Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 42 openQA Update for lodash Important Protection CVE-2025-13465

fedora
Calendar Grey February 6, 2026
Dist Fedora Esm H88
Update for Fedora 42 secures openQA by patching lodash against CVE-2025-13465, improving resilience against attacks.
This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465

Summary

openQA is a testing framework that allows you to test GUI applications on one

hand and bootloader and kernel on the other. In both cases, it is difficult to

script tests and verify the output. Output can be a popup window or it can be

an error in early boot even before init is executed.

openQA is an automated test tool that makes it possible to test the whole

installation process of an operating system. It uses virtual machines to

reproduce the process, check the output (both serial console and screen) in

every step and send the necessary keystrokes and commands to proceed to the

next. openQA can check whether the system can be installed, whether it works

properly in 'live' mode, whether applications work or whether the system

responds as expected to different installation options and commands.

Even more importantly, openQA can run several combinations of tests for every

revision of the operating system, reporting the errors detected for each

combination of hardware configuration, installation options and variant of the

operating system.

Update Information:

This update bumps the bundled lodash to 4.17.23 to ensure openQA is protected against CVE-2025-13465. It likely was not vulnerable in any case, though, as I don't believe the vulnerable codepaths were exposed by openQA's use of lodash.

Change Log

* Mon Jan 26 2026 Adam Williamson - 5^20250711git28a0214-4 - Backport PR #6920 to fix RHBZ #2432984 (CVE-2025-13465)

References


[ 1 ] Bug #2432984 - CVE-2025-13465 openqa: prototype pollution in _.unset and _.omit functions [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2432984

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-84de1534b1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: openqa
Product: Fedora 42
Version: 5^20250711git28a0214
Release: 4.fc42
Summary: OS-level automated testing framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here