The following Fedora EPEL 10.1 Security updates need testing:
 Age  URL
   6  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-ffafdd8df5   
python-pdfminer-20251230-1.el10_1
   3  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-1d10e103c9   
coturn-4.7.0-4.el10_1
   1  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-9b76de53c0   
composer-2.9.3-1.el10_1


The following builds have been pushed to Fedora EPEL 10.1 updates-testing

    foomuuri-0.31-1.el10_1
    gn-2315^20260107.5550ba0f4053-1.el10_1
    libsodium-1.0.21-2.el10_1
    mod_xsendfile-0.12-32.el10_1
    perl-X11-Protocol-0.56-49.el10_1
    perl-X11-Protocol-Other-31-19.el10_1
    pie-1.3.5-1.el10_1
    rust-base64ct-1.8.2-1.el10_1
    rust-clap_complete-4.5.64-1.el10_1
    rust-h2-0.4.13-1.el10_1
    rust-libc-0.2.179-1.el10_1
    rust-proc-macro2-1.0.105-1.el10_1
    rust-quote-1.0.43-1.el10_1
    rust-syn-2.0.114-1.el10_1

Details about builds:


================================================================================
 foomuuri-0.31-1.el10_1 (FEDORA-EPEL-2026-aff50f711b)
 Multizone bidirectional nftables firewall
--------------------------------------------------------------------------------
Update Information:

Upstream update to v0.31 with fixes to CVE-2025-67603 and CVE-2025-67858.
CVE-2025-67603: Add PolicyKit authorization to D-Bus methods.
CVE-2025-67858: Verify interface input parameter on D-Bus methods.
Security hardening:
Add ProtectSystem=full to all systemd service files. This changes /etc
    to read-only for all Foomuuri processes. Make sure you don't write any
    state files there in your startup hook or Foomuuri Monitor event hook.
Change umask to 022 when using --fork to fork as a background daemon
    process.
More strict IP address verify for iplist entries.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Kim B. Heino  <[email protected]> - 0.31-1
- Upgrade to 0.31
- CVE-2025-67603: Add PolicyKit authorization to D-Bus methods
- CVE-2025-67858: Verify interface input parameter on D-Bus methods
* Fri Dec 12 2025 Kim B. Heino  <[email protected]> - 0.30-1
- Upgrade to 0.30
--------------------------------------------------------------------------------


================================================================================
 gn-2315^20260107.5550ba0f4053-1.el10_1 (FEDORA-EPEL-2026-d122208e80)
 Meta-build system that generates build files for Ninja
--------------------------------------------------------------------------------
Update Information:

Update to version 2315
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Benjamin A. Beasley <[email protected]> - 
2315^20260107.5550ba0f4053-1
- Update to version 2315
--------------------------------------------------------------------------------


================================================================================
 libsodium-1.0.21-2.el10_1 (FEDORA-EPEL-2026-e25dddef14)
 The Sodium crypto library
--------------------------------------------------------------------------------
Update Information:

