The following Fedora EPEL 10.1 Security updates need testing:
Age URL
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-3f99ee4dca
libopenmpt-0.8.3-1.el10_1
The following builds have been pushed to Fedora EPEL 10.1 updates-testing
certbot-4.2.0-1.el10_1
lemonldap-ng-2.21.3-1.el10_1
motif-2.3.8-1.el10_1
openvpn-2.7_beta1-1.el10_1
perl-Cairo-GObject-1.005-22.el10_1
perl-Cpanel-JSON-XS-4.40-1.el10_1
perl-Text-CSV-2.06-1.el10_1
python-astropy-iers-data-0.2025.9.8.0.36.17-1.el10_1
ruby-build-20250908-1.el10_1
rust-errno-0.3.14-1.el10_1
rust-reflink-copy-0.1.28-1.el10_1
voms-api-java-3.3.6-2.el10_1
Details about builds:
================================================================================
certbot-4.2.0-1.el10_1 (FEDORA-EPEL-2025-5b3619ca27)
A free, automated certificate authority client
--------------------------------------------------------------------------------
Update Information:
Update to 4.2.0
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 Jonathan Wright <[email protected]> - 4.2.0-1
- update to 4.2.0
* Fri Aug 15 2025 Python Maint <[email protected]> - 4.1.1-3
- Rebuilt for Python 3.14.0rc2 bytecode
--------------------------------------------------------------------------------
================================================================================
lemonldap-ng-2.21.3-1.el10_1 (FEDORA-EPEL-2025-0fe19fab37)
Web Single Sign On (SSO) and Access Management
--------------------------------------------------------------------------------
Update Information:
See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-3-is-out/
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 5 2025 Clement Oudot <[email protected]> - 2.21.3-1
- Update to 2.21.3
* Thu Jul 24 2025 Fedora Release Engineering <[email protected]> -
2.21.2-1.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
motif-2.3.8-1.el10_1 (FEDORA-EPEL-2025-34e7a50a40)
Run-time libraries and programs
--------------------------------------------------------------------------------
Update Information:
10.1 build
--------------------------------------------------------------------------------
ChangeLog:
* Thu Aug 14 2025 Gwyn Ciesla <[email protected]> - 2.3.8-1
- 2.3.8
* Thu Jul 24 2025 Fedora Release Engineering <[email protected]> -
2.3.4-39
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jun 2 2025 Olivier Fourdan <[email protected]> - 2.3.4-38
- Add Xinerama support from
https://sourceforge.net/p/motif/code/merge-requests/9/
* Fri Jan 17 2025 Fedora Release Engineering <[email protected]> -
2.3.4-37
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Mon Sep 2 2024 Miroslav Suchý <[email protected]> - 2.3.4-36
- convert license to SPDX
* Thu Jul 18 2024 Fedora Release Engineering <[email protected]> -
2.3.4-35
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Sun Apr 14 2024 Yaakov Selkowitz <[email protected]> - 2.3.4-34
- Drop xorg-x11-xinit dependency
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> -
2.3.4-33
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Florian Weimer <[email protected]> - 2.3.4-32
- Backport upstream patch to fix incompatible-pointer-types issues
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> -
2.3.4-31
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Mon Nov 27 2023 José Expósito <[email protected]> - 2.3.4-30
- Fix CVE-2023-43788: out of bounds read in XpmCreateXpmImageFromBuffer()
- Fix CVE-2023-43789: out of bounds read on XPM with corrupted colormap
--------------------------------------------------------------------------------
================================================================================
openvpn-2.7_beta1-1.el10_1 (FEDORA-EPEL-2025-d5d6587ca2)
A full-featured TLS VPN solution
--------------------------------------------------------------------------------
Update Information:
Update to upstream 2.7_beta1 release
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 David Sommerseth <[email protected]> - 2.7_beta1
- Update to upstream 2.7_beta1 release
--------------------------------------------------------------------------------
================================================================================
perl-Cairo-GObject-1.005-22.el10_1 (FEDORA-EPEL-2025-90decfa2d1)
Integrate Cairo into the Glib type system
--------------------------------------------------------------------------------
Update Information:
This update brings a new perl-Cairo-GObject package, Perl bindings to Cairo
