Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9,991 articles for you...
89

Fedora 43 python-django5 Low Risk Data Exposure Bugs 2026-fbb9501b22

The Fedora 43 update for python-django5 to version 5.2.16 addresses three low-severity CVEs, enhancing security by fixing issues related to data exposure and potential vulnerabilities.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fbb9501b22 2026-07-25 01:17:32.017879+00:00 -------------------------------------------------------------------------------- Name : python-django5 Product : Fedora 43 Version : 5.2.16 Release : 1.fc43 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. -------------------------------------------------------------------------------- Update Information: Update python-django5 to version 5.2.16 Fixes three low-severity CVEs CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response CVE-2026-53877: Heap buffer over-read in GDALRaster CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michel Lind - 5.2.16-1 - Update to version 5.2.16; Resolves RHBZ#2497734 - Fixes three low-severity CVEs - CVE-2026-48588: Potential exposure of private data via cached Set-Cookie response - CVE-2026-53877: Heap buffer over-read in GDALRaster - CVE-2026-53878: Header injection possibility since DomainNameValidator accepted newlines in input * Thu Jul 16 2026 Fedora Release Engineering - 5.2.15-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild * Fri Jun 19 2026 Miro Hrončok - 5.2.15-5 - Heavily reduce the list of skipped tests * Sat Jun 6 2026 Michel Lind - 5.2.15-4 - Remove dump of disabled tests from the end of the spec * Sat Jun 6 2026Michel Lind - 5.2.15-3 - Disable failing tests on Python 3.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497734 - python-django5-5.2.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=2497734 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fbb9501b22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update python-django5 fixes three low severity security issues, enhancing data security while retaining performance standards.. python framework, security updates, Fedora advisories, web application framework, CVE fixes. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Low Fedora
89

Fedora 43 mupdf Critical Out-of-Bounds Read Fix Advisory 2026-8870088088

Fedora has released an update for MuPDF version 1.27.2 to fix CVE-2026-7233, an issue related to out-of-bounds read, enhancing security in the PDF viewer toolkit.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8870088088 2026-07-25 01:17:32.017872+00:00 -------------------------------------------------------------------------------- Name : mupdf Product : Fedora 43 Version : 1.27.2 Release : 2.fc43 URL : http://mupdf.com/ Summary : A lightweight PDF viewer and toolkit Description : MuPDF is a lightweight PDF viewer and toolkit written in portable C. The renderer in MuPDF is tailored for high quality anti-aliased graphics. MuPDF renders text with metrics and spacing accurate to within fractions of a pixel for the highest fidelity in reproducing the look of a printed page on screen. MuPDF has a small footprint. A binary that includes the standard Roman fonts is only one megabyte. A build with full CJK support (including an Asian font) is approximately seven megabytes. MuPDF has support for all non-interactive PDF 1.7 features, and the toolkit provides a simple API for accessing the internal structures of the PDF document. Example code for navigating interactive links and bookmarks, encrypting PDF files, extracting fonts, images, and searchable text, and rendering pages to image files is provided. -------------------------------------------------------------------------------- Update Information: fix CVE-2026-7233 (rhbz#2463402) -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michael J Gruber - 1.27.2-2 - fix CVE-2026-7233 (rhbz#2463402) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2463402 - CVE-2026-7233 mupdf: Artifex MuPDF: Information disclosure due to out-of-bounds read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2463402 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8870088088' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This update addresses a critical out-of-bounds read issue in MuPDF on Fedora 43, ensuring data security and integrity.. MuPDF update, Fedora 43 advisory, security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Critical Fedora
89

Fedora 43 dotnet10.0 Critical CVE Fixes Update 2026-d9817786d6

The latest Fedora update adds .NET 10.0 Runtime and SDK, improving features and fixing multiple vulnerabilities, enhancing cross-platform application development on Linux, macOS, and Windows.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d9817786d6 2026-07-25 01:17:32.017877+00:00 -------------------------------------------------------------------------------- Name : dotnet10.0 Product : Fedora 43 Version : 10.0.110 Release : 1.fc43 URL : https://github.com/dotnet/ Summary : .NET 10.0 Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: Update to .NET SDK 10.0.110 and Runtime 10.0.10 Fixes: CVE-2026-47300,CVE-2026-47302,CVE-2026-47303,CVE-2026-47304,CVE-2026- 50524,CVE-2026-50525,CVE-2026-50526,CVE-2026-50527,CVE-2026-50528,CVE-2026- 50646,CVE-2026-50648,CVE-2026-50649,CVE-2026-50650,CVE-2026-50651,CVE-2026- 50659,CVE-2026-56158,CVE-2026-57108 Release Notes: SDK: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.10/10.0.110.md Runtime: https://github.com/dotnet/core/blob/main/release- notes/10.0/10.0.10/10.0.10.md -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 14 2026 Omair Majid - 10.0.110-1 - Update to .NET SDK 10.0.110 and Runtime 10.0.10 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-d9817786d6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . The Fedora 43 dotnet10.0 update addresses critical fixes for multiple CVEs ensuring enhanced security.. Fedora update dotnet CVE fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Critical Fedora
89

