Howdy EPEL packagers,
In accordance with the EPEL policy for minor version end-of-life [0],
EPEL 10.1 will be retired once RHEL 10.2 is released. Based on
historical RHEL release dates [1], this is expected to occur sometime
this month. After the retirement, MirrorManager will direct RHEL 10
users to the EPEL 10.2 repo instead.
Similar to a Fedora release end-of-life, any EPEL 10.1 updates that
have not been pushed to stable by the time of the retirement
will be marked as obsolete and will not be promoted to stable.
Additionally, any outstanding epel10.1 side tags will be removed
during the retirement.
If you have any questions, feel free to reply here or stop by the EPEL
Matrix channel [2].
[0] https://docs.fedoraproject.org/en-US/epel/epel-policy/#policy_for_end_of_li…
[1] https://access.redhat.com/articles/red-hat-enterprise-linux-release-dates
[2] https://matrix.to/#/#epel:fedoraproject.org
--
Carl George
Hi all,
Per the EPEL retirement policy:
https://docs.fedoraproject.org/en-US/epel/epel-policy-retirement/
I'd like to propose retiring python-django3 for security reason.
python-django3 is currently shipped in these two EPEL releases
https://src.fedoraproject.org/rpms/python-django3
- python-django3-3.2.25-1.el9
- python-django3-3.2.25-1.el8
it went EOL almost two years ago (no longer even listed on Django's
website: https://www.djangoproject.com/download/ - per
https://endoflife.date/django it went EOL on 1 April 2024)
and currently has a bunch of unfixable CVE bugs
https://bugzilla.redhat.com/buglist.cgi?bug_status=__open__&classification=…
e.g.
https://bugzilla.redhat.com/show_bug.cgi?id=2393801 (EPEL 9)
https://bugzilla.redhat.com/show_bug.cgi?id=2393800 (EPEL 8)
For EPEL 9 cobbler3.2 is the only package that cannot use the newer
(and still supported upstream) python-django4.2, but it has no
dependent itself and cobbler 3.3 is available - I would recommend
retiring cobbler3.2 as well (maintainer cc:ed)
❯ fedrq-pydeps-verbose.sh django -b epel9 | grep '< 4'
+ fedrq whatrequires 'python3dist(django)' -F multiline:source,requires
-b epel9
+ grep 'python3dist(django)'
cobbler3.2 : python3dist(django) < 4
python-django-mailman3 : (python3dist(django) < 4.3~~ with
python3dist(django) >= 3.2)
python-hyperkitty : (python3dist(django) < 4.3~~ with
python3dist(django) >= 3.2)
python-mailman-web : (python3dist(django) < 4.3~~ with
python3dist(django) >= 3.2)
python-postorius : (python3dist(django) < 4.3~~ with
python3dist(django) >= 3.2)
~/src/fedora
⬢ [fedora-toolbox:latest] ❯ fedrq whatrequires cobbler3.2 -b epel9
cobbler3.2-tests-3.2.3-2.el9.noarch
cobbler3.2-web-3.2.3-2.el9.noarch
~/src/fedora
⬢ [fedora-toolbox:latest] ❯ fedrq whatrequires cobbler -b epel9
cobbler-tests-3.3.7-15.el9.noarch
cobbler-tests-containers-3.3.7-15.el9.noarch
For epel8 I'm less sure what to do - I looked into branching python-
django4.2 for epel8 in the past and IIRC it's not trivial - but there
are more dependent packages that would be affected:
❯ fedrq-pydeps-verbose.sh django -b epel8
+ fedrq whatrequires 'python3dist(django)' -F multiline:source,requires
-b epel8
+ grep 'python3dist(django)'
cobbler3.2 : python3dist(django) < 4
python-django-contrib-comments : python3dist(django) >= 1.11
python-django-contrib-comments : python3dist(django) >= 1.11
kobo : python3dist(django) >= 1.11
kobo : python3dist(django) >= 1.11
kobo : python3dist(django) >= 1.11
I can take a stab at branching python-django4.2 for epel8 again and
report back, but if that proves difficult and there's objection to
retiring python-django3 in epel8 I'd be more than happy to hand over
the package to someone willing to handle or own the security issues.
Best regards,
--
_o) Michel Lind
_( ) https://keyoxide.org/5dce2e7e9c3b1cffd335c1d78b229d2f7ccc04f2
README: https://fedoraproject.org/wiki/User:Salimma#README
The following Fedora EPEL 10.3 Security updates need testing:
Age URL
38 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a5d0ca57c2 nuclei-3.8.0-1.el10_3
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-8794c31f20 ffmpeg-7.1.4-1.el10_3
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b4a86bd068 netatalk-4.4.3-1.el10_3
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7158896891 python-wsgidav-4.3.4-1.el10_3
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-05f02b89ad roundcubemail-1.6.16-1.el10_3
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e9a72cc7ed pie-1.4.5-1.el10_3
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9b6d13e4b9 strongswan-6.0.6-1.el10_3
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b3c7c438c4 perl-Cpanel-JSON-XS-4.41-1.el10_3
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a0b50bf0a0 nextcloud-33.0.4-1.el10_3
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-39d9295352 libre-4.8.1-1.el10_3
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-025c44e73d perl-CryptX-0.089-1.el10_3
The following builds have been pushed to Fedora EPEL 10.3 updates-testing
bonnie++-2.00a-23.el10_3
chromium-148.0.7778.215-1.el10_3
converseen-0.15.2.4-1.el10_3
gsi-openssh-9.9p1-6.el10_3
highlight-4.20-3.el10_3
python-apprise-1.11.0-1.el10_3
python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_3
zmap-4.4.0-1.el10_3
Details about builds:
================================================================================
bonnie++-2.00a-23.el10_3 (FEDORA-EPEL-2026-2b96fd37c4)
Filesystem and disk benchmark & burn-in suite
--------------------------------------------------------------------------------
Update Information:
backport fixes from rawhide to silent koschei builds
eg, https://koschei.fedoraproject.org/package/bonnie++?collection=f43
--------------------------------------------------------------------------------
ChangeLog:
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-23
- Modernize spec file: use license macro, remove old comments and fix man
page glob
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-22
- Modernize Makefile: support LDFLAGS and DESTDIR
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-21
- Address security issues: missing-call-to-setgroups-before-setuid
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-20
- Fix build warnings
--------------------------------------------------------------------------------
================================================================================
chromium-148.0.7778.215-1.el10_3 (FEDORA-EPEL-2026-ebe8b4fbc3)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 148.0.7778.215
CVE-2026-9872: Out of bounds write in GPU
CVE-2026-9873: Use after free in Network
CVE-2026-9874: Use after free in Dawn
CVE-2026-9875: Out of bounds read in WebGL
CVE-2026-9876: Use after free in WebGL
CVE-2026-9877: Use after free in ANGLE
CVE-2026-9878: Use after free in ANGLE
CVE-2026-9879: Out of bounds write in ANGLE
CVE-2026-9880: Insufficient validation of untrusted input in WebGL
CVE-2026-9881: Use after free in Bluetooth
CVE-2026-9882: Integer overflow in ANGLE
CVE-2026-9883: Use after free in Base
CVE-2026-9884: Use after free in Browser
CVE-2026-9885: Insufficient validation of untrusted input in UI
CVE-2026-9886: Use after free in Base
CVE-2026-9887: Use after free in Proxy
CVE-2026-9888: Use after free in WebView
CVE-2026-9889: Out of bounds read and write in Dawn
CVE-2026-9890: Use after free in XR
CVE-2026-9891: Use after free in Extensions
CVE-2026-9892: Inappropriate implementation in Skia
CVE-2026-9893: Use after free in Skia
CVE-2026-9894: Use after free in GPU
CVE-2026-9895: Out of bounds read in GPU
CVE-2026-9896: Out of bounds write in V8
CVE-2026-9897: Use after free in DOM
CVE-2026-9898: Insufficient validation of untrusted input in GPU
CVE-2026-9899: Use after free in ANGLE
CVE-2026-9900: Out of bounds write in ANGLE
CVE-2026-9901: Use after free in ANGLE
CVE-2026-9902: Use after free in Accessibility
CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
CVE-2026-9904: Use after free in ANGLE
CVE-2026-9905: Use after free in Accessibility
CVE-2026-9906: Out of bounds write in GPU
CVE-2026-9907: Out of bounds read in Dawn
CVE-2026-9908: Out of bounds read in ANGLE
CVE-2026-9909: Integer overflow in Skia
CVE-2026-9910: Out of bounds memory access in ANGLE
CVE-2026-9911: Integer overflow in ANGLE
CVE-2026-9912: Inappropriate implementation in GPU
CVE-2026-9913: Inappropriate implementation in ANGLE
CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
CVE-2026-9915: Heap buffer overflow in ANGLE
CVE-2026-9916: Out of bounds write in ANGLE
CVE-2026-9917: Uninitialized Use in WebGL
CVE-2026-9918: Inappropriate implementation in Tint
CVE-2026-9919: Out of bounds read in WebGL
CVE-2026-9920: Uninitialized Use in GPU
CVE-2026-9921: Uninitialized Use in WebGL
