Apply fixes for CVE-2025-8262 and CVE-2025-7783.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b19f3ed5f4 2025-08-08 01:11:45.710107+00:00 -------------------------------------------------------------------------------- Name : yarnpkg Product : Fedora 41 Version : 1.22.22 Release : 11.fc41 URL : https://github.com/yarnpkg/yarn Summary : Fast, reliable, and secure dependency management. Description : Fast, reliable, and secure dependency management. -------------------------------------------------------------------------------- Update Information: Apply fixes for CVE-2025-8262 and CVE-2025-7783. -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 30 2025 Sandro Mani - 1.22.22-11 - Refresh bundle - Drop patches obsoleted by new bundle - Add yarn-update-jest.prebundle.patch to update jest and avoid some vulerable dependencies - Apply fixes for CVE-2025-8262 and CVE-2025-8263 * Fri Jul 25 2025 Fedora Release Engineering - 1.22.22-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2382001 - CVE-2025-7783 yarnpkg: Unsafe random function in form-data [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2382001 [ 2 ] Bug #2382007 - CVE-2025-7783 yarnpkg: Unsafe random function in form-data [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2382007 [ 3 ] Bug #2382017 - CVE-2025-7783 yarnpkg: Unsafe random function in form-data [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2382017 [ 4 ] Bug #2382027 - CVE-2025-7783 yarnpkg: Unsafe random function in form-data [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2382027 [ 5 ] Bug #2383877 - CVE-2025-8262 yarnpkg: Yarn Regex Complexity Vulnerability [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2383877 [ 6 ] Bug #2383879 - CVE-2025-8262 yarnpkg: Yarn Regex Complexity Vulnerability [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2383879 [ 7 ] Bug #2383880 - CVE-2025-8262 yarnpkg: Yarn Regex Complexity Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2383880 [ 8 ] Bug #2383881 - CVE-2025-8262 yarnpkg: Yarn Regex Complexity Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2383881 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b19f3ed5f4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.0.1; fix RHBZ#1932066 (unsafe use of strncpy), fix RHBZ#1932066. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-17bf9d14f8 2021-09-24 20:04:10.608225 --------------------------------------------------------------------------------Name : libss7 Product : Fedora 35 Version : 2.0.1 Release : 1.fc35 URL : https://www.asterisk.org/ Summary : SS7 protocol services to applications Description : libss7 is a userspace library that is used for providing SS7 protocol services to applications. It has a working MTP2, MTP3, and ISUP for ITU and ANSI style SS7, however it was written in a manner that will easily allow support for other various national specific variants in the future. --------------------------------------------------------------------------------Update Information: Update to 2.0.1; fix RHBZ#1932066 (unsafe use of strncpy), fix RHBZ#1932066 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 27 2021 Benjamin A. Beasley 2.0.1-1 - Update to 2.0.1 (fix RHBZ#1932066) --------------------------------------------------------------------------------References: [ 1 ] Bug #1932066 - Cannot build with -Werror=stringop-truncation https://bugzilla.redhat.com/show_bug.cgi?id=1932066 [ 2 ] Bug #1998578 - libss7-2.0.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1998578 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-17bf9d14f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.