Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b25dca4806 2026-07-06 14:53:30.168848+00:00 -------------------------------------------------------------------------------- Name : rust-gtk4-macros Product : Fedora 44 Version : 0.11.4 Release : 2.fc44 URL : https://crates.io/crates/gtk4-macros Summary : Macros helpers for GTK 4 bindings Description : Macros helpers for GTK 4 bindings. -------------------------------------------------------------------------------- Update Information: Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa v0.15.3 ebranch base-distro guard — resolve/file-requests now know EPEL must not replace RHEL/CentOS Stream packages: deps present in the base at a too-old version are blocked with clear options (alternate package via --override, or lower the requirement) instead of becoming CANTFIX branch requests; file-requests re-checks the base before filing New sandogasa-sourcehut crate — sr.ht GraphQL client; sandogasa-report gains a Sourcehut section (patches, tickets, commits split yours vs third-party, git_emails attribution) ebranch check-crate — human report on stderr alongside --koji/--copr machine output, so build scripts stay pipeable dbranch rebuild — creates debian/gbp.conf when the Debian branch has none and handles the modern single-line salsa-ci.yml Robustness: 120s HTTP timeout on every client; --version on every tool; quick-xml bumped to 0.41 for RUSTSEC-2026-0194/-0195 sandogasa-report: consistent commit detail levels across forges Fulldetails: https://github.com/slopfest/sandogasa/blob/v0.15.3/CHANGELOG.md#v0153 v0.15.2 New sandogasa-review crate — shared keep/explain/remove resolution for reviewer-curated findings; adopted by fedora-review-digest, ebranch check-update, and fedora-cve-triage New sandogasa-forgejo crate — Forgejo/Gitea REST API client (PR activity issue filing); powers sandogasa-report's Forgejo accounting ebranch check-update overhaul — condensed output (counts + version grouping), reviewer curation of blocking findings before karma, branch inference for Fedora side tags (EPEL still needs -b al9 -r @epel), plus fixes for stale-side-tag and rich-dep installability false positives and large-update performance fedora-cve-triage — per-bug keep/explain/remove review before closing detected false positives sandogasa-report — Forgejo PR-merge and issue accounting Full details: https://github.com/slopfest/sandogasa/blob/v0.15.2/CHANGELOG.md#v0152 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Michel Lind - 0.11.4-2 - Allow building against quick-xml 0.41 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494601 - rust-quick-xml-0.41.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2494601 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b25dca4806' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Stay updated on the latest Fedora security advisory regarding rust-gtk4-macros andquick-xml fixes.. Fedora Updates,rust-gtk4-macros,quick-xml,security advisory,dependency management. . Severity: Critical. LinuxSecurity.com Team
Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b25dca4806 2026-07-06 14:53:30.168848+00:00 -------------------------------------------------------------------------------- Name : mir Product : Fedora 44 Version : 2.26.0 Release : 2.fc44 URL : https://canonical.com/mir Summary : Next generation Wayland display server toolkit Description : Mir is a Wayland display server toolkit for Linux systems, with a focus on efficiency, robust operation, and a well-defined driver model. -------------------------------------------------------------------------------- Update Information: Update quick-xml for two security advisories, rebuild dependents, and update sandogasa to the latest https://rustsec.org/advisories/RUSTSEC-2026-0194.html https://rustsec.org/advisories/RUSTSEC-2026-0195.html sandogasa v0.15.3 ebranch base-distro guard — resolve/file-requests now know EPEL must not replace RHEL/CentOS Stream packages: deps present in the base at a too-old version are blocked with clear options (alternate package via --override, or lower the requirement) instead of becoming CANTFIX branch requests; file-requests re-checks the base before filing New sandogasa-sourcehut crate — sr.ht GraphQL client; sandogasa-report gains a Sourcehut section (patches, tickets, commits split yours vs third-party, git_emails attribution) ebranch check-crate — human report on stderr alongside --koji/--copr machine output, so build scripts stay pipeable dbranch rebuild — creates debian/gbp.conf when the Debian branch has none and handles the modern single-line salsa-ci.yml Robustness: 