<?xml version="1.0" ?>
<rss version="2.0">
  <channel>
    <title>Rocky Linux 10 aarch64 AppStream</title>
    <link>https://rockylinux.org</link>
    <description>Recently updated packages for Rocky Linux 10 aarch64 AppStream</description>
    <pubDate>Mon, 14 Sep 2026 05:05:22 AM GMT</pubDate>
    <generator>DNF</generator>
    <item>
      <title>gstreamer1-plugins-base-tools-1.26.7-2.el10_2.2.aarch64</title>
      <pubDate>Fri, 11 Sep 2026 04:22:31 AM GMT</pubDate>
      <guid isPermaLink="false">608f8d38054477aa13912b9c0a1c6d248d91234988b13da61aba45221e8b2235</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-base-tools-1.26.7-2.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-base-tools</strong> - Tools for GStreamer streaming media framework base plugins&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of filters which&lt;br /&gt;
operate on media data. Applications using this library can do anything&lt;br /&gt;
from real-time sound processing to playing videos, and just about anything&lt;br /&gt;
else media-related.  Its plugin-based architecture means that new data&lt;br /&gt;
types or processing capabilities can be added simply by installing new&lt;br /&gt;
plug-ins.&lt;br /&gt;
&lt;br /&gt;
This package contains the command-line tools for the base plugins.&lt;br /&gt;
These include:&lt;br /&gt;
&lt;br /&gt;
* gst-discoverer</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 09 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.2
- Fix crash in RTSP auth credential parsing (CVE-2026-85150)
  Resolves: RHEL-253746

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.1
- Add patch for CVE-2026-18297
  Resolves: RHEL-246574

Mon, 31 Mar 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.26.7-2
- Add patch for CVE-2026-2921
  Resolves: RHEL-156122

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-base-devel-1.26.7-2.el10_2.2.aarch64</title>
      <pubDate>Fri, 11 Sep 2026 04:22:31 AM GMT</pubDate>
      <guid isPermaLink="false">77b3b690cd923c5b58d9c300a7696409a4f4822c8fcca7290ff034f1682b17a7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-base-devel-1.26.7-2.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-base-devel</strong> - GStreamer Base Plugins Development files&lt;br /&gt;</p>

<p>The gstreamer1-plugins-base-devel package contains libraries and header files&lt;br /&gt;
for developing applications that use gstreamer1-plugins-base.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 09 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.2
- Fix crash in RTSP auth credential parsing (CVE-2026-85150)
  Resolves: RHEL-253746

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.1
- Add patch for CVE-2026-18297
  Resolves: RHEL-246574

Mon, 31 Mar 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.26.7-2
- Add patch for CVE-2026-2921
  Resolves: RHEL-156122

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-base-1.26.7-2.el10_2.2.aarch64</title>
      <pubDate>Fri, 11 Sep 2026 04:22:31 AM GMT</pubDate>
      <guid isPermaLink="false">cd00edf353f1d38b815d7065c808811af4a7acf3beb4c34dfc290fbbd738012a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-base-1.26.7-2.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-base</strong> - GStreamer streaming media framework base plugins&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of filters which&lt;br /&gt;
operate on media data. Applications using this library can do anything&lt;br /&gt;
from real-time sound processing to playing videos, and just about anything&lt;br /&gt;
else media-related.  Its plugin-based architecture means that new data&lt;br /&gt;
types or processing capabilities can be added simply by installing new&lt;br /&gt;
plug-ins.&lt;br /&gt;
&lt;br /&gt;
This package contains a set of well-maintained base plug-ins.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 09 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.2
- Fix crash in RTSP auth credential parsing (CVE-2026-85150)
  Resolves: RHEL-253746

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.1
- Add patch for CVE-2026-18297
  Resolves: RHEL-246574

Mon, 31 Mar 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.26.7-2
- Add patch for CVE-2026-2921
  Resolves: RHEL-156122

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-doc-6.12.0-211.54.1.el10_2.noarch</title>
      <pubDate>Thu, 10 Sep 2026 07:58:25 PM GMT</pubDate>
      <guid isPermaLink="false">4aaa3c5b364a739faab61e6d2b898e80f8dac7131f482a8eae2d8dd8c3206f48</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-doc-6.12.0-211.54.1.el10_2.noarch.rpm</link>
      <description><p><strong>kernel-doc</strong> - Various documentation bits found in the kernel source&lt;br /&gt;</p>

<p>This package contains documentation files from the kernel&lt;br /&gt;
source. Various bits of information about the Linux kernel and the&lt;br /&gt;
device drivers shipped with it are documented in these files.&lt;br /&gt;
&lt;br /&gt;
You'll want to install this package if you need a reference to the&lt;br /&gt;
options that can be passed to Linux kernel modules at load time.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-perf-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">da1955fe6d4d690687cc7680d714ec3ce555669d132d812bde8f4727eab4e930</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-perf-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-perf</strong> - Python bindings for apps which will manipulate perf events&lt;br /&gt;</p>

<p>The python3-perf package contains a module that permits applications&lt;br /&gt;
written in the Python programming language to use the interface&lt;br /&gt;
to manipulate perf events.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-headers-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">993fb7b33814d9195962393d6013931be6dbad9ee9c3a3a0470b6252bd1c8544</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-headers-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-headers</strong> - Header files for the Linux kernel for use by glibc&lt;br /&gt;</p>

<p>Kernel-headers includes the C header files that specify the interface&lt;br /&gt;
between the Linux kernel and userspace libraries and programs.  The&lt;br /&gt;
header files define structures and constants that are needed for&lt;br /&gt;
building most standard programs and are also needed for rebuilding the&lt;br /&gt;
glibc package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-devel-matched-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">55d1ff3366456de6e9af7937dad7b2099397cf161f63e6cbab69f399e42566ae</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-devel-matched-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-devel-matched</strong> - Meta package to install matching core and devel packages for a given kernel&lt;br /&gt;</p>

<p>This meta package is used to install matching core and devel packages for a given kernel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-devel-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">c1925582b3d5b5560f8dfe6c68375534a342227f1b7111b94297572a74224684</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-devel-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-devel</strong> - Development package for building kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-debug-devel-matched-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">de7007a577e7f0b4640f919e0afb480c2f445789fe40e6ff4967cacd97d5d9bd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-debug-devel-matched-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-debug-devel-matched</strong> - Meta package to install matching core and devel packages for a given kernel&lt;br /&gt;</p>

<p>This meta package is used to install matching core and devel packages for a given kernel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-debug-devel-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">d732ce71ab29d9734a35ecaf409e23da3fb63c9a3a5e3745e2f70f53b3cabeec</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-debug-devel-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-debug-devel</strong> - Development package for building kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-64k-devel-matched-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">a720578e5f732bcea4b2824f88120e7614865b4fd48e18419cea01b668f9a8ff</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-64k-devel-matched-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-64k-devel-matched</strong> - Meta package to install matching core and devel packages for a given kernel&lt;br /&gt;</p>

<p>This meta package is used to install matching core and devel packages for a given kernel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-64k-devel-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">4b9c8946eec092b1644c384bfb871ec0bfed5952e2920326730246c5b0af7526</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-64k-devel-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-64k-devel</strong> - Development package for building kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-64k-debug-devel-matched-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">035fa7e086100a4ef81995a62f63aa01d3cc7fa3a3a2616a7a0778eedf5105bf</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-64k-debug-devel-matched-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-64k-debug-devel-matched</strong> - Meta package to install matching core and devel packages for a given kernel&lt;br /&gt;</p>

<p>This meta package is used to install matching core and devel packages for a given kernel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>kernel-64k-debug-devel-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">481d83a59a635d878798e60fd5ed7fa81d40a5770eba517ea7c61f5fb68187eb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/k/kernel-64k-debug-devel-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>kernel-64k-debug-devel</strong> - Development package for building kernel modules to match the kernel&lt;br /&gt;</p>

<p>This package provides kernel headers and makefiles sufficient to build modules&lt;br /&gt;
against the kernel package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perf-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">d2b4ba79b0c848fbb35f48fb46e1a3c092c645b719e95d07c4728d835a14ed2a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perf-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>perf</strong> - Performance monitoring for the Linux kernel&lt;br /&gt;</p>

<p>This package contains the perf tool, which enables performance monitoring&lt;br /&gt;
of the Linux kernel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>rv-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">1ff48df1af04a3107b9c672b627ec8ee38a08ec1c426d3f3601f5aecd9f52267</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/r/rv-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>rv</strong> - RV: Runtime Verification&lt;br /&gt;</p>

<p>Runtime Verification (RV) is a lightweight (yet rigorous) method that&lt;br /&gt;
complements classical exhaustive verification techniques (such as model&lt;br /&gt;
checking and theorem proving) with a more practical approach for&lt;br /&gt;
complex systems.&lt;br /&gt;
The rv tool is the interface for a collection of monitors that aim&lt;br /&gt;
analysing the logical and timing behavior of Linux.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>rtla-6.12.0-211.54.1.el10_2.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 05:29:51 PM GMT</pubDate>
      <guid isPermaLink="false">91049b9d5b80f55a64bfb3f66fb53077a59f609b7a2e60794b79230bb51e196a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/r/rtla-6.12.0-211.54.1.el10_2.aarch64.rpm</link>
      <description><p><strong>rtla</strong> - Real-Time Linux Analysis tools&lt;br /&gt;</p>

<p>The rtla meta-tool includes a set of commands that aims to analyze&lt;br /&gt;
the real-time properties of Linux. Instead of testing Linux as a black box,&lt;br /&gt;
rtla leverages kernel tracing capabilities to provide precise information&lt;br /&gt;
about the properties and root causes of unexpected results.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 6.12.0-211.54.1
- Add partial riscv64 support for build root
- Provide basic VisionFive 2 support

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.54.1.el10_2]
- net: bridge: stop fast-leave after deleting a port group (CKI Backport Bot) [RHEL-246933] {CVE-2026-74480}

Mon, 07 Sep 2026 GMT - CKI KWF Bot &amp;lt;cki-ci-bot+kwf-gitlab-com@redhat.com&amp;gt; [6.12.0-211.53.1.el10_2]
- dm-verity: fix buffer overflow in FEC calculation (Benjamin Marzinski) [RHEL-244969] {CVE-2026-72098}
- nvmet-rdma: handle inline data with a nonzero offset (CKI Backport Bot) [RHEL-244928] {CVE-2026-72129}
- rtla/timerlat_top: Fix on-threshold actions firing on signal (Tomas Glozar) [RHEL-193027]
- rtla/timerlat: Exit top main loop on any non-zero wait_retval (Tomas Glozar) [RHEL-193027]
- wifi: mac80211: defer link RX stats percpu free to RCU (Jose Ignacio Tornos Martinez) [RHEL-237706] {CVE-2026-68409}
- wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (Jose Ignacio Tornos Martinez) [RHEL-237681] {CVE-2026-68193}
- wifi: mt76: mt7925: fix crash in reset link replay (Jose Ignacio Tornos Martinez) [RHEL-237527] {CVE-2026-68307}
- wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers (Jose Ignacio Tornos Martinez) [RHEL-232015] {CVE-2026-64255}
- wifi: mac80211: capture fast-RX rate before mesh reuses skb-&amp;gt;cb (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: mac80211: fix missing RX bitrate update for mesh forwarding path (Jose Ignacio Tornos Martinez) [RHEL-231685] {CVE-2026-64117}
- wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled (Jose Ignacio Tornos Martinez) [RHEL-230977] {CVE-2026-64037}
- wifi: nl80211: reject oversized EMA RNR lists (Jose Ignacio Tornos Martinez) [RHEL-230604] {CVE-2026-53182}
- net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (Jose Ignacio Tornos Martinez) [RHEL-229725] {CVE-2026-52947}
- wifi: mac80211: fix multi-link element inheritance (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- wifi: mac80211: fix MLE defragmentation (Jose Ignacio Tornos Martinez) [RHEL-227617] {CVE-2026-64515}
- Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (CKI Backport Bot) [RHEL-232673] {CVE-2026-53072}
- accel/qaic: Add overflow check to remap_pfn_range during mmap (CKI Backport Bot) [RHEL-232178] {CVE-2026-64051}
- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (CKI Backport Bot) [RHEL-231067] {CVE-2026-63947}
- Bluetooth: virtio_bt: validate rx pkt_type header length (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: virtio_bt: clamp rx length before skb_put (CKI Backport Bot) [RHEL-230949] {CVE-2026-46123}
- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (CKI Backport Bot) [RHEL-230076] {CVE-2026-53209}
- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (CKI Backport Bot) [RHEL-230013] {CVE-2026-63944}
- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (CKI Backport Bot) [RHEL-228750] {CVE-2026-63975}
- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- Bluetooth: ISO: fix UAF in iso_recv_frame (CKI Backport Bot) [RHEL-227911] {CVE-2026-63946}
- ixgbevf: fix use-after-free in VEPA multicast source pruning (CKI Backport Bot) [RHEL-227889] {CVE-2026-64113}
- Bluetooth: SMP: force responder MITM requirements before building the pairing response (CKI Backport Bot) [RHEL-227532] {CVE-2026-43334}
- vfio/pci: Check BAR resources before exporting a DMABUF (CKI Backport Bot) [RHEL-227133] {CVE-2026-64042}
- security/keys: fix missed RCU read section on lookup (CKI Backport Bot) [RHEL-225690] {CVE-2026-64015}
- Bluetooth: RFCOMM: validate skb length in MCC handlers (CKI Backport Bot) [RHEL-225653] {CVE-2026-53254}
- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (CKI Backport Bot) [RHEL-225574] {CVE-2026-53256}
- Bluetooth: serialize accept_q access (CKI Backport Bot) [RHEL-225552] {CVE-2026-52918}
- xfrm: Don't clobber inner headers when already set (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: pull headers in qdisc_pkt_len_segs_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: qdisc_pkt_len_segs_init() cleanup (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: initialize qdisc_skb_cb(skb)-&amp;gt;pkt_segs in qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: init shinfo-&amp;gt;gso_segs from qdisc_pkt_len_init() (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net_sched: make room for (struct qdisc_skb_cb)-&amp;gt;pkt_segs (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- net: account for encap headers in qdisc pkt len (Ivan Vecera) [RHEL-188232] {CVE-2026-53091}
- vfio/pci: Clean up DMABUFs before disabling function (CKI Backport Bot) [RHEL-189549] {CVE-2026-53322}
- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (CKI Backport Bot) [RHEL-189468] {CVE-2026-43133}

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>osbuild-composer-worker-165.1-5.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 04:36:15 PM GMT</pubDate>
      <guid isPermaLink="false">e003b9d79afbbd7ac8c0163aa2e4673c601c3cb256b2965c48993270745f48c0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/o/osbuild-composer-worker-165.1-5.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>osbuild-composer-worker</strong> - The worker for osbuild-composer&lt;br /&gt;</p>

<p>The worker for osbuild-composer</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 165.1-5.rocky.0.1
- Add support for Rocky Linux

Wed, 09 Sep 2026 GMT - sraymaek &amp;lt;sraymaek@redhat.com&amp;gt; - 165.1-5
- go.mod: bump indirect golang.org/x/net dependency to v0.56.0
  Resolves: RHEL-191094, RHEL-191545, RHEL-223447
- go.mod: update github.com/labstack/echo/v4 to v4.15.3
  Resolves: RHEL-213913
- go.mod: update go.opentelemetry.io/otel to v1.44.0
  Resolves: RHEL-239489

Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 165.1-3.2
- Rebuild for updated golang

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>osbuild-composer-core-165.1-5.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 04:36:15 PM GMT</pubDate>
      <guid isPermaLink="false">3ba0ad5789e9c73da0c823af79e9e69b6d22f9566c10f007252977d50890a34a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/o/osbuild-composer-core-165.1-5.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>osbuild-composer-core</strong> - The core osbuild-composer binary&lt;br /&gt;</p>

<p>The core osbuild-composer binary. This is suitable both for spawning in containers and by systemd.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 165.1-5.rocky.0.1
- Add support for Rocky Linux

Wed, 09 Sep 2026 GMT - sraymaek &amp;lt;sraymaek@redhat.com&amp;gt; - 165.1-5
- go.mod: bump indirect golang.org/x/net dependency to v0.56.0
  Resolves: RHEL-191094, RHEL-191545, RHEL-223447
- go.mod: update github.com/labstack/echo/v4 to v4.15.3
  Resolves: RHEL-213913
- go.mod: update go.opentelemetry.io/otel to v1.44.0
  Resolves: RHEL-239489

Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 165.1-3.2
- Rebuild for updated golang

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>osbuild-composer-165.1-5.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 04:36:15 PM GMT</pubDate>
      <guid isPermaLink="false">6a02a999d5840e2052bf2103087aa9e1f418dc83f6e7d4644887f786c24419f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/o/osbuild-composer-165.1-5.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>osbuild-composer</strong> - An image building service based on osbuild&lt;br /&gt;</p>

<p>&lt;br /&gt;
A service for building customized OS artifacts, such as VM images and OSTree&lt;br /&gt;
commits, that uses osbuild under the hood. Besides building images for local&lt;br /&gt;
usage, it can also upload images directly to cloud.&lt;br /&gt;
&lt;br /&gt;
It is compatible with composer-cli and cockpit-composer clients.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 165.1-5.rocky.0.1
- Add support for Rocky Linux

Wed, 09 Sep 2026 GMT - sraymaek &amp;lt;sraymaek@redhat.com&amp;gt; - 165.1-5
- go.mod: bump indirect golang.org/x/net dependency to v0.56.0
  Resolves: RHEL-191094, RHEL-191545, RHEL-223447
- go.mod: update github.com/labstack/echo/v4 to v4.15.3
  Resolves: RHEL-213913
- go.mod: update go.opentelemetry.io/otel to v1.44.0
  Resolves: RHEL-239489

Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 165.1-3.2
- Rebuild for updated golang

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>scap-security-guide-doc-0.1.82-2.el10_2.rocky.1.1.noarch</title>
      <pubDate>Thu, 10 Sep 2026 04:28:59 PM GMT</pubDate>
      <guid isPermaLink="false">dfc37e634e4742f4787c9d72a82e7afed3135934752e486cfb4dadd218ae4bb7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/scap-security-guide-doc-0.1.82-2.el10_2.rocky.1.1.noarch.rpm</link>
      <description><p><strong>scap-security-guide-doc</strong> - HTML formatted security guides generated from XCCDF benchmarks&lt;br /&gt;</p>

<p>The scap-security-guide-doc package contains HTML formatted documents containing&lt;br /&gt;
hardening guidances that have been generated from XCCDF benchmarks&lt;br /&gt;
present in scap-security-guide package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 0.1.82-2.rocky.1.1
- Add Rocky Linux as derivative of RHEL

Tue, 08 Sep 2026 GMT - Jan Černý &amp;lt;jcerny@redhat.com&amp;gt; - 0.1.82-2
- Resolve dropped changelog entry

Tue, 01 Sep 2026 GMT - Jan Černý &amp;lt;jcerny@redhat.com&amp;gt; - 0.1.82-1
- Rebase scap-security-guide to 0.1.82 in RHEL 10.2.z (RHEL-242530)
- Explicitly set file owner and permissions when creating new files or directories (RHEL-182657)
- Add a rationale text for rule package_sssd_installed (RHEL-178437)
- Align RHEL 10 STIG profile with official RHEL 10 DISA STIG V1R2 (RHEL-164451)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>scap-security-guide-0.1.82-2.el10_2.rocky.1.1.noarch</title>
      <pubDate>Thu, 10 Sep 2026 04:28:59 PM GMT</pubDate>
      <guid isPermaLink="false">84975731baf34495f3f466e9ebb8c4be6315e7810e3bbc75f01b42761261a473</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/scap-security-guide-0.1.82-2.el10_2.rocky.1.1.noarch.rpm</link>
      <description><p><strong>scap-security-guide</strong> - Security guidance and baselines in SCAP formats&lt;br /&gt;</p>

<p>The scap-security-guide project provides a guide for configuration of the&lt;br /&gt;
system from the final system's security point of view. The guidance is specified&lt;br /&gt;
in the Security Content Automation Protocol (SCAP) format and constitutes&lt;br /&gt;
a catalog of practical hardening advice, linked to government requirements&lt;br /&gt;
where applicable. The project bridges the gap between generalized policy&lt;br /&gt;
requirements and specific implementation guidelines. The system&lt;br /&gt;
administrator can use the oscap CLI tool from openscap-scanner package, or the&lt;br /&gt;
scap-workbench GUI tool from scap-workbench package to verify that the system&lt;br /&gt;
conforms to provided guideline. Refer to scap-security-guide(8) manual page for&lt;br /&gt;
further information.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 10 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 0.1.82-2.rocky.1.1
- Add Rocky Linux as derivative of RHEL

Tue, 08 Sep 2026 GMT - Jan Černý &amp;lt;jcerny@redhat.com&amp;gt; - 0.1.82-2
- Resolve dropped changelog entry

Tue, 01 Sep 2026 GMT - Jan Černý &amp;lt;jcerny@redhat.com&amp;gt; - 0.1.82-1
- Rebase scap-security-guide to 0.1.82 in RHEL 10.2.z (RHEL-242530)
- Explicitly set file owner and permissions when creating new files or directories (RHEL-182657)
- Add a rationale text for rule package_sssd_installed (RHEL-178437)
- Align RHEL 10 STIG profile with official RHEL 10 DISA STIG V1R2 (RHEL-164451)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libwinpr-2:3.10.3-12.el10_2.11.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:52 PM GMT</pubDate>
      <guid isPermaLink="false">522245e5957f331d328c465fc557d11397a4c6a2e65ccaf98192eb43ff901009</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libwinpr-3.10.3-12.el10_2.11.aarch64.rpm</link>
      <description><p><strong>libwinpr</strong> - Windows Portable Runtime&lt;br /&gt;</p>

<p>WinPR provides API compatibility for applications targeting non-Windows&lt;br /&gt;
environments. When on Windows, the original native API is being used instead of&lt;br /&gt;
the equivalent WinPR implementation, without having to modify the code using it.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:3.10.3-12.11
- Fix RPC gateway fragment size and capacity checks (CVE-2026-55193)
  Resolves: RHEL-247346

Tue, 25 Aug 2026 GMT - Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.10
- Backport several CVE fixes (CVE-2026-55194, CVE-2026-63633, CVE-2026-63652,
  CVE-2026-67288, CVE-2026-67291, CVE-2026-67296, CVE-2026-67297,
  CVE-2026-67301, CVE-2026-67304, CVE-2026-69159, CVE-2026-73241)
  Resolves: RHEL-245652, RHEL-245635, RHEL-245599, RHEL-245539, RHEL-238534
  Resolves: RHEL-236056, RHEL-227734, RHEL-225225, RHEL-225097, RHEL-224250
  Resolves: RHEL-224185

Mon, 17 Aug 2026 GMT - RHEL Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.9
- Backport several CVE fixes (CVE-2026-67298, CVE-2026-73242)
  Resolves: RHEL-224050, RHEL-238931

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>freerdp-libs-2:3.10.3-12.el10_2.11.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:52 PM GMT</pubDate>
      <guid isPermaLink="false">f55438475f566f3477d464d9bb557e7b3983b6b623d08d88cd9387353d86d3ad</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/f/freerdp-libs-3.10.3-12.el10_2.11.aarch64.rpm</link>
      <description><p><strong>freerdp-libs</strong> - Core libraries implementing the RDP protocol&lt;br /&gt;</p>

<p>libfreerdp-core can be embedded in applications.&lt;br /&gt;
&lt;br /&gt;
libfreerdp-channels and libfreerdp-kbd might be convenient to use in X&lt;br /&gt;
applications together with libfreerdp-core.&lt;br /&gt;
&lt;br /&gt;
libfreerdp-core can be extended with plugins handling RDP channels.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:3.10.3-12.11
- Fix RPC gateway fragment size and capacity checks (CVE-2026-55193)
  Resolves: RHEL-247346

Tue, 25 Aug 2026 GMT - Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.10
- Backport several CVE fixes (CVE-2026-55194, CVE-2026-63633, CVE-2026-63652,
  CVE-2026-67288, CVE-2026-67291, CVE-2026-67296, CVE-2026-67297,
  CVE-2026-67301, CVE-2026-67304, CVE-2026-69159, CVE-2026-73241)
  Resolves: RHEL-245652, RHEL-245635, RHEL-245599, RHEL-245539, RHEL-238534
  Resolves: RHEL-236056, RHEL-227734, RHEL-225225, RHEL-225097, RHEL-224250
  Resolves: RHEL-224185

Mon, 17 Aug 2026 GMT - RHEL Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.9
- Backport several CVE fixes (CVE-2026-67298, CVE-2026-73242)
  Resolves: RHEL-224050, RHEL-238931

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>freerdp-2:3.10.3-12.el10_2.11.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:52 PM GMT</pubDate>
      <guid isPermaLink="false">288a40dce0d1b13a5c82685f5345e222d6210ecf298e0dda9e743c514c807f6f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/f/freerdp-3.10.3-12.el10_2.11.aarch64.rpm</link>
      <description><p><strong>freerdp</strong> - Free implementation of the Remote Desktop Protocol (RDP)&lt;br /&gt;</p>

<p>The xfreerdp &amp; wlfreerdp Remote Desktop Protocol (RDP) clients from the FreeRDP&lt;br /&gt;
project.&lt;br /&gt;
&lt;br /&gt;
xfreerdp &amp; wlfreerdp can connect to RDP servers such as Microsoft Windows&lt;br /&gt;
machines, xrdp and VirtualBox.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:3.10.3-12.11
- Fix RPC gateway fragment size and capacity checks (CVE-2026-55193)
  Resolves: RHEL-247346

