The following Fedora EPEL 8 Security updates need testing:
Age URL
7
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-34c7addedb
chromium-121.0.6167.160-1.el8
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-4d3eb328e3
libmodsecurity-3.0.12-1.el8
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-10430622fd
syncthing-1.27.3-1.el8
1
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2024-0b7ba715af
pdns-recursor-4.8.6-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
ascii-3.20-1.el8
lexertl14-0.1.0-21.20240216git7a365a2.el8
libmongocrypt-1.9.0-1.el8
mock-5.5-1.el8
mock-core-configs-40.2-1.el8
python-treq-20.4.1-1.el8
python-virt-firmware-24.2-1.el8
Details about builds:
================================================================================
ascii-3.20-1.el8 (FEDORA-EPEL-2024-734f899efe)
Interactive ascii name and synonym chart
--------------------------------------------------------------------------------
Update Information:
Update from upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Didier Fabert <didier.fabert(a)gmail.com> - 3.20-1
- Update to 3.20 version
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2264550 - ascii-3.20 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2264550
--------------------------------------------------------------------------------
================================================================================
lexertl14-0.1.0-21.20240216git7a365a2.el8 (FEDORA-EPEL-2024-08b49cccda)
The Modular Lexical Analyser Generator
--------------------------------------------------------------------------------
Update Information:
Update to 0.1.0^20240216git7a365a2
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.1.0-21
- Update to 0.1.0^20240216git7a365a2
* Fri Feb 16 2024 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.1.0-20
- Keep timestamps when converting text file line endings
* Fri Feb 16 2024 Benjamin A. Beasley <code(a)musicinmybrain.net> - 0.1.0-19
- Update to c045058 (multilib fixed upstream)
--------------------------------------------------------------------------------
================================================================================
libmongocrypt-1.9.0-1.el8 (FEDORA-EPEL-2024-c96deabbe8)
The companion C library for client side encryption in drivers
--------------------------------------------------------------------------------
Update Information:
Version 1.9.0
New features
Support named KMS providers.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Remi Collet <remi(a)remirepo.net> - 1.9.0-1
- update to 1.9.0
--------------------------------------------------------------------------------
================================================================================
mock-5.5-1.el8 (FEDORA-EPEL-2024-e9e1b2dad6)
Builds packages inside chroots
--------------------------------------------------------------------------------
Update Information:
https://rpm-software-management.github.io/mock/Release-Notes-5.5
https://rpm-software-management.github.io/mock/Release-Notes-Configs-40.2
--------------------------------------------------------------------------------
ChangeLog:
* Wed Feb 14 2024 Pavel Raiskup <praiskup(a)redhat.com>
- allow chroot_scan to create archive instead of directory (tkopecek(a)redhat.com)
- handle greedy options in Bash completion
- fix root_cache invalidation (not) triggered by config changes
- new '{{ repo_arch }}' Jinja2 template support
- package_manager: disable %-interpolation in dnf.conf parser
- only `chown` the in-chroot home files with the --rebuild mode
- all non-privileged actions performed wiht EGID=135 (mock group)
- mock newly requires a precise version of mock-filesystem
- allow shadow-utils to run in buildroot by exception if necessary (martjack(a)redhat.com)
- hw_info now reports file system type (vondruch(a)redhat.com)
--------------------------------------------------------------------------------
================================================================================
mock-core-configs-40.2-1.el8 (FEDORA-EPEL-2024-e9e1b2dad6)
Mock core config files basic chroots
--------------------------------------------------------------------------------
Update Information:
https://rpm-software-management.github.io/mock/Release-Notes-5.5
https://rpm-software-management.github.io/mock/Release-Notes-Configs-40.2
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Pavel Raiskup <praiskup(a)redhat.com> 40.2-1
- Use dnf5 on Fedora 40+ (miro(a)hroncok.cz)
* Wed Feb 14 2024 Pavel Raiskup <praiskup(a)redhat.com> 40.1-1
- new '{{ repo_arch }}' template variable used for Mageia
- Mageia 7 is EOL (wally(a)mageia.org)
- OpenMandriva i686 is EOL (frostyx(a)email.cz)
- Fedora 40 branched
--------------------------------------------------------------------------------
================================================================================
python-treq-20.4.1-1.el8 (FEDORA-EPEL-2024-aa663fed4a)
A requests-like API built on top of twisted.web's Agent
--------------------------------------------------------------------------------
Update Information:
Update to 20.4.1 (latest possible in EPEL8 currently)
Backport patch for CVE-2022-23607 (bz#2049579)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Orion Poplawski <orion(a)nwra.com> - 20.4.1-1
- Update to 20.4.1 (latest possible in EPEL8 currently)
- Backport patch for CVE-2022-23607 (bz#2049579)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2049579 - CVE-2022-23607 python-treq: Exposure of Sensitive Information to
an Unauthorized Actor [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2049579
--------------------------------------------------------------------------------
================================================================================
python-virt-firmware-24.2-1.el8 (FEDORA-EPEL-2024-0860114e0e)
Tools for virtual machine firmware volumes
--------------------------------------------------------------------------------
Update Information:
update to version 24.2
--------------------------------------------------------------------------------
ChangeLog:
* Fri Feb 16 2024 Gerd Hoffmann <kraxel(a)redhat.com> - 24.2-1
- update to version 24.2
--------------------------------------------------------------------------------