Skip to content
Fedora 43 C-Kermit Medium Buffer Overflow Vuln 2026

Fedora 43 C-Kermit Medium Buffer Overflow Vuln 2026

Linuxsecurity •LinuxSecurity Advisories • September 27, 2026

CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×

C-Kermit is a combined serial and network communication software

package offering a consistent, medium-independent, cross-platform

approach to connection establishment, terminal sessions, file transfer

and management, character-set translation, and automation of

Update to 11.0.509 to address CVE-2025-68920

* Thu Sep 17 2026 Martin Jackson - 11.0.509-2 - Conditionalize tests - skip on EL8 and EL9 due to missing pyftpdlib. Run tests by default. - Include new docs files. * Thu Sep 17 2026 Martin Jackson - 11.0.509-1 - Update to 11.0.509 - Link with -llockdev (upstream linux target passes -DHAVE_LOCKDEV instead) - Keep optflags/ldflags so debuginfo is generated * Wed Jul 29 2026 John Goerzen - 11.0.505-1 - Update to 11.0.505 - Upstream noticed the discussion in README.fedora and clarified the error message. Discussion in README.fedora updated. - Drop -D'krb5_init_ets(__ctx)=' from KFLAGS and the The makefile rules in use here never define CK_KERBEROS, so krb5_init_ets() was never compiled in to begin with; the macro override has done nothing since we moved off the old Kerberos-enabled Red Hat build target from around 2005 (see the 8.0.211 changelog entry below: "remove now-unnecessary use of krb5_init_ets()"). - Drop ckermit-9.0.302-fix_build_with_glibc_2_28_and_earlier.patch. Upstream modernization already addressed this. - Drop ckermit-9.0.302-printw.patch; upstream independently replaced the one remaining unsafe printw() call with fputs() - Drop ckermit-9.0.302-fedora-c99.patch: all missing #includes it added have been added upstream via generic mechanisms - Drop -DMAINTYPE=int and -ansi from KFLAGS. -DMAINTYPE=int is unnecessary due to typedef upstream. -ansi also is no longer necessary due to upstream modernization. - Add "make check"/pytest test suite integration, gated by a new "tests" bcond - %files: replace %doc ckc302.txt, which no longer exists in this release. doc/*.md in the source tree now provides various documentation. - URL: point at the current project , openkermit.org, instead of the old kermitproject.org ck90.html page, which described the 9.0 release specifically * Wed Jul 15 2026 Fedora Release Engineering - 9.0.302-43 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 9.0.302-42 - Rebuilt for openssl 4.0 * Fri Jan 16 2026 Fedora Release Engineering - 9.0.302-41 - Rebuilt for * Fri Jan 16 2026 Fedora Release Engineering - 9.0.302-40 - Rebuilt for

* Thu Sep 17 2026 Martin Jackson - 11.0.509-2 - Conditionalize tests - skip on EL8 and EL9 due to missing pyftpdlib. Run tests by default. - Include new docs files. * Thu Sep 17 2026 Martin Jackson - 11.0.509-1 - Update to 11.0.509 - Link with -llockdev (upstream linux target passes -DHAVE_LOCKDEV instead) - Keep optflags/ldflags so debuginfo is generated * Wed Jul 29 2026 John Goerzen - 11.0.505-1 - Update to 11.0.505 - Upstream noticed the discussion in README.fedora and clarified the error message. Discussion in README.fedora updated. - Drop -D'krb5_init_ets(__ctx)=' from KFLAGS and the The makefile rules in use here never define CK_KERBEROS, so krb5_init_ets() was never compiled in to begin with; the macro override has done nothing since we moved off the old Kerberos-enabled Red Hat build target from around 2005 (see the 8.0.211 changelog entry below: "remove now-unnecessary use of krb5_init_ets()"). - Drop ckermit-9.0.302-fix_build_with_glibc_2_28_and_earlier.patch. Upstream modernization already addressed this. - Drop ckermit-9.0.302-printw.patch; upstream independently replaced the one remaining unsafe printw() call with fputs() - Drop ckermit-9.0.302-fedora-c99.patch: all missing #includes it added have been added upstream via generic mechanisms - Drop -DMAINTYPE=int and -ansi from KFLAGS. -DMAINTYPE=int is unnecessary due to typedef upstream. -ansi also is no longer necessary due to upstream modernization. - Add "make check"/pytest test suite integration, gated by a new "tests" bcond - %files: replace %doc ckc302.txt, which no longer exists in this release. doc/*.md in the source tree now provides various documentation. - URL: point at the current project , openkermit.org, instead of the old kermitproject.org ck90.html page, which described the 9.0 release specifically * Wed Jul 15 2026 Fedora Release Engineering - 9.0.302-43 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 9.0.302-42 - Rebuilt for openssl 4.0 * Fri Jan 16 2026 Fedora Release Engineering - 9.0.302-41 - Rebuilt for * Fri Jan 16 2026 Fedora Release Engineering - 9.0.302-40 - Rebuilt for

[ 1 ] Bug #2425363 - CVE-2025-68920 ckermit: From CVEorg collector [fedora-43]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cc3b077d5b' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities