It was discovered that SPIP, a website engine for publishing, would allow
a malicious user to execute arbitrary code or escalate privileges.
Category Archives: Advisories
DSA-5192 openjdk-17 – security update
Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in the execution of arbitrary Java bytecode or the
bypass of the Java sandbox.
DSA-5191 linux – security update
Several vulnerabilities have been discovered in the Linux kernel that may
lead to privilege escalation, denial of service or information leaks:
kubernetes-1.24.1-7.fc36
FEDORA-2022-ee81809570
Packages in this update:
kubernetes-1.24.1-7.fc36
Update description:
This package release removes references completely for Dockershim. If you still require support for Docker please visit for more info https://www.mirantis.com/blog/mirantis-to-take-over-support-of-kubernetes-dockershim-2/
This was originally a bug-fix that removed arguments no longer used in the 1.24 Kublet which stemmed from Dockershim. Since Dockershim is now out of tree this package won’t support it unless there’s a compelling use-case.
More info: https://kubernetes.io/blog/2022/02/17/dockershim-faq/
Shell completions have been added beyond bash. Fish and shell completions are now included.
Users should also test the usage of sysusers
kubernetes-1.24.1-5.fc36
FEDORA-2022-3efc2a74cf
Packages in this update:
kubernetes-1.24.1-5.fc36
Update description:
This package release removes references completely for Dockershim. If you still require support for Docker please visit for more info https://www.mirantis.com/blog/mirantis-to-take-over-support-of-kubernetes-dockershim-2/
This was originally a bug-fix that removed arguments no longer used in the 1.24 Kublet which stemmed from Dockershim. Since Dockershim is now out of tree this package won’t support it unless there’s a compelling use-case.
More info: https://kubernetes.io/blog/2022/02/17/dockershim-faq/
python-ujson-5.4.0-1.fc35
FEDORA-2022-33e816bc37
Packages in this update:
python-ujson-5.4.0-1.fc35
Update description:
Security fix for CVE-2022-31116, CVE-2022-31117, and CVE-2021-45958.
See https://github.com/ultrajson/ultrajson/releases for release notes since 3.0.0. Despite the major version bump, this should be a compatible update. See also https://pagure.io/fesco/issue/2834.
ceph-16.2.10-1.fc35
FEDORA-2022-6d129f14f2
Packages in this update:
ceph-16.2.10-1.fc35
Update description:
ceph 16.2.10 GA
Security fix for CVE-2022-0670
java-1.8.0-openjdk-1.8.0.342.b07-1.fc35
FEDORA-2022-80afe2304a
Packages in this update:
java-1.8.0-openjdk-1.8.0.342.b07-1.fc35
Update description:
New in release OpenJDK 8u342 (2022-07-19)
The release announcement can be found at: https://bitly.com/openjdk8u342
Full release details can be found at https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u342.txt
Security Fixes
JDK-8272243: Improve DER parsing
JDK-8272249: Better properties of loaded Properties
JDK-8277608: Address IP Addressing
JDK-8281859, CVE-2022-21540: Improve class compilation
JDK-8281866, CVE-2022-21541: Enhance MethodHandle invocations
JDK-8283190: Improve MIDI processing
JDK-8284370: Improve zlib usage
JDK-8285407, CVE-2022-34169: Improve Xalan supports
FIPS Changes
RH2007331: SecretKey generate/import operations don’t add the CKA_SIGN attribute in FIPS mode
RH2051605: Detect NSS at Runtime for FIPS detection
RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
RH2090378: Revert to disabling system security properties and FIPS mode support together
Depend on crypto-policies package at build-time and run-time
Other Changes
Add javaver- and origin-specific javadoc and javadoczip alternatives (thanks to FeRD (Frank Dana) ferdnyc@gmail.com)
JDK-8215293: Customizing PKCS12 keystore Generation
New system and security properties have been added to enable users to customize the generation of PKCS #12 keystores. This includes algorithms and parameters for key protection, certificate protection, and MacData. The detailed explanation and possible values for these properties can be found in the “PKCS12 KeyStore properties” section of the java.security file.
Also, support for the following SHA-2 based HmacPBE algorithms has been added to the SunJCE provider:
HmacPBESHA224
HmacPBESHA256
HmacPBESHA384
HmacPBESHA512
HmacPBESHA512/224
HmacPBESHA512/256
java-1.8.0-openjdk-1.8.0.342.b07-1.fc36
FEDORA-2022-19b6f21746
Packages in this update:
java-1.8.0-openjdk-1.8.0.342.b07-1.fc36
Update description:
New in release OpenJDK 8u342 (2022-07-19)
The release announcement can be found at: https://bitly.com/openjdk8u342
Full release details can be found at https://builds.shipilev.net/backports-monitor/release-notes-openjdk8u342.txt
Security Fixes
JDK-8272243: Improve DER parsing
JDK-8272249: Better properties of loaded Properties
JDK-8277608: Address IP Addressing
JDK-8281859, CVE-2022-21540: Improve class compilation
JDK-8281866, CVE-2022-21541: Enhance MethodHandle invocations
JDK-8283190: Improve MIDI processing
JDK-8284370: Improve zlib usage
JDK-8285407, CVE-2022-34169: Improve Xalan supports
FIPS Changes
RH2007331: SecretKey generate/import operations don’t add the CKA_SIGN attribute in FIPS mode
RH2051605: Detect NSS at Runtime for FIPS detection
RH2036462: sun.security.pkcs11.wrapper.PKCS11.getInstance breakage
RH2090378: Revert to disabling system security properties and FIPS mode support together
Depend on crypto-policies package at build-time and run-time
Other Changes
Add javaver- and origin-specific javadoc and javadoczip alternatives (thanks to FeRD (Frank Dana) ferdnyc@gmail.com)
JDK-8215293: Customizing PKCS12 keystore Generation
New system and security properties have been added to enable users to customize the generation of PKCS #12 keystores. This includes algorithms and parameters for key protection, certificate protection, and MacData. The detailed explanation and possible values for these properties can be found in the “PKCS12 KeyStore properties” section of the java.security file.
Also, support for the following SHA-2 based HmacPBE algorithms has been added to the SunJCE provider:
HmacPBESHA224
HmacPBESHA256
HmacPBESHA384
HmacPBESHA512
HmacPBESHA512/224
HmacPBESHA512/256
CVE-2020-28435
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.