Fedora 43 wget1 Critical Memory Corruption DoS Fix 2026-7bbb52b49d

A Fedora update for wget1 addresses multiple vulnerabilities, including a server-side request forgery and buffer overflow, improving the security of file retrieval via HTTP and FTP protocols.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7bbb52b49d 2026-07-25 01:17:32.017870+00:00 -------------------------------------------------------------------------------- Name : wget1 Product : Fedora 43 Version : 1.25.0 Release : 3.fc43 URL : http://www.gnu.org/software/wget/ Summary : A utility for retrieving files using the HTTP or FTP protocols Description : GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 16 2026 Michal Ruprich - 1.25.0-3 - Fix for CVE-2026-15146, CVE-2026-58470, CVE-2026-58471, CVE-2026-58472 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2499188 - CVE-2026-15146 wget1: Wget: Server-Side Request Forgery via FTP PASV response IP address validation bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499188 [ 2 ] Bug #2499583 - CVE-2026-58471 wget1: GNU Wget: Heap buffer overflow via server-supplied filename leads to memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499583 [ 3 ] Bug#2499957 - CVE-2026-58470 wget1: GNU Wget: Integer overflow in Content-Range header parsing causes download desynchronization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499957 [ 4 ] Bug #2499971 - CVE-2026-58472 wget1: GNU Wget: Arbitrary code execution or denial of service via crafted HTML attribute [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2499971 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7bbb52b49d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . This advisory details critical fixes for wget1 in Fedora 43 addressing multiple security issues that could lead to data loss.. Fedora, wget1, security issues, software update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Important Fedora
89

Fedora 43 mbedtls 3.6.7 Important Fixes for Multiple CVEs

Fedora 43 has released mbedtls version 3.6.7, addressing multiple CVEs to enhance security for this lightweight cryptographic and SSL/TLS library.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0bb141710c 2026-07-25 01:17:32.017863+00:00 -------------------------------------------------------------------------------- Name : mbedtls Product : Fedora 43 Version : 3.6.7 Release : 1.fc43 URL : https://www.trustedfirmware.org/projects/mbed-tls Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. -------------------------------------------------------------------------------- Update Information: Update to 3.6.7 Fixes CVE-2026-25832, CVE-2026-35336, CVE-2026-49300, CVE-2026-50579, CVE-2026-50580, CVE-2026-50581, CVE-2026-50583, CVE-2026-50584, CVE-2026-50585, CVE-2026-50586, CVE-2026-50587, CVE-2026-50588, CVE-2026-50640, CVE-2026-50713, CVE-2026-54435, CVE-2026-54441 Release notes: https://github.com/Mbed-TLS/mbedtls/releases#release- mbedtls-3.6.7 -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 11 2026 Morten Stevens - 3.6.7-1 - Update to 3.6.7 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0bb141710c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . An update for mbedtls on Fedora 43 addresses multiple critical flaws improving cryptographic security.. Fedora Updates, mbedtls 3.6.7, CVE Fixes, Fedora Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Important Fedora
89

Fedora 43 sssd Critical Use-After-Free and GPO Cache Issues 2026-9ab663dcd4

An update for the System Security Services Daemon (sssd) in Fedora 43 addresses multiple CVEs, fixing a use-after-free crash, a Kerberos authentication bypass, and privilege escalation risks.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9ab663dcd4 2026-07-25 01:17:32.017844+00:00 -------------------------------------------------------------------------------- Name : sssd Product : Fedora 43 Version : 2.12.0 Release : 3.fc43 URL : https://github.com/SSSD/sssd/ Summary : System Security Services Daemon Description : Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd subpackage is a meta-package that contains the daemon as well as all the existing back ends. -------------------------------------------------------------------------------- Update Information: CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 - rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process - rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass - rhbz#2497651: CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 8 2026 Sumit Bose - 2.12.0-3 - CVE fixes: CVE-2026-12610 CVE-2026-14474 CVE-2026-14476 - rhbz#2494777: CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process - rhbz#2497650: CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass - rhbz#2497651:CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation * Tue Apr 28 2026 Pavel Březina - 2.12.0-2 - spec: add default value for samba_package_version -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494777 - CVE-2026-12610 sssd: Use-after-free crash in SSSD' 'sssd_pam' process [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494777 [ 2 ] Bug #2497650 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497650 [ 3 ] Bug #2497651 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497651 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9ab663dcd4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical fixes for Fedora 43 sssd address use-after-free crash and GPO cache traversal issues to enhance security.. Fedora sssd security, system authentication, access control vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Critical Fedora
89

