Update to 2.69.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f6901d5918 2026-03-07 03:20:54.895538+00:00 -------------------------------------------------------------------------------- Name : chezmoi Product : Fedora 42 Version : 2.69.4 Release : 1.fc42 URL : https://github.com/twpayne/chezmoi Summary : Manage your dotfiles across multiple diverse machines Description : Manage your dotfiles across multiple diverse machines, securely. -------------------------------------------------------------------------------- Update Information: Update to 2.69.4 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 11 2026 Packit - 2.69.4-1 - Update to 2.69.4 upstream release - Resolves: rhbz#2430279 * Mon Feb 2 2026 Maxwell G - 2.69.1-4 - Rebuild for https://fedoraproject.org/wiki/Changes/golang1.26 * Fri Jan 16 2026 Fedora Release Engineering - 2.69.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jan 16 2026 Fedora Release Engineering - 2.69.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Sat Jan 10 2026 Packit - 2.69.1-1 - Update to 2.69.1 upstream release - Resolves: rhbz#2428410 * Mon Jan 5 2026 Packit - 2.69.0-1 - Update to 2.69.0 upstream release - Resolves: rhbz#2427071 * Wed Dec 17 2025 Mikel Olasagasti Uranga - 2.68.1-1 - Update to 2.68.1 - Closes rhbz#2394285 * Fri Oct 10 2025 Maxwell G - 2.63.1-2 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398284 - CVE-2025-47910 chezmoi: CrossOriginProtection bypass in net/http [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2398284 [ 2 ] Bug #2398651 - CVE-2025-47910 chezmoi: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398651 [ 3] Bug #2399325 - CVE-2025-47906 chezmoi: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399325 [ 4 ] Bug #2403147 - CVE-2025-11579 chezmoi: RarDecode Out Of Memory Crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2403147 [ 5 ] Bug #2407853 - CVE-2025-58189 chezmoi: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407853 [ 6 ] Bug #2408630 - CVE-2025-61725 chezmoi: Excessive CPU consumption in ParseAddress in net/mail [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2408630 [ 7 ] Bug #2409320 - CVE-2025-61723 chezmoi: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409320 [ 8 ] Bug #2410272 - CVE-2025-58185 chezmoi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410272 [ 9 ] Bug #2411184 - CVE-2025-58188 chezmoi: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411184 [ 10 ] Bug #2412478 - CVE-2025-58183 chezmoi: Unbounded allocation when parsing GNU sparse map [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2412478 [ 11 ] Bug #2412748 - CVE-2025-58183 chezmoi: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412748 [ 12 ] Bug #2420578 - CVE-2025-47913 chezmoi: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2420578 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f6901d5918' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.69.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-004192d79d 2026-01-14 00:50:55.476182+00:00 -------------------------------------------------------------------------------- Name : chezmoi Product : Fedora 43 Version : 2.69.0 Release : 1.fc43 URL : https://github.com/twpayne/chezmoi Summary : Manage your dotfiles across multiple diverse machines Description : Manage your dotfiles across multiple diverse machines, securely. -------------------------------------------------------------------------------- Update Information: Update to 2.69.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 5 2026 Packit - 2.69.0-1 - Update to 2.69.0 upstream release - Resolves: rhbz#2427071 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2409601 - CVE-2025-61723 chezmoi: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409601 [ 2 ] Bug #2410552 - CVE-2025-58185 chezmoi: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410552 [ 3 ] Bug #2411450 - CVE-2025-58188 chezmoi: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411450 [ 4 ] Bug #2412669 - CVE-2025-58183 chezmoi: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412669 [ 5 ] Bug #2420608 - CVE-2025-47913 chezmoi: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2420608 -------------------------------------------------------------------------------- This update can be installed withthe "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-004192d79d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.68.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-28e625afa6 2025-12-26 00:43:51.117598+00:00 -------------------------------------------------------------------------------- Name : chezmoi Product : Fedora 43 Version : 2.68.1 Release : 1.fc43 URL : https://github.com/twpayne/chezmoi Summary : Manage your dotfiles across multiple diverse machines Description : Manage your dotfiles across multiple diverse machines, securely. -------------------------------------------------------------------------------- Update Information: Update to 2.68.1 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 17 2025 Mikel Olasagasti Uranga - 2.68.1-1 - Update to 2.68.1 - Closes rhbz#2394285 * Fri Oct 10 2025 Maxwell G - 2.63.1-2 - Rebuild for golang 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408131 - CVE-2025-58189 chezmoi: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408131 [ 2 ] Bug #2408695 - CVE-2025-61725 chezmoi: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408695 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-28e625afa6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.