Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : plasma-nm Product : Fedora 44 Version : 6.6.4 Release : 1.fc44 URL : https://invent.kde.org/plasma/plasma-nm Summary : Plasma for managing network connections Description : Plasma applet and editor for managing your network connections in KDE 4 using the default NetworkManager service. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 10 2026 Steve Cossette - 6.6.4-1 - 6.6.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-solid Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://solid.kde.org/ Summary : KDE Frameworks 6 Tier 1 integration module that provides hardware information Description : Solid provides the following features for application developers: - Hardware Discovery - Power Management - Network Management -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8353 http://linux.oracle.com/errata/ELSA-2024-8353.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: NetworkManager-libreswan-1.2.10-7.el8_10.x86_64.rpm NetworkManager-libreswan-gnome-1.2.10-7.el8_10.x86_64.rpm aarch64: NetworkManager-libreswan-1.2.10-7.el8_10.aarch64.rpm NetworkManager-libreswan-gnome-1.2.10-7.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//NetworkManager-libreswan-1.2.10-7.el8_10.src.rpm Related CVEs: CVE-2024-9050 Description of changes: [1.2.10-7] - Unbreak validation of unknown keys [1.2.10-6] - Fix improper escaping of Libreswan configuration (CVE-2024-9050) _______________________________________________ El-errata mailing list
iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-fdce971b84 2024-03-08 01:18:13.751618 -------------------------------------------------------------------------------- Name : iwd Product : Fedora 39 Version : 2.15 Release : 1.fc39 URL : https://archive.kernel.org/oldwiki/iwd.wiki.kernel.org/ Summary : Wireless daemon for Linux Description : The daemon and utilities for controlling and configuring the Wi-Fi network hardware. -------------------------------------------------------------------------------- Update Information: iwd 2.15: Fix issue with notice events for connection timeouts. Fix issue with reason code and deauthenticate event. Fix issue with handling basename() functionality. libell 0.63: Fix issue with handling ending boundary of the PEM. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 28 2024 Peter Robinson - 2.15-1 - Update to 2.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2263042 - libell-0.63 is available https://bugzilla.redhat.com/show_bug.cgi?id=2263042 [ 2 ] Bug #2263573 - iwd-2.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=2263573 [ 3 ] Bug #2264597 - TRIAGE CVE-2023-52161 iwd: potential authorization bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2264597 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-fdce971b84' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0369-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-369=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp155.4.3.1 connman-client-1.42-bp155.4.3.1 connman-devel-1.42-bp155.4.3.1 connman-doc-1.42-bp155.4.3.1 connman-nmcompat-1.42-bp155.4.3.1 connman-plugin-iospm-1.42-bp155.4.3.1 connman-plugin-l2tp-1.42-bp155.4.3.1 connman-plugin-openvpn-1.42-bp155.4.3.1 connman-plugin-polkit-1.42-bp155.4.3.1 connman-plugin-pptp-1.42-bp155.4.3.1 connman-plugin-wireguard-1.42-bp155.4.3.1 connman-test-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp155.4.3.1 - openSUSE Backports SLE-15-SP5 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp155.4.3.1 connman-plugin-tist-1.42-bp155.4.3.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . This patch targets a significant flaw within connman on openSUSE, successfully rectifying security vulnerabilities and fortifying protection.. openSUSE Update, Connman Security, Important Fix, SLE-15-SP5, Security Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for connman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0370-1 Rating: important References: #1210395 Cross-References: CVE-2023-28488 CVSS scores: CVE-2023-28488 (NVD) : 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for connman fixes the following issues: - Update to 1.42 * Fix issue with iwd and signal strength calculation. * Fix issue with iwd and handling service removal. * Fix issue with iwd and handling new connections. * Fix issue with handling default online check URL. * Fix issue with handling nameservers refresh. * Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488) * Fix issue with handling multiple proxies from PAC. * Fix issue with handling manual time update changes. * Fix issue with handling invalid gateway routes. * Fix issue with handling hidden WiFi agent requests. * Fix issue with handling WiFi SAE authentication failure. * Fix issue with handling DNS Proxy and TCP server replies. * Add support for regulatory domain following timezone. * Add support for localtime configuration option. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-370=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): connman-1.42-bp154.2.6.1 connman-client-1.42-bp154.2.6.1 connman-devel-1.42-bp154.2.6.1 connman-doc-1.42-bp154.2.6.1 connman-nmcompat-1.42-bp154.2.6.1 connman-plugin-iospm-1.42-bp154.2.6.1 connman-plugin-l2tp-1.42-bp154.2.6.1 connman-plugin-openvpn-1.42-bp154.2.6.1 connman-plugin-polkit-1.42-bp154.2.6.1 connman-plugin-pptp-1.42-bp154.2.6.1 connman-plugin-wireguard-1.42-bp154.2.6.1 connman-test-1.42-bp154.2.6.1 - openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64): connman-plugin-vpnc-1.42-bp154.2.6.1 - openSUSE Backports SLE-15-SP4 (aarch64 i586 s390x x86_64): connman-plugin-hh2serial-gps-1.42-bp154.2.6.1 connman-plugin-tist-1.42-bp154.2.6.1 References: https://www.suse.com/security/cve/CVE-2023-28488.html https://bugzilla.suse.com/1210395 . Upgrade released for connman to tackle critical problems along with several corrections in network handling.. openSUSE Connman Update, Connman Security Fix, Network Management Linux, openSUSE Backports Security Update. . Severity: Important. LinuxSecurity.com Team
Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-37ae269843 2023-05-18 00:49:56.087782 --------------------------------------------------------------------------------Name : nmstate Product : Fedora 37 Version : 2.2.10 Release : 5.fc37 URL : https://github.com/nmstate/nmstate Summary : Declarative network manager API Description : Nmstate is a library with an accompanying command line tool that manages host networking settings in a declarative manner and aimed to satisfy enterprise needs to manage host networking through a northbound declarative API and multi provider support on the southbound. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of all affected applications against the latest versions of these crates, which have addressed all linkedissues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 2.2.10-5 - Rebuild for tokio crate > = v1.24.2 (RUSTSEC-2023-0005) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-37ae269843' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-cc21019773 2023-05-07 01:19:58.787245 --------------------------------------------------------------------------------Name : nmstate Product : Fedora 38 Version : 2.2.10 Release : 4.fc38 URL : https://github.com/nmstate/nmstate Summary : Declarative network manager API Description : Nmstate is a library with an accompanying command line tool that manages host networking settings in a declarative manner and aimed to satisfy enterprise needs to manage host networking through a northbound declarative API and multi provider support on the southbound. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of all affected applications against the latest versions of these crates, which have addressed all linkedissues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 2.2.10-4 - Rebuild for tokio crate > = v1.24.2 (RUSTSEC-2023-0005) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cc21019773' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.