Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 42: yq Important Input Sanitation Issue Fix FEDORA-2025-99309ef35f

fedora
Calendar Grey September 7, 2025
Dist Fedora Esm H88
The latest yq update for Fedora 42 brings crucial security improvements addressing input validation vulnerabilities along with various enhancements.
Add shell-completions Update to 4.47.1 and adopt go-vendor-tools

Summary

Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties

processor.

Update Information:

Add shell-completions Update to 4.47.1 and adopt go-vendor-tools

Change Log

* Fri Aug 29 2025 Mikel Olasagasti Uranga - 4.47.1-2 - Add shell completions * Thu Aug 21 2025 Romain Geissler - 4.47.1-1 - Upgrade to upstream version 4.47.1 and use vendoring (rhbz#2282002). * Fri Aug 15 2025 Maxwell G - 4.43.1-7 - Rebuild for golang-1.25.0 * Fri Jul 25 2025 Fedora Release Engineering - 4.43.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild

References


[ 1 ] Bug #2282002 - v4.44.1 of yq was released https://bugzilla.redhat.com/show_bug.cgi?id=2282002 [ 2 ] Bug #2360655 - CVE-2025-22872 yq: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2360655

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-99309ef35f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: yq
Product: Fedora 42
Version: 4.47.1
Release: 2.fc42
Summary: Yq is a portable command-line YAML, JSON, XML, CSV, TOML and properties processor

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here