The following Fedora EPEL 9 Security updates need testing:
Age URL
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-e35c40aadd
linenoise-1.0-3.20200312git97d2850.el9
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-305ac41026
libopenmpt-0.8.3-1.el9
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-b73f867b3a
lemonldap-ng-2.21.3-1.el9
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-73b3fd3fe3
perl-Cpanel-JSON-XS-4.40-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
chromium-140.0.7339.127-1.el9
kiwi-10.2.33-1.el9
kiwi-boxed-plugin-0.2.56-1.el9
nordugrid-arc7-7.1.0-1.el9
parallel-20250822-2.el9
postgresql16-anonymizer-2.3.0-2.el9
rpkg-1.68-7.el9
rust-bitstream-io-4.6.0-1.el9
rust-clang-ast-0.1.33-1.el9
rust-foldhash-0.2.0-1.el9
rust-foldhash0.1-0.1.5-1.el9
rust-indexmap-2.11.1-1.el9
rust-linux-raw-sys-0.11.0-1.el9
rust-png-0.18.0-1.el9
rust-png0.17-0.17.16-1.el9
rust-rustix-1.1.2-2.el9
rust-rustls-webpki-0.103.5-1.el9
rust-simba-0.9.1-1.el9
rust-target-lexicon-0.13.3-1.el9
rust-tiff-0.10.2-1.el9
rust-tiff0.9-0.9.1-1.el9
rust-twox-hash-2.1.2-1.el9
rust-unicode-ident-1.0.19-1.el9
rust-uuid-1.18.1-1.el9
rust-zune-jpeg-0.4.21-1.el9
smtprelay-1.12.0-1.el9
Details about builds:
================================================================================
chromium-140.0.7339.127-1.el9 (FEDORA-EPEL-2025-2f117a9b68)
A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:
Update to 140.0.7339.127
CVE-2025-10200: Use after free in Serviceworker
CVE-2025-10201: Inappropriate implementation in Mojo
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 11 2025 Than Ngo <[email protected]> - 140.0.7339.127-1
- Update to 140.0.7339.127
* CVE-2025-10200: Use after free in Serviceworker
* CVE-2025-10201: Inappropriate implementation in Mojo
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2390725 - CVE-2025-4609 chromium: Incorrect handle provided in
unspecified circumstances in Mojo [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2390725
[ 2 ] Bug #2392286 - CVE-2025-9478 chromium: Use after free in ANGLE [epel-8]
https://bugzilla.redhat.com/show_bug.cgi?id=2392286
[ 3 ] Bug #2392293 - CVE-2025-9478 chromium: Use after free in ANGLE
[fedora-42]
https://bugzilla.redhat.com/show_bug.cgi?id=2392293
[ 4 ] Bug #2393035 - CVE-2025-9864 chromium: Use after free in Cast in Google
Chrome [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2393035
[ 5 ] Bug #2393036 - CVE-2025-9864 chromium: Use after free in Cast in Google
Chrome [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2393036
[ 6 ] Bug #2393051 - CVE-2025-9866 chromium: Inappropriate implementation in
Extensions in Google Chrome [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2393051
[ 7 ] Bug #2393052 - CVE-2025-9866 chromium: Inappropriate implementation in
Extensions in Google Chrome [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2393052
--------------------------------------------------------------------------------
================================================================================
kiwi-10.2.33-1.el9 (FEDORA-EPEL-2025-7fc1ed6f03)
Flexible operating system image builder
--------------------------------------------------------------------------------
Update Information:
Add a fix to ensure os-prober does not activate during image builds and pick up
host environment boot entries and fix tumbleweed boxed build URL for AArch64
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Neal Gompa <[email protected]> - 10.2.33-1
- Update to 10.2.33
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2389061 - kiwi-boxed-plugin-0.2.56 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2389061
[ 2 ] Bug #2394539 - kiwi-10.2.33 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2394539
--------------------------------------------------------------------------------
================================================================================
kiwi-boxed-plugin-0.2.56-1.el9 (FEDORA-EPEL-2025-7fc1ed6f03)
KIWI - Boxed Build Plugin
--------------------------------------------------------------------------------
Update Information:
Add a fix to ensure os-prober does not activate during image builds and pick up
host environment boot entries and fix tumbleweed boxed build URL for AArch64
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Neal Gompa <[email protected]> - 0.2.56-1
- Update to 0.2.56
