The following Fedora 35 Security updates need testing:
Age URL
231
https://bodhi.fedoraproject.org/updates/FEDORA-2022-dfc6924a11
mysql-connector-java-8.0.28-1.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-204ee3da84
unbound-1.16.3-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-bafb72fdc0 efl-1.26.3-1.fc35
enlightenment-0.25.4-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-3dd3274ae2
libdxfrw-1.1.0-0.1.rc1.fc35 librecad-2.2.0-0.15.rc4.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-cdeabe1bc0
postgresql-jdbc-42.2.26-1.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-3ca063941b
chromium-105.0.5195.125-2.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-23e6ee1fb9 squid-5.7-1.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-07dd9375b2
scala-2.13.9-1.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-c26b19568d
lighttpd-1.4.67-1.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-5b644a935b bash-5.1.8-3.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-58055cb1ef
nodejs-16.17.1-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-afdea1c747 php-8.0.24-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-e0a87993b8
booth-1.0-251.4.bfb2f92.git.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-4490a4772d
php-twig-1.44.7-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-d39b2a755b
php-twig2-2.15.3-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-e915614918
php-twig3-3.4.3-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-c68d90efc3 expat-2.4.9-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-1454bee2fa
thunderbird-102.3.1-1.fc35
The following Fedora 35 Critical Path updates have yet to be approved:
Age URL
50
https://bodhi.fedoraproject.org/updates/FEDORA-2022-bca7996d14
annobin-10.81-1.fc35
14
https://bodhi.fedoraproject.org/updates/FEDORA-2022-97f6c4fd2a
libblockdev-2.28-2.fc35
11
https://bodhi.fedoraproject.org/updates/FEDORA-2022-f292a3fec5
python-urllib3-1.26.12-1.fc35
11
https://bodhi.fedoraproject.org/updates/FEDORA-2022-22e2ce7a16
shadow-utils-4.9-11.fc35
9
https://bodhi.fedoraproject.org/updates/FEDORA-2022-64e32530e5
mtools-4.0.41-1.fc35
8
https://bodhi.fedoraproject.org/updates/FEDORA-2022-68ba1f1566
appstream-data-35-8.fc35
8
https://bodhi.fedoraproject.org/updates/FEDORA-2022-ece971e713
langtable-0.0.60-1.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-204ee3da84
unbound-1.16.3-1.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-642c095091
dnf-plugins-core-4.3.1-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-341937ef95
hwdata-0.362-2.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-38bd922ff7
libbluray-1.3.3-1.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-17a4844b47
tzdata-2022d-1.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-cd0501fc8f
ima-evm-utils-1.3.2-4.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-5b644a935b bash-5.1.8-3.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-53d671cb30 rsync-3.2.6-2.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-1454bee2fa
thunderbird-102.3.1-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-bdc70ae90d
linux-firmware-20220913-140.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-c68d90efc3 expat-2.4.9-1.fc35
1
https://bodhi.fedoraproject.org/updates/FEDORA-2022-55648ecee1
samba-4.15.10-0.fc35
The following builds have been pushed to Fedora 35 updates-testing
ansible-2.9.27-4.fc35
ansible-packaging-1-8.1.fc35
archlinux-keyring-20220927-1.fc35
dotnet3.1-3.1.423-1.fc35
fluidsynth-2.3.0-1.fc35
gitqlient-1.5.0-2.fc35
golang-github-task-3.16.0-1.fc35
google-api-python-client-2.63.0-1.fc35
mame-0.248-1.fc35
php-getid3-1.9.22-1.fc35
php-symfony4-4.4.46-1.fc35
rust-sha1collisiondetection-0.2.6-1.fc35
rust-tzfile-0.1.3-5.fc35
sysmontask-1.3.9-8.fc35
testssl-3.0.8-1.fc35
Details about builds:
================================================================================
ansible-2.9.27-4.fc35 (FEDORA-2022-008f09ea1f)
SSH-based configuration management, deployment, and task execution system
--------------------------------------------------------------------------------
Update Information:
## ansible - Drop ansible-packaging dependency ## ansible-packaging - Refactor
%ansible_collection_url, %ansible_collection_install, %ansible_test_unit. -
Specfiles no longer need to define %collection_namespace or %collection_name
for the macros to work. - Add new %ansible_collections_dir, %ansible_roles_dir,
and %ansible_collection_filelist macros. - Prepare to deprecate
%ansible_collection_files - Undefine %_package_note_file to stop that file from
leaking into collection artifacts. - Require ansible-core at buildtime now
that the source of the conflict has been addressed. Relates: 2121892
--------------------------------------------------------------------------------
ChangeLog:
* Sun Sep 25 2022 Maxwell G <gotmax(a)e.email> - 2.9.27-4
- Remove ansible-packaging dependency
- Related: #2121892 and #2126557.
