Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to 1.3.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-1c78e384e3 2026-07-21 01:13:08.976738+00:00 -------------------------------------------------------------------------------- Name : dnsx Product : Fedora 43 Version : 1.3.0 Release : 1.fc43 URL : https://github.com/projectdiscovery/dnsx Summary : Dnsx is a fast and multi-purpose DNS toolkit Description : Dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. -------------------------------------------------------------------------------- Update Information: Update to 1.3.0 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Mikel Olasagasti Uranga - 1.3.0-1 - Update to 1.3.0 - Closes rhbz#2420897 * Wed Jul 15 2026 Fedora Release Engineering - 1.2.3-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Mon Feb 2 2026 Maxwell G - 1.2.3-4 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 1.2.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jan 16 2026 Fedora Release Engineering - 1.2.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Dec 17 2025 Mikel Olasagasti Uranga - 1.2.3-1 - Update to 1.2.3 - Closes rhbz#2420897 * Fri Oct 10 2025 Alejandro Sáez - 1.2.2-6 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408156 - CVE-2025-58189 dnsx: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408156 [ 2 ] Bug #2409626 - CVE-2025-61723 dnsx: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409626 [ 3 ] Bug #2410577 -CVE-2025-58185 dnsx: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410577 [ 4 ] Bug #2411475 - CVE-2025-58188 dnsx: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411475 [ 5 ] Bug #2412680 - CVE-2025-58183 dnsx: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412680 [ 6 ] Bug #2442405 - CVE-2026-1229 dnsx: CIRCL ecc/p384: Incorrect cryptographic calculations via specific inputs [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2442405 [ 7 ] Bug #2456017 - CVE-2026-33817 dnsx: go.etcd.io/bbolt: Denial of Service via index out-of-range error [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456017 [ 8 ] Bug #2458982 - CVE-2026-5160 dnsx: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458982 [ 9 ] Bug #2494342 - CVE-2026-27145 dnsx: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494342 [ 10 ] Bug #2495280 - CVE-2026-25681 dnsx: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2495280 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1c78e384e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Installing the dnsx update for Fedora 43 resolves multiple critical issues including Denial of Service vulnerabilities.. Fedora Update,dnsx Security Advisory,Denial of Service,fedora dnsx. . Severity: Important. LinuxSecurity.com Team
CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-169fd93089 2026-07-21 01:13:08.976736+00:00 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 43 Version : 10.0p1 Release : 11.fc43 URL : http://www.openssh.com/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Zoltan Fridrich - 10.0p1-11 - CVE-2026-59996: Fix remote glob result of ".." causing files to be placed in unintended parent directories when scp performs remote-to-remote copy via the local host Resolves: rhbz#2498027 - CVE-2026-60002: Fix use-after-free in cached hostkey during key re-exchange Resolves: rhbz#2497966 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497966 - CVE-2026-60002 openssh: OpenSSH: Use-after-free vulnerability during host key re-exchange on the client side [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497966 [ 2 ] Bug #2498027 - CVE-2026-59996 openssh: OpenSSH: `scp` file misplacement vulnerability during remote copy [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498027 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-169fd93089' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 3.30.0 Update to 3.29.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fa672d26a8 2026-07-21 01:13:08.976727+00:00 -------------------------------------------------------------------------------- Name : freerdp Product : Fedora 43 Version : 3.30.0 Release : 1.fc43 URL : http://www.freerdp.com/ Summary : Free implementation of the Remote Desktop Protocol (RDP) Description : The xfreerdp & wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP project. xfreerdp & wlfreerdp can connect to RDP servers such as Microsoft Windows machines, xrdp and VirtualBox. -------------------------------------------------------------------------------- Update Information: Update to 3.30.0 Update to 3.29.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Ondrej Holy - 2:3.30.0-1 - Update to 3.30.0 Resolves: rhbz#2501274 * Wed Jul 15 2026 Fedora Release Engineering - 2:3.29.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Wed Jul 15 2026 Ondrej Holy - 2:3.29.0-1 - Update to 3.29.0 Resolves: rhbz#2499994 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2499994 - freerdp-3.29.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2499994 [ 2 ] Bug #2501274 - freerdp-3.30.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2501274 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fa672d26a8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used bythe Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
updated to 4.7.2, fixes security issues. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-feac063d56 2026-07-21 01:13:08.976725+00:00 -------------------------------------------------------------------------------- Name : libtiff Product : Fedora 43 Version : 4.7.2 Release : 1.fc43 URL : http://www.simplesystems.org/libtiff/ Summary : Library of functions for manipulating TIFF format image files Description : The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large. The libtiff package should be installed if you need to manipulate TIFF format image files. -------------------------------------------------------------------------------- Update Information: updated to 4.7.2, fixes security issues -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 13 2026 Michal Hlavinka - 4.7.2-1 - updated to 4.7.2 (#2496751) * Fri Jan 16 2026 Fedora Release Engineering - 4.