Tuesday 28th July 2026
Fedora Project
Merged PR#5 for perl-Compress-Raw-Lzma (2.221) in Rawhide: Disable optional dependencies in RHEL
Merged PR#1 for perl-Module-Build-Tiny (0.053) in Rawhide: Conditionalize CPAN::Requirements::Dynamic dependency
Updated proftpd (1.3.8d in EPEL-9 and 1.3.6e in EPEL-8):
Address another avenue for SQL injection, via custom SQLUserInfo queries
Fix SFTP request payload length underflow calculation (GH#2115, CVE-2026-53994)
Fix signed integer overflow via scp file size record parser (CVE-2026-63091)
Fix heap buffer overflow via SFTP packet reassembly (GH#2190, CVE-2026-63090)
Add mod_procfs, enabled by default: this addresses CVE-2026-35025 (ACL bypass via /proc/self/root path prefix); the mod_procfs module disallows file accesses via procfs filesystems