Update to release v28.3.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9e2840094a 2025-08-08 00:53:07.923924+00:00 -------------------------------------------------------------------------------- Name : moby-engine Product : Fedora 42 Version : 28.3.3 Release : 1.fc42 URL : https://github.com/moby/moby Summary : The open-source application container engine Description : Docker is an open source project to build, ship and run any application as a lightweight container. Docker containers are both hardware-agnostic and platform-agnostic. This means they can run anywhere, from your laptop to the largest EC2 compute instance and everything in between \u2014 and they do not require you to use a particular language, framework or packaging system. That makes them great building blocks for deploying and scaling web apps, databases, and backend services without depending on a particular stack or provider. -------------------------------------------------------------------------------- Update Information: Update to release v28.3.3 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 29 2025 Bradley G Smith - 28.3.3-1 - Update to release v28.3.3 - Resolves: rhbz#2384219 - Resolves: CVE-2025-54388 / GHSA-x4rx-4gw3-53p4 - Upstream fixes * Thu Jul 24 2025 Fedora Release Engineering - 28.3.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2384219 - moby-engine-28.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2384219 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e2840094a' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The recent Mob Engine update for Fedora 42 addresses a major vulnerability, CVE-2025-54388. For detailed info and installation guidance, check the official documentation. moby engine security Fedora 42 CVE-2025-54388 update. . Severity: Critical. LinuxSecurity.com Team
- Update to 20.10.20. - Mitigates CVE-2022-39253. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-2c33bba286 2022-11-10 22:04:44.632361 --------------------------------------------------------------------------------Name : moby-engine Product : Fedora 37 Version : 20.10.20 Release : 1.fc37 URL : https://www.docker.com Summary : The open-source application container engine Description : Docker is an open source project to build, ship and run any application as a lightweight container. Docker containers are both hardware-agnostic and platform-agnostic. This means they can run anywhere, from your laptop to the largest EC2 compute instance and everything in between - and they don't require you to use a particular language, framework or packaging system. That makes them great building blocks for deploying and scaling web apps, databases, and backend services without depending on a particular stack or provider. --------------------------------------------------------------------------------Update Information: - Update to 20.10.20. - Mitigates CVE-2022-39253 --------------------------------------------------------------------------------ChangeLog: * Thu Oct 20 2022 Jan Kuparinen - 20.10.20-1 - Update to 20.10.20. - Mitigates CVE-2022-39253 * Tue Oct 18 2022 Jan Kuparinen - 20.10.19-1 - Update to 20.10.19. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-2c33bba286' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update to 20.10.20. - Mitigates CVE-2022-39253. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-12790ca71a 2022-10-22 13:50:51.503624 --------------------------------------------------------------------------------Name : moby-engine Product : Fedora 36 Version : 20.10.20 Release : 1.fc36 URL : https://www.docker.com Summary : The open-source application container engine Description : Docker is an open source project to build, ship and run any application as a lightweight container. Docker containers are both hardware-agnostic and platform-agnostic. This means they can run anywhere, from your laptop to the largest EC2 compute instance and everything in between - and they don't require you to use a particular language, framework or packaging system. That makes them great building blocks for deploying and scaling web apps, databases, and backend services without depending on a particular stack or provider. --------------------------------------------------------------------------------Update Information: - Update to 20.10.20. - Mitigates CVE-2022-39253 --------------------------------------------------------------------------------ChangeLog: * Thu Oct 20 2022 Jan Kuparinen - 20.10.20-1 - Update to 20.10.20. - Mitigates CVE-2022-39253 * Tue Oct 18 2022 Jan Kuparinen - 20.10.19-1 - Update to 20.10.19. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-12790ca71a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
## moby-engine https://github.com/moby/moby/releases/tag/v20.10.17 Includes updates to bundled libraries that fix CVEs. ## golang-github-docker-libnetwork Bump to f6ccccb1c082a432c2a5814aaedaca56af33d9ea. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3ecd21576a 2022-06-20 01:08:31.414447 --------------------------------------------------------------------------------Name : moby-engine Product : Fedora 35 Version : 20.10.17 Release : 2.fc35 URL : https://www.docker.com Summary : The open-source application container engine Description : Docker is an open source project to build, ship and run any application as a lightweight container. Docker containers are both hardware-agnostic and platform-agnostic. This means they can run anywhere, from your laptop to the largest EC2 compute instance and everything in between - and they don't require you to use a particular language, framework or packaging system. That makes them great building blocks for deploying and scaling web apps, databases, and backend services without depending on a particular stack or provider. --------------------------------------------------------------------------------Update Information: ## moby-engine https://github.com/moby/moby/releases/tag/v20.10.17 Includes updates to bundled libraries that fix CVEs. ## golang-github-docker-libnetwork Bump to f6ccccb1c082a432c2a5814aaedaca56af33d9ea --------------------------------------------------------------------------------ChangeLog: * Sat Jun 11 2022 Maxwell G - 20.10.17-2 - Rebuild for new golang-github-docker-libnetwork * Fri Jun 10 2022 Maxwell G - 20.10.17-1 - Update to 20.10.17. Fixes rhbz#2095714. --------------------------------------------------------------------------------References: [ 1 ] Bug #2095714 - moby-engine-20.10.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=2095714 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3ecd21576a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
uWSGI could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5054-1 August 30, 2021 uwsgi vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: uWSGI could be made to crash if it received specially crafted input. Software Description: - uwsgi: fast, self-healing application container server Details: Felix Wilhelm discovered a buffer overflow flaw in the mod_proxy_uwsgi module. An attacker could use this vulnerability to provoke an information disclosure or potentially remote code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libapache2-mod-proxy-uwsgi 2.0.15-10.2ubuntu2.2 libapache2-mod-ruwsgi 2.0.15-10.2ubuntu2.2 libapache2-mod-uwsgi 2.0.15-10.2ubuntu2.2 uwsgi 2.0.15-10.2ubuntu2.2 uwsgi-core 2.0.15-10.2ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5054-1 CVE-2020-11984 Package Information: https://launchpad.net/ubuntu/+source/uwsgi/2.0.15-10.2ubuntu2.2 . Recently, Security Alert USN-5054-1 exposes a severe vulnerability in uWSGI, which could lead to system instability and exploitation through specially designed input.. uWSGI, Ubuntu 18.04, security update, buffer overflow, crash risk. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.