Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
nginx-mod-headers-more: Rebuild for 1.30.3 nginx-mod-brotli: Rebuild for 1.30.3 nginx-mod-vts:. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-9d7328702e 2026-06-27 00:54:50.049683+00:00 -------------------------------------------------------------------------------- Name : nginx-mod-modsecurity Product : Fedora 43 Version : 1.0.4 Release : 12.fc43 URL : https://github.com/SpiderLabs/ModSecurity-nginx Summary : ModSecurity v3 nginx connector Description : The ModSecurity-nginx connector is the connection point between nginx and libmodsecurity (ModSecurity v3). Said another way, this project provides a communication channel between nginx and libmodsecurity. This connector is required to use LibModSecurity with nginx. The ModSecurity-nginx connector takes the form of an nginx module. The module simply serves as a layer of communication between nginx and ModSecurity -------------------------------------------------------------------------------- Update Information: nginx-mod-headers-more: Rebuild for 1.30.3 nginx-mod-brotli: Rebuild for 1.30.3 nginx-mod-vts: Rebuild for 1.30.3 nginx-mod-modsecurity: Rebuild for 1.30.3 nginx-mod-fancyindex: Rebuild for 1.30.3 nginx-mod-naxsi: Rebuild for 1.30.3 nginx: update to 1.30.3 fixes CVE-2026-42055, CVE-2026-42530 and CVE-2026-48142 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 17 2026 Felix Kaechele - 1.0.4-12 - Rebuild for 1.30.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9d7328702e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5c5f4f40a4 2026-06-05 04:25:00.359000+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-chameleon-gnupg Product : Fedora 44 Version : 0.13.1 Release : 13.fc44 URL : https://crates.io/crates/sequoia-chameleon-gnupg Summary : Sequoia's reimplementation of the GnuPG interface Description : Sequoia's reimplementation of the GnuPG interface. -------------------------------------------------------------------------------- Update Information: Update the sequoia-wot crate to version 0.15.2. Update the sequoia-keystore crate to version 0.7.3. This includes a rebuild of all dependent applications to address three low- severity security vulnerabilities in sequoia-wot: https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/77605b2f https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/81210321 https://gitlab.com/sequoia-pgp/sequoia-wot/-/commit/dd2ffb50 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Fabio Valentini - 0.13.1-13 - Bump sequoia-wot dependency from 0.14 to 0.15 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2356514 - Package NEWS https://bugzilla.redhat.com/show_bug.cgi?id=2356514 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c5f4f40a4' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild rust-sequoia-chameleon-gnupg with rust-tar 0.4.45 for CVE-2026-33056. Update rust-pty-process to 0.5.3, and adjust the dev-dependency in rust-sequoia- chameleon-gnupg to allow it.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-936a74ccc0 2026-03-29 00:48:39.566648+00:00 -------------------------------------------------------------------------------- Name : rust-sequoia-chameleon-gnupg Product : Fedora 43 Version : 0.13.1 Release : 11.fc43 URL : https://crates.io/crates/sequoia-chameleon-gnupg Summary : Sequoia's reimplementation of the GnuPG interface Description : Sequoia's reimplementation of the GnuPG interface. -------------------------------------------------------------------------------- Update Information: Rebuild rust-sequoia-chameleon-gnupg with rust-tar 0.4.45 for CVE-2026-33056. Update rust-pty-process to 0.5.3, and adjust the dev-dependency in rust-sequoia- chameleon-gnupg to allow it. -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 23 2026 Benjamin A. Beasley - 0.13.1-11 - Rebuilt with rust-tar 0.4.45 for CVE-2026-33056 * Tue Mar 17 2026 Benjamin A. Beasley - 0.13.1-10 - Update pty-process dev-dependency from v0.4 to v0.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2344560 - rust-pty-process-0.5.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2344560 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-936a74ccc0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild for CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-be54db24e3 2025-12-30 01:14:05.828904+00:00 -------------------------------------------------------------------------------- Name : golang-github-evanw-esbuild Product : Fedora 42 Version : 0.24.2 Release : 4.fc42 URL : https://github.com/evanw/esbuild Summary : Fast JavaScript bundler and minifier Description : This is a JavaScript bundler and minifier. It packages up JavaScript and TypeScript code for distribution on the web. -------------------------------------------------------------------------------- Update Information: Rebuild for CVEs -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 21 2025 W. Michael Petullo - 0.24.2-4 - Rebuild for CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2398272 - CVE-2025-56648 golang-github-evanw-esbuild: Parcel Origin Validation Error [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398272 [ 2 ] Bug #2398722 - CVE-2025-47910 golang-github-evanw-esbuild: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398722 [ 3 ] Bug #2407928 - CVE-2025-58189 golang-github-evanw-esbuild: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2407928 [ 4 ] Bug #2409398 - CVE-2025-61723 golang-github-evanw-esbuild: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2409398 [ 5 ] Bug #2410348 - CVE-2025-58185 golang-github-evanw-esbuild: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2410348 [ 6 ] Bug #2411249 - CVE-2025-58188golang-github-evanw-esbuild: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2411249 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-be54db24e3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild for CVEs. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-4068748872 2025-12-30 00:38:13.645663+00:00 -------------------------------------------------------------------------------- Name : golang-github-evanw-esbuild Product : Fedora 43 Version : 0.24.2 Release : 6.fc43 URL : https://github.com/evanw/esbuild Summary : Fast JavaScript bundler and minifier Description : This is a JavaScript bundler and minifier. It packages up JavaScript and TypeScript code for distribution on the web. -------------------------------------------------------------------------------- Update Information: Rebuild for CVEs -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 21 2025 W. Michael Petullo - 0.24.2-6 - Rebuild for CVEs -------------------------------------------------------------------------------- References: [ 1 ] Bug #2408203 - CVE-2025-58189 golang-github-evanw-esbuild: go crypto/tls ALPN negotiation error contains attacker controlled information [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2408203 [ 2 ] Bug #2409673 - CVE-2025-61723 golang-github-evanw-esbuild: Quadratic complexity when parsing some invalid inputs in encoding/pem [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2409673 [ 3 ] Bug #2410625 - CVE-2025-58185 golang-github-evanw-esbuild: Parsing DER payload can cause memory exhaustion in encoding/asn1 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2410625 [ 4 ] Bug #2411522 - CVE-2025-58188 golang-github-evanw-esbuild: Panic when validating certificates with DSA public keys in crypto/x509 [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2411522 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-4068748872' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-15f6a132bf 2025-09-23 01:47:24.731858+00:00 -------------------------------------------------------------------------------- Name : checkpointctl Product : Fedora 41 Version : 1.4.0 Release : 3.fc41 URL : https://github.com/checkpoint-restore/checkpointctl Summary : A command-line tool for in-depth analysis of container checkpoints Description : The checkpointctl command can be used for in-depth analysis of container checkpoints created with Podman and Kubernetes. -------------------------------------------------------------------------------- Update Information: Rebuild -------------------------------------------------------------------------------- ChangeLog: * Sun Sep 14 2025 Radostin Stoyanov - 1:1.4.0-3 - Rebuild * Sun Sep 14 2025 Radostin Stoyanov - 1:1.4.0-2 - Bump epoch to 1 * Fri Sep 5 2025 Radostin Stoyanov - 1:1.4.0-1 - Rebuild with epoch 1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2391649 - CVE-2025-58058 checkpointctl: github.com/ulikunitz/xz leaks memory [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2391649 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-15f6a132bf' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-467e4d1489 2025-09-11 01:18:51.472351+00:00 -------------------------------------------------------------------------------- Name : rust-monitord-exporter Product : Fedora 41 Version : 0.4.1 Release : 2.fc41 URL : https://crates.io/crates/monitord-exporter Summary : Let Prometheus know how happy your systemd is Description : monitord-exporter is a Prometheus exporter using monitord to export statistic to Prometheus collectors. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 2 2025 Fabio Valentini - 0.4.1-2 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-467e4d1489' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b1dd6d1575 2025-09-11 01:18:51.472348+00:00 -------------------------------------------------------------------------------- Name : rust-crypto-auditing-agent Product : Fedora 41 Version : 0.2.3 Release : 3.fc41 URL : https://crates.io/crates/crypto-auditing-agent Summary : Event collector agent for crypto-auditing project Description : Event collector agent for crypto-auditing project. -------------------------------------------------------------------------------- Update Information: Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160. -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 2 2025 Fabio Valentini - 0.2.3-3 - Rebuild with tracing-subscriber v0.3.20 for CVE-2025-58160 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2310970 - rust-crypto-auditing-client-0.2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2310970 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b1dd6d1575' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.