The following Fedora 35 Security updates need testing:
Age URL
284
https://bodhi.fedoraproject.org/updates/FEDORA-2022-dfc6924a11
mysql-connector-java-8.0.28-1.fc35
15
https://bodhi.fedoraproject.org/updates/FEDORA-2022-de515f765f
nodejs-16.18.1-1.fc35
13
https://bodhi.fedoraproject.org/updates/FEDORA-2022-5495b36bed
xorg-x11-server-Xwayland-21.1.4-3.fc35
13
https://bodhi.fedoraproject.org/updates/FEDORA-2022-9100b7aafd
xorg-x11-server-1.20.14-9.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-f44dd1bec2
python3.10-3.10.8-3.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-e733724edb
freerdp-2.8.1-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-003403ec6b
samba-4.15.12-0.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-14f11bfc73
ntfs-3g-2022.10.3-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-927df621df
thunderbird-102.5.0-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-53a4a5dd11 xen-4.15.4-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-99c5ddb2ae
varnish-6.6.2-3.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-73e61f4c0b
drupal7-i18n-1.31-1.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-42723b43fe
python-virtualbmc-3.0.0-1.fc35
0
https://bodhi.fedoraproject.org/updates/FEDORA-2022-333df1c4aa
galera-26.4.13-1.fc35 mariadb-10.5.18-1.fc35
0
https://bodhi.fedoraproject.org/updates/FEDORA-2022-cbbd105d08
heimdal-7.7.1-3.fc35
0
https://bodhi.fedoraproject.org/updates/FEDORA-2022-07dd239d6c
admesh-0.98.5-1.fc35
The following Fedora 35 Critical Path updates have yet to be approved:
Age URL
103
https://bodhi.fedoraproject.org/updates/FEDORA-2022-bca7996d14
annobin-10.81-1.fc35
67
https://bodhi.fedoraproject.org/updates/FEDORA-2022-97f6c4fd2a
libblockdev-2.28-2.fc35
13
https://bodhi.fedoraproject.org/updates/FEDORA-2022-91930d445c imath-3.1.6-1.fc35
13
https://bodhi.fedoraproject.org/updates/FEDORA-2022-9100b7aafd
xorg-x11-server-1.20.14-9.fc35
13
https://bodhi.fedoraproject.org/updates/FEDORA-2022-5495b36bed
xorg-x11-server-Xwayland-21.1.4-3.fc35
9
https://bodhi.fedoraproject.org/updates/FEDORA-2022-43fa48ce4e
python-rpmautospec-0.3.1-1.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-08abe36a9e
linux-firmware-20221109-144.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-0f700faae4 glibc-2.34-49.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-e733724edb
freerdp-2.8.1-1.fc35
7
https://bodhi.fedoraproject.org/updates/FEDORA-2022-f44dd1bec2
python3.10-3.10.8-3.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-53a4a5dd11 xen-4.15.4-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-927df621df
thunderbird-102.5.0-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-14f11bfc73
ntfs-3g-2022.10.3-1.fc35
5
https://bodhi.fedoraproject.org/updates/FEDORA-2022-003403ec6b
samba-4.15.12-0.fc35
4
https://bodhi.fedoraproject.org/updates/FEDORA-2022-b402a5ebdf
libxcrypt-4.4.33-1.fc35
2
https://bodhi.fedoraproject.org/updates/FEDORA-2022-0187d93584 nss-3.85.0-1.fc35
0
https://bodhi.fedoraproject.org/updates/FEDORA-2022-7184211fc4 koji-1.31.0-1.fc35
0
https://bodhi.fedoraproject.org/updates/FEDORA-2022-1b29661d86 vim-9.0.915-1.fc35
The following builds have been pushed to Fedora 35 updates-testing
ImageMagick-6.9.12.67-1.fc35
SDL2-2.26.0-1.fc35
blueman-2.3.5-1.fc35
coturn-4.6.0-2.fc35
datovka-4.21.1-1.fc35
dotnet6.0-6.0.111-1.fc35
exim-4.96-6.fc35
git-extras-6.5.0-1.fc35
golang-github-charmbracelet-bubbletea-0.23.1-1.fc35
grub2-2.06-13.fc35
mingw-SDL2-2.26.0-1.fc35
python-pymssql-2.2.7-1.fc35
quisk-4.2.12-1.fc35
Details about builds:
================================================================================
ImageMagick-6.9.12.67-1.fc35 (FEDORA-2022-a0f122f1d4)
An X application for displaying and manipulating images
--------------------------------------------------------------------------------
Update Information:
Update ImageMagick to 6.9.12.67 (#2133270)
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 21 2022 S��rgio Basto <sergio(a)serjux.com> - 1:6.9.12.67-1
- Update ImageMagick to 6.9.12.67 (#2133270)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2133270 - ImageMagick-6.9.12.67 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2133270
--------------------------------------------------------------------------------
================================================================================
SDL2-2.26.0-1.fc35 (FEDORA-2022-f2aba4ff60)
