perl-Compress-Taw-Bzip2 - Updated to 2.218 perl-IO-Compress - Updated to 2.221 - Fix CVE-2025-15649, CVE-2026-48959, CVE-2026-48961, CVE-2026-48962
* Mon Jun 22 2026 Jitka Plesnikova - 2.221-1 - 2.221 bump (rhbz#2489325) Fixed CVE-2026-48961, CVE-2026-48962, CVE-2026-48959
* Mon Jun 22 2026 Jitka Plesnikova - 2.221-1 - 2.221 bump (rhbz#2489325) Fixed CVE-2026-48961, CVE-2026-48962, CVE-2026-48959
[ 1 ] Bug #2445591 - perl-Compress-Raw-Bzip2-2.218 is available [ 2 ] Bug #2483254 - CVE-2026-48962 perl-IO-Compress: perl-IO-Compress: Arbitrary code execution via attacker-controlled output glob [fedora-all] [ 3 ] Bug #2489171 - CVE-2025-15649 perl-IO-Compress: perl-IO-Compress: Denial of Service via malformed DOS date in zip header [fedora-all] [ 4 ] Bug #2489766 - CVE-2026-48961 perl-IO-Compress: IO::Compress: Denial of Service in zipdetails CLI tool via malformed Info-ZIP Unix Extra Field [fedora-all] [ 5 ] Bug #2489781 - CVE-2026-48959 perl-IO-Compress: perl-IO-Compress: CPU exhaustion via per-byte read loop in fastForward [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7ecfdcf0e3' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