CVE-2026-9922: Use after free in GPU
CVE-2026-9923: Use after free in Skia
CVE-2026-9924: Heap buffer overflow in ANGLE
CVE-2026-9925: Use after free in ANGLE
CVE-2026-9926: Heap buffer overflow in ANGLE
CVE-2026-9927: Use after free in ANGLE
CVE-2026-9928: Out of bounds read in ANGLE
CVE-2026-9929: Inappropriate implementation in WebGL
CVE-2026-9930: Out of bounds write in Dawn
CVE-2026-9931: Use after free in GPU
CVE-2026-9932: Use after free in ANGLE
CVE-2026-9933: Use after free in Input
CVE-2026-9934: Use after free in Aura
CVE-2026-9935: Uninitialized Use in ANGLE
CVE-2026-9936: Use after free in GFX
CVE-2026-9937: Use after free in UI
CVE-2026-9938: Inappropriate implementation in V8
CVE-2026-9939: Heap buffer overflow in WebCodecs
CVE-2026-9940: Heap buffer overflow in ANGLE
CVE-2026-9941: Use after free in ANGLE
CVE-2026-9942: Uninitialized Use in ANGLE
CVE-2026-9943: Out of bounds read in WebGL
CVE-2026-9944: Uninitialized Use in ANGLE
CVE-2026-9945: Use after free in Media
CVE-2026-9946: Use after free in ANGLE
CVE-2026-9947: Use after free in XML
CVE-2026-9948: Use after free in Views
CVE-2026-9949: Use after free in Core
CVE-2026-9950: Insufficient validation of untrusted input in iOS
CVE-2026-9951: Use after free in UI
CVE-2026-9952: Use after free in WebAudio
CVE-2026-9953: Out of bounds read in ANGLE
CVE-2026-9954: Use after free in TabStrip
CVE-2026-9955: Inappropriate implementation in iOS
CVE-2026-9956: Use after free in iOS
CVE-2026-9957: Use after free in PDF
CVE-2026-9958: Use after free in PDFium
CVE-2026-9959: Race in WebRTC
CVE-2026-9960: Integer overflow in PDFium
CVE-2026-9961: Use after free in SurfaceCapture
CVE-2026-9962: Use after free in WebRTC
CVE-2026-9963: Uninitialized Use in iOS
CVE-2026-9964: Use after free in Bluetooth
CVE-2026-9965: Out of bounds write in ANGLE
CVE-2026-9966: Integer overflow in XML
CVE-2026-9967: Out of bounds write in GPU
CVE-2026-9968: Integer overflow in V8
CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
CVE-2026-9970: Use after free in WebGL
CVE-2026-9971: Inappropriate implementation in iOS
CVE-2026-9972: Uninitialized Use in Gamepad
CVE-2026-9973: Out of bounds write in V8
CVE-2026-9974: Out of bounds write in GPU
CVE-2026-9975: Out of bounds read and write in ANGLE
CVE-2026-9976: Inappropriate implementation in USB
CVE-2026-9977: Insufficient validation of untrusted input in WebShare
CVE-2026-9978: Use after free in Glic
CVE-2026-9979: Insufficient validation of untrusted input in Input
CVE-2026-9980: Insufficient validation of untrusted input in Printing
CVE-2026-9981: Inappropriate implementation in Skia
CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
CVE-2026-9983: Type Confusion in Skia
CVE-2026-9984: Use after free in UI
CVE-2026-9985: Insufficient validation of untrusted input in Media
CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-9988: Use after free in WebRTC
CVE-2026-9989: Inappropriate implementation in Media
CVE-2026-9990: Use after free in WebAppInstalls
CVE-2026-9991: Inappropriate implementation in Media
CVE-2026-9992: Use after free in Network
CVE-2026-9993: Use after free in Views
CVE-2026-9994: Use after free in Core
CVE-2026-9995: Use after free in WebXR
CVE-2026-9996: Out of bounds read in WebRTC
CVE-2026-9997: Use after free in Input
CVE-2026-9998: Integer overflow in Skia
CVE-2026-9999: Inappropriate implementation in ANGLE
CVE-2026-10000: Use after free in Passwords
CVE-2026-10001: Use after free in PerformanceManager
CVE-2026-10002: Use after free in PDFium
CVE-2026-10003: Use after free in Views
CVE-2026-10004: Insufficient validation of untrusted input in Passwords
CVE-2026-10005: Use after free in WebAppInstalls
CVE-2026-10006: Race in WebAudio
CVE-2026-10007: Use after free in SVG
CVE-2026-10008: Uninitialized Use in GPU
CVE-2026-10009: Integer overflow in Skia
CVE-2026-10010: Inappropriate implementation in Input
CVE-2026-10011: Inappropriate implementation in Skia
CVE-2026-10012: Use after free in Skia
CVE-2026-10013: Use after free in WebCodecs
CVE-2026-10014: Use after free in WebMIDI
CVE-2026-10015: Integer overflow in WTF
CVE-2026-10016: Use after free in DOM
CVE-2026-10017: Out of bounds read in Headless
CVE-2026-10018: Integer overflow in ANGLE
CVE-2026-10019: Integer overflow in ANGLE
CVE-2026-10020: Insufficient validation of untrusted input in Skia
CVE-2026-10021: Insufficient validation of untrusted input in USB
CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Than Ngo <than(a)redhat.com> - 148.0.7778.215-1
- Update to 148.0.7778.215
* CVE-2026-9872: Out of bounds write in GPU
* CVE-2026-9873: Use after free in Network
* CVE-2026-9874: Use after free in Dawn
* CVE-2026-9875: Out of bounds read in WebGL
* CVE-2026-9876: Use after free in WebGL
* CVE-2026-9877: Use after free in ANGLE
* CVE-2026-9878: Use after free in ANGLE
* CVE-2026-9879: Out of bounds write in ANGLE
* CVE-2026-9880: Insufficient validation of untrusted input in WebGL
* CVE-2026-9881: Use after free in Bluetooth
* CVE-2026-9882: Integer overflow in ANGLE
* CVE-2026-9883: Use after free in Base
* CVE-2026-9884: Use after free in Browser
* CVE-2026-9885: Insufficient validation of untrusted input in UI
* CVE-2026-9886: Use after free in Base
* CVE-2026-9887: Use after free in Proxy
* CVE-2026-9888: Use after free in WebView
* CVE-2026-9889: Out of bounds read and write in Dawn
* CVE-2026-9890: Use after free in XR
* CVE-2026-9891: Use after free in Extensions
* CVE-2026-9892: Inappropriate implementation in Skia
* CVE-2026-9893: Use after free in Skia
* CVE-2026-9894: Use after free in GPU
* CVE-2026-9895: Out of bounds read in GPU
* CVE-2026-9896: Out of bounds write in V8
* CVE-2026-9897: Use after free in DOM
* CVE-2026-9898: Insufficient validation of untrusted input in GPU
* CVE-2026-9899: Use after free in ANGLE
* CVE-2026-9900: Out of bounds write in ANGLE
* CVE-2026-9901: Use after free in ANGLE
* CVE-2026-9902: Use after free in Accessibility
* CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
* CVE-2026-9904: Use after free in ANGLE
* CVE-2026-9905: Use after free in Accessibility
* CVE-2026-9906: Out of bounds write in GPU
* CVE-2026-9907: Out of bounds read in Dawn
* CVE-2026-9908: Out of bounds read in ANGLE
* CVE-2026-9909: Integer overflow in Skia
* CVE-2026-9910: Out of bounds memory access in ANGLE
* CVE-2026-9911: Integer overflow in ANGLE
* CVE-2026-9912: Inappropriate implementation in GPU
* CVE-2026-9913: Inappropriate implementation in ANGLE
* CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9915: Heap buffer overflow in ANGLE
* CVE-2026-9916: Out of bounds write in ANGLE
* CVE-2026-9917: Uninitialized Use in WebGL
* CVE-2026-9918: Inappropriate implementation in Tint
* CVE-2026-9919: Out of bounds read in WebGL
* CVE-2026-9920: Uninitialized Use in GPU
* CVE-2026-9921: Uninitialized Use in WebGL
* CVE-2026-9922: Use after free in GPU
* CVE-2026-9923: Use after free in Skia
* CVE-2026-9924: Heap buffer overflow in ANGLE
* CVE-2026-9925: Use after free in ANGLE
* CVE-2026-9926: Heap buffer overflow in ANGLE
* CVE-2026-9927: Use after free in ANGLE
* CVE-2026-9928: Out of bounds read in ANGLE
* CVE-2026-9929: Inappropriate implementation in WebGL
* CVE-2026-9930: Out of bounds write in Dawn
* CVE-2026-9931: Use after free in GPU
* CVE-2026-9932: Use after free in ANGLE
* CVE-2026-9933: Use after free in Input
* CVE-2026-9934: Use after free in Aura
* CVE-2026-9935: Uninitialized Use in ANGLE
* CVE-2026-9936: Use after free in GFX
* CVE-2026-9937: Use after free in UI
* CVE-2026-9938: Inappropriate implementation in V8
* CVE-2026-9939: Heap buffer overflow in WebCodecs
* CVE-2026-9940: Heap buffer overflow in ANGLE
* CVE-2026-9941: Use after free in ANGLE
* CVE-2026-9942: Uninitialized Use in ANGLE
* CVE-2026-9943: Out of bounds read in WebGL
* CVE-2026-9944: Uninitialized Use in ANGLE
* CVE-2026-9945: Use after free in Media
* CVE-2026-9946: Use after free in ANGLE
* CVE-2026-9947: Use after free in XML
* CVE-2026-9948: Use after free in Views
* CVE-2026-9949: Use after free in Core
* CVE-2026-9950: Insufficient validation of untrusted input in iOS
* CVE-2026-9951: Use after free in UI
* CVE-2026-9952: Use after free in WebAudio
* CVE-2026-9953: Out of bounds read in ANGLE
* CVE-2026-9954: Use after free in TabStrip
* CVE-2026-9955: Inappropriate implementation in iOS
* CVE-2026-9956: Use after free in iOS
* CVE-2026-9957: Use after free in PDF
* CVE-2026-9958: Use after free in PDFium
* CVE-2026-9959: Race in WebRTC
* CVE-2026-9960: Integer overflow in PDFium
* CVE-2026-9961: Use after free in SurfaceCapture
* CVE-2026-9962: Use after free in WebRTC
* CVE-2026-9963: Uninitialized Use in iOS
