Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The Fedora update for WebKitGTK version 2.52.5 includes crash fixes, increased network timeout, and multiple CVE vulnerabilities resolved, enhancing overall stability and security.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ec8e535c6e 2026-07-26 01:15:59.915548+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 43 Version : 2.52.5 Release : 1.fc43 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Fire scrollend event for instant programmatic scrolls. Increase network idle connection timeout to 115 seconds. Fix several crashes and rendering issues. Fix CVE-2024-4367, CVE-2026-39872, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 9 2026 Michael Catanzaro - 2.52.5-1 - Update to 2.52.5 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec8e535c6e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A new version of python-idna (3.18) has been released in Fedora 43, fixing vulnerabilities CVE-2026-45409 and CVE-2024-3651, while supporting updated IDNA protocols.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6215e65f6c 2026-07-26 01:15:59.915545+00:00 -------------------------------------------------------------------------------- Name : python-idna Product : Fedora 43 Version : 3.18 Release : 1.fc43 URL : https://github.com/kjd/idna Summary : Internationalized Domain Names in Applications (IDNA) Description : A library to support the Internationalised Domain Names in Applications (IDNA) protocol as specified in RFC 5891 . This version of the protocol is often referred to as "IDNA2008" and can produce different results from the earlier standard from 2003. The library is also intended to act as a suitable drop-in replacement for the "encodings.idna" module that comes with the Python standard library but currently only supports the older 2003 specification. -------------------------------------------------------------------------------- Update Information: Update to the latest version to bring fixes for CVE-2026-45409 and CVE-2024-3651 into the stable releases. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 9 2026 Lumir Balhar - 3.18-1 - Update to 3.18 (rhbz#2483976) * Wed Jun 3 2026 Python Maint - 3.17-2 - Rebuilt for Python 3.15 * Sun May 31 2026 Lumir Balhar - 3.17-1 - Update to 3.17 (rhbz#2480667) * Wed May 13 2026 Lumir Balhar - 3.15-1 - Update to 3.15 (rhbz#2476912) * Mon May 11 2026 Lumir Balhar - 3.14-1 - Update to 3.14 (rhbz#2468686) * Thu Apr 23 2026 Lumir Balhar - 3.13-1 - Update to 3.13 (rhbz#2460821) * Sat Jan 17 2026 Fedora Release Engineering - 3.11-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Sun Oct 12 2025 Lumir Balhar - 3.11-1 - Updateto 3.11 (rhbz#2403375) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2498560 - CVE-2026-45409 python-idna: idna: Denial of Service via specially crafted long inputs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2498560 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6215e65f6c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora released a security update for the PAM library to fix a timing leak issue in the pam_userdb module, addressing CVE-2026-54411 and enhancing authentication security.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-adc8ddbeaa 2026-07-26 01:15:59.915520+00:00 -------------------------------------------------------------------------------- Name : pam Product : Fedora 43 Version : 1.7.1 Release : 5.fc43 URL : http://www.linux-pam.org/ Summary : An extensible library which provides authentication for applications Description : PAM (Pluggable Authentication Modules) is a system security tool that allows system administrators to set authentication policy without having to recompile programs that handle authentication. -------------------------------------------------------------------------------- Update Information: pam_userdb: fix password comparison timing leak -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 10 2026 Iker Pedrosa - 1.7.1-5 - pam_userdb: fix password comparison timing leak Resolves: #2496416 Resolves: CVE-2026-54411 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2496416 - CVE-2026-54411 pam: Plaintext password recovery via timing discrepancy in pam_userdb module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2496416 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-adc8ddbeaa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 updates GitPython to version 3.1.55, addressing multiple security vulnerabilities and enhancing functionality for interacting with git repositories via a high-level or low-level approach.