The following Fedora 32 Security updates need testing: Age URL 56 https://bodhi.fedoraproject.org/updates/FEDORA-2020-062e2c016b qutebrowser-1.11.1-1.fc32 18 https://bodhi.fedoraproject.org/updates/FEDORA-2020-eca8f3489f dnsmasq-2.81-4.fc32 13 https://bodhi.fedoraproject.org/updates/FEDORA-2020-ebbf149f3b podofo-0.9.6-12.fc32 6 https://bodhi.fedoraproject.org/updates/FEDORA-2020-83d2616f81 targetcli-2.1.53-1.fc32 6 https://bodhi.fedoraproject.org/updates/FEDORA-2020-4f4c778096 mingw-LibRaw-0.19.5-4.fc32 6 https://bodhi.fedoraproject.org/updates/FEDORA-2020-46ec9e748b python-rtslib-2.1.73-1.fc32 6 https://bodhi.fedoraproject.org/updates/FEDORA-2020-2f88bad887 php-horde-kronolith-4.2.29-1.fc32 4 https://bodhi.fedoraproject.org/updates/FEDORA-2020-dfb11916cc mingw-python3-3.8.3-3.fc32 4 https://bodhi.fedoraproject.org/updates/FEDORA-2020-8a15713da2 cacti-1.2.13-1.fc32 cacti-spine-1.2.13-1.fc32 4 https://bodhi.fedoraproject.org/updates/FEDORA-2020-fa74e15364 mbedtls-2.16.7-1.fc32 4 https://bodhi.fedoraproject.org/updates/FEDORA-2020-716d38e751 singularity-3.6.0-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-48653597f1 tor-0.4.3.6-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-2ca6e97024 python3-3.8.4-1.fc32 python3-docs-3.8.4-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-aeea04cd13 origin-3.11.2-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-cfbed9c9ff mod_authnz_pam-1.2.1-1.fc32 2 https://bodhi.fedoraproject.org/updates/FEDORA-2020-6584a641ae clamav-0.102.4-1.fc32 0 https://bodhi.fedoraproject.org/updates/FEDORA-2020-02cf7850ca zabbix-4.0.22-1.fc32 0 https://bodhi.fedoraproject.org/updates/FEDORA-2020-e418151dc3 java-1.8.0-openjdk-1.8.0.262.b10-1.fc32
The following Fedora 32 Critical Path updates have yet to be approved: Age URL 18 https://bodhi.fedoraproject.org/updates/FEDORA-2020-eca8f3489f dnsmasq-2.81-4.fc32 16 https://bodhi.fedoraproject.org/updates/FEDORA-2020-ebbe0f7b25 cpio-2.13-6.fc32 8 https://bodhi.fedoraproject.org/updates/FEDORA-2020-e5226c4023 libnma-1.8.30-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-2aaafc27ed libdrm-2.4.102-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-2ca6e97024 python3-3.8.4-1.fc32 python3-docs-3.8.4-1.fc32 3 https://bodhi.fedoraproject.org/updates/FEDORA-2020-30d3ad8250 pcre2-10.35-4.fc32 0 https://bodhi.fedoraproject.org/updates/FEDORA-2020-902bd5b07a gpgme-1.14.0-1.fc32
The following builds have been pushed to Fedora 32 updates-testing
Carla-2.2.0-0.1.rc1.fc32 digikam-7.0.0-1.fc32 fedora-obsolete-packages-32-53 igt-gpu-tools-1.25-1.20200719git9b964d7.fc32 java-11-openjdk-11.0.8.10-2.fc32 kernel-5.7.9-200.fc32 plasma-applet-translator-0.4-1.fc32
Details about builds:
================================================================================ Carla-2.2.0-0.1.rc1.fc32 (FEDORA-2020-cdd3e8fe29) Audio plugin host -------------------------------------------------------------------------------- Update Information:
Update to 2.2.0-0.1.rc1 -------------------------------------------------------------------------------- ChangeLog:
* Sun Jul 19 2020 Martin Gansser martinkg@fedoraproject.org - 1:2.2.0-0.1.rc1 - Update to 2.2.0-0.1.rc1 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1858532 - Carla-2.2.0-RC1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1858532 --------------------------------------------------------------------------------
================================================================================ digikam-7.0.0-1.fc32 (FEDORA-2020-e71a1ae7fa) A digital camera accessing & photo management application -------------------------------------------------------------------------------- Update Information:
Digikam 7.0.0 stable release -------------------------------------------------------------------------------- ChangeLog:
* Fri Jul 17 2020 Rex Dieter rdieter@fedoraproject.org - 7.0.0-1 - digikam-7.0.0 * Fri May 29 2020 Rex Dieter rdieter@fedoraproject.org - 7.0.0-0.7.beta3 - rebuild (opencv) --------------------------------------------------------------------------------
