FEDORA-2022-2173709172
Packages in this update:
pypy3.7-7.3.9-4.3.7.fc36
Update description:
Backport fix for CVE-2021-28861
pypy3.7-7.3.9-4.3.7.fc36
Backport fix for CVE-2021-28861
pypy3.7-7.3.9-4.3.7.fc35
Backport fix for CVE-2021-28861
Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.
libxml2-2.10.3-1.fc36
Update to 2.10.3
Fix CVE-2022-40303
Fix CVE-2022-40304
nginx-mainline-3720221019155610.9e842022
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash, worker process memory disclosure, or might have potential other impact (CVE-2022-41741, CVE-2022-41742).
Feature: the “$proxy_protocol_tlv_…” variables.
Feature: TLS session tickets encryption keys are now automatically rotated when using shared memory in the “ssl_session_cache” directive.
Change: the logging level of the “bad record type” SSL errors has been lowered from “crit” to “info”. Thanks to Murilo Andrade.
Change: now when using shared memory in the “ssl_session_cache” directive the “could not allocate new session” errors are logged at the “warn” level instead of “alert” and not more often than once per second.
Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x.
Bugfix: in logging of the PROXY protocol errors. Thanks to Sergey Brester.
Workaround: shared memory from the “ssl_session_cache” directive was spent on sessions using TLS session tickets when using TLSv1.3 with OpenSSL.
Workaround: timeout specified with the “ssl_session_timeout” directive did not work when using TLSv1.3 with OpenSSL or BoringSSL.
nginx-mainline-820220816123924.9edba152
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash, worker process memory disclosure, or might have potential other impact (CVE-2022-41741, CVE-2022-41742).
Feature: the “$proxy_protocol_tlv_…” variables.
Feature: TLS session tickets encryption keys are now automatically rotated when using shared memory in the “ssl_session_cache” directive.
Change: the logging level of the “bad record type” SSL errors has been lowered from “crit” to “info”. Thanks to Murilo Andrade.
Change: now when using shared memory in the “ssl_session_cache” directive the “could not allocate new session” errors are logged at the “warn” level instead of “alert” and not more often than once per second.
Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x.
Bugfix: in logging of the PROXY protocol errors. Thanks to Sergey Brester.
Workaround: shared memory from the “ssl_session_cache” directive was spent on sessions using TLS session tickets when using TLSv1.3 with OpenSSL.
Workaround: timeout specified with the “ssl_session_timeout” directive did not work when using TLSv1.3 with OpenSSL or BoringSSL.
nginx-mainline-3520221019155610.f27b74a8
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash, worker process memory disclosure, or might have potential other impact (CVE-2022-41741, CVE-2022-41742).
Feature: the “$proxy_protocol_tlv_…” variables.
Feature: TLS session tickets encryption keys are now automatically rotated when using shared memory in the “ssl_session_cache” directive.
Change: the logging level of the “bad record type” SSL errors has been lowered from “crit” to “info”. Thanks to Murilo Andrade.
Change: now when using shared memory in the “ssl_session_cache” directive the “could not allocate new session” errors are logged at the “warn” level instead of “alert” and not more often than once per second.
Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x.
Bugfix: in logging of the PROXY protocol errors. Thanks to Sergey Brester.
Workaround: shared memory from the “ssl_session_cache” directive was spent on sessions using TLS session tickets when using TLSv1.3 with OpenSSL.
Workaround: timeout specified with the “ssl_session_timeout” directive did not work when using TLSv1.3 with OpenSSL or BoringSSL.
nginx-mainline-3620221019155610.5e5ad4a0
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash, worker process memory disclosure, or might have potential other impact (CVE-2022-41741, CVE-2022-41742).
Feature: the “$proxy_protocol_tlv_…” variables.
Feature: TLS session tickets encryption keys are now automatically rotated when using shared memory in the “ssl_session_cache” directive.
Change: the logging level of the “bad record type” SSL errors has been lowered from “crit” to “info”. Thanks to Murilo Andrade.
Change: now when using shared memory in the “ssl_session_cache” directive the “could not allocate new session” errors are logged at the “warn” level instead of “alert” and not more often than once per second.
Bugfix: nginx/Windows could not be built with OpenSSL 3.0.x.
Bugfix: in logging of the PROXY protocol errors. Thanks to Sergey Brester.
Workaround: shared memory from the “ssl_session_cache” directive was spent on sessions using TLS session tickets when using TLSv1.3 with OpenSSL.
Workaround: timeout specified with the “ssl_session_timeout” directive did not work when using TLSv1.3 with OpenSSL or BoringSSL.
nginx-1.22.1-1.fc35
Security: processing of a specially crafted mp4 file by the
ngx_http_mp4_module might cause a worker process crash, worker
process memory disclosure, or might have potential other impact
(CVE-2022-41741, CVE-2022-41742).
nginx-1.22.1-1.fc37
Security: processing of a specially crafted mp4 file by the
ngx_http_mp4_module might cause a worker process crash, worker
process memory disclosure, or might have potential other impact
(CVE-2022-41741, CVE-2022-41742).