Tue, 25 Aug 2026 GMT - Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.10
- Backport several CVE fixes (CVE-2026-55194, CVE-2026-63633, CVE-2026-63652,
  CVE-2026-67288, CVE-2026-67291, CVE-2026-67296, CVE-2026-67297,
  CVE-2026-67301, CVE-2026-67304, CVE-2026-69159, CVE-2026-73241)
  Resolves: RHEL-245652, RHEL-245635, RHEL-245599, RHEL-245539, RHEL-238534
  Resolves: RHEL-236056, RHEL-227734, RHEL-225225, RHEL-225097, RHEL-224250
  Resolves: RHEL-224185

Mon, 17 Aug 2026 GMT - RHEL Ondrej Holy &amp;lt;oholy@redhat.com&amp;gt; - 2:3.10.3-12.9
- Backport several CVE fixes (CVE-2026-67298, CVE-2026-73242)
  Resolves: RHEL-224050, RHEL-238931

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-sqlite-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">5e1bb98477ac4b1c27dbf02b536e16d1daab240e7712dcf62b87fac5d0c63f81</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-sqlite-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-sqlite</strong> - APR utility library SQLite DBD driver&lt;br /&gt;</p>

<p>This package provides the SQLite driver for the apr-util DBD&lt;br /&gt;
(database abstraction) interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-pgsql-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">215c37c3d15aaa371f5999ccbd11d62d2ee2449e9d3277779aab87af721ec65d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-pgsql-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-pgsql</strong> - APR utility library PostgreSQL DBD driver&lt;br /&gt;</p>

<p>This package provides the PostgreSQL driver for the apr-util&lt;br /&gt;
DBD (database abstraction) interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-openssl-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">5360d8fd466746494746edb0161d65faeabb6a630681f953b231f9d22b09dc82</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-openssl-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-openssl</strong> - APR utility library OpenSSL crypto support&lt;br /&gt;</p>

<p>This package provides the OpenSSL crypto support for the apr-util.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-odbc-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">9c3e56861fc9cd4bdf4bc9e58d4cccf4929ecbc37dd3a870a7a431c6ee4d1c3b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-odbc-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-odbc</strong> - APR utility library ODBC DBD driver&lt;br /&gt;</p>

<p>This package provides the ODBC driver for the apr-util DBD&lt;br /&gt;
(database abstraction) interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-mysql-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">4d6e1ea808091732f1a3cba45c975def7cea2240ed2189dba7822e2da55b537d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-mysql-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-mysql</strong> - APR utility library MySQL DBD driver&lt;br /&gt;</p>

<p>This package provides the MySQL driver for the apr-util DBD&lt;br /&gt;
(database abstraction) interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-lmdb-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">4db17a314fa6c73a39c109386a99cd2963edee36068098a7d103ddf9902feaf3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-lmdb-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-lmdb</strong> - APR utility library LMDB driver&lt;br /&gt;</p>

<p>This package provides the LMDB driver for the apr-util&lt;br /&gt;
DBM (database abstraction) interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-ldap-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">bf0e2fb9d0624b316e2f8c671a6b175b13efcdd0f21aaca197d14887c489ca2e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-ldap-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-ldap</strong> - APR utility library LDAP support&lt;br /&gt;</p>

<p>This package provides the LDAP support for the apr-util.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-devel-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">bdd6ec068c579fd28c2eb75d14646fdeca8661bceafb9d0d22031577bb975304</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-devel-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util-devel</strong> - APR utility library development kit&lt;br /&gt;</p>

<p>This package provides the support files which can be used to&lt;br /&gt;
build applications using the APR utility library.  The mission&lt;br /&gt;
of the Apache Portable Runtime (APR) is to provide a free&lt;br /&gt;
library of C data structures and routines.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>apr-util-1.6.3-23.el10_2.1.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 03:07:12 PM GMT</pubDate>
      <guid isPermaLink="false">6ea208316f95a37383d44271ab67f4a5c0e2fd1ef2eb0edc45b44efc1ed9f032</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/apr-util-1.6.3-23.el10_2.1.aarch64.rpm</link>
      <description><p><strong>apr-util</strong> - Apache Portable Runtime Utility library&lt;br /&gt;</p>

<p>The mission of the Apache Portable Runtime (APR) is to provide a&lt;br /&gt;
free library of C data structures and routines.  This library&lt;br /&gt;
contains additional utility interfaces for APR; including support&lt;br /&gt;
for XML, LDAP, database interfaces, URI parsing and more.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23.1
- Resolves: RHEL-236629 - apr-util: Apache Portable Runtime Utility: Information
  disclosure via timing attack in password validation (CVE-2025-49506)
- Resolves: RHEL-236264 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in APR memcached client (CVE-2026-34502)
- Resolves: RHEL-236469 - apr-util: Apache Portable Runtime Utility: Heap buffer
  overflow in redis client (CVE-2026-34501)
- Resolves: RHEL-235667 - apr-util: APR-util: Denial of Service via XML stack
  recursion attack (CVE-2026-32327)

Fri, 05 Dec 2025 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 1.6.3-23
- Resolves: RHEL-117419 - apr-util lmdb prevent htdbm to remove user

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1.6.3-21
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>xxd-2:9.1.083-9.el10_2.20.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 09:16:28 AM GMT</pubDate>
      <guid isPermaLink="false">0292d03bce51a878b23d3ea927437d6d210bcd9e925cda1518043919ac2f5026</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/x/xxd-9.1.083-9.el10_2.20.aarch64.rpm</link>
      <description><p><strong>xxd</strong> - A hex dump utility&lt;br /&gt;</p>

<p>xxd creates a hex dump of a given file or standard input.  It can also convert&lt;br /&gt;
a hex dump back to its original binary form.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 04 Sep 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 2:9.1.083-9.20
- RHEL-253668 CVE-2026-28420 buffer overflow in terminal emulator

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.19
- RHEL-215660 CVE-2026-55892 vim: stack out-of-bounds write in
  dump_prefixes()

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.18
- RHEL-215683 CVE-2026-59857 vim: stack out-of-bounds write in
  spell_soundfold_sal()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>vim-enhanced-2:9.1.083-9.el10_2.20.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 09:16:28 AM GMT</pubDate>
      <guid isPermaLink="false">eb4d8bb16b49c0ef8c97be05acc4f8e63d4aafea084422b62338500d2f902dbc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/v/vim-enhanced-9.1.083-9.el10_2.20.aarch64.rpm</link>
      <description><p><strong>vim-enhanced</strong> - A version of the VIM editor which includes recent enhancements&lt;br /&gt;</p>

<p>VIM (VIsual editor iMproved) is an updated and improved version of the&lt;br /&gt;
vi editor.  Vi was the first real screen-based editor for UNIX, and is&lt;br /&gt;
still very popular.  VIM improves on vi by adding new features:&lt;br /&gt;
multiple windows, multi-level undo, block highlighting and more.  The&lt;br /&gt;
vim-enhanced package contains a version of VIM with extra, recently&lt;br /&gt;
introduced features like Python and Perl interpreters.&lt;br /&gt;
&lt;br /&gt;
Install the vim-enhanced package if you'd like to use a version of the&lt;br /&gt;
VIM editor which includes recently added enhancements like&lt;br /&gt;
interpreters for the Python and Perl scripting languages.  You'll also&lt;br /&gt;
need to install the vim-common package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 04 Sep 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 2:9.1.083-9.20
- RHEL-253668 CVE-2026-28420 buffer overflow in terminal emulator

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.19
- RHEL-215660 CVE-2026-55892 vim: stack out-of-bounds write in
  dump_prefixes()

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.18
- RHEL-215683 CVE-2026-59857 vim: stack out-of-bounds write in
  spell_soundfold_sal()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>vim-common-2:9.1.083-9.el10_2.20.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 09:16:28 AM GMT</pubDate>
      <guid isPermaLink="false">74d365bca4eb8c55d92efce738893044c35fa6d2f2109f93601796cda3b3341a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/v/vim-common-9.1.083-9.el10_2.20.aarch64.rpm</link>
      <description><p><strong>vim-common</strong> - The common files needed by any version of the VIM editor&lt;br /&gt;</p>

<p>VIM (VIsual editor iMproved) is an updated and improved version of the&lt;br /&gt;
vi editor.  Vi was the first real screen-based editor for UNIX, and is&lt;br /&gt;
still very popular.  VIM improves on vi by adding new features:&lt;br /&gt;
multiple windows, multi-level undo, block highlighting and more.  The&lt;br /&gt;
vim-common package contains files which every VIM binary will need in&lt;br /&gt;
order to run.&lt;br /&gt;
&lt;br /&gt;
If you are installing vim-enhanced or vim-X11, you'll also need&lt;br /&gt;
to install the vim-common package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 04 Sep 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 2:9.1.083-9.20
- RHEL-253668 CVE-2026-28420 buffer overflow in terminal emulator

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.19
- RHEL-215660 CVE-2026-55892 vim: stack out-of-bounds write in
  dump_prefixes()

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.18
- RHEL-215683 CVE-2026-59857 vim: stack out-of-bounds write in
  spell_soundfold_sal()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>vim-X11-2:9.1.083-9.el10_2.20.aarch64</title>
      <pubDate>Thu, 10 Sep 2026 09:16:28 AM GMT</pubDate>
      <guid isPermaLink="false">dcdc456976f7445a4616b69fab868de441e4143c32cab5e59c1dd25f42e3a06e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/v/vim-X11-9.1.083-9.el10_2.20.aarch64.rpm</link>
      <description><p><strong>vim-X11</strong> - The VIM version of the vi editor for the X Window System - GVim&lt;br /&gt;</p>

<p>VIM (VIsual editor iMproved) is an updated and improved version of the&lt;br /&gt;
vi editor.  Vi was the first real screen-based editor for UNIX, and is&lt;br /&gt;
still very popular.  VIM improves on vi by adding new features:&lt;br /&gt;
multiple windows, multi-level undo, block highlighting and&lt;br /&gt;
more. VIM-X11 is a version of the VIM editor which will run within the&lt;br /&gt;
X Window System.  If you install this package, you can run VIM as an X&lt;br /&gt;
application with a full GUI interface and mouse support by command gvim.&lt;br /&gt;
&lt;br /&gt;
Install the vim-X11 package if you'd like to try out a version of vi&lt;br /&gt;
with graphics and mouse capabilities.  You'll also need to install the&lt;br /&gt;
vim-common package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 04 Sep 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 2:9.1.083-9.20
- RHEL-253668 CVE-2026-28420 buffer overflow in terminal emulator

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.19
- RHEL-215660 CVE-2026-55892 vim: stack out-of-bounds write in
  dump_prefixes()

Fri, 04 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2:9.1.083-9.18
- RHEL-215683 CVE-2026-59857 vim: stack out-of-bounds write in
  spell_soundfold_sal()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-DBI-1.643-26.el10_2.4.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:46:41 PM GMT</pubDate>
      <guid isPermaLink="false">0958f5772d1d1c3839451d65a23179ece056adfb2db56faeb8512c21972c3dfc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-DBI-1.643-26.el10_2.4.aarch64.rpm</link>
      <description><p><strong>perl-DBI</strong> - A database access API for perl&lt;br /&gt;</p>

<p>DBI is a database access Application Programming Interface (API) for&lt;br /&gt;
the Perl Language. The DBI API Specification defines a set of&lt;br /&gt;
functions, variables and conventions that provide a consistent&lt;br /&gt;
database interface independent of the actual database being used.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 12 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.643-26.4
- Fix CVE-2026-19546: incomplete fix for CVE-2026-14380 in
  DBI::Profile
  Resolves: RHEL-236830

Thu, 16 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.643-26.3
- Fix CVE-2026-14380: unsafe string eval in DBI::Profile
- Resolves: RHEL-211146

Fri, 10 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.643-26.2
- Fix CVE-2026-14739: set a hard limit of 99999 on '?' placeholders
- Resolves: RHEL-193293

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>postgis-utils-3.5.3-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:43:23 PM GMT</pubDate>
      <guid isPermaLink="false">84e9d4ced0452a972df4b96bbf83efc4342c967850e826cf5312b1166cb9f9bc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/postgis-utils-3.5.3-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>postgis-utils</strong> - The utils for PostGIS&lt;br /&gt;</p>

<p>The postgis-utils package provides the utilities for PostGIS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 16 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.5.3-4.1
- Fix CVE-2026-73515: validate flatgeobuf input buffers before decoding

Wed, 22 Oct 2025 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 3.5.3-4
- Avoid perl(Pg) dependency on RHEL, adapted from
  the Fedora spec change from yselkowi@redhat.com

Tue, 29 Jul 2025 GMT - Sandro Mani &amp;lt;manisandro@gmail.com&amp;gt; - 3.5.3-3
- Rebuild (gdal)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>postgis-upgrade-3.5.3-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:43:23 PM GMT</pubDate>
      <guid isPermaLink="false">64d2f677dbe7d62026829567b3ab3f929df2c4340a5feb1c1866d3b8f9fd3499</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/postgis-upgrade-3.5.3-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>postgis-upgrade</strong> - Support for upgrading Postgis&lt;br /&gt;</p>

<p>&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The postgis-upgrade package contains the current version of Postgis built&lt;br /&gt;
against the previous version of PostgreSQL necessary for correct dump of schema&lt;br /&gt;
from the previous version of PostgreSQL.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 16 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.5.3-4.1
- Fix CVE-2026-73515: validate flatgeobuf input buffers before decoding

Wed, 22 Oct 2025 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 3.5.3-4
- Avoid perl(Pg) dependency on RHEL, adapted from
  the Fedora spec change from yselkowi@redhat.com

Tue, 29 Jul 2025 GMT - Sandro Mani &amp;lt;manisandro@gmail.com&amp;gt; - 3.5.3-3
- Rebuild (gdal)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>postgis-docs-3.5.3-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:43:23 PM GMT</pubDate>
      <guid isPermaLink="false">ae7eef7a22efc258c828f14748221e8abe3af11806e60709fc52c6bde5ff717b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/postgis-docs-3.5.3-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>postgis-docs</strong> - Extra documentation for PostGIS&lt;br /&gt;</p>

<p>The postgis-docs package includes PDF documentation of PostGIS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 16 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.5.3-4.1
- Fix CVE-2026-73515: validate flatgeobuf input buffers before decoding

Wed, 22 Oct 2025 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 3.5.3-4
- Avoid perl(Pg) dependency on RHEL, adapted from
  the Fedora spec change from yselkowi@redhat.com

Tue, 29 Jul 2025 GMT - Sandro Mani &amp;lt;manisandro@gmail.com&amp;gt; - 3.5.3-3
- Rebuild (gdal)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>postgis-client-3.5.3-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:43:23 PM GMT</pubDate>
      <guid isPermaLink="false">fcd5d4d6fe02af469c6e7a2ebfafc6173bc711635ff75f8f75cc24403eebd97b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/postgis-client-3.5.3-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>postgis-client</strong> - The CLI clients for PostGIS&lt;br /&gt;</p>

<p>The client package provides shp2pgsql, raster2pgsql and pgsql2shp for PostGIS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 16 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.5.3-4.1
- Fix CVE-2026-73515: validate flatgeobuf input buffers before decoding

Wed, 22 Oct 2025 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 3.5.3-4
- Avoid perl(Pg) dependency on RHEL, adapted from
  the Fedora spec change from yselkowi@redhat.com

Tue, 29 Jul 2025 GMT - Sandro Mani &amp;lt;manisandro@gmail.com&amp;gt; - 3.5.3-3
- Rebuild (gdal)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>postgis-3.5.3-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 01:43:23 PM GMT</pubDate>
      <guid isPermaLink="false">9fcdee40c9e09bb59369f0d48bb3f823c0c8ce3ff8de34b11c4d646a25c99fbc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/postgis-3.5.3-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>postgis</strong> - Geographic Information Systems Extensions to PostgreSQL&lt;br /&gt;</p>

<p>PostGIS adds support for geographic objects to the PostgreSQL object-relational&lt;br /&gt;
database. In effect, PostGIS "spatially enables" the PostgreSQL server,&lt;br /&gt;
allowing it to be used as a backend spatial database for geographic information&lt;br /&gt;
systems (GIS), much like ESRI's SDE or Oracle's Spatial extension. PostGIS&lt;br /&gt;
follows the OpenGIS "Simple Features Specification for SQL" and has been&lt;br /&gt;
certified as compliant with the "Types and Functions" profile.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 16 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.5.3-4.1
- Fix CVE-2026-73515: validate flatgeobuf input buffers before decoding

Wed, 22 Oct 2025 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 3.5.3-4
- Avoid perl(Pg) dependency on RHEL, adapted from
  the Fedora spec change from yselkowi@redhat.com

Tue, 29 Jul 2025 GMT - Sandro Mani &amp;lt;manisandro@gmail.com&amp;gt; - 3.5.3-3
- Rebuild (gdal)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qt6-qt5compat-devel-6.10.1-1.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 11:12:43 AM GMT</pubDate>
      <guid isPermaLink="false">26691fb928edb4e6f0ff53efd0dcc9185451eb2264805037d854932dca578358</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qt6-qt5compat-devel-6.10.1-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>qt6-qt5compat-devel</strong> - Development files for qt6-qt5compat&lt;br /&gt;</p>

<p>Development files for qt6-qt5compat.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 6.10.1-1.1
- Fix out-of-bounds read in QTextCodec::codecForName() (CVE-2026-9499)
  Resolves: RHEL-247204

Mon, 24 Nov 2025 GMT - Jan Grulich &amp;lt;jgrulich@redhat.com&amp;gt; - 6.10.1-1
- 6.10.1
  Resolves: RHEL-109197

Fri, 06 Jun 2025 GMT - Jan Grulich &amp;lt;jgrulich@redhat.com&amp;gt; - 6.9.1-2
- Rebuild (broken buildroot)
  Resolves: RHEL-78530

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qt6-qt5compat-6.10.1-1.el10_2.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 11:12:43 AM GMT</pubDate>
      <guid isPermaLink="false">cc7370cd9b0199207768e509822f3ca345ca1a8efc39e38bb86a466e2b1e1fee</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qt6-qt5compat-6.10.1-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>qt6-qt5compat</strong> - Qt6 - Qt 5 Compatibility Libraries&lt;br /&gt;</p>

<p>Qt6 - Qt 5 Compatibility Libraries.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 6.10.1-1.1
- Fix out-of-bounds read in QTextCodec::codecForName() (CVE-2026-9499)
  Resolves: RHEL-247204

Mon, 24 Nov 2025 GMT - Jan Grulich &amp;lt;jgrulich@redhat.com&amp;gt; - 6.10.1-1
- 6.10.1
  Resolves: RHEL-109197

Fri, 06 Jun 2025 GMT - Jan Grulich &amp;lt;jgrulich@redhat.com&amp;gt; - 6.9.1-2
- Rebuild (broken buildroot)
  Resolves: RHEL-78530

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>image-builder-52.1-1.el10_2.2.rocky.0.1.aarch64</title>
      <pubDate>Wed, 09 Sep 2026 11:11:32 AM GMT</pubDate>
      <guid isPermaLink="false">693dc14920e6e1c13c1642f85beea0daad092f0c583c2e5fd33e8c477f5a03c6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/image-builder-52.1-1.el10_2.2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>image-builder</strong> - An image building executable using osbuild&lt;br /&gt;</p>

<p>&lt;br /&gt;
A local binary for building customized OS artifacts such as VM images and&lt;br /&gt;
OSTree commits. Uses osbuild under the hood.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 09 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 52.1-1.2.rocky.0.1
- Disable riscv64 tests

Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 52.1-1.2
- Rebuild for updated golang

Wed, 08 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 52.1-1.1
- Rebuild for updated golang
- Resolves: RHEL-175286, RHEL-187127, RHEL-177125

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>thunderbird-140.14.0-1.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 01:50:58 PM GMT</pubDate>
      <guid isPermaLink="false">33fe875d575ea83317d5262d81a12f19c4b6902b258f0b40e744d0ba795f59a6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/t/thunderbird-140.14.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>thunderbird</strong> - Mozilla Thunderbird mail/newsgroup client&lt;br /&gt;</p>

<p>Mozilla Thunderbird is a standalone mail and newsgroup client.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 08 Sep 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 140.14.0-1
- Add custom Rocky Linux Thunderbird prefs (Louis Abel)
- Ensure s390x and riscv64 are locked to 3 CPU's (Louis Abel)

Tue, 18 Aug 2026 GMT - Jan Horak &amp;lt;jhorak@redhat.com&amp;gt; - 140.14.0-1
- Update to 140.14.0 ESR

Wed, 22 Jul 2026 GMT - Jan Horak &amp;lt;jhorak@redhat.com&amp;gt; - 140.13.0-1
- Update to 140.13.0 ESR

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3.14-cryptography-45.0.4-4.el10_2.5.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 12:16:57 PM GMT</pubDate>
      <guid isPermaLink="false">9e8874c0ce4b6ab9bbf4fdf399576be485e63e9ecf07f152753e4964f76f2708</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3.14-cryptography-45.0.4-4.el10_2.5.aarch64.rpm</link>
      <description><p><strong>python3.14-cryptography</strong> - PyCA's cryptography library&lt;br /&gt;</p>

<p>cryptography is a package designed to expose cryptographic primitives and&lt;br /&gt;
recipes to Python developers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 45.0.4-5
- Security fixes for CVE-2026-69248 and CVE-2026-69249

Fri, 28 Nov 2025 GMT - Lumir Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 45.0.4-4
- Reuploaded sources

Fri, 28 Nov 2025 GMT - Lukáš Zachar &amp;lt;lzachar@redhat.com&amp;gt; - 45.0.4-3
- Add gating

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-gpsd-1:3.26.1-3.el10_2.2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 11:21:41 AM GMT</pubDate>
      <guid isPermaLink="false">d4bed7f2799fb85ae995af7a96667fb1feb2928258aeda59fbf1e1c4e99d3187</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-gpsd-3.26.1-3.el10_2.2.aarch64.rpm</link>
      <description><p><strong>python3-gpsd</strong> - Python libraries and modules for use with gpsd&lt;br /&gt;</p>

<p>This package contains the python3 modules that manage access to a GPS for&lt;br /&gt;
applications.&lt;br /&gt;
&lt;br /&gt;
The Red Hat support for this package is limited. See&lt;br /&gt;
https://access.redhat.com/support/policy/gpsd-support for more details.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 26 Aug 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.2
- fix another command injection in gpsprof (CVE-2026-60122)

Mon, 13 Jul 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.1
- fix command injection in gpsprof (CVE-2026-58459)

Mon, 19 Jan 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3
- fix buffer overflow in NMEA2000 driver (CVE-2025-67268)
- fix integer underflow in handling of Navcom packets (CVE-2025-67269)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gpsd-clients-1:3.26.1-3.el10_2.2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 11:21:41 AM GMT</pubDate>
      <guid isPermaLink="false">21f377d5ba06480872bd59eee1a09783d2dc56ef565c313a3c16c79e9dbf1cfc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gpsd-clients-3.26.1-3.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gpsd-clients</strong> - Clients for gpsd&lt;br /&gt;</p>

<p>This package contains various clients using gpsd.&lt;br /&gt;
&lt;br /&gt;
The Red Hat support for this package is limited. See&lt;br /&gt;
https://access.redhat.com/support/policy/gpsd-support for more details.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 26 Aug 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.2
- fix another command injection in gpsprof (CVE-2026-60122)

Mon, 13 Jul 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.1
- fix command injection in gpsprof (CVE-2026-58459)

Mon, 19 Jan 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3
- fix buffer overflow in NMEA2000 driver (CVE-2025-67268)
- fix integer underflow in handling of Navcom packets (CVE-2025-67269)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gpsd-1:3.26.1-3.el10_2.2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 11:21:41 AM GMT</pubDate>
      <guid isPermaLink="false">9eb53ecf72b83fa6225ec387e97ee80165704afbd0b303b8d1e1b3c2cb58e659</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gpsd-3.26.1-3.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gpsd</strong> - Service daemon for mediating access to a GPS&lt;br /&gt;</p>

<p>gpsd is a service daemon that mediates access to a GPS sensor&lt;br /&gt;
connected to the host computer by serial or USB interface, making its&lt;br /&gt;
data on the location/course/velocity of the sensor available to be&lt;br /&gt;
queried on TCP port 2947 of the host computer.  With gpsd, multiple&lt;br /&gt;
GPS client applications (such as navigational and war-driving software)&lt;br /&gt;
can share access to a GPS without contention or loss of data.  Also,&lt;br /&gt;
gpsd responds to queries with a format that is substantially easier to&lt;br /&gt;
parse than NMEA 0183.&lt;br /&gt;
&lt;br /&gt;
The Red Hat support for this package is limited. See&lt;br /&gt;
https://access.redhat.com/support/policy/gpsd-support for more details.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 26 Aug 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.2
- fix another command injection in gpsprof (CVE-2026-60122)

Mon, 13 Jul 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3.el10_2.1
- fix command injection in gpsprof (CVE-2026-58459)

Mon, 19 Jan 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; - 1:3.26.1-3
- fix buffer overflow in NMEA2000 driver (CVE-2025-67268)
- fix integer underflow in handling of Navcom packets (CVE-2025-67269)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>opentelemetry-collector-0.152.1-2.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 09:34:25 AM GMT</pubDate>
      <guid isPermaLink="false">a68ff2f4c2b66976010f84599cee65c1ea970b7246a10de7415b318b564a0c21</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/o/opentelemetry-collector-0.152.1-2.el10_2.aarch64.rpm</link>
      <description><p><strong>opentelemetry-collector</strong> - Red Hat build of OpenTelemetry&lt;br /&gt;</p>