================================================================================ fedora-obsolete-packages-32-53 (FEDORA-2020-43c3b1377e) A package to obsolete retired packages -------------------------------------------------------------------------------- Update Information:
Obsolete python2-pillow-devel, bump version of python2-pillow-tk and -qt. ---- Bump Obsoletes for python2-beautifulsoup4 -------------------------------------------------------------------------------- ChangeLog:
* Sun Jul 19 2020 Miro Hron��ok mhroncok@redhat.com - 32-53 - Obsolete python2-pillow-devel (#1858557) - Bump version of python2-pillow-tk and -qt * Sun Jul 19 2020 Elliott Sales de Andrade quantum.analyst@gmail.com - 32-52 - Bump Obsoletes for python2-beautifulsoup4 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1858557 - Obsolete python2-pillow-devel https://bugzilla.redhat.com/show_bug.cgi?id=1858557 --------------------------------------------------------------------------------
================================================================================ igt-gpu-tools-1.25-1.20200719git9b964d7.fc32 (FEDORA-2020-3757979580) Test suite and tools for DRM drivers -------------------------------------------------------------------------------- Update Information:
New git snapshot -------------------------------------------------------------------------------- ChangeLog:
* Sun Jul 19 2020 Lyude Paul lyude@redhat.com - 1.25-1.20200719git9b964d7 - New git snapshot --------------------------------------------------------------------------------
================================================================================ java-11-openjdk-11.0.8.10-2.fc32 (FEDORA-2020-5d0b4a2b5b) OpenJDK Runtime Environment 11 -------------------------------------------------------------------------------- Update Information:
# July 2020 OpenJDK security update for OpenJDK 11 Full release notes: https://bitly.com/openjdk1108 ## Security fixes - JDK-8230613: Better ASCII conversions - JDK-8231800: Better listing of arrays - JDK-8232014: Expand DTD support - JDK-8233234: Better Zip Naming - JDK-8233239, CVE-2020-14562: Enhance TIFF support - JDK-8233255: Better Swing Buttons - JDK-8234032: Improve basic calendar services - JDK-8234042: Better factory production of certificates - JDK-8234418: Better parsing with CertificateFactory - JDK-8234836: Improve serialization handling - JDK-8236191: Enhance OID processing - JDK-8236867, CVE-2020-14573: Enhance Graal interface handling - JDK-8237117, CVE-2020-14556: Better ForkJoinPool behavior - JDK-8237592, CVE-2020-14577: Enhance certificate verification - JDK-8238002, CVE-2020-14581: Better matrix operations - JDK-8238013: Enhance String writing - JDK-8238804: Enhance key handling process - JDK-8238842: AIOOBE in GIFImageReader.initializeStringTable - JDK-8238843: Enhanced font handing - JDK-8238920, CVE-2020-14583: Better Buffer support - JDK-8238925: Enhance WAV file playback - JDK-8240119, CVE-2020-14593: Less Affine Transformations - JDK-8240482: Improved WAV file playback - JDK-8241379: Update JCEKS support - JDK-8241522: Manifest improved jar headers redux - JDK-8242136, CVE-2020-14621: Better XML namespace handling ## [JDK-8244167](https://bugs.openjdk.java.net/browse/JDK-8244167): Removal of Comodo Root CA Certificate The following expired Comodo root CA certificate was removed from the `cacerts` keystore: + alias name "addtrustclass1ca [jdk]" Distinguished Name: CN=AddTrust Class 1 CA Root, OU=AddTrust TTP Network, O=AddTrust AB, C=SE ## [JDK-8244166](https://bugs.openjdk.java.net/browse/JDK-8244166): Removal of DocuSign Root CA Certificate The following expired DocuSign root CA certificate was removed from the `cacerts` keystore: + alias name "keynectisrootca [jdk]" Distinguished Name: CN=KEYNECTIS ROOT CA, OU=ROOT, O=KEYNECTIS, C=FR ## [JDK-8240191](https://bugs.openjdk.java.net/browse/JDK-8240191): Allow SunPKCS11 initialization with NSS when external FIPS modules are present in the Security Modules Database The SunPKCS11 security provider can now be initialized with NSS when FIPS-enabled external modules are configured in the Security Modules Database (NSSDB). Prior to this change, the SunPKCS11 