update to 1.154.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9a360acefb 2026-04-25 01:21:36.171611+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 44 Version : 1.154.0 Release : 1.fc44 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: update to 1.154.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Mikel Olasagasti Uranga - 1.154.0-1 - Update to 1.154.0 - Closes rhbz#2448615 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2453090 - CVE-2026-33748 doctl: BuildKit: Unauthorized file access via Git URL fragment subdir components [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453090 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9a360acefb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 1.154.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-729f84f3b6 2026-04-10 01:10:26.730895+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 42 Version : 1.154.0 Release : 1.fc42 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: update to 1.154.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Mikel Olasagasti Uranga - 1.154.0-1 - Update to 1.154.0 - Closes rhbz#2448615 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452189 - CVE-2026-33747 doctl: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2452189 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-729f84f3b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
update to 1.154.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6ad76ebb29 2026-04-10 00:59:15.834450+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 43 Version : 1.154.0 Release : 1.fc43 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: update to 1.154.0 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 1 2026 Mikel Olasagasti Uranga - 1.154.0-1 - Update to 1.154.0 - Closes rhbz#2448615 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452200 - CVE-2026-33747 doctl: BuildKit: Arbitrary file write and code execution via untrusted frontend [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2452200 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6ad76ebb29' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 1.148.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-cfdb90b52d 2026-01-04 01:00:12.006236+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 42 Version : 1.148.0 Release : 1.fc42 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: Update to 1.148.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 29 2025 Mikel Olasagasti Uranga - 1.148.0-1 - Update to 1.148.0 - Closes rhbz#2397308 * Fri Oct 10 2025 Alejandro Sez - 1.142.0-2 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398680 - CVE-2025-47910 doctl: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398680 [ 2 ] Bug #2399357 - CVE-2025-47906 doctl: Unexpected paths returned from LookPath in os/exec [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399357 [ 3 ] Bug #2407883 - CVE-2025-58189 doctl: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407883 [ 4 ] Bug #2409352 - CVE-2025-61723 doctl: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409352 [ 5 ] Bug #2410302 - CVE-2025-58185 doctl: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410302 [ 6 ] Bug #2412383 - CVE-2025-58188 doctl: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412383 [ 7 ] Bug #2412764 - CVE-2025-58183 doctl: Unbounded allocation when parsing GNU sparse map [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2412764 [ 8 ] Bug #2419006 - CVE-2024-25621 doctl: containerd local privilege escalation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419006 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-cfdb90b52d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates released for doctl on Fedora address several security issues including memory exhaustion and privilege escalation.. doctl updates,memory exhaustion,security updates,Fedora applications,CrossOriginProtection. . Severity: Important. LinuxSecurity.com Team
Update to 1.148.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-714a42ffeb 2026-01-04 00:48:37.722154+00:00 -------------------------------------------------------------------------------- Name : doctl Product : Fedora 43 Version : 1.148.0 Release : 1.fc43 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. -------------------------------------------------------------------------------- Update Information: Update to 1.148.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 29 2025 Mikel Olasagasti Uranga - 1.148.0-1 - Update to 1.148.0 - Closes rhbz#2397308 * Fri Oct 10 2025 Alejandro Sez - 1.142.0-2 - rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408160 - CVE-2025-58189 doctl: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408160 [ 2 ] Bug #2409630 - CVE-2025-61723 doctl: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409630 [ 3 ] Bug #2410581 - CVE-2025-58185 doctl: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410581 [ 4 ] Bug #2411479 - CVE-2025-58188 doctl: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411479 [ 5 ] Bug #2412684 - CVE-2025-58183 doctl: Unbounded allocation when parsing GNU sparse map [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2412684 [ 6 ] Bug #2419035 - CVE-2024-25621 doctl: containerd local privilege escalation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2419035 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-714a42ffeb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Critical updates for doctl version 1.148.0 on Fedora 43 enhance API command line interface functionality.. doctl update, Fedora 43, command line interface, local escalation, memory management. . Severity: Critical. LinuxSecurity.com Team
Update to 1.93.1. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3737bc1c0a 2023-04-22 00:53:57.594785 --------------------------------------------------------------------------------Name : doctl Product : Fedora 37 Version : 1.93.1 Release : 2.fc37 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API. --------------------------------------------------------------------------------Update Information: Update to 1.93.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 12 2023 Mikel Olasagasti Uranga - 1.93.1-2 - Skip integration tests * Fri Mar 10 2023 Mikel Olasagasti Uranga - 1.93.1-1 - Update to 1.93.1 - Closes rhbz#2176716 --------------------------------------------------------------------------------References: [ 1 ] Bug #2174541 - doctl: containerd: Supplementary groups are not set up properly [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2174541 [ 2 ] Bug #2178431 - CVE-2022-41723 doctl: golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2178431 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3737bc1c0a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08ae2dd481 2022-05-07 04:08:14.315797 --------------------------------------------------------------------------------Name : doctl Product : Fedora 36 Version : 1.73.0 Release : 2.fc36 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.73.0-2 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2045471 - golang-github-appc-goaci: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045471 [ 2 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08ae2dd481' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : doctl Product : Fedora 35 Version : 1.73.0 Release : 2.fc35 URL : https://github.com/digitalocean/doctl Summary : The official command line interface for the DigitalOcean API Description : The official command line interface for the DigitalOcean API --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.73.0-2 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.