* CVE-2026-9964: Use after free in Bluetooth
* CVE-2026-9965: Out of bounds write in ANGLE
* CVE-2026-9966: Integer overflow in XML
* CVE-2026-9967: Out of bounds write in GPU
* CVE-2026-9968: Integer overflow in V8
* CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9970: Use after free in WebGL
* CVE-2026-9971: Inappropriate implementation in iOS
* CVE-2026-9972: Uninitialized Use in Gamepad
* CVE-2026-9973: Out of bounds write in V8
* CVE-2026-9974: Out of bounds write in GPU
* CVE-2026-9975: Out of bounds read and write in ANGLE
* CVE-2026-9976: Inappropriate implementation in USB
* CVE-2026-9977: Insufficient validation of untrusted input in WebShare
* CVE-2026-9978: Use after free in Glic
* CVE-2026-9979: Insufficient validation of untrusted input in Input
* CVE-2026-9980: Insufficient validation of untrusted input in Printing
* CVE-2026-9981: Inappropriate implementation in Skia
* CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9983: Type Confusion in Skia
* CVE-2026-9984: Use after free in UI
* CVE-2026-9985: Insufficient validation of untrusted input in Media
* CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
* CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
* CVE-2026-9988: Use after free in WebRTC
* CVE-2026-9989: Inappropriate implementation in Media
* CVE-2026-9990: Use after free in WebAppInstalls
* CVE-2026-9991: Inappropriate implementation in Media
* CVE-2026-9992: Use after free in Network
* CVE-2026-9993: Use after free in Views
* CVE-2026-9994: Use after free in Core
* CVE-2026-9995: Use after free in WebXR
* CVE-2026-9996: Out of bounds read in WebRTC
* CVE-2026-9997: Use after free in Input
* CVE-2026-9998: Integer overflow in Skia
* CVE-2026-9999: Inappropriate implementation in ANGLE
* CVE-2026-10000: Use after free in Passwords
* CVE-2026-10001: Use after free in PerformanceManager
* CVE-2026-10002: Use after free in PDFium
* CVE-2026-10003: Use after free in Views
* CVE-2026-10004: Insufficient validation of untrusted input in Passwords
* CVE-2026-10005: Use after free in WebAppInstalls
* CVE-2026-10006: Race in WebAudio
* CVE-2026-10007: Use after free in SVG
* CVE-2026-10008: Uninitialized Use in GPU
* CVE-2026-10009: Integer overflow in Skia
* CVE-2026-10010: Inappropriate implementation in Input
* CVE-2026-10011: Inappropriate implementation in Skia
* CVE-2026-10012: Use after free in Skia
* CVE-2026-10013: Use after free in WebCodecs
* CVE-2026-10014: Use after free in WebMIDI
* CVE-2026-10015: Integer overflow in WTF
* CVE-2026-10016: Use after free in DOM
* CVE-2026-10017: Out of bounds read in Headless
* CVE-2026-10018: Integer overflow in ANGLE
* CVE-2026-10019: Integer overflow in ANGLE
* CVE-2026-10020: Insufficient validation of untrusted input in Skia
* CVE-2026-10021: Insufficient validation of untrusted input in USB
* CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
================================================================================
converseen-0.15.2.4-1.el10_3 (FEDORA-EPEL-2026-c10ec7c928)
A batch image conversion and resizing tool written in C++ with Qt6 and Magick++
--------------------------------------------------------------------------------
Update Information:
New upstream release: 0.15.2.4
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 0.15.2.4-1
- Update to 0.15.2.4 upstream release
- Resolves: rhbz#2480322
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 0.15.2.3-2
- opt-in to packit
--------------------------------------------------------------------------------
================================================================================
gsi-openssh-9.9p1-6.el10_3 (FEDORA-EPEL-2026-9b14351f08)
An implementation of the SSH protocol with GSI authentication
--------------------------------------------------------------------------------
Update Information:
Sync with openssh packages.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 9.9p1-6
- Based on openssh-9.9p1-26.el10
--------------------------------------------------------------------------------
================================================================================
highlight-4.20-3.el10_3 (FEDORA-EPEL-2026-049d75c464)
Universal source code to formatted text converter
--------------------------------------------------------------------------------
Update Information:
update to 4.20 and opt-in to packit
update to 4.20 and opt-in to packit
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-3
- enable packit only for rawhide
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-2
- add bodhi_update packit job
* Wed May 27 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-1
- update to 4.20 and opt-in to packit
--------------------------------------------------------------------------------
================================================================================
python-apprise-1.11.0-1.el10_3 (FEDORA-EPEL-2026-93e851d8de)
A simple wrapper to many popular notification services used today
--------------------------------------------------------------------------------
Update Information:
Updated to v1.11.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Chris Caron <lead2gold(a)gmail.com> - 1.11.0-1
- Updated to v1.11.0
* Sun Apr 26 2026 Chris Caron <lead2gold(a)gmail.com> - 1.10.0-1
- Updated to v1.10.0
--------------------------------------------------------------------------------
================================================================================
python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_3 (FEDORA-EPEL-2026-edb53253fa)
IERS Earth Rotation and Leap Second tables for the astropy core package
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_3.
Changelog for python-astropy-iers-data
* Mon May 25 2026 Packit <hello(a)packit.dev> - 0.2026.5.25.1.14.13-1
- Update to 0.2026.5.25.1.14.13 upstream release
- Resolves: rhbz#2481100
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
Automatic update for python-astropy-iers-data-0.2026.5.18.1.11.28-1.el10_3.
Changelog for python-astropy-iers-data
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2026 Packit <hello(a)packit.dev> - 0.2026.5.25.1.14.13-1
- Update to 0.2026.5.25.1.14.13 upstream release
- Resolves: rhbz#2481100
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2478363 - python-astropy-iers-data-0.2026.5.18.1.11.28 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2478363
[ 2 ] Bug #2481100 - python-astropy-iers-data-0.2026.5.25.1.14.13 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2481100
--------------------------------------------------------------------------------
================================================================================
zmap-4.4.0-1.el10_3 (FEDORA-EPEL-2026-0d1984a285)
Network scanner for Internet-wide network studies
--------------------------------------------------------------------------------
Update Information:
New upstream release: 4.4.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.4.0-1
- Update to 4.4.0 upstream release
- Resolves: rhbz#2483167
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.3.4-4
- enable packit only for rawhide
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.3.4-3
- opt-in to packit
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.3.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 10.2 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b7aa3a90db perl-Crypt-PasswdMD5-1.4.3-1.el10_2
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-bd1cc59137 objfw-1.5.4-1.el10_2
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-8d6263d15f suricata-8.0.4-1.el10_2
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-c185cd6f77 nix-2.31.5-1.el10_2
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-aa33047e8e roundcubemail-1.6.16-1.el10_2
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-4114f4323c pie-1.4.5-1.el10_2
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-4aaa6e0ce5 perl-Cpanel-JSON-XS-4.41-1.el10_2
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-688571a474 nextcloud-33.0.4-1.el10_2
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-fdfd52de3c libre-4.8.1-1.el10_2
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-3fb3a6ee48 perl-CryptX-0.089-1.el10_2
The following builds have been pushed to Fedora EPEL 10.2 updates-testing
bonnie++-2.00a-23.el10_2
chromium-148.0.7778.215-1.el10_2
converseen-0.15.2.4-1.el10_2
gsi-openssh-9.9p1-6.el10_2
highlight-4.20-3.el10_2
python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_2
zmap-4.4.0-1.el10_2
Details about builds:
================================================================================
bonnie++-2.00a-23.el10_2 (FEDORA-EPEL-2026-fefdf31201)
Filesystem and disk benchmark & burn-in suite
