Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
cleanups and fixes remove RHEL 7 compatibility add RHEL 9 compatibility and EOL comments restore RHEL 8 compatibility. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8b992398d3 2026-01-11 00:54:21.425399+00:00 -------------------------------------------------------------------------------- Name : nginx Product : Fedora 42 Version : 1.28.1 Release : 3.fc42 URL : https://nginx.org Summary : A high performance web server and reverse proxy server Description : Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and IMAP protocols, with a strong focus on high concurrency, performance and low memory usage. -------------------------------------------------------------------------------- Update Information: cleanups and fixes remove RHEL 7 compatibility add RHEL 9 compatibility and EOL comments restore RHEL 8 compatibility -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 2 2026 Felix Kaechele - 2:1.28.1-3 - cleanups and fixes - remove RHEL 7 compatibility - add RHEL 9 compatibility and EOL comments - restore RHEL 8 compatibility * Sat Dec 27 2025 Aleksei Bavshin - 2:1.28.1-2 - Fix crash in stream SSL configuration (rhbz#2421955) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8b992398d3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announcemailing list --
Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ff98facbc6 2024-10-19 01:18:49.824560 -------------------------------------------------------------------------------- Name : rust-rustls-native-certs Product : Fedora 39 Version : 0.8.0 Release : 1.fc39 URL : https://crates.io/crates/rustls-native-certs Summary : Allows rustls to use the platform native certificate store Description : Rustls-native-certs allows rustls to use the platform native certificate store. -------------------------------------------------------------------------------- Update Information: Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 8 2024 Fabio Valentini - 0.8.0-1 - Update to version 0.8.0; Fixes RHBZ#2306094 * Sat Jul 20 2024 Fedora Release Engineering - 0.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `
Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Drop i686 support in rust-libcramjam and python-cramjam.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2096f5d14c 2024-10-12 00:17:42.525118 -------------------------------------------------------------------------------- Name : rust-nu-protocol Product : Fedora 41 Version : 0.96.1 Release : 3.fc41 URL : Summary : Nushell's internal protocols, including its abstract syntax tree Description : Nushell's internal protocols, including its abstract syntax tree. -------------------------------------------------------------------------------- Update Information: Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Drop i686 support in rust-libcramjam and python-cramjam. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 2 2024 Benjamin A. Beasley - 0.96.1-3 - Update rust-brotli to 7.0 * Mon Sep 30 2024 Benjamin A. Beasley - 0.96.1-2 - Update brotli from 5.0 to 6.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2272914 - rust-brotli-6.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2272914 [ 2 ] Bug #2272915 - rust-brotli-decompressor-4.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2272915 [ 3 ] Bug #2273733 - rust-async-compression-0.4.12 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273733 [ 4 ] Bug #2316061 - rust-brotli-7.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2316061 [ 5 ] Bug #2316120 - rust-async-compression-0.4.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2316120 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2096f5d14c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
ClamAV was updated to remain compatible with signature database downloads.. ========================================================================== Ubuntu Security Notice USN-6568-1 January 08, 2024 clamav update ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: ClamAV was updated to remain compatible with signature database downloads. Software Description: - clamav: Anti-virus utility for Unix Details: The ClamAV package was updated to a new upstream version to remain compatible with signature database downloads. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: clamav 1.0.4+dfsg-0ubuntu0.23.10.1 Ubuntu 23.04: clamav 0.103.11+dfsg-0ubuntu0.23.04.1 Ubuntu 22.04 LTS: clamav 0.103.11+dfsg-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: clamav 0.103.11+dfsg-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6568-1 https://bugs.launchpad.net/ubuntu/+source/clamav/+bug/2046581 Package Information: https://launchpad.net/ubuntu/+source/clamav/1.0.4+dfsg-0ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/clamav/0.103.11+dfsg-0ubuntu0.20.04.1 . ClamAV was updated for compatibility with signature database downloads affecting multiple Ubuntu versions.. ClamAV Update, Ubuntu Security, Signature Database Compatibility. . LinuxSecurity.com Team
Update to 2.53.12 For compatibility with modern sites the default version of Firefox for the User-Agent string has now been set to 78.0 . The value can be changed in Preferences--> Advanced--> HTTP Networking . Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro-independed build available at https://buc.fedorapeople.org/seamonkey/ . So. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7c0f2c2d67 2022-05-09 01:35:33.152653 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 35 Version : 2.53.12 Release : 1.fc35 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.12 For compatibility with modern sites the default version of Firefox for the User-Agent string has now been set to 78.0 . The value can be changed in Preferences--> Advanced--> HTTP Networking . Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro-independed build available at https://buc.fedorapeople.org/seamonkey/ . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them. --------------------------------------------------------------------------------ChangeLog: * Tue May 3 2022 Dmitry Butskoy 2.53.12-1 - update to2.53.12 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7c0f2c2d67' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences--> Advanced--> HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-609c83fc75 2022-03-26 14:56:28.650081 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 36 Version : 2.53.11 Release : 1.fc36 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences--> Advanced--> HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in the application dir is now additionally used for a list of overrides. You can copy it into your profile and edit if needed (be careful with format.) The "general.useragent.override.*" way continues to work and takes precedence. The new mechanism can be toggled by "general.useragent.updates.enabled" prefs(in about:config). --------------------------------------------------------------------------------ChangeLog: * Wed Feb 23 2022 Dmitry Butskoy 2.53.11-1 - update to 2.53.11 - use ua-update.json mechanism for site-specific user-agent overrides - fix some minor issues --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-609c83fc75' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to 2.53.10.1 Backport fixes to improve compatibility of some sites. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8808996450 2021-12-26 01:23:55.864059 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 35 Version : 2.53.10.1 Release : 1.fc35 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.10.1 Backport fixes to improve compatibility of some sites --------------------------------------------------------------------------------ChangeLog: * Wed Dec 15 2021 Dmitry Butskoy 2.53.10.1-1 - update to 2.53.10.1 - backport new regexp stuff (derived from Waterfox-Classic) - backport fixes for mozbz 1434478, 1449641, 1460295 - fix possible postMessage race conditions --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8808996450' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Update the tiny_http crate to version 0.8.2. - Introduce a compat package for tiny_http versions 0.6.x. Both versions contain a fix for RUSTSEC-2020-0031 / CVE-2020-35884, and the only dependent application (drg) has been rebuilt against the version containing the fix.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-571e3ed33c 2021-12-13 01:03:28.685557 --------------------------------------------------------------------------------Name : rust-tiny_http Product : Fedora 35 Version : 0.8.2 Release : 1.fc35 URL : Summary : Low level HTTP server library Description : Low level HTTP server library. --------------------------------------------------------------------------------Update Information: - Update the tiny_http crate to version 0.8.2. - Introduce a compat package for tiny_http versions 0.6.x. Both versions contain a fix for RUSTSEC-2020-0031 / CVE-2020-35884, and the only dependent application (drg) has been rebuilt against the version containing the fix. --------------------------------------------------------------------------------ChangeLog: * Sat Dec 4 2021 Fabio Valentini 0.8.2-1 - Update to version 0.8.2 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-571e3ed33c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.