Rebuild rust-sequoia-chameleon-gnupg with rust-tar 0.4.45 for CVE-2026-33056. Update rust-pty-process to 0.5.3, and adjust the dev-dependency in rust-sequoia- chameleon-gnupg to allow it.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-936a74ccc0 2026-03-29 00:48:39.566648+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-chameleon-gnupg Product : Fedora 43 Version : 0.13.1 Release : 11.fc43 URL : https://crates.io/crates/sequoia-chameleon-gnupg Summary : Sequoia's reimplementation of the GnuPG interface Description : Sequoia's reimplementation of the GnuPG interface. -------------------------------------------------------------------------------- Update Information: Rebuild rust-sequoia-chameleon-gnupg with rust-tar 0.4.45 for CVE-2026-33056. Update rust-pty-process to 0.5.3, and adjust the dev-dependency in rust-sequoia- chameleon-gnupg to allow it. -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 23 2026 Benjamin A. Beasley - 0.13.1-11 - Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 * Tue Mar 17 2026 Benjamin A. Beasley - 0.13.1-10 - Update pty-process dev-dependency from v0.4 to v0.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344560 - rust-pty-process-0.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2344560 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-936a74ccc0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild for CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-be54db24e3 2025-12-30 01:14:05.828904+00:00 -------------------------------------------------------------------------------- Name : golang-github-evanw-esbuild Product : Fedora 42 Version : 0.24.2 Release : 4.fc42 URL : https://github.com/evanw/esbuild Summary : Fast JavaScript bundler and minifier Description : This is a JavaScript bundler and minifier. It packages up JavaScript and TypeScript code for distribution on the web. -------------------------------------------------------------------------------- Update Information: Rebuild for CVEs -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 21 2025 W. Michael Petullo - 0.24.2-4 - Rebuild for CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398272 - CVE-2025-56648 golang-github-evanw-esbuild: Parcel Origin Validation Error [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398272 [ 2 ] Bug #2398722 - CVE-2025-47910 golang-github-evanw-esbuild: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398722 [ 3 ] Bug #2407928 - CVE-2025-58189 golang-github-evanw-esbuild: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407928 [ 4 ] Bug #2409398 - CVE-2025-61723 golang-github-evanw-esbuild: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409398 [ 5 ] Bug #2410348 - CVE-2025-58185 golang-github-evanw-esbuild: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410348 [ 6 ] Bug #2411249 - CVE-2025-58188golang-github-evanw-esbuild: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411249 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-be54db24e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild for CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4068748872 2025-12-30 00:38:13.645663+00:00 -------------------------------------------------------------------------------- Name : golang-github-evanw-esbuild Product : Fedora 43 Version : 0.24.2 Release : 6.fc43 URL : https://github.com/evanw/esbuild Summary : Fast JavaScript bundler and minifier Description : This is a JavaScript bundler and minifier. It packages up JavaScript and TypeScript code for distribution on the web. -------------------------------------------------------------------------------- Update Information: Rebuild for CVEs -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 21 2025 W. Michael Petullo - 0.24.2-6 - Rebuild for CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408203 - CVE-2025-58189 golang-github-evanw-esbuild: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408203 [ 2 ] Bug #2409673 - CVE-2025-61723 golang-github-evanw-esbuild: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409673 [ 3 ] Bug #2410625 - CVE-2025-58185 golang-github-evanw-esbuild: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410625 [ 4 ] Bug #2411522 - CVE-2025-58188 golang-github-evanw-esbuild: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411522 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-4068748872' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-15f6a132bf 2025-09-23 01:47:24.731858+00:00 -------------------------------------------------------------------------------- Name : checkpointctl Product : Fedora 41 Version : 1.4.0 Release : 3.fc41 URL : https://github.com/checkpoint-restore/checkpointctl Summary : A command-line tool for in-depth analysis of container checkpoints Description : The checkpointctl command can be used for in-depth analysis of container checkpoints created with Podman and Kubernetes. -------------------------------------------------------------------------------- Update Information: Rebuild -------------------------------------------------------------------------------- ChangeLog: * Sun Sep 14 2025 Radostin Stoyanov - 1:1.4.0-3 - Rebuild * Sun Sep 14 2025 Radostin Stoyanov - 1:1.4.0-2 - Bump epoch to 1 * Fri Sep 5 2025 Radostin Stoyanov - 1:1.4.0-1 - Rebuild with epoch 1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2391649 - CVE-2025-58058 checkpointctl: github.com/ulikunitz/xz leaks memory [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391649 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-15f6a132bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-467e4d1489 2025-09-11 01:18:51.472351+00:00 -------------------------------------------------------------------------------- Name : rust-monitord-exporter Product : Fedora 41 Version : 0.4.1 Release : 2.fc41 URL : https://crates.io/crates/monitord-exporter Summary : Let Prometheus know how happy your systemd is Description : monitord-exporter is a Prometheus exporter using monitord to export statistic to Prometheus collectors. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 2 2025 Fabio Valentini - 0.4.1-2 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-467e4d1489' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b1dd6d1575 2025-09-11 01:18:51.472348+00:00 -------------------------------------------------------------------------------- Name : rust-crypto-auditing-agent Product : Fedora 41 Version : 0.2.3 Release : 3.fc41 URL : https://crates.io/crates/crypto-auditing-agent Summary : Event collector agent for crypto-auditing project Description : Event collector agent for crypto-auditing project. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 2 2025 Fabio Valentini - 0.2.3-3 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2310970 - rust-crypto-auditing-client-0.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2310970 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b1dd6d1575' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild for CVE-2024-12224, CVE-2025-4574. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-26640e9e35 2025-06-17 02:28:46.265681+00:00 -------------------------------------------------------------------------------- Name : rust-git-interactive-rebase-tool Product : Fedora 41 Version : 2.4.1 Release : 9.fc41 URL : https://crates.io/crates/git-interactive-rebase-tool Summary : Full-featured terminal-based sequence editor for Git interactive rebase Description : Full-featured terminal-based sequence editor for Git interactive rebase. -------------------------------------------------------------------------------- Update Information: Rebuild for CVE-2024-12224, CVE-2025-4574 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 8 2025 Benjamin Gilbert - 2.4.1-9 - Rebuild for CVE-2024-12224, CVE-2025-4574 (rhbz#2370599, rhbz#2366573) * Sun Jan 19 2025 Fedora Release Engineering - 2.4.1-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2366573 - CVE-2025-4574 rust-git-interactive-rebase-tool: crossbeam-channel Vulnerable to Double Free on Drop [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366573 [ 2 ] Bug #2370599 - CVE-2024-12224 rust-git-interactive-rebase-tool: idna accepts Punycode labels that do not produce any non-ASCII when decoded [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2370599 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-26640e9e35' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild against idna 1.0+ for CVE-2024-12224. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e375586840 2025-06-17 02:28:46.265688+00:00 -------------------------------------------------------------------------------- Name : fido-device-onboard Product : Fedora 41 Version : 0.5.1 Release : 3.fc41 URL : https://github.com/fdo-rs/fido-device-onboard-rs Summary : A rust implementation of the FIDO Device Onboard Specification Description : A rust implementation of the FIDO Device Onboard Specification. -------------------------------------------------------------------------------- Update Information: Rebuild against idna 1.0+ for CVE-2024-12224 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 8 2025 Peter Robinson - 0.5.1-3 - Rebuild against idna 1.0+ for CVE-2024-12224 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2370564 - CVE-2024-12224 fido-device-onboard: idna accepts Punycode labels that do not produce any non-ASCII when decoded [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2370564 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e375586840' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.