Cross-platform multimedia library
--------------------------------------------------------------------------------
Update Information:
In addition to lots of bug fixes, here are the major changes in this release:
#### General * Updated OpenGL headers to the latest API from The Khronos Group
Inc. * Added SDL_GetWindowSizeInPixels() to get the window size in pixels, which
may differ from the window coordinate size for windows with high-DPI support *
Added simulated vsync synchronization for the software renderer * Added the
mouse position to SDL_MouseWheelEvent * Added SDL_ResetHints() to reset all
hints to their default values * Added SDL_GetJoystickGUIDInfo() to get device
information encoded in a joystick GUID * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_360 to control whether the HIDAPI driver for XBox
360 controllers should be used * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_360_PLAYER_LED to control whether the player LEDs
should be lit to indicate which player is associated with an Xbox 360 controller
* Added the hint SDL_HINT_JOYSTICK_HIDAPI_XBOX_360_WIRELESS to control whether
the HIDAPI driver for XBox 360 wireless controllers should be used * Added the
hint SDL_HINT_JOYSTICK_HIDAPI_XBOX_ONE to control whether the HIDAPI driver for
XBox One controllers should be used * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_ONE_HOME_LED to control the brightness of the XBox
One guide button LED * Added support for PS3 controllers to the HIDAPI driver,
enabled by default on macOS, controlled by the SDL_HINT_JOYSTICK_HIDAPI_PS3 hint
* Added support for Nintendo Wii controllers to the HIDAPI driver, not enabled
by default, controlled by the SDL_HINT_JOYSTICK_HIDAPI_WII hint * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_WII_PLAYER_LED to control whether the player LED should
be lit on the Nintendo Wii controllers * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_VERTICAL_JOY_CONS to control whether Nintendo Switch
Joy-Con controllers will be in vertical mode when using the HIDAPI driver *
Added access to the individual left and right gyro sensors of the combined Joy-
Cons controller * Added a microsecond timestamp to SDL_SensorEvent and
SDL_ControllerSensorEvent, when the hardware provides that information * Added
SDL_SensorGetDataWithTimestamp() and
SDL_GameControllerGetSensorDataWithTimestamp() to retrieve the last sensor data
with the associated microsecond timestamp * Added the hint
SDL_HINT_HIDAPI_IGNORE_DEVICES to have the SDL HID API ignore specific devices *
SDL_GetRevision() now includes more information about the SDL build, including
the git commit hash if available #### Windows: * Added the hint
SDL_HINT_MOUSE_RELATIVE_SYSTEM_SCALE to control whether the system mouse
acceleration curve is used for relative mouse motion #### Linux: * Added
SDL_SetPrimarySelectionText(), SDL_GetPrimarySelectionText(), and
SDL_HasPrimarySelectionText() to interact with the X11 primary selection
clipboard * Added the hint SDL_HINT_VIDEO_WAYLAND_EMULATE_MOUSE_WARP to control
whether mouse pointer warp emulation is enabled under Wayland
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Neal Gompa <ngompa(a)fedoraproject.org> - 2.26.0-1
- Update to 2.26.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2132564 - SDL2-2.24.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2132564
--------------------------------------------------------------------------------
================================================================================
blueman-2.3.5-1.fc35 (FEDORA-2022-6da0b70e07)
GTK+ Bluetooth Manager
--------------------------------------------------------------------------------
Update Information:
Update to v2.3.5
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Artur Frenszek-Iwicki <fedora(a)svgames.pl> - 1:2.3.5-1
- Update to v2.3.5
--------------------------------------------------------------------------------
================================================================================
coturn-4.6.0-2.fc35 (FEDORA-2022-f70288fa1c)
TURN/STUN & ICE Server
--------------------------------------------------------------------------------
Update Information:
* Include `CAP_NET_BIND_SERVICE` in the ambient capability set (to allow to
bind coturn to privileged ports (ports < 1024), e.g. port 80 or 443, to handle
