The following Fedora EPEL 9 Security updates need testing:
Age URL
92 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-9a55de96db xpdf-4.06-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-a2dfe68ed3 apptainer-1.4.5-3.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-19c3e58e98 libmodbus-3.1.12-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-3994fa9db2 postgresql16-anonymizer-3.0.5-3.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-b65cc58fcd chromium-145.0.7632.75-1.el9
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-8abd97fa3c gh-2.87.0-2.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
R-rpm-macros-1.3.5-1.el9
atuin-18.11.0-1.el9
rust-libz-rs-sys-0.6.2-1.el9
rust-metrics-exporter-prometheus-0.17.2-1.el9
rust-metrics-util-0.20.1-1.el9
rust-norm-0.1.1-1.el9
rust-sequoia-openpgp1-1.22.0-4.el9
rust-zlib-rs-0.6.2-1.el9
scitokens-cpp-1.4.0-3.el9
Details about builds:
================================================================================
R-rpm-macros-1.3.5-1.el9 (FEDORA-EPEL-2026-2e406104a3)
Macros to help produce R packages
--------------------------------------------------------------------------------
Update Information:
Update to 1.3.5
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Iñaki Úcar <iucar(a)fedoraproject.org> - 1.3.5-1
- Update to 1.3.5
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.4-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
atuin-18.11.0-1.el9 (FEDORA-EPEL-2026-61cb54e7c2)
Magical shell history
--------------------------------------------------------------------------------
Update Information:
atuin:
Update to version 18.11.0
Atuin 18.9.0 fixes fish 4.x removal of bind -k (rhbz#2440541)
Add better documentation of how to handle MSRV
Move the profile.d script outside of the spec file
rust-metrics-exporter-prometheus:
Update to 0.17.2
rust-metrics-util:
Update to 0.20.1 (rhbz#2361247)
rust-norm:
Import rhbz#2437707
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Cristian Le <git(a)lecris.dev> - 18.11.0-1
- Update to version 18.11.0
- Atuin 18.9.0 fixes fish 4.x removal of `bind -k` (rhbz#2440541)
- Add better documentation of how to handle MSRV
- Move the profile.d script outside of the spec file
--------------------------------------------------------------------------------
================================================================================
rust-libz-rs-sys-0.6.2-1.el9 (FEDORA-EPEL-2026-31e026934a)
Memory-safe zlib implementation written in rust
--------------------------------------------------------------------------------
Update Information:
Update rust-zlib-rs and rust-libz-rs-sys to 0.6.2, fixing some possible integer
overflows.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.6.2-1
- Update to version 0.6.2; Fixes RHBZ#2440377
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2440369 - rust-zlib-rs-0.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2440369
[ 2 ] Bug #2440377 - rust-libz-rs-sys-0.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2440377
--------------------------------------------------------------------------------
================================================================================
rust-metrics-exporter-prometheus-0.17.2-1.el9 (FEDORA-EPEL-2026-61cb54e7c2)
Metrics-compatible exporter for sending metrics to Prometheus
--------------------------------------------------------------------------------
Update Information:
atuin:
Update to version 18.11.0
Atuin 18.9.0 fixes fish 4.x removal of bind -k (rhbz#2440541)
Add better documentation of how to handle MSRV
Move the profile.d script outside of the spec file
rust-metrics-exporter-prometheus:
Update to 0.17.2
rust-metrics-util:
Update to 0.20.1 (rhbz#2361247)
rust-norm:
Import rhbz#2437707
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Cristian Le <git(a)lecris.dev> - 0.17.2-1
- Update to 0.17.2
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.16.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.16.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-metrics-util-0.20.1-1.el9 (FEDORA-EPEL-2026-61cb54e7c2)
Helper types/functions used by the metrics ecosystem
--------------------------------------------------------------------------------
Update Information:
atuin:
Update to version 18.11.0
Atuin 18.9.0 fixes fish 4.x removal of bind -k (rhbz#2440541)
Add better documentation of how to handle MSRV
Move the profile.d script outside of the spec file
rust-metrics-exporter-prometheus:
Update to 0.17.2
rust-metrics-util:
Update to 0.20.1 (rhbz#2361247)
rust-norm:
Import rhbz#2437707
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Cristian Le <git(a)lecris.dev> - 0.20.1-1
- Update to 0.20.1 (rhbz#2361247)
* Sat Jan 17 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.18.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jul 25 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.18.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-norm-0.1.1-1.el9 (FEDORA-EPEL-2026-61cb54e7c2)
Collection of distance metrics on strings
--------------------------------------------------------------------------------
Update Information:
atuin:
Update to version 18.11.0
Atuin 18.9.0 fixes fish 4.x removal of bind -k (rhbz#2440541)
Add better documentation of how to handle MSRV
Move the profile.d script outside of the spec file
rust-metrics-exporter-prometheus:
Update to 0.17.2
rust-metrics-util:
Update to 0.20.1 (rhbz#2361247)
rust-norm:
Import rhbz#2437707
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 13 2026 Cristian Le <git(a)lecris.dev> - 0.1.1-1
- Import rhbz#2437707
--------------------------------------------------------------------------------
================================================================================