<p>&lt;br /&gt;
Collector with the supported components for a Red Hat build of OpenTelemetry</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 03 Sep 2026 GMT - Kseniia Nivnia &amp;lt;knivnia@redhat.com&amp;gt; - 0.152.1-2
- Rebuild with updated golang and otel
- Update addresses CVE-2026-39820, CVE-2026-42499, CVE-2026-42504,
  CVE-2026-56860, CVE-2026-56859, CVE-2026-41178, CVE-2026-56862,
  CVE-2026-56858, CVE-2026-33818, CVE-2026-56853
- Resolves: RHEL-251683, RHEL-251827, RHEL-251152, RHEL-241746,
  RHEL-241986, RHEL-239491, RHEL-241432, RHEL-242138, RHEL-241640,
  RHEL-241125

Wed, 01 Jul 2026 GMT - Kseniia Nivnia &amp;lt;knivnia@redhat.com&amp;gt; - 0.152.1-1
- Update to v0.152.1
- Addresses CVE-2026-39821, CVE-2026-42154, CVE-2026-33811, CVE-2026-42151,
  CVE-2026-27145, CVE-2026-25681

Tue, 28 Apr 2026 GMT - Kseniia Nivnia &amp;lt;knivnia@redhat.com&amp;gt; - 0.144.0-2
- Update to Go v1.26.2, go-jose v4.1.4, go-grcp v1.79.3
- Addresses: CVE-2026-25679, CVE-2026-33186, CVE-2026-34986,
  CVE-2026-32282, CVE-2026-32283, CVE-2026-32280, CVE-2026-33810

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>glib2-tests-2.80.4-12.el10_2.22.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:54:34 AM GMT</pubDate>
      <guid isPermaLink="false">1460838d71a8f519ebe7673b0e59f2c7b7720405a291a3f1d43b38805da8c3e8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/glib2-tests-2.80.4-12.el10_2.22.aarch64.rpm</link>
      <description><p><strong>glib2-tests</strong> - Tests for the glib2 package&lt;br /&gt;</p>

<p>The glib2-tests package contains tests that can be used to verify&lt;br /&gt;
the functionality of the installed glib2 package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-22
- Fix CVE-2026-16118: heap-buffer-overflow in xdgmime byte-swap

Thu, 30 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-21
- Fix CVE-2026-15588: limit D-Bus auth line read length

Thu, 30 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-20
- Fix CVE-2026-58011: range validation in g_date_time_add_full()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>glib2-devel-2.80.4-12.el10_2.22.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:54:34 AM GMT</pubDate>
      <guid isPermaLink="false">5490733ac767ee0fa5f0b0d987b2c354b5e2d87af27910501792609c31a27c43</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/glib2-devel-2.80.4-12.el10_2.22.aarch64.rpm</link>
      <description><p><strong>glib2-devel</strong> - A library of handy utility functions&lt;br /&gt;</p>

<p>The glib2-devel package includes the header files for the GLib library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-22
- Fix CVE-2026-16118: heap-buffer-overflow in xdgmime byte-swap

Thu, 30 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-21
- Fix CVE-2026-15588: limit D-Bus auth line read length

Thu, 30 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.80.4-20
- Fix CVE-2026-58011: range validation in g_date_time_add_full()

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-lib389-3.2.0-10.el10_2.noarch</title>
      <pubDate>Tue, 08 Sep 2026 08:53:04 AM GMT</pubDate>
      <guid isPermaLink="false">8357878df5314a847419b2ab49d9718d46e23a10421d7f68a06d43048d8e5bc8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-lib389-3.2.0-10.el10_2.noarch.rpm</link>
      <description><p><strong>python3-lib389</strong> - A library for accessing, testing, and configuring the 389 Directory Server&lt;br /&gt;</p>

<p>This module contains tools and libraries for accessing, testing,&lt;br /&gt;
 and configuring the 389 Directory Server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-10
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
  via SASL wrapped-record length lower-bound underflow in
  sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
  NULL pointer dereference via paged results and USE_ONE_BACKEND control in
  op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 -  CVE-2026-18922 389-ds-base: SASL PLAIN
  authentication allows privilege escalation to Directory Manager via stale
  identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
  ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
  can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
  incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
  when nsDS5ReplicaBindDNGroup is set after agreement creation
  [rhel-10.2.z]

Wed, 29 Jul 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-9
- Bump version to 3.2.0-9
- Resolves: RHEL-183075 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth
  LDAP filter injection in CleanAllRUV status check [rhel-10.2.z]
- Resolves: RHEL-190776 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL
  pointer dereference in deref control plugin BER parser [rhel-10.2.z]
- Resolves: RHEL-210874 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-
  authentication stack buffer overflow in get_ruvelement_from_berval() via
  unbounded replica ID parsing [rhel-10.2.z]

Fri, 26 Jun 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-8
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
  overflow in SASL packet length bypasses size limit leading to heap buffer
  overflow [rhel-10.2.z]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>git-lfs-3.7.1-5.el10_2.7.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:50:56 AM GMT</pubDate>
      <guid isPermaLink="false">1483a862e2656e21738aaa603c53db0d83443dd45717fac8d44637d92b8e9579</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/git-lfs-3.7.1-5.el10_2.7.aarch64.rpm</link>
      <description><p><strong>git-lfs</strong> - Git extension for versioning large files&lt;br /&gt;</p>

<p>Git Large File Storage (LFS) replaces large files such as audio samples,&lt;br /&gt;
videos, datasets, and graphics with text pointers inside Git, while&lt;br /&gt;
storing the file contents on a remote server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 03 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.7.1-7
- Rebuild with new Golang

Wed, 08 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.7.1-6
- Rebuild with new Golang

Thu, 11 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.7.1-5
- Fix CVE-2026-39821 in vendored golang.org/x/net idna package

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>389-ds-base-snmp-3.2.0-10.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:50:55 AM GMT</pubDate>
      <guid isPermaLink="false">dc03ca61900dd492c3e4d01abdd9e5f2380bfed206c4e01062755640e99ab2d7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/3/389-ds-base-snmp-3.2.0-10.el10_2.aarch64.rpm</link>
      <description><p><strong>389-ds-base-snmp</strong> - SNMP Agent for 389 Directory Server&lt;br /&gt;</p>

<p>SNMP Agent for the 389 Directory Server base package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-10
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
  via SASL wrapped-record length lower-bound underflow in
  sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
  NULL pointer dereference via paged results and USE_ONE_BACKEND control in
  op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 -  CVE-2026-18922 389-ds-base: SASL PLAIN
  authentication allows privilege escalation to Directory Manager via stale
  identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
  ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
  can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
  incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
  when nsDS5ReplicaBindDNGroup is set after agreement creation
  [rhel-10.2.z]

Wed, 29 Jul 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-9
- Bump version to 3.2.0-9
- Resolves: RHEL-183075 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth
  LDAP filter injection in CleanAllRUV status check [rhel-10.2.z]
- Resolves: RHEL-190776 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL
  pointer dereference in deref control plugin BER parser [rhel-10.2.z]
- Resolves: RHEL-210874 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-
  authentication stack buffer overflow in get_ruvelement_from_berval() via
  unbounded replica ID parsing [rhel-10.2.z]

Fri, 26 Jun 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-8
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
  overflow in SASL packet length bypasses size limit leading to heap buffer
  overflow [rhel-10.2.z]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>389-ds-base-libs-3.2.0-10.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:50:55 AM GMT</pubDate>
      <guid isPermaLink="false">ac41e71f345c27dd8626c74c2a4ee5820afd60cba01a60343080db8d15c5a271</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/3/389-ds-base-libs-3.2.0-10.el10_2.aarch64.rpm</link>
      <description><p><strong>389-ds-base-libs</strong> - Core libraries for 389 Directory Server (base)&lt;br /&gt;</p>

<p>Core libraries for the 389 Directory Server base package.  These libraries&lt;br /&gt;
are used by the main package and the -devel package.  This allows the -devel&lt;br /&gt;
package to be installed with just the -libs package and without the main package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-10
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
  via SASL wrapped-record length lower-bound underflow in
  sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
  NULL pointer dereference via paged results and USE_ONE_BACKEND control in
  op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 -  CVE-2026-18922 389-ds-base: SASL PLAIN
  authentication allows privilege escalation to Directory Manager via stale
  identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
  ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
  can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
  incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
  when nsDS5ReplicaBindDNGroup is set after agreement creation
  [rhel-10.2.z]

Wed, 29 Jul 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-9
- Bump version to 3.2.0-9
- Resolves: RHEL-183075 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth
  LDAP filter injection in CleanAllRUV status check [rhel-10.2.z]
- Resolves: RHEL-190776 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL
  pointer dereference in deref control plugin BER parser [rhel-10.2.z]
- Resolves: RHEL-210874 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-
  authentication stack buffer overflow in get_ruvelement_from_berval() via
  unbounded replica ID parsing [rhel-10.2.z]

Fri, 26 Jun 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-8
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
  overflow in SASL packet length bypasses size limit leading to heap buffer
  overflow [rhel-10.2.z]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>389-ds-base-3.2.0-10.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:50:55 AM GMT</pubDate>
      <guid isPermaLink="false">5585d69e5ac403316ce4d52a201101fb0bea82c428e9f88a3576aa76c0295cf0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/3/389-ds-base-3.2.0-10.el10_2.aarch64.rpm</link>
      <description><p><strong>389-ds-base</strong> - 389 Directory Server (base)&lt;br /&gt;</p>

<p>389 Directory Server is an LDAPv3 compliant server.  The base package includes&lt;br /&gt;
the LDAP server and command line utilities for server administration.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-10
- Bump version to 3.2.0-10
- Resolves: RHEL-220500 - CVE-2026-18355 389-ds-base: heap buffer overflow
  via SASL wrapped-record length lower-bound underflow in
  sasl_io_start_packet() [rhel-10.2.z]
- Resolves: RHEL-222320 - CVE-2026-18453 389-ds-base: pre-authentication
  NULL pointer dereference via paged results and USE_ONE_BACKEND control in
  op_shared_search [rhel-10.2.z]
- Resolves: RHEL-232863 -  CVE-2026-18922 389-ds-base: SASL PLAIN
  authentication allows privilege escalation to Directory Manager via stale
  identity in Cyrus SASL auxiliary property [rhel-10.2.z]
- Resolves: RHEL-244470 - lib389: set nsDS5ReplicaBindDNGroup before
  ensure_agreement() [rhel-10.2.z]
- Resolves: RHEL-245372 - CVE-2026-76560 389-ds-base: anonymous LDAP client
  can defeat SELFDN ACI bind-rule checks via empty bind DN [rhel-10.2.z]
- Resolves: RHEL-247859 - CVE-2026-78701 389-ds-base: CVE-2026-11610
  incomplete fix may introduce a connection-stall DoS [rhel-10.2.z]
- Resolves: RHEL-248770 - CVE-2026-11770 fix breaks replication total init
  when nsDS5ReplicaBindDNGroup is set after agreement creation
  [rhel-10.2.z]

Wed, 29 Jul 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-9
- Bump version to 3.2.0-9
- Resolves: RHEL-183075 - CVE-2026-11770 389-ds-base: 389-ds-base: pre-auth
  LDAP filter injection in CleanAllRUV status check [rhel-10.2.z]
- Resolves: RHEL-190776 - CVE-2026-11788 389-ds-base: 389-ds-base: NULL
  pointer dereference in deref control plugin BER parser [rhel-10.2.z]
- Resolves: RHEL-210874 - CVE-2026-15722 389-ds-base: 389-ds-base: pre-
  authentication stack buffer overflow in get_ruvelement_from_berval() via
  unbounded replica ID parsing [rhel-10.2.z]

Fri, 26 Jun 2026 GMT - Viktor Ashirov &amp;lt;vashirov@redhat.com&amp;gt; - 3.2.0-8
- Bump version to 3.2.0-8
- Resolves: RHEL-182152 - CVE-2026-11610 389-ds-base: 389-ds-base: Heap
  buffer overflow in sasl_io_recv() via padded SASL UNBIND [rhel-10.2.z]
- Resolves: RHEL-183105 - CVE-2026-11774 389-ds-base: 389-ds-base: integer
  overflow in SASL packet length bypasses size limit leading to heap buffer
  overflow [rhel-10.2.z]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>valkey-devel-8.0.11-1.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:49:17 AM GMT</pubDate>
      <guid isPermaLink="false">e3a0b0418f73adcc03e0e8b03733cd49328555ba1a17864155bc65ee884451a3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/v/valkey-devel-8.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>valkey-devel</strong> - Development header for Valkey module development&lt;br /&gt;</p>

<p>Header file required for building loadable Valkey modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.0.11-1
- Rebase to 8.0.11 for CVE-2026-56684 CVE-2026-63639 (CVE-2026-66373 in redis)

Tue, 19 May 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.0.9-1
- Rebase to 8.0.9 for CVE-2026-23479 CVE-2026-25243 CVE-2026-23631

Mon, 02 Mar 2026 GMT - Lukas Javorsky &amp;lt;ljavorsk@redhat.com&amp;gt; - 8.0.7-1
- Rebase to 8.0.7 for CVE-2026-21863 CVE-2025-67733

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>valkey-8.0.11-1.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:49:17 AM GMT</pubDate>
      <guid isPermaLink="false">489f4724ebfa06a3127e81700003d3de0d4f187e8acea07589f8b409a2269ae7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/v/valkey-8.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>valkey</strong> - A persistent key-value database&lt;br /&gt;</p>

<p>Valkey is an advanced key-value store. It is often referred to as a data&lt;br /&gt;
structure server since keys can contain strings, hashes, lists, sets and&lt;br /&gt;
sorted sets.&lt;br /&gt;
&lt;br /&gt;
You can run atomic operations on these types, like appending to a string;&lt;br /&gt;
incrementing the value in a hash; pushing to a list; computing set&lt;br /&gt;
intersection, union and difference; or getting the member with highest&lt;br /&gt;
ranking in a sorted set.&lt;br /&gt;
&lt;br /&gt;
In order to achieve its outstanding performance, Valkey works with an&lt;br /&gt;
in-memory dataset. Depending on your use case, you can persist it either&lt;br /&gt;
by dumping the dataset to disk every once in a while, or by appending&lt;br /&gt;
each command to a log.&lt;br /&gt;
&lt;br /&gt;
Valkey also supports trivial-to-setup master-slave replication, with very&lt;br /&gt;
fast non-blocking first synchronization, auto-reconnection on net split&lt;br /&gt;
and so forth.&lt;br /&gt;
&lt;br /&gt;
Other features include Transactions, Pub/Sub, Lua scripting, Keys with a&lt;br /&gt;
limited time-to-live, and configuration settings to make Valkey behave like&lt;br /&gt;
a cache.&lt;br /&gt;
&lt;br /&gt;
You can use Valkey from most programming languages also.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.0.11-1
- Rebase to 8.0.11 for CVE-2026-56684 CVE-2026-63639 (CVE-2026-66373 in redis)

Tue, 19 May 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.0.9-1
- Rebase to 8.0.9 for CVE-2026-23479 CVE-2026-25243 CVE-2026-23631

Mon, 02 Mar 2026 GMT - Lukas Javorsky &amp;lt;ljavorsk@redhat.com&amp;gt; - 8.0.7-1
- Rebase to 8.0.7 for CVE-2026-21863 CVE-2025-67733

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>xz-lzma-compat-1:5.6.2-4.el10_2.1.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:49:01 AM GMT</pubDate>
      <guid isPermaLink="false">4dfbb41cf9a51b0dee2f10c3a12f466dfdc8b2d20dac59303d6b44d06ee1cea2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/x/xz-lzma-compat-5.6.2-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>xz-lzma-compat</strong> - Older LZMA format compatibility binaries&lt;br /&gt;</p>

<p>The lzma-compat package contains compatibility links for older&lt;br /&gt;
commands that deal with the older LZMA format.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Jakub Martisko &amp;lt;jamartis@redhat.com&amp;gt; - 1:5.6.2-4.1
- Fix: a buffer overflow in lzma_index_append()
- Add test for the issue above (needs a special build config to actually fail -&amp;gt; does not fail in our environemnt)
- Resolves: CVE-2026-34743

Tue, 13 May 2025 GMT - Jakub Martisko &amp;lt;jamartis@redhat.com&amp;gt; - 1:5.6.2-4
- Fix: heap-use-after-free bug in threaded .xz decoder (CVE-2025-31115)
- Resolves: RHEL-86029

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1:5.6.2-3
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>xz-devel-1:5.6.2-4.el10_2.1.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:49:01 AM GMT</pubDate>
      <guid isPermaLink="false">b9e292e7bc25ec312e36d9eae891a0c6c4bc9d168ca7ec7286effb590e2048d6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/x/xz-devel-5.6.2-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>xz-devel</strong> - Devel libraries &amp; headers for liblzma&lt;br /&gt;</p>

<p>Devel libraries and headers for liblzma.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Jakub Martisko &amp;lt;jamartis@redhat.com&amp;gt; - 1:5.6.2-4.1
- Fix: a buffer overflow in lzma_index_append()
- Add test for the issue above (needs a special build config to actually fail -&amp;gt; does not fail in our environemnt)
- Resolves: CVE-2026-34743

Tue, 13 May 2025 GMT - Jakub Martisko &amp;lt;jamartis@redhat.com&amp;gt; - 1:5.6.2-4
- Fix: heap-use-after-free bug in threaded .xz decoder (CVE-2025-31115)
- Resolves: RHEL-86029

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 1:5.6.2-3
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>buildah-tests-2:1.43.1-6.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:47:55 AM GMT</pubDate>
      <guid isPermaLink="false">62f108810fe452a2d43e091c8899b965a1abafcda95ec90f7ef2276cec5b0eb3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/buildah-tests-1.43.1-6.el10_2.aarch64.rpm</link>
      <description><p><strong>buildah-tests</strong> - Tests for buildah&lt;br /&gt;</p>

<p>Tests for buildah&lt;br /&gt;
&lt;br /&gt;
This package contains system tests for buildah</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-6
- Rebuild for golang CVE fixes
- Resolves: RHEL-229833 RHEL-241142 RHEL-241389 RHEL-241658 RHEL-241706 RHEL-242148 RHEL-251830

Sat, 08 Aug 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-5
- rebuild for CVE-2026-33810
- Resolves: RHEL-229833

Fri, 10 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-4
- rebuild for CVE-2026-39822
- Resolves: RHEL-193643

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>buildah-2:1.43.1-6.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:47:55 AM GMT</pubDate>
      <guid isPermaLink="false">ee7c6f61f5893cf4617500d14eb5550cbc072a9eeca30de8d4cef14557d96e4a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/buildah-1.43.1-6.el10_2.aarch64.rpm</link>
      <description><p><strong>buildah</strong> - A command line tool used for creating OCI Images&lt;br /&gt;</p>

<p>The buildah package provides a command line tool which can be used to&lt;br /&gt;
* create a working container from scratch&lt;br /&gt;
or&lt;br /&gt;
* create a working container from an image as a starting point&lt;br /&gt;
* mount/umount a working container's root file system for manipulation&lt;br /&gt;
* save container's root file system layer to create a new image&lt;br /&gt;
* delete a working container or an image</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-6
- Rebuild for golang CVE fixes
- Resolves: RHEL-229833 RHEL-241142 RHEL-241389 RHEL-241658 RHEL-241706 RHEL-242148 RHEL-251830

Sat, 08 Aug 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-5
- rebuild for CVE-2026-33810
- Resolves: RHEL-229833

Fri, 10 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.43.1-4
- rebuild for CVE-2026-39822
- Resolves: RHEL-193643

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>skopeo-tests-2:1.22.2-5.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:47:54 AM GMT</pubDate>
      <guid isPermaLink="false">4c6dc124eea134e8d0372dafe43d64ca1d7be6304466db156da3c881f8223c5f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/skopeo-tests-1.22.2-5.el10_2.aarch64.rpm</link>
      <description><p><strong>skopeo-tests</strong> - Test dependencies for skopeo&lt;br /&gt;</p>

<p>This package installs system test dependencies for skopeo</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-5
- Rebuild for golang CVE fixes
- Resolves: RHEL-241177 RHEL-241425 RHEL-241563 RHEL-241763 RHEL-242151 RHEL-251832

Wed, 08 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-4
- re-add test file installation to fix tier0 tests

Wed, 08 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-3
- Rebuild for CVE-2026-27145

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>skopeo-2:1.22.2-5.el10_2.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:47:54 AM GMT</pubDate>
      <guid isPermaLink="false">0fccd7ec5bd1525fd2ce54a3eb08f03f2e2222c7cc857bbffd481af9900df602</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/skopeo-1.22.2-5.el10_2.aarch64.rpm</link>
      <description><p><strong>skopeo</strong> - Inspect container images and repositories on registries&lt;br /&gt;</p>

<p>Command line utility to inspect images and repositories directly on Docker&lt;br /&gt;
registries without the need to pull them.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-5
- Rebuild for golang CVE fixes
- Resolves: RHEL-241177 RHEL-241425 RHEL-241563 RHEL-241763 RHEL-242151 RHEL-251832

Wed, 08 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-4
- re-add test file installation to fix tier0 tests

Wed, 08 Jul 2026 GMT - Jindrich Novy &amp;lt;jnovy@redhat.com&amp;gt; - 2:1.22.2-3
- Rebuild for CVE-2026-27145

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>expat-devel-2.7.3-1.el10_2.3.aarch64</title>
      <pubDate>Tue, 08 Sep 2026 08:47:53 AM GMT</pubDate>
      <guid isPermaLink="false">74a93f2ce98ca2b0f9a4dc3b1fe60961bd42020a282795c02768f414eec5d9c9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/e/expat-devel-2.7.3-1.el10_2.3.aarch64.rpm</link>
      <description><p><strong>expat-devel</strong> - Libraries and header files to develop applications using expat&lt;br /&gt;</p>

<p>The expat-devel package contains the libraries, include files and documentation&lt;br /&gt;
to develop XML applications with expat.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 31 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.7.3-59
- Fix CVE-2026-56132: out-of-bound scaffolding index store in doProlog

Fri, 31 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.7.3-58
- Fix CVE-2026-50219: forbid XML_ParserFree/Reset from handlers

Wed, 27 May 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.7.3-57
- expat: backport CVE-2026-45186 fix (attribute collision check DoS)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>grafana-pcp-5.3.0-8.el10_2.1.aarch64</title>
      <pubDate>Fri, 04 Sep 2026 11:02:27 AM GMT</pubDate>
      <guid isPermaLink="false">f0a021b653e520e22b854424f51c5aed3fe5c53f4b2a7bf8d07b75a5a27b8e24</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/grafana-pcp-5.3.0-8.el10_2.1.aarch64.rpm</link>
      <description><p><strong>grafana-pcp</strong> - Performance Co-Pilot Grafana Plugin&lt;br /&gt;</p>

<p>This Grafana plugin for Performance Co-Pilot includes data sources for&lt;br /&gt;
scalable time series from pmseries(1) and Valkey, live PCP metrics and&lt;br /&gt;
bpftrace scripts from pmdabpftrace(1), as well as several dashboards.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 02 Sep 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 5.3.0-8.1
- Rebuilt for updated golang
- Resolves RHEL-241480, RHEL-251115, RHEL-242257, RHEL-242154, RHEL-241751

Wed, 22 Jul 2026 GMT - Sam Feifer &amp;lt;sfeifer@redhat.com&amp;gt; - 5.3.0-8
- Resolves RHEL-188287: Remove Lua ExclusiveArch macro for Konflux build

Wed, 01 Jul 2026 GMT - Sam Feifer &amp;lt;sfeifer@redhat.com&amp;gt; - 5.3.0-7
- Resolves RHEL-183688: CVE-2026-39821

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>grafana-selinux-10.2.6-28.el10_2.5.aarch64</title>
      <pubDate>Thu, 03 Sep 2026 09:35:32 AM GMT</pubDate>
      <guid isPermaLink="false">9416e620b49d6da19df55597106a8e6de97c1eba5e19f4cfd16ab6c44b833ab6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/grafana-selinux-10.2.6-28.el10_2.5.aarch64.rpm</link>
      <description><p><strong>grafana-selinux</strong> - SELinux policy module supporting grafana&lt;br /&gt;</p>

<p>SELinux policy module supporting grafana</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.5
- Rebuild against updated golang
- Resolves RHEL-241197
- Resolves RHEL-241426
- Resolves RHEL-241690
- Resolves RHEL-241975
- Resolves RHEL-242171
- Resolves RHEL-242372
- Resolves RHEL-251690
- Resolves RHEL-251818

Thu, 06 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.4
- Resolves RHEL-211020: CVE-2026-33377

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.3
- Resolves RHEL-211376: CVE-2026-8609

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>grafana-10.2.6-28.el10_2.5.aarch64</title>
      <pubDate>Thu, 03 Sep 2026 09:35:32 AM GMT</pubDate>
      <guid isPermaLink="false">ede527ab1420e66a24a5622282f508e545bc3a8b649627ff2262b0f56c295da4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/grafana-10.2.6-28.el10_2.5.aarch64.rpm</link>
      <description><p><strong>grafana</strong> - Metrics dashboard and graph editor&lt;br /&gt;</p>

