Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-db5621b65e 2026-05-18 01:23:32.591522+00:00 -------------------------------------------------------------------------------- Name : apptainer Product : Fedora 42 Version : 1.5.0 Release : 1.fc42 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. -------------------------------------------------------------------------------- Update Information: Update to upstream 1.5.0, fix CVE-2026-32285 and CVE-2026-34986 Update to upstream 1.5.0-rc.2 Update to upstream 1.5.0-rc.1 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Dave Dykstra - 1.5.0 - Update to upstream 1.5.0 * Tue Apr 14 2026 Dave Dykstra - 1.5.0~rc.2 - Update to upstream 1.5.0~rc.2 * Thu Mar 12 2026 Dave Dykstra - 1.5.0~rc.1 - Update to upstream 1.5.0~rc.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447072 - apptainer-1.5.0-rc.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447072 [ 2 ] Bug #2452369 - CVE-2026-32285 apptainer: github.com/buger/jsonparser: Denial of Service via malformed JSON input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452369 [ 3 ] Bug #2455644 - CVE-2026-34986 apptainer: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2455644 [ 4 ] Bug #2467573 - apptainer-1.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-db5621b65e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.