Fedora 44 and 43 Ongres Security Updates Address Authentication Vulnerabilities

Fedora 44 and 43 Ongres Security Updates Address Authentication Vulnerabilities

First seen 19 Jun 2026, 02:54 UTC Linuxsecurity 87% similarity 60.6

Article Content

Browse articles
ThreatCluster

Recent security updates for Fedora 44 and 43 address significant vulnerabilities in the Ongres database authentication mechanisms. The updates fix silent channel-binding authentication downgrades via unsupported certificate algorithms, which could potentially allow attackers to exploit these vulnerabilities. Affected systems include Fedora 43 and 44 versions utilizing the Ongres database. The specific bugs are tracked as Bug #2487526 and Bug #2487527. Users are advised to apply the updates using the 'dnf' update program. These vulnerabilities were reported as significant security risks, prompting immediate action from the Fedora development team. The updates were released on June 10 and June 19, 2026, with advisories published on June 20, 2026. The vulnerabilities do not appear to be actively exploited at this time.

Key Points: • Fedora 44 and 43 received critical security updates for Ongres database vulnerabilities. • The vulnerabilities involve silent channel-binding authentication downgrades. • Users are urged to apply updates using the 'dnf' update program immediately.

ThreatCluster AI How this analysis works

Timeline

2026-06-10
Fedora 44 update released
An important security fix for PostgreSQL JDBC was released, addressing authentication vulnerabilities.
Linuxsecurity
2026-06-19
Fedora 43 update released
A significant security update for Ongres Stringprep was published to address vulnerabilities.
Linuxsecurity
2026-06-20
Multiple advisories published
Advisories for Fedora 44 Ongres Stringprep and Scram were released, detailing critical security fixes.
Linuxsecurity
2026-06-20
Fedora 44 Ongres Scram major patch released
A major security patch was issued for Ongres Scram to mitigate authentication vulnerabilities.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story