library.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
1.005-22
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Mon Jul 7 2025 Jitka Plesnikova <[email protected]> - 1.005-21
- Perl 5.42 rebuild
* Mon May 12 2025 Petr Pisar <[email protected]> - 1.005-20
- Correct a license tag to "LGPL-2.1-or-later"
- Package the tests
* Fri Jan 17 2025 Fedora Release Engineering <[email protected]> -
1.005-19.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Mon Sep 2 2024 Miroslav Suchý <[email protected]> - 1.005-18.1
- convert license to SPDX
* Thu Jul 18 2024 Fedora Release Engineering <[email protected]> -
1.005-17.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Mon Jun 10 2024 Jitka Plesnikova <[email protected]> - 1.005-16.1
- Perl 5.40 rebuild
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> -
1.005-15.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> -
1.005-14.1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2369999 - Add perl-Cairo-GObject to EPEL 10 and EPEL 10.0
https://bugzilla.redhat.com/show_bug.cgi?id=2369999
--------------------------------------------------------------------------------
================================================================================
perl-Cpanel-JSON-XS-4.40-1.el10_1 (FEDORA-EPEL-2025-3c054007d7)
JSON::XS for Cpanel, fast and correct serializing
--------------------------------------------------------------------------------
Update Information:
This update is the latest upstream release of the Cpanel::JSON::XS module,
bringing many bug fixes and enhancements since the original EPEL package
release. Amongst the bug fixes is one to fix an integer overflow issue that
could be triggered by a specially-crafted JSON input, which could lead to a
crash in the program parsing the JSON (CVE-2025-40929).
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 Paul Howarth <[email protected]> - 4.40-1
- Update to 4.40
- Fix overflow with overlong numbers, fuzzing only (CVE-2025-40929)
- Detect more malformed numbers, with two decimal points
- Pin Github actions to latest @v via pinact run -u
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 4.39-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue Jul 8 2025 Jitka Plesnikova <[email protected]> - 4.39-4
- Perl 5.42 re-rebuild of bootstrapped packages
* Mon Jul 7 2025 Jitka Plesnikova <[email protected]> - 4.39-3
- Perl 5.42 rebuild
* Sat Jan 18 2025 Fedora Release Engineering <[email protected]> - 4.39-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Dec 13 2024 Paul Howarth <[email protected]> - 4.39-1
- Update to 4.39
- Fix Windows -Dusequadmath (GH#229, GH#235)
- Fix inconsistent behavior between decoding escaped and unescaped
surrogates, and escaped non-characters vs. non-escaped non-characters; now
aligned to JSON::PP (GH#227, GH#233)
- Add type_all_string tests (GH#236)
- Silence UV to char cast warnings (GH#232)
- Fix MSVC preprocessor errors (GH#232)
- Fix -Wformat warnings on Windows (GH#228)
- Clarify BigInt decoding (GH#226)
- Drop EL-7 support
- Use %{make_build} and %{make_install}
* Thu Jul 18 2024 Fedora Release Engineering <[email protected]> - 4.38-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Wed Jun 12 2024 Jitka Plesnikova <[email protected]> - 4.38-3
- Perl 5.40 re-rebuild of bootstrapped packages
* Tue Jun 11 2024 Jitka Plesnikova <[email protected]> - 4.38-2
- Perl 5.40 rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2393915 - CVE-2025-40929 perl-Cpanel-JSON-XS: integer buffer
overflow causing a segfault when parsing crafted JSON [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2393915
--------------------------------------------------------------------------------
================================================================================
perl-Text-CSV-2.06-1.el10_1 (FEDORA-EPEL-2025-d1c1663f12)
Comma-separated values manipulator
--------------------------------------------------------------------------------
Update Information:
First EPEL 10 build.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 20 2025 Jitka Plesnikova <[email protected]> - 2.06-1
- 2.06 bump (rhbz#2349284)
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 2.05-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sat Jan 18 2025 Fedora Release Engineering <[email protected]> - 2.04-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 19 2024 Fedora Release Engineering <[email protected]> - 2.04-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Mon May 20 2024 Jitka Plesnikova <[email protected]> - 2.04-1
