stable

chezmoi-2.72.0-1.fc44

FEDORA-2026-4ca48be67c created by mikelo2 a month ago for Fedora 44

Update to 2.72.0

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-4ca48be67c

This update has been submitted for testing by mikelo2.

a month ago

This update's test gating status has been changed to 'waiting'.

a month ago

mikelo2 edited this update.

a month ago

This update's test gating status has been changed to 'passed'.

a month ago

This update has been pushed to testing.

a month ago
User Icon hhlp commented & provided feedback a month ago
karma

LGMT

This update can be pushed to stable now if the maintainer wishes

a month ago

This update has been submitted for stable by mikelo2.

a month ago

This update has been pushed to stable.

a month ago

Please log in to add feedback.

Metadata
Type
security
Karma
1
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
a month ago
modified
a month ago
approved
a month ago
BZ#2489891 CVE-2026-39828 chezmoi: golang.org/x/crypto/ssh: Unauthorized command execution via discarded SSH permissions [fedora-all]
0
0
BZ#2490088 CVE-2026-39829 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters [fedora-all]
0
0
BZ#2490398 CVE-2026-39830 chezmoi: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses [fedora-all]
0
0
BZ#2493053 CVE-2026-39832 chezmoi: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions [fedora-all]
0
0
BZ#2493488 CVE-2026-39835 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate [fedora-all]
0
0
BZ#2495261 CVE-2026-25681 chezmoi: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting [fedora-all]
0
0
BZ#2496497 CVE-2026-44740 chezmoi: Billy: Denial of Service via crafted input due to insufficient validation [fedora-all]
0
0
BZ#2509311 CVE-2026-46597 chezmoi: golang.org/x/crypto/ssh: Denial of Service via crafted AES-GCM packet decoder inputs [fedora-all]
0
0
BZ#2509459 CVE-2026-39831 chezmoi: golang.org/x/crypto/ssh: Security key bypass due to missing user presence check [fedora-all]
0
0

Automated Test Results