Fedora Security Advisories

ImageMagick-7.1.2.13-2.fc44 LibRaw-0.22.1-1.fc44 OpenImageIO-3.1.12.0-2.fc44 OpenImageIO2.5-2.5.19.1-10.fc44 deepin-image-viewer-5.8.2-21.fc44 dtk6gui-6.7.32-5.fc44 dtkgui-5.7.30-4.fc44 efl-1.28.1-6.fc44 elementary-photos-8.0.1-6.fc44 entangle-3.0-17…

9 hours 21 minutes ago
FEDORA-2026-bef0050737 Packages in this update:
  • deepin-image-viewer-5.8.2-21.fc44
  • dtk6gui-6.7.32-5.fc44
  • dtkgui-5.7.30-4.fc44
  • efl-1.28.1-6.fc44
  • elementary-photos-8.0.1-6.fc44
  • entangle-3.0-17.fc44
  • freeimage-3.19.0-0.31.svn1909.fc44
  • geeqie-2.7-2.fc44
  • gegl04-0.4.70-2.fc44
  • gthumb-3.12.10-7.fc44
  • ImageMagick-7.1.2.13-2.fc44
  • kf5-kimageformats-5.116.0-8.fc44
  • kf5-libkdcraw-23.08.5-7.fc44
  • kf6-kimageformats-6.24.0-3.fc44
  • kstars-3.8.0-6.fc44
  • libkdcraw-26.03.80-2.fc44
  • libpasraw-1.3.0-22.fc44
  • LibRaw-0.22.1-1.fc44
  • luminance-hdr-2.6.1.1-89.fc44
  • nomacs-3.22.0-5.fc44
  • OpenImageIO2.5-2.5.19.1-10.fc44
  • OpenImageIO-3.1.12.0-2.fc44
  • photoqt-5.2-3.fc44
  • rawtherapee-5.12-8.fc44
  • shotwell-33~alpha-9.fc44
  • siril-1.4.2-3.fc44
  • swayimg-5.1-2.fc44
  • vips-8.18.0-6.fc44
Update description:

LibRaw 0.22.1 and rebuilds

Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0

oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and other metadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use of AI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999

tinyproxy-1.11.3-2.fc45

9 hours 46 minutes ago
FEDORA-2026-1c7a717dbc Packages in this update:
  • tinyproxy-1.11.3-2.fc45
Update description:

Automatic update for tinyproxy-1.11.3-2.fc45.

Changelog * Wed Apr 8 2026 Carl George <carlwgeorge@fedoraproject.org> - 1.11.3-2 - Backport upstream CVE fixes - Fixes rhbz#2452969 CVE-2026-3945 - Fixes rhbz#2455913 CVE-2026-31842 - Run upstream test suite

ImageMagick-7.1.2.13-2.fc45 LibRaw-0.22.1-1.fc45 OpenImageIO-3.1.12.0-2.fc45 OpenImageIO2.5-2.5.19.1-10.fc45 deepin-image-viewer-5.8.2-21.fc45 dtk6gui-6.7.32-5.fc45 dtkgui-5.7.30-4.fc45 efl-1.28.1-6.fc45 elementary-photos-8.0.1-6.fc45 entangle-3.0-17…

11 hours 25 minutes ago
FEDORA-2026-ffba395f42 Packages in this update:
  • deepin-image-viewer-5.8.2-21.fc45
  • dtk6gui-6.7.32-5.fc45
  • dtkgui-5.7.30-4.fc45
  • efl-1.28.1-6.fc45
  • elementary-photos-8.0.1-6.fc45
  • entangle-3.0-17.fc45
  • freeimage-3.19.0-0.31.svn1909.fc45
  • geeqie-2.7-2.fc45
  • gegl04-0.4.70-2.fc45
  • gthumb-3.12.10-7.fc45
  • ImageMagick-7.1.2.13-2.fc45
  • kf5-kimageformats-5.116.0-8.fc45
  • kf5-libkdcraw-23.08.5-7.fc45
  • kf6-kimageformats-6.24.0-3.fc45
  • kstars-3.8.0-6.fc45
  • libkdcraw-26.03.80-2.fc45
  • libpasraw-1.3.0-22.fc45
  • LibRaw-0.22.1-1.fc45
  • luminance-hdr-2.6.1.1-89.fc45
  • nomacs-3.22.0-5.fc45
  • OpenImageIO2.5-2.5.19.1-10.fc45
  • OpenImageIO-3.1.12.0-2.fc45
  • photoqt-5.2-3.fc45
  • rawtherapee-5.12-8.fc45
  • shotwell-33~alpha-9.fc45
  • siril-1.4.2-3.fc45
  • swayimg-5.1-2.fc45
  • vips-8.18.0-6.fc45
Update description:

LibRaw 0.22.1 and rebuilds.

cockpit-360-1.fc44

12 hours 10 minutes ago
FEDORA-2026-bbc8f7695a Packages in this update:
  • cockpit-360-1.fc44
Update description:

Automatic update for cockpit-360-1.fc44.