- 2.04 bump (rhbz#2252556)
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> - 2.03-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> - 2.03-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Mon Sep 11 2023 Jitka Plesnikova <[email protected]> - 2.03-1
- 2.03 bump (rhbz#2231263)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2394086 - Please branch and build perl-Text-CSV for EPEL 10
https://bugzilla.redhat.com/show_bug.cgi?id=2394086
--------------------------------------------------------------------------------
================================================================================
python-astropy-iers-data-0.2025.9.8.0.36.17-1.el10_1
(FEDORA-EPEL-2025-ef54f1457c)
IERS Earth Rotation and Leap Second tables for the astropy core package
--------------------------------------------------------------------------------
Update Information:
Automatic update for python-astropy-iers-data-0.2025.9.8.0.36.17-1.el10_1.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Sep 8 2025 Packit <[email protected]> - 0.2025.9.8.0.36.17-1
- Update to 0.2025.9.8.0.36.17 upstream release
- Resolves: rhbz#2390650
* Wed Aug 20 2025 Sergio Pascual <[email protected]> -
0.2025.8.18.0.40.14-1
- Import into epel10
--------------------------------------------------------------------------------
================================================================================
ruby-build-20250908-1.el10_1 (FEDORA-EPEL-2025-94600c50f5)
Compile and install Ruby
--------------------------------------------------------------------------------
Update Information:
Update to 20250908
--------------------------------------------------------------------------------
ChangeLog:
* Mon Sep 8 2025 Packit <[email protected]> - 20250908-1
- Update to 20250908 upstream release
- Resolves: rhbz#2393922
--------------------------------------------------------------------------------
================================================================================
rust-errno-0.3.14-1.el10_1 (FEDORA-EPEL-2025-af201baad1)
Cross-platform interface to the errno variable
--------------------------------------------------------------------------------
Update Information:
Update to version 0.3.14.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 9 2025 Fabio Valentini <[email protected]> - 0.3.14-1
- Update to version 0.3.14; Fixes RHBZ#2394005
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.3.13-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rust-reflink-copy-0.1.28-1.el10_1 (FEDORA-EPEL-2025-cf586c152b)
Copy-on-write mechanism on supported file systems
--------------------------------------------------------------------------------
Update Information:
Update to version 0.1.28; Fixes RHBZ#2393863
Loosens a dependency version bound, for Windows users only
Update to 0.1.27 (close RHBZ#2393617)
This update only bumps a dependency for Windows users.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Sep 8 2025 Benjamin A. Beasley <[email protected]> - 0.1.28-1
- Update to version 0.1.28; Fixes RHBZ#2393863
* Sat Sep 6 2025 Benjamin A. Beasley <[email protected]> - 0.1.27-1
- Update to 0.1.27 (close RHBZ#2393617)
* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> -
0.1.26-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Tue May 13 2025 Benjamin A. Beasley <[email protected]> - 0.1.26-2
- Remove no-longer-necessary .rpmlintrc file
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2393617 - rust-reflink-copy-0.1.27 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2393617
[ 2 ] Bug #2393863 - rust-reflink-copy-0.1.28 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2393863
--------------------------------------------------------------------------------
================================================================================
voms-api-java-3.3.6-2.el10_1 (FEDORA-EPEL-2025-9b58d7d1c1)
Virtual Organization Membership Service Java API
--------------------------------------------------------------------------------
Update Information:
Enable tests in package build.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Sep 8 2025 Mattias Ellert <[email protected]> - 3.3.6-2
- Include upstream's scripts for generating test certificates
- Enable tests again
--------------------------------------------------------------------------------
--
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it:
https://pagure.io/fedora-infrastructure/new_issue