-------------------------------------------------------------------------------- Fedora EPEL Update Notification FEDORA-EPEL-2025-d12b62c436 2025-11-03 00:51:33.254409+00:00 --------------------------------------------------------------------------------
Name : rust-reqsign-command-execute-tokio Product : Fedora EPEL 10.2 Version : 2.0.0 Release : 1.el10_2 URL : https://crates.io/crates/reqsign-command-execute-tokio Summary : Tokio-based command execution implementation for reqsign Description : Tokio-based command execution implementation for reqsign. -------------------------------------------------------------------------------- Update Information: uv 0.9.5 https://github.com/astral-sh/uv/blob/0.9.5/CHANGELOG.md Since uv was built with astral-tokio-tar 0.5.6, this is a security fix for CVE-2025-62518. ruff 0.14.2 https://github.com/astral-sh/ruff/blob/0.14.2/CHANGELOG.md rust-astral-tokio-tar 0.5.6 Fixed a parser desynchronization vulnerability when reading tar archives that contain mismatched size information in PAX/ustar headers. This vulnerability is being tracked as GHSA-j5gw-2vrg-8fgx and CVE-2025-62518. Initial packages for a number of new dependencies for ruff and uv, and initial EPEL10 packages for a few of their dependencies. Update rust-tikv-jemallocator and rust-tikv-jemalloc-sys to 0.6.1. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 23 2025 Benjamin A. Beasley <[email protected]> - 2.0.0-1 - Update to version 2.0.0; Fixes RHBZ#2402442 * Thu Oct 2 2025 Benjamin A. Beasley <[email protected]> - 1.0.0-1 - Initial package (close RHBZ#2400111) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360699 - ruff-0.14.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2360699 [ 2 ] Bug #2402441 - rust-reqsign-core-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402441 [ 3 ] Bug #2402442 - rust-reqsign-command-execute-tokio-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402442 [ 4 ] Bug #2402443 - rust-reqsign-http-send-reqwest-2.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402443 [ 5 ] Bug #2402923 - uv-0.9.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2402923 [ 6 ] Bug #2405468 - CVE-2025-62518 rust-astral-tokio-tar: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2405468 [ 7 ] Bug #2405469 - CVE-2025-62518 uv: astral-tokio-tar Vulnerable to PAX Header Desynchronization [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2405469 [ 8 ] Bug #2406135 - ruff-0.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2406135 -------------------------------------------------------------------------------- This update can be installed with the "yum" update programs. Use su -c 'yum update rust-reqsign-command-execute-tokio' at the command line. For more information, refer to "YUM", available at https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\ /html/System_Administrators_Guide/ch-yum.html All packages are signed with the Fedora EPEL GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ epel-package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
