Fedora Security Advisories

pyOpenSSL-26.0.0-1.fc44

1 hour 7 minutes ago
FEDORA-2026-5697f4e025 Packages in this update:
  • pyOpenSSL-26.0.0-1.fc44
Update description:

Update to version 26.0.0

  • Added support for using aws-lc instead of OpenSSL.
  • Properly raise an error if a DTLS cookie callback returned a cookie longer than DTLS1_COOKIE_LENGTH bytes. Previously this would result in a buffer-overflow. Credit to dark_haxor for reporting the issue. CVE-2026-27459
  • Added OpenSSL.SSL.Connection.get_group_name to determine which group name was negotiated.
  • Context.set_tlsext_servername_callback now handles exceptions raised in the callback by calling sys.excepthook and returning a fatal TLS alert. Previously, exceptions were silently swallowed and the handshake would proceed as if the callback had succeeded. Credit to Leury Castillo for reporting this issue. CVE-2026-27448

openssh-10.2p1-6.fc44

8 hours 45 minutes ago
FEDORA-2026-62fb46caac Packages in this update:
  • openssh-10.2p1-6.fc44
Update description:
  • CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

openssh-9.9p1-13.fc42

8 hours 45 minutes ago
FEDORA-2026-39819a3d62 Packages in this update:
  • openssh-9.9p1-13.fc42
Update description:
  • CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

openssh-10.0p1-7.fc43

8 hours 45 minutes ago
FEDORA-2026-bab4aa5da7 Packages in this update:
  • openssh-10.0p1-7.fc43
Update description:
  • CVE-2026-3497: Fix information disclosure or denial of service due to uninitialized variables in gssapi-keyex

vtk-9.2.6-44.fc43

15 hours 3 minutes ago
FEDORA-2026-55f82da186 Packages in this update:
  • vtk-9.2.6-44.fc43
Update description:

Add patch to fix integer overflow on 32-bit in KissFFT (CVE-2025-34297)

vtk-9.2.6-38.fc42

15 hours 3 minutes ago
FEDORA-2026-ff768f8e37 Packages in this update:
  • vtk-9.2.6-38.fc42
Update description:

Add patch to fix integer overflow on 32-bit in KissFFT (CVE-2025-34297)

xen-4.21.0-5.fc44

21 hours 17 minutes ago
FEDORA-2026-5ee06b864d Packages in this update:
  • xen-4.21.0-5.fc44
Update description:

Use after free of paging structures in EPT [XSA-480, CVE-2026-23554] Xenstored DoS by unprivileged domain [XSA-481, CVE-2026-23555]

Checked
56 minutes 48 seconds ago