Fedora alert FEDORA-2026-2b5249b4b6 (perl-HarfBuzz-Shaper)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 43 Update: perl-HarfBuzz-Shaper-0.033-2.fc43 | |
| Date: | Thu, 29 Jan 2026 00:56:21 +0000 | |
| Message-ID: | <20260129005621.97A05798EF@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-2b5249b4b6 2026-01-29 00:55:04.138829+00:00 -------------------------------------------------------------------------------- Name : perl-HarfBuzz-Shaper Product : Fedora 43 Version : 0.033 Release : 2.fc43 URL : https://metacpan.org/release/HarfBuzz-Shaper Summary : Access to a small subset of the native HarfBuzz library Description : HarfBuzz::Shaper is a perl module that provides access to a small subset of the native HarfBuzz library. The subset is suitable for typesetting programs that need to deal with complex languages like Devanagari. This module is intended to be used with module L<Text::Layout>. -------------------------------------------------------------------------------- Update Information: Merge branch 'rawhide' into f43 Upgrade to upstream 0.032 to fix CVE-2026-22693. -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 20 2026 Johan Vromans <jvromans@squirrel.nl> - 0.033-1 - Upgrade to upstream. Eliminates distributing harfbuzz sources. * Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.032-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Jan 14 2026 Johan Vromans <jvromans@squirrel.nl> - 0.032-1 - Upgrade to upstream 0.032. Upgrade embedded harfbuzz to 12.3.0 to fix CVE-2026-22693. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2342927 - perl-HarfBuzz-Shaper-0.033 is available https://bugzilla.redhat.com/show_bug.cgi?id=2342927 [ 2 ] Bug #2429296 - CVE-2026-22693 perl-HarfBuzz-Shaper: Null Pointer Dereference in harfbuzz [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2429296 [ 3 ] Bug #2430874 - CVE-2026-0943 perl-HarfBuzz-Shaper: HarfBuzz::Shaper null pointer dereference vulnerability [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2430874 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2b5249b4b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
