Fix version ldflag for #2424534. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7da33c2d62 2026-01-04 00:48:37.722157+00:00 -------------------------------------------------------------------------------- Name : grpcurl Product : Fedora 43 Version : 1.9.3 Release : 6.fc43 URL : https://github.com/fullstorydev/grpcurl Summary : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers Description : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers. -------------------------------------------------------------------------------- Update Information: Fix version ldflag for #2424534 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 29 2025 Mikel Olasagasti Uranga - 1.9.3-6 - Fix version ldflag - Closes rhbz#2424534 * Fri Oct 10 2025 Alejandro Sez - 1.9.3-5 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408296 - CVE-2025-58189 grpcurl: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408296 [ 2 ] Bug #2408718 - CVE-2025-61725 grpcurl: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408718 [ 3 ] Bug #2409769 - CVE-2025-61723 grpcurl: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409769 [ 4 ] Bug #2410719 - CVE-2025-58185 grpcurl: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410719 [ 5 ] Bug #2411615 - CVE-2025-58188 grpcurl: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411615 [ 6 ] Bug #2424534 - -versionreturns no version https://bugzilla.redhat.com/show_bug.cgi?id=2424534 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7da33c2d62' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fix for grpcurl on Fedora 43 addresses critical security issues and improves functionality as a command-line tool.. grpcurl, Fedora, command-line tool, security fix, software update. . Severity: Important. LinuxSecurity.com Team
Update to 2.83.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c6b2100f44 2026-01-02 00:38:59.597977+00:00 -------------------------------------------------------------------------------- Name : gh Product : Fedora 43 Version : 2.83.2 Release : 1.fc43 URL : https://github.com/cli/cli Summary : GitHub's official command line tool Description : A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. -------------------------------------------------------------------------------- Update Information: Update to 2.83.2 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 10 2025 Packit - 2.83.2-1 - Update to 2.83.2 upstream release - Resolves: rhbz#2414900 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2409639 - CVE-2025-61723 gh: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409639 [ 2 ] Bug #2410590 - CVE-2025-58185 gh: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410590 [ 3 ] Bug #2411488 - CVE-2025-58188 gh: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411488 [ 4 ] Bug #2412688 - CVE-2025-58183 gh: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412688 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c6b2100f44' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.83.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6981d97f47 2025-11-14 01:25:41.063322+00:00 -------------------------------------------------------------------------------- Name : gh Product : Fedora 43 Version : 2.83.0 Release : 1.fc43 URL : https://github.com/cli/cli Summary : GitHub's official command line tool Description : A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. -------------------------------------------------------------------------------- Update Information: Update to 2.83.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 4 2025 Packit - 2.83.0-1 - Update to 2.83.0 upstream release - Resolves: rhbz#2397664 * Fri Oct 10 2025 Alejandro Sez - 2.79.0-2 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408169 - CVE-2025-58189 gh: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408169 [ 2 ] Bug #2408706 - CVE-2025-61725 gh: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408706 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6981d97f47' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key.More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 43 includes critical updates to gh for enhanced GitHub command line operations.. Fedora 43, gh, command line, security fix, update. . Severity: Critical. LinuxSecurity.com Team
Rebuild for security fixes in golang. bump to v1.42.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8f97b687c8 2025-11-07 00:54:39.974739+00:00 -------------------------------------------------------------------------------- Name : buildah Product : Fedora 43 Version : 1.42.0 Release : 4.fc43 URL : https://buildah.io Summary : A command line tool used for creating OCI Images Description : The buildah package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container's root file system for manipulation * save container's root file system layer to create a new image * delete a working container or an image -------------------------------------------------------------------------------- Update Information: Rebuild for security fixes in golang. bump to v1.42.