Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-kjobwidgets Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/kjobwidgets Summary : KDE Frameworks 6 Tier 2 addon for KJobs Description : KDE Frameworks 6 Tier 2 addon for KJobs. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kdeplasma-addons Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/kdeplasma-addons Summary : Additional Plasmoids for Plasma 6 Description : Additional Plasmoids for Plasma 6. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: containernetworking-plugins security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3341", "synopsis": "Important: containernetworking-plugins security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for containernetworking-plugins.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. \n\nSecurity Fix(es):\n\n* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2418462", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "description": ""}, {"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe":"CWE-770"}, {"name": "CVE-2025-61729", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61729", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1050"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-02-26T20:45:27.603517Z", "rpms": {"Rocky Linux 9": {"nvras": ["containernetworking-plugins-1:1.7.1-3.el9_7.aarch64.rpm", "containernetworking-plugins-1:1.7.1-3.el9_7.ppc64le.rpm", "containernetworking-plugins-1:1.7.1-3.el9_7.s390x.rpm", "containernetworking-plugins-1:1.7.1-3.el9_7.src.rpm", "containernetworking-plugins-1:1.7.1-3.el9_7.x86_64.rpm", "containernetworking-plugins-debuginfo-1:1.7.1-3.el9_7.aarch64.rpm", "containernetworking-plugins-debuginfo-1:1.7.1-3.el9_7.ppc64le.rpm", "containernetworking-plugins-debuginfo-1:1.7.1-3.el9_7.s390x.rpm", "containernetworking-plugins-debuginfo-1:1.7.1-3.el9_7.x86_64.rpm", "containernetworking-plugins-debugsource-1:1.7.1-3.el9_7.aarch64.rpm", "containernetworking-plugins-debugsource-1:1.7.1-3.el9_7.ppc64le.rpm", "containernetworking-plugins-debugsource-1:1.7.1-3.el9_7.s390x.rpm", "containernetworking-plugins-debugsource-1:1.7.1-3.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for Rocky Linux 9 addresses important security issues in containernetworking-plugins to enhance system protection.. Rocky Linux, Container Networking Plugins, Important Update. . Severity: Important. LinuxSecurity.com Team
Update to 1.52.2 Partially fixes CVE-2025-9615. To protect totally from it, see: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/- /merge_requests/2325.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-27f16898ba 2025-12-19 04:14:19.799977+00:00 -------------------------------------------------------------------------------- Name : NetworkManager Product : Fedora 42 Version : 1.52.2 Release : 1.fc42 URL : https://networkmanager.dev/ Summary : Network connection manager and user applications Description : NetworkManager is a system service that manages network interfaces and connections based on user or automatic configuration. It supports Ethernet, Bridge, Bond, VLAN, Team, InfiniBand, Wi-Fi, mobile broadband (WWAN), PPPoE and other devices, and supports a variety of different VPN services. -------------------------------------------------------------------------------- Update Information: Update to 1.52.2 Partially fixes CVE-2025-9615. To protect totally from it, see: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/- /merge_requests/2325. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 15 2025 igo Huguet - 1:1.52.2-1 - Update to 1.52.2 - Partially fixes CVE-2025-9615. To protect totally from it, see: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2325. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-27f16898ba' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update to Fedora 42 NetworkManager 1.52.2 addressing security concerns with CVE-2025-9615.. Fedora 42, NetworkManager, CVE-2025-9615, security advisory. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20114 http://linux.oracle.com/errata/ELSA-2025-20114.