Linuxsecurity Fedora 44 and 43 Ongres Security Updates Address Authentication Vulnerabilities
Article Content
- •Fedora 44 and 43 received critical security updates for Ongres database vulnerabilities.
- •The vulnerabilities involve silent channel-binding authentication downgrades.
- •Users are urged to apply updates using the 'dnf' update program immediately.
Recent security updates for Fedora 44 and 43 address significant vulnerabilities in the Ongres database authentication mechanisms. The updates fix silent channel-binding authentication downgrades via unsupported certificate algorithms, which could potentially allow attackers to exploit these vulnerabilities. Affected systems include Fedora 43 and 44 versions utilizing the Ongres database. The specific bugs are tracked as Bug #2487526 and Bug #2487527. Users are advised to apply the updates using the 'dnf' update program. These vulnerabilities were reported as significant security risks, prompting immediate action from the Fedora development team. The updates were released on June 10 and June 19, 2026, with advisories published on June 20, 2026. The vulnerabilities do not appear to be actively exploited at this time.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Fedora in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…