Explore top 10 tips to secure your open-source projects now. Read More
×
Version 2.5.2 of opam fixes CVE-2026-57825. See https://github.com/ocaml/opam/releases/tag/2.5.2 for more information.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fb48505840 2026-07-19 03:55:06.729078+00:00 -------------------------------------------------------------------------------- Name : opam Product : Fedora 43 Version : 2.5.2 Release : 1.fc43 URL : https://opam.ocaml.org/ Summary : Source-based package manager for OCaml Description : Opam is a source-based package manager for OCaml. It supports multiple simultaneous compiler installations, flexible package constraints, and a Git-friendly development workflow. -------------------------------------------------------------------------------- Update Information: Version 2.5.2 of opam fixes CVE-2026-57825. See https://github.com/ocaml/opam/releases/tag/2.5.2 for more information. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 10 2026 Jerry James - 2.5.2-1 - Version 2.5.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fb48505840' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For Debian 12 bookworm, this problem has been fixed in version. Debian LTS Advisory DLA-4684-1
Kate Deplaix reported that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. Installing files through .install files did not check symlinks resolution on the target path, which could result in directory traversal out of the package area. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6386-1
update to 2.34.7: fixes high GHSA-vh5x-56v6-4368 and moderate GHSA- gr92-w2r5-qw5p https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in- lix-and-nix/77407 https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-65ce3da435 2026-05-14 00:25:16.447772+00:00 -------------------------------------------------------------------------------- Name : nix Product : Fedora 44 Version : 2.34.7 Release : 2.fc44 URL : https://github.com/NixOS/nix Summary : A purely functional package manager Description : Nix is a purely functional package manager. It allows multiple versions of a package to be installed side-by-side, ensures that dependency specifications are complete, supports atomic upgrades and rollbacks, allows non-root users to install software, and has many other features. It is the basis of the NixOS Linux distribution, but it can be used equally well under other Unix systems. See the README.fedora.md file for setup instructions. -------------------------------------------------------------------------------- Update Information: update to 2.34.7: fixes high GHSA-vh5x-56v6-4368 and moderate GHSA- gr92-w2r5-qw5p https://discourse.nixos.org/t/security-advisory-local-privilege-escalation-in- lix-and-nix/77407 https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368 -------------------------------------------------------------------------------- ChangeLog: * Tue May 5 2026 Jens Petersen - 2.34.7-2 - unbreak the build with meson-1.11 * Tue May 5 2026 Jens Petersen - 2.34.7-1 - update to 2.34.7 (rhbz#2457630) fixes GHSA-vh5x-56v6-4368 - https://discourse.nixos.org/t/security-advisory-local-privilege- escalation-in-lix-and-nix/77407 -https://github.com/NixOS/nix/security/advisories/GHSA-vh5x-56v6-4368 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2457630 - nix-2.34.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=2457630 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-65ce3da435' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Andrew Nesbitt discovered that .install file directives were insufficiently restricted in OPAM, a package manager for OCaml. This could result in directory traversal out of the package area. For the oldstable distribution (bookworm), this problem has been fixed in version 2.1.2-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6216-1
update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860): https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6c1a1c78c1 2026-04-17 00:53:26.068864+00:00 -------------------------------------------------------------------------------- Name : nix Product : Fedora 43 Version : 2.31.4 Release : 1.fc43 URL : https://github.com/NixOS/nix Summary : A purely functional package manager Description : Nix is a purely functional package manager. It allows multiple versions of a package to be installed side-by-side, ensures that dependency specifications are complete, supports atomic upgrades and rollbacks, allows non-root users to install software, and has many other features. It is the basis of the NixOS Linux distribution, but it can be used equally well under other Unix systems. See the README.fedora.md file for setup instructions. -------------------------------------------------------------------------------- Update Information: update to 2.31.4 fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860): https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Jens Petersen - 2.31.4-1 - update to 2.31.4 - fixes nix-daemon critical GHSA-g3g9-5vj6-r3gj (CVE-2026-39860) * Wed Apr 8 2026 Jens Petersen - 2.31.3-2 - sync readme/gating/tests improvements from rawhide/f44 - document nixGL - enable gating on tier0 and install CI tests -------------------------------------------------------------------------------- References: [ 1 ] Bug #2456893 - CVE-2026-39860 nix: privilege escalation via symlink following during output registration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456893 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6c1a1c78c1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client. Update to upstream release 5.4.0.0. Full changelog.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-6072c6888a 2026-03-13 00:15:54.963939+00:00 -------------------------------------------------------------------------------- Name : dnf5 Product : Fedora 44 Version : 5.4.0.0 Release : 2.fc44 URL : https://github.com/rpm-software-management/dnf5 Summary : Command-line package manager Description : DNF5 is a command-line package manager that automates the process of installing, upgrading, configuring, and removing computer programs in a consistent manner. It supports RPM packages, modulemd modules, and comps groups & environments. -------------------------------------------------------------------------------- Update Information: This release fixes CVE-2026-3836 (a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client. Update to upstream release 5.4.0.0. Full changelog. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 10 2026 Petr Pisar - 5.4.0.0-2 - Fix a crash in dnf5daemon-server when receiving an unknown locale from a D-Bus client (CVE-2026-3836) (bug #2445771) * Mon Mar 2 2026 Petr Pisar - 5.4.0.0-1 - Fix segmentation fault in bash completion (bug #2443105) * Thu Feb 19 2026 Petr Pisar - 5.4.0.0-1 - Honor localpkg_gpgcheck in RPM transaction per-element policy (bug #2440722) * Tue Feb 17 2026 Packit - 5.4.0.0-1 - Update to version 5.4.0.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2445770 - CVE-2026-3836 dnf5: dnf5: Denial of Service via path traversal in D-Bus locale configuration https://bugzilla.redhat.com/show_bug.cgi?id=2445770 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6072c6888a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language- server to version 5.6.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-69a1acbbc0 2025-05-03 02:07:27.616707+00:00 -------------------------------------------------------------------------------- Name : nodejs-pnpm Product : Fedora 42 Version : 10.9.0 Release : 1.fc42 URL : https://pnpm.io Summary : Fast, disk space efficient package manager Description : A fast, disk space efficient package manager for NodeJS. -------------------------------------------------------------------------------- Update Information: Update pnpm to version 10.9.0 to fix CVE-2024-47829 and nodejs-bash-language- server to version 5.6.0 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 24 2025 Andreas Schneider - 10.9.0-1 - Update to version 10.9.0 - Fixes CVE-2024-47829 - resolves: rhbz#2361976 * Thu Apr 17 2025 ErrorNoInternet - 10.8.1-1 - Update to version 10.8.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2361976 - CVE-2024-47829 nodejs-pnpm: pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2361976 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-69a1acbbc0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.