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: NetworkManager-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-adsl-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-bluetooth-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-config-connectivity-oracle-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-config-server-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-initscripts-updown-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-libnm-1.48.10-5.0.3.el9_5.i686.rpm NetworkManager-libnm-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-team-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-tui-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-wifi-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-wwan-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-cloud-setup-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-dispatcher-routing-rules-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-ovs-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-ppp-1.48.10-5.0.3.el9_5.x86_64.rpm NetworkManager-libnm-devel-1.48.10-5.0.3.el9_5.i686.rpm NetworkManager-libnm-devel-1.48.10-5.0.3.el9_5.x86_64.rpm aarch64: NetworkManager-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-adsl-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-bluetooth-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-config-connectivity-oracle-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-config-server-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-initscripts-updown-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-libnm-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-team-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-tui-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-wifi-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-wwan-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-cloud-setup-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-dispatcher-routing-rules-1.48.10-5.0.3.el9_5.noarch.rpm NetworkManager-ovs-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-ppp-1.48.10-5.0.3.el9_5.aarch64.rpm NetworkManager-libnm-devel-1.48.10-5.0.3.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//NetworkManager-1.48.10-5.0.3.el9_5.src.rpm Description ofchanges: [1.48.10-5.0.3] - Drop 777 permissions from the NetworkManager-dispatcher drop-in directory [Orabug: 37581907] [1.48.10-5.0.2] - Add a dropin file to make Networkmanager-dispatcher persistent [Orabug: 36989910] _______________________________________________ El-errata mailing list
USN-6851-1 caused systemctl enable to fail. ========================================================================== Ubuntu Security Notice USN-6851-2 June 28, 2024 netplan.io regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: USN-6851-1 caused systemctl enable to fail Software Description: - netplan.io: Declarative network configuration for various backends Details: USN-6851-1 fixed vulnerabilities in Netplan. The update lead to the discovery of a regression in netplan which caused systemctl enable to fail on systems without dbus. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Andreas Hasenack discovered that netplan incorrectly handled the permissions for netdev files containing wireguard configuration. An attacker could use this to obtain wireguard secret keys. It was discovered that netplan configuration could be manipulated into injecting arbitrary commands while setting up network interfaces. An attacker could use this to execute arbitrary commands or escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libnetplan1 1.0-2ubuntu1.2 netplan-generator 1.0-2ubuntu1.2 netplan.io 1.0-2ubuntu1.2 Ubuntu 23.10 libnetplan0 0.107-5ubuntu0.4 netplan-generator 0.107-5ubuntu0.4 netplan.io 0.107-5ubuntu0.4 Ubuntu 22.04 LTS libnetplan0 0.106.1-7ubuntu0.22.04.4 netplan.io 0.106.1-7ubuntu0.22.04.4 Ubuntu 20.04 LTS libnetplan0 0.104-0ubuntu2~20.04.6 netplan.io 0.104-0ubuntu2~20.04.6 In general, astandard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6851-2 https://ubuntu.com/security/notices/USN-6851-1 https://bugs.launchpad.net/ubuntu/+source/netplan.io/+bug/2071333 Package Information: https://launchpad.net/ubuntu/+source/netplan.io/1.0-2ubuntu1.2 https://launchpad.net/ubuntu/+source/netplan.io/0.107-5ubuntu0.4 https://launchpad.net/ubuntu/+source/netplan.io/0.106.1-7ubuntu0.22.04.4 https://launchpad.net/ubuntu/+source/netplan.io/0.104-0ubuntu2~20.04.6 . Recent modifications address a netplan.io issue stemming from a security loophole. Crucial for Ubuntu users overseeing network configurations.. Ubuntu Security Notices, Netplan Updates, System Security Fixes. . Severity: Important. LinuxSecurity.com Team