--------------------------------------------------------------------------------
Update Information:
backport fixes from rawhide to silent koschei builds
eg, https://koschei.fedoraproject.org/package/bonnie++?collection=f43
--------------------------------------------------------------------------------
ChangeLog:
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-23
- Modernize spec file: use license macro, remove old comments and fix man
page glob
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-22
- Modernize Makefile: support LDFLAGS and DESTDIR
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-21
- Address security issues: missing-call-to-setgroups-before-setuid
* Sat Mar 14 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 2.00a-20
- Fix build warnings
--------------------------------------------------------------------------------
================================================================================
chromium-148.0.7778.215-1.el10_2 (FEDORA-EPEL-2026-16a47e9002)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 148.0.7778.215
CVE-2026-9872: Out of bounds write in GPU
CVE-2026-9873: Use after free in Network
CVE-2026-9874: Use after free in Dawn
CVE-2026-9875: Out of bounds read in WebGL
CVE-2026-9876: Use after free in WebGL
CVE-2026-9877: Use after free in ANGLE
CVE-2026-9878: Use after free in ANGLE
CVE-2026-9879: Out of bounds write in ANGLE
CVE-2026-9880: Insufficient validation of untrusted input in WebGL
CVE-2026-9881: Use after free in Bluetooth
CVE-2026-9882: Integer overflow in ANGLE
CVE-2026-9883: Use after free in Base
CVE-2026-9884: Use after free in Browser
CVE-2026-9885: Insufficient validation of untrusted input in UI
CVE-2026-9886: Use after free in Base
CVE-2026-9887: Use after free in Proxy
CVE-2026-9888: Use after free in WebView
CVE-2026-9889: Out of bounds read and write in Dawn
CVE-2026-9890: Use after free in XR
CVE-2026-9891: Use after free in Extensions
CVE-2026-9892: Inappropriate implementation in Skia
CVE-2026-9893: Use after free in Skia
CVE-2026-9894: Use after free in GPU
CVE-2026-9895: Out of bounds read in GPU
CVE-2026-9896: Out of bounds write in V8
CVE-2026-9897: Use after free in DOM
CVE-2026-9898: Insufficient validation of untrusted input in GPU
CVE-2026-9899: Use after free in ANGLE
CVE-2026-9900: Out of bounds write in ANGLE
CVE-2026-9901: Use after free in ANGLE
CVE-2026-9902: Use after free in Accessibility
CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
CVE-2026-9904: Use after free in ANGLE
CVE-2026-9905: Use after free in Accessibility
CVE-2026-9906: Out of bounds write in GPU
CVE-2026-9907: Out of bounds read in Dawn
CVE-2026-9908: Out of bounds read in ANGLE
CVE-2026-9909: Integer overflow in Skia
CVE-2026-9910: Out of bounds memory access in ANGLE
CVE-2026-9911: Integer overflow in ANGLE
CVE-2026-9912: Inappropriate implementation in GPU
CVE-2026-9913: Inappropriate implementation in ANGLE
CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
CVE-2026-9915: Heap buffer overflow in ANGLE
CVE-2026-9916: Out of bounds write in ANGLE
CVE-2026-9917: Uninitialized Use in WebGL
CVE-2026-9918: Inappropriate implementation in Tint
CVE-2026-9919: Out of bounds read in WebGL
CVE-2026-9920: Uninitialized Use in GPU
CVE-2026-9921: Uninitialized Use in WebGL
CVE-2026-9922: Use after free in GPU
CVE-2026-9923: Use after free in Skia
CVE-2026-9924: Heap buffer overflow in ANGLE
CVE-2026-9925: Use after free in ANGLE
CVE-2026-9926: Heap buffer overflow in ANGLE
CVE-2026-9927: Use after free in ANGLE
CVE-2026-9928: Out of bounds read in ANGLE
CVE-2026-9929: Inappropriate implementation in WebGL
CVE-2026-9930: Out of bounds write in Dawn
CVE-2026-9931: Use after free in GPU
CVE-2026-9932: Use after free in ANGLE
CVE-2026-9933: Use after free in Input
CVE-2026-9934: Use after free in Aura
CVE-2026-9935: Uninitialized Use in ANGLE
CVE-2026-9936: Use after free in GFX
CVE-2026-9937: Use after free in UI
CVE-2026-9938: Inappropriate implementation in V8
CVE-2026-9939: Heap buffer overflow in WebCodecs
CVE-2026-9940: Heap buffer overflow in ANGLE
CVE-2026-9941: Use after free in ANGLE
CVE-2026-9942: Uninitialized Use in ANGLE
CVE-2026-9943: Out of bounds read in WebGL
CVE-2026-9944: Uninitialized Use in ANGLE
CVE-2026-9945: Use after free in Media
CVE-2026-9946: Use after free in ANGLE
CVE-2026-9947: Use after free in XML
CVE-2026-9948: Use after free in Views
CVE-2026-9949: Use after free in Core
CVE-2026-9950: Insufficient validation of untrusted input in iOS
CVE-2026-9951: Use after free in UI
CVE-2026-9952: Use after free in WebAudio
CVE-2026-9953: Out of bounds read in ANGLE
CVE-2026-9954: Use after free in TabStrip
CVE-2026-9955: Inappropriate implementation in iOS
CVE-2026-9956: Use after free in iOS
CVE-2026-9957: Use after free in PDF
CVE-2026-9958: Use after free in PDFium
CVE-2026-9959: Race in WebRTC
CVE-2026-9960: Integer overflow in PDFium
CVE-2026-9961: Use after free in SurfaceCapture
CVE-2026-9962: Use after free in WebRTC
CVE-2026-9963: Uninitialized Use in iOS
CVE-2026-9964: Use after free in Bluetooth
CVE-2026-9965: Out of bounds write in ANGLE
CVE-2026-9966: Integer overflow in XML
CVE-2026-9967: Out of bounds write in GPU
CVE-2026-9968: Integer overflow in V8
CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
CVE-2026-9970: Use after free in WebGL
CVE-2026-9971: Inappropriate implementation in iOS
CVE-2026-9972: Uninitialized Use in Gamepad
CVE-2026-9973: Out of bounds write in V8
CVE-2026-9974: Out of bounds write in GPU
CVE-2026-9975: Out of bounds read and write in ANGLE
CVE-2026-9976: Inappropriate implementation in USB
CVE-2026-9977: Insufficient validation of untrusted input in WebShare
CVE-2026-9978: Use after free in Glic
CVE-2026-9979: Insufficient validation of untrusted input in Input
CVE-2026-9980: Insufficient validation of untrusted input in Printing
CVE-2026-9981: Inappropriate implementation in Skia
CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
CVE-2026-9983: Type Confusion in Skia
CVE-2026-9984: Use after free in UI
CVE-2026-9985: Insufficient validation of untrusted input in Media
CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-9988: Use after free in WebRTC
CVE-2026-9989: Inappropriate implementation in Media
CVE-2026-9990: Use after free in WebAppInstalls
CVE-2026-9991: Inappropriate implementation in Media
CVE-2026-9992: Use after free in Network
CVE-2026-9993: Use after free in Views
CVE-2026-9994: Use after free in Core
CVE-2026-9995: Use after free in WebXR
CVE-2026-9996: Out of bounds read in WebRTC
CVE-2026-9997: Use after free in Input
CVE-2026-9998: Integer overflow in Skia
CVE-2026-9999: Inappropriate implementation in ANGLE
CVE-2026-10000: Use after free in Passwords
CVE-2026-10001: Use after free in PerformanceManager
CVE-2026-10002: Use after free in PDFium
CVE-2026-10003: Use after free in Views
CVE-2026-10004: Insufficient validation of untrusted input in Passwords
CVE-2026-10005: Use after free in WebAppInstalls
CVE-2026-10006: Race in WebAudio
CVE-2026-10007: Use after free in SVG
CVE-2026-10008: Uninitialized Use in GPU
CVE-2026-10009: Integer overflow in Skia
CVE-2026-10010: Inappropriate implementation in Input
CVE-2026-10011: Inappropriate implementation in Skia
CVE-2026-10012: Use after free in Skia
CVE-2026-10013: Use after free in WebCodecs
CVE-2026-10014: Use after free in WebMIDI
CVE-2026-10015: Integer overflow in WTF
CVE-2026-10016: Use after free in DOM
CVE-2026-10017: Out of bounds read in Headless
CVE-2026-10018: Integer overflow in ANGLE
CVE-2026-10019: Integer overflow in ANGLE
CVE-2026-10020: Insufficient validation of untrusted input in Skia
CVE-2026-10021: Insufficient validation of untrusted input in USB
CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Than Ngo <than(a)redhat.com> - 148.0.7778.215-1
- Update to 148.0.7778.215
* CVE-2026-9872: Out of bounds write in GPU
* CVE-2026-9873: Use after free in Network
* CVE-2026-9874: Use after free in Dawn
* CVE-2026-9875: Out of bounds read in WebGL
* CVE-2026-9876: Use after free in WebGL
* CVE-2026-9877: Use after free in ANGLE
* CVE-2026-9878: Use after free in ANGLE
* CVE-2026-9879: Out of bounds write in ANGLE
* CVE-2026-9880: Insufficient validation of untrusted input in WebGL
* CVE-2026-9881: Use after free in Bluetooth
* CVE-2026-9882: Integer overflow in ANGLE
* CVE-2026-9883: Use after free in Base
* CVE-2026-9884: Use after free in Browser
* CVE-2026-9885: Insufficient validation of untrusted input in UI
* CVE-2026-9886: Use after free in Base
* CVE-2026-9887: Use after free in Proxy
* CVE-2026-9888: Use after free in WebView
* CVE-2026-9889: Out of bounds read and write in Dawn
* CVE-2026-9890: Use after free in XR