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2450771 - CVE-2026-4775 libtiff: libtiff: Arbitrary code execution or denial of service via signed integer overflow in TIFF file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2450771 [ 2 ] Bug #2494140 - CVE-2026-12912 libtiff: libtiff: Heap-based buffer overflow via crafted PixarLog-compressed TIFF image [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494140 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-feac063d56' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to pip-26.1.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-71562f8836 2026-07-21 01:13:08.976682+00:00 -------------------------------------------------------------------------------- Name : mingw-python-pip Product : Fedora 43 Version : 26.1.2 Release : 1.fc43 URL : https://pypi.python.org/pypi/pip Summary : MinGW Windows Python pip library Description : MinGW Windows Python pip library. -------------------------------------------------------------------------------- Update Information: Update to pip-26.1.2. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 4 2026 Sandro Mani - 26.1.2-1 - Update to 26.1.2 * Fri May 22 2026 Sandro Mani - 26.1.1-1 - Update to 26.1.1 * Sun Mar 1 2026 Sandro Mani - 26.0.1-1 - Update to 26.0.1 * Fri Jan 16 2026 Fedora Release Engineering - 25.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Dec 3 2025 Sandro Mani - 25.3-1 - Update to 25.3 * Sat Aug 30 2025 Sandro Mani - 25.2-1 - Update to 25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494474 - CVE-2026-8643 mingw-python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494474 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-71562f8836' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 3.18.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9dbf4d0ca8 2026-07-21 01:13:08.976679+00:00 -------------------------------------------------------------------------------- Name : mingw-python-idna Product : Fedora 43 Version : 3.18 Release : 1.fc43 URL : https://github.com/kjd/idna Summary : MinGW Windows Python idna Description : MinGW Windows Python idna. -------------------------------------------------------------------------------- Update Information: Update to 3.18. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 15 2026 Sandro Mani - 3.18-1 - Update to 3.18 * Fri May 15 2026 Sandro Mani - 3.15-1 - Update to 3.15 * Sun Apr 26 2026 Sandro Mani - 3.13-1 - Update to 3.13 * Fri Jan 16 2026 Fedora Release Engineering - 3.11-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Sun Oct 19 2025 Sandro Mani - 3.11-1 - Update to 3.11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498561 - CVE-2026-45409 mingw-python-idna: idna: Denial of Service via specially crafted long inputs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498561 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9dbf4d0ca8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
1.34.7 accidentally broke the API compatibility, this is fixed in 1.34.8. update to 1.34.7 fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA- jv8r-gqr9-68wj. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d70d93fcd7 2026-07-21 01:13:08.976658+00:00 -------------------------------------------------------------------------------- Name : c-ares Product : Fedora 43 Version : 1.34.8 Release : 1.fc43 URL : http://c-ares.org/ Summary : A library that performs asynchronous DNS operations Description : c-ares is a C library that performs DNS requests and name resolves asynchronously. c-ares is a fork of the library named 'ares', written by Greg Hudson at MIT. -------------------------------------------------------------------------------- Update Information: 1.34.7 accidentally broke the API compatibility, this is fixed in 1.34.8. update to 1.34.7 fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA- jv8r-gqr9-68wj -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Tom Callaway - 1.34.8-1 - update to 1.34.8 * Mon Jul 6 2026 Tom Callaway - 1.34.7-1 - update to 1.34.7 - fixes CVE-2026-33630 (GHSA-6wfj-rwm7-3542) and GHSA-pjmc-gx33-gc76 and GHSA-jv8r-gqr9-68wj * Fri Jan 16 2026 Fedora Release Engineering - 1.34.6-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jan 16 2026 Fedora Release Engineering - 1.34.6-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Dec 17 2025 Tom Callaway - 1.34.6-1 - update to 1.34.6 - fixes CVE-2025-62408 (among other fixes) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2420051 - c-ares-1.34.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2420051 [ 2 ] Bug #2497696 - CVE-2026-33630 c-ares:c-ares: Use-after-free / double-free in query-completion handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497696 [ 3 ] Bug #2497764 - c-ares-1.34.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=2497764 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d70d93fcd7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 5.3.2 for CVE-2026-14957 (with newsources). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-538c26f96a 2026-07-21 00:56:03.169768+00:00 -------------------------------------------------------------------------------- Name : libreswan Product : Fedora 44 Version : 5.3.2 Release : 2.fc44 URL : https://libreswan.org/ Summary : Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec Description : Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network or VPN. This package contains the daemons and userland tools for setting up Libreswan. Libreswan also supports IKEv2 (RFC7296) and Secure Labeling Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04 -------------------------------------------------------------------------------- Update Information: Update to 5.3.2 for CVE-2026-14957 (with newsources) -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Paul Wouters - 5.3.2-2 - Update to 5.3.2 for CVE-2026-14957 (with newsources) * Fri Jul 17 2026 Paul Wouters - 5.3.2-1 - Update to 5.3.2 for CVE-2026-14957 * Thu Jul 16 2026 Fedora Release Engineering - 5.3.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Wed Jun 24 2026 Paul Wouters - 5.3.1-1 - Update to libreswan-5.3.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2026-538c26f96a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.