rust-sequoia-openpgp1-1.22.0-4.el9 (FEDORA-EPEL-2026-b877e66c83)
OpenPGP data types and associated machinery
--------------------------------------------------------------------------------
Update Information:
Backport change to relax the lalrpop / lalrpop-util crate dependencies to allow
building with v0.22. Fixes FailsToInstall issues on Fedora 42 and on EPEL 9.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Fabio Valentini <decathorpe(a)gmail.com> - 1.22.0-4
- Relax lalrpop dependency to allow up to v0.22
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2440931 - F42FailsToInstall: rust-sequoia-openpgp1-devel
https://bugzilla.redhat.com/show_bug.cgi?id=2440931
--------------------------------------------------------------------------------
================================================================================
rust-zlib-rs-0.6.2-1.el9 (FEDORA-EPEL-2026-31e026934a)
Memory-safe zlib implementation written in rust
--------------------------------------------------------------------------------
Update Information:
Update rust-zlib-rs and rust-libz-rs-sys to 0.6.2, fixing some possible integer
overflows.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.6.2-1
- Update to version 0.6.2; Fixes RHBZ#2440369
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2440369 - rust-zlib-rs-0.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2440369
[ 2 ] Bug #2440377 - rust-libz-rs-sys-0.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2440377
--------------------------------------------------------------------------------
================================================================================
scitokens-cpp-1.4.0-3.el9 (FEDORA-EPEL-2026-cc713fdbd9)
C++ Implementation of the SciTokens Library
--------------------------------------------------------------------------------
Update Information:
Add keycache.allow_in_memory config option with in-memory SQLite fallback
Add persistent anchor connection for shared in-memory SQLite database
Improve error messages when keycache file cannot be read or written
Add integration test for keycache not-writable error message
Improve cache directory permission tests to handle common deployment
misconfigurations
Implement keycache location retrieval and update library to 0.0.3
Fix typo in SQLite file extension in integration and main tests
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 19 2026 Derek Weitzel <dweitzel(a)unl.edu> - 1.4.0-3
- Replace cmake3 with cmake macros
* Thu Feb 19 2026 Derek Weitzel <dweitzel(a)unl.edu> - 1.4.0-2
- Add keycache.allow_in_memory config option with in-memory SQLite fallback
- Add persistent anchor connection for shared in-memory SQLite database
- Improve error messages when keycache file cannot be read or written
- Add integration test for keycache not-writable error message
- Improve cache directory permission tests to handle common deployment misconfigurations
- Implement keycache location retrieval and update library to 0.0.3
- Fix typo in SQLite file extension in integration and main tests
--------------------------------------------------------------------------------
The following Fedora EPEL 8 Security updates need testing:
Age URL
90 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-5b2095e2c2 xpdf-4.06-1.el8
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-5e10141457 openbao-2.5.0-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
apptainer-1.4.5-3.el8
tuptime-5.2.5-2.el8
Details about builds:
================================================================================
apptainer-1.4.5-3.el8 (FEDORA-EPEL-2026-82f07c2a59)
Application and environment virtualization formerly known as Singularity
--------------------------------------------------------------------------------
Update Information:
Enable FIPS support. This was built with golang-1.25.7 so it also fixes these
CVE's based on older golang versions: CVE-2025-61723, CVE-2025-61725,
CVE-2025-58183, CVE-2025-58185, CVE-2025-58188, and CVE-2025-58189.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Dave Dykstra <dwd(a)cern.ch> - 1.4.5-3
- Enable FIPS support. Fixes BZ#2437258.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2407504 - CVE-2025-58189 apptainer: go crypto/tls ALPN negotiation error contains attacker controlled information [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2407504
[ 2 ] Bug #2408539 - CVE-2025-61725 apptainer: Excessive CPU consumption in ParseAddress in net/mail [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2408539
[ 3 ] Bug #2408956 - CVE-2025-61723 apptainer: Quadratic complexity when parsing some invalid inputs in encoding/pem [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2408956
[ 4 ] Bug #2409898 - CVE-2025-58185 apptainer: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2409898
[ 5 ] Bug #2410838 - CVE-2025-58188 apptainer: Panic when validating certificates with DSA public keys in crypto/x509 [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2410838
[ 6 ] Bug #2412476 - CVE-2025-58183 apptainer: Unbounded allocation when parsing GNU sparse map [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2412476
[ 7 ] Bug #2437258 - Apptainer is compiled without FIPS support
https://bugzilla.redhat.com/show_bug.cgi?id=2437258
--------------------------------------------------------------------------------
================================================================================
tuptime-5.2.5-2.el8 (FEDORA-EPEL-2026-00184bb972)
Report historical system real time
--------------------------------------------------------------------------------
Update Information:
Drop some unnecessary files from the production RPM
