Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Fedora 43 Goose Update Fixes CVE-2026-33056 Permission Modifications

fedora
Calendar Grey April 8, 2026
Dist Fedora Esm H88
Critical update for Goose in Fedora 43 addressing permission issues with crafted tar archives. Upgrade recommended immediately.
Update goose to fix fedora#2449678

Summary

Goose is your on-machine AI agent, capable of automating complex development

tasks from start to finish. More than just code suggestions, goose can build

entire projects from scratch, write and execute code, debug failures,

orchestrate workflows, and interact with external APIs - autonomously.

Whether you're prototyping an idea, refining existing code, or managing

intricate engineering pipelines, goose adapts to your workflow and executes

tasks with precision.

Designed for maximum flexibility, goose works with any LLM and supports

multi-model configuration to optimize performance and cost, seamlessly

integrates with MCP servers, and is available as both a desktop app as well as

CLI - making it the ultimate AI assistant for developers who want to move

faster and focus on innovation.

Update Information:

Update goose to fix fedora#2449678

Change Log

* Fri Mar 27 2026 Manuel Moran - 1.23.2-7 - [skip changelog] Fix gating * Fri Mar 27 2026 Martin Litwora - 1.23.2-6 - Change the test plan URL to point directly to centos-stream test repository * Fri Mar 27 2026 Sam Doran - 1.23.2-5 - Fix CVE-2026-33056 for tar dependency * Thu Mar 26 2026 Sam Doran - 1.23.2-4 - Raise recursion limit on server_test.rs * Mon Mar 23 2026 Manuel Moran - 1.23.2-3 - Add gating

References


[ 1 ] Bug #2449678 - CVE-2026-33056 goose: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449678

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a45f438402' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: goose
Product: Fedora 43
Version: 1.23.2
Release: 7.fc43
Summary: Extensible AI agent client

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here