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 3 2025 Lokesh Mandvekar - 2:1.42.0-4 - Rebuild for CVE fixes * Thu Oct 23 2025 Lokesh Mandvekar - 2:1.42.0-3 - cleanup changelog * Thu Oct 23 2025 Lokesh Mandvekar - 2:1.42.0-2 - build with sequoia on f43+ * Wed Oct 22 2025 Packit - 2:1.42.0-1 - Update to 1.42.0 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408127 - CVE-2025-58189 buildah: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408127 [ 2 ] Bug #2408694 - CVE-2025-61725 buildah: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408694 [ 3 ] Bug #2409597 - CVE-2025-61723 buildah: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409597 [ 4 ] Bug #2410548 - CVE-2025-58185 buildah: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410548 [ 5 ] Bug #2411446 - CVE-2025-58188 buildah: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411446 [ 6 ] Bug #2412667 - CVE-2025-58183 buildah: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412667 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-8f97b687c8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.79.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d4c9910925 2025-09-19 01:37:20.892456+00:00 -------------------------------------------------------------------------------- Name : gh Product : Fedora 42 Version : 2.79.0 Release : 1.fc42 URL : https://github.com/cli/cli Summary : GitHub's official command line tool Description : A command-line interface to GitHub for use in your terminal or your scripts. gh is a tool designed to enhance your workflow when working with GitHub. It provides a seamless way to interact with GitHub repositories and perform various actions right from the command line, eliminating the need to switch between your terminal and the GitHub website. -------------------------------------------------------------------------------- Update Information: Update to 2.79.0 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 9 2025 Packit - 2.79.0-1 - Update to 2.79.0 upstream release - Resolves: rhbz#2385309 * Tue Sep 9 2025 Mikel Olasagasti Uranga - 2.76.1-5 - Integrate Packit with Go Vendor Tools * Fri Aug 15 2025 Maxwell G - 2.76.1-4 - Rebuild for golang-1.25.0 * Fri Aug 15 2025 Maxwell G - 2.76.1-3 - Revert "Rebuild for golang-1.25.0" * Fri Aug 15 2025 Maxwell G - 2.76.1-2 - Rebuild for golang-1.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2390863 - gh: go-viper's mapstructure May Leak Sensitive Information in Logs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2390863 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-d4c9910925' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security update for CVE-2025-9566 Automatic update for containers-common-0.64.2-1.fc42, podman-5.6.1-1.fc42, buildah-1.41.4-1.fc42. Changelog for containers-common * Wed Sep 03 2025 Packit - 5:0.64.2-1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-19f7dd07d9 2025-09-10 00:51:50.217478+00:00 -------------------------------------------------------------------------------- Name : buildah Product : Fedora 42 Version : 1.41.4 Release : 1.fc42 URL : https://buildah.io Summary : A command line tool used for creating OCI Images Description : The buildah package provides a command line tool which can be used to * create a working container from scratch or * create a working container from an image as a starting point * mount/umount a working container's root file system for manipulation * save container's root file system layer to create a new image * delete a working container or an image -------------------------------------------------------------------------------- Update Information: Security update for CVE-2025-9566 Automatic update for containers-common-0.64.2-1.fc42, podman-5.6.1-1.fc42, buildah-1.41.4-1.fc42. Changelog for containers-common * Wed Sep 03 2025 Packit - 5:0.64.2-1 - Update to 0.64.2 upstream release Changelog for podman * Thu Sep 04 2025 Packit - 5:5.6.1-1 - Update to 5.6.1 upstream release Changelog for buildah * Thu Sep 04 2025 Packit - 2:1.41.4-1 - Update to 1.41.4 upstream release -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 4 2025 Packit - 2:1.41.4-1 - Update to 1.41.4 upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393154 - CVE-2025-9566 podman: Podman kube play command may overwrite host files [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2393154 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-19f7dd07d9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Two security issues were found in Curl, an easy-to-use client-side URL transfer library and command line tool. Additionally, the command line tool does now: . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3692-1
Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-37ae269843 2023-05-18 00:49:56.087782 --------------------------------------------------------------------------------Name : rust-tealdeer Product : Fedora 37 Version : 1.6.1 Release : 2.fc37 URL : Summary : Fetch and show tldr help pages for many CLI commands Description : Fetch and show tldr help pages for many CLI commands. Full featured offline client with caching support. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of all affected applications against the latest versions of these crates, which have addressed all linked issues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 1.6.1-2 - Rebuild for tokio, h2, and openssl crate securityupdates --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-37ae269843' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.