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Frank Crawford <frank(a)crawford.emu.id.au> - 5.2.5-2
- Drop some unnecessary files from the production RPM
--------------------------------------------------------------------------------
The following Fedora EPEL 10.1 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-eea9bfd64c roundcubemail-1.6.13-1.el10_1
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-e148a6bb84 python3.13-3.13.12-1.el10_1
The following builds have been pushed to Fedora EPEL 10.1 updates-testing
apptainer-1.4.5-3.el10_1
dpkg-1.23.5-2.el10_1
libdivide-5.3.0-1.el10_1
steam-devices-1.0.0.101^git20260123.e0ab314-7.el10_1
tuptime-5.2.5-2.el10_1
Details about builds:
================================================================================
apptainer-1.4.5-3.el10_1 (FEDORA-EPEL-2026-aba9cbc84b)
Application and environment virtualization formerly known as Singularity
--------------------------------------------------------------------------------
Update Information:
Enable FIPS support. This was built with golang-1.25.7 so it also fixes these
CVE's based on older golang versions: CVE-2025-61723, CVE-2025-61725,
CVE-2025-58183, CVE-2025-58185, CVE-2025-58188, and CVE-2025-58189.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Dave Dykstra <dwd(a)cern.ch> - 1.4.5-3
- Enable FIPS support. Fixes BZ#2437258.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2407465 - CVE-2025-58189 apptainer: go crypto/tls ALPN negotiation error contains attacker controlled information [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2407465
[ 2 ] Bug #2408523 - CVE-2025-61725 apptainer: Excessive CPU consumption in ParseAddress in net/mail [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2408523
[ 3 ] Bug #2408910 - CVE-2025-61723 apptainer: Quadratic complexity when parsing some invalid inputs in encoding/pem [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2408910
[ 4 ] Bug #2409855 - CVE-2025-58185 apptainer: Parsing DER payload can cause memory exhaustion in encoding/asn1 [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2409855
[ 5 ] Bug #2410799 - CVE-2025-58188 apptainer: Panic when validating certificates with DSA public keys in crypto/x509 [epel-10]
https://bugzilla.redhat.com/show_bug.cgi?id=2410799
[ 6 ] Bug #2412476 - CVE-2025-58183 apptainer: Unbounded allocation when parsing GNU sparse map [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2412476
[ 7 ] Bug #2437258 - Apptainer is compiled without FIPS support
https://bugzilla.redhat.com/show_bug.cgi?id=2437258
--------------------------------------------------------------------------------
================================================================================
dpkg-1.23.5-2.el10_1 (FEDORA-EPEL-2026-93c4172065)
Package maintenance system for Debian Linux
--------------------------------------------------------------------------------
Update Information:
Update to version 1.23.5.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Simone Caronni <negativo17(a)gmail.com> - 1.23.5-2
- Trim changelog
* Tue Feb 17 2026 Simone Caronni <negativo17(a)gmail.com> - 1.23.5-1
- Update to 1.23.5
* Tue Feb 17 2026 Simone Caronni <negativo17(a)gmail.com> - 1.22.21-1
- Update to 1.22.21
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.22.20-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.22.20-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Wed Jul 23 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.22.20-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2423143 - dpkg-1.23.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2423143
--------------------------------------------------------------------------------
================================================================================
libdivide-5.3.0-1.el10_1 (FEDORA-EPEL-2026-d447559985)
Optimized integer division
--------------------------------------------------------------------------------
Update Information:
Update to 5.3.0
https://github.com/ridiculousfish/libdivide/releases/tag/v5.3.0
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 16 2026 Benjamin A. Beasley <code(a)musicinmybrain.net> - 5.3.0-1
- Update to 5.3.0 (close RHBZ#2440259)
* Fri Jan 16 2026 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.2.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild
* Thu Jul 24 2025 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.2.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2440259 - libdivide-5.3.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2440259
--------------------------------------------------------------------------------
================================================================================
steam-devices-1.0.0.101^git20260123.e0ab314-7.el10_1 (FEDORA-EPEL-2026-e70f2baecb)
Device support for Steam-related hardware
--------------------------------------------------------------------------------
Update Information:
Update to latest snapshot.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Simone Caronni <negativo17(a)gmail.com> - 1.0.0.101^git20260123.e0ab314-7
- Update to latest snapshot.
--------------------------------------------------------------------------------
================================================================================
tuptime-5.2.5-2.el10_1 (FEDORA-EPEL-2026-6c2bd39a81)
Report historical system real time
--------------------------------------------------------------------------------
Update Information:
Drop some unnecessary files from the production RPM
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 17 2026 Frank Crawford <frank(a)crawford.emu.id.au> - 5.2.5-2
- Drop some unnecessary files from the production RPM
--------------------------------------------------------------------------------