<p>Grafana is an open source, feature rich metrics dashboard and graph editor for&lt;br /&gt;
Graphite, InfluxDB &amp; OpenTSDB.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 31 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.5
- Rebuild against updated golang
- Resolves RHEL-241197
- Resolves RHEL-241426
- Resolves RHEL-241690
- Resolves RHEL-241975
- Resolves RHEL-242171
- Resolves RHEL-242372
- Resolves RHEL-251690
- Resolves RHEL-251818

Thu, 06 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.4
- Resolves RHEL-211020: CVE-2026-33377

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 10.2.6-28.3
- Resolves RHEL-211376: CVE-2026-8609

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-xml-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">ac15231cd776c4998da2f4e9c4155576210123158a5b5b87fd8d0e7cd0c84a9a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-xml-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-xml</strong> - A module for PHP applications which use XML&lt;br /&gt;</p>

<p>The php-xml package contains dynamic shared objects which add support&lt;br /&gt;
to PHP for manipulating XML documents using the DOM tree,&lt;br /&gt;
and performing XSL transformations on XML documents.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-soap-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">888d11410c26aaa3962a7d7bbd3ccb2909695574fec53aa79f153f3624e11278</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-soap-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-soap</strong> - A module for PHP applications that use the SOAP protocol&lt;br /&gt;</p>

<p>The php-soap package contains a dynamic shared object that will add&lt;br /&gt;
support to PHP for using the SOAP web services protocol.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-snmp-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">3a547178da77e081b7efd8afedddaba3f658f45699822d1f42419676b3857ee3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-snmp-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-snmp</strong> - A module for PHP applications that query SNMP-managed devices&lt;br /&gt;</p>

<p>The php-snmp package contains a dynamic shared object that will add&lt;br /&gt;
support for querying SNMP devices to PHP.  PHP is an HTML-embeddable&lt;br /&gt;
scripting language. If you need SNMP support for PHP applications, you&lt;br /&gt;
will need to install this package and the php package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-process-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">8f1536bd4532e4256baf054cf257fd61770f3922e0ff61bcddf79d6093675ba9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-process-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-process</strong> - Modules for PHP script using system process interfaces&lt;br /&gt;</p>

<p>The php-process package contains dynamic shared objects which add&lt;br /&gt;
support to PHP using system interfaces for inter-process&lt;br /&gt;
communication.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-pgsql-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">cbf888279668fdfae4eb31b01d82f5269de161c9d5991c09f3e2dba7dd9cd0b2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-pgsql-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-pgsql</strong> - A PostgreSQL database module for PHP&lt;br /&gt;</p>

<p>The php-pgsql package add PostgreSQL database support to PHP.&lt;br /&gt;
PostgreSQL is an object-relational database management&lt;br /&gt;
system that supports almost all SQL constructs. PHP is an&lt;br /&gt;
HTML-embedded scripting language. If you need back-end support for&lt;br /&gt;
PostgreSQL, you should install this package in addition to the main&lt;br /&gt;
php package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-pdo-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">fe96bc16a410413ba3ca4c1dfb7177e0ddb7358d327ccada35f40fe57e5dd89d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-pdo-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-pdo</strong> - A database access abstraction module for PHP applications&lt;br /&gt;</p>

<p>The php-pdo package contains a dynamic shared object that will add&lt;br /&gt;
a database access abstraction layer to PHP.  This module provides&lt;br /&gt;
a common interface for accessing MySQL, PostgreSQL or other&lt;br /&gt;
databases.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-opcache-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">d0337d35b129d3dbd169ce5a486418e6e2401301eae60489a849928c5b3ced9e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-opcache-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-opcache</strong> - The Zend OPcache&lt;br /&gt;</p>

<p>The Zend OPcache provides faster PHP execution through opcode caching and&lt;br /&gt;
optimization. It improves PHP performance by storing precompiled script&lt;br /&gt;
bytecode in the shared memory. This eliminates the stages of reading code from&lt;br /&gt;
the disk and compiling it on future access. In addition, it applies a few&lt;br /&gt;
bytecode optimization patterns that make code execution faster.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-odbc-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">9e1e0d448c39edb338f1a786bf00f0c94ca3f98b29e546f610373aa09b6f967b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-odbc-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-odbc</strong> - A module for PHP applications that use ODBC databases&lt;br /&gt;</p>

<p>The php-odbc package contains a dynamic shared object that will add&lt;br /&gt;
database support through ODBC to PHP. ODBC is an open specification&lt;br /&gt;
which provides a consistent API for developers to use for accessing&lt;br /&gt;
data sources (which are often, but not always, databases). PHP is an&lt;br /&gt;
HTML-embeddable scripting language. If you need ODBC support for PHP&lt;br /&gt;
applications, you will need to install this package and the php&lt;br /&gt;
package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-mysqlnd-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">193d0725224138c74465a0b99b144b19ecb2a90f17dccd2a8688086be37cf1ce</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-mysqlnd-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-mysqlnd</strong> - A module for PHP applications that use MySQL databases&lt;br /&gt;</p>

<p>The php-mysqlnd package contains a dynamic shared object that will add&lt;br /&gt;
MySQL database support to PHP. MySQL is an object-relational database&lt;br /&gt;
management system. PHP is an HTML-embeddable scripting language. If&lt;br /&gt;
you need MySQL support for PHP applications, you will need to install&lt;br /&gt;
this package and the php package.&lt;br /&gt;
&lt;br /&gt;
This package use the MySQL Native Driver</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-mbstring-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">c0cb6b05465a6c728584c35bf78f71cec3f3025264ff78877c2cbb03e6ad8aad</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-mbstring-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-mbstring</strong> - A module for PHP applications which need multi-byte string handling&lt;br /&gt;</p>

<p>The php-mbstring package contains a dynamic shared object that will add&lt;br /&gt;
support for multi-byte string handling to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-ldap-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">11dcbdd0c7ca0791b5ee2746d7af8782a999b0427bbe093d3767f21339b57621</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-ldap-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-ldap</strong> - A module for PHP applications that use LDAP&lt;br /&gt;</p>

<p>The php-ldap adds Lightweight Directory Access Protocol (LDAP)&lt;br /&gt;
support to PHP. LDAP is a set of protocols for accessing directory&lt;br /&gt;
services over the Internet. PHP is an HTML-embedded scripting&lt;br /&gt;
language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-intl-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">f8a0810ff21f563663f138972c04ad15377e09ede586939c6e68dd71048acaa1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-intl-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-intl</strong> - Internationalization extension for PHP applications&lt;br /&gt;</p>

<p>The php-intl package contains a dynamic shared object that will add&lt;br /&gt;
support for using the ICU library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-gmp-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">88d6907f36d5c3303ae834c0f2c9ac1e1044c11d048938a56c7cf4dd1379a1f0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-gmp-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-gmp</strong> - A module for PHP applications for using the GNU MP library&lt;br /&gt;</p>

<p>These functions allow you to work with arbitrary-length integers&lt;br /&gt;
using the GNU MP library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-gd-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">6949e2b171bc9e27c39bade03621808ab9186cc19a417b04cb2ae544237e884f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-gd-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-gd</strong> - A module for PHP applications for using the gd graphics library&lt;br /&gt;</p>

<p>The php-gd package contains a dynamic shared object that will add&lt;br /&gt;
support for using the gd graphics library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-fpm-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">0e1be0e66ff00189518ac45217c6a1d36a0ab98e9689f126f4ac1cb3cdabb58c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-fpm-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-fpm</strong> - PHP FastCGI Process Manager&lt;br /&gt;</p>

<p>PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI&lt;br /&gt;
implementation with some additional features useful for sites of&lt;br /&gt;
any size, especially busier sites.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-ffi-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">bee269879c70b8d5df1b500f8df35b06b5fe125bf7818fb0f1ed4dc6d45d4be1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-ffi-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-ffi</strong> - Foreign Function Interface&lt;br /&gt;</p>

<p>FFI is one of the features that made Python and LuaJIT very useful for fast&lt;br /&gt;
prototyping. It allows calling C functions and using C data types from pure&lt;br /&gt;
scripting language and therefore develop “system code” more productively.&lt;br /&gt;
&lt;br /&gt;
For PHP, FFI opens a way to write PHP extensions and bindings to C libraries&lt;br /&gt;
in pure PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-enchant-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">d6afc0dbd830224893aa1221e6fa191f8e3fd19551255c7a6b6531024970e7f4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-enchant-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-enchant</strong> - Enchant spelling extension for PHP applications&lt;br /&gt;</p>

<p>The php-enchant package contains a dynamic shared object that will add&lt;br /&gt;
support for using the enchant library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-embedded-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">9ca328d62d7739cc57ba8dc9507eb390d62a0c129099aca408c1f473a61a54a7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-embedded-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-embedded</strong> - PHP library for embedding in applications&lt;br /&gt;</p>

<p>The php-embedded package contains a library which can be embedded&lt;br /&gt;
into applications to provide PHP scripting language support.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-devel-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">ec6cabce787ea6e1bf778a831ff010f89fb5ae919edd5a2464bb7ae05353f281</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-devel-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-devel</strong> - Files needed for building PHP extensions&lt;br /&gt;</p>

<p>The php-devel package contains the files needed for building PHP&lt;br /&gt;
extensions. If you need to compile your own PHP extensions, you will&lt;br /&gt;
need to install this package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-dbg-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">d5c17f0bc0d41723859b8b678056a1f0c6ca1c535cbeb0e30d940300f4248bfe</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-dbg-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-dbg</strong> - The interactive PHP debugger&lt;br /&gt;</p>

<p>The php-dbg package contains the interactive PHP debugger.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-dba-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">7b4280efab48b1a435849e211256156353ff6c14546b792f5fd93da773912f11</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-dba-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-dba</strong> - A database abstraction layer module for PHP applications&lt;br /&gt;</p>

<p>The php-dba package contains a dynamic shared object that will add&lt;br /&gt;
support for using the DBA database abstraction layer to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-common-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">f70ce46a4d8e9243cd79dd58c1b414b806afaeea74f5ea3ac066a34c3ff418f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-common-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-common</strong> - Common files for PHP&lt;br /&gt;</p>

<p>The php-common package contains files used by both the php&lt;br /&gt;
package and the php-cli package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-cli-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">b30b75cbe7fb678387cb98ffcaca2a349d7d90225df9c398f6ac059b44e7e1f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-cli-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-cli</strong> - Command-line interface for PHP&lt;br /&gt;</p>

<p>The php-cli package contains the command-line interface&lt;br /&gt;
executing PHP scripts, /usr/bin/php, and the CGI interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-bcmath-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">f1e9addfaac97642a5b8e409c42d3f38695253558dbf21daf3429b4f99a77df0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-bcmath-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php-bcmath</strong> - A module for PHP applications for using the bcmath library&lt;br /&gt;</p>

<p>The php-bcmath package contains a dynamic shared object that will add&lt;br /&gt;
support for using the bcmath library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php-8.3.33-1.el10_2.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">7933fafaa10df60b01cb09516e585214100e401775367360fb5f54f03e10c118</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php-8.3.33-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php</strong> - PHP scripting language for creating dynamic web sites&lt;br /&gt;</p>

<p>PHP is an HTML-embedded scripting language. PHP attempts to make it&lt;br /&gt;
easy for developers to write dynamically generated web pages. PHP also&lt;br /&gt;
offers built-in database integration for several commercial and&lt;br /&gt;
non-commercial database management systems, so writing a&lt;br /&gt;
database-enabled webpage with PHP is fairly simple. The most common&lt;br /&gt;
use of PHP coding is probably as a replacement for CGI scripts.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.33-1
- rebase to 8.3.33

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.32-1
- rebase to 8.3.32

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.3.31-1
- rebase to 8.3.31
- add tmpfiles.d configuration file for ImageMode

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>ipp-usb-0.9.27-7.el10_2.3.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:21 PM GMT</pubDate>
      <guid isPermaLink="false">03b0e7c1339d99fcce8dcf36c22d74df66e881545b49064c40b636d4f85d21e5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/ipp-usb-0.9.27-7.el10_2.3.aarch64.rpm</link>
      <description><p><strong>ipp-usb</strong> - HTTP reverse proxy capable of IPP-over-USB connection&lt;br /&gt;</p>

<p>&lt;br /&gt;
HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables&lt;br /&gt;
 driverless support for USB devices capable of using IPP-over-USB protocol.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 31 Aug 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 0.9.27-7.3
- Rebuilt with golang-1.26.7-1.el10_2 to fix
  CVE-2026-42504,CVE-2026-33818,CVE-2026-56853,CVE-2026-56859,CVE-2026-56860,CVE-2026-56862

Mon, 29 Jun 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 0.9.27-7.2
- rebuilt with golang-1.26.4-1.el10_2 to fix CVE-2026-33811, CVE-2026-27145

Tue, 02 Jun 2026 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 0.9.27-7.1
- rebuilt with golang-1.26.3-4.el10_2 to fix CVE-2026-32281

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-fdo-client-1.0.0-4.el10_2.7.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:15 PM GMT</pubDate>
      <guid isPermaLink="false">b9adfb026b16c1ccef31db746fc661287a2d2f2a016a131591379c3d7983d7ab</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-fdo-client-1.0.0-4.el10_2.7.aarch64.rpm</link>
      <description><p><strong>go-fdo-client</strong> - FIDO FDO compliant device on-boarding tool&lt;br /&gt;</p>

<p>go-fdo-client is the device-side implementation of FIDO Device Onboard&lt;br /&gt;
specification in Go. It provides an FDO client that interacts with&lt;br /&gt;
FDO manufacturer and owner servers to perform device on-boarding.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 26 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.0-7
- Rebuild go-fdo-client against updated golang

Tue, 18 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.0-6
- Rebuild go-fdo-client against updated golang

Tue, 30 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.0-5
- Rebuild against updated golang

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-fdo-server-rendezvous-1.0.1-2.el10_2.4.noarch</title>
      <pubDate>Wed, 02 Sep 2026 02:24:14 PM GMT</pubDate>
      <guid isPermaLink="false">c1a67a3a13e75eb1836d988a04c1799e7f84f5dc4411a8863f81610f330953fe</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-fdo-server-rendezvous-1.0.1-2.el10_2.4.noarch.rpm</link>
      <description><p><strong>go-fdo-server-rendezvous</strong> - A Go implementation of the FDO rendezvous server&lt;br /&gt;</p>

<p>This package provides the rendezvous server component of the FDO stack.&lt;br /&gt;
The rendezvous server acts as a trusted intermediary, redirecting devices&lt;br /&gt;
to their designated owner's on-boarding service based on their ownership&lt;br /&gt;
voucher.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 19 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-4
- Rebuild go-fdo-server against updated golang

Mon, 13 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-3
- Rebuild against updated golang

Wed, 20 May 2026 GMT - Sarita Mahajan &amp;lt;sarmahaj@redhat.com&amp;gt; - 1.0.1-2
- Rebuild to fix CVE-2026-32282 and CVE-2025-68121

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-fdo-server-owner-1.0.1-2.el10_2.4.noarch</title>
      <pubDate>Wed, 02 Sep 2026 02:24:14 PM GMT</pubDate>
      <guid isPermaLink="false">cff0c907acd635fd64aee39a1936b4cfbdbbfb896e5640954e3a39cd5cd5aabf</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-fdo-server-owner-1.0.1-2.el10_2.4.noarch.rpm</link>
      <description><p><strong>go-fdo-server-owner</strong> - A Go implementation of the FDO owner server&lt;br /&gt;</p>

<p>This package provides the owner server component of the FDO stack. The owner&lt;br /&gt;
server is the final destination for a device during on-boarding. It verifies&lt;br /&gt;
the device's authenticity, establishes ownership, and provisions it with the&lt;br /&gt;
necessary credentials and configuration for operation.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 19 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-4
- Rebuild go-fdo-server against updated golang

Mon, 13 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-3
- Rebuild against updated golang

Wed, 20 May 2026 GMT - Sarita Mahajan &amp;lt;sarmahaj@redhat.com&amp;gt; - 1.0.1-2
- Rebuild to fix CVE-2026-32282 and CVE-2025-68121

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-fdo-server-manufacturer-1.0.1-2.el10_2.4.noarch</title>
      <pubDate>Wed, 02 Sep 2026 02:24:14 PM GMT</pubDate>
      <guid isPermaLink="false">f278f3cb32060c9049d83865104e85a844ba5a2bcef810b0857c1f05464203cc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-fdo-server-manufacturer-1.0.1-2.el10_2.4.noarch.rpm</link>
      <description><p><strong>go-fdo-server-manufacturer</strong> - A Go implementation of the FDO manufacturer server&lt;br /&gt;</p>

<p>This package provides the manufacturer server component of the FDO stack.&lt;br /&gt;
The manufacturer server is responsible for creating ownership vouchers and&lt;br /&gt;
preparing devices for the on-boarding process during the manufacturing phase.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 19 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-4
- Rebuild go-fdo-server against updated golang

Mon, 13 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-3
- Rebuild against updated golang

Wed, 20 May 2026 GMT - Sarita Mahajan &amp;lt;sarmahaj@redhat.com&amp;gt; - 1.0.1-2
- Rebuild to fix CVE-2026-32282 and CVE-2025-68121

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-fdo-server-1.0.1-2.el10_2.4.aarch64</title>
      <pubDate>Wed, 02 Sep 2026 02:24:13 PM GMT</pubDate>
      <guid isPermaLink="false">62f136fd0fe509eec411fda41afe2b0ea8e1376feb6259c30951f1e41f5291db</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-fdo-server-1.0.1-2.el10_2.4.aarch64.rpm</link>
      <description><p><strong>go-fdo-server</strong> - A Go implementation of the FIDO Device Onboard Specification&lt;br /&gt;</p>

<p>This package provides a server-side implementation of the FIDO Device Onboard&lt;br /&gt;
(FDO) specification, written in Go. FDO is an open standard for the late&lt;br /&gt;
binding of device credentials, allowing for automated and secure on-boarding of&lt;br /&gt;
devices when they are first powered on in their final location.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 19 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-4
- Rebuild go-fdo-server against updated golang

Mon, 13 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.0.1-3
- Rebuild against updated golang

Wed, 20 May 2026 GMT - Sarita Mahajan &amp;lt;sarmahaj@redhat.com&amp;gt; - 1.0.1-2
- Rebuild to fix CVE-2026-32282 and CVE-2025-68121

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>wget-1.24.5-8.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 10:05:46 PM GMT</pubDate>
      <guid isPermaLink="false">0eb144ad1cf58eac653856c34a7c83fd90785ad5549f944694067ecc2f6e999e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/w/wget-1.24.5-8.el10_2.aarch64.rpm</link>
      <description><p><strong>wget</strong> - A utility for retrieving files using the HTTP or FTP protocols&lt;br /&gt;</p>

<p>GNU Wget is a file retrieval utility which can use either the HTTP or&lt;br /&gt;
FTP protocols. Wget features include the ability to work in the&lt;br /&gt;
background while you are logged out, recursive retrieval of&lt;br /&gt;
directories, file name wildcard matching, remote file timestamp&lt;br /&gt;
storage and comparison, use of Rest with FTP servers and Range with&lt;br /&gt;
HTTP servers to retrieve files over slow or unstable connections,&lt;br /&gt;
support for Proxy servers, and configurability.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 03 Aug 2026 GMT - Michal Ruprich &amp;lt;mruprich@redhat.com&amp;gt; - 1.24.5-8
- Resolves: RHEL-220498 - async unsafe code in signal handler context

Wed, 15 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.5-7
- Fix CVE-2026-58471: buffer overflow in convert_fname()
  Resolves: RHEL-194518

Wed, 15 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.5-6
- Fix integer and buffer overflow in html_quote_string()
  Resolves: RHEL-210625

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-docs-1:22.23.2-1.el10_2.noarch</title>
      <pubDate>Tue, 01 Sep 2026 09:11:38 AM GMT</pubDate>
      <guid isPermaLink="false">9533edd7d933e617afda30a4dd138cd46b80e4ed17134ddf6c1f3159b473a5ae</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-docs-22.23.2-1.el10_2.noarch.rpm</link>
      <description><p><strong>nodejs-docs</strong> - Node.js API documentation&lt;br /&gt;</p>

<p>The API documentation for the Node.js JavaScript runtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-npm-1:10.9.8-1.22.23.2.1.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 09:11:30 AM GMT</pubDate>
      <guid isPermaLink="false">a34c8a4ba54da92611a971b751ed7609d9cd51d38f843d8fd45f34d47a529370</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-npm-10.9.8-1.22.23.2.1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs-npm</strong> - Node.js Package Manager&lt;br /&gt;</p>

<p>npm is a package manager for node.js. You can use it to install and publish&lt;br /&gt;
your node programs. It manages dependencies and does other cool stuff.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-libs-1:22.23.2-1.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 09:11:30 AM GMT</pubDate>
      <guid isPermaLink="false">8db1700a53c2fb55788dadf8a8706e9eedf1fdccc9261c042f62e27e7cbb92e2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-libs-22.23.2-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs-libs</strong> - Node.js and v8 libraries&lt;br /&gt;</p>

<p>Libraries to support Node.js and provide stable v8 interfaces.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-full-i18n-1:22.23.2-1.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 09:11:30 AM GMT</pubDate>
      <guid isPermaLink="false">5ee4cdb846b975309482fe966a95ac98c4217907848d71bd8c4b2a4c4b9f0b96</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-full-i18n-22.23.2-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs-full-i18n</strong> - Non-English locale data for Node.js&lt;br /&gt;</p>

<p>Optional data files to provide full-icu support for Node.js. Remove this&lt;br /&gt;
package to save space if non-English locales are not needed.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-devel-1:22.23.2-1.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 09:11:30 AM GMT</pubDate>
      <guid isPermaLink="false">dbdc1553ba4b7abe50600a13632c8dc10388fd00cb3afef064d0641e8b18b866</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-devel-22.23.2-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs-devel</strong> - JavaScript runtime - development headers&lt;br /&gt;</p>

<p>Development headers for the Node.js JavaScript runtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs-1:22.23.2-1.el10_2.aarch64</title>
      <pubDate>Tue, 01 Sep 2026 09:11:30 AM GMT</pubDate>
      <guid isPermaLink="false">13d7ea17f539ad4c420b2bfee2a4065a500ff218d0907507bfdb85667e0b2629</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs-22.23.2-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs</strong> - JavaScript runtime&lt;br /&gt;</p>

<p>Node.js is a platform built on Chrome's JavaScript runtime \&lt;br /&gt;
for easily building fast, scalable network applications. \&lt;br /&gt;
Node.js uses an event-driven, non-blocking I/O model that \&lt;br /&gt;
makes it lightweight and efficient, perfect for data-intensive \&lt;br /&gt;
real-time applications that run across distributed devices.}</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.2-1
- Update to version 22.23.2

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-6
- Fix for CVE-2026-69152

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:22.23.1-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>iperf3-3.17.1-6.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 09:44:08 PM GMT</pubDate>
      <guid isPermaLink="false">457c692f2d506f4e4e7dcbf2c44e3dc2e9d659bffb896945b21f0ef6d511b93a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/iperf3-3.17.1-6.el10_2.1.aarch64.rpm</link>
      <description><p><strong>iperf3</strong> - Measurement tool for TCP/UDP bandwidth performance&lt;br /&gt;</p>

<p>Iperf is a tool to measure maximum TCP bandwidth, allowing the tuning of&lt;br /&gt;
various parameters and UDP characteristics. Iperf reports bandwidth, delay&lt;br /&gt;
jitter, data-gram loss.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 12 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.17.1-6.1
- Fix JSON value bounds checks in get_parameters and
  iperf_parse_arguments (CVE-2026-71217)
- Resolves: RHEL-236170

Mon, 13 Apr 2026 GMT - Michal Ruprich &amp;lt;mruprich@redhat.com&amp;gt; - 3.17.1-6
- Resolves: RHEL-151876 - authentication no longer works with the new openssl

Tue, 20 Jan 2026 GMT - Michal Ruprich &amp;lt;mruprich@redhat.com&amp;gt; - 3.17.1-5
- Resolves: RHEL-136170 - iperf Heap Buffer Overflow (CVE-2025-54349)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-libs-1:24.19.0-1.el10_2.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 02:25:29 PM GMT</pubDate>
      <guid isPermaLink="false">5a21f10a3a95ebf8a2e451efa985fcdebf58215588bd7ee0bc5cea2494fe0d05</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-libs-24.19.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs24-libs</strong> - Node.js and v8 libraries&lt;br /&gt;</p>

<p>Libraries to support Node.js and provide stable v8 interfaces.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-full-i18n-1:24.19.0-1.el10_2.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 02:25:29 PM GMT</pubDate>
      <guid isPermaLink="false">9393d85c28d848a196c35f64f1eb847ec15ee1a479eeeffb5db1da65e89e2ae7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-full-i18n-24.19.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs24-full-i18n</strong> - Non-English locale data for Node.js&lt;br /&gt;</p>

<p>Optional data files to provide full ICU support for Node.js.&lt;br /&gt;
Remove this package to save space if non-English locales are not needed.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-devel-1:24.19.0-1.el10_2.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 02:25:29 PM GMT</pubDate>
      <guid isPermaLink="false">231d4136fd51f068a88e36345d715a75e43ecf9a81b8a11d375a70ca8fcdf875</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-devel-24.19.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs24-devel</strong> - JavaScript runtime – development headers&lt;br /&gt;</p>

