Linuxsecurity Multiple Security Updates for Fedora Address Critical Vulnerabilities
Article Content
- •CVE-2026-10846 affects the ldns library, crucial for DNS operations.
- •CVE-2026-44898 in python-mistune allows arbitrary code execution via HTML injection.
- •Fedora users are urged to update their systems to prevent exploitation.
Fedora has released important updates addressing vulnerabilities in the ldns and python-mistune packages. The ldns library update (CVE-2026-10846), published on June 10, 2026, resolves a significant issue affecting low-level DNS operations. Additionally, python-mistune received a critical update (CVE-2026-44898) on June 18, 2026, which fixes an arbitrary code execution vulnerability due to HTML injection in table of contents rendering. Users of Fedora 43 and 44 are advised to apply these updates promptly to mitigate potential exploitation risks. Both vulnerabilities have been acknowledged by the Fedora community, emphasizing the importance of maintaining updated systems. The updates can be installed using the dnf package manager, with specific advisories provided for each CVE.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Fedora and CVE-2026-10846 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…