- What: Fedora 42 has a security update addressing a denial-of-service vulnerability (CVE-2026-25537) in the time crate and other dependencies.
- Impact: Applications using the affected crates may be vulnerable to denial-of-service attacks.
- CVE: CVE-2026-25537
News Advisories HOWTOs Features Newsletters Polls About Security Dictionary Login Sign Up Fedora 42 sad Update CVE-2026-25537 Denial of Service Vulnerability Update the time crate to version 0.3.47 SUMMARY Space Age seD - Batch File Edit tool. It will show you a really nice diff of proposed changes before you commit them. Update Information: Update the time crate to version 0.3.47. Update the time-macros crate to version 0.2.27. Update the time-core crate to version 0.1.8. Update the num-conv crate to version 0.2.0. Update the git2 crate to version 0.20.4. Update the bytes crate to version 1.11.1. Additionally, this update contains rebuilds of applications affected by security advisories: bytes: RUSTSEC-2026-0007 git2: RUSTSEC-2026-0008 jsonwebtoken: CVE-2026-25537 time: RUSTSEC-2026-0009 All applications that statically link libgit2 via the git2 Rust bindings were also rebuilt against the latest version of the git2 / libgit2-sys crates to pull in fixes included in libgit2 between v1.8.1 and v1.9.2. CHANGE LOG * Sat Feb 7 2026 Fabio Valentini <decathorpe@gmail.com> - 0.4.32-4 - Rebuild for RUSTSEC-2026-{0007,0008,0009} and CVE-2026-25537 * Sat Jan 17 2026 Fedora Release Engineering <releng@fedoraproject.org> - 0.4.32-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jul 25 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.4.32-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild REFERENCES [ 1 ] Bug #2437465 - CVE-2026-25537 rust-jsonwebtoken: jsonwebtoken has Type Confusion that leads to potential authorization bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2437465 [ 2 ] Bug #2437467 - CVE-2026-25537 uv: jsonwebtoken has Type Confusion that leads to potential authorization bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2437467 [ 3 ] Bug #2438046 - CVE-2026-25727 atuin: time affected by a stack exhaustion denial of service attack [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2438046 [ 4 ] Bug #2438075 - CVE-2026-25727 keylime-agent-rust: time affected by a stack exhaustion denial of service attack [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2438075 [ 5 ] Bug #2438077 - CVE-2026-25727 maturin: time affected by a stack exhaustion denial of service attack [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2438077 [ 6 ] Bug #2438086 - CVE-2026-25727 rus... Read the Full Advisory UPDATE INSTRUCTIONS This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-6388b28850' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label Severity Name : sad Issued Date: February 11, 2026 Product : Fedora 42 Version : 0.4.32 Release : 4.fc42 URL : https://github.com/ms-jpq/sad Summary : CLI search and replace tool Get the Latest News & Insights Sign up to get the latest security news affecting Linux and open source delivered straight to your inbox Linux Advisory Watch Linux Security Week Yes, sign me up! Prev: Fedora 42 tuigreet CVE-2026-25537 Stack Exhaustion Advisory Next: Fedora 42 uv Critical JSON Web Token Issue Advisory CVE-2026-25537 Related News Search Exposure Linux Security Threats Impacting Personal Data 6 - 11 min read Feb 11, 2026 Search-indexed personal data increases security risk in Linux environments. When email addresses, usernames, phone numbers, and role information are Linux Security Hardening Guide 2026 SSH Backup Strategies 3 - 5 min read Feb 05, 2026 Linux security is not about stacking tools and hoping for the best. It comes down to deliberate configuration, steady maintenance, and systems that AI Coding, Rust, and the Linux Security Tradeoffs We Have to Manage 6 - 11 min read Feb 02, 2026 I keep seeing Rust show up in places it never could have five years ago. Kernel-adjacent tools. Security agents. Parsers that used to be a pile of Intrusion Detection System Auto Response Risks and Best Practices 5 - 10 min read Feb 02, 2026 An intrusion detection system can identify suspicious activity. Once an alert is generated, a decision has to be made. The alert can be logged, 11-Year-Old telnetd Flaw Found in GNU InetUtils: What Linux Admins Need to Reassess Now 8 - 15 min read Feb 01, 2026 Seeing the word “telnet” on a system tends to trigger a reaction. For some admins, it means risk. For others, it means legacy noise that can be Linux Users Targeted as Crypto-stealing Malware Hits Snap Packages 7 - 14 min read Jan 28, 2026 We’ve been telling ourselves that Snap apps are sandboxed, signed, and therefore low-risk. Not perfect, but good enough. That assumption has been UFW in Linux: Why Firewall Issues Repeat and How to Recognize Them 4 - 8 min read Jan 23, 2026 We’ve all run into UFW on Linux systems that were already in use. When firewall problems show up, they almost never show up in new or surprising Managing Unintended Exposure from UFW Application Profiles in Linux 7 - 14 min read Jan 20, 2026 On most long-running Linux servers, UFW rules don’t get removed; they get forgotten. Services change, ports shift, packages come and go, and the 1 2 News Cloud Security Cryptography Desktop Security Firewall Government Hacks/Cracks IoT Security Network Security Organizations/Events Privacy Security Projects Security Trends Security Vulnerabilities Server Security Vendors/Products Advisories Debian Debian LTS Fedora Gentoo Mageia Oracle openSUSE RockyLinux Slackware SuSE Ubuntu HOWTOs Harden My Filesystem Learn Tips and Tricks Secure My E-mail Secure My Firewall Secure My Network Secure My Webserver Strengthen My Privacy Features Best Secure Linux Distros for Enhanced Privacy & Security The Truth About Linux Malware & How to Protect Your System Is Linux A More Secure Option Than Windows For Businesses? How Secure Is Linux? Top Tips for Securing Your Linux System About Us Advertise Contribute Your Article Legal Notice RSS Feeds Contact Us Terms of Service Privacy Policy Powered By Linux Security - Your source for Top Linux News, Advisories, HowTo's and Feature Release. © 2026 Guardian Digital, Inc All Rights Reserved We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy. Accept