Fedora Restic and Singularity-CE Vulnerabilities Lead to Denial of Service Risks

Fedora Restic and Singularity-CE Vulnerabilities Lead to Denial of Service Risks

First seen 19 Jun 2026, 02:54 UTC Linuxsecurityfedoraproject.org 81% similarity 60.6

Article Content

Browse articles
ThreatCluster

Recent updates for Fedora 43 and 44 address multiple vulnerabilities in Restic and Singularity-CE, including Denial of Service (DoS) issues and unauthorized access risks. The vulnerabilities, identified as CVE-2026-34986, CVE-2026-41179, and CVE-2026-41176, affect Fedora systems and allow attackers to exploit crafted JSON Web Encryption objects and unauthorized command execution. The updates were released on June 10, 2026, and are critical for users to apply to mitigate potential attacks. The vulnerabilities were reported to have been published between April 6 and April 23, 2026. Users are advised to upgrade to the latest versions using the provided commands to secure their systems against these threats.

Key Points: • Fedora 43 and 44 updates address critical DoS and access vulnerabilities in Restic. • CVE-2026-34986 allows DoS via crafted JSON Web Encryption objects. • Immediate updates are recommended to mitigate risks from unauthorized access and command execution.

ThreatCluster AI How this analysis works

Timeline

2026-03-27
CVE-2026-33748 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-06
CVE-2026-34986 published
Denial of Service vulnerability in Restic via crafted JSON Web Encryption objects disclosed.
Linuxsecurity
2026-04-14
CVE-2026-39984 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-22
CVE-2026-41176 published
Unauthorized access vulnerability in Restic's Remote Control endpoint disclosed.
Linuxsecurity
2026-04-23
CVE-2026-41179 published
Unauthenticated local command execution vulnerability in Restic disclosed.
Linuxsecurity
2026-06-04
CVE-2026-45287 published
Denial of Service due to file descriptor leak in Restic disclosed.
Linuxsecurity
2026-06-10
Fedora updates released
Updates for Fedora 43 and 44 released to address multiple vulnerabilities in Restic and Singularity-CE.
Linuxsecurity

Community

Browse all →