fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fbeaecb457 2026-05-13 21:26:39.337184+00:00 -------------------------------------------------------------------------------- Name : nano Product : Fedora 42 Version : 8.3 Release : 4.fc42 URL : https://www.nano-editor.org Summary : A small text editor Description : GNU nano is a small and friendly text editor. -------------------------------------------------------------------------------- Update Information: fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Luk\u0161 Zaoral - 8.3-4 - fix CVE-2026-6842 and CVE-29026-6843 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455127 - [Security] Format String Vulnerability in nano's statusline() via errormessage Buffer https://bugzilla.redhat.com/show_bug.cgi?id=2455127 [ 2 ] Bug #2460502 - CVE-2026-6842 nano: nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460502 [ 3 ] Bug #2460503 - CVE-2026-6843 nano: nano: Format string vulnerability leads to Denial of Service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460503 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fbeaecb457' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update for Fedora 42 nano resolves critical issues with two CVEs ensuring enhanced security against attacks.. Fedora update nano critical fix CVEs exploit. . Severity: Critical. LinuxSecurity.com Team
fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d0a0f1c3d2 2026-05-07 01:08:17.601152+00:00 -------------------------------------------------------------------------------- Name : nano Product : Fedora 43 Version : 8.5 Release : 3.fc43 URL : https://www.nano-editor.org Summary : A small text editor Description : GNU nano is a small and friendly text editor. -------------------------------------------------------------------------------- Update Information: fix CVE-2026-6842 and CVE-29026-6843 Resolves: CVE-2026-6842 Resolves: CVE-2026-6843 Resolves: rhbz#2455127 Resolves: rhbz#2455314 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 30 2026 Luk\u0161 Zaoral - 8.5-3 - fix CVE-2026-6842 and CVE-29026-6843 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455127 - [Security] Format String Vulnerability in nano's statusline() via errormessage Buffer https://bugzilla.redhat.com/show_bug.cgi?id=2455127 [ 2 ] Bug #2460502 - CVE-2026-6842 nano: nano: Local attacker can inject malicious .desktop launcher due to insecure directory permissions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460502 [ 3 ] Bug #2460503 - CVE-2026-6843 nano: nano: Format string vulnerability leads to Denial of Service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460503 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d0a0f1c3d2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Nano text editor for Fedora 43 updated to fix critical issues including Denial of Service vulnerabilities.. Fedora nano update CVE-2026-6842 CVE-2026-6843. . Severity: Important. LinuxSecurity.com Team
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-ktexteditor Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/ktexteditor Summary : KDE Frameworks 6 Tier 3 with advanced embeddable text editor Description : KTextEditor provides a powerful text editor component that you can embed in your application, either as a KPart or using the KF6::TextEditor library (if you need more control). The text editor component contains many useful features, from syntax highlighting and automatic indentation to advanced scripting support, making it suitable for everything from a simple embedded text-file editor to an advanced IDE. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
rust-which 8.0.0 Add new Sys trait to allow abstracting over the underlying filesystem. Particularly useful for wasm32-unknown-unknown targets. Thanks @dsherret for this contribution to which! Add more debug level tracing for otherwise silent I/O errors.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-0cde7282be 2025-07-10 15:21:50.193768+00:00 -------------------------------------------------------------------------------- Name : helix Product : Fedora 42 Version : 25.01.1 Release : 6.fc42 URL : https://helix-editor.com/ Summary : A post-modern modal text editor written in Rust Description : A Kakoune / Neovim inspired editor, written in Rust. -------------------------------------------------------------------------------- Update Information: rust-which 8.0.0 Add new Sys trait to allow abstracting over the underlying filesystem. Particularly useful for wasm32-unknown-unknown targets. Thanks @dsherret for this contribution to which! Add more debug level tracing for otherwise silent I/O errors. Call the NonFatalHandler in more places to catch previously ignored I/O errors. Remove use of the either dependency. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 25 2025 Benjamin A. Beasley - 25.01.1-6 - Allow which 8 * Thu Jun 12 2025 blinxen - 25.01.1-5 - Add weak dependency on clipboard tools (rhbz#2372518) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2370374 - rust-which-8.