* Fri Aug 15 2025 Python Maint <[email protected]> - 0.2.55-2
- Rebuilt for Python 3.14.0rc2 bytecode
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2389061 - kiwi-boxed-plugin-0.2.56 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2389061
[ 2 ] Bug #2394539 - kiwi-10.2.33 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2394539
--------------------------------------------------------------------------------
================================================================================
nordugrid-arc7-7.1.0-1.el9 (FEDORA-EPEL-2025-2a311f3833)
Advanced Resource Connector Middleware
--------------------------------------------------------------------------------
Update Information:
ARC 7.1
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 11 2025 Mattias Ellert <[email protected]> - 7.1.0-1
- Update to version 7.1.0
* Tue May 20 2025 Mattias Ellert <[email protected]> - 7.0.0-4
- Don't build arc-exporter for EPEL 10.0 (missing dependency)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2372920 - Failure to detect DNF presence since migration to DNF5
https://bugzilla.redhat.com/show_bug.cgi?id=2372920
--------------------------------------------------------------------------------
================================================================================
parallel-20250822-2.el9 (FEDORA-EPEL-2025-dd410832e8)
Shell tool for executing jobs in parallel
--------------------------------------------------------------------------------
Update Information:
Update to 20250822
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Mikel Olasagasti Uranga <[email protected]> - 20250822-2
- Add missing BuildRequire on gnupg2
* Tue Sep 9 2025 Mikel Olasagasti Uranga <[email protected]> - 20250822-1
- Update to 20250822 - Closes rhbz#2394007
* Thu Jul 24 2025 Fedora Release Engineering <[email protected]> -
20241222-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Jan 17 2025 Fedora Release Engineering <[email protected]> -
20241222-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
postgresql16-anonymizer-2.3.0-2.el9 (FEDORA-EPEL-2025-0d14da3eca)
Mask or replace personally identifiable information (PII) or sensitive data
--------------------------------------------------------------------------------
Update Information:
Added an EPEL 9 build as required by customer, using the postgresql:16 module in
RHEL. Testing can be done by following the Quick Start guide in upstream's
README.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 11 2025 Petr Khartskhaev <[email protected]> - 2.3.0-2
- Adding package to EPEL 9 as required by customer
* Thu Sep 11 2025 Petr Khartskhaev <[email protected]> - 2.3.0-1
- Initial import (fedora#2391300).
--------------------------------------------------------------------------------
================================================================================
rpkg-1.68-7.el9 (FEDORA-EPEL-2025-ce60063066)
Python library for interacting with rpm+git
--------------------------------------------------------------------------------
Update Information:
Patch: Add mock configuration option to build and srpm
https://pagure.io/rpkg/pull-request/750
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 11 2025 OndÅej Nosek <[email protected]> - 1.68-7
- Patch: Add mock configuration option to build and srpm
--------------------------------------------------------------------------------
================================================================================
rust-bitstream-io-4.6.0-1.el9 (FEDORA-EPEL-2025-b409f1938e)
Library for reading/writing un-aligned values from/to streams
--------------------------------------------------------------------------------
Update Information:
Update to version 4.6.0.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 4.6.0-1
- Update to version 4.6.0; Fixes RHBZ#2394583
--------------------------------------------------------------------------------
================================================================================
rust-clang-ast-0.1.33-1.el9 (FEDORA-EPEL-2025-a6ed54ffa8)
Data structures for processing Clang's -ast-dump=json format
--------------------------------------------------------------------------------
Update Information:
Update the rustix crate to version 1.1.2.
Update the linux-raw-sys crate to version 0.11.0.
Update the clang-ast crate to version 0.1.33.
Update the foldhash crate to version 0.2.0.