<p>Development headers for the Node.js JavaScript runtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-1:24.19.0-1.el10_2.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 02:25:29 PM GMT</pubDate>
      <guid isPermaLink="false">0d58bd1b8d44b7d7cc5177f27c69414901359a9ee36c20007d7f47a73e829b5f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-24.19.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>nodejs24</strong> - JavaScript runtime&lt;br /&gt;</p>

<p>Node.js is a platform built on Chrome's JavaScript runtime&lt;br /&gt;
for easily building fast, scalable network applications.&lt;br /&gt;
Node.js uses an event-driven, non-blocking I/O model that&lt;br /&gt;
makes it lightweight and efficient, perfect for data-intensive&lt;br /&gt;
real-time applications that run across distributed devices.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-npm-1:11.17.0-1.24.19.0.1.el10_2.noarch</title>
      <pubDate>Mon, 31 Aug 2026 02:25:27 PM GMT</pubDate>
      <guid isPermaLink="false">1f6d6189a801d03442a16d0b225e38042810f73b2221598a6d14fb65751bd6fd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-npm-11.17.0-1.24.19.0.1.el10_2.noarch.rpm</link>
      <description><p><strong>nodejs24-npm</strong> - Node.js Package Manager&lt;br /&gt;</p>

<p>npm is a package manager for node.js. You can use it to install and publish&lt;br /&gt;
your node programs. It manages dependencies and does other cool stuff.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nodejs24-docs-1:24.19.0-1.el10_2.noarch</title>
      <pubDate>Mon, 31 Aug 2026 02:25:27 PM GMT</pubDate>
      <guid isPermaLink="false">c68b9417a86be968a4e81634a88dfdf176b29768b067e2698f29c57a044da6db</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nodejs24-docs-24.19.0-1.el10_2.noarch.rpm</link>
      <description><p><strong>nodejs24-docs</strong> - Node.js API documentation&lt;br /&gt;</p>

<p>The API documentation for the Node.js JavaScript runtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.19.0-1
- Update to version 24.19.0

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-5
- Fix for CVE-2026-69192 &amp;amp; CVE-2026-54272 : ip-address

Tue, 04 Aug 2026 GMT - tjuhasz &amp;lt;tjuhasz@redhat.com&amp;gt; - 1:24.18.0-4
- Fix CVE-2026-13149 (brace-expansion)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-utils-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">86d6f8563c60abed08f6e595e035815ef46cc37df9f5eb43890a0d62cf8e502f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-utils-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-utils</strong> - PipeWire media server utilities&lt;br /&gt;</p>

<p>This package contains command line utilities for the PipeWire media server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-pulseaudio-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">ecedae253864e83f86cba91616cfa7a0c07389bc37c68f8f64ae9527dd454755</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-pulseaudio-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-pulseaudio</strong> - PipeWire PulseAudio implementation&lt;br /&gt;</p>

<p>This package provides a PulseAudio implementation based on PipeWire</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-plugin-libcamera-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">d94ce44a1472b9784fe4d36b660be3a6869b20c434f9d071e71e05e2fcbcea8d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-plugin-libcamera-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-plugin-libcamera</strong> - PipeWire media server libcamera support&lt;br /&gt;</p>

<p>This package contains the PipeWire spa plugin to access cameras through libcamera.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-module-x11-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">380d700e302ca182e692fa675a108a1f20ebbcaaf17a2b9afdd8b7d38d4f9c75</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-module-x11-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-module-x11</strong> - PipeWire media server x11 support&lt;br /&gt;</p>

<p>This package contains X11 bell support for PipeWire.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-libs-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">984c9feee16a387a7d9b58745ac250ba719d304fcc731f91b23fd99db63595a8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-libs-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-libs</strong> - Libraries for PipeWire clients&lt;br /&gt;</p>

<p>This package contains the runtime libraries for any application that wishes&lt;br /&gt;
to interface with a PipeWire media server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-jack-audio-connection-kit-libs-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">18b6cf41fa9bfe6a8d4f61be6db3b129a0a73ecfe68ca67c6debeafc290d97be</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-jack-audio-connection-kit-libs-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-jack-audio-connection-kit-libs</strong> - PipeWire JACK implementation libraries&lt;br /&gt;</p>

<p>This package provides a JACK implementation libraries based on PipeWire</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-jack-audio-connection-kit-devel-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">e8e29082e4f7e7247053a22db705577f5bda09f1af144a409e1feed27d80249d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-jack-audio-connection-kit-devel-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-jack-audio-connection-kit-devel</strong> - Development files for pipewire-jack-audio-connection-kit&lt;br /&gt;</p>

<p>This package provides development files for building JACK applications&lt;br /&gt;
using PipeWire's JACK library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-jack-audio-connection-kit-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">3cd7c72d76ca26e5238848637132028207318d75a1c5cff4e433ae0be07accc4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-jack-audio-connection-kit-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-jack-audio-connection-kit</strong> - PipeWire JACK implementation&lt;br /&gt;</p>

<p>This package provides a JACK implementation based on PipeWire</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-gstreamer-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">8267b2e561a6d756148d658cd8bf85cea2a689f547039d43cf6ebe1866f2fb98</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-gstreamer-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-gstreamer</strong> - GStreamer elements for PipeWire&lt;br /&gt;</p>

<p>This package contains GStreamer elements to interface with a&lt;br /&gt;
PipeWire media server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-devel-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">9307501bf21b01eb954a25a4ca1497cd2a5e3ad9eb0112bcc64c7b49dbf8b9dd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-devel-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-devel</strong> - Headers and libraries for PipeWire client development&lt;br /&gt;</p>

<p>Headers and libraries for developing applications that can communicate with&lt;br /&gt;
a PipeWire media server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-alsa-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">6c70d2ebd3ec20b5f8aaaf91f80d12c6ae1c74fa8a06d450c4884606e91b7b6b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-alsa-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire-alsa</strong> - PipeWire media server ALSA support&lt;br /&gt;</p>

<p>This package contains an ALSA plugin for the PipeWire media server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pipewire-1.4.11-1.el10_2.1.aarch64</title>
      <pubDate>Mon, 31 Aug 2026 08:46:03 AM GMT</pubDate>
      <guid isPermaLink="false">56a407ec92912856e019dae4959be7e05a22a85eff442b9922644164f981a6f2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pipewire-1.4.11-1.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pipewire</strong> - Media Sharing Server&lt;br /&gt;</p>

<p>PipeWire is a multimedia server for Linux and other Unix like operating&lt;br /&gt;
systems.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 27 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.4.11-1.1
- Fix CVE-2026-14324: limit RTSP Content-Length and check
  allocation in RAOP client
  Resolves: RHEL-249305

Fri, 15 May 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4.11-1
- Rebase to 1.4.11
- Add fixes for CVE-2026-5674
  Resolves: RHEL-164823

Mon, 30 Jun 2025 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.4-6-1
- Update version to 1.4.6
  Resolves: DESKTOP-1857

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libxml2-devel-2.12.5-10.el10_2.3.aarch64</title>
      <pubDate>Thu, 27 Aug 2026 11:14:30 AM GMT</pubDate>
      <guid isPermaLink="false">3c27619f4c27cb04b4f666789d33ad43c1fee00c0f27b238b6585d8a7b093550</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libxml2-devel-2.12.5-10.el10_2.3.aarch64.rpm</link>
      <description><p><strong>libxml2-devel</strong> - Libraries, includes, etc. to develop XML and HTML applications&lt;br /&gt;</p>

<p>Libraries, include files, etc you can use to develop XML applications.&lt;br /&gt;
This library allows to manipulate XML files. It includes support&lt;br /&gt;
to read, modify and write XML and HTML files. There is DTDs support&lt;br /&gt;
this includes parsing and validation even with complex DtDs, either&lt;br /&gt;
at parse time or later once the document has been modified. The output&lt;br /&gt;
can be a simple SAX stream or and in-memory DOM like representations.&lt;br /&gt;
In this case one can use the built-in XPath and XPointer implementation&lt;br /&gt;
to select sub nodes or ranges. A flexible Input/Output mechanism is&lt;br /&gt;
available, with existing HTTP and FTP modules and combined to an&lt;br /&gt;
URI library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sat, 25 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.12.5-10.3
- Fix CVE-2026-11979 (RHEL-215571)

Tue, 16 Jun 2026 GMT - David King &amp;lt;dking@redhat.com&amp;gt; - 2.12.5-10.2
- Fix CVE-2025-6170 (RHEL-182007)

Mon, 18 May 2026 GMT - David King &amp;lt;dking@redhat.com&amp;gt; - 2.12.5-10.1
- Fix CVE-2024-34459 (RHEL-177890)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-tests-1.26.7-1.el10_2.noarch</title>
      <pubDate>Wed, 26 Aug 2026 02:38:18 PM GMT</pubDate>
      <guid isPermaLink="false">926e66f5e6adbeff4c0ce353874e5b93b257111f9c134d600f038bec7dd8420b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-tests-1.26.7-1.el10_2.noarch.rpm</link>
      <description><p><strong>golang-tests</strong> - Golang compiler tests for stdlib&lt;br /&gt;</p>

<p>Golang compiler tests for stdlib.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-src-1.26.7-1.el10_2.noarch</title>
      <pubDate>Wed, 26 Aug 2026 02:38:18 PM GMT</pubDate>
      <guid isPermaLink="false">27e1f17fab89581973cd3420071917b1145e13f778353d404d3cc255169ae176</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-src-1.26.7-1.el10_2.noarch.rpm</link>
      <description><p><strong>golang-src</strong> - Golang compiler source tree&lt;br /&gt;</p>

<p>Golang compiler source tree</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-misc-1.26.7-1.el10_2.noarch</title>
      <pubDate>Wed, 26 Aug 2026 02:38:18 PM GMT</pubDate>
      <guid isPermaLink="false">b44708e469614108d1ced2e4aa2973b3401a04a5e96e6bc829066e79c32d954f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-misc-1.26.7-1.el10_2.noarch.rpm</link>
      <description><p><strong>golang-misc</strong> - Golang compiler miscellaneous sources&lt;br /&gt;</p>

<p>Golang compiler miscellaneous sources.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-docs-1.26.7-1.el10_2.noarch</title>
      <pubDate>Wed, 26 Aug 2026 02:38:18 PM GMT</pubDate>
      <guid isPermaLink="false">f21699f1e3057fe1c6799c980badf82cf29126a5613849b3dcf1925e2e8a6236</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-docs-1.26.7-1.el10_2.noarch.rpm</link>
      <description><p><strong>golang-docs</strong> - Golang compiler docs&lt;br /&gt;</p>

<p>Golang compiler docs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-race-1.26.7-1.el10_2.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 02:38:16 PM GMT</pubDate>
      <guid isPermaLink="false">b0aded533753f7c9f877c17f9332b6dcecb80100390cdea10994a5708c9e3d7f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-race-1.26.7-1.el10_2.aarch64.rpm</link>
      <description><p><strong>golang-race</strong> - Race detetector library object files.&lt;br /&gt;</p>

<p>Binary library objects for Go's race detector.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-bin-1.26.7-1.el10_2.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 02:38:16 PM GMT</pubDate>
      <guid isPermaLink="false">62e566f6a0d2f43b8a6072a35578b11c70ad140e60f6291547348c4198cdc3eb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-bin-1.26.7-1.el10_2.aarch64.rpm</link>
      <description><p><strong>golang-bin</strong> - Golang core compiler tools&lt;br /&gt;</p>

<p>Golang core compiler tools</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>golang-1.26.7-1.el10_2.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 02:38:16 PM GMT</pubDate>
      <guid isPermaLink="false">de085fb28e59fec97f82f906635ed8baf0997b84a70856bf4784a872da485678</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/golang-1.26.7-1.el10_2.aarch64.rpm</link>
      <description><p><strong>golang</strong> - The Go Programming Language&lt;br /&gt;</p>

<p>The Go Programming Language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>go-toolset-1.26.7-1.el10_2.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 02:38:16 PM GMT</pubDate>
      <guid isPermaLink="false">91de68baadfe9bcfdba20f293fa48930199fa45ed7febcfd27bfa60a60960582</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/go-toolset-1.26.7-1.el10_2.aarch64.rpm</link>
      <description><p><strong>go-toolset</strong> - Package that installs go-toolset&lt;br /&gt;</p>

<p>This is the main package for go-toolset.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 21 Aug 2026 GMT - Archana &amp;lt;aravinda@redhat.com&amp;gt; - 1.26.7-1
- Update to Go 1.26.7 (fips-1)

Wed, 08 Jul 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.26.5-1
- Update to Go 1.26.5 (fips-1)

Thu, 12 Feb 2026 GMT - dbenoit &amp;lt;dbenoit@redhat.com&amp;gt; - 1.25.7-1
- Update to Go 1.25.7 (fips-1)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-tools-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">43b0cb2dcddc9327868cccadd20735eda0a3fb8eb931a43573510d09469885c7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-tools-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>httpd-tools</strong> - Tools for use with the Apache HTTP Server&lt;br /&gt;</p>

<p>The httpd-tools package contains tools which can be used with&lt;br /&gt;
the Apache HTTP Server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-devel-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">3344d0200917a455e4e79d4bf861b9b6d7af5a0e44b0930b12f95ab72197d37d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-devel-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>httpd-devel</strong> - Development interfaces for the Apache HTTP Server&lt;br /&gt;</p>

<p>The httpd-devel package contains the APXS binary and other files&lt;br /&gt;
that you need to build Dynamic Shared Objects (DSOs) for the&lt;br /&gt;
Apache HTTP Server.&lt;br /&gt;
&lt;br /&gt;
If you are installing the Apache HTTP Server and you want to be&lt;br /&gt;
able to compile or develop additional modules for Apache, you need&lt;br /&gt;
to install this package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-core-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">e40a44f35bd0b36f0e09a5af86c7a8fdb72962c0e3752ba6abeba478f959fee0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-core-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>httpd-core</strong> - httpd minimal core&lt;br /&gt;</p>

<p>The httpd-core package contains essential httpd binaries.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">4ac77c12b6d4df471899b660c1a08a07061a40cfeb94e39ab8fc8f649c1c9e36</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>httpd</strong> - Apache HTTP Server&lt;br /&gt;</p>

<p>The Apache HTTP Server is a powerful, efficient, and extensible&lt;br /&gt;
web server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mod_ssl-1:2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">91b64f732cb26c159c6134b48dcedcea45d56d71ca25a3ef33197e83425f8e12</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mod_ssl-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>mod_ssl</strong> - SSL/TLS module for the Apache HTTP Server&lt;br /&gt;</p>

<p>The mod_ssl module provides strong cryptography for the Apache HTTP&lt;br /&gt;
server via the Secure Sockets Layer (SSL) and Transport Layer&lt;br /&gt;
Security (TLS) protocols.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mod_session-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">c0f6649aaa6f4e898ec82c664136ca1df72caa5434836c7127567ba9db752cde</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mod_session-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>mod_session</strong> - Session interface for the Apache HTTP Server&lt;br /&gt;</p>

<p>The mod_session module and associated backends provide an abstract&lt;br /&gt;
interface for storing and accessing per-user session data.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mod_proxy_html-1:2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">ebf0508ef5eeec97ac19dedb70ed55fe697c360f9136bec2a2b29d6e7044b1c6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mod_proxy_html-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>mod_proxy_html</strong> - HTML and XML content filters for the Apache HTTP Server&lt;br /&gt;</p>

<p>The mod_proxy_html and mod_xml2enc modules provide filters which can&lt;br /&gt;
transform and modify HTML and XML content.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mod_lua-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">17d933c73c1343249372030d261f725b720ba5384110f5c086754075669d1e93</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mod_lua-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>mod_lua</strong> - Lua scripting support for the Apache HTTP Server&lt;br /&gt;</p>

<p>The mod_lua module allows the server to be extended with scripts&lt;br /&gt;
written in the Lua programming language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mod_ldap-2.4.63-13.el10_2.6.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 09:52:06 AM GMT</pubDate>
      <guid isPermaLink="false">e8819947f708582f486b33bfd02b5e2da1fce6fd4f37e15818d42ce660148333</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mod_ldap-2.4.63-13.el10_2.6.aarch64.rpm</link>
      <description><p><strong>mod_ldap</strong> - LDAP authentication modules for the Apache HTTP Server&lt;br /&gt;</p>

<p>The mod_ldap and mod_authnz_ldap modules add support for LDAP&lt;br /&gt;
authentication to the Apache HTTP Server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-manual-2.4.63-13.el10_2.6.noarch</title>
      <pubDate>Wed, 26 Aug 2026 09:52:04 AM GMT</pubDate>
      <guid isPermaLink="false">2a9af9614debda58ddc105f72636f1f8b89bfa715b1b568e3d6ec5a3dc3b6611</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-manual-2.4.63-13.el10_2.6.noarch.rpm</link>
      <description><p><strong>httpd-manual</strong> - Documentation for the Apache HTTP Server&lt;br /&gt;</p>

<p>The httpd-manual package contains the complete manual and&lt;br /&gt;
reference guide for the Apache HTTP Server. The information can&lt;br /&gt;
also be found at https://httpd.apache.org/docs/2.4/.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>httpd-filesystem-2.4.63-13.el10_2.6.noarch</title>
      <pubDate>Wed, 26 Aug 2026 09:52:04 AM GMT</pubDate>
      <guid isPermaLink="false">a5ba7f194b23d9909332627be60c3fd9085e7dcad396ba94ca35ef98a7d15dc1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/httpd-filesystem-2.4.63-13.el10_2.6.noarch.rpm</link>
      <description><p><strong>httpd-filesystem</strong> - The basic directory layout for the Apache HTTP Server&lt;br /&gt;</p>

<p>The httpd-filesystem package contains the basic directory layout&lt;br /&gt;
for the Apache HTTP Server including the correct permissions&lt;br /&gt;
for the directories.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.6
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
  or denial of service via use-after-free in mod_ldap per-directory
  configuration (CVE-2026-29167)

Thu, 09 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.5
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

Tue, 23 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2.4.63-13.4
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
  mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
  crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for 
  CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
  request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.8.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 08:39:02 AM GMT</pubDate>
      <guid isPermaLink="false">cdfeced1c8f44ba792084e43fc3901f3133319a071eb85c7bda8a6743c56d687</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-good-gtk-1.26.7-2.el10_2.8.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-good-gtk</strong> - GStreamer "good" plugins gtk plugin&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of elements which&lt;br /&gt;
operate on media data.&lt;br /&gt;
&lt;br /&gt;
GStreamer Good Plugins is a collection of well-supported plugins of&lt;br /&gt;
good quality and under the LGPL license.&lt;br /&gt;
&lt;br /&gt;
This package (gstreamer1-plugins-good-gtk) contains the gtksink output plugin.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.8
- Fix use-after-free vulnerability in RTP SBC depayloader
  (CVE-2026-18299)
  Resolves: RHEL-246613

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.7
- Fix CVE-2026-18298 in gdkpixbufdec element
  Resolves: RHEL-246557

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.6
- Fix insufficient size validation in MRF file parsing in qtmoovrecover
  (CVE-2026-18296)
  Resolves: RHEL-246546

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-good-1.26.7-2.el10_2.8.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 08:39:02 AM GMT</pubDate>
      <guid isPermaLink="false">749d628435155face06e0fdde0e2ea3c69c11e3c98eaa041ee00f9c13a89c214</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-good-1.26.7-2.el10_2.8.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-good</strong> - GStreamer plugins with good code and licensing&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of filters which&lt;br /&gt;
operate on media data. Applications using this library can do anything&lt;br /&gt;
from real-time sound processing to playing videos, and just about anything&lt;br /&gt;
else media-related.  Its plugin-based architecture means that new data&lt;br /&gt;
types or processing capabilities can be added simply by installing new&lt;br /&gt;
plugins.&lt;br /&gt;
&lt;br /&gt;
GStreamer Good Plugins is a collection of well-supported plugins of&lt;br /&gt;
good quality and under the LGPL license.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 25 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.8
- Fix use-after-free vulnerability in RTP SBC depayloader
  (CVE-2026-18299)
  Resolves: RHEL-246613

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.7
- Fix CVE-2026-18298 in gdkpixbufdec element
  Resolves: RHEL-246557

Sat, 22 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.6
- Fix insufficient size validation in MRF file parsing in qtmoovrecover
  (CVE-2026-18296)
  Resolves: RHEL-246546

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>polkit-docs-125-4.el10_2.1.noarch</title>
      <pubDate>Wed, 26 Aug 2026 08:38:33 AM GMT</pubDate>
      <guid isPermaLink="false">579538c64ce479848051fdf53b81ea952437bfe4f71817f7651be1935a06aea0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/polkit-docs-125-4.el10_2.1.noarch.rpm</link>
      <description><p><strong>polkit-docs</strong> - Development documentation for polkit&lt;br /&gt;</p>

<p>Development documentation for polkit.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 125-4.1
- NOTICE (jrybar): the record 125-4 below was added in manually after Ymir's initial
- commit 125-3.1. For some reason, 125-3.1 for rhel-10.2 was based on contents
- of rhel-10.0 release instead of version 125-4 present in rhel-10.1.
- Fix CVE-2026-4897: string overflow in polkit agent helper
  Resolves: RHEL-218025

Tue, 12 Aug 2025 GMT - Jan Rybar &amp;lt;jrybar@redhat.com&amp;gt; - 125-4
- changing log level via dbus is now restricted to root
- backport of https://github.com/polkit-org/polkit/commit/5a4ba7dfdcc3f

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 125-3
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>polkit-devel-125-4.el10_2.1.aarch64</title>
      <pubDate>Wed, 26 Aug 2026 08:38:29 AM GMT</pubDate>
      <guid isPermaLink="false">f898d6d48af0ee8e15e88771a4fd2043aa9d00b07df07fb62aee1c54722d89e5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/polkit-devel-125-4.el10_2.1.aarch64.rpm</link>
      <description><p><strong>polkit-devel</strong> - Development files for polkit&lt;br /&gt;</p>

<p>Development files for polkit.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 125-4.1
- NOTICE (jrybar): the record 125-4 below was added in manually after Ymir's initial
- commit 125-3.1. For some reason, 125-3.1 for rhel-10.2 was based on contents
- of rhel-10.0 release instead of version 125-4 present in rhel-10.1.
- Fix CVE-2026-4897: string overflow in polkit agent helper
  Resolves: RHEL-218025

Tue, 12 Aug 2025 GMT - Jan Rybar &amp;lt;jrybar@redhat.com&amp;gt; - 125-4
- changing log level via dbus is now restricted to root
- backport of https://github.com/polkit-org/polkit/commit/5a4ba7dfdcc3f

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 125-3
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pam-devel-1.6.1-9.el10_2.1.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:28:50 PM GMT</pubDate>
      <guid isPermaLink="false">c34c998ab3a5abc9b277be1c27ade8b5fcbb4ae6353f2ace028666de7e463d8a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pam-devel-1.6.1-9.el10_2.1.aarch64.rpm</link>
      <description><p><strong>pam-devel</strong> - Files needed for developing PAM-aware applications and modules for PAM&lt;br /&gt;</p>

<p>PAM (Pluggable Authentication Modules) is a system security tool that&lt;br /&gt;
allows system administrators to set authentication policy without&lt;br /&gt;
having to recompile programs that handle authentication. This package&lt;br /&gt;
contains header files used for building both PAM-aware applications&lt;br /&gt;
and modules for use with the PAM system.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 12 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.6.1-9.1
- pam_userdb: fix password comparison timing leak.
  Resolves: CVE-2026-54411 and RHEL-191704

Mon, 01 Dec 2025 GMT - Iker Pedrosa &amp;lt;ipedrosa@redhat.com&amp;gt; - 1.6.1-9
- pam_faillock: skip clearing user's failed attempt.
  Resolves: RHEL-130871

Tue, 01 Jul 2025 GMT - Iker Pedrosa &amp;lt;ipedrosa@redhat.com&amp;gt; - 1.6.1-8
- pam_namespace: fix potential privilege escalation.
  Resolves: CVE-2025-6020 and RHEL-101174

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>amd-gpu-firmware-20260804-23.2.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:25:47 PM GMT</pubDate>
      <guid isPermaLink="false">91a245b01c5f9fc45e5b916294ddac9545e25cc7bce2e79651bb3fb5848b8be5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/amd-gpu-firmware-20260804-23.2.el10_2.noarch.rpm</link>
      <description><p><strong>amd-gpu-firmware</strong> - Firmware for AMD GPUs&lt;br /&gt;</p>

<p>Firmware for AMD amdgpu and radeon GPUs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260804-23.2
- Update linux-firmware to latest upstream (RHEL-214057)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- linux-firmware: Add firmware binary files for new HP project (Messi)
- qcom: Add gpu firmwares for Eliza chipset
- cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
- rtw89: 8922d: add fw 0.35.113.2
- qcom: venus-5.4: fix vp9 decoder assertion failure
- qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
- qcom: Update qdsp6sw firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- intel_vpu: Update NPU firmware
- qcom: Update DSP firmware for qcs8300 platform
- linux-firmware: Add firmware for new soundwire projects
- rtw88: add firmware v41.0.0 for RTL8723B
- linux-firmware: Update AMD cpu microcode
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- amdgpu: DMCUB updates for various ASICs
- amdgpu: DMCUB updates for various ASICs
- qcom: add ADSP firmware for hawi platform
- powervr: add firmware for Imagination Technologies BXM-4-64 GPU
- qcom: Update DSP firmware for sa8775p platform
Resolves: RHEL-214057

