Fedora Security Advisories

freeipmi-1.6.19-1.fc44

5 hours 4 minutes ago
FEDORA-2026-febfd10293 Packages in this update:
  • freeipmi-1.6.19-1.fc44
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

postgresql16-anonymizer-3.2.2-1.fc45

5 hours 9 minutes ago
FEDORA-2026-bc7408de42 Packages in this update:
  • postgresql16-anonymizer-3.2.2-1.fc45
Update description:

Upstream changelog: https://gitlab.com/dalibo/postgresql_anonymizer/-/releases

  • [core] CVE-2026-19633: Escalation via custom types, operators and rangevars
  • [core] update dependencies
  • [static] Define masking policy with parallel static masking
  • [pseudo] Add seeded_street_name
  • [static] CVE-2026-83534: Elevation in parallel masking
  • [make] call extension+install before regress
  • [pseudo] new panel of seeded_* functions
  • [impexp] CVE-2026-19634: SQL injection via import functions
  • [partial] Add anon.array_remove_regex()
  • [static] Ignore a TABLESAMPLE sampling ratio on non-plain-table relations
  • [parallel] Reject a materialized view before parallel masking
  • [dynamic] Proper error message on write operations
  • [static] Optionally drop indexes during static masking (beta)
  • [doc] update the permission matrix
  • [tests] Gate the impexp unit tests on cfg(test) only
  • [doc] split Load and Support out of the Install page
  • [docker] make the image ready for replica masking
  • [tests] Introduce cargo pgrx regress
  • [core] Upgrade dependencies
  • [core] Remove useless compatibility function
  • [image] Define a default value for the sigma parameter
  • [doc] Add the "Anonymized Replica" tutorial
  • [docker] disable fsync during initdb
  • [static] Improve performance and correctness for parallel masking
  • [doc] how to fix cargo audit warnings
  • [doc] Install on Fedora
  • [core] Support PostgreSQL 19 (beta)
  • [core] Upgrade to PGRX 0.19

postgresql16-anonymizer-3.2.2-1.fc44

5 hours 9 minutes ago
FEDORA-2026-58a319c686 Packages in this update:
  • postgresql16-anonymizer-3.2.2-1.fc44
Update description:

Upstream changelog: https://gitlab.com/dalibo/postgresql_anonymizer/-/releases

  • [core] CVE-2026-19633: Escalation via custom types, operators and rangevars
  • [core] update dependencies
  • [static] Define masking policy with parallel static masking
  • [pseudo] Add seeded_street_name
  • [static] CVE-2026-83534: Elevation in parallel masking
  • [make] call extension+install before regress
  • [pseudo] new panel of seeded_* functions
  • [impexp] CVE-2026-19634: SQL injection via import functions
  • [partial] Add anon.array_remove_regex()
  • [static] Ignore a TABLESAMPLE sampling ratio on non-plain-table relations
  • [parallel] Reject a materialized view before parallel masking
  • [dynamic] Proper error message on write operations
  • [static] Optionally drop indexes during static masking (beta)
  • [doc] update the permission matrix
  • [tests] Gate the impexp unit tests on cfg(test) only
  • [doc] split Load and Support out of the Install page
  • [docker] make the image ready for replica masking
  • [tests] Introduce cargo pgrx regress
  • [core] Upgrade dependencies
  • [core] Remove useless compatibility function
  • [image] Define a default value for the sigma parameter
  • [doc] Add the "Anonymized Replica" tutorial
  • [docker] disable fsync during initdb
  • [static] Improve performance and correctness for parallel masking
  • [doc] how to fix cargo audit warnings
  • [doc] Install on Fedora
  • [core] Support PostgreSQL 19 (beta)
  • [core] Upgrade to PGRX 0.19

freeipmi-1.6.19-1.fc45

6 hours 5 minutes ago
FEDORA-2026-abe39f1809 Packages in this update:
  • freeipmi-1.6.19-1.fc45
Update description:

Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode

perl-Net-DNS-1.57-1.el10_4

6 hours 59 minutes ago
FEDORA-EPEL-2026-0f5b361fa5 Packages in this update:
  • perl-Net-DNS-1.57-1.el10_4
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.el10_3

6 hours 59 minutes ago
FEDORA-EPEL-2026-8a37d4d02f Packages in this update:
  • perl-Net-DNS-1.57-1.el10_3
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc44

7 hours 11 minutes ago
FEDORA-2026-57f107ed83 Packages in this update:
  • perl-Net-DNS-1.57-1.fc44
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

perl-Net-DNS-1.57-1.fc43

7 hours 11 minutes ago
FEDORA-2026-48a4531e02 Packages in this update:
  • perl-Net-DNS-1.57-1.fc43
Update description:

Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)

evolution-3.62.0-1.fc45 evolution-data-server-3.62.0-1.fc45 evolution-ews-3.62.0-1.fc45

8 hours 24 minutes ago
FEDORA-2026-5debc0de2b Packages in this update:
  • evolution-3.62.0-1.fc45
  • evolution-data-server-3.62.0-1.fc45
  • evolution-ews-3.62.0-1.fc45
Update description:

Update to 3.62.0

evolution-data-server

Bug Fixes:

  • I#660 - GOA EWS: Do not require OABUrl in autodiscover
  • I#662 - EBackend: Document how OAuth2 sources should ask to be authenticated (Tobias Mueller)
  • I#665 - CalDAV: Ignore Bad Request (400) on overwrite
  • M!243 - ESourceRegistry: Name the credentials source in failed-lookup debug message (Tobias Mueller)

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • Emin Tufan Çetin (tr)
  • Juliano de Souza Camargo (pt_BR)
  • Kjartan Maraas (nb)
evolution

Bug Fixes:

  • I#3381 - Composer: De-duplicate inline images before send
  • I#3383 - junk-filters: Do not leak the child stdin pipe into concurrent spawns (Benjamin Herrenschmidt)
  • I#3386 - Default to not use read-only calendars for reminders and conflict search
  • I#3387 - EUIParser: Notify about accelerators moved by an action rename (Martin Monperrus (AI-assisted))
  • I#3388 - Mail: Validate clickable preview elements are generated by Evolution
  • M!235 - Mail: Remove deprecated SHA1 signature algorithm (Robin Haberkorn)

Miscellaneous:

  • docs: Add API index for newly added symbols in 3.62 for e-util

Translations:

  • Alan Mortensen (da)
  • Aurimas Černius (lt)
  • Balázs Úr (hu)
  • Baurzhan Muftakhidinov (kk)
  • burns (pt_BR)
  • Emin Tufan Çetin (tr)
  • Guillaume Bernard (fr)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)
evolution-ews

Bug Fixes:

  • M!18 - Add a per-folder coalescing gate for sync and refresh (Benjamin Herrenschmidt)
  • M!19 - camel: Do not save the folder summary in the subclass dispose (David Woodhouse)

Translations:

  • Alan Mortensen (da)
  • Balázs Úr (hu)
  • Jiri Eischmann (cs)
  • Kjartan Maraas (nb)

perl-HTML-FormHandler-0.410002-1.fc44

1 day 7 hours ago
FEDORA-2026-21850d7df0 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc44
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc43

1 day 7 hours ago
FEDORA-2026-167a356523 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc43
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

perl-HTML-FormHandler-0.410002-1.fc45

1 day 7 hours ago
FEDORA-2026-406a152d49 Packages in this update:
  • perl-HTML-FormHandler-0.410002-1.fc45
Update description:

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.

HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.

Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.

Checked
48 minutes 38 seconds ago