Qt 6.10.3 bugfix update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-70776c2dc3 2026-04-25 01:21:36.172096+00:00 -------------------------------------------------------------------------------- Name : mingw-qt6-qtsensors Product : Fedora 44 Version : 6.10.3 Release : 1.fc44 URL : http://qt.io/ Summary : Qt6 for Windows - QtSensors component Description : This package contains the Qt software toolkit for developing cross-platform applications. This is the Windows version of Qt, for use in conjunction with the Fedora Windows cross-compiler. -------------------------------------------------------------------------------- Update Information: Qt 6.10.3 bugfix update. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jan Grulich - 6.10.3-1 - 6.10.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-70776c2dc3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Qt 6.10.3 bugfix update.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-70776c2dc3 2026-04-25 01:21:36.172096+00:00 -------------------------------------------------------------------------------- Name : mingw-qt6-qtbase Product : Fedora 44 Version : 6.10.3 Release : 1.fc44 URL : http://qt.io/ Summary : Qt6 for Windows - QtBase component Description : This package contains the Qt software toolkit for developing cross-platform applications. This is the 32-bit Windows version of Qt, for use in conjunction with the Fedora Windows cross-compiler. -------------------------------------------------------------------------------- Update Information: Qt 6.10.3 bugfix update. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jan Grulich - 6.10.3-1 - 6.10.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-70776c2dc3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to exiv2-0.28.8.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-592e4238fa 2026-04-12 15:52:51.750287+00:00 -------------------------------------------------------------------------------- Name : mingw-exiv2 Product : Fedora 42 Version : 0.28.8 Release : 1.fc42 URL : https://exiv2.org/ Summary : MinGW Windows exiv2 library Description : MinGW Windows exiv2 library. -------------------------------------------------------------------------------- Update Information: Update to exiv2-0.28.8. -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 7 2026 Sandro Mani - 0.28.8-1 - Update to 0.28.8 * Fri Jan 16 2026 Fedora Release Engineering - 0.28.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2453392 - CVE-2026-25884 mingw-exiv2: Exiv2: Denial of service via out-of-bounds read in CRW image parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453392 [ 2 ] Bug #2453394 - CVE-2026-27596 mingw-exiv2: Exiv2: Denial of Service via out-of-bounds read in preview component [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453394 [ 3 ] Bug #2453396 - CVE-2026-27631 mingw-exiv2: Exiv2: Denial of Service via integer overflow in preview component [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453396 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-592e4238fa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to gstreamer-1.26.11.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e6d8e9fd49 2026-04-05 00:52:10.725721+00:00 -------------------------------------------------------------------------------- Name : mingw-gstreamer1 Product : Fedora 43 Version : 1.26.11 Release : 1.fc43 URL : http://gstreamer.freedesktop.org/ Summary : MinGW Windows Streaming-Media Framework Runtime Description : GStreamer is a streaming-media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plug-in-based architecture means that new data types or processing capabilities can be added by installing new plug-ins. -------------------------------------------------------------------------------- Update Information: Update to gstreamer-1.26.11. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 27 2026 Sandro Mani - 1.26.11-1 - Update to 1.26.11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447936 - CVE-2026-2920 mingw-gstreamer1: GStreamer: Arbitrary code execution via ASF file processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2447936 [ 2 ] Bug #2448013 - CVE-2026-3084 mingw-gstreamer1: GStreamer: Remote Code Execution via integer underflow in H.266 Codec Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448013 [ 3 ] Bug #2448019 - CVE-2026-2922 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in RealMedia Demuxer [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448019 [ 4 ] Bug #2448020 - CVE-2026-2921 mingw-gstreamer1: GStreamer: Arbitrary code execution via RIFF palette integer overflow in AVI file handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448020 [ 5 ] Bug #2448021 - CVE-2026-2923 mingw-gstreamer1: GStreamer: Remote Code Execution via out-of-bounds write in DVB Subtitles handling [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448021 [ 6 ] Bug #2448022 - CVE-2026-3085 mingw-gstreamer1: GStreamer: Remote Code Execution via Heap-based Buffer Overflow in rtpqdm2depay [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448022 [ 7 ] Bug #2448029 - CVE-2026-3081 mingw-gstreamer1: GStreamer: Arbitrary code execution via H.266 codec parsing stack-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448029 [ 8 ] Bug #2448030 - CVE-2026-3083 mingw-gstreamer1: GStreamer: Remote Code Execution via Out-Of-Bounds Write in rtpqdm2depay [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448030 [ 9 ] Bug #2448032 - CVE-2026-3086 mingw-gstreamer1: GStreamer: Remote Code Execution via Out-Of-Bounds Write in H.266 Codec Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448032 [ 10 ] Bug #2448038 - CVE-2026-3082 mingw-gstreamer1: GStreamer: Remote Code Execution via heap-based buffer overflow in JPEG parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2448038 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e6d8e9fd49' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Update to 2.32.4. Fixes CVE-2024-47081.