Tue, 07 Jul 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260707-23.1
- Update linux-firmware to latest upstream (RHEL-188389)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- xe: Release GuC firmware for NVL-S
- cirrus: cs35l56: Update firmware for the ASUS UX5406SA
- qcom: vpu: add Gen2 firmware binary for Purwa
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
- iwlwifi: add Bz/Sc FW for core24.60-33 release
- iwlwifi: Add Hr/Gf firmware for core24.60-33 release
- iwlwifi: update ty/So/Ma firmwares for core24.60-33 release
- iwlwifi: update cc/Qu/QuZ firmwares for core24.60-33 release
- cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
- docs: address feedback on LICENSE-CRITERIA.md
- Adjust statement on existing firmware
- docs: add LICENSE-CRITERIA.md as project licensing policy
- ueagle-atm: sadly drop unlicensed files
- linux-firmware: qcom: sync audioreach firmwares from v1.0.4 build
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware for new projects
- rtw89: 8852a: add TX power track R34
- linux-firmware: Update AMD SEV firmware
- nxp: add firmware for IW61x WiFi device
- mediatek MT7922: update bluetooth firmware to 20260605203811
- mediatek MT7925: update bluetooth firmware to 20260605184935
- linux-firmware: update firmware for MT7925 WiFi device
- linux-firmware: update firmware for MT7922 WiFi device
- amdgpu: DMCUB updates for various ASICs
- qcom: add LPAICP firmware for shikra platform
- qcom: Add qdsp6sw firmware for shikra platform
- linux-firmware: update firmware for MT7986
- linux-firmware: update firmware for MT7981
- linux-firmware: update firmware for MT7996
- linux-firmware: update firmware for MT7992
- linux-firmware: update firmware for MT7990
- qcom: Update ADSP firmware for Kaanapali platform
- qcom: update ADSP firmware for glymur platform
- qcom: update CDSP firmware for glymur platform
- QCA: Add bluetooth firmware nvm files for USI/NFA725B
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- qcom: update ADSP firmware for qcs615 platform
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- rtl_bt: Update RTL8852A BT USB firmware to 0x244F_91B6
- realtek: rt1321: Update the patch code to v1.10
- amdgpu: DMCUB updates for various ASICs
- QCA: Update Bluetooth WCN3950 firmware 1.3.0-00108 to 1.3.0-00184
- qcom: update CDSP firmware for shikra platform
- qcom: Update ADSP firmware for Glymur platform
- Remove any files with unknown licenses
- AGENTS.md, README: address second round of MR review
- README: document AI assisted contribution convention
- AGENTS.md: clarify areas raised in MR review
- Add AGENTS.md for AI coding agents
- LICENSES: update GPL-2.0 text and references
- LICENSES: rename GPL-3 to GPL-3.0-only
- LICENSES: rename Apache-2 to Apache-2.0
- Move firmware licenses to a LICENSES/ directory
- qcom: update ADSP firmware for sm8750 platform
Resolves: RHEL-188389

Tue, 09 Jun 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260609-23
- Update linux-firmware to latest upstream (RHEL-179828)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00666 to 2.1.0-00669
- qcom: Update DSP firmware for qcs8300 platform
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: Update DMCUB fw for DCN314
- amdgpu: revert yellow carp VCN firmware
- amdgpu: revert vangogh VCN firmware
- amdgpu: revert sienna cichlid VCN firmware
- amdgpu: revert navy flounder VCN firmware
- amdgpu: revert dimgrey cavefish VCN firmware
- amdgpu: revert beige_goby VCN firmware
- qcom: update CDSP firmware for x1e80100 platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Dell laptop
- linux-firmware: Add RCA firmware files for tas257x projects
- intel_vpu: Update NPU firmware
- cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for various Dell laptops
- cirrus: cs35l56: Update firmware for Cirrus Amps for a couple of Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Lenovo laptop
- QCA: Add BCS calibration binary for QCC2072
- QCA: Update Bluetooth firmware for QCC2072 UART interface
- amdgpu: DMCUB updates for various ASICs
- rtl_nic: add firmware rtl8261c.bin for RTL8261c
- cirrus: cs35l56: Add Cirrus CS35L56 firmware mappings for two Dell laptops
- i915: Xe3LPD DMC v2.36
- i915: Xe3LPD_3002 DMC v2.31
- i915: Xe3p_LPD DMC v2.37
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Lenovo laptops
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Lenovo laptops
- qcom: Add gpu firmwares for Shikra chipset
- cirrus: cs35l56: Update firmware for Cirrus Amps for some Dell laptops
- rtw89: 8852b: update fw to v0.29.29.18
- rtw89: 8852bt: update fw to v0.29.122.2
- amdgpu: Update gc 11.0.1 microcode
- ASoC: tas2783: Add Firmware files for tas2783A projects
- linux-firmware: add firmware for MT7927 WiFi device
- Add HP ISH firmware for Intel Panther Lake systems
- ti: Add PCM6240 firmware with multiple audio profiles support
- qcom: add CDSP firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- qcom: update ADSP firmware for x1e80100 platform
- lt*_fw.bin: move to Lontium subdir
- qcom: Add cdsp1r.jsn for sa8775p platform
- amdgpu: rembrandt DMCUB v4.0.74.0
- linux-firmware: Add firmware for Lontium LT9611C
- xe: Update GUC to v70.65.0 for LNL, BMG, PTL
- amdgpu: update SMU 14.0.3 kicker firmware
- amdgpu: update navy flounder firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.3 firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update VCN 3.1.2 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update navi14 firmware
- amdgpu: update SDMA 6.0.3 firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update navi12 firmware
- amdgpu: update vangogh firmware
- amdgpu: update navi10 firmware
- amdgpu: update green sardine firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update SDMA 6.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 4.4.4 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- amdgpu: update SDMA 4.4.5 firmware
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update VPE 6.1.1 firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update beige goby firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update SDMA 4.4.2 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update renoir firmware
- amdgpu: update aldebaran firmware
- rtl_bt: Add missing rtl8761a_config.bin for RTL8761AU
- amdgpu: DMCUB updates for various ASICs
- Linux-firmware: Add Dell ISH firmware 581.7783.0 for Intel Panther Lake systems.
- qcom: update ADSP firmware for x1e80100 platform
- linux-firmware:Add firmware for Lontium LT7911EXC bridge
- qcom/x1e80100/dell: mark that qcom/NOTICE.txt is applicable too
- qcom: Update CDSP firmware for Kaanapali platform
- qcom: vpu: add Gen2 firmware binary for Agatti
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarI core
- qcom: Update ADSP firmware for Glymur platform
- mediatek MT7925: update bluetooth firmware to 20260414153243
- linux-firmware: update firmware for MT7925 WiFi device
- Revert "linux-firmware: Update firmware file for Intel Quasar core"
- qcom: Add gpdspr.jsn for qcs8300 platform
- ath12k: QCC2072 hw1.0: add to WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1
- ath12k: QCC2072 hw1.0: add board-2.bin
- ath12k: IPQ5424 hw1.0: add to WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
- ath12k: IPQ5424 hw1.0: add board-2.bin
- qcom: Update ADSP firmware for Kaanapali platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops (17aa235c 17aa235d)
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00665 to 2.1.0-00666
- amdgpu: DMCUB updates for DCN36
- linux-firmware: Update AMD cpu microcode
- powervr: update Imagination Rogue firmware images
- qcom: Update ADSP firmware for Kaanapali platform
- i915: Xe3LPD DMC v2.34
- i915: Xe3LPD_3002 DMC v2.29
- qcom: Update ADSP firmware for QCM6490 platform
- firmware/amdgpu: Update DMCUB fw to Release 0.1.55.0
- mediatek: vpu: drop old sym link
- amdgpu: Revert Yellow Carp DMUB fw to 0x4000045
- linux-firmware: qcom: sync audioreach firmwares from v1.0.3 build
- qcom: consolidate audioreach-tplg firmwares into one location in WHENCE
- WHENCE: Fix ISH firmware symlink prefix for Lenovo PTL systems
- intel_vpu: Update NPU firmware
- Revert "rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673"
- nvidia: add acr/bl symlink for booting GSP-RM on GA100
- qcom: add QUPv3 firmware for shikra
- xe: Update GUC to v70.60.0 for LNL, BMG, PTL
- qcom: update ADSP firmware for sm8750 platform
- qcom: update CDSP firmware for glymur platform
- cirrus: cs35l41: Add support for new HP laptops
- cirrus: cs35l41: Add support for new ASUS laptops
- cirrus: cs35l41: Add support for ASUS GZ302EAC and add 15.5dB bincfg
- WHENCE: Move Dell remoteproc firmware to correct section
- qcom: vpu: add video firmware for SM8450
- cirrus: cs35l56: Add firmware for Cirrus Amps for some ASUS laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- iwlwifi: add Bz/Sc FW for core103-40 release
- iwlwifi: Add Hr/Gf firmware for core103-40 release
- iwlwifi: update ty/So/Ma firmwares for core103-40 release
- amdgpu: DMCUB updates for various ASICs
- xe: Update PTL GSC to v105.0.2.1397
- linux-firmware: add firmware for Moxa mux50u devices
- rtl_bt: Update RTL8852B BT USB FW to 0x127C_FD78
- ath11k: WCN6855 hw2.0@nfa765: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- linux-firmware: update firmware for qat_4xxx devices
- linux-firmware: update firmware for qat_402xx devices
- linux-firmware: update firmware for qat_420xx devices
- linux-firmware: update firmware for an8811hb 2.5G ethernet phy
- linux-firmware: qcom: Add FW blobs for DELL XPS13 9345
- amdgpu: DMCUB updates for various ASICs
- cirrus: cs35l63: Update firmware for Cirrus Amps for some Dell laptops
- cirrus: cs35l63: Fix Cirrus Amp firmware links for some Dell laptops
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- iwlwifi: add Bz/Wh FW for core102-56 release
- ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
- mediatek MT7921: update bluetooth firmware to 20260224111243
- mediatek MT7920: update bluetooth firmware to 20260224111231
- Add LENOVO ISH firmware v5.8.1.7720 for X1 Carbon (Gen 14) and X1 2-in-1 (Gen 11)
- linux-firmware: Add ISH firmware file for Intel Wildcat Lake platform
- linux-firmware: update firmware for MT7920 WiFi device
- linux-firmware: update firmware for MT7921 WiFi device
- linux-firmware: Update firmware file for Intel Quasar core
- Intel Bluetooth: Update firmware file for Intel Bluetooth AX201
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarIGfP core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- intel_vpu: Update NPU firmware
- amdgpu: DMCUB updates for various ASICs
- qcom: add QUPv3 firmware for QCS615 platform
- Add LENOVO ISH firmware v5.8.0.7720 for X9-15 2025
- mediatek MT7922: update bluetooth firmware to 20260224103448
- linux-firmware: update firmware for MT7922 WiFi device
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- cirrus: cs35l63: Add firmware for Cirrus CS35L63 for various Dell laptops
- linux-firmware: Remove duplicate fw and Rename Lenovo ISH LNLM firmware files accordingly
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00069
- qcom: Update CDSP firmware for QCM6490 platform
- linux-firmware: add firmware for Lontium LT8713SX DP hub
- linux-firmware: qcom: sync audioreach firmwares from v1.0.2 build
- qcom: update ADSP, CDSP firmware for sm8750  platform
- qcom: update ADSP dtb.mbn for glymur platform
- qca: Update Bluetooth WCN6750 1.1.3-00105 firmware to 1.1.3-00106
-  QCA: Update Bluetooth WCN6856 firmware 2.1.0-00659 to 2.1.0-00665
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update GC 9.4.4 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update beige goby firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update vangogh firmware
- amdgpu: update navy flounder firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update navi14 firmware
- amdgpu: update green sardine firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update SMU 14.0.3 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update navi12 firmware
- amdgpu: update SMU 14.0.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update renoir firmware
- amdgpu: update navi10 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- amdnpu: Restore old NPU firmware for compatibility
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- lenovo: remove obsolete ish_lnlm_53c4ffad_2a17559f.bin firmware
- linux-firmware: update firmware for MT7902 BT device
- linux-firmware: update firmware for MT7902 WiFi device
- qcom: vpu: fix SC7280 VPU Gen2 firmware and add compatibility symlink
- amdgpu: DMCUB updates for various ASICs
- qcom: Update DSP firmware for qcs8300 platform
- cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: DMCUB updates for various ASICs
- rtw89: 8851b: add format-1 for fw v0.29.41.5 with fw elements
- rtw89: 8852a: add format-1 for fw v0.13.36.2 with fw elements
- rtw89: 8852bt: add regd and diag_mac and update txpwr to R09
- rtw89: 8852b: update txpwr element to R43
- rtw89: 8852b: add format-2 with v0.29.29.15 and fw elements
- Revert "rtw89: 8852b: update fw to v0.29.128.0 with format suffix -2"
- xe: Update GUC to v70.58.0 for LNL, BMG, PTL
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6390 hw2.0: update board-2.bin
- qcom: Add gpu firmwares for Glymur chipset
- amdgpu: DMCUB updates for various ASICs
- qcom: vpu: add video firmware for Glymur
- qcom: add QUPv3 firmware for x1e80100 platform
- Bluetooth: Add symbolic links for Intel Solar JfP2/1 firmware variants
- Bluetooth: Add symbolic links for Intel Solar firmware variants
- Bluetooth: Add symbolic links for Intel Pulsar firmware variants
- Bluetooth: Add symbolic links for Intel AX201 firmware variants
- ath10k: WCN3990 hw1.0: update board-2.bin
- qcom: add ADSP, CDSP firmware for glymur platform
- ASoC: tas2783: Add Firmware files for tas2783A
- linux-firmware: Update firmware file for Intel Solar core
- mediatek MT7921: update bluetooth firmware to 20251223091725
- rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673
- ath12k: WCN7850 hw2.0: update board-2.bin
- ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6698AQ hw2.1: update board-2.bin
- WHENCE: Correct 2 trailing whitespaces
- linux-firmware: Add firmware for airoha-npu-7581 driver used for MT7990 offloading
- linux-firmware: Add Dell ISH firmware for Intel panther lake systems
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: update Aeonsemi AS21x1x firmware to 1.9.1
- rtl_nic: add firmware rtl8125cp-1 for RTL8125cp
- ice: update DDP LAG package to 1.3.2.0
- cirrus: cs35l56: Add WHENCE links for 17aa233c spkid0 firmware
- rtw89: 8922a: update REGD R73-R08, txpwr R46 and element of diag MAC
- rtw89: 8852c: update REGD R73-R60, txpwr R82 and element of diag MAC
- Update firmware for NPU PHX, STX and STX HALO
- qcom: Update ADSP and add CDSP firmware for qcs6490-radxa-dragon-q6a
- qcom: Remove ADSP SensorPD json for Radxa Dragon Q6A
- amdgpu: DMCUB updates for various ASICs
Resolves: RHEL-179828

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>intel-gpu-firmware-20260804-23.2.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:25:47 PM GMT</pubDate>
      <guid isPermaLink="false">221221b40be598d047d2fa8cddebd5459a152e201f7108ac45903f2aa922786b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/intel-gpu-firmware-20260804-23.2.el10_2.noarch.rpm</link>
      <description><p><strong>intel-gpu-firmware</strong> - Firmware for Intel GPUs&lt;br /&gt;</p>

<p>Firmware for Intel GPUs including GuC (Graphics Microcontroller), HuC (HEVC/H.265&lt;br /&gt;
Microcontroller) and DMC (Display Microcontroller) firmware for Skylake and later&lt;br /&gt;
platforms.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260804-23.2
- Update linux-firmware to latest upstream (RHEL-214057)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- linux-firmware: Add firmware binary files for new HP project (Messi)
- qcom: Add gpu firmwares for Eliza chipset
- cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
- rtw89: 8922d: add fw 0.35.113.2
- qcom: venus-5.4: fix vp9 decoder assertion failure
- qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
- qcom: Update qdsp6sw firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- intel_vpu: Update NPU firmware
- qcom: Update DSP firmware for qcs8300 platform
- linux-firmware: Add firmware for new soundwire projects
- rtw88: add firmware v41.0.0 for RTL8723B
- linux-firmware: Update AMD cpu microcode
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- amdgpu: DMCUB updates for various ASICs
- amdgpu: DMCUB updates for various ASICs
- qcom: add ADSP firmware for hawi platform
- powervr: add firmware for Imagination Technologies BXM-4-64 GPU
- qcom: Update DSP firmware for sa8775p platform
Resolves: RHEL-214057

Tue, 07 Jul 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260707-23.1
- Update linux-firmware to latest upstream (RHEL-188389)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- xe: Release GuC firmware for NVL-S
- cirrus: cs35l56: Update firmware for the ASUS UX5406SA
- qcom: vpu: add Gen2 firmware binary for Purwa
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
- iwlwifi: add Bz/Sc FW for core24.60-33 release
- iwlwifi: Add Hr/Gf firmware for core24.60-33 release
- iwlwifi: update ty/So/Ma firmwares for core24.60-33 release
- iwlwifi: update cc/Qu/QuZ firmwares for core24.60-33 release
- cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
- docs: address feedback on LICENSE-CRITERIA.md
- Adjust statement on existing firmware
- docs: add LICENSE-CRITERIA.md as project licensing policy
- ueagle-atm: sadly drop unlicensed files
- linux-firmware: qcom: sync audioreach firmwares from v1.0.4 build
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware for new projects
- rtw89: 8852a: add TX power track R34
- linux-firmware: Update AMD SEV firmware
- nxp: add firmware for IW61x WiFi device
- mediatek MT7922: update bluetooth firmware to 20260605203811
- mediatek MT7925: update bluetooth firmware to 20260605184935
- linux-firmware: update firmware for MT7925 WiFi device
- linux-firmware: update firmware for MT7922 WiFi device
- amdgpu: DMCUB updates for various ASICs
- qcom: add LPAICP firmware for shikra platform
- qcom: Add qdsp6sw firmware for shikra platform
- linux-firmware: update firmware for MT7986
- linux-firmware: update firmware for MT7981
- linux-firmware: update firmware for MT7996
- linux-firmware: update firmware for MT7992
- linux-firmware: update firmware for MT7990
- qcom: Update ADSP firmware for Kaanapali platform
- qcom: update ADSP firmware for glymur platform
- qcom: update CDSP firmware for glymur platform
- QCA: Add bluetooth firmware nvm files for USI/NFA725B
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- qcom: update ADSP firmware for qcs615 platform
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- rtl_bt: Update RTL8852A BT USB firmware to 0x244F_91B6
- realtek: rt1321: Update the patch code to v1.10
- amdgpu: DMCUB updates for various ASICs
- QCA: Update Bluetooth WCN3950 firmware 1.3.0-00108 to 1.3.0-00184
- qcom: update CDSP firmware for shikra platform
- qcom: Update ADSP firmware for Glymur platform
- Remove any files with unknown licenses
- AGENTS.md, README: address second round of MR review
- README: document AI assisted contribution convention
- AGENTS.md: clarify areas raised in MR review
- Add AGENTS.md for AI coding agents
- LICENSES: update GPL-2.0 text and references
- LICENSES: rename GPL-3 to GPL-3.0-only
- LICENSES: rename Apache-2 to Apache-2.0
- Move firmware licenses to a LICENSES/ directory
- qcom: update ADSP firmware for sm8750 platform
Resolves: RHEL-188389

Tue, 09 Jun 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260609-23
- Update linux-firmware to latest upstream (RHEL-179828)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00666 to 2.1.0-00669
- qcom: Update DSP firmware for qcs8300 platform
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: Update DMCUB fw for DCN314
- amdgpu: revert yellow carp VCN firmware
- amdgpu: revert vangogh VCN firmware
- amdgpu: revert sienna cichlid VCN firmware
- amdgpu: revert navy flounder VCN firmware
- amdgpu: revert dimgrey cavefish VCN firmware
- amdgpu: revert beige_goby VCN firmware
- qcom: update CDSP firmware for x1e80100 platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Dell laptop
- linux-firmware: Add RCA firmware files for tas257x projects
- intel_vpu: Update NPU firmware
- cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for various Dell laptops
- cirrus: cs35l56: Update firmware for Cirrus Amps for a couple of Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Lenovo laptop
- QCA: Add BCS calibration binary for QCC2072
- QCA: Update Bluetooth firmware for QCC2072 UART interface
- amdgpu: DMCUB updates for various ASICs
- rtl_nic: add firmware rtl8261c.bin for RTL8261c
- cirrus: cs35l56: Add Cirrus CS35L56 firmware mappings for two Dell laptops
- i915: Xe3LPD DMC v2.36
- i915: Xe3LPD_3002 DMC v2.31
- i915: Xe3p_LPD DMC v2.37
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Lenovo laptops
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Lenovo laptops
- qcom: Add gpu firmwares for Shikra chipset
- cirrus: cs35l56: Update firmware for Cirrus Amps for some Dell laptops
- rtw89: 8852b: update fw to v0.29.29.18
- rtw89: 8852bt: update fw to v0.29.122.2
- amdgpu: Update gc 11.0.1 microcode
- ASoC: tas2783: Add Firmware files for tas2783A projects
- linux-firmware: add firmware for MT7927 WiFi device
- Add HP ISH firmware for Intel Panther Lake systems
- ti: Add PCM6240 firmware with multiple audio profiles support
- qcom: add CDSP firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- qcom: update ADSP firmware for x1e80100 platform
- lt*_fw.bin: move to Lontium subdir
- qcom: Add cdsp1r.jsn for sa8775p platform
- amdgpu: rembrandt DMCUB v4.0.74.0
- linux-firmware: Add firmware for Lontium LT9611C
- xe: Update GUC to v70.65.0 for LNL, BMG, PTL
- amdgpu: update SMU 14.0.3 kicker firmware
- amdgpu: update navy flounder firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.3 firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update VCN 3.1.2 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update navi14 firmware
- amdgpu: update SDMA 6.0.3 firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update navi12 firmware
- amdgpu: update vangogh firmware
- amdgpu: update navi10 firmware
- amdgpu: update green sardine firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update SDMA 6.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 4.4.4 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- amdgpu: update SDMA 4.4.5 firmware
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update VPE 6.1.1 firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update beige goby firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update SDMA 4.4.2 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update renoir firmware
- amdgpu: update aldebaran firmware
- rtl_bt: Add missing rtl8761a_config.bin for RTL8761AU
- amdgpu: DMCUB updates for various ASICs
- Linux-firmware: Add Dell ISH firmware 581.7783.0 for Intel Panther Lake systems.
- qcom: update ADSP firmware for x1e80100 platform
- linux-firmware:Add firmware for Lontium LT7911EXC bridge
- qcom/x1e80100/dell: mark that qcom/NOTICE.txt is applicable too
- qcom: Update CDSP firmware for Kaanapali platform
- qcom: vpu: add Gen2 firmware binary for Agatti
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarI core
- qcom: Update ADSP firmware for Glymur platform
- mediatek MT7925: update bluetooth firmware to 20260414153243
- linux-firmware: update firmware for MT7925 WiFi device
- Revert "linux-firmware: Update firmware file for Intel Quasar core"
- qcom: Add gpdspr.jsn for qcs8300 platform
- ath12k: QCC2072 hw1.0: add to WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1
- ath12k: QCC2072 hw1.0: add board-2.bin
- ath12k: IPQ5424 hw1.0: add to WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
- ath12k: IPQ5424 hw1.0: add board-2.bin
- qcom: Update ADSP firmware for Kaanapali platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops (17aa235c 17aa235d)
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00665 to 2.1.0-00666
- amdgpu: DMCUB updates for DCN36
- linux-firmware: Update AMD cpu microcode
- powervr: update Imagination Rogue firmware images
- qcom: Update ADSP firmware for Kaanapali platform
- i915: Xe3LPD DMC v2.34
- i915: Xe3LPD_3002 DMC v2.29
- qcom: Update ADSP firmware for QCM6490 platform
- firmware/amdgpu: Update DMCUB fw to Release 0.1.55.0
- mediatek: vpu: drop old sym link
- amdgpu: Revert Yellow Carp DMUB fw to 0x4000045
- linux-firmware: qcom: sync audioreach firmwares from v1.0.3 build
- qcom: consolidate audioreach-tplg firmwares into one location in WHENCE
- WHENCE: Fix ISH firmware symlink prefix for Lenovo PTL systems
- intel_vpu: Update NPU firmware
- Revert "rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673"
- nvidia: add acr/bl symlink for booting GSP-RM on GA100
- qcom: add QUPv3 firmware for shikra
- xe: Update GUC to v70.60.0 for LNL, BMG, PTL
- qcom: update ADSP firmware for sm8750 platform
- qcom: update CDSP firmware for glymur platform
- cirrus: cs35l41: Add support for new HP laptops
- cirrus: cs35l41: Add support for new ASUS laptops
- cirrus: cs35l41: Add support for ASUS GZ302EAC and add 15.5dB bincfg
- WHENCE: Move Dell remoteproc firmware to correct section
- qcom: vpu: add video firmware for SM8450
- cirrus: cs35l56: Add firmware for Cirrus Amps for some ASUS laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- iwlwifi: add Bz/Sc FW for core103-40 release
- iwlwifi: Add Hr/Gf firmware for core103-40 release
- iwlwifi: update ty/So/Ma firmwares for core103-40 release
- amdgpu: DMCUB updates for various ASICs
- xe: Update PTL GSC to v105.0.2.1397
- linux-firmware: add firmware for Moxa mux50u devices
- rtl_bt: Update RTL8852B BT USB FW to 0x127C_FD78
- ath11k: WCN6855 hw2.0@nfa765: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- linux-firmware: update firmware for qat_4xxx devices
- linux-firmware: update firmware for qat_402xx devices
- linux-firmware: update firmware for qat_420xx devices
- linux-firmware: update firmware for an8811hb 2.5G ethernet phy
- linux-firmware: qcom: Add FW blobs for DELL XPS13 9345
- amdgpu: DMCUB updates for various ASICs
- cirrus: cs35l63: Update firmware for Cirrus Amps for some Dell laptops
- cirrus: cs35l63: Fix Cirrus Amp firmware links for some Dell laptops
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- iwlwifi: add Bz/Wh FW for core102-56 release
- ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
- mediatek MT7921: update bluetooth firmware to 20260224111243
- mediatek MT7920: update bluetooth firmware to 20260224111231
- Add LENOVO ISH firmware v5.8.1.7720 for X1 Carbon (Gen 14) and X1 2-in-1 (Gen 11)
- linux-firmware: Add ISH firmware file for Intel Wildcat Lake platform
- linux-firmware: update firmware for MT7920 WiFi device
- linux-firmware: update firmware for MT7921 WiFi device
- linux-firmware: Update firmware file for Intel Quasar core
- Intel Bluetooth: Update firmware file for Intel Bluetooth AX201
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarIGfP core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- intel_vpu: Update NPU firmware
- amdgpu: DMCUB updates for various ASICs
- qcom: add QUPv3 firmware for QCS615 platform
- Add LENOVO ISH firmware v5.8.0.7720 for X9-15 2025
- mediatek MT7922: update bluetooth firmware to 20260224103448
- linux-firmware: update firmware for MT7922 WiFi device
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- cirrus: cs35l63: Add firmware for Cirrus CS35L63 for various Dell laptops
- linux-firmware: Remove duplicate fw and Rename Lenovo ISH LNLM firmware files accordingly
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00069
- qcom: Update CDSP firmware for QCM6490 platform
- linux-firmware: add firmware for Lontium LT8713SX DP hub
- linux-firmware: qcom: sync audioreach firmwares from v1.0.2 build
- qcom: update ADSP, CDSP firmware for sm8750  platform
- qcom: update ADSP dtb.mbn for glymur platform
- qca: Update Bluetooth WCN6750 1.1.3-00105 firmware to 1.1.3-00106
-  QCA: Update Bluetooth WCN6856 firmware 2.1.0-00659 to 2.1.0-00665
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update GC 9.4.4 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update beige goby firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update vangogh firmware
- amdgpu: update navy flounder firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update navi14 firmware
- amdgpu: update green sardine firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update SMU 14.0.3 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update navi12 firmware
- amdgpu: update SMU 14.0.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update renoir firmware
- amdgpu: update navi10 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- amdnpu: Restore old NPU firmware for compatibility
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- lenovo: remove obsolete ish_lnlm_53c4ffad_2a17559f.bin firmware
- linux-firmware: update firmware for MT7902 BT device
- linux-firmware: update firmware for MT7902 WiFi device
- qcom: vpu: fix SC7280 VPU Gen2 firmware and add compatibility symlink
- amdgpu: DMCUB updates for various ASICs
- qcom: Update DSP firmware for qcs8300 platform
- cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: DMCUB updates for various ASICs
- rtw89: 8851b: add format-1 for fw v0.29.41.5 with fw elements
- rtw89: 8852a: add format-1 for fw v0.13.36.2 with fw elements
- rtw89: 8852bt: add regd and diag_mac and update txpwr to R09
- rtw89: 8852b: update txpwr element to R43
- rtw89: 8852b: add format-2 with v0.29.29.15 and fw elements
- Revert "rtw89: 8852b: update fw to v0.29.128.0 with format suffix -2"
- xe: Update GUC to v70.58.0 for LNL, BMG, PTL
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6390 hw2.0: update board-2.bin
- qcom: Add gpu firmwares for Glymur chipset
- amdgpu: DMCUB updates for various ASICs
- qcom: vpu: add video firmware for Glymur
- qcom: add QUPv3 firmware for x1e80100 platform
- Bluetooth: Add symbolic links for Intel Solar JfP2/1 firmware variants
- Bluetooth: Add symbolic links for Intel Solar firmware variants
- Bluetooth: Add symbolic links for Intel Pulsar firmware variants
- Bluetooth: Add symbolic links for Intel AX201 firmware variants
- ath10k: WCN3990 hw1.0: update board-2.bin
- qcom: add ADSP, CDSP firmware for glymur platform
- ASoC: tas2783: Add Firmware files for tas2783A
- linux-firmware: Update firmware file for Intel Solar core
- mediatek MT7921: update bluetooth firmware to 20251223091725
- rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673
- ath12k: WCN7850 hw2.0: update board-2.bin
- ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6698AQ hw2.1: update board-2.bin
- WHENCE: Correct 2 trailing whitespaces
- linux-firmware: Add firmware for airoha-npu-7581 driver used for MT7990 offloading
- linux-firmware: Add Dell ISH firmware for Intel panther lake systems
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: update Aeonsemi AS21x1x firmware to 1.9.1
- rtl_nic: add firmware rtl8125cp-1 for RTL8125cp
- ice: update DDP LAG package to 1.3.2.0
- cirrus: cs35l56: Add WHENCE links for 17aa233c spkid0 firmware
- rtw89: 8922a: update REGD R73-R08, txpwr R46 and element of diag MAC
- rtw89: 8852c: update REGD R73-R60, txpwr R82 and element of diag MAC
- Update firmware for NPU PHX, STX and STX HALO
- qcom: Update ADSP and add CDSP firmware for qcs6490-radxa-dragon-q6a
- qcom: Remove ADSP SensorPD json for Radxa Dragon Q6A
- amdgpu: DMCUB updates for various ASICs
Resolves: RHEL-179828

