Back Linuxsecurity Fedora 43 restic Update Denial of Service Issues 2026
* Wed Jun 10 2026 Mikel Olasagasti Uranga - 0.19.0-1 - Update to 0.19.0 - Closes rhbz#2487290 * Tue Feb 3 2026 Maxwell G - 0.18.1-3 - Rebuild for * Sat Jan 17 2026 Fedora Release Engineering - 0.18.1-2 - Rebuilt for
* Wed Jun 10 2026 Mikel Olasagasti Uranga - 0.19.0-1 - Update to 0.19.0 - Closes rhbz#2487290 * Tue Feb 3 2026 Maxwell G - 0.18.1-3 - Rebuild for * Sat Jan 17 2026 Fedora Release Engineering - 0.18.1-2 - Rebuilt for
[ 1 ] Bug #2455673 - CVE-2026-34986 restic: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object [fedora-all] [ 2 ] Bug #2464136 - CVE-2026-41179 restic: Rclone: Unauthenticated local command execution via exposed RC endpoint [fedora-all] [ 3 ] Bug #2464140 - CVE-2026-41176 restic: Rclone: Unauthorized access to administrative functions through unauthenticated Remote Control endpoint. [fedora-all] [ 4 ] Bug #2486238 - CVE-2026-45287 restic: OpenTelemetry-Go: Denial of Service due to file descriptor leak [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e6094447f0' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
