Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
89

Fedora 43 nginx-mod-brotli Critical CVE-2026-1642 Man-in-the-Middle

nginx-mod-naxsi: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-fancyindex:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cd0705c6a7 2026-02-15 01:10:21.966685+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-brotli Product : Fedora 43 Version : 1.0.0~rc Release : 6.fc43 URL : https://github.com/google/ngx_brotli Summary : NGINX module for Brotli compression Description : NGINX module for Brotli compression. -------------------------------------------------------------------------------- Update Information: nginx-mod-naxsi: Rebuild for 1.28.2 nginx-mod-brotli: Rebuild for 1.28.2 nginx-mod-fancyindex: Rebuild for 1.28.2 nginx-mod-modsecurity: Rebuild for 1.28.2 nginx-mod-headers-more: Rebuild for 1.28.2 nginx-mod-vts: Rebuild for 1.28.2 nginx: Update to 1.28.2 fixes CVE-2026-1642 move log directory to nginx-filesystem subpackage (PR#20) delete Maxim Dounin's key, it's no longer listed on the nginx website -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 4 2026 Felix Kaechele - 1.0.0~rc-6 - Rebuild for 1.28.2 * Fri Jan 16 2026 Fedora Release Engineering - 1.0.0~rc-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2436871 - CVE-2026-1642 nginx: NGINX: Data injection via man-in-the-middle attack on TLS proxied connections [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2436871 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cd0705c6a7' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . NGINX module for Brotli compression update addressing CVE-2026-1642 in Fedora 43. Install with dnf upgrade command.. Fedora Security NGINX Brotli Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 15, 2026 Critical Fedora
217

Oracle Linux 8 Brotli Important DoS Threat Advisory ELSA-2026-2389

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2389 http://linux.oracle.com/errata/ELSA-2026-2389.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.0.6-4.el8_10.i686.rpm brotli-1.0.6-4.el8_10.x86_64.rpm brotli-devel-1.0.6-4.el8_10.i686.rpm brotli-devel-1.0.6-4.el8_10.x86_64.rpm python3-brotli-1.0.6-4.el8_10.x86_64.rpm aarch64: brotli-1.0.6-4.el8_10.aarch64.rpm brotli-devel-1.0.6-4.el8_10.aarch64.rpm python3-brotli-1.0.6-4.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/brotli-1.0.6-4.el8_10.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.0.6-4] - Resolves: RHEL-133986 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 brotli update addresses a critical DoS threat with advisory ELSA-2026-2389 and resolves CVE-2025-6176.. Oracle Linux 8,brotli,security advisory,DoS,update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 11, 2026 Important Oracle
219

Rocky Linux 9 Brotli Denial of Service Vulnerability Fix RLSA-2026-2042

Important: brotli security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2042", "synopsis": "Important: brotli security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for brotli.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. \n\nSecurity Fix(es):\n\n* Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2408762", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", "description": ""}], "cves": [{"name": "CVE-2025-6176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-6176", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2026-02-07T09:06:42.672591Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3-brotli-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-0:1.0.9-9.el9_7.i686.rpm", "brotli-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-0:1.0.9-9.el9_7.s390x.rpm", "brotli-0:1.0.9-9.el9_7.src.rpm", "brotli-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.i686.rpm","brotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "brotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.i686.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.s390x.rpm", "brotli-debugsource-0:1.0.9-9.el9_7.x86_64.rpm", "brotli-devel-0:1.0.9-9.el9_7.aarch64.rpm", "brotli-devel-0:1.0.9-9.el9_7.i686.rpm", "brotli-devel-0:1.0.9-9.el9_7.ppc64le.rpm", "brotli-devel-0:1.0.9-9.el9_7.s390x.rpm", "brotli-devel-0:1.0.9-9.el9_7.x86_64.rpm", "libbrotli-0:1.0.9-9.el9_7.aarch64.rpm", "libbrotli-0:1.0.9-9.el9_7.i686.rpm", "libbrotli-0:1.0.9-9.el9_7.ppc64le.rpm", "libbrotli-0:1.0.9-9.el9_7.s390x.rpm", "libbrotli-0:1.0.9-9.el9_7.x86_64.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.i686.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "libbrotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm", "python3-brotli-0:1.0.9-9.el9_7.ppc64le.rpm", "python3-brotli-0:1.0.9-9.el9_7.s390x.rpm", "python3-brotli-0:1.0.9-9.el9_7.x86_64.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.aarch64.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.ppc64le.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.s390x.rpm", "python3-brotli-debuginfo-0:1.0.9-9.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Brotli security update for Rocky Linux addresses a DoS threat. Updates are critical for maintaining system integrity.. Brotli security update, Rocky Linux DoS threat, Important security fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 07, 2026 Important Rocky Linux
217

Oracle Linux 9 ELSA-2026-2042 Brotli Important DoS CVE-2025-6176

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2042 http://linux.oracle.com/errata/ELSA-2026-2042.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.0.9-9.el9_7.i686.rpm brotli-1.0.9-9.el9_7.x86_64.rpm brotli-devel-1.0.9-9.el9_7.i686.rpm brotli-devel-1.0.9-9.el9_7.x86_64.rpm libbrotli-1.0.9-9.el9_7.i686.rpm libbrotli-1.0.9-9.el9_7.x86_64.rpm python3-brotli-1.0.9-9.el9_7.x86_64.rpm aarch64: brotli-1.0.9-9.el9_7.aarch64.rpm brotli-devel-1.0.9-9.el9_7.aarch64.rpm libbrotli-1.0.9-9.el9_7.aarch64.rpm python3-brotli-1.0.9-9.el9_7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/brotli-1.0.9-9.el9_7.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.0.9-9] - Resolves: RHEL-133995 Rebuild for CVE-2025-6176 Brotli decompression bomb DoS in scrapy [1.0.9-8] - Resolves: RHEL-133995 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates for Brotli software address an important DoS vulnerability, ELSA-2026-2042, with related CVE-2025-6176.. Oracle Linux updates, Brotli security, DoS vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 05, 2026 Important Oracle
219

Rocky Linux 10 Brotli Major Denial of Service Vulnerability RLSA-2026-0845

Important: brotli security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:0845", "synopsis": "Important: brotli security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for brotli.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. \n\nSecurity Fix(es):\n\n* Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS (CVE-2025-6176)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2408762", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2408762", "description": ""}], "cves": [{"name": "CVE-2025-6176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-6176", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2026-01-21T09:06:31.007549Z", "rpms": {"Rocky Linux 10": {"nvras": ["libbrotli-debuginfo-0:1.1.0-7.el10_1.ppc64le.rpm", "brotli-0:1.1.0-7.el10_1.s390x.rpm", "python3-brotli-debuginfo-0:1.1.0-7.el10_1.aarch64.rpm", "python3-brotli-0:1.1.0-7.el10_1.ppc64le.rpm", "libbrotli-0:1.1.0-7.el10_1.ppc64le.rpm", "brotli-debuginfo-0:1.1.0-7.el10_1.aarch64.rpm", "python3-brotli-debuginfo-0:1.1.0-7.el10_1.ppc64le.rpm", "brotli-debugsource-0:1.1.0-7.el10_1.s390x.rpm","libbrotli-debuginfo-0:1.1.0-7.el10_1.s390x.rpm", "brotli-debugsource-0:1.1.0-7.el10_1.aarch64.rpm", "python3-brotli-0:1.1.0-7.el10_1.s390x.rpm", "brotli-devel-0:1.1.0-7.el10_1.x86_64.rpm", "libbrotli-0:1.1.0-7.el10_1.aarch64.rpm", "python3-brotli-debuginfo-0:1.1.0-7.el10_1.s390x.rpm", "brotli-0:1.1.0-7.el10_1.x86_64.rpm", "python3-brotli-debuginfo-0:1.1.0-7.el10_1.x86_64.rpm", "python3-brotli-0:1.1.0-7.el10_1.x86_64.rpm", "python3-brotli-0:1.1.0-7.el10_1.aarch64.rpm", "brotli-debuginfo-0:1.1.0-7.el10_1.x86_64.rpm", "brotli-debuginfo-0:1.1.0-7.el10_1.ppc64le.rpm", "brotli-0:1.1.0-7.el10_1.src.rpm", "brotli-devel-0:1.1.0-7.el10_1.s390x.rpm", "libbrotli-debuginfo-0:1.1.0-7.el10_1.x86_64.rpm", "brotli-debugsource-0:1.1.0-7.el10_1.x86_64.rpm", "brotli-debuginfo-0:1.1.0-7.el10_1.s390x.rpm", "brotli-debugsource-0:1.1.0-7.el10_1.ppc64le.rpm", "libbrotli-debuginfo-0:1.1.0-7.el10_1.aarch64.rpm", "brotli-0:1.1.0-7.el10_1.ppc64le.rpm", "libbrotli-0:1.1.0-7.el10_1.s390x.rpm", "brotli-devel-0:1.1.0-7.el10_1.aarch64.rpm", "brotli-0:1.1.0-7.el10_1.aarch64.rpm", "libbrotli-0:1.1.0-7.el10_1.x86_64.rpm", "brotli-devel-0:1.1.0-7.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the important brotli security update for Rocky Linux 10, detailing its impact and necessary fixes in response to CVE-2025-6176.. rocky linux brotli security update, security patch brotli, CVE-2025-6176. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 21, 2026 Important Rocky Linux
217

Oracle Linux 10: Brotli Important DoS Fix ELSA-2026-0845 CVE-2025-6176

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-0845 http://linux.oracle.com/errata/ELSA-2026-0845.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: brotli-1.1.0-7.el10_1.x86_64.rpm brotli-devel-1.1.0-7.el10_1.x86_64.rpm libbrotli-1.1.0-7.el10_1.x86_64.rpm python3-brotli-1.1.0-7.el10_1.x86_64.rpm aarch64: brotli-1.1.0-7.el10_1.aarch64.rpm brotli-devel-1.1.0-7.el10_1.aarch64.rpm libbrotli-1.1.0-7.el10_1.aarch64.rpm python3-brotli-1.1.0-7.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/brotli-1.1.0-7.el10_1.src.rpm Related CVEs: CVE-2025-6176 Description of changes: [1.1.0-7] - Resolves: RHEL-133984 CVE-2025-6176 Brotli decompression bomb DoS in scrapy _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated rpms for Oracle Linux 10 with Important advisory addressing Brotli decompression bomb DoS vulnerability.. Oracle Linux,brotli,security advisory,denial of service,security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 21, 2026 Important Oracle
89

Fedora 42: brotli 1.2.0 Critical DoS Fix FEDORA-2025-9e233a4e22

Update brotli to 1.2.0. This update provides the necessary Python APIs in python3-brotli to fix denial- of-service security issues related to \u201cdecompression bombs,\u201d such as CVE-2025-66471 or CVE-2025-6176, but actually fixing them would require separate updates in affected packages.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9e233a4e22 2025-12-18 01:10:20.380939+00:00 -------------------------------------------------------------------------------- Name : brotli Product : Fedora 42 Version : 1.2.0 Release : 1.fc42 URL : https://github.com/google/brotli Summary : Lossless compression algorithm Description : Brotli is a generic-purpose lossless compression algorithm that compresses data using a combination of a modern variant of the LZ77 algorithm, Huffman coding and 2nd order context modeling, with a compression ratio comparable to the best currently available general-purpose compression methods. It is similar in speed with deflate but offers more dense compression. -------------------------------------------------------------------------------- Update Information: Update brotli to 1.2.0. This update provides the necessary Python APIs in python3-brotli to fix denial- of-service security issues related to \u201cdecompression bombs,\u201d such as CVE-2025-66471 or CVE-2025-6176, but actually fixing them would require separate updates in affected packages. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 8 2025 Benjamin A. Beasley - 1.2.0-1 - Update to 1.2.0 (close RHBZ#2401888) - Stop trying to support EPEL7, which is end-of-life - Port to pyproject-rpm-macros (close RHBZ#2377212) - Test the Python extension * Fri Sep 19 2025 Python Maint - 1.1.0-10 - Rebuilt for Python 3.14.0rc3 bytecode * Fri Aug 15 2025 Python Maint - 1.1.0-9 - Rebuilt for Python 3.14.0rc2 bytecode * Wed Jul 23 2025 Fedora Release Engineering - 1.1.0-8 - Rebuiltfor https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jun 2 2025 Python Maint - 1.1.0-7 - Rebuilt for Python 3.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419491 - CVE-2025-6176 brotli: Brotli decompression bomb DoS in scrapy/scrapy [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419491 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9e233a4e22' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . The update to brotli version 1.2.0 mitigates denial-of-service vulnerabilities and improves the Python API for better performance and security. brotli update, Fedora 42, denial of service, Python security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 18, 2025 Critical Fedora
89

Fedora 43: perl-Alien-Brotli Critical Security DoS Fix 2025-d93200cf16

Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d93200cf16 2025-12-12 01:32:22.209029+00:00 -------------------------------------------------------------------------------- Name : perl-Alien-Brotli Product : Fedora 43 Version : 0.2.2 Release : 11.fc43 URL : http://metacpan.org/dist/Alien-Brotli Summary : Find and install the Brotli compressor Description : This distribution installs the brotli compressor, so that it can be used by other distributions, and provides a way to find the executable. -------------------------------------------------------------------------------- Update Information: Update brotli to 1.2.0 and python-urllib3 to 2.6.1. In python-urllib3: Fixed a security issue where streaming API could improperly handle highly compressed HTTP content ("decompression bombs") leading to excessive resource consumption even when a small amount of data was requested. Reading small chunks of compressed data is safer and much more efficient now. (CVE-2025-66471 / `GHSA-2xpw-w6gg-jr37) Fixed a security issue where an attacker could compose an HTTP response with virtually unlimited links in the Content-Encoding header, potentially leading to a denial of service (DoS) attack by exhausting system resources during decoding. The number of allowed chained encodings is now limited to 5. (CVE-2025-66418 / `GHSA-gm62-xv2j-4w53) -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 10 2025 Miro Hron\u010dok - 0.2.2-11 - Rebuilt for brotli 1.2.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug#2419408 - python-urllib3-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2419408 [ 2 ] Bug #2419493 - CVE-2025-6176 brotli: Brotli decompression bomb DoS in scrapy/scrapy [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419493 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d93200cf16' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 addresses critical issues in Brotli and python-urllib3, including decompression bombs and DoS risks.. Fedora updates, python-urllib3 security, Brotli compression, critical security issues, DoS prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 12, 2025 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200