Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b8b59dcf44 2026-03-28 00:15:26.019955+00:00 -------------------------------------------------------------------------------- Name : rust-reqsign-azure-storage Product : Fedora 44 Version : 3.0.0 Release : 1.fc44 URL : https://crates.io/crates/reqsign-azure-storage Summary : Azure Storage signing implementation for reqsign Description : Azure Storage signing implementation for reqsign. -------------------------------------------------------------------------------- Update Information: Update uv and python-uv-build to 0.11.2. Version 0.11 includes changes to the networking stack used by uv. While its developers think that breakage will be rare, it is possible that these changes will result in the rejection of certificates previously trusted by uv so, they have marked the change as breaking out of an abundance of caution. The changes are largely driven by the upgrade of reqwest, which powers uv's HTTP clients, to v0.13, which included some breaking changes to TLS certificate verification. This update also includes updates for several of uv\u2019s Rust library dependencies. Update rust-openssl-probe to 0.2.1, including breaking changes introduced in 0.2.0, and introduce a new rust-openssl-probe0.1 compat package. Update rust-rustls-native-certs to 0.8.3, now using openssl-probe 0.2. Update rust-native-tls to 0.2.18. Version 0.2.16 added TLS 1.3 as an option, added stack_from_pem, and upgraded openssl-probe to 0.2. Version 0.2.17 added support for ALPN on the server side. Version 0.2.18fixed min/max protocol selection fallback for very old OpenSSL versions. Add an initial package for rust-webpki-root-certs. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2026 Benjamin A. Beasley - 3.0.0-1 - Update to version 3.0.0; Fixes RHBZ#2432771 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2425802 - rust-openssl-probe-0.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425802 [ 2 ] Bug #2425819 - rust-rustls-native-certs-0.8.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2425819 [ 3 ] Bug #2432768 - rust-reqsign-aliyun-oss-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432768 [ 4 ] Bug #2432769 - rust-reqsign-core-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432769 [ 5 ] Bug #2432770 - rust-reqsign-0.20.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432770 [ 6 ] Bug #2432771 - rust-reqsign-azure-storage-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432771 [ 7 ] Bug #2432772 - rust-reqsign-http-send-reqwest-4.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432772 [ 8 ] Bug #2432773 - rust-reqsign-google-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432773 [ 9 ] Bug #2432774 - rust-reqsign-file-read-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432774 [ 10 ] Bug #2432775 - rust-reqsign-command-execute-tokio-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432775 [ 11 ] Bug #2432776 - rust-reqsign-aws-v4-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432776 [ 12 ] Bug #2432777 - rust-reqsign-huaweicloud-obs-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432777 [ 13 ] Bug #2432779 - rust-reqsign-tencent-cos-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2432779 [ 14 ] Bug #2436289 - rust-ambient-id-0.0.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=2436289 [ 15 ] Bug #2437941 - rust-astral-reqwest-middleware-0.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437941 [ 16 ] Bug #2437942 - rust-astral-reqwest-retry-0.9.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437942 [ 17 ] Bug #2437976 - rust-astral_async_http_range_reader-0.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2437976 [ 18 ] Bug #2439752 - rust-native-tls-0.2.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2439752 [ 19 ] Bug #2450541 - python-uv-build-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450541 [ 20 ] Bug #2450582 - uv-0.11.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2450582 [ 21 ] Bug #2451103 - Review Request: rust-webpki-root-certs - Mozilla trusted certificate authorities in self-signed X.509 format https://bugzilla.redhat.com/show_bug.cgi?id=2451103 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b8b59dcf44' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for rust-reqsign-azure-storage in Fedora 44 addressing breaking changes to TLS certificates and networking stack.. rust-reqsign-azure-storage,tls update,networking change,security advisory. . Severity: Important. LinuxSecurity.com Team
