Fast, reliable, and secure dependency management.
Update Information:
Fix CVE-2025-48387.
* Wed Jun 4 2025 Sandro Mani
[ 1 ] Bug #2369950 - CVE-2025-48387 yarnpkg: tar-fs has issue where extract can write outside the specified dir with a specific tarball [epel-9]
https://bugzilla.redhat.com/show_bug.cgi?id=2369950
[ 2 ] Bug #2369951 - CVE-2025-48387 yarnpkg: tar-fs has issue where extract can write outside the specified dir with a specific tarball [fedora-41]
https://bugzilla.redhat.com/show_bug.cgi?id=2369951
[ 3 ] Bug #2369953 - CVE-2025-48387 yarnpkg: tar-fs has issue where extract can write outside the specified dir with a specific tarball [fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2369953
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-732290e75c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.