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nvidia-gpu-firmware-20260804-23.2.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:25:47 PM GMT</pubDate>
      <guid isPermaLink="false">9e53425ddfb1ddfa5276cf0f437ff4cc4dfb7421e808edfadd9c2d6b0a3a34f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nvidia-gpu-firmware-20260804-23.2.el10_2.noarch.rpm</link>
      <description><p><strong>nvidia-gpu-firmware</strong> - Firmware for NVIDIA GPUs&lt;br /&gt;</p>

<p>Firmware for NVIDIA GPUs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260804-23.2
- Update linux-firmware to latest upstream (RHEL-214057)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- linux-firmware: Add firmware binary files for new HP project (Messi)
- qcom: Add gpu firmwares for Eliza chipset
- cirrus: cs35l57: Add firmware for Cirrus Amps for some Samsung laptops
- rtw89: 8922d: add fw 0.35.113.2
- qcom: venus-5.4: fix vp9 decoder assertion failure
- qla2xxx: Add ql2900_fw.bin firmware for 29xx adapters
- qcom: Update qdsp6sw firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- intel_vpu: Update NPU firmware
- qcom: Update DSP firmware for qcs8300 platform
- linux-firmware: Add firmware for new soundwire projects
- rtw88: add firmware v41.0.0 for RTL8723B
- linux-firmware: Update AMD cpu microcode
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- amdgpu: DMCUB updates for various ASICs
- amdgpu: DMCUB updates for various ASICs
- qcom: add ADSP firmware for hawi platform
- powervr: add firmware for Imagination Technologies BXM-4-64 GPU
- qcom: Update DSP firmware for sa8775p platform
Resolves: RHEL-214057

Tue, 07 Jul 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260707-23.1
- Update linux-firmware to latest upstream (RHEL-188389)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- xe: Release GuC firmware for NVL-S
- cirrus: cs35l56: Update firmware for the ASUS UX5406SA
- qcom: vpu: add Gen2 firmware binary for Purwa
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- QCA: Add Bluetooth firmware for WCN6855 ROM 1.0
- iwlwifi: add Bz/Sc FW for core24.60-33 release
- iwlwifi: Add Hr/Gf firmware for core24.60-33 release
- iwlwifi: update ty/So/Ma firmwares for core24.60-33 release
- iwlwifi: update cc/Qu/QuZ firmwares for core24.60-33 release
- cirrus: cs35l56: Add firmware for Cirrus Amps for a few Dell laptops
- docs: address feedback on LICENSE-CRITERIA.md
- Adjust statement on existing firmware
- docs: add LICENSE-CRITERIA.md as project licensing policy
- ueagle-atm: sadly drop unlicensed files
- linux-firmware: qcom: sync audioreach firmwares from v1.0.4 build
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00072
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware for new projects
- rtw89: 8852a: add TX power track R34
- linux-firmware: Update AMD SEV firmware
- nxp: add firmware for IW61x WiFi device
- mediatek MT7922: update bluetooth firmware to 20260605203811
- mediatek MT7925: update bluetooth firmware to 20260605184935
- linux-firmware: update firmware for MT7925 WiFi device
- linux-firmware: update firmware for MT7922 WiFi device
- amdgpu: DMCUB updates for various ASICs
- qcom: add LPAICP firmware for shikra platform
- qcom: Add qdsp6sw firmware for shikra platform
- linux-firmware: update firmware for MT7986
- linux-firmware: update firmware for MT7981
- linux-firmware: update firmware for MT7996
- linux-firmware: update firmware for MT7992
- linux-firmware: update firmware for MT7990
- qcom: Update ADSP firmware for Kaanapali platform
- qcom: update ADSP firmware for glymur platform
- qcom: update CDSP firmware for glymur platform
- QCA: Add bluetooth firmware nvm files for USI/NFA725B
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel Scorpius core
- qcom: update ADSP firmware for qcs615 platform
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Dell laptops
- rtl_bt: Update RTL8852A BT USB firmware to 0x244F_91B6
- realtek: rt1321: Update the patch code to v1.10
- amdgpu: DMCUB updates for various ASICs
- QCA: Update Bluetooth WCN3950 firmware 1.3.0-00108 to 1.3.0-00184
- qcom: update CDSP firmware for shikra platform
- qcom: Update ADSP firmware for Glymur platform
- Remove any files with unknown licenses
- AGENTS.md, README: address second round of MR review
- README: document AI assisted contribution convention
- AGENTS.md: clarify areas raised in MR review
- Add AGENTS.md for AI coding agents
- LICENSES: update GPL-2.0 text and references
- LICENSES: rename GPL-3 to GPL-3.0-only
- LICENSES: rename Apache-2 to Apache-2.0
- Move firmware licenses to a LICENSES/ directory
- qcom: update ADSP firmware for sm8750 platform
Resolves: RHEL-188389

Tue, 09 Jun 2026 GMT - Denys Vlasenko &amp;lt;dvlasenk@redhat.com&amp;gt; - 20260609-23
- Update linux-firmware to latest upstream (RHEL-179828)
  Changes since the last update are noted on items below, copied from
  the git changelog of upstream linux-firmware repository.
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00666 to 2.1.0-00669
- qcom: Update DSP firmware for qcs8300 platform
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: Update DMCUB fw for DCN314
- amdgpu: revert yellow carp VCN firmware
- amdgpu: revert vangogh VCN firmware
- amdgpu: revert sienna cichlid VCN firmware
- amdgpu: revert navy flounder VCN firmware
- amdgpu: revert dimgrey cavefish VCN firmware
- amdgpu: revert beige_goby VCN firmware
- qcom: update CDSP firmware for x1e80100 platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Dell laptop
- linux-firmware: Add RCA firmware files for tas257x projects
- intel_vpu: Update NPU firmware
- cirrus: cs35l63: Add Cirrus CS35L63 firmware mappings for various Dell laptops
- cirrus: cs35l56: Update firmware for Cirrus Amps for a couple of Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for a Lenovo laptop
- QCA: Add BCS calibration binary for QCC2072
- QCA: Update Bluetooth firmware for QCC2072 UART interface
- amdgpu: DMCUB updates for various ASICs
- rtl_nic: add firmware rtl8261c.bin for RTL8261c
- cirrus: cs35l56: Add Cirrus CS35L56 firmware mappings for two Dell laptops
- i915: Xe3LPD DMC v2.36
- i915: Xe3LPD_3002 DMC v2.31
- i915: Xe3p_LPD DMC v2.37
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs42l45: Update CS42L45 SDCA codec firmware for Lenovo laptops
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Lenovo laptops
- qcom: Add gpu firmwares for Shikra chipset
- cirrus: cs35l56: Update firmware for Cirrus Amps for some Dell laptops
- rtw89: 8852b: update fw to v0.29.29.18
- rtw89: 8852bt: update fw to v0.29.122.2
- amdgpu: Update gc 11.0.1 microcode
- ASoC: tas2783: Add Firmware files for tas2783A projects
- linux-firmware: add firmware for MT7927 WiFi device
- Add HP ISH firmware for Intel Panther Lake systems
- ti: Add PCM6240 firmware with multiple audio profiles support
- qcom: add CDSP firmware for shikra platform
- amdgpu: DMCUB updates for various ASICs
- qcom: update ADSP firmware for x1e80100 platform
- lt*_fw.bin: move to Lontium subdir
- qcom: Add cdsp1r.jsn for sa8775p platform
- amdgpu: rembrandt DMCUB v4.0.74.0
- linux-firmware: Add firmware for Lontium LT9611C
- xe: Update GUC to v70.65.0 for LNL, BMG, PTL
- amdgpu: update SMU 14.0.3 kicker firmware
- amdgpu: update navy flounder firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.3 firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update VCN 3.1.2 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update navi14 firmware
- amdgpu: update SDMA 6.0.3 firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update navi12 firmware
- amdgpu: update vangogh firmware
- amdgpu: update navi10 firmware
- amdgpu: update green sardine firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update SDMA 6.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 4.4.4 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- amdgpu: update SDMA 4.4.5 firmware
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update VPE 6.1.1 firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update beige goby firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update SDMA 4.4.2 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update renoir firmware
- amdgpu: update aldebaran firmware
- rtl_bt: Add missing rtl8761a_config.bin for RTL8761AU
- amdgpu: DMCUB updates for various ASICs
- Linux-firmware: Add Dell ISH firmware 581.7783.0 for Intel Panther Lake systems.
- qcom: update ADSP firmware for x1e80100 platform
- linux-firmware:Add firmware for Lontium LT7911EXC bridge
- qcom/x1e80100/dell: mark that qcom/NOTICE.txt is applicable too
- qcom: Update CDSP firmware for Kaanapali platform
- qcom: vpu: add Gen2 firmware binary for Agatti
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarI core
- qcom: Update ADSP firmware for Glymur platform
- mediatek MT7925: update bluetooth firmware to 20260414153243
- linux-firmware: update firmware for MT7925 WiFi device
- Revert "linux-firmware: Update firmware file for Intel Quasar core"
- qcom: Add gpdspr.jsn for qcs8300 platform
- ath12k: QCC2072 hw1.0: add to WLAN.COL.1.0.c2-00074-QCACOLSWPL_V1_TO_SILICONZ-1
- ath12k: QCC2072 hw1.0: add board-2.bin
- ath12k: IPQ5424 hw1.0: add to WLAN.WBE.1.6-01275-QCAHKSWPL_SILICONZ-1
- ath12k: IPQ5424 hw1.0: add board-2.bin
- qcom: Update ADSP firmware for Kaanapali platform
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops (17aa235c 17aa235d)
- QCA: Update Bluetooth WCN6856 firmware 2.1.0-00665 to 2.1.0-00666
- amdgpu: DMCUB updates for DCN36
- linux-firmware: Update AMD cpu microcode
- powervr: update Imagination Rogue firmware images
- qcom: Update ADSP firmware for Kaanapali platform
- i915: Xe3LPD DMC v2.34
- i915: Xe3LPD_3002 DMC v2.29
- qcom: Update ADSP firmware for QCM6490 platform
- firmware/amdgpu: Update DMCUB fw to Release 0.1.55.0
- mediatek: vpu: drop old sym link
- amdgpu: Revert Yellow Carp DMUB fw to 0x4000045
- linux-firmware: qcom: sync audioreach firmwares from v1.0.3 build
- qcom: consolidate audioreach-tplg firmwares into one location in WHENCE
- WHENCE: Fix ISH firmware symlink prefix for Lenovo PTL systems
- intel_vpu: Update NPU firmware
- Revert "rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673"
- nvidia: add acr/bl symlink for booting GSP-RM on GA100
- qcom: add QUPv3 firmware for shikra
- xe: Update GUC to v70.60.0 for LNL, BMG, PTL
- qcom: update ADSP firmware for sm8750 platform
- qcom: update CDSP firmware for glymur platform
- cirrus: cs35l41: Add support for new HP laptops
- cirrus: cs35l41: Add support for new ASUS laptops
- cirrus: cs35l41: Add support for ASUS GZ302EAC and add 15.5dB bincfg
- WHENCE: Move Dell remoteproc firmware to correct section
- qcom: vpu: add video firmware for SM8450
- cirrus: cs35l56: Add firmware for Cirrus Amps for some ASUS laptops
- cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
- iwlwifi: add Bz/Sc FW for core103-40 release
- iwlwifi: Add Hr/Gf firmware for core103-40 release
- iwlwifi: update ty/So/Ma firmwares for core103-40 release
- amdgpu: DMCUB updates for various ASICs
- xe: Update PTL GSC to v105.0.2.1397
- linux-firmware: add firmware for Moxa mux50u devices
- rtl_bt: Update RTL8852B BT USB FW to 0x127C_FD78
- ath11k: WCN6855 hw2.0@nfa765: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04866.5-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
- linux-firmware: update firmware for qat_4xxx devices
- linux-firmware: update firmware for qat_402xx devices
- linux-firmware: update firmware for qat_420xx devices
- linux-firmware: update firmware for an8811hb 2.5G ethernet phy
- linux-firmware: qcom: Add FW blobs for DELL XPS13 9345
- amdgpu: DMCUB updates for various ASICs
- cirrus: cs35l63: Update firmware for Cirrus Amps for some Dell laptops
- cirrus: cs35l63: Fix Cirrus Amp firmware links for some Dell laptops
- linux-firmware: Add firmware file for Intel BlazarIW
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- iwlwifi: add Bz/Wh FW for core102-56 release
- ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c7-00108-QCAHMTSWPL_V1.0_V2.0_SILICONZ_UPSTREAM-3
- mediatek MT7921: update bluetooth firmware to 20260224111243
- mediatek MT7920: update bluetooth firmware to 20260224111231
- Add LENOVO ISH firmware v5.8.1.7720 for X1 Carbon (Gen 14) and X1 2-in-1 (Gen 11)
- linux-firmware: Add ISH firmware file for Intel Wildcat Lake platform
- linux-firmware: update firmware for MT7920 WiFi device
- linux-firmware: update firmware for MT7921 WiFi device
- linux-firmware: Update firmware file for Intel Quasar core
- Intel Bluetooth: Update firmware file for Intel Bluetooth AX201
- linux-firmware: Add firmware file for Intel ScorpiusGfp2 core
- linux-firmware: Update firmware file for Intel Scorpius core
- linux-firmware: Update firmware file for Intel BlazarIGfP core
- linux-firmware: Update firmware file for Intel BlazarI core
- linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
- linux-firmware: Update firmware file for Intel BlazarU core
- intel_vpu: Update NPU firmware
- amdgpu: DMCUB updates for various ASICs
- qcom: add QUPv3 firmware for QCS615 platform
- Add LENOVO ISH firmware v5.8.0.7720 for X9-15 2025
- mediatek MT7922: update bluetooth firmware to 20260224103448
- linux-firmware: update firmware for MT7922 WiFi device
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- cirrus: cs35l63: Add firmware for Cirrus CS35L63 for various Dell laptops
- linux-firmware: Remove duplicate fw and Rename Lenovo ISH LNLM firmware files accordingly
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: Add firmware file for Intel BlazarIGfp2 core
- QCA: Update Bluetooth QCA6698 firmware to 2.1.2-00069
- qcom: Update CDSP firmware for QCM6490 platform
- linux-firmware: add firmware for Lontium LT8713SX DP hub
- linux-firmware: qcom: sync audioreach firmwares from v1.0.2 build
- qcom: update ADSP, CDSP firmware for sm8750  platform
- qcom: update ADSP dtb.mbn for glymur platform
- qca: Update Bluetooth WCN6750 1.1.3-00105 firmware to 1.1.3-00106
-  QCA: Update Bluetooth WCN6856 firmware 2.1.0-00659 to 2.1.0-00665
- amdgpu: update PSP 13.0.14 firmware
- amdgpu: update GC 9.4.4 firmware
- amdgpu: update PSP 13.0.5 firmware
- amdgpu: update GC 10.3.6 firmware
- amdgpu: update PSP 13.0.0 kicker firmware
- amdgpu: update VCN 4.0.0 firmware
- amdgpu: update PSP 13.0.0 firmware
- amdgpu: update GC 11.0.0 firmware
- amdgpu: update SDMA 6.1.3 firmware
- amdgpu: update PSP 14.0.5 firmware
- amdgpu: update GC 11.5.3 firmware
- amdgpu: update beige goby firmware
- amdgpu: update SDMA 6.1.2 firmware
- amdgpu: update PSP 14.0.4 firmware
- amdgpu: update GC 11.5.2 firmware
- amdgpu: update dimgrey cavefish firmware
- amdgpu: update vangogh firmware
- amdgpu: update navy flounder firmware
- amdgpu: update PSP 13.0.11 firmware
- amdgpu: update GC 11.0.4 firmware
- amdgpu: update VCN 4.0.2 firmware
- amdgpu: update SDMA 6.0.1 firmware
- amdgpu: update PSP 13.0.4 firmware
- amdgpu: update GC 11.0.1 firmware
- amdgpu: update sienna cichlid firmware
- amdgpu: update navi14 firmware
- amdgpu: update green sardine firmware
- amdgpu: update VCN 4.0.6 firmware
- amdgpu: update SDMA 6.1.1 firmware
- amdgpu: update PSP 14.0.1 firmware
- amdgpu: update GC 11.5.1 firmware
- amdgpu: update VCN 5.0.0 firmware
- amdgpu: update SMU 14.0.3 firmware
- amdgpu: update PSP 14.0.3 firmware
- amdgpu: update GC 12.0.1 firmware
- amdgpu: update VPE 6.1.0 firmware
- amdgpu: update VCN 4.0.5 firmware
- amdgpu: update SDMA 6.1.0 firmware
- amdgpu: update PSP 14.0.0 firmware
- amdgpu: update GC 11.5.0 firmware
- amdgpu: update navi12 firmware
- amdgpu: update SMU 14.0.2 firmware
- amdgpu: update PSP 14.0.2 firmware
- amdgpu: update GC 12.0.0 firmware
- amdgpu: update renoir firmware
- amdgpu: update navi10 firmware
- amdgpu: update VCN 4.0.4 firmware
- amdgpu: update SDMA 6.0.2 firmware
- amdgpu: update PSP 13.0.7 firmware
- amdgpu: update GC 11.0.2 firmware
- amdgpu: update VCN 4.0.3 firmware
- amdgpu: update PSP 13.0.6 firmware
- amdgpu: update GC 9.4.3 firmware
- amdgpu: update yellow carp firmware
- amdgpu: update PSP 13.0.10 firmware
- amdgpu: update GC 11.0.3 firmware
- amdgpu: update VCN 5.0.1 firmware
- amdgpu: update PSP 13.0.12 firmware
- amdgpu: update GC 9.5.0 firmware
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- linux-firmware:Renaming the file back for HP EliteBook X Flip G1i
- amdnpu: Restore old NPU firmware for compatibility
- cirrus: cs42l45: Add CS42L45 SDCA codec firmware for Dell laptops
- lenovo: remove obsolete ish_lnlm_53c4ffad_2a17559f.bin firmware
- linux-firmware: update firmware for MT7902 BT device
- linux-firmware: update firmware for MT7902 WiFi device
- qcom: vpu: fix SC7280 VPU Gen2 firmware and add compatibility symlink
- amdgpu: DMCUB updates for various ASICs
- qcom: Update DSP firmware for qcs8300 platform
- cirrus: cs35l41: Add Firmware for ASUS Zenbook Laptop using CS35L41 HDA
- qcom: Update DSP firmware for sa8775p platform
- amdgpu: DMCUB updates for various ASICs
- rtw89: 8851b: add format-1 for fw v0.29.41.5 with fw elements
- rtw89: 8852a: add format-1 for fw v0.13.36.2 with fw elements
- rtw89: 8852bt: add regd and diag_mac and update txpwr to R09
- rtw89: 8852b: update txpwr element to R43
- rtw89: 8852b: add format-2 with v0.29.29.15 and fw elements
- Revert "rtw89: 8852b: update fw to v0.29.128.0 with format suffix -2"
- xe: Update GUC to v70.58.0 for LNL, BMG, PTL
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6390 hw2.0: update board-2.bin
- qcom: Add gpu firmwares for Glymur chipset
- amdgpu: DMCUB updates for various ASICs
- qcom: vpu: add video firmware for Glymur
- qcom: add QUPv3 firmware for x1e80100 platform
- Bluetooth: Add symbolic links for Intel Solar JfP2/1 firmware variants
- Bluetooth: Add symbolic links for Intel Solar firmware variants
- Bluetooth: Add symbolic links for Intel Pulsar firmware variants
- Bluetooth: Add symbolic links for Intel AX201 firmware variants
- ath10k: WCN3990 hw1.0: update board-2.bin
- qcom: add ADSP, CDSP firmware for glymur platform
- ASoC: tas2783: Add Firmware files for tas2783A
- linux-firmware: Update firmware file for Intel Solar core
- mediatek MT7921: update bluetooth firmware to 20251223091725
- rtl_bt: Update RTL8822C BT USB and UART firmware to 0x0673
- ath12k: WCN7850 hw2.0: update board-2.bin
- ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.6-01243-QCAHKSWPL_SILICONZ-1
- ath11k: WCN6855 hw2.0: update board-2.bin
- ath11k: QCA6698AQ hw2.1: update board-2.bin
- WHENCE: Correct 2 trailing whitespaces
- linux-firmware: Add firmware for airoha-npu-7581 driver used for MT7990 offloading
- linux-firmware: Add Dell ISH firmware for Intel panther lake systems
- amdgpu: DMCUB updates for various ASICs
- linux-firmware: update Aeonsemi AS21x1x firmware to 1.9.1
- rtl_nic: add firmware rtl8125cp-1 for RTL8125cp
- ice: update DDP LAG package to 1.3.2.0
- cirrus: cs35l56: Add WHENCE links for 17aa233c spkid0 firmware
- rtw89: 8922a: update REGD R73-R08, txpwr R46 and element of diag MAC
- rtw89: 8852c: update REGD R73-R60, txpwr R82 and element of diag MAC
- Update firmware for NPU PHX, STX and STX HALO
- qcom: Update ADSP and add CDSP firmware for qcs6490-radxa-dragon-q6a
- qcom: Remove ADSP SensorPD json for Radxa Dragon Q6A
- amdgpu: DMCUB updates for various ASICs
Resolves: RHEL-179828

