--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2026-cf3b9d64bd
2026-01-23 00:45:11.436190+00:00
--------------------------------------------------------------------------------

Name        : rclone
Product     : Fedora EPEL 9
Version     : 1.72.1
Release     : 1.el9
URL         : https://github.com/rclone/rclone
Summary     : Rsync for cloud storage
Description :
"rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive,
Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex
Files.

--------------------------------------------------------------------------------
Update Information:

Update to 1.72.1
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jan 14 2026 Mikel Olasagasti Uranga <[email protected]> - 1.72.1-1
- Apply EPEL9-specific changes
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2384107 - rclone: Host Header Injection in github.com/go-chi/chi 
[epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2384107
  [ 2 ] Bug #2398372 - CVE-2025-47910 rclone: CrossOriginProtection bypass in 
net/http [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2398372
  [ 3 ] Bug #2399022 - CVE-2025-47906 rclone: Unexpected paths returned from 
LookPath in os/exec [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2399022
  [ 4 ] Bug #2407558 - CVE-2025-58189 rclone: go crypto/tls ALPN negotiation 
error contains attacker controlled information [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2407558
  [ 5 ] Bug #2408557 - CVE-2025-61725 rclone: Excessive CPU consumption in 
ParseAddress in net/mail [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2408557
  [ 6 ] Bug #2409013 - CVE-2025-61723 rclone: Quadratic complexity when parsing 
some invalid inputs in encoding/pem [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409013
  [ 7 ] Bug #2409960 - CVE-2025-58185 rclone: Parsing DER payload can cause 
memory exhaustion in encoding/asn1 [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2409960
  [ 8 ] Bug #2410893 - CVE-2025-58188 rclone: Panic when validating 
certificates with DSA public keys in crypto/x509 [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2410893
  [ 9 ] Bug #2420574 - CVE-2025-47913 rclone: golang.org/x/crypto/ssh/agent: 
SSH client panic due to unexpected SSH_AGENT_SUCCESS [epel-9]
        https://bugzilla.redhat.com/show_bug.cgi?id=2420574
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update rclone' at the command line.
For more information, refer to "YUM", available at
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7\
/html/System_Administrators_Guide/ch-yum.html

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------

-- 
_______________________________________________
epel-package-announce mailing list -- 
[email protected]
To unsubscribe send an email to 
[email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to