Version 1.0.21
This point release includes all the changes from 1.0.20-stable, which
include a security fix for the crypto_core_ed25519_is_valid_point()
function, as well as two new sets of functions:
The new crypto_ipcrypt_* functions implement mechanisms for securely
encrypting and anonymizing IP addresses as specified in https://ipcrypt-
std.github.io
The sodium_bin2ip and sodium_ip2bin helper functions have been added
to complement the crypto_ipcrypt_* functions and easily convert addresses
between bytes and strings.
XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions
are standard extendable output functions. From input of any length, they can
derive output of any length with the same properties as hash functions. These
primitives are required by many post-quantum mechanisms, but can also be used
for a wide range of applications, including key derivation, session encryption
and more.
Version 1.0.20-stable
XCFramework: cross-compilation is now forced on Apple Silicon to
avoid Rosetta-related build issues
The Fil-C compiler is supported out of the box
The CompCert compiler is supported out of the box
MSVC 2026 (Visual Studio 2026) is now supported
Zig builds now support FreeBSD targets
Performance of AES256-GCM and AEGIS on ARM has been improved
with some compilers
Android binaries have been added to the NuGet package
Windows ARM binaries have been added to the NuGet package
The Android build script has been improved. The base SDK is
now 27c, and the default platform is 21, supporting 16 KB page sizes.
The library can now be compiled with Zig 0.15 and Zig 0.16
Zig builds now generate position-independent static libraries by
default on targets that support PIC
arm64e builds have been added to the XCFramework packages
XCFramework packages are now full builds instead of minimal
builds
MSVC builds have been enabled for ARM64
iOS 32-bit (armv7/armv7s) support has been removed from the
XCFramework build script
Security: optblockers have been introduced in critical code paths
to prevent compilers from introducing unwanted side channels via
conditional jumps. This was observed on RISC-V targets with specific
compilers and options.
Security: crypto_core_ed25519_is_valid_point() now properly
rejects small-order points that are not in the main subgroup
((nonnull)) attributes have been relaxed on some crypto_stream*
functions to allow NULL output buffers when the output length is zero
A cross-compilation issue with old clang versions has been
fixed
JavaScript: support for Cloudflare Workers has been added
JavaScript: WASM_BIGINT is forcibly disabled to retain
compatibility with older runtimes
A compilation issue with old toolchains on Solaris has been
fixed
crypto_aead_aes256gcm_is_available is exported to JavaScript
libsodium is now compatible with Emscripten 4.x
Security: memory fences have been added after MAC verification in
AEAD to prevent speculative access to plaintext before authentication
is complete
Assembly files now include .gnu.property notes for proper IBT and
Shadow Stack support when building with CET instrumentation
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Remi Collet <[email protected]> - 1.0.21-2
- fix aarch64 build failure using upstream patch
* Wed Jan  7 2026 Remi Collet <[email protected]> - 1.0.21-1
- update to 1.0.21
- open https://github.com/jedisct1/libsodium/discussions/1503 build failure on 
aarch64
- workaround build failure using -flax-vector-conversions on aarch64
- Add missing SPDX identifiers to license field
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2426614 - CVE-2025-69277 libsodium: libsodium: Improper validation 
of elliptic curve points could lead to data integrity or information 
disclosure. [epel-10]
        https://bugzilla.redhat.com/show_bug.cgi?id=2426614
--------------------------------------------------------------------------------


================================================================================
 mod_xsendfile-0.12-32.el10_1 (FEDORA-EPEL-2026-71ccc08674)
 Apache module to send files efficiently
--------------------------------------------------------------------------------
Update Information:

Build for EPEL10
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 24 2024 Miroslav Suchý <[email protected]> - 0.12-32
- convert license to SPDX
* Thu Jul 18 2024 Fedora Release Engineering <[email protected]> - 
0.12-31
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> - 
0.12-30
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> - 
0.12-29
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Jul 20 2023 Fedora Release Engineering <[email protected]> - 
0.12-28
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering <[email protected]> - 
0.12-27
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2426527 - Please branch and build mod_xsendfile in epel10 and 
epel10.1
        https://bugzilla.redhat.com/show_bug.cgi?id=2426527
--------------------------------------------------------------------------------


================================================================================
 perl-X11-Protocol-0.56-49.el10_1 (FEDORA-EPEL-2026-4b3a5d9eab)
 X11-Protocol - Raw interface to X Window System servers
--------------------------------------------------------------------------------
Update Information:

Add to EPEL 10
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 
0.56-49
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sat Jan 18 2025 Fedora Release Engineering <[email protected]> - 
0.56-48
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 19 2024 Fedora Release Engineering <[email protected]> - 
0.56-47
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> - 
0.56-46
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> - 
0.56-45
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2427428 - Need EL10 build of perl-X11-Protocol
        https://bugzilla.redhat.com/show_bug.cgi?id=2427428
  [ 2 ] Bug #2427430 - Need EL10 build of perl-X11-Protocol-Other (it is a 
dependency for other packages)
        https://bugzilla.redhat.com/show_bug.cgi?id=2427430
--------------------------------------------------------------------------------


================================================================================
 perl-X11-Protocol-Other-31-19.el10_1 (FEDORA-EPEL-2026-4b3a5d9eab)
 Miscellaneous X11::Protocol helpers
--------------------------------------------------------------------------------
Update Information:

Add to EPEL 10
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 25 2025 Fedora Release Engineering <[email protected]> - 31-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Sat Jan 18 2025 Fedora Release Engineering <[email protected]> - 31-18
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Fri Jul 19 2024 Fedora Release Engineering <[email protected]> - 31-17
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jan 25 2024 Fedora Release Engineering <[email protected]> - 31-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <[email protected]> - 31-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2427428 - Need EL10 build of perl-X11-Protocol
        https://bugzilla.redhat.com/show_bug.cgi?id=2427428
  [ 2 ] Bug #2427430 - Need EL10 build of perl-X11-Protocol-Other (it is a 
dependency for other packages)
        https://bugzilla.redhat.com/show_bug.cgi?id=2427430
--------------------------------------------------------------------------------


================================================================================
 pie-1.3.5-1.el10_1 (FEDORA-EPEL-2026-c0ada6a66f)
 PHP Installer for Extensions
--------------------------------------------------------------------------------
Update Information:

Version 1.3.5
Ensure whitespace is trimmed from PHP binary output thanks to @asgrim
Version 1.3.4
Ensure aarch64 is parsed as a valid architecture as arm64 thanks to @asgrim
Version 1.3.3
fix intermittent failure to look up packages thanks to @asgrim
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Remi Collet <[email protected]> - 1.3.5-1
- update to 1.3.5
* Sat Jan  3 2026 Remi Collet <[email protected]> - 1.3.4-1
- update to 1.3.4
--------------------------------------------------------------------------------


================================================================================
 rust-base64ct-1.8.2-1.el10_1 (FEDORA-EPEL-2026-db4c5d4074)
 Pure Rust implementation of Base64
--------------------------------------------------------------------------------
Update Information:

Update to version 1.8.2.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 1.8.2-1
- Update to version 1.8.2; Fixes RHBZ#2426981
--------------------------------------------------------------------------------


================================================================================
 rust-clap_complete-4.5.64-1.el10_1 (FEDORA-EPEL-2026-76cda53fbc)
 Generate shell completion scripts for your clap::Command
--------------------------------------------------------------------------------
Update Information:

Update to version 4.5.64.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 4.5.64-1
- Update to version 4.5.64; Fixes RHBZ#2425844
--------------------------------------------------------------------------------


================================================================================
 rust-h2-0.4.13-1.el10_1 (FEDORA-EPEL-2026-a73aeca278)
 HTTP/2 client and server
--------------------------------------------------------------------------------
Update Information:

Update to version 0.4.13.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 0.4.13-1
- Update to version 0.4.13; Fixes RHBZ#2427232
--------------------------------------------------------------------------------


================================================================================
 rust-libc-0.2.179-1.el10_1 (FEDORA-EPEL-2026-63f73ed1a9)
 Raw FFI bindings to platform libraries like libc
--------------------------------------------------------------------------------
Update Information:

Update to version 0.2.179.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 0.2.179-1
- Update to version 0.2.179; Fixes RHBZ#2426939
--------------------------------------------------------------------------------


================================================================================
 rust-proc-macro2-1.0.105-1.el10_1 (FEDORA-EPEL-2026-a405f40acc)
 Substitute implementation of the Rust compiler's proc_macro API
--------------------------------------------------------------------------------
Update Information:

Update to version 1.0.105.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 1.0.105-1
- Update to version 1.0.105; Fixes RHBZ#2425615
--------------------------------------------------------------------------------


================================================================================
 rust-quote-1.0.43-1.el10_1 (FEDORA-EPEL-2026-ca0d96267f)
 Quasi-quoting macro quote!(...)
--------------------------------------------------------------------------------
Update Information:

Update to version 1.0.43.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 1.0.43-1
- Update to version 1.0.43; Fixes RHBZ#2427258
--------------------------------------------------------------------------------


================================================================================
 rust-syn-2.0.114-1.el10_1 (FEDORA-EPEL-2026-e514ed15fb)
 Parser for Rust source code
--------------------------------------------------------------------------------
Update Information:

Update to version 2.0.114.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan  7 2026 Fabio Valentini <[email protected]> - 2.0.114-1
- Update to version 2.0.114; Fixes RHBZ#2426291
--------------------------------------------------------------------------------


-- 
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to