restrictive corporate firewalls)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Robert Scheck <robert(a)fedoraproject.org> - 4.6.0-2
- Include CAP_NET_BIND_SERVICE in the ambient capability set (to
bind to privileged ports due to restrictive corporate firewalls)
--------------------------------------------------------------------------------
================================================================================
datovka-4.21.1-1.fc35 (FEDORA-2022-de83315180)
A free graphical interface for Czech Databox (Datov�� schr��nky)
--------------------------------------------------------------------------------
Update Information:
This is new version of datovka.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.21.1-1
- New version
Resolves: rhbz#2144857
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2144857 - datovka-4.21.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2144857
--------------------------------------------------------------------------------
================================================================================
dotnet6.0-6.0.111-1.fc35 (FEDORA-2022-1a701a1823)
.NET Runtime and SDK
--------------------------------------------------------------------------------
Update Information:
This is the November 2022 update for .NET 6. It updates .NET SDK to 6.0.111 and
the Runtime to 6.0.11. Upstream release notes: - SDK:
https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.11/6.0.111.md -
Runtime:
https://github.com/dotnet/core/blob/main/release-
notes/6.0/6.0.11/6.0.11.md
--------------------------------------------------------------------------------
ChangeLog:
* Thu Nov 10 2022 Omair Majid <omajid(a)redhat.com> - 6.0.111-1
- Update to .NET SDK 6.0.111 and Runtime 6.0.11
--------------------------------------------------------------------------------
================================================================================
exim-4.96-6.fc35 (FEDORA-2022-31ec445169)
The exim mail transfer agent
--------------------------------------------------------------------------------
Update Information:
This is an update fixing exit on attempt to rewrite malformed address.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.96-6
- Fixed exit on attempt to rewrite malformed address
Resolves: rhbz#2143283
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2143283 - Version 4.96-4 does not contain fix for bug 2903
https://bugzilla.redhat.com/show_bug.cgi?id=2143283
--------------------------------------------------------------------------------
================================================================================
git-extras-6.5.0-1.fc35 (FEDORA-2022-35f6a6fd97)
Little git extras
--------------------------------------------------------------------------------
Update Information:
Update git-extras to 6.5.0 (#2132833)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 S��rgio Basto <sergio(a)serjux.com> - 6.5.0-1
- Update git-extras to 6.5.0 (#2132833)
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 6.4.0-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2132833 - git-extras-6.5.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2132833
--------------------------------------------------------------------------------
================================================================================
golang-github-charmbracelet-bubbletea-0.23.1-1.fc35 (FEDORA-2022-25bbec8d21)
A powerful little TUI framework
--------------------------------------------------------------------------------
Update Information:
Update to 0.23.1 ---- Initial package
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> 0.23.1-1
- Update to 0.23.1 - Closes rhbz#2144543
* Mon Oct 10 2022 Mikel Olasagasti Uranga <mikel(a)olasagasti.info> 0.22.1-1
- Initial package - Closes rhbz#2131402
--------------------------------------------------------------------------------
================================================================================
grub2-2.06-13.fc35 (FEDORA-2022-9b03e69561)
Bootloader with support for Linux, Multiboot and more
--------------------------------------------------------------------------------
Update Information:
- Adjust the way we provide unicode.pf2 for post-CVE lockdown policy ---- Two
font-related CVE updates (CVE-2022-2601 and CVE-2022-3775). For more
information, see [upstream's
disclosure](https://lists.gnu.org/archive/html/grub-devel/2022-11/msg0005...