* CVE-2026-9891: Use after free in Extensions
* CVE-2026-9892: Inappropriate implementation in Skia
* CVE-2026-9893: Use after free in Skia
* CVE-2026-9894: Use after free in GPU
* CVE-2026-9895: Out of bounds read in GPU
* CVE-2026-9896: Out of bounds write in V8
* CVE-2026-9897: Use after free in DOM
* CVE-2026-9898: Insufficient validation of untrusted input in GPU
* CVE-2026-9899: Use after free in ANGLE
* CVE-2026-9900: Out of bounds write in ANGLE
* CVE-2026-9901: Use after free in ANGLE
* CVE-2026-9902: Use after free in Accessibility
* CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
* CVE-2026-9904: Use after free in ANGLE
* CVE-2026-9905: Use after free in Accessibility
* CVE-2026-9906: Out of bounds write in GPU
* CVE-2026-9907: Out of bounds read in Dawn
* CVE-2026-9908: Out of bounds read in ANGLE
* CVE-2026-9909: Integer overflow in Skia
* CVE-2026-9910: Out of bounds memory access in ANGLE
* CVE-2026-9911: Integer overflow in ANGLE
* CVE-2026-9912: Inappropriate implementation in GPU
* CVE-2026-9913: Inappropriate implementation in ANGLE
* CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9915: Heap buffer overflow in ANGLE
* CVE-2026-9916: Out of bounds write in ANGLE
* CVE-2026-9917: Uninitialized Use in WebGL
* CVE-2026-9918: Inappropriate implementation in Tint
* CVE-2026-9919: Out of bounds read in WebGL
* CVE-2026-9920: Uninitialized Use in GPU
* CVE-2026-9921: Uninitialized Use in WebGL
* CVE-2026-9922: Use after free in GPU
* CVE-2026-9923: Use after free in Skia
* CVE-2026-9924: Heap buffer overflow in ANGLE
* CVE-2026-9925: Use after free in ANGLE
* CVE-2026-9926: Heap buffer overflow in ANGLE
* CVE-2026-9927: Use after free in ANGLE
* CVE-2026-9928: Out of bounds read in ANGLE
* CVE-2026-9929: Inappropriate implementation in WebGL
* CVE-2026-9930: Out of bounds write in Dawn
* CVE-2026-9931: Use after free in GPU
* CVE-2026-9932: Use after free in ANGLE
* CVE-2026-9933: Use after free in Input
* CVE-2026-9934: Use after free in Aura
* CVE-2026-9935: Uninitialized Use in ANGLE
* CVE-2026-9936: Use after free in GFX
* CVE-2026-9937: Use after free in UI
* CVE-2026-9938: Inappropriate implementation in V8
* CVE-2026-9939: Heap buffer overflow in WebCodecs
* CVE-2026-9940: Heap buffer overflow in ANGLE
* CVE-2026-9941: Use after free in ANGLE
* CVE-2026-9942: Uninitialized Use in ANGLE
* CVE-2026-9943: Out of bounds read in WebGL
* CVE-2026-9944: Uninitialized Use in ANGLE
* CVE-2026-9945: Use after free in Media
* CVE-2026-9946: Use after free in ANGLE
* CVE-2026-9947: Use after free in XML
* CVE-2026-9948: Use after free in Views
* CVE-2026-9949: Use after free in Core
* CVE-2026-9950: Insufficient validation of untrusted input in iOS
* CVE-2026-9951: Use after free in UI
* CVE-2026-9952: Use after free in WebAudio
* CVE-2026-9953: Out of bounds read in ANGLE
* CVE-2026-9954: Use after free in TabStrip
* CVE-2026-9955: Inappropriate implementation in iOS
* CVE-2026-9956: Use after free in iOS
* CVE-2026-9957: Use after free in PDF
* CVE-2026-9958: Use after free in PDFium
* CVE-2026-9959: Race in WebRTC
* CVE-2026-9960: Integer overflow in PDFium
* CVE-2026-9961: Use after free in SurfaceCapture
* CVE-2026-9962: Use after free in WebRTC
* CVE-2026-9963: Uninitialized Use in iOS
* CVE-2026-9964: Use after free in Bluetooth
* CVE-2026-9965: Out of bounds write in ANGLE
* CVE-2026-9966: Integer overflow in XML
* CVE-2026-9967: Out of bounds write in GPU
* CVE-2026-9968: Integer overflow in V8
* CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9970: Use after free in WebGL
* CVE-2026-9971: Inappropriate implementation in iOS
* CVE-2026-9972: Uninitialized Use in Gamepad
* CVE-2026-9973: Out of bounds write in V8
* CVE-2026-9974: Out of bounds write in GPU
* CVE-2026-9975: Out of bounds read and write in ANGLE
* CVE-2026-9976: Inappropriate implementation in USB
* CVE-2026-9977: Insufficient validation of untrusted input in WebShare
* CVE-2026-9978: Use after free in Glic
* CVE-2026-9979: Insufficient validation of untrusted input in Input
* CVE-2026-9980: Insufficient validation of untrusted input in Printing
* CVE-2026-9981: Inappropriate implementation in Skia
* CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9983: Type Confusion in Skia
* CVE-2026-9984: Use after free in UI
* CVE-2026-9985: Insufficient validation of untrusted input in Media
* CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
* CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
* CVE-2026-9988: Use after free in WebRTC
* CVE-2026-9989: Inappropriate implementation in Media
* CVE-2026-9990: Use after free in WebAppInstalls
* CVE-2026-9991: Inappropriate implementation in Media
* CVE-2026-9992: Use after free in Network
* CVE-2026-9993: Use after free in Views
* CVE-2026-9994: Use after free in Core
* CVE-2026-9995: Use after free in WebXR
* CVE-2026-9996: Out of bounds read in WebRTC
* CVE-2026-9997: Use after free in Input
* CVE-2026-9998: Integer overflow in Skia
* CVE-2026-9999: Inappropriate implementation in ANGLE
* CVE-2026-10000: Use after free in Passwords
* CVE-2026-10001: Use after free in PerformanceManager
* CVE-2026-10002: Use after free in PDFium
* CVE-2026-10003: Use after free in Views
* CVE-2026-10004: Insufficient validation of untrusted input in Passwords
* CVE-2026-10005: Use after free in WebAppInstalls
* CVE-2026-10006: Race in WebAudio
* CVE-2026-10007: Use after free in SVG
* CVE-2026-10008: Uninitialized Use in GPU
* CVE-2026-10009: Integer overflow in Skia
* CVE-2026-10010: Inappropriate implementation in Input
* CVE-2026-10011: Inappropriate implementation in Skia
* CVE-2026-10012: Use after free in Skia
* CVE-2026-10013: Use after free in WebCodecs
* CVE-2026-10014: Use after free in WebMIDI
* CVE-2026-10015: Integer overflow in WTF
* CVE-2026-10016: Use after free in DOM
* CVE-2026-10017: Out of bounds read in Headless
* CVE-2026-10018: Integer overflow in ANGLE
* CVE-2026-10019: Integer overflow in ANGLE
* CVE-2026-10020: Insufficient validation of untrusted input in Skia
* CVE-2026-10021: Insufficient validation of untrusted input in USB
* CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
================================================================================
converseen-0.15.2.4-1.el10_2 (FEDORA-EPEL-2026-2f06114f77)
A batch image conversion and resizing tool written in C++ with Qt6 and Magick++
--------------------------------------------------------------------------------
Update Information:
New upstream release: 0.15.2.4
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 0.15.2.4-1
- Update to 0.15.2.4 upstream release
- Resolves: rhbz#2480322
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 0.15.2.3-2
- opt-in to packit
--------------------------------------------------------------------------------
================================================================================
gsi-openssh-9.9p1-6.el10_2 (FEDORA-EPEL-2026-c58ced790c)
An implementation of the SSH protocol with GSI authentication
--------------------------------------------------------------------------------
Update Information:
Sync with openssh packages.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 9.9p1-6
- Based on openssh-9.9p1-26.el10
--------------------------------------------------------------------------------
================================================================================
highlight-4.20-3.el10_2 (FEDORA-EPEL-2026-7c02a42bac)
Universal source code to formatted text converter
--------------------------------------------------------------------------------
Update Information:
update to 4.20 and opt-in to packit
update to 4.20 and opt-in to packit
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-3
- enable packit only for rawhide
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-2
- add bodhi_update packit job
* Wed May 27 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.20-1
- update to 4.20 and opt-in to packit
--------------------------------------------------------------------------------
================================================================================
python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_2 (FEDORA-EPEL-2026-58c903100f)
IERS Earth Rotation and Leap Second tables for the astropy core package
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-astropy-iers-data-0.2026.5.25.1.14.13-1.el10_2.
Changelog for python-astropy-iers-data
* Mon May 25 2026 Packit <hello(a)packit.dev> - 0.2026.5.25.1.14.13-1
- Update to 0.2026.5.25.1.14.13 upstream release
- Resolves: rhbz#2481100
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
Automatic update for python-astropy-iers-data-0.2026.5.18.1.11.28-1.el10_2.