provider would throw a RuntimeException with the message: "FIPS flag set for non-internal module" when such a library was configured for NSS in non-FIPS mode. This change allows the JDK to work properly with recent NSS releases in GNU/Linux operating systems when the system-wide FIPS policy is turned on. Further information can be found in [JDK-8238555](https://bugs.openjdk.java.net/browse/JDK-8238555). ## [JDK-8245077](https://bugs.openjdk.java.net/browse/JDK-8245077): Default SSLEngine Should Create in Server Role In JDK 11 and later, `javax.net.ssl.SSLEngine` by default used client mode when handshaking. As a result, the set of default enabled protocols may differ to what is expected. `SSLEngine` would usually be used in server mode. From this JDK release onwards, `SSLEngine` will default to server mode. The `javax.net.ssl.SSLEngine.setUseClientMode(boolean mode)` method may be used to configure the mode. ## [JDK-8242147](https://bugs.openjdk.java.net/browse/JDK-8242147): New System Properties to Configure the TLS Signature Schemes Two new System Properties are added to customize the TLS signature schemes in JDK. `jdk.tls.client.SignatureSchemes` is added for TLS client side, and `jdk.tls.server.SignatureSchemes` is added for server side. Each System Property contains a comma-separated list of supported signature scheme names specifying the signature schemes that could be used for the TLS connections. The names are described in the "Signature Schemes" section of the *Java Security Standard Algorithm Names Specification*. -------------------------------------------------------------------------------- ChangeLog:
* Sat Jul 18 2020 Severin Gehwolf sgehwolf@redhat.com - 1:11.0.8.10-2 - Build static-libs-image and add resulting files via -static-libs sub-package. - Disable stripping of debug symbols for static libraries part of the -static-libs sub-package. * Mon Jul 13 2020 Andrew Hughes gnu.andrew@redhat.com - 1:11.0.8.10-1 - Sync JDK-8247874 patch with upstream status in 11.0.9. * Mon Jul 13 2020 Jayashree Huttanagoudar jhuttana@redhat.com -1:11.0.8.10-1 - Moved vendor_version_string to better place - Added a patch jdk8247874-fix_ampersand_in_vm_bug_url.patch * Mon Jul 13 2020 Jiri Vanek jvanek@redhat.com - 1:11.0.8.10-1 - Set vendor property and vendor URLs - Made urls to be preconfigured by OS * Sat Jul 11 2020 Andrew Hughes gnu.andrew@redhat.com - 1:11.0.8.10-0 - Update to shenandoah-jdk-11.0.8+10 (GA) - Add release notes for 11.0.7 & 11.0.8 releases. - Amend release notes, removing issue actually fixed in 11.0.6. - Update release notes with last minute fix (JDK-8248505). - Drop JDK-8237396, JDK-8228407 & JDK-8243541 backports now applied upstream. - Make use of --with-extra-asflags introduced in jdk-11.0.6+1. --------------------------------------------------------------------------------
================================================================================ kernel-5.7.9-200.fc32 (FEDORA-2020-c5938abe2d) The Linux kernel -------------------------------------------------------------------------------- Update Information:
The 5.7.9 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog:
* Fri Jul 17 2020 Justin M. Forbes jforbes@fedoraproject.org - 5.7.9-100 - Linux v5.7.9 * Wed Jul 15 2020 Justin M. Forbes jforbes@fedoraproject.org - Make some killer wireless ac 1550 cards work again * Sun Jul 12 2020 Peter Robinson pbrobinson@fedoraproject.org - selinux: allow reading labels before policy is loaded (rhbz 1845210) --------------------------------------------------------------------------------
================================================================================ plasma-applet-translator-0.4-1.fc32 (FEDORA-2020-9d148fdda6) Plasma 5 applet for translate-shell -------------------------------------------------------------------------------- Update Information:
Update to 0.4. -------------------------------------------------------------------------------- ChangeLog:
* Sun Jul 19 2020 Vasiliy Glazov vascom2@gmail.com - 0.4-1 - Update to 0.4 --------------------------------------------------------------------------------