Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to 1.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3d1fcd4ffc 2026-06-23 01:06:46.785055+00:00 -------------------------------------------------------------------------------- Name : thorvg Product : Fedora 44 Version : 1.0.6 Release : 1.fc44 URL : https://www.thorvg.org/ Summary : Lightweight vector-based scenes and animation drawing library Description : ThorVG is an open-source graphics library designed for creating vector-based scenes and animations. It combines immense power with remarkable lightweight efficiency, as Thor embodies a dual meaning—symbolizing both thunderous strength and lightning-fast agility. Embracing the philosophy of simpler is better, the ThorVG project provides intuitive, user-friendly interfaces while maintaining a compact footprint and minimal overhead. The following list shows primitives that are supported by ThorVG: - Lines & Shapes: rectangles, circles, and paths with coordinate control - Filling: solid colors, linear & radial gradients, and path clipping - Stroking: stroke width, joins, caps, dash patterns, and trimming - Scene Management: retainable scene graph and object transformations - Composition: various blending and masking - Text: unicode characters with horizontal text layout using scalable fonts (TTF) - Images: SVG, JPG, PNG, WebP, and raw bitmaps - Effects: blur, drop shadow, fill, tint, tritone and color replacement - Animations: Lottie -------------------------------------------------------------------------------- Update Information: Update to 1.0.6 -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 14 2026 Benson Muite - 1.0.6-1 - Update to 1.0.6 * Sat Feb 14 2026 Benson Muite - 1.0.1-1 - Update to 1.0.1 rhbz#2433764 * Sat Jan 17 2026 Fedora Release Engineering - 0.15.16-2 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2483802 - CVE-2026-45729 thorvg: ThorVG: Denial of Service via untrusted SVG data processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483802 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3d1fcd4ffc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . ThorVG 1.0.6 update in Fedora 44 fixes security concerns, enhancing stability and efficiency in vector graphics processing.. Fedora thorvg Denial Of Service Vector Graphics Security. . Severity: Informational. LinuxSecurity.com Team
Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bb6bb5d1e4 2026-05-17 01:05:24.299228+00:00 -------------------------------------------------------------------------------- Name : libgit2_1.8 Product : Fedora 42 Version : 1.8.5 Release : 1.fc42 URL : https://libgit2.org/ Summary : C implementation of the Git core methods as a library with a solid API Description : libgit2 is a portable, pure C implementation of the Git core methods provided as a re-entrant linkable library with a solid API, allowing you to write native speed custom Git applications in any language with bindings. -------------------------------------------------------------------------------- Update Information: Update to version 1.8.5. Release notes: https://github.com/libgit2/libgit2/releases/tag/v1.8.5 -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2026 Fabio Valentini - 1.8.5-1 - Update to version 1.8.5 * Fri Jan 16 2026 Fedora Release Engineering - 1.8.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Thu Jul 24 2025 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Sun May 18 2025 Benjamin A. Beasley - 1.8.4-3 - Rebuilt for llhttp 9.3.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bb6bb5d1e4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed. For the stable distribution (trixie), this problem has been fixed in version 7:7.1.4-0+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6268-1
Update the openssl crate to version 0.10.78 and the openssl-sys crate to version 0.9.114. Release notes: openssl 0.10.77 / openssl-sys 0.9.113: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.77. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-16a3cea414 2026-05-02 01:51:01.714148+00:00 -------------------------------------------------------------------------------- Name : rust-openssl-sys Product : Fedora 43 Version : 0.9.114 Release : 1.fc43 URL : https://crates.io/crates/openssl-sys Summary : FFI bindings to OpenSSL Description : FFI bindings to OpenSSL. -------------------------------------------------------------------------------- Update Information: Update the openssl crate to version 0.10.78 and the openssl-sys crate to version 0.9.114. Release notes: openssl 0.10.77 / openssl-sys 0.9.113: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.77 openssl 0.10.78 / openssl-sys 0.9.114: https://github.com/rust-openssl/rust- openssl/releases/tag/openssl-v0.10.78 This addresses the following security advisories: GHSA-pqf5-4pqq-29f5 / CVE-2026-41676: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-pqf5-4pqq-29f5 GHSA-xmgf-hq76-4vx2 / CVE-2026-41677: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-xmgf-hq76-4vx2 GHSA-8c75-8mhr-p7r9 / CVE-2026-41678: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-8c75-8mhr-p7r9 GHSA-ghm9-cr32-g9qj / CVE-2026-41681: https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-ghm9-cr32-g9qj GHSA-hppc-g8h3-xhp3 (no CVE entry): https://github.com/rust-openssl/rust- openssl/security/advisories/GHSA-hppc-g8h3-xhp3 Affected applications still need to be rebuilt to pick up these fixes. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 23 2026 Fabio Valentini -0.9.114-1 - Update to version 0.9.114; Fixes RHBZ#2457692 * Mon Apr 13 2026 Fabio Valentini - 0.9.112-2 - Add upper bound to OpenSSL dependency since 4.0 is not supported yet -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-16a3cea414' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service or potentially the execution of arbitrary code if malformed PSP, JPEG 2000 or PSD files are opened. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4547-1
Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-kcmutils Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/kcmutils Summary : KDE Frameworks 6 Tier 3 addon with extra API to write KConfigModules Description : KCMUtils provides various classes to work with KCModules. KCModules can be created with the KConfigWidgets framework. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
1.26.11. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e77ad9d792 2026-04-01 00:56:24.864678+00:00 -------------------------------------------------------------------------------- Name : gstreamer1 Product : Fedora 43 Version : 1.26.11 Release : 1.fc43 URL : http://gstreamer.freedesktop.org/ Summary : GStreamer streaming media framework runtime Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plugins. -------------------------------------------------------------------------------- Update Information: 1.26.11 -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 30 2026 Gwyn Ciesla - 1.26.11-1 - 1.26.11 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e77ad9d792' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to version 0.16.3. Includes the fix for RUSTSEC-2026-0002.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-e153bc6b6a 2026-01-20 01:37:20.161994+00:00 -------------------------------------------------------------------------------- Name : rust-lru Product : Fedora 42 Version : 0.16.3 Release : 1.fc42 URL : https://crates.io/crates/lru Summary : LRU cache implementation Description : A LRU cache implementation. -------------------------------------------------------------------------------- Update Information: Update to version 0.16.3. Includes the fix for RUSTSEC-2026-0002. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 11 2026 Fabio Valentini - 0.16.3-1 - Update to version 0.16.3; Fixes RHBZ#2427568 * Mon Oct 20 2025 Fabio Valentini - 0.16.2-1 - Update to version 0.16.2; Fixes RHBZ#2403982 * Fri Sep 12 2025 Fabio Valentini - 0.16.1-1 - Update to version 0.16.1; Fixes RHBZ#2394055 * Wed Aug 13 2025 Fabio Valentini - 0.16.0-1 - Update to version 0.16.0; Fixes RHBZ#2359224 * Fri Jul 25 2025 Fedora Release Engineering - 0.14.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e153bc6b6a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.