Backport fix for CVE-2025-14523. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-20b533bbc7 2026-01-27 04:51:32.146744+00:00 -------------------------------------------------------------------------------- Name : mingw-libsoup Product : Fedora 43 Version : 2.74.3 Release : 16.fc43 URL : https://wiki.gnome.org/Projects/libsoup Summary : MinGW library for HTTP and XML-RPC functionality Description : Libsoup is an HTTP library implementation in C. It was originally part of a SOAP (Simple Object Access Protocol) implementation called Soup, but the SOAP and non-SOAP parts have now been split into separate packages. libsoup uses the Glib main loop and is designed to work well with GTK applications. This enables GNOME applications to access HTTP servers on the network in a completely asynchronous fashion, very similar to the Gtk+ programming model (a synchronous operation mode is also supported for those who want it). This is the MinGW build of Libsoup -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2025-14523 -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 17 2026 Sandro Mani - 2.74.3-16 - Backport patch for CVE-2025-14523 * Fri Jan 16 2026 Fedora Release Engineering - 2.74.3-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2421353 - CVE-2025-14523 mingw-libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2421353 [ 2 ] Bug #2421356 - CVE-2025-14523 mingw-libsoup: libsoup: Duplicate Host Header Handling Causes Host-Parsing Discrepancy (First- vs Last-Value Wins) [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2421356 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-20b533bbc7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport patch for CVE-2024-8088. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-48fd84da22 2024-09-13 20:43:08.472806 -------------------------------------------------------------------------------- Name : mingw-python3 Product : Fedora 41 Version : 3.11.9 Release : 2.fc41 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 -------------------------------------------------------------------------------- Update Information: Backport patch for CVE-2024-8088 -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 28 2024 Sandro Mani - 3.11.9-2 - Backport patch for CVE-2024-8088 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2307457 - CVE-2024-8088 mingw-python3: From NVD collector [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2307457 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-48fd84da22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fix for CVE-2023-5841.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f4d51715fe 2024-02-25 01:24:47.525747 -------------------------------------------------------------------------------- Name : mingw-openexr Product : Fedora 38 Version : 3.1.10 Release : 4.fc38 URL : https://openexr.com/en/latest/ Summary : MinGW Windows openexr library Description : MinGW Windows openexr library. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-5841. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 16 2024 Sandro Mani - 3.1.10-4 - Backport patch for CVE-2023-5841 * Thu Jan 25 2024 Fedora Release Engineering - 3.1.10-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 3.1.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Aug 4 2023 Sandro Mani - 3.1.10-1 - Update to 3.1.10 * Thu Jul 20 2023 Fedora Release Engineering - 3.1.9-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 18 2023 Sandro Mani - 3.1.9-1 - Update to 3.1.9 * Fri May 19 2023 Sandro Mani - 3.1.7-1 - Update to 3.1.7 * Mon Mar 20 2023 Sandro Mani - 3.1.6-1 - Update to 3.1.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2262407 - TRIAGE CVE-2023-5841 mingw-openexr: OpenEXR: Heap Overflow in Scanline Deep Data Parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2262407 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f4d51715fe' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Backport fix for CVE-2023-1729.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-88c87f6191 2023-05-19 01:23:33.798314 --------------------------------------------------------------------------------Name : mingw-LibRaw Product : Fedora 37 Version : 0.20.2 Release : 9.fc37 URL : https://www.libraw.org/ Summary : Library for reading RAW files obtained from digital photo cameras Description : MinGW Windows LibRaw library. --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2023-1729. --------------------------------------------------------------------------------ChangeLog: * Wed May 10 2023 Sandro Mani - 0.20.2-9 - Backport patch for CVE-2023-1729 --------------------------------------------------------------------------------References: [ 1 ] Bug #2188277 - CVE-2023-1729 mingw-LibRaw: LibRaw: a heap-buffer-overflow in raw2image_ex() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2188277 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-88c87f6191' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport fix for CVE-2023-2004.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-ddc617c87f 2023-04-22 00:53:57.594838 --------------------------------------------------------------------------------Name : mingw-freetype Product : Fedora 37 Version : 2.12.1 Release : 4.fc37 URL : https://freetype.org/ Summary : Free and portable font rendering engine Description : MinGW Windows Freetype library. --------------------------------------------------------------------------------Update Information: Backport fix for CVE-2023-2004. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 13 2023 Sandro Mani - 2.12.1-4 - Backport patch for CVE-2023-2004 * Thu Jan 19 2023 Fedora Release Engineering - 2.12.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2186437 - CVE-2023-2004 mingw-freetype: freetype: integer overflowin in tt_hvadvance_adjust() in src/truetype/ttgxvar.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2186437 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ddc617c87f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport patch for CVE-2023-24593.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-cfe20dbcab 2023-04-14 01:05:02.596157 --------------------------------------------------------------------------------Name : mingw-glib2 Product : Fedora 37 Version : 2.74.1 Release : 2.fc37 URL : https://www.gtk.org/ Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. --------------------------------------------------------------------------------Update Information: Backport patch for CVE-2023-24593. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 5 2023 Sandro Mani - 2.74.1-2 - Backport patch for CVE-2023-24593 --------------------------------------------------------------------------------References: [ 1 ] Bug #2181192 - CVE-2023-24593 mingw-glib2: glib: DoS caused by handling a malicious text-form variant [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2181192 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cfe20dbcab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport patch for CVE-2023-25587.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-dbba9e7218 2023-03-11 03:04:11.190273 --------------------------------------------------------------------------------Name : mingw-binutils Product : Fedora 38 Version : 2.39 Release : 5.fc38 URL : Summary : Cross-compiled version of binutils for Win32 and Win64 environments Description : Cross compiled binutils (utilities like 'strip', 'as', 'ld') which understand Windows executables and DLLs. --------------------------------------------------------------------------------Update Information: Backport patch for CVE-2023-25587. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 7 2023 Sandro Mani - 2.39-5 - Backport patch for CVE-2023-25587 --------------------------------------------------------------------------------References: [ 1 ] Bug #2174099 - CVE-2023-25587 mingw-binutils: binutils: NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols` [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2174099 [ 2 ] Bug #2174111 - CVE-2023-25587 mingw-binutils: binutils: NULL pointer segmentation fault when accessing field `the_bfd` in function `compare_symbols` [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2174111 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-dbba9e7218' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Backport patch for CVE-2022-45061.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3e859b6bc6 2022-11-30 01:33:59.394805 --------------------------------------------------------------------------------Name : mingw-python3 Product : Fedora 37 Version : 3.10.8 Release : 2.fc37 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 library. --------------------------------------------------------------------------------Update Information: Backport patch for CVE-2022-45061. --------------------------------------------------------------------------------ChangeLog: * Mon Nov 21 2022 Sandro Mani - 3.10.8-2 - Backport patch for CVE-2022-45061 --------------------------------------------------------------------------------References: [ 1 ] Bug #2144417 - CVE-2022-45061 mingw-python3: Python: CPU denial of service via inefficient IDNA decoder [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2144417 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3e859b6bc6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.