Fedora 44 Chromium Significant Buffer Overflow and Input Validation Issues

The Fedora update for Chromium (version 150.0.7871.181) addresses several security vulnerabilities, including issues related to insufficient validation, out of bounds errors, and use after free.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4870f59184 2026-07-25 00:54:36.250235+00:00 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 44 Version : 150.0.7871.181 Release : 1.fc44 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: Update to 150.0.7871.181 * CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417: Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 22 2026 Than Ngo - 150.0.7871.181-1 - Update to 150.0.7871.181 * CVE-2026-16413: Out of bounds write in ANGLE * CVE-2026-16414: Insufficient validation of untrusted input in Chromecast * CVE-2026-16415: Insufficient validation of untrusted input in Extensions * CVE-2026-16416: Integer overflow in Chromecast * CVE-2026-16417:Uninitialized Use in Skia * CVE-2026-16418: Stack buffer overflow in V8 * CVE-2026-16419: Out of bounds read and write in ANGLE * CVE-2026-16420: Type Confusion in WebAudio * CVE-2026-16421: Inappropriate implementation in WebAudio * CVE-2026-16422: Insufficient validation of untrusted input in Certificate * CVE-2026-16423: Use after free in UI * CVE-2026-16424: Use after free in GPU -------------------------------------------------------------------------------- References: [ 1 ] Bug #2506058 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506058 [ 2 ] Bug #2506059 - CVE-2026-15764 CVE-2026-15765 CVE-2026-15766 CVE-2026-15767 CVE-2026-15768 CVE-2026-15769 CVE-2026-15770 CVE-2026-15771 CVE-2026-15772 CVE-2026-15773 CVE-2026-15774 CVE-2026-15775 CVE-2026-15776 CVE-2026-15777 ... chromium: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506059 [ 3 ] Bug #2506110 - CVE-2026-13022 chromium: From CVEorg collector [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506110 [ 4 ] Bug #2506111 - CVE-2026-13022 chromium: From CVEorg collector [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506111 [ 5 ] Bug #2506114 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506114 [ 6 ] Bug #2506115 - CVE-2026-13021 chromium: chromium-browser: Inappropriate implementation in DeviceBoundSessionCredentials [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506115 [ 7 ] Bug #2506116 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506116 [ 8 ] Bug #2506117 - CVE-2026-13034 chromium: chromium-browser: Inappropriate implementation in Passwords [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506117 [ 9 ] Bug #2506118 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506118 [ 10 ] Bug #2506119 - CVE-2026-13037 chromium: chromium-browser: Use after free in WebView [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506119 [ 11 ] Bug #2506124 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506124 [ 12 ] Bug #2506125 - CVE-2026-13036 chromium: chromium-browser: Use after free in Blink [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2506125 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4870f59184' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it:https://forge.fedoraproject.org/infra/tickets/issues/new . Update for Fedora 44 Chromium addresses multiple flaws, enhancing security against various issues affecting browser performance.. Chromium updates, Fedora security, Linux browser vulnerabilities, security flaws, open source software. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Important Fedora
89

Fedora 44 Skopeo Critical DoS Fix CVE-2026-27145 Advisory 2026-9b2e56edf5

The Fedora update addresses a security vulnerability in skopeo with a rebuild using Golang 1.26.5 to mitigate a Denial of Service issue affecting DNS SAN entries.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9b2e56edf5 2026-07-25 00:54:36.250222+00:00 -------------------------------------------------------------------------------- Name : skopeo Product : Fedora 44 Version : 1.22.2 Release : 2.fc44 URL : https://github.com/containers/skopeo Summary : Inspect container images and repositories on registries Description : Command line utility to inspect images and repositories directly on Docker registries without the need to pull them. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2026-27145 (Go stdlib crypto/x509 DoS vulnerability). Rebuild with golang-1.26.5 which includes the fix. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 22 2026 Lokesh Mandvekar - 1:1.22.2-2 - Rebuild for CVE-2026-27145 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494281 - CVE-2026-27145 skopeo: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2494281 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9b2e56edf5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Get the security fix for CVE-2026-27145 involving skopeo with Fedora 44 for denial of service. Update now!. Fedora Skopeo Security Update, CVE-2026-27145, Denial of Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 24, 2026 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200