Fedora Security Advisories

7zip-26.04-1.el9

3 hours 51 minutes ago
FEDORA-EPEL-2026-29947f7caa Packages in this update:
  • 7zip-26.04-1.el9
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_3

3 hours 51 minutes ago
FEDORA-EPEL-2026-e527d77d36 Packages in this update:
  • 7zip-26.04-1.el10_3
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

7zip-26.04-1.el10_4

3 hours 51 minutes ago
FEDORA-EPEL-2026-7b07dd12c9 Packages in this update:
  • 7zip-26.04-1.el10_4
Update description:

Some bugs and vulnerabilities were fixed

7-Zip 26.03
  • Improved support for Joliet ISO images and Compound archives.
  • Some bugs and vulnerabilities were fixed.

Irrelevant to us, listing for completeness as it affects only decompressing RAR archives (which we disable) on Windows (which we're not)

  • CVE-2026-58052 : 7-Zip failed to preserve the Mark-of-the-Web when extracting a crafted archive.

https://github.com/ip7z/7zip/releases/tag/26.03

exim-4.100.1-1.el8

7 hours 57 minutes ago
FEDORA-EPEL-2026-71b80f48fa Packages in this update:
  • exim-4.100.1-1.el8
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el9

8 hours 4 minutes ago
FEDORA-EPEL-2026-61a5ea9fcd Packages in this update:
  • exim-4.100.1-1.el9
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.el10_4

8 hours 8 minutes ago
FEDORA-EPEL-2026-15b5988543 Packages in this update:
  • exim-4.100.1-1.el10_4
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc43

8 hours 15 minutes ago
FEDORA-2026-d202b74c6a Packages in this update:
  • exim-4.100.1-1.fc43
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc44

8 hours 17 minutes ago
FEDORA-2026-4f9e436ed5 Packages in this update:
  • exim-4.100.1-1.fc44
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

exim-4.100.1-1.fc45

8 hours 31 minutes ago
FEDORA-2026-3f88ddbd83 Packages in this update:
  • exim-4.100.1-1.fc45
Update description:

This is new version of exim fixing CVE-2026-94054, CVE-2026-94055, CVE-2026-94056, CVE-2026-94057.

curl-8.18.0-12.fc44

10 hours ago
FEDORA-2026-8efcd7a2a0 Packages in this update:
  • curl-8.18.0-12.fc44
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)
  • Fix HTTP/2 server push UAF (CVE-2026-18924)

curl-8.21.0-7.fc45

14 hours 58 minutes ago
FEDORA-2026-c2d4a9aa16 Packages in this update:
  • curl-8.21.0-7.fc45
Update description:
  • fix secure cookie attribute bypass with tab (CVE-2026-80255)
  • fix OpenSSL provider use-after-free (CVE-2026-80229)

chromium-154.0.8037.97-1.el10_4

16 hours 36 minutes ago
FEDORA-EPEL-2026-d1c26f4ffd Packages in this update:
  • chromium-154.0.8037.97-1.el10_4
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el9

16 hours 36 minutes ago
FEDORA-EPEL-2026-923ac1e238 Packages in this update:
  • chromium-154.0.8037.97-1.el9
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_3

16 hours 36 minutes ago
FEDORA-EPEL-2026-b3497ed039 Packages in this update:
  • chromium-154.0.8037.97-1.el10_3
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.el10_2

16 hours 36 minutes ago
FEDORA-EPEL-2026-421dd4a529 Packages in this update:
  • chromium-154.0.8037.97-1.el10_2
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC

chromium-154.0.8037.97-1.fc43

16 hours 36 minutes ago
FEDORA-2026-02902c2fa0 Packages in this update:
  • chromium-154.0.8037.97-1.fc43
Update description:

Update to 154.0.8037.97, includes 11 security fixes

  • CVE-2026-103621: Integer overflow in Compositing
  • CVE-2026-103622: Use after free in SVG
  • CVE-2026-103623: Use after free in MediaStream
  • CVE-2026-103624: Use after free in Contextual Tasks
  • CVE-2026-103625: Type confusion in V8
  • CVE-2026-103626: Incorrect authorization in FileSystem
  • CVE-2026-103627: Information leak in SVG
  • CVE-2026-103628: Out of bounds write in WebGL
  • CVE-2026-103629: Integer overflow in Skia
  • CVE-2026-103630: Use after free in FedCM
  • CVE-2026-103631: Buffer overflow in WebRTC
Checked
13 minutes 37 seconds ago