Fedora Security Advisories

libpng-1.6.55-1.fc42

22 hours 54 minutes ago
FEDORA-2026-168ebcb4a8 Packages in this update:
  • libpng-1.6.55-1.fc42
Update description:

Version 1.6.54 [January 12, 2026] Fixed CVE-2026-22695 (medium severity): Heap buffer over-read in png_image_read_direct_scaled. Fixed CVE-2026-22801 (medium severity): Integer truncation causing heap buffer over-read in png_image_write_*.

Version 1.6.55 [February 9, 2026] Fixed CVE-2026-25646 (high severity): Heap buffer overflow in png_set_quantize.

libpng-1.6.55-1.fc43

22 hours 54 minutes ago
FEDORA-2026-a9ae661fa2 Packages in this update:
  • libpng-1.6.55-1.fc43
Update description:

Version 1.6.54 [January 12, 2026] Fixed CVE-2026-22695 (medium severity): Heap buffer over-read in png_image_read_direct_scaled. Fixed CVE-2026-22801 (medium severity): Integer truncation causing heap buffer over-read in png_image_write_*.

Version 1.6.55 [February 9, 2026] Fixed CVE-2026-25646 (high severity): Heap buffer overflow in png_set_quantize.

python-uv-build-0.10.2-1.fc42 rust-ambient-id-0.0.10-1.fc42 uv-0.10.2-1.fc42

1 day 9 hours ago
FEDORA-2026-086a367966 Packages in this update:
  • python-uv-build-0.10.2-1.fc42
  • rust-ambient-id-0.0.10-1.fc42
  • uv-0.10.2-1.fc42
Update description:

Update uv and python-uv-build to 0.10.2. There are some minor breaking changes in uv; most users should not have to change anything. See https://github.com/astral-sh/uv/blob/0.10.2/CHANGELOG.md for details. There are no breaking changes to python-uv-build.

roundcubemail-1.6.13-1.el10_2

3 days 12 hours ago
FEDORA-EPEL-2026-8d8337c33f Packages in this update:
  • roundcubemail-1.6.13-1.el10_2
Update description: Release 1.6.13
  • Managesieve: Fix handling of string-list format values for date tests in Out of Office (#10075)
  • Fix remote image blocking bypass via SVG content reported by nullcathedral
  • Fix CSS injection vulnerability reported by CERT Polska

roundcubemail-1.6.13-1.fc43

3 days 12 hours ago
FEDORA-2026-547e298156 Packages in this update:
  • roundcubemail-1.6.13-1.fc43
Update description: Release 1.6.13
  • Managesieve: Fix handling of string-list format values for date tests in Out of Office (#10075)
  • Fix remote image blocking bypass via SVG content reported by nullcathedral
  • Fix CSS injection vulnerability reported by CERT Polska
Checked
32 minutes 13 seconds ago