Fedora Security Advisories

strongswan-6.0.6-1.el9

3 hours 45 minutes ago
FEDORA-EPEL-2026-ea9af18b11 Packages in this update:
  • strongswan-6.0.6-1.el9
Update description:

Update to 6.0.6 to fix CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291

rust-sequoia-cert-store-0.7.3-1.fc43 rust-sequoia-chameleon-gnupg-0.13.1-13.fc43 rust-sequoia-octopus-librnp-1.11.1-7.fc43 rust-sequoia-sop-0.37.3-4.fc43 rust-sequoia-sq-1.3.1-12.fc43 rust-sequoia-wot-0.15.2-1.fc43

5 hours 44 minutes ago
FEDORA-2026-ecfadb29a1 Packages in this update:
  • rust-sequoia-cert-store-0.7.3-1.fc43
  • rust-sequoia-chameleon-gnupg-0.13.1-13.fc43
  • rust-sequoia-octopus-librnp-1.11.1-7.fc43
  • rust-sequoia-sop-0.37.3-4.fc43
  • rust-sequoia-sq-1.3.1-12.fc43
  • rust-sequoia-wot-0.15.2-1.fc43
Update description:
  • Update the sequoia-wot crate to version 0.15.2.
  • Update the sequoia-keystore crate to version 0.7.3.

This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:

rust-sequoia-cert-store-0.7.3-1.fc44 rust-sequoia-chameleon-gnupg-0.13.1-13.fc44 rust-sequoia-octopus-librnp-1.11.1-7.fc44 rust-sequoia-sop-0.37.3-4.fc44 rust-sequoia-sq-1.3.1-12.fc44 rust-sequoia-wot-0.15.2-1.fc44

5 hours 44 minutes ago
FEDORA-2026-5c5f4f40a4 Packages in this update:
  • rust-sequoia-cert-store-0.7.3-1.fc44
  • rust-sequoia-chameleon-gnupg-0.13.1-13.fc44
  • rust-sequoia-octopus-librnp-1.11.1-7.fc44
  • rust-sequoia-sop-0.37.3-4.fc44
  • rust-sequoia-sq-1.3.1-12.fc44
  • rust-sequoia-wot-0.15.2-1.fc44
Update description:
  • Update the sequoia-wot crate to version 0.15.2.
  • Update the sequoia-keystore crate to version 0.7.3.

This includes a rebuild of all dependent applications to address three low-severity security vulnerabilities in sequoia-wot:

strongswan-6.0.6-1.el10_3

7 hours 34 minutes ago
FEDORA-EPEL-2026-9b6d13e4b9 Packages in this update:
  • strongswan-6.0.6-1.el10_3
Update description:

Fixes CVE-2026-35328, CVE-2026-35329, CVE-2026-35330, CVE-2026-35331, CVE-2026-35332, CVE-2026-35333, CVE-2026-35334, CVE-2026-25075, CVE-2025-9615, CVE-2025-62291

kernel-7.0.10-201.fc44

11 hours 43 minutes ago
FEDORA-2026-bc20b091a8 Packages in this update:
  • kernel-7.0.10-201.fc44
Update description:

The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.

kernel-7.0.10-101.fc43

11 hours 43 minutes ago
FEDORA-2026-146d86eefc Packages in this update:
  • kernel-7.0.10-101.fc43
Update description:

The 7.0.10-101/201 stable kernel updates contain a number of important fixes across the tree.

pie-1.4.5-1.fc44

1 day 12 hours ago
FEDORA-2026-e5d5fc359d Packages in this update:
  • pie-1.4.5-1.fc44
Update description: Version 1.4.5

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

pie-1.4.5-1.el10_2

1 day 12 hours ago
FEDORA-EPEL-2026-4114f4323c Packages in this update:
  • pie-1.4.5-1.el10_2
Update description: Version 1.4.5

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

pie-1.4.5-1.el10_3

1 day 12 hours ago
FEDORA-EPEL-2026-e9a72cc7ed Packages in this update:
  • pie-1.4.5-1.el10_3
Update description: Version 1.4.5

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

pie-1.4.5-1.fc43

1 day 12 hours ago
FEDORA-2026-b2fe14ec86 Packages in this update:
  • pie-1.4.5-1.fc43
Update description: Version 1.4.5

This release contains vulnerability fixes for the following security advisories:

  • GHSA-h842-vjwg-pxxx - Sudo-elevated arbitrary file deletion via extra.pie-installed-binary metadata in UninstallUsingUnlink
  • GHSA-pm6p-666q-hvj5 - Sudo-elevated root code execution via TOCTOU between self-update verify and write
  • GHSA-f67f-c344-cqqr - PIE self-update accepts any historically-attested pie.phar (rollback gap)
  • GHSA-vcv4-gmjc-mxvq - php-ext.build-path traversal escapes PIE's vendor extract directory
  • GHSA-8xmh-xrvp-hwrf - WindowsInstall::copyExtraFile lacks destination containment check (Windows-only path traversal)
  • GHSA-p4j8-36rr-gjfq - Self-update attestation verification is scoped to --owner=php, not --repo=php/pie

libpng-1.6.58-1.fc43

1 day 21 hours ago
FEDORA-2026-a109a9ac2c Packages in this update:
  • libpng-1.6.58-1.fc43
Update description:
  • updated to 1.6.58
  • 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56.
  • 1.6.57 is released with fixes for the following security vulnerability:
  • CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56 (oops).

libpng-1.6.58-1.fc42

1 day 21 hours ago
FEDORA-2026-9a678a08c8 Packages in this update:
  • libpng-1.6.58-1.fc42
Update description:
  • updated to 1.6.58
  • 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56.
  • 1.6.57 is released with fixes for the following security vulnerability:
  • CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56 (oops).
Checked
32 minutes 38 seconds ago