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-47916db6c7 2025-07-14 02:33:25.946188+00:00 -------------------------------------------------------------------------------- Name : mingw-python-requests Product : Fedora 41 Version : 2.32.4 Release : 1.fc41 URL : https://requests.readthedocs.io/en/latest/ Summary : MinGW Windows Python requests library Description : MinGW Windows Python requests. -------------------------------------------------------------------------------- Update Information: Update to 2.32.4. Fixes CVE-2024-47081. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 5 2025 Sandro Mani - 2.32.4-1 - Update to 2.32.4 * Fri Jan 17 2025 Fedora Release Engineering - 2.32.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2375883 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375883 [ 2 ] Bug #2375885 - CVE-2024-47081 mingw-python-requests: Requests vulnerable to .netrc credentials leak via malicious URLs [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375885 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-47916db6c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to flask-3.1.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-853e37285c 2025-05-30 01:14:13.237014+00:00 -------------------------------------------------------------------------------- Name : mingw-python-flit-core Product : Fedora 42 Version : 3.12.0 Release : 1.fc42 URL : https://pypi.org/project/flit-core/ Summary : MinGW Python flit_core library Description : MinGW Python flit_core library. -------------------------------------------------------------------------------- Update Information: Update to flask-3.1.1. -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 28 2025 Sandro Mani - 3.12.0-1 - Update to 3.12.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2366239 - CVE-2025-47278 mingw-python-flask: Flask Session Signing Fallback Key Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366239 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-853e37285c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to LibRaw 0.21.4.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-32a9eb17af 2025-04-30 01:59:13.913508+00:00 -------------------------------------------------------------------------------- Name : mingw-LibRaw Product : Fedora 40 Version : 0.21.4 Release : 1.fc40 URL : http://www.libraw.org Summary : Library for reading RAW files obtained from digital photo cameras Description : MinGW Windows LibRaw library. -------------------------------------------------------------------------------- Update Information: Update to LibRaw 0.21.4. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 16 2025 Sandro Mani - 0.21.4-1 - Update to 0.21.4 * Fri Jan 17 2025 Fedora Release Engineering - 0.21.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Mon Sep 23 2024 Sandro Mani - 0.21.3-1 - Update to 0.21.3 * Thu Jul 18 2024 Fedora Release Engineering - 0.21.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2361338 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361338 [ 2 ] Bug #2361343 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361343 [ 3 ] Bug #2361348 - CVE-2025-43963 mingw-LibRaw: out-of-buffer access [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361348 [ 4 ] Bug #2361356 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361356 [ 5 ] Bug #2361361 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361361 [ 6 ] Bug #2361366 - CVE-2025-43964 mingw-LibRaw: Improper Validation of Specified Quantity in Input in LibRaw [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361366 [ 7 ] Bug #2361374 - CVE-2025-43962 mingw-LibRaw: Out-of-Bounds Read in LibRaw's phase_one_correct Function [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361374 [ 8 ] Bug #2361379 - CVE-2025-43962 mingw-LibRaw: Out-of-Bounds Read in LibRaw's phase_one_correct Function [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361379 [ 9 ] Bug #2361384 - CVE-2025-43962 mingw-LibRaw: Out-of-Bounds Read in LibRaw's phase_one_correct Function [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361384 [ 10 ] Bug #2361401 - CVE-2025-43961 mingw-LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2361401 [ 11 ] Bug #2361406 - CVE-2025-43961 mingw-LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2361406 [ 12 ] Bug #2361411 - CVE-2025-43961 mingw-LibRaw: Out-of-Bounds Read in Fujifilm 0xf00c Tag Parser in LibRaw [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361411 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-32a9eb17af' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailinglist --
Backport fix for CVE-2024-9287 Update to python-3.11.0.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e6b1e638d1 2024-11-28 03:19:40.039643+00:00 -------------------------------------------------------------------------------- Name : mingw-python3 Product : Fedora 41 Version : 3.11.10 Release : 2.fc41 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2024-9287 Update to python-3.11.0. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 18 2024 Sandro Mani - 3.11.10-2 - Backport fix for CVE-2024-9287 * Sat Nov 9 2024 Sandro Mani - 3.11.10-1 - Update to 3.11.10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2321653 - CVE-2024-9287 mingw-python3: Virtual environment (venv) activation scripts don't quote paths [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2321653 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e6b1e638d1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.