Fedora Security Advisories

xen-4.21.1-4.fc44

15 hours 30 minutes ago
FEDORA-2026-24b84f97af Packages in this update:
  • xen-4.21.1-4.fc44
Update description:

x86 HVM I/O port list traversal [XSA-491, CVE-2026-42487] domctl lock open to abuse [XSA-492, CVE-2026-42489, CVE-2026-42490] Arm: Completion of memory accesses not guaranteed by completion of a TLBI [XSA-493, CVE-2025-10263] x86: mismatched mapcache metadata [XSA-494, CVE-2026-42488]

ImageMagick-6.9.13.50-1.el8

20 hours 38 minutes ago
FEDORA-EPEL-2026-bc7538a3d7 Packages in this update:
  • ImageMagick-6.9.13.50-1.el8
Update description:

Update to 6.9.13.50

Summary

This update fixes several security vulnerabilities, including multiple high-severity CVEs: Security fixes

  • CVE-2026-33901 (High) — Heap buffer overflow in the MVG decoder that could result in an out-of-bounds write when processing a crafted image.
  • CVE-2026-33908 (High) — Recursive DestroyXMLTree() call with no depth limit causes stack exhaustion when processing deeply nested XML structures, resulting in a Denial of Service (DoS).
  • CVE-2026-40310 (High) — Heap out-of-bounds write in the JP2 encoder triggered when a user specifies an invalid sampling index.

Additional security and bug fixes are included in the upstream releases between 6.9.13.25 and 6.9.13.49. See the upstream release history at: https://github.com/ImageMagick/ImageMagick6/releases

ImageMagick-6.9.13.50-1.el9

20 hours 38 minutes ago
FEDORA-EPEL-2026-49c3a0ffa2 Packages in this update:
  • ImageMagick-6.9.13.50-1.el9
Update description:

Update to 6.9.13.50

Summary

This update fixes several security vulnerabilities, including multiple high-severity CVEs: Security fixes

  • CVE-2026-33901 (High) — Heap buffer overflow in the MVG decoder that could result in an out-of-bounds write when processing a crafted image.
  • CVE-2026-33908 (High) — Recursive DestroyXMLTree() call with no depth limit causes stack exhaustion when processing deeply nested XML structures, resulting in a Denial of Service (DoS).
  • CVE-2026-40310 (High) — Heap out-of-bounds write in the JP2 encoder triggered when a user specifies an invalid sampling index.

Additional security and bug fixes are included in the upstream releases between 6.9.13.25 and 6.9.13.49. See the upstream release history at: https://github.com/ImageMagick/ImageMagick6/releases

Checked
3 minutes 21 seconds ago