Fedora Linux 8906 Published by

Both Fedora Linux 40 and 41 have been updated with security updates for Python and Vaultwarden:

Fedora 41 Update: python3.8-3.8.20-2.fc41
Fedora 41 Update: vaultwarden-1.33.2-1.fc41
Fedora 40 Update: python3.8-3.8.20-2.fc40
Fedora 40 Update: vaultwarden-1.33.2-1.fc40




[SECURITY] Fedora 41 Update: python3.8-3.8.20-2.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-bec494726c
2025-02-23 02:07:31.517005+00:00
--------------------------------------------------------------------------------

Name : python3.8
Product : Fedora 41
Version : 3.8.20
Release : 2.fc41
URL : https://www.python.org/
Summary : Version 3.8 of the Python interpreter
Description :
Python 3.8 package for developers.

This package exists to allow developers to test their code against an older
version of Python. This is not a full Python stack and if you wish to run
your applications with Python 3.8, see other distributions
that support it, such as an older Fedora release.

--------------------------------------------------------------------------------
Update Information:

Security fixes for CVE-2024-11168 and CVE-2025-0938
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 13 2025 Charalampos Stratakis [cstratak@redhat.com] - 3.8.20-2
- Security fixes for CVE-2024-11168 and CVE-2025-0938
- Fixes: rhbz#2343279
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2343279 - CVE-2025-0938 python3.8: URL parser allowed square brackets in domain names [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2343279
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-bec494726c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 41 Update: vaultwarden-1.33.2-1.fc41


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-5f07738947
2025-02-23 02:07:31.516788+00:00
--------------------------------------------------------------------------------

Name : vaultwarden
Product : Fedora 41
Version : 1.33.2
Release : 1.fc41
URL : https://github.com/dani-garcia/vaultwarden
Summary : Unofficial Bitwarden compatible server
Description :
Unofficial Bitwarden compatible server.

--------------------------------------------------------------------------------
Update Information:

update to 1.33.2
fix CVE-2025-24898
--------------------------------------------------------------------------------
ChangeLog:

* Mon Feb 10 2025 Jonathan Wright [jonathan@almalinux.org] - 1.33.2-1
- update to 1.33.2 rhbz#2343535
Fix CVE-2025-0977 ssl::select_next_proto use after free rhbz#2344558
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-5f07738947' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: python3.8-3.8.20-2.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-b353a46e0c
2025-02-23 02:01:51.624167+00:00
--------------------------------------------------------------------------------

Name : python3.8
Product : Fedora 40
Version : 3.8.20
Release : 2.fc40
URL : https://www.python.org/
Summary : Version 3.8 of the Python interpreter
Description :
Python 3.8 package for developers.

This package exists to allow developers to test their code against an older
version of Python. This is not a full Python stack and if you wish to run
your applications with Python 3.8, see other distributions
that support it, such as an older Fedora release.

--------------------------------------------------------------------------------
Update Information:

Security fixes for CVE-2024-11168 and CVE-2025-0938
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 13 2025 Charalampos Stratakis [cstratak@redhat.com] - 3.8.20-2
- Security fixes for CVE-2024-11168 and CVE-2025-0938
- Fixes: rhbz#2343279
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2343279 - CVE-2025-0938 python3.8: URL parser allowed square brackets in domain names [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2343279
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-b353a46e0c' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--



[SECURITY] Fedora 40 Update: vaultwarden-1.33.2-1.fc40


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2025-0e5d6864d8
2025-02-23 02:01:51.623894+00:00
--------------------------------------------------------------------------------

Name : vaultwarden
Product : Fedora 40
Version : 1.33.2
Release : 1.fc40
URL : https://github.com/dani-garcia/vaultwarden
Summary : Unofficial Bitwarden compatible server
Description :
Unofficial Bitwarden compatible server.

--------------------------------------------------------------------------------
Update Information:

update to 1.33.2
fix CVE-2025-24898
--------------------------------------------------------------------------------
ChangeLog:

* Mon Feb 10 2025 Jonathan Wright [jonathan@almalinux.org] - 1.33.2-1
- update to 1.33.2 rhbz#2343535
Fix CVE-2025-0977 ssl::select_next_proto use after free rhbz#2344558
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2025-0e5d6864d8' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

--