Netplan could reveal secrets or execute commands with specially crafted configuration file.. ========================================================================== Ubuntu Security Notice USN-6851-1 June 26, 2024 netplan.io vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Netplan could reveal secrets or execute commands with specially crafted configuration file. Software Description: - netplan.io: Declarative network configuration for various backends Details: Andreas Hasenack discovered that netplan incorrectly handled the permissions for netdev files containing wireguard configuration. An attacker could use this to obtain wireguard secret keys. It was discovered that netplan configuration could be manipulated into injecting arbitrary commands while setting up network interfaces. An attacker could use this to execute arbitrary commands or escalate privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libnetplan1 1.0-2ubuntu1.1 netplan-generator 1.0-2ubuntu1.1 netplan.io 1.0-2ubuntu1.1 Ubuntu 23.10 libnetplan0 0.107-5ubuntu0.3 netplan-generator 0.107-5ubuntu0.3 netplan.io 0.107-5ubuntu0.3 Ubuntu 22.04 LTS libnetplan0 0.106.1-7ubuntu0.22.04.3 netplan.io 0.106.1-7ubuntu0.22.04.3 Ubuntu 20.04 LTS libnetplan0 0.104-0ubuntu2~20.04.5 netplan.io 0.104-0ubuntu2~20.04.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6851-1 CVE-2022-4968, https://bugs.launchpad.net/netplan/+bug/1987842,https://bugs.launchpad.net/ubuntu/+source/netplan.io/+bug/2065738, Package Information: https://launchpad.net/ubuntu/+source/netplan.io/1.0-2ubuntu1.1 https://launchpad.net/ubuntu/+source/netplan.io/0.107-5ubuntu0.3 https://launchpad.net/ubuntu/+source/netplan.io/0.106.1-7ubuntu0.22.04.3 https://launchpad.net/ubuntu/+source/netplan.io/0.104-0ubuntu2~20.04.5 . Uncover the Ubuntu 6851-1 announcement concerning netplan.io weaknesses and measures to prevent command execution vulnerabilities.. Netplan Security Advisory, Ubuntu Security Update, Network Configuration Vulnerability. . LinuxSecurity.com Team
An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: containernetworking-plugins security and bug fix update Advisory ID: RHSA-2023:2367-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2367 Issue date: 2023-05-09 CVE Names: CVE-2022-30629 CVE-2022-41717 ==================================================================== 1. Summary: An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The Container Network Interface (CNI) project consists of a specification and libraries for writing plug-ins for configuring network interfaces in Linux containers, along with a number of supported plug-ins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted. Security Fix(es): * golang: net/http: An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests (CVE-2022-41717) * golang: crypto/tls: session tickets lack random ticket_age_add (CVE-2022-30629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Referencessection. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2092793 - CVE-2022-30629 golang: crypto/tls: session tickets lack random ticket_age_add 2129076 - containernetworking-plugins bug fix and enhancement update [rhel-9.2.0] 2161274 - CVE-2022-41717 golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: containernetworking-plugins-1.2.0-1.el9.src.rpm aarch64: containernetworking-plugins-1.2.0-1.el9.aarch64.rpm containernetworking-plugins-debuginfo-1.2.0-1.el9.aarch64.rpm containernetworking-plugins-debugsource-1.2.0-1.el9.aarch64.rpm ppc64le: containernetworking-plugins-1.2.0-1.el9.ppc64le.rpm containernetworking-plugins-debuginfo-1.2.0-1.el9.ppc64le.rpm containernetworking-plugins-debugsource-1.2.0-1.el9.ppc64le.rpm s390x: containernetworking-plugins-1.2.0-1.el9.s390x.rpm containernetworking-plugins-debuginfo-1.2.0-1.el9.s390x.rpm containernetworking-plugins-debugsource-1.2.0-1.el9.s390x.rpm x86_64: containernetworking-plugins-1.2.0-1.el9.x86_64.rpm containernetworking-plugins-debuginfo-1.2.0-1.el9.x86_64.rpm containernetworking-plugins-debugsource-1.2.0-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-30629 https://access.redhat.com/security/cve/CVE-2022-41717 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZFo1ntzjgjWX9erEAQii8w//RBP5bit9OiF3n2tn1Euwuz6ENQFoANTZ JONxDv2sS28yHyikWOs335v0FTNyqHKw7txTRflWHBzb+/chgeAjbBGWNXBUUsJU I9xf6iYgMa8Uu9+3NCZaDZvFjiXkeCy2/yPVnjkTpA1XKcMpbu+NP9AnzgLSOw0n +CQl1xt+jp6IY0uemlC+utIe9TW6iNafnvWcJ20/agHXhHVniwwb6ia3zY49CO1/ ZWFLlvz63AKgGqsq2tuneuF8ZEzoxn4nQhqeYGoTLmeJ6OYuZ+zitghh/vGEinUa HcnmFDRiENUngXYFz5mSkC6e/si6/iUg3ZhRYQCQ0yJkdzub/Lp5aTXqwXcOmR5o 6MyF51sxIIIdngoTWpLrZUqSOlUJFHlONwzAuzkNoRUhInunDnD2DYUN8YyHmpP8 r0YTncPAUxwu0w/eHM5JNaN6owSCdBHffIK5pphpaUzwcyhpeeIgtFl+gSNPCrNw RHAgx2rzH6HjNd20PFBceRdFXLe1yM074cHPmnXXhrsV0KHzNiOsRrYR+G/7rsDu 1rewsne4p8NDSLuMN6dLeaPO7uEwiDTttEgB+LbPLVMsp7sbLE+DNt8S9bVfpthk ywwtZ2yH5o4jq+maQHY07yAlAauvdYZvFFcRJMr3YaZh8XTmXBYEsJsSVnxGygeS G10VGQBbBlM=lDuv -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.