Fedora Security Advisories

python-pydicom-3.0.2-1.fc43

1 hour 10 minutes ago
FEDORA-2026-f5c971af6c Packages in this update:
  • python-pydicom-3.0.2-1.fc43
Update description:

Patch release for security advisory CVE-2026-32711. A crafted DICOMDIR could create a path traversal by setting ReferencedFileID to a path outside the File-set root.

python-pydicom-3.0.2-1.fc44

1 hour 28 minutes ago
FEDORA-2026-9eecdef4e0 Packages in this update:
  • python-pydicom-3.0.2-1.fc44
Update description:

Patch release for security advisory CVE-2026-32711. A crafted DICOMDIR could create a path traversal by setting ReferencedFileID to a path outside the File-set root.

roundcubemail-1.7~rc6-1.fc44

3 hours 20 minutes ago
FEDORA-2026-6d293b6889 Packages in this update:
  • roundcubemail-1.7~rc6-1.fc44
Update description:

Version 1.7-rc6

This is hopefully the last release candidate for the next major version 1.7 of Roundcube Webmail. It provides a fix to recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

We believe it is production ready, but we recommend to test it on a separate environment.

Migrate existing configs with either the installto.sh or the update.sh scripts.

And don't forget to backup your data before installing it!

CHANGELOG

  • Added support for arrays in smtp_user and smtp_pass config options (#10083)
  • Added system health checker CLI script (#10106)
  • Stricter recognition of an Ajax request (#10118)
  • Password: Added Stalwart driver (#10114)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.6.15-1.el10_2

3 hours 26 minutes ago
FEDORA-EPEL-2026-646aebe990 Packages in this update:
  • roundcubemail-1.6.15-1.el10_2
Update description:

Version 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.6.15-1.fc42

3 hours 26 minutes ago
FEDORA-2026-051825ca18 Packages in this update:
  • roundcubemail-1.6.15-1.fc42
Update description:

Version 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.6.15-1.el10_1

3 hours 26 minutes ago
FEDORA-EPEL-2026-82b702d826 Packages in this update:
  • roundcubemail-1.6.15-1.el10_1
Update description:

Version 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.6.15-1.el10_3

3 hours 26 minutes ago
FEDORA-EPEL-2026-f7a0d90857 Packages in this update:
  • roundcubemail-1.6.15-1.el10_3
Update description:

Version 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.6.15-1.fc43

3 hours 26 minutes ago
FEDORA-2026-8ba1a085a9 Packages in this update:
  • roundcubemail-1.6.15-1.fc43
Update description:

Version 1.6.15

This is a security update to the stable version 1.6 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.6.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

roundcubemail-1.5.15-1.el9

3 hours 36 minutes ago
FEDORA-EPEL-2026-bf73d904ba Packages in this update:
  • roundcubemail-1.5.15-1.el9
Update description:

Version 1.5.15

This is a security update to the stable version 1.5 of Roundcube Webmail. It provides fixes to some regressions introduced in the previous release as well a recently reported security vulnerability:

  • SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke, reported by class_nzm.

This version is considered stable and we recommend to update all productive installations of Roundcube 1.5.x with it. Please do backup your data before updating!

CHANGELOG

  • Fix so distribution packages (and composer.json) don't include development dependencies
  • Fix regression where mail search would fail on non-ascii search criteria (#10121)
  • Fix regression where some data url images could get ignored/lost (#10128)
  • Fix SVG Animate FUNCIRI Attribute Bypass — Remote Image Loading via fill/filter/stroke

gst-devtools-1.26.11-1.fc42 gst-editing-services-1.26.11-1.fc42 gstreamer1-1.26.11-1.fc42 gstreamer1-doc-1.26.11-1.fc42 gstreamer1-plugin-libav-1.26.11-1.fc42 gstreamer1-plugins-bad-free-1.26.11-1.fc42 gstreamer1-plugins-base-1.26.11-1.fc42 gstreamer1…

14 hours 39 minutes ago
FEDORA-2026-5e16254ca6 Packages in this update:
  • gst-devtools-1.26.11-1.fc42
  • gst-editing-services-1.26.11-1.fc42
  • gstreamer1-1.26.11-1.fc42
  • gstreamer1-doc-1.26.11-1.fc42
  • gstreamer1-plugin-libav-1.26.11-1.fc42
  • gstreamer1-plugins-bad-free-1.26.11-1.fc42
  • gstreamer1-plugins-base-1.26.11-1.fc42
  • gstreamer1-plugins-good-1.26.11-1.fc42
  • gstreamer1-plugins-ugly-free-1.26.11-1.fc42
  • gstreamer1-rtsp-server-1.26.11-1.fc42
  • gstreamer1-vaapi-1.26.11-1.fc42
  • python-gstreamer1-1.26.11-1.fc42
Update description:

1.26.11

gst-devtools-1.26.11-1.fc43 gst-editing-services-1.26.11-1.fc43 gstreamer1-1.26.11-1.fc43 gstreamer1-doc-1.26.11-1.fc43 gstreamer1-plugin-libav-1.26.11-1.fc43 gstreamer1-plugins-bad-free-1.26.11-1.fc43 gstreamer1-plugins-base-1.26.11-1.fc43 gstreamer1…

17 hours 24 minutes ago
FEDORA-2026-e77ad9d792 Packages in this update:
  • gst-devtools-1.26.11-1.fc43
  • gst-editing-services-1.26.11-1.fc43
  • gstreamer1-1.26.11-1.fc43
  • gstreamer1-doc-1.26.11-1.fc43
  • gstreamer1-plugin-libav-1.26.11-1.fc43
  • gstreamer1-plugins-bad-free-1.26.11-1.fc43
  • gstreamer1-plugins-base-1.26.11-1.fc43
  • gstreamer1-plugins-good-1.26.11-1.fc43
  • gstreamer1-plugins-ugly-free-1.26.11-1.fc43
  • gstreamer1-rtsp-server-1.26.11-1.fc43
  • gstreamer1-vaapi-1.26.11-1.fc43
  • python-gstreamer1-1.26.11-1.fc43
Update description:

1.26.11

kea-2.6.5-1.el9

20 hours 29 minutes ago
FEDORA-EPEL-2026-01ea52d899 Packages in this update:
  • kea-2.6.5-1.el9
Update description:
  • New version 2.6.5
  • Fixes CVE-2026-3608 (rhbz#2452134)

kea-3.0.3-1.fc42

20 hours 31 minutes ago
FEDORA-2026-66f19b11e0 Packages in this update:
  • kea-3.0.3-1.fc42
Update description:
  • New version 3.0.3 (rhbz#2451141)
  • Fixes CVE-2026-3608 (rhbz#2451621)

kea-3.0.3-1.fc43

20 hours 31 minutes ago
FEDORA-2026-04263e2a5b Packages in this update:
  • kea-3.0.3-1.fc43
Update description:
  • New version 3.0.3 (rhbz#2451141)
  • Fixes CVE-2026-3608 (rhbz#2451621)
Checked
32 minutes 13 seconds ago