Fedora Security Advisories

chromium-154.0.8037.57-1.el10_2

5 hours 42 minutes ago
FEDORA-EPEL-2026-c4d340d432 Packages in this update:
  • chromium-154.0.8037.57-1.el10_2
Update description:

Update to 154.0.8037.57

CVE-2026-95274: Improper output encoding in DevTools CVE-2026-95275: Incorrect reference resolution in MediaStream CVE-2026-95276: Improper input validation in Themes CVE-2026-95277: Use after free in Views CVE-2026-95278: Missing authorization in WakeLock CVE-2026-95279: UI misrepresentation in Omnibox CVE-2026-95280: Race condition in V8 CVE-2026-95281: Buffer overflow in ANGLE CVE-2026-95282: Use after free in Platform CVE-2026-95283: Buffer overflow in Tint CVE-2026-95284: Buffer overflow in ANGLE CVE-2026-95285: Missing authorization in WebView CVE-2026-95286: Type confusion in Bindings CVE-2026-95287: Missing authorization in Navigation CVE-2026-95288: UI misrepresentation in Mobile CVE-2026-95289: Incorrect authorization in Scroll CVE-2026-95290: Missing authorization in NFC CVE-2026-95291: UI misrepresentation in SecurityIndicators CVE-2026-95292: Incorrect authorization in Safebrowsing CVE-2026-95293: Uninitialized resource in GPU CVE-2026-95294: UI misrepresentation in Browser CVE-2026-95295: Information leak in Mobile CVE-2026-95296: Missing authorization in Core CVE-2026-95297: Missing authorization in Contextual Tasks CVE-2026-95298: Use after free in Browser CVE-2026-95299: Use after free in GPU CVE-2026-95300: Missing authorization in DevTools CVE-2026-95301: Missing authorization in Extensions CVE-2026-95302: Incorrect authorization in WebAPKs CVE-2026-95303: Incomplete cleanup in SmartCard CVE-2026-95304: Out of bounds write in V8 CVE-2026-95305: UI misrepresentation in Chromoting CVE-2026-95306: Type confusion in V8 CVE-2026-95307: UI misrepresentation in ExtensionsMenu CVE-2026-95308: Integer overflow in Metrics CVE-2026-95309: UI misrepresentation in Mobile CVE-2026-95310: Use after free in AdFilter CVE-2026-95311: Free of non-heap memory in Fonts CVE-2026-95312: Information leak in Passwords CVE-2026-95313: Use after free in Fullscreen CVE-2026-95314: Incorrect authorization in HID CVE-2026-95315: Use after free in Aura CVE-2026-95316: Unchecked return value in Performance CVE-2026-95317: Incorrect authorization in MediaCapture CVE-2026-95318: Buffer overflow in Video CVE-2026-95319: Use after free in Printing CVE-2026-95320: Missing authorization in Navigation CVE-2026-95321: UI misrepresentation in Payments CVE-2026-95322: Out of bounds write in GPU CVE-2026-95323: UI misrepresentation in Chromium CVE-2026-95324: Uninitialized resource in GPU CVE-2026-95325: Use after free in ANGLE CVE-2026-95326: Incomplete cleanup in Bluetooth CVE-2026-95327: Information leak in Networking CVE-2026-95328: Confused deputy in Mobile CVE-2026-95329: Out of bounds write in WebGL CVE-2026-95330: Improper state validation in Downloads CVE-2026-95331: Out of bounds write in ANGLE CVE-2026-95332: Use of uninitialized variable in Tint CVE-2026-95333: Use after free in Metrics CVE-2026-95334: Incorrect reference resolution in WebProtect CVE-2026-95335: Use after free in HID CVE-2026-95336: Information leak in Transactions Platform CVE-2026-95337: UI misrepresentation in Messages CVE-2026-95338: Use after free in PDFium CVE-2026-95339: Use after free in ServiceWorker CVE-2026-95340: Incorrect authorization in PictureInPicture CVE-2026-95341: Improper input validation in Desktop CVE-2026-95342: Missing authorization in V8 CVE-2026-95343: Use after free in WebAudio CVE-2026-95344: Race condition in DevTools CVE-2026-95345: Use after free in Actor CVE-2026-95346: UI misrepresentation in Chromoting CVE-2026-95347: Use after free in Updater CVE-2026-95348: Use after free in Bluetooth CVE-2026-95349: Buffer overflow in WebGL CVE-2026-95350: Buffer overflow in ANGLE CVE-2026-95351: Use after free in Views CVE-2026-95352: Incorrect authorization in DevTools CVE-2026-95353: Use after free in Bindings CVE-2026-95354: Use after free in Verifier CVE-2026-95355: Incorrect authorization in Navigation CVE-2026-95356: Use after free in WindowDialog CVE-2026-95357: Out of bounds write in GPU CVE-2026-95358: Incorrect authorization in Mobile CVE-2026-95359: Uninitialized resource in GPU CVE-2026-95360: Race condition in Editing CVE-2026-95361: Confused deputy in DevTools CVE-2026-95362: Cross-site request forgery in DevTools CVE-2026-95363: UI misrepresentation in FileSystem CVE-2026-95364: Improper input validation in Passwords CVE-2026-95365: Type confusion in IndexedDB CVE-2026-95366: Use of released resource in Core CVE-2026-95367: Information leak in DataTransfer CVE-2026-95368: Incorrect authorization in DevTools CVE-2026-95369: Inappropriate implementation in XML CVE-2026-95370: Inappropriate implementation in NFC CVE-2026-95371: Missing authorization in Views CVE-2026-95372: Use after free in Chromecast CVE-2026-95373: Use after free in DevTools CVE-2026-95374: Incorrect authorization in Network CVE-2026-95375: Incorrect authorization in BrowserTag CVE-2026-95376: Externally controlled reference in DevTools CVE-2026-95380: Type confusion in V8 CVE-2026-95381: Improper input validation in Printing CVE-2026-95382: Improper input validation in Auth CVE-2026-95384: Race condition in Transactions Platform CVE-2026-95385: Inappropriate implementation in PlatformIntegration

