
--log-min-level (log_min_level in the config file) — a real minimum-log-level
filter, since -v/--verbose had little effect on turnserver logging.
Alternate-server TCP/UDP distinction — alternate servers are now tracked per
transport, so TCP and UDP clients can be redirected to different alternate
servers.
Fail-fast allocation wrappers — all heap allocation in coturn-owned code goes
through turn_malloc/turn_calloc/turn_realloc/turn_strdup, which log the call
site and abort on OOM rather than risking NULL-dereference or silent degradation
in a long-running server.
Reliability and correctness fixes
Fixed the remaining misaligned wire-buffer accesses and added alignment-safe
turn_read_u16/u32/u64 / turn_write_* helpers — misaligned reads of STUN
attribute values were undefined behavior and a SIGBUS on strict-alignment
targets.
Fixed uint32_t counter wraparound in the relay port allocator.
Worker threads are now joined on shutdown, fixing an exit-time OpenSSL race;
OpenSSL atexit cleanup is disabled in turnserver.
Released the alternate-server list mutex when del_alt_server removes the last
entry, fixing a deadlock.
setgroups is no longer called unconditionally in mainrelay, fixing startup under
environments where it's not permitted.
Freed EVP_CIPHER_CTX on error paths in the OAuth GCM encode/decode and avoided
leaks on realloc failure in TCP relay allocation.
Cast to unsigned char before isspace() in config-file parsing.
Log an explicit error when a configured tls-listening-port cannot start.
Autotools build now detects hiredis_ssl, enabling Redis TLS in the ./configure
build.
Metrics
Every STUN Binding response is now counted in the Prometheus metrics.
Client utilities
turnutils_uclient now sends the SNI host name on TLS connections.
heap-allocates its STUN message buffers instead of using large stack buffers.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 24 2026 Robert Scheck [robert@fedoraproject.org] - 4.15.0-1
- Upgrade to 4.15.0 (#2506022)
* Wed Jul 15 2026 Fedora Release Engineering [releng@fedoraproject.org] - 4.14.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2506022 - coturn-4.15.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id%06022
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2026-8856c5be6f' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------