120s HTTP timeout on every client; --version on every tool; quick-xml bumped to 0.41 forRUSTSEC-2026-0194/-0195 sandogasa-report: consistent commit detail levels across forges Full details: https://github.com/slopfest/sandogasa/blob/v0.15.3/CHANGELOG.md#v0153 v0.15.2 New sandogasa-review crate — shared keep/explain/remove resolution for reviewer-curated findings; adopted by fedora-review-digest, ebranch check-update, and fedora-cve-triage New sandogasa-forgejo crate — Forgejo/Gitea REST API client (PR activity issue filing); powers sandogasa-report's Forgejo accounting ebranch check-update overhaul — condensed output (counts + version grouping), reviewer curation of blocking findings before karma, branch inference for Fedora side tags (EPEL still needs -b al9 -r @epel), plus fixes for stale-side-tag and rich-dep installability false positives and large-update performance fedora-cve-triage — per-bug keep/explain/remove review before closing detected false positives sandogasa-report — Forgejo PR-merge and issue accounting Full details: https://github.com/slopfest/sandogasa/blob/v0.15.2/CHANGELOG.md#v0152 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Michel Lind - 2.26.0-2 - Rebuild for rust-quick-xml 0.41.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494601 - rust-quick-xml-0.41.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2494601 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b25dca4806' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 security advisory updating quick-xml and sandogasa for vulnerabilities reported on RustSec.. Fedora Security Advisory, quick-xml Update, sandogasa Dependency, Linux Applications, Security Vulnerabilities. . Severity: Important. LinuxSecurity.com Team
New upstream release varnish-8.0.2, a security release. Includes fix for VSV00019. Dependent packages are included in this update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2148c0e80b 2026-06-13 01:09:32.029605+00:00 -------------------------------------------------------------------------------- Name : collectd Product : Fedora 44 Version : 5.12.0 Release : 64.fc44 URL : https://collectd.org/ Summary : Statistics collection daemon for filling RRD files Description : collectd is a daemon which collects system performance statistics periodically and provides mechanisms to store the values in a variety of ways, for example in RRD files. -------------------------------------------------------------------------------- Update Information: New upstream release varnish-8.0.2, a security release. Includes fix for VSV00019. Dependent packages are included in this update. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 1 2026 Kevin Fenzi - 5.12.0-64 - Rebuild for varnish-8.0.2-1 * Thu Feb 26 2026 Remi Collet - 5.12.0-63 - disable write_mongodb FTBFS #2440914 - disable mqtt FTBFS #2440548 * Mon Feb 2 2026 Jonathan Wright - 5.12.0-62 - More (final) spec file updates for EPEL10 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2148c0e80b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update vendor dependencies to fix: * CVE-2026-33762 * CVE-2026-33817 * CVE-2026-34165. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cf660bc96a 2026-05-06 16:45:18.195717+00:00 -------------------------------------------------------------------------------- Name : forgejo-runner Product : Fedora 43 Version : 12.7.3 Release : 2.fc43 URL : https://code.forgejo.org/forgejo/runner Summary : A daemon that fetches workflows to run from a Forgejo instance. Description : The Forgejo Runner is a daemon that fetches workflows to run from a Forgejo instance, executes them, sends back with the logs and ultimately reports its success or failure. -------------------------------------------------------------------------------- Update Information: Update vendor dependencies to fix: * CVE-2026-33762 * CVE-2026-33817 * CVE-2026-34165 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 23 2026 Diego Herrera - 12.7.3-2 - Backport dependency updates * Tue Apr 21 2026 Diego Herrera - 12.7.3-1 - Update to 12.7.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454559 - CVE-2026-34165 forgejo-runner: go-git: Denial of Service via crafted .idx file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454559 [ 2 ] Bug #2454560 - CVE-2026-33762 forgejo-runner: go-git: Denial of Service via crafted Git index file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454560 [ 3 ] Bug #2456022 - CVE-2026-33817 forgejo-runner: go.etcd.io/bbolt: Denial of Service via index out-of-range error [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456022 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2026-cf660bc96a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-13643 http://linux.oracle.com/errata/ELSA-2026-13643.