Changelog for python-astropy-iers-data
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 25 2026 Packit <hello(a)packit.dev> - 0.2026.5.25.1.14.13-1
- Update to 0.2026.5.25.1.14.13 upstream release
- Resolves: rhbz#2481100
* Mon May 18 2026 Packit <hello(a)packit.dev> - 0.2026.5.18.1.11.28-1
- Update to 0.2026.5.18.1.11.28 upstream release
- Resolves: rhbz#2478363
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2478363 - python-astropy-iers-data-0.2026.5.18.1.11.28 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2478363
[ 2 ] Bug #2481100 - python-astropy-iers-data-0.2026.5.25.1.14.13 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2481100
--------------------------------------------------------------------------------
================================================================================
zmap-4.4.0-1.el10_2 (FEDORA-EPEL-2026-3983ed3cd6)
Network scanner for Internet-wide network studies
--------------------------------------------------------------------------------
Update Information:
New upstream release: 4.4.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.4.0-1
- Update to 4.4.0 upstream release
- Resolves: rhbz#2483167
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.3.4-4
- enable packit only for rawhide
* Sat May 30 2026 Filipe Rosset <rosset.filipe(a)gmail.com> - 4.3.4-3
- opt-in to packit
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.3.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
192 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-9a55de96db xpdf-4.06-1.el9
38 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e794b68cc6 nuclei-3.8.0-1.el9
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7e25a1d2ec ffmpeg-5.1.9-1.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-44e2e43519 perl-Crypt-PasswdMD5-1.4.3-1.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2538be24ab objfw-1.5.4-1.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-0e5b0277cf suricata-7.0.15-1.el9
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea9af18b11 strongswan-6.0.6-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-06873e634a perl-Cpanel-JSON-XS-4.41-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e3f844d4d5 libre-4.8.1-1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-0e1191456b pdns-5.0.5-1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-267188ebd0 perl-CryptX-0.089-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
chromium-148.0.7778.215-1.el9
gsi-openssh-9.9p1-2.el9
python-apprise-1.11.0-1.el9
Details about builds:
================================================================================
chromium-148.0.7778.215-1.el9 (FEDORA-EPEL-2026-694ab77296)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 148.0.7778.215
CVE-2026-9872: Out of bounds write in GPU
CVE-2026-9873: Use after free in Network
CVE-2026-9874: Use after free in Dawn
CVE-2026-9875: Out of bounds read in WebGL
CVE-2026-9876: Use after free in WebGL
CVE-2026-9877: Use after free in ANGLE
CVE-2026-9878: Use after free in ANGLE
CVE-2026-9879: Out of bounds write in ANGLE
CVE-2026-9880: Insufficient validation of untrusted input in WebGL
CVE-2026-9881: Use after free in Bluetooth
CVE-2026-9882: Integer overflow in ANGLE
CVE-2026-9883: Use after free in Base
CVE-2026-9884: Use after free in Browser
CVE-2026-9885: Insufficient validation of untrusted input in UI
CVE-2026-9886: Use after free in Base
CVE-2026-9887: Use after free in Proxy
CVE-2026-9888: Use after free in WebView
CVE-2026-9889: Out of bounds read and write in Dawn
CVE-2026-9890: Use after free in XR
CVE-2026-9891: Use after free in Extensions
CVE-2026-9892: Inappropriate implementation in Skia
CVE-2026-9893: Use after free in Skia
CVE-2026-9894: Use after free in GPU
CVE-2026-9895: Out of bounds read in GPU
CVE-2026-9896: Out of bounds write in V8
CVE-2026-9897: Use after free in DOM
CVE-2026-9898: Insufficient validation of untrusted input in GPU
CVE-2026-9899: Use after free in ANGLE
CVE-2026-9900: Out of bounds write in ANGLE
CVE-2026-9901: Use after free in ANGLE
CVE-2026-9902: Use after free in Accessibility
CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
CVE-2026-9904: Use after free in ANGLE
CVE-2026-9905: Use after free in Accessibility
CVE-2026-9906: Out of bounds write in GPU
CVE-2026-9907: Out of bounds read in Dawn
CVE-2026-9908: Out of bounds read in ANGLE
CVE-2026-9909: Integer overflow in Skia
CVE-2026-9910: Out of bounds memory access in ANGLE
CVE-2026-9911: Integer overflow in ANGLE
CVE-2026-9912: Inappropriate implementation in GPU
CVE-2026-9913: Inappropriate implementation in ANGLE
CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
CVE-2026-9915: Heap buffer overflow in ANGLE
CVE-2026-9916: Out of bounds write in ANGLE
CVE-2026-9917: Uninitialized Use in WebGL
CVE-2026-9918: Inappropriate implementation in Tint
CVE-2026-9919: Out of bounds read in WebGL
CVE-2026-9920: Uninitialized Use in GPU
CVE-2026-9921: Uninitialized Use in WebGL
CVE-2026-9922: Use after free in GPU
CVE-2026-9923: Use after free in Skia
CVE-2026-9924: Heap buffer overflow in ANGLE
CVE-2026-9925: Use after free in ANGLE
CVE-2026-9926: Heap buffer overflow in ANGLE
CVE-2026-9927: Use after free in ANGLE
CVE-2026-9928: Out of bounds read in ANGLE
CVE-2026-9929: Inappropriate implementation in WebGL
CVE-2026-9930: Out of bounds write in Dawn
CVE-2026-9931: Use after free in GPU
CVE-2026-9932: Use after free in ANGLE
CVE-2026-9933: Use after free in Input
CVE-2026-9934: Use after free in Aura
CVE-2026-9935: Uninitialized Use in ANGLE
CVE-2026-9936: Use after free in GFX
CVE-2026-9937: Use after free in UI
CVE-2026-9938: Inappropriate implementation in V8
CVE-2026-9939: Heap buffer overflow in WebCodecs
CVE-2026-9940: Heap buffer overflow in ANGLE
CVE-2026-9941: Use after free in ANGLE
CVE-2026-9942: Uninitialized Use in ANGLE
CVE-2026-9943: Out of bounds read in WebGL
CVE-2026-9944: Uninitialized Use in ANGLE
CVE-2026-9945: Use after free in Media
CVE-2026-9946: Use after free in ANGLE
CVE-2026-9947: Use after free in XML
CVE-2026-9948: Use after free in Views
CVE-2026-9949: Use after free in Core
CVE-2026-9950: Insufficient validation of untrusted input in iOS
CVE-2026-9951: Use after free in UI
CVE-2026-9952: Use after free in WebAudio
CVE-2026-9953: Out of bounds read in ANGLE
CVE-2026-9954: Use after free in TabStrip
CVE-2026-9955: Inappropriate implementation in iOS
CVE-2026-9956: Use after free in iOS
CVE-2026-9957: Use after free in PDF
CVE-2026-9958: Use after free in PDFium
CVE-2026-9959: Race in WebRTC
CVE-2026-9960: Integer overflow in PDFium
CVE-2026-9961: Use after free in SurfaceCapture
CVE-2026-9962: Use after free in WebRTC
CVE-2026-9963: Uninitialized Use in iOS
CVE-2026-9964: Use after free in Bluetooth
CVE-2026-9965: Out of bounds write in ANGLE
CVE-2026-9966: Integer overflow in XML
CVE-2026-9967: Out of bounds write in GPU
CVE-2026-9968: Integer overflow in V8
CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
CVE-2026-9970: Use after free in WebGL
CVE-2026-9971: Inappropriate implementation in iOS
CVE-2026-9972: Uninitialized Use in Gamepad
CVE-2026-9973: Out of bounds write in V8
CVE-2026-9974: Out of bounds write in GPU
CVE-2026-9975: Out of bounds read and write in ANGLE
CVE-2026-9976: Inappropriate implementation in USB
CVE-2026-9977: Insufficient validation of untrusted input in WebShare
CVE-2026-9978: Use after free in Glic
CVE-2026-9979: Insufficient validation of untrusted input in Input
CVE-2026-9980: Insufficient validation of untrusted input in Printing
CVE-2026-9981: Inappropriate implementation in Skia
CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
CVE-2026-9983: Type Confusion in Skia
CVE-2026-9984: Use after free in UI
CVE-2026-9985: Insufficient validation of untrusted input in Media
CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
CVE-2026-9988: Use after free in WebRTC
CVE-2026-9989: Inappropriate implementation in Media
CVE-2026-9990: Use after free in WebAppInstalls
CVE-2026-9991: Inappropriate implementation in Media
CVE-2026-9992: Use after free in Network
CVE-2026-9993: Use after free in Views
CVE-2026-9994: Use after free in Core
CVE-2026-9995: Use after free in WebXR
CVE-2026-9996: Out of bounds read in WebRTC
CVE-2026-9997: Use after free in Input
CVE-2026-9998: Integer overflow in Skia
CVE-2026-9999: Inappropriate implementation in ANGLE
CVE-2026-10000: Use after free in Passwords
CVE-2026-10001: Use after free in PerformanceManager
CVE-2026-10002: Use after free in PDFium
CVE-2026-10003: Use after free in Views
CVE-2026-10004: Insufficient validation of untrusted input in Passwords
CVE-2026-10005: Use after free in WebAppInstalls
CVE-2026-10006: Race in WebAudio
CVE-2026-10007: Use after free in SVG
CVE-2026-10008: Uninitialized Use in GPU
CVE-2026-10009: Integer overflow in Skia
CVE-2026-10010: Inappropriate implementation in Input
CVE-2026-10011: Inappropriate implementation in Skia
CVE-2026-10012: Use after free in Skia
CVE-2026-10013: Use after free in WebCodecs
CVE-2026-10014: Use after free in WebMIDI
CVE-2026-10015: Integer overflow in WTF
CVE-2026-10016: Use after free in DOM
CVE-2026-10017: Out of bounds read in Headless
CVE-2026-10018: Integer overflow in ANGLE
CVE-2026-10019: Integer overflow in ANGLE
CVE-2026-10020: Insufficient validation of untrusted input in Skia
CVE-2026-10021: Insufficient validation of untrusted input in USB
CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Than Ngo <than(a)redhat.com> - 148.0.7778.215-1
- Update to 148.0.7778.215
* CVE-2026-9872: Out of bounds write in GPU
* CVE-2026-9873: Use after free in Network
* CVE-2026-9874: Use after free in Dawn
* CVE-2026-9875: Out of bounds read in WebGL
* CVE-2026-9876: Use after free in WebGL
* CVE-2026-9877: Use after free in ANGLE
* CVE-2026-9878: Use after free in ANGLE
* CVE-2026-9879: Out of bounds write in ANGLE
* CVE-2026-9880: Insufficient validation of untrusted input in WebGL
* CVE-2026-9881: Use after free in Bluetooth
* CVE-2026-9882: Integer overflow in ANGLE
* CVE-2026-9883: Use after free in Base
* CVE-2026-9884: Use after free in Browser