--------------------------------------------------------------------------------
================================================================================
ansible-packaging-1-8.1.fc35 (FEDORA-2022-008f09ea1f)
RPM packaging macros and generators for Ansible collections
--------------------------------------------------------------------------------
Update Information:
## ansible - Drop ansible-packaging dependency ## ansible-packaging - Refactor
%ansible_collection_url, %ansible_collection_install, %ansible_test_unit. -
Specfiles no longer need to define %collection_namespace or %collection_name
for the macros to work. - Add new %ansible_collections_dir, %ansible_roles_dir,
and %ansible_collection_filelist macros. - Prepare to deprecate
%ansible_collection_files - Undefine %_package_note_file to stop that file from
leaking into collection artifacts. - Require ansible-core at buildtime now
that the source of the conflict has been addressed. Relates: 2121892
--------------------------------------------------------------------------------
ChangeLog:
* Sat Sep 24 2022 Maxwell G <gotmax(a)e.email> - 1-8.1
- Refactor %ansible_collection_url, %ansible_collection_install,
%ansible_test_unit.
- Specfiles no longer need to define %collection_namespace or %collection_name
for the macros to work.
- Add new %ansible_collections_dir, %ansible_roles_dir, and
%ansible_collection_filelist macros.
- Prepare to deprecate %ansible_collection_files
- Undefine %_package_note_file to stop that file from leaking into collection
artifacts.
- Require ansible-core at buildtime now that the source of the conflict
has been addressed.
Relates: 2121892
--------------------------------------------------------------------------------
================================================================================
archlinux-keyring-20220927-1.fc35 (FEDORA-2022-96bacd8346)
GPG keys used by Arch distribution to sign packages
--------------------------------------------------------------------------------
Update Information:
Version 20220927 (#2130137)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Frantisek Sumsal <frantisek(a)sumsal.cz> 20220927-1
- Version 20220927 (#2130137)
--------------------------------------------------------------------------------
================================================================================
dotnet3.1-3.1.423-1.fc35 (FEDORA-2022-847c67b3cd)
.NET Core Runtime and SDK
--------------------------------------------------------------------------------
Update Information:
Update to the September 2022 update release of .NET Core 3.1 Release Notes:
https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md
This includes a fix for CVE-2022-38013
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 27 2022 Omair Majid <omajid(a)redhat.com> - 3.1.423-1
- Update to .NET SDK 3.1.423 and Runtime 3.1.29
--------------------------------------------------------------------------------
================================================================================
fluidsynth-2.3.0-1.fc35 (FEDORA-2022-c8b9590254)
Real-time software synthesizer
--------------------------------------------------------------------------------
Update Information:
Update to 2.3.0 Add Pipewire audio driver
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Christoph Karl <pampelmuse [AT] gmx [DOT] at> - 2.3.0-1
- Update to 2.3.0
--------------------------------------------------------------------------------
================================================================================
gitqlient-1.5.0-2.fc35 (FEDORA-2022-4b9af31ea5)
Multi-platform Git client written with Qt
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Artem Polishchuk <ego.cordatus(a)gmail.com> 1.5.0-2
- build: Add qt5-qtsvg dep | rhbz#2001086
* Thu Sep 29 2022 Artem Polishchuk <ego.cordatus(a)gmail.com> 1.5.0-1
- chore(update): 1.5.0
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.4.3-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.4.3-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
golang-github-task-3.16.0-1.fc35 (FEDORA-2022-9e5cc6671c)
A task runner / simpler Make alternative written in Go
--------------------------------------------------------------------------------
Update Information:
update to v3.16.0 (closes rhbz#2131132) and switch to autorelease/changelog
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Mark E. Fuller <mark.e.fuller(a)gmx.de> - 3.16.0-1
- Update to v3.16.0 (close rhbz#2131132)
* Tue Sep 20 2022 Mark E. Fuller <mark.e.fuller(a)gmx.de> - 3.15.2-1
- Update to v3.15.2 (closes rhbz#2125765)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2131132 - golang-github-task-3.16.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2131132
--------------------------------------------------------------------------------
================================================================================
google-api-python-client-2.63.0-1.fc35 (FEDORA-2022-1914b9fb7e)
Google APIs Client Library for Python
--------------------------------------------------------------------------------
Update Information:
Update to 2.63.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> 2:2.63.0-1
- Update to 2.63.0 - Closes rhbz#2130929
--------------------------------------------------------------------------------
================================================================================
mame-0.248-1.fc35 (FEDORA-2022-1f19f728bd)
Multiple Arcade Machine Emulator
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release: *
https://www.mamedev.org/?p=517
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 29 2022 Julian Sikorski <belegdol(a)fedoraproject.org> 0.248-1
- Update to 0.248
--------------------------------------------------------------------------------
================================================================================
php-getid3-1.9.22-1.fc35 (FEDORA-2022-f26b2c22df)
The PHP media file parser
--------------------------------------------------------------------------------
Update Information:
**Version 1.9.22**: (2022-09-29) James Heinrich :: 1.9.22-202207161647 * bugfix
#387 fails to detect h265 video codec (QuickTime) * bugfix #385 Quicktime
extended atom size * bugfix #378 AAC bitrate cache warning * bugfix #376
simplexml_load_string improvments * bugfix #374 MOD improved SoundTracker
support * bugfix #371 fragmented MP4 unsupported warning * bugfix #369 fix
remote URLs pattern * bugfix #366 change @error-suppress to isset (quicktime) *
bugfix #365 ZIP array offset on value of type int * bugfix #364 add support for
ANIMEXTS1.0 in GIF files * bugfix #363 ASF improve support of Header Extension
Object data * bugfix #362 version update for ramsey/composer-install * bugfix
#359 MPEG-2 aspect ratio divide-by-zero * bugfix #358 free format mp3 bitrate *
bugfix #355 undefined array key in ID3v2 chapters * bugfix #352 avoid false
detection of Musepack format * bugfix #351 Incorrect length passed to fread on a
flac file * bugfix #348 more targeted usage of clearstatcache calls * bugfix
#347 fixed reported by PHPStan v0.12.99 * bugfix QuickTime support 'ID32' frame
(ID3v2 inside QT) * bugfix fix various PHP 8.1 issues * bugfix PDF prevent
undefined index
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Remi Collet <remi(a)remirepo.net> - 1.9.22-1
- update to 1.9.22
--------------------------------------------------------------------------------
================================================================================
php-symfony4-4.4.46-1.fc35 (FEDORA-2022-90d31ff089)
Symfony PHP framework (version 4)
--------------------------------------------------------------------------------
Update Information:
**Version 4.4.46** (2022-09-30) * bug #47547 [Ldap] Do not run
ldap_set_option on failed connection (tatankat) * bug #47578 [Security] Fix
AbstractFormLoginAuthenticator return types (AndrolGenhald) * bug #47614
[FrameworkBundle] Fix a phpdoc in mailer assertions (HeahDude) * bug #47516
[HttpFoundation] Prevent BinaryFileResponse::prepare from adding content type if
no content is sent (naitsirch) * bug #47533 [Messenger] decode URL-encoded
characters in DSN's usernames/passwords (xabbuh) * bug #47530 [HttpFoundation]
Always return strings from accept headers (ausi) * bug #47497 [Bridge] Fix
mkdir() race condition in ProxyCacheWarmer (andrey-tech) * bug #47415
[HttpClient] Psr18Client ignore invalid HTTP headers (nuryagdym) * bug #47435
[HttpKernel] lock when writting profiles (nicolas-grekas) * bug #47437 [Mime]
Fix email rendering when having inlined parts that are not related to the
content (fabpot) * bug #47434 [HttpFoundation] move flushing outside of
Response::closeOutputBuffers (nicolas-grekas) * bug #47351 [FrameworkBundle] Do
not throw when describing a factory definition (MatTheCat) * bug #47403
[Mailer] Fix edge cases in STMP transports (fabpot)
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Remi Collet <remi(a)remirepo.net> - 4.4.46-1
- update to 4.4.46
--------------------------------------------------------------------------------
================================================================================
rust-sha1collisiondetection-0.2.6-1.fc35 (FEDORA-2022-bd1ba94168)
SHA-1 hash function with collision detection and mitigation
--------------------------------------------------------------------------------
Update Information:
Update to version 0.2.6.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Fabio Valentini <decathorpe(a)gmail.com> 0.2.6-1
- Update to version 0.2.6; Fixes RHBZ#2122032
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> 0.2.5-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Tue Feb 15 2022 Zbigniew J��drzejewski-Szmek <zbyszek(a)in.waw.pl> 0.2.5-2
- Rebuild with package notes
--------------------------------------------------------------------------------
================================================================================
rust-tzfile-0.1.3-5.fc35 (FEDORA-2022-f4e7b5f5be)
Chrono::TimeZone implementation using system tz database
--------------------------------------------------------------------------------
Update Information:
Skip tests that fail with tzdata 2022b and newer. Fixes FTBFS issues on all
branches of Fedora.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Fabio Valentini <decathorpe(a)gmail.com> - 0.1.3-5
- Skip a test that fails with tzdata 2022b and newer.
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.3-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Fri Jan 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.1.3-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
sysmontask-1.3.9-8.fc35 (FEDORA-2022-decff36f65)
Linux system monitor with the compactness and usefulness of WTM
--------------------------------------------------------------------------------
Update Information:
fix: Add libwnck3 dep | rhbz#2130770
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Artem Polishchuk <ego.cordatus(a)gmail.com> 1.3.9-8
- chore(update): Add libwnck3 dep | rhbz#2130770
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.9-6
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Mon Jun 13 2022 Python Maint <python-maint(a)redhat.com> - 1.3.9-5
- Rebuilt for Python 3.11
* Sat Jan 22 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.3.9-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2130770 - sysmontask is missing dependency on libwnck3
https://bugzilla.redhat.com/show_bug.cgi?id=2130770
--------------------------------------------------------------------------------
================================================================================
testssl-3.0.8-1.fc35 (FEDORA-2022-8afc7f0eb7)
Testing TLS/SSL encryption
--------------------------------------------------------------------------------
Update Information:
Update to 3.0.8
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> 3.0.8-1
- Update to 3.0.8 - Closes rhbz#2131338
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> 3.0.7-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
--------------------------------------------------------------------------------