Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2fc36ddefe 2026-04-25 01:21:36.170784+00:00 -------------------------------------------------------------------------------- Name : bpfman Product : Fedora 44 Version : 0.5.4 Release : 7.fc44 URL : https://bpfman.io Summary : EBPF Program Manager Description : bpfman operates as an eBPF manager, focusing on simplifying the deployment and administration of eBPF programs. -------------------------------------------------------------------------------- Update Information: Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 22 2026 Daniel Mellado - 0.5.4-7 - Fix CVE-2026-31812: Bump tar-rs to .5.45 - Closes rhbz#2449672 * Wed Mar 11 2026 Daniel Mellado - 0.5.4-6 - Fix CVE-2026-31812: Bump quinn-proto to 0.11.14 - Closes rhbz#2446359 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2449672 - CVE-2026-33056 bpfman: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449672 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2fc36ddefe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Automatic update for fido-device-onboard-0.5.5-8.fc43. Changelog for fido-device-onboard * Wed Apr 01 2026 Peter Robinson - 0.5.5-8 - Rebuild for CVE-2026-25727, CVE-2026-33056 * Sun Mar 15 2026 Benjamin A. Beasley - 0.5.5-7. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e6237c2efe 2026-04-10 00:59:15.834445+00:00 -------------------------------------------------------------------------------- Name : fido-device-onboard Product : Fedora 43 Version : 0.5.5 Release : 8.fc43 URL : https://github.com/fdo-rs/fido-device-onboard-rs Summary : A rust implementation of the FIDO Device Onboard Specification Description : A rust implementation of the FIDO Device Onboard Specification. -------------------------------------------------------------------------------- Update Information: Automatic update for fido-device-onboard-0.5.5-8.fc43. Changelog for fido-device-onboard * Wed Apr 01 2026 Peter Robinson - 0.5.5-8 - Rebuild for CVE-2026-25727, CVE-2026-33056 * Sun Mar 15 2026 Benjamin A. Beasley - 0.5.5-7 - In Fedora, update nix dependency from 0.26 to 0.31 * Mon Feb 02 2026 Maxwell G - 0.5.5-6 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 0.5.5-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Oct 10 2025 Maxwell G - 0.5.5-4 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Peter Robinson - 0.5.5-8 - Rebuild for CVE-2026-25727, CVE-2026-33056 * Sun Mar 15 2026 Benjamin A. Beasley - 0.5.5-7 - In Fedora, update nix dependency from 0.26 to 0.31 * Mon Feb 2 2026 Maxwell G - 0.5.5-6 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 0.5.5-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Oct 102025 Maxwell G - 0.5.5-4 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438126 - CVE-2026-25727 fido-device-onboard: time affected by a stack exhaustion denial of service attack [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438126 [ 2 ] Bug #2449677 - CVE-2026-33056 fido-device-onboard: tar-rs: Arbitrary directory permission modification via crafted tar archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2449677 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e6237c2efe' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.