Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5c5f4f40a4 2026-06-05 04:25:00.359000+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sq Product : Fedora 44 Version : 1.3.1 Release : 12.fc44 URL : https://crates.io/crates/sequoia-sq Summary : Command-line frontends for Sequoia Description : Command-line frontends for Sequoia. -------------------------------------------------------------------------------- Update Information: Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/81210321 https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/dd2ffb50 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Fabio Valentini - 1.3.1-12 - Bump sequoia-wot dependency from 0.14 to 0.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2356514 - Package NEWS https://bugzilla.redhat.com/show_bug.cgi?id=2356514 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c5f4f40a4' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ecfadb29a1 2026-06-05 04:07:33.980011+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sq Product : Fedora 43 Version : 1.3.1 Release : 12.fc43 URL : https://crates.io/crates/sequoia-sq Summary : Command-line frontends for Sequoia Description : Command-line frontends for Sequoia. -------------------------------------------------------------------------------- Update Information: Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/81210321 https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/dd2ffb50 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Fabio Valentini - 1.3.1-12 - Bump sequoia-wot dependency from 0.14 to 0.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2356514 - Package NEWS https://bugzilla.redhat.com/show_bug.cgi?id=2356514 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ecfadb29a1' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5c5f4f40a4 2026-06-05 04:25:00.359000+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-sq Product : Fedora 44 Version : 1.3.1 Release : 12.fc44 URL : https://crates.io/crates/sequoia-sq Summary : Command-line frontends for Sequoia Description : Command-line frontends for Sequoia. -------------------------------------------------------------------------------- Update Information: Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/81210321 https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/dd2ffb50 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Fabio Valentini - 1.3.1-12 - Bump sequoia-wot dependency from 0.14 to 0.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2356514 - Package NEWS https://bugzilla.redhat.com/show_bug.cgi?id=2356514 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c5f4f40a4' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.92.0 and make telemetry sending opt in.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5df889949e 2026-05-07 00:51:26.512946+00:00 -------------------------------------------------------------------------------- Name : gh Product : Fedora 44 Version : 2.92.0 Release : 1.fc44 URL : https://github.com/cli/cli Summary : GitHub's official command line tool Description : A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. -------------------------------------------------------------------------------- Update Information: Update to 2.92.0 and make telemetry sending opt in. -------------------------------------------------------------------------------- ChangeLog: * Mon May 4 2026 Maxwell G - 2.92.0-1 - Update to 2.92.0. Fixes rhbz#2451741. * Fri Apr 24 2026 Maxwell G - 2.91.0-3 - Make telemetry sending opt in * Fri Apr 24 2026 Maxwell G - 2.91.0-1 - Update to 2.91.0. Fixes rhbz#2451741. * Thu Mar 12 2026 Packit - 2.88.1-1 - Update to 2.88.1 upstream release - Resolves: rhbz#2446304 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2458931 - CVE-2026-39984 gh: improper certificate validation in verifier [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458931 [ 2 ] Bug #2458984 - CVE-2026-5160 gh: github.com/yuin/goldmark/renderer/html: Cross-site Scripting due to improper URL validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458984 -------------------------------------------------------------------------------- This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5df889949e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
wheel could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8221-1 April 29, 2026 wheel vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: wheel could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - wheel: Command line tool for manipulating Python wheel files Details: It was discovered that wheel did not correctly handle certain file paths. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-wheel-common 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro python3-wheel-whl 0.42.0-2ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8221-1 CVE-2026-24049 . A critical issue with Ubuntu's wheel allows remote code execution from crafted files. Update immediately for security.. Ubuntu 24.04 LTS, wheel application, remote code execution, security update. . Severity: Critical. LinuxSecurity.com Team
ws: be more explicit when handling hostnames on cli [CVE-2026-4631]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-134819a61b 2026-04-28 01:11:18.587340+00:00 -------------------------------------------------------------------------------- Name : cockpit Product : Fedora 42 Version : 357 Release : 2.fc42 URL : https://cockpit-project.org/ Summary : Web Console for Linux servers Description : The Cockpit Web Console enables users to administer GNU/Linux servers using a web browser. It offers network configuration, log inspection, diagnostic reports, SELinux troubleshooting, interactive command-line sessions, and more. -------------------------------------------------------------------------------- Update Information: ws: be more explicit when handling hostnames on cli [CVE-2026-4631] -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Jelle van der Waa - 357-2 - ws: be more explicit when handling hostnames on cli (CVE-2026-4631) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-134819a61b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fixes CVE-2026-32316 Fixes CVE-2026-33947 Fixes CVE-2026-39956 Fixes CVE-2026-39979 Fixes CVE-2026-40164. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4e57162966 2026-04-22 07:48:13.355010+00:00 -------------------------------------------------------------------------------- Name : jq Product : Fedora 43 Version : 1.8.1 Release : 3.fc43 URL : https://jqlang.org/ Summary : Command-line JSON processor Description : lightweight and flexible command-line JSON processor jq is like sed for JSON data \u2013 you can use it to slice and filter and map and transform structured data with the same ease that sed, awk, grep and friends let you play with text. It is written in portable C, and it has zero runtime dependencies. jq can mangle the data format that you have into the one that you want with very little effort, and the program to do so is often shorter and simpler than you'd expect. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2026-32316 Fixes CVE-2026-33947 Fixes CVE-2026-39956 Fixes CVE-2026-39979 Fixes CVE-2026-40164 Fixes bug https://github.com/jqlang/jq/issues/3413 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 16 2026 Jonathan Wright - 1.8.1-3 - Fixes multiple CVEs * Fri Jan 16 2026 Fedora Release Engineering - 1.8.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2458029 - CVE-2026-32316 jq: jq: Denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458029 [ 2 ] Bug #2458368 - CVE-2026-40164 jq: jq: Denial of Service via crafted JSON object causing hash collisions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458368 [ 3 ] Bug #2458400 - CVE-2026-39979 jq: out-of-bounds read in jv_parse_sized() on error formatting for non-NUL-terminated buffers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458400 [ 4 ] Bug #2458401 - CVE-2026-33947 jq: unbounded Recursion in jv_setpath() / jv_getpath() / delpaths_sorted() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458401 [ 5 ] Bug #2458402 - CVE-2026-39956 jq: missing runtime type checks for _strindices lead to crash and limited memory disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458402 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4e57162966' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical update for jq in Fedora 43 resolving multiple issues, including denial-of-service risks and integer overflow errors.. Fedora jq update security command-line JSON processor. . Severity: Important. LinuxSecurity.com Team
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kde-cli-tools Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/kde-cli-tools Summary : Tools based on KDE Frameworks 5 to better interact with the system Description : Provides several KDE and Plasma specific command line tools to allow better interaction with the system. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.