Add a compat package for foldhash version 0.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.1.33-1
- Update to version 0.1.33; Fixes RHBZ#2390576
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.1.31-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-foldhash-0.2.0-1.el9 (FEDORA-EPEL-2025-a6ed54ffa8)
Fast, non-cryptographic, minimally DoS-resistant hashing algorithm
--------------------------------------------------------------------------------
Update Information:
Update the rustix crate to version 1.1.2.
Update the linux-raw-sys crate to version 0.11.0.
Update the clang-ast crate to version 0.1.33.
Update the foldhash crate to version 0.2.0.
Add a compat package for foldhash version 0.1.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 11 2025 Fabio Valentini <[email protected]> - 0.2.0-1
- Update to version 0.2.0; Fixes RHBZ#2390561
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.1.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-foldhash0.1-0.1.5-1.el9 (FEDORA-EPEL-2025-a6ed54ffa8)
Fast, non-cryptographic, minimally DoS-resistant hashing algorithm
--------------------------------------------------------------------------------
Update Information:
Update the rustix crate to version 1.1.2.
Update the linux-raw-sys crate to version 0.11.0.
Update the clang-ast crate to version 0.1.33.
Update the foldhash crate to version 0.2.0.
Add a compat package for foldhash version 0.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.1.5-1
- Initial import (foldhash 0.1 compat package)
--------------------------------------------------------------------------------
================================================================================
rust-indexmap-2.11.1-1.el9 (FEDORA-EPEL-2025-0966330fc8)
Hash table with consistent order and fast iteration
--------------------------------------------------------------------------------
Update Information:
Update to version 2.11.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 2.11.1-1
- Update to version 2.11.1; Fixes RHBZ#2393989
--------------------------------------------------------------------------------
================================================================================
rust-linux-raw-sys-0.11.0-1.el9 (FEDORA-EPEL-2025-a6ed54ffa8)
Generated bindings for Linux's userspace API
--------------------------------------------------------------------------------
Update Information:
Update the rustix crate to version 1.1.2.
Update the linux-raw-sys crate to version 0.11.0.
Update the clang-ast crate to version 0.1.33.
Update the foldhash crate to version 0.2.0.
Add a compat package for foldhash version 0.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.11.0-1
- Update to version 0.11.0; Fixes RHBZ#2375393
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.9.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-png-0.18.0-1.el9 (FEDORA-EPEL-2025-7480e285cf)
Decoding and encoding library in pure Rust
--------------------------------------------------------------------------------
Update Information:
Update the zune-jpeg crate to version 0.4.21.
Update the png crate to version 0.18.0 and add a compat package for version
0.17.
Update the tiff crate to version 0.10.2 and add a compat package for version
0.9.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.18.0-1
- Update to version 0.18.0; Fixes RHBZ#2391896
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.17.16-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <[email protected]> -
0.17.16-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-png0.17-0.17.16-1.el9 (FEDORA-EPEL-2025-7480e285cf)
Decoding and encoding library in pure Rust
--------------------------------------------------------------------------------
Update Information:
Update the zune-jpeg crate to version 0.4.21.
Update the png crate to version 0.18.0 and add a compat package for version
0.17.
Update the tiff crate to version 0.10.2 and add a compat package for version
0.9.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.17.16-1
- Initial import (png 0.17 compat package)
--------------------------------------------------------------------------------
================================================================================
rust-rustix-1.1.2-2.el9 (FEDORA-EPEL-2025-a6ed54ffa8)
Safe Rust bindings to POSIX/Unix/Linux/Winsock-like syscalls
--------------------------------------------------------------------------------
Update Information:
Update the rustix crate to version 1.1.2.
Update the linux-raw-sys crate to version 0.11.0.
Update the clang-ast crate to version 0.1.33.
Update the foldhash crate to version 0.2.0.
