Back Linuxsecurity Fedora 44 C-Kermit 11.0.509 Medium Threat CVE-2025
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
C-Kermit is a combined serial and network communication software
package offering a consistent, medium-independent, cross-platform
approach to connection establishment, terminal sessions, file transfer
and management, character-set translation, and automation of
Update to 11.0.509 which fixes CVE-2025-68920
* Thu Sep 17 2026 Martin Jackson - 11.0.509-2 - Conditionalize tests - skip on EL8 and EL9 due to missing pyftpdlib. Run tests by default. - Include new docs files. * Thu Sep 17 2026 Martin Jackson - 11.0.509-1 - Update to 11.0.509 - Link with -llockdev (upstream linux target passes -DHAVE_LOCKDEV instead) - Keep optflags/ldflags so debuginfo is generated * Wed Jul 29 2026 John Goerzen - 11.0.505-1 - Update to 11.0.505 - Upstream noticed the discussion in README.fedora and clarified the error message. Discussion in README.fedora updated. - Drop -D'krb5_init_ets(__ctx)=' from KFLAGS and the The makefile rules in use here never define CK_KERBEROS, so krb5_init_ets() was never compiled in to begin with; the macro override has done nothing since we moved off the old Kerberos-enabled Red Hat build target from around 2005 (see the 8.0.211 changelog entry below: "remove now-unnecessary use of krb5_init_ets()"). - Drop ckermit-9.0.302-fix_build_with_glibc_2_28_and_earlier.patch. Upstream modernization already addressed this. - Drop ckermit-9.0.302-printw.patch; upstream independently replaced the one remaining unsafe printw() call with fputs() - Drop ckermit-9.0.302-fedora-c99.patch: all missing #includes it added have been added upstream via generic mechanisms - Drop -DMAINTYPE=int and -ansi from KFLAGS. -DMAINTYPE=int is unnecessary due to typedef upstream. -ansi also is no longer necessary due to upstream modernization. - Add "make check"/pytest test suite integration, gated by a new "tests" bcond - %files: replace %doc ckc302.txt, which no longer exists in this release. doc/*.md in the source tree now provides various documentation. - URL: point at the current project , openkermit.org, instead of the old kermitproject.org ck90.html page, which described the 9.0 release specifically * Wed Jul 15 2026 Fedora Release Engineering - 9.0.302-43 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 9.0.302-42 - Rebuilt for openssl 4.0
* Thu Sep 17 2026 Martin Jackson - 11.0.509-2 - Conditionalize tests - skip on EL8 and EL9 due to missing pyftpdlib. Run tests by default. - Include new docs files. * Thu Sep 17 2026 Martin Jackson - 11.0.509-1 - Update to 11.0.509 - Link with -llockdev (upstream linux target passes -DHAVE_LOCKDEV instead) - Keep optflags/ldflags so debuginfo is generated * Wed Jul 29 2026 John Goerzen - 11.0.505-1 - Update to 11.0.505 - Upstream noticed the discussion in README.fedora and clarified the error message. Discussion in README.fedora updated. - Drop -D'krb5_init_ets(__ctx)=' from KFLAGS and the The makefile rules in use here never define CK_KERBEROS, so krb5_init_ets() was never compiled in to begin with; the macro override has done nothing since we moved off the old Kerberos-enabled Red Hat build target from around 2005 (see the 8.0.211 changelog entry below: "remove now-unnecessary use of krb5_init_ets()"). - Drop ckermit-9.0.302-fix_build_with_glibc_2_28_and_earlier.patch. Upstream modernization already addressed this. - Drop ckermit-9.0.302-printw.patch; upstream independently replaced the one remaining unsafe printw() call with fputs() - Drop ckermit-9.0.302-fedora-c99.patch: all missing #includes it added have been added upstream via generic mechanisms - Drop -DMAINTYPE=int and -ansi from KFLAGS. -DMAINTYPE=int is unnecessary due to typedef upstream. -ansi also is no longer necessary due to upstream modernization. - Add "make check"/pytest test suite integration, gated by a new "tests" bcond - %files: replace %doc ckc302.txt, which no longer exists in this release. doc/*.md in the source tree now provides various documentation. - URL: point at the current project , openkermit.org, instead of the old kermitproject.org ck90.html page, which described the 9.0 release specifically * Wed Jul 15 2026 Fedora Release Engineering - 9.0.302-43 - Rebuilt for * Fri Jun 12 2026 Yaakov Selkowitz - 9.0.302-42 - Rebuilt for openssl 4.0
[ 1 ] Bug #2425363 - CVE-2025-68920 ckermit: From CVEorg collector [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-32742a29dc' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
