Fedora alert FEDORA-2026-7d3c7180c7 (yt-dlp)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 42 Update: yt-dlp-2026.02.21-1.fc42 | |
| Date: | Thu, 05 Mar 2026 01:13:50 +0000 | |
| Message-ID: | <20260305011350.788AD82E0A@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-7d3c7180c7 2026-03-05 01:12:27.918866+00:00 -------------------------------------------------------------------------------- Name : yt-dlp Product : Fedora 42 Version : 2026.02.21 Release : 1.fc42 URL : https://github.com/yt-dlp/yt-dlp Summary : A command-line program to download videos from online video platforms Description : yt-dlp is a command-line program to download videos from many different online video platforms, such as youtube.com. The project is a fork of youtube-dl with additional features and fixes. -------------------------------------------------------------------------------- Update Information: Update to 2026.02.21. Fixes rhbz#2441709. Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244) -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 24 2026 Maxwell G <maxwell@gtmx.me> - 2026.02.21-1 - Update to 2026.02.21. Fixes rhbz#2441709. - Mitigates CVE-2026-26331 / GHSA-g3gw-q23r-pgqm (rhbz#2442244) * Sat Feb 21 2026 Dominik 'Rathann' Mierzejewski <dominik@greysector.net> - 2026.02.04-2 - fix FTBFS with python 3.14.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2441709 - yt-dlp-2026.02.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=2441709 [ 2 ] Bug #2442244 - CVE-2026-26331 yt-dlp: yt-dlp: Arbitrary command injection via maliciously crafted URL when --netrc-cmd is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2442244 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7d3c7180c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
