Upgrade to 4.3.5 upstream version.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-54d78b9fed 2025-12-12 01:45:35.303645+00:00 -------------------------------------------------------------------------------- Name : singularity-ce Product : Fedora 42 Version : 4.3.5 Release : 1.fc42 URL : Summary : Application and environment virtualization Description : SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. -------------------------------------------------------------------------------- Update Information: Upgrade to 4.3.5 upstream version. -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 3 2025 David Trudgian - 4.3.5-1 - Upgrade to 4.3.5 upstream version. - Fixes CVE-2025-64750 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-54d78b9fed' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Upgrade to 4.3.4 upstream version. Go 1.25.2 for build fixes multiple go CVEs. BZ#2408346 BZ#2408744 BZ#2409819 BZ#2410769 BZ#2411665. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-a6641a44f2 2025-11-08 01:06:29.234624+00:00 -------------------------------------------------------------------------------- Name : singularity-ce Product : Fedora 43 Version : 4.3.4 Release : 1.fc43 URL : Summary : Application and environment virtualization Description : SingularityCE is the Community Edition of Singularity, an open source container platform designed to be simple, fast, and secure. -------------------------------------------------------------------------------- Update Information: Upgrade to 4.3.4 upstream version. Go 1.25.2 for build fixes multiple go CVEs. BZ#2408346 BZ#2408744 BZ#2409819 BZ#2410769 BZ#2411665 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 30 2025 David Trudgian - 4.3.4-1 - Upgrade to 4.3.4 upstream version. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408346 - CVE-2025-58189 singularity-ce: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408346 [ 2 ] Bug #2408744 - CVE-2025-61725 singularity-ce: Excessive CPU consumption in ParseAddress in net/mail [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408744 [ 3 ] Bug #2409819 - CVE-2025-61723 singularity-ce: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409819 [ 4 ] Bug #2410769 - CVE-2025-58185 singularity-ce: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410769 [ 5 ] Bug #2411665 - CVE-2025-58188singularity-ce: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411665 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-a6641a44f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to upstream 1.1.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-01ff262091 2023-02-22 10:10:35.979031 --------------------------------------------------------------------------------Name : apptainer Product : Fedora 37 Version : 1.1.6 Release : 1.fc37 URL : https://apptainer.org Summary : Application and environment virtualization formerly known as Singularity Description : Apptainer provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Update to upstream 1.1.6 --------------------------------------------------------------------------------ChangeLog: * Tue Feb 14 2023 Dave Dykstra - 1.1.6-1 - Update to upstream 1.1.6. --------------------------------------------------------------------------------References: [ 1 ] Bug #2161895 - apptainer does not declare bundled dependencies https://bugzilla.redhat.com/show_bug.cgi?id=2161895 [ 2 ] Bug #2161899 - apptainer: vulnerable to CVE-2022-23538 https://bugzilla.redhat.com/show_bug.cgi?id=2161899 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-01ff262091' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuild 3.8.5 using golang-1.16.12. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-7333cffa91 2021-12-24 01:23:26.059842 --------------------------------------------------------------------------------Name : singularity Product : Fedora 35 Version : 3.8.5 Release : 2.fc35 URL : https://singularity.hpcng.org Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Rebuild 3.8.5 using golang-1.16.12 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Dave Dykstra - 3.8.5-2 - Rebuild using golang-1.16.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2032683 - singularity-3.8.5 needs to be rebuilt with golang-1.16.12 https://bugzilla.redhat.com/show_bug.cgi?id=2032683 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-7333cffa91' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream 3.6.4.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-efff92f6c4 2020-10-23 22:01:02.261284 --------------------------------------------------------------------------------Name : singularity Product : Fedora 33 Version : 3.6.4 Release : 1.fc33 URL : / Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream 3.6.4. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 13 2020 Dave Dykstra - 3.6.4-1 - Upgrade to upstream 3.6.4. --------------------------------------------------------------------------------References: [ 1 ] Bug #1887917 - singularity-3.6.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1887917 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-efff92f6c4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream 3.6.0. Remove patch #4679 for el8.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-198fdb12a1 2020-07-23 01:17:08.656167 --------------------------------------------------------------------------------Name : singularity Product : Fedora 31 Version : 3.6.0 Release : 1.fc31 URL : Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream 3.6.0. Remove patch #4679 for el8. --------------------------------------------------------------------------------ChangeLog: * Tue Jul 14 2020 Dave Dykstra - 3.6.0-1 - Upgrade to upstream 3.6.0. Remove patch #4679 for el8, since golang-12 is now available for that build machine. --------------------------------------------------------------------------------References: [ 1 ] Bug #1828680 - singularity-3.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1828680 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-198fdb12a1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream 3.5.2, still using golang-1.11 on epel8 ---- Upgrade to upstream 3.5.1, use golang-1.11 on epel8 ---- Upgrade to upstream 3.5.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f4eb2a01d1 2020-01-05 00:38:52.032153 --------------------------------------------------------------------------------Name : singularity Product : Fedora 31 Version : 3.5.2 Release : 1.1.fc31 URL : Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream 3.5.2, still using golang-1.11 on epel8 ---- Upgrade to upstream 3.5.1, use golang-1.11 on epel8 ---- Upgrade to upstream 3.5.0 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 17 2019 Dave Dykstra - 3.5.2-1.1 - Upgrade to upstream 3.5.2, keeping #4768 patch only on el8 * Thu Dec 5 2019 Dave Dykstra - 3.5.1-1.1 - Upgrade to upstream 3.5.1, keeping #4768 patch only on el8 * Wed Nov 20 2019 Dave Dykstra - 3.5.0-1.1 - Apply patch from PR #4769 to build with golang-1.11 on el8 only * Wed Nov 13 2019 Dave Dykstra - 3.5.0-1 - Upgrade to upstream 3.5.0 * Thu Nov 7 2019 Dave Dykstra - 3.5.0~rc.2-1 - Upgrade to upstream 3.5.0~rc.2. * Wed Oct 30 2019 Dave Dykstra - 3.5.0~rc.1-1 - Upgrade to upstream 3.5.0~rc.1. Drop PR #4522 patch. * Mon Oct 21 2019 Dave Dykstra - 3.4.2-1.1 - Upgrade to upstream 3.4.2. Remove PR #4522, no longer needed. Still contains config fakeroot cli PR #4346. * Thu Sep 26 2019 Dave Dykstra - 3.4.1-1.2 - Add PR #4522 to fix sandbox rootless builds --------------------------------------------------------------------------------References: [ 1 ] Bug #1777565 - singularity-3.5.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1777565 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f4eb2a01d1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02051f8300 2018-06-16 19:31:27.218113 --------------------------------------------------------------------------------Name : singularity Product : Fedora 27 Version : 2.5.1 Release : 1.fc27 URL : https://singularity.lbl.gov/ Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: This rebases singularity from 2.2.1 to 2.5.1, which should include all corresponding updates (n.b. a request for rebase permission has been put into FESCo; hence auto-push has been disabled until they approve). Please test for functionality and backward compatibility issues, particularly around the runtime components. --------------------------------------------------------------------------------ChangeLog: * Fri May 4 2018 Dave Dykstra - 2.5.1-1 - Update to upstream version 2.5.1 * Fri Apr 27 2018 Dave Dykstra - 2.5.0-1 - Update to upstream version 2.5.0 * Mon Apr 16 2018 Dave Dykstra - 2.4.6-1 - Update to upstream version 2.4.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1585620 - singularity: Multiple security vulnerabilities fixed in 2.5.0 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1585620 [ 2 ] Bug #1585619 - singularity: Multiple security vulnerabilities fixed in 2.5.0 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1585619 [ 3 ] Bug #1452572 - singularity: Switch to Python 3 https://bugzilla.redhat.com/show_bug.cgi?id=1452572 [ 4 ] Bug #1457856 - singularity-2.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1457856 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-02051f8300' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.