Add a compat package for foldhash version 0.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 1.1.2-2
- Fix bootstrap condition
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 1.1.2-1
- Update to version 1.1.2; Fixes RHBZ#2394015
--------------------------------------------------------------------------------
================================================================================
rust-rustls-webpki-0.103.5-1.el9 (FEDORA-EPEL-2025-06c2d56b2f)
Web PKI X.509 Certificate Verification
--------------------------------------------------------------------------------
Update Information:
Update to version 0.103.5.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.103.5-1
- Update to version 0.103.5; Fixes RHBZ#2394498
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.103.4-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-simba-0.9.1-1.el9 (FEDORA-EPEL-2025-bfa2b1523f)
SIMD algebra for Rust
--------------------------------------------------------------------------------
Update Information:
Update to version 0.9.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.9.1-1
- Update to version 0.9.1; Fixes RHBZ#2393460
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.9.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-target-lexicon-0.13.3-1.el9 (FEDORA-EPEL-2025-094eb2034e)
LLVM target triple types
--------------------------------------------------------------------------------
Update Information:
Update to version 0.13.3.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.13.3-1
- Update to version 0.13.3; Fixes RHBZ#2394211
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.13.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-tiff-0.10.2-1.el9 (FEDORA-EPEL-2025-7480e285cf)
Decoding and encoding library in pure Rust
--------------------------------------------------------------------------------
Update Information:
Update the zune-jpeg crate to version 0.4.21.
Update the png crate to version 0.18.0 and add a compat package for version
0.17.
Update the tiff crate to version 0.10.2 and add a compat package for version
0.9.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 Fabio Valentini <[email protected]> - 0.10.2-1
- Update to version 0.10.2
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.9.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sun Jan 19 2025 Fedora Release Engineering <[email protected]> -
0.9.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Sat Jul 20 2024 Fedora Release Engineering <[email protected]> -
0.9.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sat Jan 27 2024 Fedora Release Engineering <[email protected]> -
0.9.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-tiff0.9-0.9.1-1.el9 (FEDORA-EPEL-2025-7480e285cf)
Decoding and encoding library in pure Rust
--------------------------------------------------------------------------------
Update Information:
Update the zune-jpeg crate to version 0.4.21.
Update the png crate to version 0.18.0 and add a compat package for version
0.17.
Update the tiff crate to version 0.10.2 and add a compat package for version
0.9.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.9.1-1
- Initial import (tiff 0.9 compat package)
--------------------------------------------------------------------------------
================================================================================
rust-twox-hash-2.1.2-1.el9 (FEDORA-EPEL-2025-eb1d4aa56f)
Rust implementation of the XXHash and XXH3 algorithms
--------------------------------------------------------------------------------
Update Information:
Update to version 2.1.2.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 2.1.2-1
- Update to version 2.1.2; Fixes RHBZ#2392944
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
2.1.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-unicode-ident-1.0.19-1.el9 (FEDORA-EPEL-2025-82893f45da)
Determine whether characters have the XID_Start or XID_Continue properties
--------------------------------------------------------------------------------
Update Information:
Update to version 1.0.19.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 1.0.19-1
- Update to version 1.0.19; Fixes RHBZ#2394337
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
1.0.18-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-uuid-1.18.1-1.el9 (FEDORA-EPEL-2025-1308a53f74)
Library to generate and parse UUIDs
--------------------------------------------------------------------------------
Update Information:
Update to version 1.18.1.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 1.18.1-1
- Update to version 1.18.1; Fixes RHBZ#2392511
--------------------------------------------------------------------------------
================================================================================
rust-zune-jpeg-0.4.21-1.el9 (FEDORA-EPEL-2025-7480e285cf)
Fast, correct and safe jpeg decoder
--------------------------------------------------------------------------------
Update Information:
Update the zune-jpeg crate to version 0.4.21.
Update the png crate to version 0.18.0 and add a compat package for version
0.17.
Update the tiff crate to version 0.10.2 and add a compat package for version
0.9.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 12 2025 Fabio Valentini <[email protected]> - 0.4.21-1
- Update to version 0.4.21; Fixes RHBZ#2393455
--------------------------------------------------------------------------------
================================================================================
smtprelay-1.12.0-1.el9 (FEDORA-EPEL-2025-411096564b)
Simple Golang SMTP relay/proxy server
--------------------------------------------------------------------------------
Update Information:
smtprelay for EPEL 9/10
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 Neel Chauhan <[email protected]> - 1.12.0-1
- Initial import (fedora#2393738).
--------------------------------------------------------------------------------
--
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://pagure.io/fedora-infrastructure/new_issue