Update to 3.6.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3a9536df40 2026-04-25 01:21:36.171769+00:00 -------------------------------------------------------------------------------- Name : mbedtls Product : Fedora 44 Version : 3.6.6 Release : 1.fc44 URL : https://www.trustedfirmware.org/projects/mbed-tls Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. -------------------------------------------------------------------------------- Update Information: Update to 3.6.6 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Peter Robinson - 3.6.6-1 - Update to 3.6.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454030 - CVE-2026-25833 mbedtls: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454030 [ 2 ] Bug #2454045 - CVE-2026-34874 mbedtls: NULL pointer dereference when setting a distinguished name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454045 [ 3 ] Bug #2454085 - CVE-2026-34871 mbedtls: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454085 [ 4 ] Bug #2454116 - CVE-2026-25835 mbedtls: PSA random generator cloning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454116 [ 5 ] Bug #2454193 - CVE-2026-34873 mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454193 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3a9536df40' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 3.6.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8c332fbf00 2026-04-10 00:59:15.834486+00:00 -------------------------------------------------------------------------------- Name : mbedtls Product : Fedora 43 Version : 3.6.6 Release : 1.fc43 URL : https://www.trustedfirmware.org/projects/mbed-tls Summary : Light-weight cryptographic and SSL/TLS library Description : Mbed TLS is a light-weight open source cryptographic and SSL/TLS library written in C. Mbed TLS makes it easy for developers to include cryptographic and SSL/TLS capabilities in their (embedded) applications with as little hassle as possible. -------------------------------------------------------------------------------- Update Information: Update to 3.6.6 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2026 Peter Robinson - 3.6.6-1 - Update to 3.6.6 * Fri Jan 16 2026 Fedora Release Engineering - 3.6.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2454030 - CVE-2026-25833 mbedtls: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454030 [ 2 ] Bug #2454045 - CVE-2026-34874 mbedtls: NULL pointer dereference when setting a distinguished name [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454045 [ 3 ] Bug #2454085 - CVE-2026-34871 mbedtls: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454085 [ 4 ] Bug #2454116 - CVE-2026-25835 mbedtls: PSA random generator cloning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454116 [ 5 ] Bug #2454193 - CVE-2026-34873 mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454193 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8c332fbf00' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.