The following Fedora EPEL 8 Security updates need testing:
Age URL
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-d07bda68c0
php-adodb-5.22.10-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
apptainer-1.4.2-1.el8
baresip-4.0.0-1.el8
libre-4.0.0-1.el8
Details about builds:
================================================================================
apptainer-1.4.2-1.el8 (FEDORA-EPEL-2025-3ac8c09de6)
Application and environment virtualization formerly known as Singularity
--------------------------------------------------------------------------------
Update Information:
Update to upstream 1.4.2 and fix CVE-2025-22870
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 8 2025 Dave Dykstra <[email protected]> - 1.4.2
- Update to upstream 1.4.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2351865 - CVE-2025-22870 apptainer: HTTP Proxy bypass using IPv6
Zone IDs in golang.org/x/net [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2351865
[ 2 ] Bug #2387209 - apptainer-1.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2387209
--------------------------------------------------------------------------------
================================================================================
baresip-4.0.0-1.el8 (FEDORA-EPEL-2025-8ab557eb02)
Modular SIP user-agent with audio and video support
--------------------------------------------------------------------------------
Update Information:
Baresip v4.0.0 (2025-08-06)
bevent: ensure that pointer to call is valid
ebuacip: move to baresip-apps
net: remove IPv6 check which is no longer needed
av1: remove backwards definition of AOM_USAGE_REALTIME
srtp: fix size err printf
avcodec: remove ifdef AV_CODEC_ID_H265, should be always enabled
misc: add baresip_version() to get Baresip version string
docs: update README
bevent: remove deprecated ua_event API
ctrl_dbus: check return value of mtx_init()
pulse: use str_ncpy() instead of insecure strcpy()
av1: use av1_packetize() function instead of wrapper
enum ua event rename
call: prepare to receive video immediately with 200 Ok
in_band_dtmf: fix cross compiler alignment warning
uri: remove password field
audio: remove deprecated audio_start
bevent: remove unused CNT_DEPRECATED_WARNINGS enum
Baresip v3.24.0 (2025-07-09)
test/ccheck: add LIST_FOREACH_SAFE check
config: removed "rtp_rxmode thread is currently experimental" warning
gzrtp: increase mbuf size if about to run out
ci: update mingw.yml
ci/clang: use clang-20
call: Get cancel reason from close message
uuid: check that uuid file contains valid uuid
test/jbuf_gnack: add Generic NACK jitterbuffer test
menu: Add hangup sound on closed calls
rtp: use rtp_seq_less
cmake: sort SRCS in alphabetical order
aac: fix debug printf (confSize)
webrtc: init re_trace.json if enabled
prepare for release -- bump version to 3.24.0
libre v4.0.0 (2025-08-06)
rem: remove backwards wrapper for au_calc_nsamp()
rem: remove local macros, include stdint.h instead
mod: remove unused MOD_PRE macro
tcp: remove special case for mingw32/wine
dd: update AV1 and DD docs
test: fix formatted string arguments in URI testcode
tls: drop OpenSSL 1.1.1 support
Update supported OS versions
readme: update supported compilers
tls: disable tls_conn_change_cert for LibreSSL
ci/ssl: bump ssl tools assets
aubuf: remove unused struct auframe in ajb.c
aubuf: remove unused private function plot_underrun()
readme: bump supported GNU C library (glibc) 2.31
misc: remove deprecated functions/params
uri: remove password field
websock: increase test coverage
udp: remove obsolete todo in udp_local_get()
av1: remove av1_packetize_new() -- backwards compat wrapper
tls: remove tls_set_selfsigned_rsa() -- use Elliptic Curve instead
test: enable dtls_set_single() for DTLS client test
libre v3.24.0 (2025-07-09)
list: add LIST_FOREACH_SAFE helper macro
test: SDP interop testing
ci/abi: bump old ref version
list: improve already linked warning
ci/mingw: use windows-latest
ci/clang: use clang-20
av1: rename av1_packetize_new() and add wrapper
trice: update header to match filename
rtp/rr: fix fraction left shift promotion
test/sipsess: cast rel100_mode
test: print trice_debug to buffer to test debug functions
trice: update doxygen documentation
rtp: add rtp_seq_less inline function helper
trice: remove trice_set_software()
trice: always enable PRFLX candidates
rtp: add TWCC packet definition helpers
test: add support check for SRTP GCM test cases
trice: add more doxygen comments