* CVE-2026-9885: Insufficient validation of untrusted input in UI
* CVE-2026-9886: Use after free in Base
* CVE-2026-9887: Use after free in Proxy
* CVE-2026-9888: Use after free in WebView
* CVE-2026-9889: Out of bounds read and write in Dawn
* CVE-2026-9890: Use after free in XR
* CVE-2026-9891: Use after free in Extensions
* CVE-2026-9892: Inappropriate implementation in Skia
* CVE-2026-9893: Use after free in Skia
* CVE-2026-9894: Use after free in GPU
* CVE-2026-9895: Out of bounds read in GPU
* CVE-2026-9896: Out of bounds write in V8
* CVE-2026-9897: Use after free in DOM
* CVE-2026-9898: Insufficient validation of untrusted input in GPU
* CVE-2026-9899: Use after free in ANGLE
* CVE-2026-9900: Out of bounds write in ANGLE
* CVE-2026-9901: Use after free in ANGLE
* CVE-2026-9902: Use after free in Accessibility
* CVE-2026-9903: Insufficient validation of untrusted input in Site Isolation
* CVE-2026-9904: Use after free in ANGLE
* CVE-2026-9905: Use after free in Accessibility
* CVE-2026-9906: Out of bounds write in GPU
* CVE-2026-9907: Out of bounds read in Dawn
* CVE-2026-9908: Out of bounds read in ANGLE
* CVE-2026-9909: Integer overflow in Skia
* CVE-2026-9910: Out of bounds memory access in ANGLE
* CVE-2026-9911: Integer overflow in ANGLE
* CVE-2026-9912: Inappropriate implementation in GPU
* CVE-2026-9913: Inappropriate implementation in ANGLE
* CVE-2026-9914: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9915: Heap buffer overflow in ANGLE
* CVE-2026-9916: Out of bounds write in ANGLE
* CVE-2026-9917: Uninitialized Use in WebGL
* CVE-2026-9918: Inappropriate implementation in Tint
* CVE-2026-9919: Out of bounds read in WebGL
* CVE-2026-9920: Uninitialized Use in GPU
* CVE-2026-9921: Uninitialized Use in WebGL
* CVE-2026-9922: Use after free in GPU
* CVE-2026-9923: Use after free in Skia
* CVE-2026-9924: Heap buffer overflow in ANGLE
* CVE-2026-9925: Use after free in ANGLE
* CVE-2026-9926: Heap buffer overflow in ANGLE
* CVE-2026-9927: Use after free in ANGLE
* CVE-2026-9928: Out of bounds read in ANGLE
* CVE-2026-9929: Inappropriate implementation in WebGL
* CVE-2026-9930: Out of bounds write in Dawn
* CVE-2026-9931: Use after free in GPU
* CVE-2026-9932: Use after free in ANGLE
* CVE-2026-9933: Use after free in Input
* CVE-2026-9934: Use after free in Aura
* CVE-2026-9935: Uninitialized Use in ANGLE
* CVE-2026-9936: Use after free in GFX
* CVE-2026-9937: Use after free in UI
* CVE-2026-9938: Inappropriate implementation in V8
* CVE-2026-9939: Heap buffer overflow in WebCodecs
* CVE-2026-9940: Heap buffer overflow in ANGLE
* CVE-2026-9941: Use after free in ANGLE
* CVE-2026-9942: Uninitialized Use in ANGLE
* CVE-2026-9943: Out of bounds read in WebGL
* CVE-2026-9944: Uninitialized Use in ANGLE
* CVE-2026-9945: Use after free in Media
* CVE-2026-9946: Use after free in ANGLE
* CVE-2026-9947: Use after free in XML
* CVE-2026-9948: Use after free in Views
* CVE-2026-9949: Use after free in Core
* CVE-2026-9950: Insufficient validation of untrusted input in iOS
* CVE-2026-9951: Use after free in UI
* CVE-2026-9952: Use after free in WebAudio
* CVE-2026-9953: Out of bounds read in ANGLE
* CVE-2026-9954: Use after free in TabStrip
* CVE-2026-9955: Inappropriate implementation in iOS
* CVE-2026-9956: Use after free in iOS
* CVE-2026-9957: Use after free in PDF
* CVE-2026-9958: Use after free in PDFium
* CVE-2026-9959: Race in WebRTC
* CVE-2026-9960: Integer overflow in PDFium
* CVE-2026-9961: Use after free in SurfaceCapture
* CVE-2026-9962: Use after free in WebRTC
* CVE-2026-9963: Uninitialized Use in iOS
* CVE-2026-9964: Use after free in Bluetooth
* CVE-2026-9965: Out of bounds write in ANGLE
* CVE-2026-9966: Integer overflow in XML
* CVE-2026-9967: Out of bounds write in GPU
* CVE-2026-9968: Integer overflow in V8
* CVE-2026-9969: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9970: Use after free in WebGL
* CVE-2026-9971: Inappropriate implementation in iOS
* CVE-2026-9972: Uninitialized Use in Gamepad
* CVE-2026-9973: Out of bounds write in V8
* CVE-2026-9974: Out of bounds write in GPU
* CVE-2026-9975: Out of bounds read and write in ANGLE
* CVE-2026-9976: Inappropriate implementation in USB
* CVE-2026-9977: Insufficient validation of untrusted input in WebShare
* CVE-2026-9978: Use after free in Glic
* CVE-2026-9979: Insufficient validation of untrusted input in Input
* CVE-2026-9980: Insufficient validation of untrusted input in Printing
* CVE-2026-9981: Inappropriate implementation in Skia
* CVE-2026-9982: Insufficient validation of untrusted input in ANGLE
* CVE-2026-9983: Type Confusion in Skia
* CVE-2026-9984: Use after free in UI
* CVE-2026-9985: Insufficient validation of untrusted input in Media
* CVE-2026-9986: Insufficient validation of untrusted input in OptimizationGuide
* CVE-2026-9987: Insufficient validation of untrusted input in WebAppInstalls
* CVE-2026-9988: Use after free in WebRTC
* CVE-2026-9989: Inappropriate implementation in Media
* CVE-2026-9990: Use after free in WebAppInstalls
* CVE-2026-9991: Inappropriate implementation in Media
* CVE-2026-9992: Use after free in Network
* CVE-2026-9993: Use after free in Views
* CVE-2026-9994: Use after free in Core
* CVE-2026-9995: Use after free in WebXR
* CVE-2026-9996: Out of bounds read in WebRTC
* CVE-2026-9997: Use after free in Input
* CVE-2026-9998: Integer overflow in Skia
* CVE-2026-9999: Inappropriate implementation in ANGLE
* CVE-2026-10000: Use after free in Passwords
* CVE-2026-10001: Use after free in PerformanceManager
* CVE-2026-10002: Use after free in PDFium
* CVE-2026-10003: Use after free in Views
* CVE-2026-10004: Insufficient validation of untrusted input in Passwords
* CVE-2026-10005: Use after free in WebAppInstalls
* CVE-2026-10006: Race in WebAudio
* CVE-2026-10007: Use after free in SVG
* CVE-2026-10008: Uninitialized Use in GPU
* CVE-2026-10009: Integer overflow in Skia
* CVE-2026-10010: Inappropriate implementation in Input
* CVE-2026-10011: Inappropriate implementation in Skia
* CVE-2026-10012: Use after free in Skia
* CVE-2026-10013: Use after free in WebCodecs
* CVE-2026-10014: Use after free in WebMIDI
* CVE-2026-10015: Integer overflow in WTF
* CVE-2026-10016: Use after free in DOM
* CVE-2026-10017: Out of bounds read in Headless
* CVE-2026-10018: Integer overflow in ANGLE
* CVE-2026-10019: Integer overflow in ANGLE
* CVE-2026-10020: Insufficient validation of untrusted input in Skia
* CVE-2026-10021: Insufficient validation of untrusted input in USB
* CVE-2026-10022: Type Confusion in V8
--------------------------------------------------------------------------------
================================================================================
gsi-openssh-9.9p1-2.el9 (FEDORA-EPEL-2026-e79cf37e93)
An implementation of the SSH protocol with GSI authentication
--------------------------------------------------------------------------------
Update Information:
Sync with openssh packages.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 9.9p1-2
- Based on openssh-9.9p1-8.el9
--------------------------------------------------------------------------------
================================================================================
python-apprise-1.11.0-1.el9 (FEDORA-EPEL-2026-ed7865a158)
A simple wrapper to many popular notification services used today
--------------------------------------------------------------------------------
Update Information:
Updated to v1.11.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Chris Caron <lead2gold(a)gmail.com> - 1.11.0-1
- Updated to v1.11.0
* Sun Apr 26 2026 Chris Caron <lead2gold(a)gmail.com> - 1.10.0-1
- Updated to v1.10.0
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
191 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5b2095e2c2 xpdf-4.06-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-cabae86b4e perl-Crypt-PasswdMD5-1.4.3-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-82451c4348 objfw-1.5.4-1.el8
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a57474dbd8 suricata-7.0.15-1.el8
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-395b39d32e perl-Cpanel-JSON-XS-4.41-1.el8
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2d8dd834d8 strongswan-6.0.6-1.el8
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-035f48b183 libre-4.8.1-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
lemonldap-ng-2.23.0-1.el8
perl-CryptX-0.089-1.el8
python-specfile-0.41.0-1.el8
Details about builds:
================================================================================
lemonldap-ng-2.23.0-1.el8 (FEDORA-EPEL-2026-6be1483de0)
Web Single Sign On (SSO) and Access Management
--------------------------------------------------------------------------------
Update Information:
Update to 2.23.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Clement Oudot <clement.oudot(a)worteks.com> - 2.23.0-1
- Update to 2.23.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2483351 - lemonldap-ng-2.23.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2483351
--------------------------------------------------------------------------------
================================================================================
perl-CryptX-0.089-1.el8 (FEDORA-EPEL-2026-e788f7bb84)
Cryptographic toolkit
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2026-41565
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 10 2026 Xavier Bachelot <xavier(a)bachelot.org> - 0.089-1
- Update to 0.089 (RHBZ#2468592)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482787 - CVE-2026-41565 perl-CryptX: perl-CryptX: Stack buffer overflow allows arbitrary code execution via a crafted authentication tag. [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2482787
--------------------------------------------------------------------------------
================================================================================
python-specfile-0.41.0-1.el8 (FEDORA-EPEL-2026-46e0e88d29)
A library for parsing and manipulating RPM spec files
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-specfile-0.41.0-1.el8.
