Fedora Security Advisories

OpenBoard-1.7.7-6.fc45 Pencil2D-0.7.2-6.fc45 alsa-plugins-1.2.12-11.fc45 amarok-3.3.3-4.fc45 aqualung-2.0-12.fc45 atomes-1.3.1-4.fc45 attract-mode-2.7.0-21.fc45 audacious-plugins-4.6.1-6.fc45 audacity-3.7.9-2.fc45 baresip-4.11.0-2.fc45 blender-5.2.2-2…

2 hours 18 minutes ago
FEDORA-2026-040732b5dc Packages in this update:
  • alsa-plugins-1.2.12-11.fc45
  • amarok-3.3.3-4.fc45
  • aqualung-2.0-12.fc45
  • atomes-1.3.1-4.fc45
  • attract-mode-2.7.0-21.fc45
  • audacious-plugins-4.6.1-6.fc45
  • audacity-3.7.9-2.fc45
  • baresip-4.11.0-2.fc45
  • blender-5.2.2-2.fc45
  • calibre-9.14.0-3.fc45
  • cantata-3.5.0-7.fc45
  • cef-146.0.11^chromium146.0.7680.177-6.fc45
  • chromaprint-1.6.1-2.fc45
  • chromium-153.0.8010.36-2.fc45
  • digikam-9.1.0-4.fc45
  • dragon-26.08.1-2.fc45
  • ffmpeg-9.0.1-4.fc45
  • ffmpegthumbnailer-2.3.0-4.fc45
  • ffmpegthumbs-26.08.1-2.fc45
  • ffms2-5.0-10.fc45
  • fooyin-0.12.6-2.fc45
  • glaxnimate-0.6.0-5.fc45
  • goldendict-ng-2026.03.09-5.20260309git4a4237d.fc45
  • gpac-26.07.0-4.fc45
  • gstreamer1-plugin-libav-1.28.7-2.fc45
  • guacamole-server-1.6.0-9.fc45
  • guvcview-2.2.2-4.fc45
  • haruna-1.8.1-4.fc45
  • hedgewars-1.0.3-8.fc45
  • icecat-140.16.0-2.rh1.fc45
  • janus-1.4.1-7.fc45
  • k3b-26.08.1-2.fc45
  • kdenlive-26.08.1-2.fc45
  • kf5-kfilemetadata-5.116.0-11.fc45
  • kf6-kfilemetadata-6.30.0-2.fc45
  • kpipewire-6.7.5-2.fc45
  • lazygal-0.12-5.fc45
  • libcamera-apps-1.13.0-2.fc45
  • libheif-1.23.4-6.fc45
  • libopenshot-0.7.0-2.fc45
  • libopenshot-audio-0.6.0-2.fc45
  • libvncserver-0.9.15-9.fc45
  • localsearch-3.12~rc-2.fc45
  • mat2-0.14.0-7.fc45
  • minidlna-1.3.3-18.fc45
  • mivisionx-7.2.1-5.fc45
  • mixxx-2.5.6-6.fc45
  • mlt-7.40.0-2.fc45
  • monado-25.1.0^20260820git01c1f6b-2.fc45
  • mpd-0.24.14-2.fc45
  • mpv-0.41.0-10.fc45
  • mpv-mpris-1.2-4.fc45
  • neatvnc-0.9.0-9.fc45
  • notcurses-3.0.17-8.fc45
  • nv-codec-headers13.0-13.0.19.1-1.fc45
  • obs-studio-32.2.2-3.fc45
  • obs-studio-plugin-droidcam-2.4.3-7.fc45
  • obs-studio-plugin-pwvideo-0.2.4-3.fc45
  • obs-studio-plugin-vaapi-0.4.2-7.fc45
  • obs-studio-plugin-vkcapture-1.5.6-1.fc45
  • obs-studio-plugin-webkitgtk-0~git20231023.3c0978b-11.fc45
  • olive-0.2.0^20241204git8ac191c-10.fc45
  • openal-soft-1.24.2-10.fc45
  • OpenBoard-1.7.7-6.fc45
  • opencv-4.13.0-11.fc45
  • openmw-0.51.0-8.fc45
  • opustags-1.10.1-8.fc45
  • os-autoinst-5^20260601git6ee8da2-5.fc45
  • Pencil2D-0.7.2-6.fc45
  • pianobar-2024.12.21-6.fc45
  • python-audioread-3.0.1-15.fc45
  • python-torchaudio-2.11.0-4.fc45
  • python-torchvision-0.27.1-6.fc45
  • qmmp-2.3.3-5.fc45
  • qmmp-plugin-pack-2.3.1-3.fc45
  • qmplay2-26.08.02-2.fc45
  • qt5-qtwebengine-5.15.19-10.fc45
  • qt6-qtmultimedia-6.11.2-2.fc45
  • qt6-qtwebengine-6.11.2-3.fc45
  • qtox-1.18.5-3.fc45
  • retroarch-1.22.0-24.fc45
  • rocdecode-7.2.0-7.fc45
  • rocdecode7.2-7.2.0-6.fc45
  • rsgain-3.8-2.fc45
  • siril-1.4.4-4.fc45
  • squeezelite-2.0.0.1586-4.20260814gitde70976.fc45
  • swayimg-5.6-2.fc45
  • tigervnc-1.16.2-8.fc45
  • timg-1.6.3-7.fc45
  • unpaper-7.0.0-18.fc45
  • vlc-3.0.23-18.fc45
  • vtk-9.6.2-12.fc45
  • waypipe-0.11.2-2.fc45
  • wf-recorder-0.6.0-5.fc45
  • wivrn-26.9-3.fc45
  • wxsvg-1.5.25-9.fc45
  • xine-lib-1.2.13-36.fc45
  • xmms2-0.9.7-8.fc45
  • xpra-6.5.3-2.fc45
  • xscreensaver-6.16-2.fc45
  • yle-dl-20260624-3.fc45
Update description:

Latest FFmpeg stable release and rebuilds of dependent packages. Fixes a number of high severity security bugs: CVE-2026-64832 CVE-2026-70628 CVE-2026-70632 CVE-2026-75147 CVE-2026-75146 .

Includes:

  • icecat release 140.16.0
  • wivrn v26.9, which fixes install of the APK via the dashboard.

python-streamlink-8.4.0-2.fc43 python-urllib3-2.8.0-1.fc43

15 hours 2 minutes ago
FEDORA-2026-72a7879d08 Packages in this update:
  • python-streamlink-8.4.0-2.fc43
  • python-urllib3-2.8.0-1.fc43
Update description:

Update python-urllib3 to version 2.8.0, fixing three security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (Rated high severity by upstream, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (Rated high severity by upstream, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Rated medium severity by upstream, GHSA-gh4c-6fx4-qh6g)

python-streamlink-8.4.0-2.fc44 python-urllib3-2.8.0-1.fc44

15 hours 3 minutes ago
FEDORA-2026-700dc0d93d Packages in this update:
  • python-streamlink-8.4.0-2.fc44
  • python-urllib3-2.8.0-1.fc44
Update description:

Update python-urllib3 to version 2.8.0, fixing three security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (Rated high severity by upstream, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (Rated high severity by upstream, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Rated medium severity by upstream, GHSA-gh4c-6fx4-qh6g)

python-quart-trio-0.13.0-1.fc45 python-streamlink-8.4.0-5.fc45 python-urllib3-2.8.0-1.fc45

15 hours 4 minutes ago
FEDORA-2026-9a652403b1 Packages in this update:
  • python-quart-trio-0.13.0-1.fc45
  • python-streamlink-8.4.0-5.fc45
  • python-urllib3-2.8.0-1.fc45
Update description:

Update python-urllib3 to version 2.8.0, fixing three security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (Rated high severity by upstream, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (Rated high severity by upstream, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Rated medium severity by upstream, GHSA-gh4c-6fx4-qh6g)

python-streamlink-8.4.0-5.fc46 python-urllib3-2.8.0-1.fc46

15 hours 44 minutes ago
FEDORA-2026-3a61bdd470 Packages in this update:
  • python-streamlink-8.4.0-5.fc46
  • python-urllib3-2.8.0-1.fc46
Update description:

Update python-urllib3 to version 2.8.0, fixing three security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (Rated high severity by upstream, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (Rated high severity by upstream, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Rated medium severity by upstream, GHSA-gh4c-6fx4-qh6g)
Checked
45 minutes 17 seconds ago