This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c53905e83d 2025-06-14 01:51:14.531329+00:00 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 41 Version : 1.13.0 Release : 1.fc41 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 4 2025 Sergio Lopez - 1.13.0-1 - Update to version 1.13.0 * Tue May 20 2025 Sergio Lopez - 1.12.2-1 - Update to version 1.12.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c53905e83d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4fc3431dab 2025-06-14 01:09:53.632877+00:00 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 42 Version : 1.13.0 Release : 1.fc42 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: This release includes improvements and fixes, and updates crossbeam-channel dependency to address CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 4 2025 Sergio Lopez - 1.13.0-1 - Update to version 1.13.0 * Tue May 20 2025 Sergio Lopez - 1.12.2-1 - Update to version 1.12.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-4fc3431dab' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6f07616b52 2025-02-13 02:00:53.381620+00:00 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 40 Version : 1.10.1 Release : 2.fc40 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate. -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 6 2025 Fabio Valentini - 1.10.1-2 - Rebuild for openssl crate > = v0.10.70 (RUSTSEC-2025-0004) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343478 - CVE-2025-0977 rust-openssl: ssl::select_next_proto use after free [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2343478 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6f07616b52' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-f8be7978e3 2025-02-08 02:15:29.328151+00:00 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 41 Version : 1.10.1 Release : 2.fc41 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate. -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 6 2025 Fabio Valentini - 1.10.1-2 - Rebuild for openssl crate > = v0.10.70 (RUSTSEC-2025-0004) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2343479 - CVE-2025-0977 rust-openssl: ssl::select_next_proto use after free [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2343479 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-f8be7978e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update rust-vmm components and their consumers to address CVE-2023-50711. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f2305d485f 2024-02-14 01:11:43.154092 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 38 Version : 1.7.2 Release : 4.fc38 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Update rust-vmm components and their consumers to address CVE-2023-50711 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 25 2024 Fedora Release Engineering - 1.7.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.7.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 11 2024 Sergio Lopez - 1.7.2-2 - Update versions of rust-vmm dependencies -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f2305d485f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update rust-vmm components and their consumers to address CVE-2023-50711. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-04877592b7 2024-02-10 01:24:59.648730 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 39 Version : 1.7.2 Release : 4.fc39 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Update rust-vmm components and their consumers to address CVE-2023-50711 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 25 2024 Fedora Release Engineering - 1.7.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 1.7.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 11 2024 Sergio Lopez - 1.7.2-2 - Update versions of rust-vmm dependencies -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-04877592b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-6215ea423b 2023-12-06 01:45:51.746952 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 38 Version : 1.5.0 Release : 7.fc38 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Affected applications were rebuilt against version 0.10.60 of the the `openssl` crate (the Rust bindings for OpenSSL) to address two security advisories: - https://rustsec.org/advisories/RUSTSEC-2023-0044.html - https://rustsec.org/advisories/RUSTSEC-2023-0072.html -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 1 2023 Fabio Valentini - 1.5.0-7 - Rebuild for openssl crate > = v0.10.60 (RUSTSEC-2023-0044, RUSTSEC-2023-0072) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6215ea423b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-c19aaa2283 2023-09-28 01:34:46.976714 -------------------------------------------------------------------------------- Name : libkrun Product : Fedora 38 Version : 1.5.0 Release : 6.fc38 URL : https://github.com/containers/libkrun Summary : Dynamic library providing Virtualization-based process isolation capabilities Description : Dynamic library providing Virtualization-based process isolation capabilities. -------------------------------------------------------------------------------- Update Information: Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 19 2023 Fabio Valentini - 1.5.0-6 - Rebuild for vm-memory v0.12.2 / CVE-2023-41051. * Thu Jul 20 2023 Fedora Release Engineering - 1.5.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236894 - CVE-2023-41051 rust-vm-memory: vm-memory: out-of-bounds access in memory functions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c19aaa2283' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.