Fedora Security Advisories

rubygem-json-2.19.2-1.fc44

56 minutes 5 seconds ago
FEDORA-2026-3a7663d43d Packages in this update:
  • rubygem-json-2.19.2-1.fc44
Update description:

New version 2.19.2 is released. This fixes a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210

kryoptic-1.5.0-2.fc43 pyOpenSSL-26.0.0-1.fc43 python-cryptography-46.0.5-1.fc43 rust-asn1-0.22.0-1.fc43 rust-asn1_derive-0.22.0-1.fc43 rust-cryptoki-0.12.0-2.fc43 rust-cryptoki-sys-0.5.0-2.fc43 rust-wycheproof-0.6.0-1.fc43

2 hours 8 minutes ago
FEDORA-2026-9d5b9f45ec Packages in this update:
  • kryoptic-1.5.0-2.fc43
  • pyOpenSSL-26.0.0-1.fc43
  • python-cryptography-46.0.5-1.fc43
  • rust-asn1-0.22.0-1.fc43
  • rust-asn1_derive-0.22.0-1.fc43
  • rust-cryptoki-0.12.0-2.fc43
  • rust-cryptoki-sys-0.5.0-2.fc43
  • rust-wycheproof-0.6.0-1.fc43
Update description:
  • Update pyOpenSSL to v26.0.0 (security update)
  • Update python-cryptography to v46.0.5 (dependency of pyOpenSSL 26)
  • Update rust-asn1 to 0.22 (dependency of python-cryptography)
  • Update kryoptic to v1.5 (required for rust-asn1 bump to 0.22)

The security status of this update is only for pyOpenSSL.

localsearch-3.10.2-2.fc43

2 hours 18 minutes ago
FEDORA-2026-ba6641558a Packages in this update:
  • localsearch-3.10.2-2.fc43
Update description:

Add a patch for several CVEs:

  • CVE-2026-1764 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor
  • CVE-2026-1765 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (TXXX Tags)
  • CVE-2026-1766 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor (ID3v2.3 COMM Tags)
  • CVE-2026-1767 - Heap Buffer Overflow in GNOME localsearch MP3 Extractor

glib2-2.86.4-2.fc43

5 hours 33 minutes ago
FEDORA-2026-5637749c07 Packages in this update:
  • glib2-2.86.4-2.fc43
Update description:

Add patch for CVE-2026-0988 (Integer overflow in g_buffered_input_stream_peek() leads to segmentation fault)

roundcubemail-1.7~rc5-1.fc44

9 hours 14 minutes ago
FEDORA-2026-9b0f520716 Packages in this update:
  • roundcubemail-1.7~rc5-1.fc44
Update description:

Version 1.7-rc5

  • Password: Add nt-binary hashing method (#10096)
  • Fix URL matching for domain names with port numbers (#10105)
  • Fix PHP fatal error when using IMAP cache (#10102)
  • Fix Postgres connection using IPv6 address (#10104)
  • Fix bug where rel=stylesheet part of a <link> could get removed
  • Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
  • Security: Fix bug where a password could get changed without providing the old password
  • Security: Fix IMAP Injection + CSRF bypass in mail search
  • Security: Fix remote image blocking bypass via various SVG animate attributes
  • Security: Fix remote image blocking bypass via a crafted body background attribute
  • Security: Fix fixed position mitigation bypass via use of !important
  • Security: Fix XSS issue in a HTML attachment preview
  • Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts

roundcubemail-1.6.14-1.el10_2

9 hours 15 minutes ago
FEDORA-EPEL-2026-95071cd05c Packages in this update:
  • roundcubemail-1.6.14-1.el10_2
Update description:

Version 1.6.14

  • Fix Postgres connection using IPv6 address (#10104)
  • Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
  • Security: Fix bug where a password could get changed without providing the old password
  • Security: Fix IMAP Injection + CSRF bypass in mail search
  • Security: Fix remote image blocking bypass via various SVG animate attributes
  • Security: Fix remote image blocking bypass via a crafted body background attribute
  • Security: Fix fixed position mitigation bypass via use of !important
  • Security: Fix XSS issue in a HTML attachment preview
  • Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts

roundcubemail-1.6.14-1.fc42

9 hours 15 minutes ago
FEDORA-2026-c283cce7fd Packages in this update:
  • roundcubemail-1.6.14-1.fc42
Update description:

Version 1.6.14

  • Fix Postgres connection using IPv6 address (#10104)
  • Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
  • Security: Fix bug where a password could get changed without providing the old password
  • Security: Fix IMAP Injection + CSRF bypass in mail search
  • Security: Fix remote image blocking bypass via various SVG animate attributes
  • Security: Fix remote image blocking bypass via a crafted body background attribute
  • Security: Fix fixed position mitigation bypass via use of !important
  • Security: Fix XSS issue in a HTML attachment preview
  • Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts

roundcubemail-1.6.14-1.fc43

9 hours 15 minutes ago
FEDORA-2026-2decd38070 Packages in this update:
  • roundcubemail-1.6.14-1.fc43
Update description:

Version 1.6.14

  • Fix Postgres connection using IPv6 address (#10104)
  • Security: Fix pre-auth arbitrary file write via unsafe deserialization in redis/memcache session handler
  • Security: Fix bug where a password could get changed without providing the old password
  • Security: Fix IMAP Injection + CSRF bypass in mail search
  • Security: Fix remote image blocking bypass via various SVG animate attributes
  • Security: Fix remote image blocking bypass via a crafted body background attribute
  • Security: Fix fixed position mitigation bypass via use of !important
  • Security: Fix XSS issue in a HTML attachment preview
  • Security: Fix SSRF + Information Disclosure via stylesheet links to a local network hosts
Checked
52 minutes 5 seconds ago