Fedora Security Advisories

pypy3.11-7.3.21-3.3.11.fc45

2 hours 41 minutes ago
FEDORA-2026-ab51ea3744 Packages in this update:
  • pypy3.11-7.3.21-3.3.11.fc45
Update description:

Automatic update for pypy3.11-7.3.21-3.3.11.fc45.

Changelog * Thu Mar 19 2026 Charalampos Stratakis <cstratak@redhat.com> - 7.3.21-2 - Fix CVE-2025-56005 via removing no-longer used bundled ply - Fixes: rhbz#2431978 * Thu Mar 19 2026 Charalampos Stratakis <cstratak@redhat.com> - 7.3.21-1 - Update to 7.3.21 - Fixes: rhbz#2447285

pypy3.10-7.3.19-11.3.10.fc45

4 hours 22 minutes ago
FEDORA-2026-06635fd623 Packages in this update:
  • pypy3.10-7.3.19-11.3.10.fc45
Update description:

Automatic update for pypy3.10-7.3.19-11.3.10.fc45.

Changelog * Thu Mar 19 2026 Charalampos Stratakis <cstratak@redhat.com> - 7.3.19-11 - Security fix for CVE-2025-56005 for the bundled ply within the bundled pycparser - Fixes: rhbz#2431977

pypy-7.3.21-3.fc45

4 hours 37 minutes ago
FEDORA-2026-7585365ba3 Packages in this update:
  • pypy-7.3.21-3.fc45
Update description:

Automatic update for pypy-7.3.21-3.fc45.

Changelog * Thu Mar 19 2026 Charalampos Stratakis <cstratak@redhat.com> - 7.3.21-2 - Security fix for CVE-2025-56005 for the bundled ply within the bundled pycparser - Fixes: rhbz#2431976 * Thu Mar 19 2026 Charalampos Stratakis <cstratak@redhat.com> - 7.3.21-1 - Update to 7.3.21 - Fixes: rhbz#2447284

rubygem-json-2.13.2-2.fc43

15 hours 13 minutes ago
FEDORA-2026-8c07fcde49 Packages in this update:
  • rubygem-json-2.13.2-2.fc43
Update description:

This new updates backports a fix for a format string injection vulnerability in JSON.parse, which is now assigned as CVE-2026-33210

perl-YAML-Syck-1.37-1.el9

1 day 1 hour ago
FEDORA-EPEL-2026-52be5354a0 Packages in this update:
  • perl-YAML-Syck-1.37-1.el9
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_2

1 day 1 hour ago
FEDORA-EPEL-2026-de60bba45b Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_2
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.el10_3

1 day 1 hour ago
FEDORA-EPEL-2026-e7f8f46758 Packages in this update:
  • perl-YAML-Syck-1.37-1.el10_3
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc43

1 day 2 hours ago
FEDORA-2026-3572f7e01c Packages in this update:
  • perl-YAML-Syck-1.37-1.fc43
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc44

1 day 2 hours ago
FEDORA-2026-a8d89d8ae2 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc44
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

perl-YAML-Syck-1.37-1.fc42

1 day 2 hours ago
FEDORA-2026-d226775800 Packages in this update:
  • perl-YAML-Syck-1.37-1.fc42
Update description:

YAML::Syck versions up to and including 1.36 for Perl has several potential security vulnerabilities including a high-severity heap buffer overflow in the YAML emitter. The heap overflow occurs when class names exceed the initial 512-byte allocation. The base64 decoder could read past the buffer end on trailing newlines. strtok mutated n->type_id in place, corrupting shared node data. A memory leak occurred in syck_hdlr_add_anchor when a node already had an anchor. The incoming anchor string 'a' was leaked on early return.

libsoup3-3.6.6-2.fc43

1 day 5 hours ago
FEDORA-2026-f029d04054 Packages in this update:
  • libsoup3-3.6.6-2.fc43
Update description:

Add patch for CVE-2026-1539 (Also remove Proxy-Authorization header on cross origin redirect)

Checked
22 minutes 31 seconds ago