Changelog for python-specfile
* Fri May 29 2026 Packit <hello(a)packit.dev> - 0.41.0-1
- Fixed an issue where the value of a tag could have been incorrectly expanded
if the spec file contained a macro definition shadowing the tag name, e.g.:
%global release 12
%global release_string %{release}%{?dist}
Release: %{release_string}
In this case, with `dist` being `.fc44`, `Specfile.expanded_release` returned
`12.fc44.fc44` instead of `12.fc44`. (#539)
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Packit <hello(a)packit.dev> - 0.41.0-1
- Fixed an issue where the value of a tag could have been incorrectly expanded if the spec file contained a macro definition shadowing the tag name, e.g.:
```
%global release 12
%global release_string %{release}%{?dist}
Release: %{release_string}
```
In this case, with `dist` being `.fc44`, `Specfile.expanded_release` returned `12.fc44.fc44` instead of `12.fc44`. (#539)
--------------------------------------------------------------------------------
The following Fedora EPEL 9 Security updates need testing:
Age URL
191 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-9a55de96db xpdf-4.06-1.el9
37 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e794b68cc6 nuclei-3.8.0-1.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7e25a1d2ec ffmpeg-5.1.9-1.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e7b8776a02 libssh2-1.11.1-6.el9
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-44e2e43519 perl-Crypt-PasswdMD5-1.4.3-1.el9
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-2538be24ab objfw-1.5.4-1.el9
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-0e5b0277cf suricata-7.0.15-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ea9af18b11 strongswan-6.0.6-1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-06873e634a perl-Cpanel-JSON-XS-4.41-1.el9
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e3f844d4d5 libre-4.8.1-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
lemonldap-ng-2.23.0-1.el9
nushell-0.99.1-4.el9
pdns-5.0.5-1.el9
perl-CryptX-0.089-1.el9
python-specfile-0.41.0-1.el9
resalloc-6.2-1.el9
rust-cipher-0.5.2-1.el9
rust-cmov-0.5.4-1.el9
rust-hybrid-array-0.4.12-1.el9
rust-mio-1.2.1-1.el9
rust-socket2-0.6.4-1.el9
rust-typenum-1.20.1-1.el9
rust2rpm-helper-0.1.9-1.el9
Details about builds:
================================================================================
lemonldap-ng-2.23.0-1.el9 (FEDORA-EPEL-2026-24bf661f55)
Web Single Sign On (SSO) and Access Management
--------------------------------------------------------------------------------
Update Information:
Update to 2.23.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Clement Oudot <clement.oudot(a)worteks.com> - 2.23.0-1
- Update to 2.23.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2483351 - lemonldap-ng-2.23.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2483351
--------------------------------------------------------------------------------
================================================================================
nushell-0.99.1-4.el9 (FEDORA-EPEL-2026-8d2cdc5eee)
A new type of shell
--------------------------------------------------------------------------------
Update Information:
Initial EPEL 9 release of nushell (refactored packaging of rust-nu) and
rust2rpm-helper
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Michel Lind <salimma(a)fedoraproject.org> - 0.99.1-4
- Allow fancy-regex 0.13 to 0.16
* Fri May 29 2026 Michel Lind <salimma(a)fedoraproject.org> - 0.99.1-3
- Fix license typo
* Thu May 28 2026 Michel Lind <salimma(a)fedoraproject.org> - 0.99.1-2
- Exclude building on ix86 due to OOM when linking
* Thu May 28 2026 Michel Lind <salimma(a)fedoraproject.org> - 0.99.1-1
- Initial package, replacing rust-nu
- Resolves RHBZ#2482818
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482818 - Review Request: nushell - A new type of shell
https://bugzilla.redhat.com/show_bug.cgi?id=2482818
--------------------------------------------------------------------------------
================================================================================
pdns-5.0.5-1.el9 (FEDORA-EPEL-2026-0e1191456b)
A modern, advanced and high performance authoritative-only name server
--------------------------------------------------------------------------------
Update Information:
Update to 5.0.5
Fix for CVE-2026-42000, CVE-2026-42001, CVE-2026-42002, CVE-2026-41999,
CVE-2026-42396
Security Advisory: https://doc.powerdns.com/authoritative/security-
advisories/powerdns-advisory-2026-06.html
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 21 2026 Morten Stevens <mstevens(a)fedoraproject.org> - 5.0.5-1
- Update to 5.0.5
--------------------------------------------------------------------------------
================================================================================
perl-CryptX-0.089-1.el9 (FEDORA-EPEL-2026-267188ebd0)
Cryptographic toolkit
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2026-41565
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 10 2026 Xavier Bachelot <xavier(a)bachelot.org> - 0.089-1
- Update to 0.089 (RHBZ#2468592)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482787 - CVE-2026-41565 perl-CryptX: perl-CryptX: Stack buffer overflow allows arbitrary code execution via a crafted authentication tag. [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2482787
--------------------------------------------------------------------------------
================================================================================
python-specfile-0.41.0-1.el9 (FEDORA-EPEL-2026-2792328533)
A library for parsing and manipulating RPM spec files
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-specfile-0.41.0-1.el9.
Changelog for python-specfile
* Fri May 29 2026 Packit <hello(a)packit.dev> - 0.41.0-1
- Fixed an issue where the value of a tag could have been incorrectly expanded
if the spec file contained a macro definition shadowing the tag name, e.g.:
%global release 12
%global release_string %{release}%{?dist}
Release: %{release_string}
In this case, with `dist` being `.fc44`, `Specfile.expanded_release` returned
`12.fc44.fc44` instead of `12.fc44`. (#539)
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Packit <hello(a)packit.dev> - 0.41.0-1
- Fixed an issue where the value of a tag could have been incorrectly expanded if the spec file contained a macro definition shadowing the tag name, e.g.:
```
%global release 12
%global release_string %{release}%{?dist}
Release: %{release_string}
```
In this case, with `dist` being `.fc44`, `Specfile.expanded_release` returned `12.fc44.fc44` instead of `12.fc44`. (#539)
--------------------------------------------------------------------------------
================================================================================
resalloc-6.2-1.el9 (FEDORA-EPEL-2026-5337788066)
Resource allocator for expensive resources - client tooling
--------------------------------------------------------------------------------
Update Information:
Enhancements
Provide an API endpoint with pool statistics usable for monitoring #124
Bugfixes
Fix #178 - The cmd_list is now being run with a timeout and therefore
cannot hang forever and leak file descriptors.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Jakub Kadlcik <frostyx(a)email.cz> - 6.2-1
- new upstream release
--------------------------------------------------------------------------------
================================================================================
rust-cipher-0.5.2-1.el9 (FEDORA-EPEL-2026-c18dedae2e)
Traits for describing block ciphers and stream ciphers
--------------------------------------------------------------------------------
Update Information:
Update to version 0.5.2.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.5.2-1
- Update to version 0.5.2; Fixes RHBZ#2479912
--------------------------------------------------------------------------------
================================================================================
rust-cmov-0.5.4-1.el9 (FEDORA-EPEL-2026-cdc5e94e93)
Conditional move CPU intrinsics with pure Rust fallback implemenation
--------------------------------------------------------------------------------
Update Information:
Update to version 0.5.4.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.5.4-1
- Update to version 0.5.4; Fixes RHBZ#2482851
--------------------------------------------------------------------------------
================================================================================
rust-hybrid-array-0.4.12-1.el9 (FEDORA-EPEL-2026-f5ac339ffd)
Hybrid typenum-based and const generic array types
--------------------------------------------------------------------------------
Update Information:
Update the hybrid-array crate to version 0.4.12.
Update the typenum crate to version 1.20.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.4.12-1
- Update to version 0.4.12; Fixes RHBZ#2445634
--------------------------------------------------------------------------------
================================================================================
rust-mio-1.2.1-1.el9 (FEDORA-EPEL-2026-0271c6d74e)
Lightweight non-blocking I/O
--------------------------------------------------------------------------------
Update Information:
Update to version 1.2.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 1.2.1-1
- Update to version 1.2.1; Fixes RHBZ#2482757
--------------------------------------------------------------------------------
================================================================================
rust-socket2-0.6.4-1.el9 (FEDORA-EPEL-2026-444b429ede)
Utilities for handling networking sockets
--------------------------------------------------------------------------------
Update Information:
Update to version 0.6.4.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.6.4-1
- Update to version 0.6.4; Fixes RHBZ#2482791
--------------------------------------------------------------------------------
================================================================================
rust-typenum-1.20.1-1.el9 (FEDORA-EPEL-2026-f5ac339ffd)
Type-level numbers evaluated at compile time
--------------------------------------------------------------------------------
Update Information:
Update the hybrid-array crate to version 0.4.12.
Update the typenum crate to version 1.20.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 29 2026 Fabio Valentini <decathorpe(a)gmail.com> - 1.20.1-1
- Update to version 1.20.1; Fixes RHBZ#2459492
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.19.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust2rpm-helper-0.1.9-1.el9 (FEDORA-EPEL-2026-8d2cdc5eee)
Helper program for rust2rpm
--------------------------------------------------------------------------------
Update Information:
Initial EPEL 9 release of nushell (refactored packaging of rust-nu) and
rust2rpm-helper
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jan 16 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.1.9-1
- Update to version 0.1.9; Fixes RHBZ#2429625
* Mon Jan 12 2026 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.8-1
- Update to version 0.1.8; Fixes RHBZ#2354889
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.6-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.6-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Tue Oct 22 2024 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.6-1
- Update to version 0.1.6; Fixes RHBZ#2318767
* Sat Jul 20 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu May 23 2024 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.5-3
- Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces
* Mon Mar 18 2024 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.5-2
- Regenerate with rust2rpm v26
* Thu Feb 29 2024 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.5-1
- Update to version 0.1.5; Fixes RHBZ#2265159
* Sat Jan 27 2024 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2482818 - Review Request: nushell - A new type of shell
https://bugzilla.redhat.com/show_bug.cgi?id=2482818
--------------------------------------------------------------------------------