Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
update to latest upstream release to fix CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-34cca3d390 2026-07-04 01:06:18.979284+00:00 -------------------------------------------------------------------------------- Name : pdns-recursor Product : Fedora 43 Version : 5.2.11 Release : 1.fc43 URL : https://powerdns.com Summary : Modern, advanced and high performance recursing/non authoritative name server Description : PowerDNS Recursor is a non authoritative/recursing DNS server. Use this package if you need a dns cache for your network. -------------------------------------------------------------------------------- Update Information: update to latest upstream release to fix CVEs -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 25 2026 Filipe Rosset - 5.2.11-1 - update to 5.2.11 fixes rhbz#2492868 - a bunch of other bugs were fixed and will be backported to all supported Fedora / EPEL versions -------------------------------------------------------------------------------- References: [ 1 ] Bug #2438157 - CVE-2025-59023 pdns-recursor: crafted delegations or IP fragments can poison cached delegations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438157 [ 2 ] Bug #2438176 - CVE-2025-59024 pdns-recursor: crafted delegations or IP fragments can poison cached delegations [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438176 [ 3 ] Bug #2438180 - CVE-2026-0398 pdns-recursor: crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2438180 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-34cca3d390' at the command line. Formore information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Erlang ver. 26.2.5.19. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-dd4a7e240e 2026-04-16 01:08:38.333416+00:00 -------------------------------------------------------------------------------- Name : erlang Product : Fedora 42 Version : 26.2.5.19 Release : 1.fc42 URL : https://www.erlang.org Summary : General-purpose programming language and runtime environment Description : Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. -------------------------------------------------------------------------------- Update Information: Erlang ver. 26.2.5.19 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 7 2026 Peter Lemenkov - 26.2.5.19-1 - Ver. 26.2.5.19 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2456135 - CVE-2026-28810 erlang: Erlang/OTP kernel: DNS cache poisoning via predictable DNS transaction IDs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456135 [ 2 ] Bug #2456139 - CVE-2026-28808 erlang: Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456139 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dd4a7e240e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Erlang ver. 26.2.5.19. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-53a7ddccc8 2026-04-16 00:53:32.960248+00:00 -------------------------------------------------------------------------------- Name : erlang Product : Fedora 43 Version : 26.2.5.19 Release : 1.fc43 URL : https://www.erlang.org Summary : General-purpose programming language and runtime environment Description : Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. -------------------------------------------------------------------------------- Update Information: Erlang ver. 26.2.5.19 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 7 2026 Peter Lemenkov - 26.2.5.19-1 - Ver. 26.2.5.19 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2456135 - CVE-2026-28810 erlang: Erlang/OTP kernel: DNS cache poisoning via predictable DNS transaction IDs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456135 [ 2 ] Bug #2456139 - CVE-2026-28808 erlang: Erlang OTP inets modules: Unauthenticated access to protected CGI scripts via incorrect authorization [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456139 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-53a7ddccc8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in Bouncy Castle.. ========================================================================== Ubuntu Security Notice USN-8108-1 March 18, 2026 bouncycastle vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Bouncy Castle. Software Description: - bouncycastle: Java implementation of cryptographic algorithms Details: It was discovered that Bouncy Castle did not sanitize user input when inserting it into an LDAP search filter. An attacker could possibly use this issue to perform an LDAP injection attack. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2023-33201) It was discovered that Bouncy Castle incorrectly handled specially crafted F2m parameters in the ECCurve algorithm. An attacker could possibly use this issue to cause Bouncy Castle to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-29857) It was discovered that Bouncy Castle leaked timing information when handling exceptions during an RSA handshake. An attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-30171) It was discovered that Bouncy Castle incorrectly handled endpoint identification with an SSL socket enabled without an explicit hostname. An attacker could possibly use this issue to perform a DNS poisoning attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-34447) Bing Shi discovered that Bouncy Castle incorrectly handled resource memory allocation. An attacker could possibly use this issue to causeBouncy Castle to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2025-8916) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libbcjmail-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcmail-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpg-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpkix-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcprov-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbctls-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcutil-java 1.77-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libbcmail-java 1.68-5ubuntu0.1~esm1 Available with Ubuntu Pro libbcpg-java 1.68-5ubuntu0.1~esm1 Available with Ubuntu Pro libbcpkix-java 1.68-5ubuntu0.1~esm1 Available with Ubuntu Pro libbcprov-java 1.68-5ubuntu0.1~esm1 Available with Ubuntu Pro libbctls-java 1.68-5ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libbcmail-java 1.61-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpg-java 1.61-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpkix-java 1.61-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcprov-java 1.61-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libbcmail-java 1.59-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpg-java 1.59-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcpkix-java 1.59-1ubuntu0.1~esm1 Available with Ubuntu Pro libbcprov-java 1.59-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libbcmail-java 1.51-4ubuntu1+esm1 Available with Ubuntu Pro libbcpg-java 1.51-4ubuntu1+esm1 Available with Ubuntu Pro libbcpkix-java 1.51-4ubuntu1+esm1 Available with Ubuntu Pro libbcprov-java 1.51-4ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8108-1 CVE-2023-33201, CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-34447, CVE-2025-8916 . Critical security issues were fixed in Bouncy Castle on multiple Ubuntu versions, addressing significant exploits. Bouncy Castle Security, Ubuntu Update, LDAP Injection, DoS Prevention. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.