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: osbuild-composer-149-6.0.1.el10_1.x86_64.rpm osbuild-composer-core-149-6.0.1.el10_1.x86_64.rpm osbuild-composer-worker-149-6.0.1.el10_1.x86_64.rpm aarch64: osbuild-composer-149-6.0.1.el10_1.aarch64.rpm osbuild-composer-core-149-6.0.1.el10_1.aarch64.rpm osbuild-composer-worker-149-6.0.1.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/osbuild-composer-149-6.0.1.el10_1.src.rpm Related CVEs: CVE-2026-25679 Description of changes: [149-6.0.1] - Add missing dependency over dracut-config-rescue for image-installer [Orabug: 38587453] - Add OL10 support - Update repository URLs for baseos, appstream and UERK - Fix the label for UEKR repository - Simplify repository names [JIRA: OLDIS-35893] - Ensure build on latest golang: CVE-2024-34156 - Refactor patches to fix some naming and set a correct kernel for Oracle Linux [Orabug: 37253643] - Support using OCI variables inside built images [JIRA: OLDIS-35302] - Support using repository definitons with OCI variables [JIRA: OLDIS-38657] - Update repositories to contain OCI variables - Remove image types Minimal-raw and wsl [JIRA: OLDIS-38123] - Increase default /boot size to 1GB [Orabug: 36827079] - Add support for OCI hybrid images [JIRA: OLDIS-33593] - enable aarch64 OCI image builds [JIRA: OLDIS-33593] - support for building OL8/9 images on Oracle Linux 9 [Orabug: 36400619] [149-6] - Rebuilt to fix: - CVE-2026-25679 - CVE-2026-27137 - RHEL-158464 - RHEL-158602 _______________________________________________ El-errata mailing list
An update that solves one vulnerability can now be installed.. # Security update for cockpit-machines Announcement ID: SUSE-SU-2026:0396-1 Release Date: 2026-02-06T08:02:20Z Rating: important References: * bsc#1257325 Cross-References: * CVE-2025-13465 CVSS scores: * CVE-2025-13465 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-13465 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-13465 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for cockpit-machines fixes the following issues: * CVE-2025-13465: Update the lodash dependencie to avoid prototype pollution. (bsc#1257324) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-396=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-396=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (noarch) * cockpit-machines-249.1-150300.5.3.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * cockpit-machines-249.1-150300.5.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13465.html * https://bugzilla.suse.com/show_bug.cgi?id=1257325 . Stay informed with this important security update for cockpit-machines addressing critical dependency issues.. SUSE Cockpit Machines Security Update Dependency CVE-2025-13465. . Severity: Important. LinuxSecurity.com Team
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c53905e83d 2025-06-14 01:51:14.531329+00:00 -------------------------------------------------------------------------------- Name : rust-sevctl Product : Fedora 41 Version : 0.6.2 Release : 3.fc41 URL : https://crates.io/crates/sevctl Summary : Administrative utility for AMD SEV Description : Administrative utility for AMD SEV. -------------------------------------------------------------------------------- Update Information: This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Wed May 28 2025 Sergio Lopez - 0.6.2-3 - Regenerate with rust2rpm * Wed May 28 2025 Sergio Lopez - 0.6.2-2 - Replace supported-arches with ExclusiveArch * Wed May 28 2025 Sergio Lopez - 0.6.2-1 - Update to version 0.6.2 and switch to rust2rpm -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c53905e83d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c53905e83d 2025-06-14 01:51:14.531329+00:00 -------------------------------------------------------------------------------- Name : rust-sev Product : Fedora 41 Version : 6.1.0 Release : 2.fc41 URL : https://crates.io/crates/sev Summary : Library for AMD SEV Description : Library for AMD SEV. -------------------------------------------------------------------------------- Update Information: This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Wed May 28 2025 Sergio Lopez - 6.1.0-2 - Drop vendored feature from openssl dep * Wed May 28 2025 Sergio Lopez - 6.1.0-1 - Update to version 6.1.0 * Sun Jan 19 2025 Fedora Release Engineering - 4.0.0-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c53905e83d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.