prepare for release -- bump version to 3.24.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 9 2025 Robert Scheck <[email protected]> 4.0.0-1
- Upgrade to 4.0.0 (#2379005)
* Wed Jul 23 2025 Fedora Release Engineering <[email protected]> -
3.23.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2378962 - libre-4.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2378962
[ 2 ] Bug #2379005 - baresip-4.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2379005
--------------------------------------------------------------------------------
================================================================================
libre-4.0.0-1.el8 (FEDORA-EPEL-2025-8ab557eb02)
Generic library for real-time communications
--------------------------------------------------------------------------------
Update Information:
Baresip v4.0.0 (2025-08-06)
bevent: ensure that pointer to call is valid
ebuacip: move to baresip-apps
net: remove IPv6 check which is no longer needed
av1: remove backwards definition of AOM_USAGE_REALTIME
srtp: fix size err printf
avcodec: remove ifdef AV_CODEC_ID_H265, should be always enabled
misc: add baresip_version() to get Baresip version string
docs: update README
bevent: remove deprecated ua_event API
ctrl_dbus: check return value of mtx_init()
pulse: use str_ncpy() instead of insecure strcpy()
av1: use av1_packetize() function instead of wrapper
enum ua event rename
call: prepare to receive video immediately with 200 Ok
in_band_dtmf: fix cross compiler alignment warning
uri: remove password field
audio: remove deprecated audio_start
bevent: remove unused CNT_DEPRECATED_WARNINGS enum
Baresip v3.24.0 (2025-07-09)
test/ccheck: add LIST_FOREACH_SAFE check
config: removed "rtp_rxmode thread is currently experimental" warning
gzrtp: increase mbuf size if about to run out
ci: update mingw.yml
ci/clang: use clang-20
call: Get cancel reason from close message
uuid: check that uuid file contains valid uuid
test/jbuf_gnack: add Generic NACK jitterbuffer test
menu: Add hangup sound on closed calls
rtp: use rtp_seq_less
cmake: sort SRCS in alphabetical order
aac: fix debug printf (confSize)
webrtc: init re_trace.json if enabled
prepare for release -- bump version to 3.24.0
libre v4.0.0 (2025-08-06)
rem: remove backwards wrapper for au_calc_nsamp()
rem: remove local macros, include stdint.h instead
mod: remove unused MOD_PRE macro
tcp: remove special case for mingw32/wine
dd: update AV1 and DD docs
test: fix formatted string arguments in URI testcode
tls: drop OpenSSL 1.1.1 support
Update supported OS versions
readme: update supported compilers
tls: disable tls_conn_change_cert for LibreSSL
ci/ssl: bump ssl tools assets
aubuf: remove unused struct auframe in ajb.c
aubuf: remove unused private function plot_underrun()
readme: bump supported GNU C library (glibc) 2.31
misc: remove deprecated functions/params
uri: remove password field
websock: increase test coverage
udp: remove obsolete todo in udp_local_get()
av1: remove av1_packetize_new() -- backwards compat wrapper
tls: remove tls_set_selfsigned_rsa() -- use Elliptic Curve instead
test: enable dtls_set_single() for DTLS client test
libre v3.24.0 (2025-07-09)
list: add LIST_FOREACH_SAFE helper macro
test: SDP interop testing
ci/abi: bump old ref version
list: improve already linked warning
ci/mingw: use windows-latest
ci/clang: use clang-20
av1: rename av1_packetize_new() and add wrapper
trice: update header to match filename
rtp/rr: fix fraction left shift promotion
test/sipsess: cast rel100_mode
test: print trice_debug to buffer to test debug functions
trice: update doxygen documentation
rtp: add rtp_seq_less inline function helper
trice: remove trice_set_software()
trice: always enable PRFLX candidates
rtp: add TWCC packet definition helpers
test: add support check for SRTP GCM test cases
trice: add more doxygen comments
prepare for release -- bump version to 3.24.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 9 2025 Robert Scheck <[email protected]> 4.0.0-1
- Upgrade to 4.0.0 (#2378962)
* Thu Jul 24 2025 Fedora Release Engineering <[email protected]> -
3.23.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2378962 - libre-4.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2378962
[ 2 ] Bug #2379005 - baresip-4.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2379005
--------------------------------------------------------------------------------
--
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://pagure.io/fedora-infrastructure/new_issue