or the patches themselves.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Robbie Harwood <rharwood(a)redhat.com> - 2.06-13
- Bundle unicode.pf2 with images
- Resolves: #2143725
- Resolves: #2144113
* Tue Nov 15 2022 Robbie Harwood <rharwood(a)redhat.com> - 2.06-12
- Font fixes (CVE-2022-2601 batch)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2143725 - 2.06-55.fc36 secure boot problem (non-latin1 characters broken)
https://bugzilla.redhat.com/show_bug.cgi?id=2143725
[ 2 ] Bug #2144113 - Latest grub2 breaks gfxterm
https://bugzilla.redhat.com/show_bug.cgi?id=2144113
--------------------------------------------------------------------------------
================================================================================
mingw-SDL2-2.26.0-1.fc35 (FEDORA-2022-f2aba4ff60)
MinGW Windows port of SDL2 cross-platform multimedia library
--------------------------------------------------------------------------------
Update Information:
In addition to lots of bug fixes, here are the major changes in this release:
#### General * Updated OpenGL headers to the latest API from The Khronos Group
Inc. * Added SDL_GetWindowSizeInPixels() to get the window size in pixels, which
may differ from the window coordinate size for windows with high-DPI support *
Added simulated vsync synchronization for the software renderer * Added the
mouse position to SDL_MouseWheelEvent * Added SDL_ResetHints() to reset all
hints to their default values * Added SDL_GetJoystickGUIDInfo() to get device
information encoded in a joystick GUID * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_360 to control whether the HIDAPI driver for XBox
360 controllers should be used * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_360_PLAYER_LED to control whether the player LEDs
should be lit to indicate which player is associated with an Xbox 360 controller
* Added the hint SDL_HINT_JOYSTICK_HIDAPI_XBOX_360_WIRELESS to control whether
the HIDAPI driver for XBox 360 wireless controllers should be used * Added the
hint SDL_HINT_JOYSTICK_HIDAPI_XBOX_ONE to control whether the HIDAPI driver for
XBox One controllers should be used * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_XBOX_ONE_HOME_LED to control the brightness of the XBox
One guide button LED * Added support for PS3 controllers to the HIDAPI driver,
enabled by default on macOS, controlled by the SDL_HINT_JOYSTICK_HIDAPI_PS3 hint
* Added support for Nintendo Wii controllers to the HIDAPI driver, not enabled
by default, controlled by the SDL_HINT_JOYSTICK_HIDAPI_WII hint * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_WII_PLAYER_LED to control whether the player LED should
be lit on the Nintendo Wii controllers * Added the hint
SDL_HINT_JOYSTICK_HIDAPI_VERTICAL_JOY_CONS to control whether Nintendo Switch
Joy-Con controllers will be in vertical mode when using the HIDAPI driver *
Added access to the individual left and right gyro sensors of the combined Joy-
Cons controller * Added a microsecond timestamp to SDL_SensorEvent and
SDL_ControllerSensorEvent, when the hardware provides that information * Added
SDL_SensorGetDataWithTimestamp() and
SDL_GameControllerGetSensorDataWithTimestamp() to retrieve the last sensor data
with the associated microsecond timestamp * Added the hint
SDL_HINT_HIDAPI_IGNORE_DEVICES to have the SDL HID API ignore specific devices *
SDL_GetRevision() now includes more information about the SDL build, including
the git commit hash if available #### Windows: * Added the hint
SDL_HINT_MOUSE_RELATIVE_SYSTEM_SCALE to control whether the system mouse
acceleration curve is used for relative mouse motion #### Linux: * Added
SDL_SetPrimarySelectionText(), SDL_GetPrimarySelectionText(), and
SDL_HasPrimarySelectionText() to interact with the X11 primary selection
clipboard * Added the hint SDL_HINT_VIDEO_WAYLAND_EMULATE_MOUSE_WARP to control
whether mouse pointer warp emulation is enabled under Wayland
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 22 2022 Neal Gompa <ngompa(a)fedoraproject.org> - 2.26.0-1
- Update to 2.26.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2132564 - SDL2-2.24.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2132564
--------------------------------------------------------------------------------
================================================================================
python-pymssql-2.2.7-1.fc35 (FEDORA-2022-392cb1758f)
DB-API interface to Microsoft SQL Server
--------------------------------------------------------------------------------
Update Information:
- Fill in result description in cursor.callproc (fix #772). - Add explicit link
to krb5 (fix #776), thanks to James Coder. - Some small doc fixes, thanks to
guillaumep and Logan Elandt.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 21 2022 Mohamed El Morabity <melmorabity(a)fedoraproject.org> - 2.2.7-1
- Update to 2.2.7
- Switch license tag to SPDX
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2143059 - python-pymssql-2.2.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2143059
--------------------------------------------------------------------------------
================================================================================
quisk-4.2.12-1.fc35 (FEDORA-2022-951cc908c7)
Software Defined Radio (SDR) software
--------------------------------------------------------------------------------
Update Information:
This is new version of quisk.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 21 2022 Jaroslav ��karvada <jskarvad(a)redhat.com> - 4.2.12-1
- New version
Resolves: rhbz#2144213
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2144213 - quisk-4.2.12 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2144213
--------------------------------------------------------------------------------