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2370374 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-0cde7282be' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 29.4, fixing CVE-2024-39331. Update to Emacs 29.4, fixing CVE-2024-39331.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-3fedeba41f 2024-07-02 01:23:40.345986 -------------------------------------------------------------------------------- Name : emacs Product : Fedora 39 Version : 29.4 Release : 2.fc39 URL : Summary : GNU Emacs text editor Description : Emacs is a powerful, customizable, self-documenting, modeless text editor. Emacs contains special code editing features, a scripting language (elisp), and the capability to read mail, news, and more without leaving the editor. This package provides an emacs binary with support for X windows. -------------------------------------------------------------------------------- Update Information: Update to version 29.4, fixing CVE-2024-39331. Update to Emacs 29.4, fixing CVE-2024-39331. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 25 2024 Peter Oliver - 1:29.4-2 - Update to version 29.4. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2293788 - emacs-29.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2293788 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-3fedeba41f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ce2936b568 2024-05-26 01:25:15.719720 -------------------------------------------------------------------------------- Name : rust-lino Product : Fedora 40 Version : 0.10.0 Release : 9.fc40 URL : Summary : Command line text editor with notepad like key bindings Description : A command line text editor with notepad like key bindings. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.10.0-9 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ce2936b568' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-426b3a500d 2023-11-03 18:20:20.950662 -------------------------------------------------------------------------------- Name : ckeditor Product : Fedora 39 Version : 4.22.1 Release : 1.fc39 URL : https://ckeditor.com/ Summary : WYSIWYG text editor to be used inside web pages Description : CKEditor is a text editor to be used inside web pages. It's a WYSIWYG editor, which means that the text being edited on it looks as similar as possible to the results users have when publishing it. It brings to the web common editing features found on desktop editing applications like Microsoft Word and OpenOffice. -------------------------------------------------------------------------------- Update Information: - [4.22.0/4.22.1](https://ckeditor.com/cke4/release/CKEditor-4.22.0-4.22.1) - [4.21.0](https://ckeditor.com/cke4/release/CKEditor-4.21.0) - [GHSA- vh5c-xwqv-cv9g / CVE-2023-28439](- vh5c-xwqv-cv9g) - [4.20.2](https://ckeditor.com/cke4/release/CKEditor-4.20.2) - [4.20.1](https://ckeditor.com/cke4/release/CKEditor-4.20.1) -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 4.22.1-1 - Update to 4.22.1 (RHBZ #2149680) - GHSA-vh5c-xwqv-cv9g / CVE-2023-28439 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2149680 - ckeditor-4.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2149680 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-426b3a500d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- [4.22.0/4.22.1](https://ckeditor.com/cke4/release/CKEditor-4.22.0-4.22.1) - [4.21.0](https://ckeditor.com/cke4/release/CKEditor-4.21.0) - [GHSA- vh5c-xwqv-cv9g / CVE-2023-28439](- vh5c-xwqv-cv9g) - [4.20.2](https://ckeditor.com/cke4/release/CKEditor-4.20.2) -. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-79b5902a52 2023-10-04 15:50:14.488593 -------------------------------------------------------------------------------- Name : ckeditor Product : Fedora 38 Version : 4.22.1 Release : 1.fc38 URL : https://ckeditor.com/ Summary : WYSIWYG text editor to be used inside web pages Description : CKEditor is a text editor to be used inside web pages. It's a WYSIWYG editor, which means that the text being edited on it looks as similar as possible to the results users have when publishing it. It brings to the web common editing features found on desktop editing applications like Microsoft Word and OpenOffice. -------------------------------------------------------------------------------- Update Information: - [4.22.0/4.22.1](https://ckeditor.com/cke4/release/CKEditor-4.22.0-4.22.1) - [4.21.0](https://ckeditor.com/cke4/release/CKEditor-4.21.0) - [GHSA- vh5c-xwqv-cv9g / CVE-2023-28439](- vh5c-xwqv-cv9g) - [4.20.2](https://ckeditor.com/cke4/release/CKEditor-4.20.2) - [4.20.1](https://ckeditor.com/cke4/release/CKEditor-4.20.1) -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 26 2023 Shawn Iwinski - 4.22.1-1 - Update to 4.22.1 (RHBZ #2149680) - GHSA-vh5c-xwqv-cv9g / CVE-2023-28439 * Wed Jul 19 2023 Fedora Release Engineering - 4.20.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2149680 - ckeditor-4.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2149680 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-79b5902a52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.