python-engineio-4.12.3-2.el9 python-simple-websocket-1.0.0-8.el9

6 hours 31 minutes ago
FEDORA-EPEL-2026-e47857b934 Packages in this update:
  • python-engineio-4.12.3-2.el9
  • python-simple-websocket-1.0.0-8.el9
Update description:

Update python-engineio to 4.12.3, which is not the latest version but is the latest version that could be reasonably backported to EPEL9. This required branching a new package for python-simple-websocket 1.0.0 – again, not quite the latest version. Furthermore, this update includes a backport from versions 4.13.2 and 4.13.5 of the fixes for CVE-2026-48802 and CVE-2026-48809.

cri-o1.36-1.36.6-1.fc43

15 hours 20 minutes ago
FEDORA-2026-0025579bc9 Packages in this update:
  • cri-o1.36-1.36.6-1.fc43
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc44

15 hours 35 minutes ago
FEDORA-2026-f5c88f763a Packages in this update:
  • cri-o1.36-1.36.6-1.fc44
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc45

15 hours 54 minutes ago
FEDORA-2026-77abfa2cdd Packages in this update:
  • cri-o1.36-1.36.6-1.fc45
Update description:
  • Update to release v1.36.6
  • Resolves: rhbz#2537559
  • Resolves CVE-2026-17113: rhbz#2523493
  • Resolves: rhbz#2540885

cri-o1.36-1.36.6-1.fc46

16 hours 10 minutes ago
FEDORA-2026-05f65b07d7 Packages in this update:
  • cri-o1.36-1.36.6-1.fc46
Update description:

Automatic update for cri-o1.36-1.36.6-1.fc46.

Changelog * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.6-1 - Update to release v1.36.6 - Resolves: rhbz#2537559 - Resolves CVE-2026-17113: rhbz#2523493 - Resolves: rhbz#2540885 * Sun Sep 27 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 1.36.5-2 - Define --pinns_path - pinns_path is set to the libexec path for pinns

ruff-0.16.9-1.fc46 rust-salsa-0.28.5-1.fc46 rust-salsa-macro-rules-0.28.5-1.fc46 rust-salsa-macros-0.28.5-1.fc46 ty-0.0.84-1.fc46

1 day 17 hours ago
FEDORA-2026-77f6cda09a Packages in this update:
  • ruff-0.16.9-1.fc46
  • rust-salsa-0.28.5-1.fc46
  • rust-salsa-macro-rules-0.28.5-1.fc46
  • rust-salsa-macros-0.28.5-1.fc46
  • ty-0.0.84-1.fc46
Update description:

Update the salsa/salsa-macros/salsa-macro-rules crates to 0.28.5, fixing a use-after-free bug, GHSA-xc3w-55vh-cw3w.

Update ruff to 0.16.9 and ty to 0.0.84, fixing GHSA-vxvm-j4xq-q7m4, which could result in arbitrary code execution when typechecking untrusted code.

nagios-plugins-2.5-2.fc45

1 day 18 hours ago
FEDORA-2026-c213ad9471 Packages in this update:
  • nagios-plugins-2.5-2.fc45
Update description:

Update to upstream (bz#2453492) check_icmp: host-count overflow leads to heap buffer overflow (bz#2513957) Update 0012-fix-perl-ntp-ipv6.patch to allow uppercase hostnames (bz#2500542) Added perl-Math-BigInt as dependency for nagios-plugins-ssl_validity (bz#2439960)

dnf5-5.4.6.0-2.fc45

1 day 19 hours ago
FEDORA-2026-4284af73e4 Packages in this update:
  • dnf5-5.4.6.0-2.fc45
Update description:
  • Update translations from weblate
  • spec: Symlink microdnf(8) and yum(8) manual pages to dnf5(8)
  • Update FSF's address in GPL-2.0 disclaimers
  • Update LGPL-2.1 and GPL-2.0 texts to current FSF's wording
  • fix: DNF5_FORCE_COLUMNS / non-TTY width in transaction table
  • progressbar: Report progress to terminal taskbar via OSC 9;4
  • Makefile: Add FEDORA_VERSION to unify defaults
  • spec: Require GCC ≥ 14.1 for std::chrono::parse()
  • dnf5daemon: Hide invalid offline transactions
  • Clarify plugin source language options
  • needs-restarting: Configure extra packages that require a reboot
  • VendorChangeManager: Allow empty vendor policies in compact format
  • manifest: Log before resolving & after writing files
  • manifest: Print transaction table on resolve
Checked
19 minutes 36 seconds ago