Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Fedora 44 Rust-Fern Critical Security Fixes for CVE-2026-49232 and Others

fedora
Calendar Grey July 21, 2026
Scroller Fedora
Critical security issues fixed in rust-fern update include path traversal and panic fixes. Upgrade recommended for all users.
Update routinator to the latest, pulling in updated dependencies (rpki and syslog), and switch fern to using syslog 7 instead of 6 for this update, and loosen the syslog version bo...

Summary

Simple, efficient logging.

Update Information:

Update routinator to the latest, pulling in updated dependencies (rpki and syslog), and switch fern to using syslog 7 instead of 6 for this update, and loosen the syslog version bound for ifcfg-devname. v0.15.2 This release fixes a number of vulnerabilities and security issues identified by a security audit performed by X41 D-Sec and financed by Sovereign Tech Agency. We advise all users to upgrade at their earliest convenience. Security fixes Changed how transient errors when accepting incoming HTTP and RTR connections are handled: instead of exiting, a warning is printed and the error is ignored. ([#1099]) This issue was assigned CVE-2026-49232. Extended the check for illegal path components in rsync URIs to also include the authority and module parts. (via rpki-rs#370) This fixes a path traversal vulnerability that has been assigned CVE-2026-49233. Fixed a panic when parsing certain AS numbers from strings. (via rpki-rs#373) This fixes a vulnerability that has been assigned CVE-2...

Change Log

* Thu Jul 2 2026 Michel Lind - 0.7.1-6 - Switch to building against syslog 7

References


[ 1 ] Bug #2300127 - rust-syslog-7.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2300127 [ 2 ] Bug #2396345 - rust-rpki-0.19.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2396345 [ 3 ] Bug #2400457 - rust-routinator-0.15.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2400457 [ 4 ] Bug #2497975 - CVE-2026-49232 CVE-2026-49233 CVE-2026-49234 CVE-2026-49235 rust-routinator: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497975

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec9f1ca21a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rust-fern
Product: Fedora 44
Version: 0.7.1
Release: 6.fc44
Summary: Simple, efficient logging

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.