5.15.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b42cf3db3b 2026-04-25 01:21:36.173336+00:00 -------------------------------------------------------------------------------- Name : minetest Product : Fedora 44 Version : 5.15.2 Release : 1.fc44 URL : https://luanti.org Summary : Multiplayer infinite-world block sandbox with survival mode Description : Game of mining, crafting and building in the infinite world of cubic blocks with optional hostile creatures, features both single and the network multiplayer mode, mods. Public multiplayer servers are available. -------------------------------------------------------------------------------- Update Information: 5.15.2 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 16 2026 Gwyn Ciesla - 5.15.2-1 - 5.15.2 * Sun Mar 22 2026 Bjrn Esser - 5.15.1-2 - Rebuild (jsoncpp) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2458512 - minetest-5.15.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2458512 [ 2 ] Bug #2458908 - CVE-2026-40960 minetest: Luanti: Unauthorized access to insecure environment via crafted module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458908 [ 3 ] Bug #2458909 - CVE-2026-40959 minetest: Luanti: Lua sandbox escape via crafted mod [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2458909 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b42cf3db3b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Fedora 44 Security Update: Minetest 5.15.2 fixes unauthorized access and Lua sandbox escape vulnerabilities.. minetest security update,Fedora Linux vulnerabilities,Lua sandbox security. . Severity: Important. LinuxSecurity.com Team
It was discovered that redis, a persistent key-value database, could execute insecure Lua bytecode by way of the EVAL command. This could allow remote attackers to break out of the Lua sandbox and execute arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3279-1
Get the latest Linux and open source security news straight to your inbox.