Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Fedora 44 dnf5 5.4.0.0 Important Denial of Service Fix 2026-6072c6888a

fedora
Calendar Grey March 13, 2026
Dist Fedora Esm H88
Fedora 44 update fixes crash in dnf5daemon-server from unknown locale. Ensure secure management with release 5.4.0.0.
This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client

Summary

DNF5 is a command-line package manager that automates the process of installing,

upgrading, configuring, and removing computer programs in a consistent manner.

It supports RPM packages, modulemd modules, and comps groups & environments.

Update Information:

This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client. Update to upstream release 5.4.0.0. Full changelog.

Change Log

* Tue Mar 10 2026 Petr Pisar - 5.4.0.0-2 - Fix a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client (CVE-2026-3836) (bug #2445771) * Mon Mar 2 2026 Petr Pisar - 5.4.0.0-1 - Fix segmentation fault in bash completion (bug #2443105) * Thu Feb 19 2026 Petr Pisar - 5.4.0.0-1 - Honor localpkg_gpgcheck in RPM transaction per-element policy (bug #2440722) * Tue Feb 17 2026 Packit - 5.4.0.0-1 - Update to version 5.4.0.0

References


[ 1 ] Bug #2445770 - CVE-2026-3836 dnf5: dnf5: Denial of Service via path traversal in D-Bus locale configuration https://bugzilla.redhat.com/show_bug.cgi?id=2445770

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6072c6888a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: dnf5
Product: Fedora 44
Version: 5.4.0.0
Release: 2.fc44
Summary: Command-line package manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here