Changelog for cockpit * Wed Apr 08 2026 Packit <hello@packit.dev> - 360-1 - ws: be more explicit when handling hostnames on cli [CVE-2026-4631] - ws: support loading a custom login page - Translation updates

python-cryptography-46.0.7-1.fc43

18 hours 3 minutes ago
FEDORA-2026-95233f8a79 Packages in this update:
  • python-cryptography-46.0.7-1.fc43
Update description: Changelog * Wed Apr 8 2026 Jeremy Cline <jeremycline@microsoft.com> - 46.0.7-1 - Update to 46.0.7 - SECURITY ISSUE: Fixed an issue where non-contiguous buffers could be passed to APIs that accept Python buffers, which could lead to buffer overflow. CVE-2026-39892

python-cryptography-46.0.7-1.fc44

18 hours 3 minutes ago
FEDORA-2026-aa318887d6 Packages in this update:
  • python-cryptography-46.0.7-1.fc44
Update description: Changelog * Wed Apr 8 2026 Jeremy Cline <jeremycline@microsoft.com> - 46.0.7-1 - Update to 46.0.7 - SECURITY ISSUE: Fixed an issue where non-contiguous buffers could be passed to APIs that accept Python buffers, which could lead to buffer overflow. CVE-2026-39892

python-tomli-2.4.1-1.fc44

18 hours 36 minutes ago
FEDORA-2026-42d4c822e4 Packages in this update:
  • python-tomli-2.4.1-1.fc44
Update description:

Update to 2.4.1. Limit number of parts of a TOML key to address quadratic time complexity

mingw-LibRaw-0.21.5-2.fc43

19 hours 27 minutes ago
FEDORA-2026-066dcb4c72 Packages in this update:
  • mingw-LibRaw-0.21.5-2.fc43
Update description:

Backport fixes for CVE-2026-20889 CVE-2026-21413 CVE-2026-24450 CVE-2026-24660

Update to libraw-0.21.5.

mingw-LibRaw-0.21.5-2.fc42

19 hours 27 minutes ago
FEDORA-2026-2114a370b6 Packages in this update:
  • mingw-LibRaw-0.21.5-2.fc42
Update description:

Backport fixes for CVE-2026-20889 CVE-2026-21413 CVE-2026-24450 CVE-2026-24660

Update to libraw-0.21.5.

usd-26.03-3.fc44

19 hours 43 minutes ago
FEDORA-2026-502486fc61 Packages in this update:
  • usd-26.03-3.fc44
Update description:

Backport several OpenEXRCore security fixes

  • Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493
  • Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534
  • Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505
  • Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501
  • Fixes CVE-2026-34379 / GHSA-w88v-vqhq-5p24; closes RHBZ#2455497

Backport fix for CVE-2026-34544 in OpenEXRCore

usd-26.03-3.fc45

20 hours 45 minutes ago
FEDORA-2026-c0f8cde7ad Packages in this update:
  • usd-26.03-3.fc45
Update description:

Automatic update for usd-26.03-3.fc45.

Changelog * Wed Apr 8 2026 Benjamin A. Beasley <code@musicinmybrain.net> - 26.03-3 - Backport several OpenEXRCore security fixes - Fixes CVE-2026-34378 / GHSA-v76p-4qvv-vh4g; closes RHBZ#2455493 - Fixes CVE-2026-34380 / GHSA-q3v8-hw4m-59w5; closes RHBZ#2455534 - Fixes CVE-2026-34588 / GHSA-588r-cr5c-w6hf; closes RHBZ#2455505 - Fixes CVE-2026-34589 / GHSA-p8xc-w3q4-h64x; closes RHBZ#2455501 - Fixes CVE-2026-34379 / GHSA-w88v-vqhq-5p24; closes RHBZ#2455497

flatpak-1.16.4-1.fc42

20 hours 56 minutes ago
FEDORA-2026-be26d4c1b2 Packages in this update:
  • flatpak-1.16.4-1.fc42
Update description:

Update to 1.16.4

Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg

flatpak-1.16.4-1.fc43

21 hours 9 minutes ago
FEDORA-2026-06b66012cd Packages in this update:
  • flatpak-1.16.4-1.fc43
Update description:

Update to 1.16.4

Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg

flatpak-1.17.4-1.fc44

21 hours 14 minutes ago
FEDORA-2026-17f6840cea Packages in this update:
  • flatpak-1.17.4-1.fc44
Update description:

Update to 1.17.4

Fixes for CVE-2026-34078, CVE-2026-34079, GHSA-2fxp-43j9-pwvc and GHSA-89xm-3m96-w3jg

Checked
51 minutes 49 seconds ago