Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 445
Alerts This Week
Warning Icon 1 445

Fedora 44 Lego Important Off-Path Poisoning Update 2026-30e8e9a2b2

fedora
Calendar Grey July 26, 2026
Scroller Fedora
Fedora 44 lego 5.3.1 update addresses off-path poisoning risk from insufficient query-response matching.
Fedora has released a notification for updating the lego package to version 5.3.1, an ACME client in Go, addressing issue rhbz#2504092 and related security concerns.

Summary

Let's Encrypt/ACME client written in Go.

Update Information:

Update to 5.3.1

Change Log

* Tue Jul 21 2026 Packit - 5.3.1-1 - Update to 5.3.1 upstream release - Resolves: rhbz#2504092 * Thu Jul 16 2026 Fedora Release Engineering - 5.2.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_45_Mass_Rebuild

References


[ 1 ] Bug #2500376 - CVE-2026-10846 lego: ldns: Off-path poisoning attacks due to insufficient query-response matching [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2500376

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-30e8e9a2b2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: lego
Product: Fedora 44
Version: 5.3.1
Release: 2.fc44
Summary: Let's Encrypt/ACME client written in Go

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.