An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: openvswitch2.17 security update Advisory ID: RHSA-2023:1765-01 Product: Fast Datapath Advisory URL: https://access.redhat.com/errata/RHSA-2023:1765 Issue date: 2023-04-13 CVE Names: CVE-2023-1668 ==================================================================== 1. Summary: An update for openvswitch2.17 is now available in Fast Datapath for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Fast Datapath for Red Hat Enterprise Linux 8 - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Open vSwitch provides standard network bridging functions and support for the OpenFlow protocol for remote per-flow control of traffic. Security Fix(es): * openvswitch: ip proto 0 triggers incorrect handling (CVE-2023-1668) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Bug Fix(es): * [23.C RHEL-8] Fast Datapath Release (BZ#2177685) * [CT] Inner header of ICMP related traffic does not get DNATed (BZ#2178200) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2137666 -CVE-2023-1668 openvswitch: ip proto 0 triggers incorrect handling 2177685 - [23.C RHEL-8] Fast Datapath Release 2178200 - [CT] Inner header of ICMP related traffic does not get DNATed 6. Package List: Fast Datapath for Red Hat Enterprise Linux8: Source: openvswitch2.17-2.17.0-88.el8fdp.src.rpm aarch64: network-scripts-openvswitch2.17-2.17.0-88.el8fdp.aarch64.rpm openvswitch2.17-2.17.0-88.el8fdp.aarch64.rpm openvswitch2.17-debuginfo-2.17.0-88.el8fdp.aarch64.rpm openvswitch2.17-debugsource-2.17.0-88.el8fdp.aarch64.rpm openvswitch2.17-devel-2.17.0-88.el8fdp.aarch64.rpm openvswitch2.17-ipsec-2.17.0-88.el8fdp.aarch64.rpm python3-openvswitch2.17-2.17.0-88.el8fdp.aarch64.rpm python3-openvswitch2.17-debuginfo-2.17.0-88.el8fdp.aarch64.rpm noarch: openvswitch2.17-test-2.17.0-88.el8fdp.noarch.rpm ppc64le: network-scripts-openvswitch2.17-2.17.0-88.el8fdp.ppc64le.rpm openvswitch2.17-2.17.0-88.el8fdp.ppc64le.rpm openvswitch2.17-debuginfo-2.17.0-88.el8fdp.ppc64le.rpm openvswitch2.17-debugsource-2.17.0-88.el8fdp.ppc64le.rpm openvswitch2.17-devel-2.17.0-88.el8fdp.ppc64le.rpm openvswitch2.17-ipsec-2.17.0-88.el8fdp.ppc64le.rpm python3-openvswitch2.17-2.17.0-88.el8fdp.ppc64le.rpm python3-openvswitch2.17-debuginfo-2.17.0-88.el8fdp.ppc64le.rpm s390x: network-scripts-openvswitch2.17-2.17.0-88.el8fdp.s390x.rpm openvswitch2.17-2.17.0-88.el8fdp.s390x.rpm openvswitch2.17-debuginfo-2.17.0-88.el8fdp.s390x.rpm openvswitch2.17-debugsource-2.17.0-88.el8fdp.s390x.rpm openvswitch2.17-devel-2.17.0-88.el8fdp.s390x.rpm openvswitch2.17-ipsec-2.17.0-88.el8fdp.s390x.rpm python3-openvswitch2.17-2.17.0-88.el8fdp.s390x.rpm python3-openvswitch2.17-debuginfo-2.17.0-88.el8fdp.s390x.rpm x86_64: network-scripts-openvswitch2.17-2.17.0-88.el8fdp.x86_64.rpm openvswitch2.17-2.17.0-88.el8fdp.x86_64.rpm openvswitch2.17-debuginfo-2.17.0-88.el8fdp.x86_64.rpm openvswitch2.17-debugsource-2.17.0-88.el8fdp.x86_64.rpm openvswitch2.17-devel-2.17.0-88.el8fdp.x86_64.rpm openvswitch2.17-ipsec-2.17.0-88.el8fdp.x86_64.rpm python3-openvswitch2.17-2.17.0-88.el8fdp.x86_64.rpm python3-openvswitch2.17-debuginfo-2.17.0-88.el8fdp.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2023-1668 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZDfaINzjgjWX9erEAQiMWg//d9j3aPfYak2tV8EI9xSItFv6WpoLCB4y rC4956fWN4hzmKSYHnrw4uvhEVPf1hsue5zJIO0VHlT5MqmwDn6wDjP//V8GC4lE JUmTZHQMcWlt/dZQm2mh2I0n4oR0y/4gY3f4kKXUPM0Mg1S1MAEahmm4S9NWAGF7 f2nVf1b1PACs3E4QfStldiawDDmwPCe8zsaaCCVL9sIR/KZI6yoZOJu8RjCWHac6 0kw6LpIDjOwoJ/tc2JMoP/1JORzA+6S0Lrg+ZI8Kd0qwL/6KOcBpgCYXYD1eyp60 18At7rFMonFlOW2JG8A0ewe6MZDXoyJsWjNZl2xPXsa1tHT/jnK29EbXr14X40kx /fpSdiRr1zSfChCPFVedxaBWY9L2UoAUGx6TnGXNuNC1UTM0pseMfUMy7TAC4ZV4 o6qH7hC4a2W1tOxndAq8MWGeh49pq1n/EjwF+deKU73ke834pwDfQFRO03YB4jjM myicYpRKimbd6TzFhunIaKJcEYGX5Jna6nBd50a2b5mfHOS/FKah2fmROTK8bRv8 202/9CCCGWSzE3IlUT9JcamNcdre0xZHmkYXpyLTuW0keXp+wlb19aVR42ZtRq6L U+TiznvhSU3XuH7KxJJS0AQdi+zyBWSR24ADbE70nQfu0nP6hupQBo6Eg2dnhdva w5iYSsJ1/AA=J+dO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.