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8e8273f18f 2026-07-26 00:57:16.867310+00:00 -------------------------------------------------------------------------------- Name : GitPython Product : Fedora 44 Version : 3.1.55 Release : 1.fc44 URL : https://github.com/gitpython-developers/GitPython Summary : Python Git Library Description : GitPython is a python library used to interact with git repositories, high-level like git-porcelain, or low-level like git-plumbing. It provides abstractions of git objects for easy access of repository data, and additionally allows you to access the git repository more directly using either a pure python implementation, or the faster, but more resource intensive git command implementation. The object database implementation is optimized for handling large quantities of objects and large datasets, which is achieved by using low-level structures and data streaming. -------------------------------------------------------------------------------- Update Information: Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2, GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-94p4-4cq8-9g67. -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2026 Benjamin A. Beasley - 3.1.55-1 - Update to 3.1.55: Fixes GHSA-2f96-g7mh-g2hx, GHSA-v396-v7q4-x2qj, GHSA-956x-8gvw-wg5v, GHSA-rwj8-pgh3-r573, GHSA-3rp5-jjmw-4wv2, GHSA-r9mr-m37c-5fr3, GHSA-fjr4-x663-mwxc, GHSA-6p8h-3wgx-97gf, and GHSA-94p4-4cq8-9g67 * Wed Jul 15 2026 Fedora Release Engineering - 3.1.50-3 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Wed Jun 3 2026 Python Maint - 3.1.50-2 - Rebuilt for Python 3.15 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8e8273f18f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The Fedora 44 update for the google-osconfig-agent version 20260717.00 includes several enhancements and bug fixes, addressing issues like build failures and a denial of service vulnerability.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9781489c3a 2026-07-26 00:57:16.867286+00:00 -------------------------------------------------------------------------------- Name : google-osconfig-agent Product : Fedora 44 Version : 20260717.00 Release : 1.fc44 URL : https://github.com/GoogleCloudPlatform/osconfig Summary : Google OS Config Agent Description : Google OS Config Agent -------------------------------------------------------------------------------- Update Information: Update to 20260717 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 17 2026 Mikel Olasagasti Uranga - 20260717.00-1 - Update to 200260717 - Closes rhbz#2336973 * Thu Jul 16 2026 Fedora Release Engineering - 20241029.01-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Tue Feb 3 2026 Maxwell G - 20241029.01-8 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 20241029.01-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Sun Oct 12 2025 Maxwell G - 20241029.01-6 - Rebuild for golang 1.25.2 * Fri Oct 10 2025 Alejandro Sáez - 20241029.01-5 - rebuild * Fri Aug 15 2025 Maxwell G - 20241029.01-4 - Rebuild for golang-1.25.0 * Thu Jul 24 2025 Fedora Release Engineering - 20241029.01-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Fri Jan 17 2025 Fedora Release Engineering - 20241029.01-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2434630 - google-osconfig-agent: FTBFS in Fedora rawhide/f44 https://bugzilla.redhat.com/show_bug.cgi?id=2434630 [ 2 ] Bug #2486287 - CVE-2026-45287 google-osconfig-agent: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2486287 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9781489c3a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for Fedora 44 google-osconfig-agent addresses denial of service risk stemming from a file descriptor leak.. Fedora security updates, google-osconfig-agent, denial of service, package updates. . Severity: Important. LinuxSecurity.com Team
An update for xrdp, an open-source RDP server, addresses several security vulnerabilities and improves PAM file usage, enhancing compatibility with various RDP clients in Fedora 44.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9d3c766833 2026-07-26 00:57:16.867274+00:00 -------------------------------------------------------------------------------- Name : xrdp Product : Fedora 44 Version : 0.10.6.1 Release : 3.fc44 URL : http://www.xrdp.org/ Summary : Open source remote desktop protocol (RDP) server Description : xrdp provides a fully functional RDP server compatible with a wide range of RDP clients, including FreeRDP and Microsoft RDP client. -------------------------------------------------------------------------------- Update Information: Update PAM file to better match modern reality. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 18 2026 Bojan Smojver - 1:0.10.6.1-3 - Fix bug #2499948 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2502969 - CVE-2026-54538 xrdp: infinite loop denial-of-service vulnerability during RDP packet processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502969 [ 2 ] Bug #2502971 - CVE-2026-41521 xrdp: integer overflow leads to out-of-bounds read in vnc-any mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502971 [ 3 ] Bug #2502973 - CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502973 [ 4 ] Bug #2502974 - CVE-2026-55639 xrdp: improper input validation in MCS data processing leads to potential information leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502974 [ 5 ] Bug #2502977 - CVE-2026-55626 xrdp: missing authentication when xrdp launches Xvnc inUNIX domain socket mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502977 [ 6 ] Bug #2502978 - CVE-2026-55645 xrdp: out-of-bounds read in client control PDU processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502978 [ 7 ] Bug #2502981 - CVE-2026-44978 xrdp: heap out-of-bounds read in non-TLS FIPS receive paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502981 [ 8 ] Bug #2502983 - CVE-2026-55238 xrdp: improper input validation in capability negotiation leads to denial of service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502983 [ 9 ] Bug #2502985 - CVE-2026-42218 xrdp: timing side-channel allows username enumeration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2502985 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9d3c766833' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fedora 44 has updated the moby-engine to version 29.6.2, which includes upstream security fixes addressing vulnerabilities and can be installed using the dnf upgrade command.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-70a4eeeab8 2026-07-26 00:57:16.867258+00:00 -------------------------------------------------------------------------------- Name : moby-engine Product : Fedora 44 Version : 29.6.2 Release : 1.fc44 URL : https://github.com/moby/moby Summary : The open-source application container engine Description : Docker is an open source project to build, ship and run any application as a lightweight container. Docker containers are both hardware-agnostic and platform-agnostic. This means they can run anywhere, from your laptop to the largest EC2 compute instance and everything in between — and they do not require you to use a particular language, framework or packaging system. That makes them great building blocks for deploying and scaling web apps, databases, and backend services without depending on a particular stack or provider. -------------------------------------------------------------------------------- Update Information: Update to release v29.6.2 Resolves: rhbz#2496437 Upstream security fixes GHSA-hw3h-2gp9-cxpv GHSA-qx3x-mv6r-52p6 GHSA-32pv-7hq5-qhwq GHSA-g2h8-426c-7976 GHSA-388v-wmr2-g2v2 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Bradley G Smith - 29.6.2-1 - Update to release v29.6.2 - Resolves: rhbz#2496437 - Upstream security fixes - - GHSA-hw3h-2gp9-cxpv - - GHSA-qx3x-mv6r-52p6 - - GHSA-32pv-7hq5-qhwq - - GHSA-g2h8-426c-7976 - - GHSA-388v-wmr2-g2v2 * Thu Jul 16 2026 Fedora Release Engineering - 29.6.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 26 2026 Bradley G Smith - 29.6.1-1 - Update to release v29.6.1 - Resolves: rhbz#2493405 - Upstream security fixes for:GHSA-mjcv-p78q-w5fw GHSA-jpcc-p29g-p8mq GHSA-72x6-4j93-7w86 GHSA-7236-3392-c5c6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2496437 - CVE-2026-47262 moby-engine: containerd: Denial of Service via maliciously crafted image leading to unbounded group parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2496437 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-70a4eeeab8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Explore crucial updates for Fedora 44's moby-engine, resolving vulnerabilities related to denial of service threats.. Fedora updates, moby-engine, security fixes, denial of service. . Severity: Important. LinuxSecurity.com Team
Mageia released updated wget packages addressing multiple security vulnerabilities, including denial of service and potential arbitrary code execution, affecting Mageia 9 and 10. Several CVEs are cited.. Publication date: 25 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0300.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-58469, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472, CVE-2026-15146 Description: Updated wget packages fix security vulnerabilities: -CVE-2026-58469 Wget incorrectly handled Metalink documents containing a whitespace-only URL. A remote attacker could possibly use this issue to cause a denial of service. This issue only affected Mageia 9 and Mageia 10. -CVE-2026-58470 : Wget incorrectly handled Content-Range header values, leading to an integer overflow. A remote attacker could possibly use this issue to cause download desynchronization. -CVE-2026-58471 : Wget incorrectly handled character set conversion of server-supplied filenames. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. This issue affected Mageia9 and Mageia 10. -CVE-2026-58472: It was discovered that Wget incorrectly handled HTML attributes requiring entity encoding. A remote attacker could possibly use this issue to cause a denial of service or possibly execute arbitrary code. -CVE-2026-15146: GNU Wget did not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, could exploit this behavior to redirect Wget's data connection to an arbitrary IP address and port. This allowed an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources. References: - https://bugs.mageia.org/show_bug.cgi?id=35974 - https://ubuntu.com/security/notices/USN-8543-1 -https://lists.opensuse.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.