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>iptables-utils-1.8.11-16.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:23:48 PM GMT</pubDate>
      <guid isPermaLink="false">d9bdd31096e3ace12ea4c818a3d894766ff21aefe1cc1e798a2f02035e93d559</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/iptables-utils-1.8.11-16.el10_2.aarch64.rpm</link>
      <description><p><strong>iptables-utils</strong> - iptables and ip6tables misc utilities&lt;br /&gt;</p>

<p>Utils for iptables&lt;br /&gt;
&lt;br /&gt;
This package provides nfnl_osf with the pf.os database and nfbpf_compile,&lt;br /&gt;
a bytecode generator for use with xt_bpf. Also included is iptables-apply,&lt;br /&gt;
a safer way to update iptables remotely.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-16.el10]
- spec: Simplify Recommends again, kernel fixed Provides in modules-core packages (Phil Sutter) [RHEL-213273]

Thu, 18 Jun 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-15.el10]
- spec: Recommend kernel-modules-extra only if no other recommendation applies (Phil Sutter) [RHEL-186232]

Wed, 27 May 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-14.el10]
- tests: shell: Review nft-only/0009-needless-bitwise_0 (Phil Sutter) [RHEL-179504]
- spec: Soft-depend on kernel-modules-extra (Phil Sutter) [RHEL-176386]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>iptables-nft-1.8.11-16.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:23:48 PM GMT</pubDate>
      <guid isPermaLink="false">fd5323a8e95f3c921be9d8cc8bcd94d8b2c9e49b8d9d7e1eecb2a199f5e4bb61</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/iptables-nft-1.8.11-16.el10_2.aarch64.rpm</link>
      <description><p><strong>iptables-nft</strong> - nftables compatibility for iptables, arptables and ebtables&lt;br /&gt;</p>

<p>nftables compatibility for iptables, arptables and ebtables.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-16.el10]
- spec: Simplify Recommends again, kernel fixed Provides in modules-core packages (Phil Sutter) [RHEL-213273]

Thu, 18 Jun 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-15.el10]
- spec: Recommend kernel-modules-extra only if no other recommendation applies (Phil Sutter) [RHEL-186232]

Wed, 27 May 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-14.el10]
- tests: shell: Review nft-only/0009-needless-bitwise_0 (Phil Sutter) [RHEL-179504]
- spec: Soft-depend on kernel-modules-extra (Phil Sutter) [RHEL-176386]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>iptables-devel-1.8.11-16.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:23:48 PM GMT</pubDate>
      <guid isPermaLink="false">b21b294260a00c9174a0163b274abacdc0169528983cc19b768310a2ebe8be01</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/iptables-devel-1.8.11-16.el10_2.aarch64.rpm</link>
      <description><p><strong>iptables-devel</strong> - Development package for iptables&lt;br /&gt;</p>

<p>libxtables development headers and pkgconfig files</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-16.el10]
- spec: Simplify Recommends again, kernel fixed Provides in modules-core packages (Phil Sutter) [RHEL-213273]

Thu, 18 Jun 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-15.el10]
- spec: Recommend kernel-modules-extra only if no other recommendation applies (Phil Sutter) [RHEL-186232]

Wed, 27 May 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-14.el10]
- tests: shell: Review nft-only/0009-needless-bitwise_0 (Phil Sutter) [RHEL-179504]
- spec: Soft-depend on kernel-modules-extra (Phil Sutter) [RHEL-176386]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>iptables-nft-services-1.8.11-16.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:23:26 PM GMT</pubDate>
      <guid isPermaLink="false">e0bf5c647e4d37ecbc2ce8b7eb0414b03b37fdc45c3b1063c8614e1047c1dce2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/iptables-nft-services-1.8.11-16.el10_2.noarch.rpm</link>
      <description><p><strong>iptables-nft-services</strong> - Services for nft-variants of iptables, ebtables and arptables&lt;br /&gt;</p>

<p>Services for nft-variants of iptables, ebtables and arptables&lt;br /&gt;
&lt;br /&gt;
This package provides the services iptables, ip6tables, arptables and ebtables&lt;br /&gt;
for use with iptables-nft which provides nft-variants of these tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-16.el10]
- spec: Simplify Recommends again, kernel fixed Provides in modules-core packages (Phil Sutter) [RHEL-213273]

Thu, 18 Jun 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-15.el10]
- spec: Recommend kernel-modules-extra only if no other recommendation applies (Phil Sutter) [RHEL-186232]

Wed, 27 May 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; [1.8.11-14.el10]
- tests: shell: Review nft-only/0009-needless-bitwise_0 (Phil Sutter) [RHEL-179504]
- spec: Soft-depend on kernel-modules-extra (Phil Sutter) [RHEL-176386]

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>ipset-service-7.22-13.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:23:07 PM GMT</pubDate>
      <guid isPermaLink="false">610aa3e849f4fadf552af3e6111898cdad256a95feda38ba4dcee4b33725876c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/i/ipset-service-7.22-13.el10_2.noarch.rpm</link>
      <description><p><strong>ipset-service</strong> - ipset service for ipsets&lt;br /&gt;</p>

<p>This package provides the service ipset that is split&lt;br /&gt;
out of the base package since it is not active by default.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; - 7.22-13
- Simplify Recommends again, kernel fixed Provides in modules-core packages

Thu, 11 Jun 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; - 7.22-12
- avoid pulling in kernel package if not needed

Wed, 27 May 2026 GMT - Phil Sutter &amp;lt;psutter@redhat.com&amp;gt; - 7.22-11
- spec: Soft-depend on kernel-modules-extra

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libspiro-20240903-3.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:22:35 PM GMT</pubDate>
      <guid isPermaLink="false">b0e9f3075fa6ad538fd3745fd1b2191cf5e00b69437062af4c2732c45d3a2046</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libspiro-20240903-3.el10_2.aarch64.rpm</link>
      <description><p><strong>libspiro</strong> - Library to simplify the drawing of beautiful curves&lt;br /&gt;</p>

<p>This library will take an array of spiro control points and&lt;br /&gt;
convert them into a series of bézier splines which can then&lt;br /&gt;
be used in the myriad of ways the world has come to use béziers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Josef Ridky &amp;lt;jridky@redhat.com&amp;gt; - 20240903-3
- update to 20240903 version and move pgk to AppStream

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 20221101-8
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>smc-tools-1.8.6-2.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:21:51 PM GMT</pubDate>
      <guid isPermaLink="false">79e6b50e54eb3a2a3286f8ed380986d0ada9652a81c2a9fc5a65d2eac151a20e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/smc-tools-1.8.6-2.el10_2.aarch64.rpm</link>
      <description><p><strong>smc-tools</strong> - Shared Memory Communication Tools&lt;br /&gt;</p>

<p>The Shared Memory Communication Tools (smc-tools) package enables usage of SMC&lt;br /&gt;
sockets in Linux.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 23 Jun 2026 GMT - Čestmír Kalina &amp;lt;ckalina@redhat.com&amp;gt; - 1.8.6-2
- Resolves: RHEL-185465
- smc-tools: smc_rnics is not listing the NetH/NetD cards inside the guest

Wed, 17 Dec 2025 GMT - Čestmír Kalina &amp;lt;ckalina@redhat.com&amp;gt; - 1.8.6-1
- Update to 1.8.6
  Resolves: RHEL-100170

Thu, 17 Jul 2025 GMT - Čestmír Kalina &amp;lt;ckalina@redhat.com&amp;gt; - 1.8.5-1
- Update to 1.8.5
  Resolves: RHEL-73359

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>linuxptp-4.4-8.el10_2.1.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:21:37 PM GMT</pubDate>
      <guid isPermaLink="false">1b48f2d71ff696e61be3ee61bab9e98e1e30f82dd020b416957ca4f8dd68c54f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/linuxptp-4.4-8.el10_2.1.aarch64.rpm</link>
      <description><p><strong>linuxptp</strong> - PTP implementation for Linux&lt;br /&gt;</p>

<p>This software is an implementation of the Precision Time Protocol (PTP)&lt;br /&gt;
according to IEEE standard 1588 for Linux. The dual design goals are to provide&lt;br /&gt;
a robust implementation of the standard and to use the most relevant and modern&lt;br /&gt;
Application Programming Interfaces (API) offered by the Linux kernel.&lt;br /&gt;
Supporting legacy APIs and other platforms is not a goal.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 01 Jul 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-8.el10_2.1
- fix phc2sys service to allow clocks specified by interface (RHEL-191400)
- fix high CPU usage by ptp4l when link is down (RHEL-191401)
- fix phc2sys to not get stuck in static mode (RHEL-185752)

Mon, 02 Feb 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-8
- create reverse compatibility symlink to /var/run/ptp4l (RHEL-145071)

Thu, 11 Dec 2025 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-7
- add missing build requirement on lipcap-devel

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>linuxptp-selinux-4.4-8.el10_2.1.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:21:36 PM GMT</pubDate>
      <guid isPermaLink="false">0d7cc191fd80501e83acd6acd6a67458366054fe4ad0069cef5640b2c76e733a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/linuxptp-selinux-4.4-8.el10_2.1.noarch.rpm</link>
      <description><p><strong>linuxptp-selinux</strong> - linuxptp SELinux policy&lt;br /&gt;</p>

<p>linuxptp SELinux policy module</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 01 Jul 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-8.el10_2.1
- fix phc2sys service to allow clocks specified by interface (RHEL-191400)
- fix high CPU usage by ptp4l when link is down (RHEL-191401)
- fix phc2sys to not get stuck in static mode (RHEL-185752)

Mon, 02 Feb 2026 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-8
- create reverse compatibility symlink to /var/run/ptp4l (RHEL-145071)

Thu, 11 Dec 2025 GMT - Miroslav Lichvar &amp;lt;mlichvar@redhat.com&amp;gt; 4.4-7
- add missing build requirement on lipcap-devel

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>firewall-config-2.4.3-4.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:21:30 PM GMT</pubDate>
      <guid isPermaLink="false">a204a90abd2fa6f94471e86b053b86105990ea1e3986ebe71a956370e1622ec7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/f/firewall-config-2.4.3-4.el10_2.noarch.rpm</link>
      <description><p><strong>firewall-config</strong> - Firewall configuration application&lt;br /&gt;</p>

<p>The firewall configuration application provides an configuration interface for&lt;br /&gt;
firewalld.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;&lt;/pre&gt;</description>
    </item>
    <item>
      <title>firewall-applet-2.4.3-4.el10_2.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:21:30 PM GMT</pubDate>
      <guid isPermaLink="false">917d2f16284441bb389fb690c1f779dabe75c2b567bcff53ddb929f94e68f5b7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/f/firewall-applet-2.4.3-4.el10_2.noarch.rpm</link>
      <description><p><strong>firewall-applet</strong> - Firewall panel applet&lt;br /&gt;</p>

<p>The firewall panel applet provides a status information of firewalld and also&lt;br /&gt;
the firewall settings.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bootc-1.16.4-1.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:21:26 PM GMT</pubDate>
      <guid isPermaLink="false">be740d7875d211d182ff7f21f347df27ab617956e3c0d71bc33f969f4595a36c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bootc-1.16.4-1.el10_2.aarch64.rpm</link>
      <description><p><strong>bootc</strong> - Bootable container system&lt;br /&gt;</p>

<p>Bootable container system</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - ckyrouac &amp;lt;ckyrouac@redhat.com&amp;gt; - 1.16.4-1
- spec: new upstream version 1.16.4

Tue, 05 May 2026 GMT - Joseph Marrero Corchado &amp;lt;jmarrero@redhat.com&amp;gt; - 1.15.2-1
- Release 1.15.2

Tue, 14 Apr 2026 GMT - Joseph Marrero Corchado &amp;lt;jmarrero@redhat.com&amp;gt; - 1.15.1-1
- Release 1.15.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>system-reinstall-bootc-1.16.4-1.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:21:26 PM GMT</pubDate>
      <guid isPermaLink="false">0dbd2dd3e76c12b534c18db90943dab91787d43e201181727de6de2f8edce9ed</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/system-reinstall-bootc-1.16.4-1.el10_2.aarch64.rpm</link>
      <description><p><strong>system-reinstall-bootc</strong> - Utility to reinstall the current system using bootc&lt;br /&gt;</p>

<p>This package provides a utility to simplify reinstalling the current system to a given bootc image.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - ckyrouac &amp;lt;ckyrouac@redhat.com&amp;gt; - 1.16.4-1
- spec: new upstream version 1.16.4

Tue, 05 May 2026 GMT - Joseph Marrero Corchado &amp;lt;jmarrero@redhat.com&amp;gt; - 1.15.2-1
- Release 1.15.2

Tue, 14 Apr 2026 GMT - Joseph Marrero Corchado &amp;lt;jmarrero@redhat.com&amp;gt; - 1.15.1-1
- Release 1.15.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>assertj-core-3.24.2-9.el10_2.1.noarch</title>
      <pubDate>Tue, 25 Aug 2026 11:20:54 PM GMT</pubDate>
      <guid isPermaLink="false">3c376bc8fd5403f8ed0bb6fe8f6324251aeabab60a53b5d634679a47e5ca7be2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/assertj-core-3.24.2-9.el10_2.1.noarch.rpm</link>
      <description><p><strong>assertj-core</strong> - Library of assertions similar to fest-assert&lt;br /&gt;</p>

<p>A rich and intuitive set of strongly-typed assertions to use for unit testing&lt;br /&gt;
(either with JUnit or TestNG).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 25 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.24.2-9.1
- Fix CVE-2026-24400: add XXE protection to XmlStringPrettyFormatter
- Resolves: RHEL-183469

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 3.24.2-9
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

Thu, 01 Aug 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 3.24.2-8
- Bump release for Aug 2024 java mass rebuild

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libattr-devel-2.6.0-1.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:20:51 PM GMT</pubDate>
      <guid isPermaLink="false">bd624ba15e883c1a51b575d68ee38cf728dce60707dc080aa45ba772c1779d6d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libattr-devel-2.6.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>libattr-devel</strong> - Files needed for building programs with libattr&lt;br /&gt;</p>

<p>This package contains header files and documentation needed to&lt;br /&gt;
develop programs which make use of extended attributes.&lt;br /&gt;
For Linux programs, the documented system call API is the&lt;br /&gt;
recommended interface, but an SGI IRIX compatibility interface&lt;br /&gt;
is also provided.&lt;br /&gt;
&lt;br /&gt;
Currently only ext2, ext3, ext4 and XFS support extended attributes.&lt;br /&gt;
The SGI IRIX compatibility API built above the Linux system calls is&lt;br /&gt;
used by programs such as xfsdump(8), xfsrestore(8) and xfs_fsr(8).&lt;br /&gt;
&lt;br /&gt;
You should install libattr-devel if you want to develop programs&lt;br /&gt;
which make use of extended attributes.  If you install libattr-devel,&lt;br /&gt;
you'll also want to install attr.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 25 Jun 2026 GMT - Lukáš Zaoral &amp;lt;lzaoral@redhat.com&amp;gt; - 2.6.0-1
- rebase to 2.6.0 to fix the following CVEs:
  - CVE-2026-54371 - Symlink Traversal Privilege Escalation via getfattr (RHEL-186128)

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 2.5.2-5
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-criu-4.2-2.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:20:47 PM GMT</pubDate>
      <guid isPermaLink="false">caaff350d0fca02b07ff707ae4899decd687137671477a2f9077580eb285e2ea</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-criu-4.2-2.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-criu</strong> - Python bindings for criu&lt;br /&gt;</p>

<p>python3-criu contains Python bindings for criu.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-2
- Handle rseq in generic compel code (checkpoint-restore/criu#3097)

Tue, 18 Nov 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-1
- Update to 4.2

Mon, 12 May 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.1-1
- Update to 4.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>criu-libs-4.2-2.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:20:47 PM GMT</pubDate>
      <guid isPermaLink="false">04026e6b154dd694bc35d14d7f97ff59508f03ad9b107133b74887570488ae73</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/c/criu-libs-4.2-2.el10_2.aarch64.rpm</link>
      <description><p><strong>criu-libs</strong> - Libraries for criu&lt;br /&gt;</p>

<p>This package contains the libraries for criu</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-2
- Handle rseq in generic compel code (checkpoint-restore/criu#3097)

Tue, 18 Nov 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-1
- Update to 4.2

Mon, 12 May 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.1-1
- Update to 4.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>criu-4.2-2.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:20:47 PM GMT</pubDate>
      <guid isPermaLink="false">543eea2db10138e9776c4454cf67b5fe903db02602964054e9f6c23866c9bb71</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/c/criu-4.2-2.el10_2.aarch64.rpm</link>
      <description><p><strong>criu</strong> - Tool for Checkpoint/Restore in User-space&lt;br /&gt;</p>

<p>criu is the user-space part of Checkpoint/Restore in User-space&lt;br /&gt;
(CRIU), a project to implement checkpoint/restore functionality for&lt;br /&gt;
Linux in user-space.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-2
- Handle rseq in generic compel code (checkpoint-restore/criu#3097)

Tue, 18 Nov 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-1
- Update to 4.2

Mon, 12 May 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.1-1
- Update to 4.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>crit-4.2-2.el10_2.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 11:20:47 PM GMT</pubDate>
      <guid isPermaLink="false">691f487130f06ace8a9d53f0c7d1a9c88fe9f271e60d86b14e1bcd25a12323ee</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/c/crit-4.2-2.el10_2.aarch64.rpm</link>
      <description><p><strong>crit</strong> - CRIU image tool&lt;br /&gt;</p>

<p>crit is a tool designed to decode CRIU binary dump files and show&lt;br /&gt;
their content in human-readable form.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-2
- Handle rseq in generic compel code (checkpoint-restore/criu#3097)

Tue, 18 Nov 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.2-1
- Update to 4.2

Mon, 12 May 2025 GMT - Adrian Reber &amp;lt;areber@redhat.com&amp;gt; - 4.1-1
- Update to 4.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-pyasn1-modules-0.6.2-1.el10_2.1.noarch</title>
      <pubDate>Tue, 25 Aug 2026 02:33:34 AM GMT</pubDate>
      <guid isPermaLink="false">9ebe7f2c338cb046ade99d52521199a35e43a52879128bf23b7504c86853240f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-pyasn1-modules-0.6.2-1.el10_2.1.noarch.rpm</link>
      <description><p><strong>python3-pyasn1-modules</strong> - Modules for pyasn1&lt;br /&gt;</p>

<p>ASN.1 types modules for python3-pyasn1.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 0.6.2-1.1
- Fix CVE-2026-59886: prevent overflow in Real.__float__() when
  converting ASN.1 Real values with large exponents
  Resolves: RHEL-217904

Wed, 11 Feb 2026 GMT - Florence Blanc-Renaud &amp;lt;flo@redhat.com&amp;gt; - 0.6.2-1
- Update to 0.6.2
- Update modules to 0.4.2
  Resolves: RHEL-148142

Fri, 15 Nov 2024 GMT - Simon Pichugin &amp;lt;spichugi@redhat.com&amp;gt; - 0.6.1-1
- Update to 0.6.1
- Update modules to 0.4.1
  Resolves: RHEL-67667

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-pyasn1-0.6.2-1.el10_2.1.noarch</title>
      <pubDate>Tue, 25 Aug 2026 02:33:34 AM GMT</pubDate>
      <guid isPermaLink="false">c7f5a71a6d636d103e6be538aa0a634cbe1479a5b5c61e88572c7d97fbe25929</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-pyasn1-0.6.2-1.el10_2.1.noarch.rpm</link>
      <description><p><strong>python3-pyasn1</strong> - ASN.1 tools for Python 3&lt;br /&gt;</p>

<p>This is an implementation of ASN.1 types and codecs in the Python 3 programming&lt;br /&gt;
language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 0.6.2-1.1
- Fix CVE-2026-59886: prevent overflow in Real.__float__() when
  converting ASN.1 Real values with large exponents
  Resolves: RHEL-217904

Wed, 11 Feb 2026 GMT - Florence Blanc-Renaud &amp;lt;flo@redhat.com&amp;gt; - 0.6.2-1
- Update to 0.6.2
- Update modules to 0.4.2
  Resolves: RHEL-148142

Fri, 15 Nov 2024 GMT - Simon Pichugin &amp;lt;spichugi@redhat.com&amp;gt; - 0.6.1-1
- Update to 0.6.1
- Update modules to 0.4.1
  Resolves: RHEL-67667

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-mod-stream-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">0b978c3f8e6176fa90a323a20795cffb3346a58debdffe2870e511eb058f4348</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-mod-stream-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-mod-stream</strong> - Nginx stream modules&lt;br /&gt;</p>

<p>Nginx stream modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-mod-mail-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">254b42bfc9edbfe3fe3fa6127c58305a00e5efcd460e9052251a860de258bad8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-mod-mail-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-mod-mail</strong> - Nginx mail modules&lt;br /&gt;</p>

<p>Nginx mail modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-mod-http-xslt-filter-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">9a1558c0aa9e9c94eb0dbc8153eeb3f414495c06c84832d866cd57007f4711fc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-mod-http-xslt-filter-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-mod-http-xslt-filter</strong> - Nginx XSLT module&lt;br /&gt;</p>

<p>Nginx XSLT module.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-mod-http-perl-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">b2ebfa14460e4bd6f01cb48634f923ed36eb4c4b9d5f4272025578228951c026</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-mod-http-perl-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-mod-http-perl</strong> - Nginx HTTP perl module&lt;br /&gt;</p>

<p>Nginx HTTP perl module.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-mod-http-image-filter-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">e1d69c1edde06b10a291061c7372d54e6320dc41d38fc185ad6ef0147943d201</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-mod-http-image-filter-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-mod-http-image-filter</strong> - Nginx HTTP image filter module&lt;br /&gt;</p>

<p>Nginx HTTP image filter module.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-core-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">5b69f80a0f6789418b5cb2ec0d9c5d02bbb566523f5cc154948edd259d5d1a90</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-core-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx-core</strong> - nginx minimal core&lt;br /&gt;</p>

<p>nginx minimal core</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-2:1.26.3-6.el10_2.6.aarch64</title>
      <pubDate>Tue, 25 Aug 2026 01:59:37 AM GMT</pubDate>
      <guid isPermaLink="false">c246765d40ca3b3ae4d1d72aa0a11488c47ee27eab828bfabbf78b4ae4e6f016</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-1.26.3-6.el10_2.6.aarch64.rpm</link>
      <description><p><strong>nginx</strong> - A high performance web server and reverse proxy server&lt;br /&gt;</p>

<p>Nginx is a web server and a reverse proxy server for HTTP, SMTP, POP3 and&lt;br /&gt;
IMAP protocols, with a strong focus on high concurrency, performance and low&lt;br /&gt;
memory usage.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-filesystem-2:1.26.3-6.el10_2.6.noarch</title>
      <pubDate>Tue, 25 Aug 2026 01:59:36 AM GMT</pubDate>
      <guid isPermaLink="false">7ca1cbfd49937ed24fbe5d644c10b72900a58fae227e2b82113c51f171731c2f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-filesystem-1.26.3-6.el10_2.6.noarch.rpm</link>
      <description><p><strong>nginx-filesystem</strong> - The basic directory layout for the Nginx server&lt;br /&gt;</p>

<p>The nginx-filesystem package contains the basic directory layout&lt;br /&gt;
for the Nginx server including the correct permissions for the&lt;br /&gt;
directories.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nginx-all-modules-2:1.26.3-6.el10_2.6.noarch</title>
      <pubDate>Tue, 25 Aug 2026 01:59:36 AM GMT</pubDate>
      <guid isPermaLink="false">a7020fc6956fa6f8ca78335798dd52b70cb727052ba31cee499cc810262a3675</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nginx-all-modules-1.26.3-6.el10_2.6.noarch.rpm</link>
      <description><p><strong>nginx-all-modules</strong> - A meta package that installs all available Nginx modules&lt;br /&gt;</p>

<p>Meta package that installs all available nginx modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 30 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.6
- Resolves: RHEL-219313 - nginx: NGINX: Heap buffer over-read allows memory
  modification or denial of service (CVE-2026-56434)
- Resolves: RHEL-217956 - nginx: NGINX: Memory disclosure and denial of service
  in ngx_http_slice_module (CVE-2026-60005)

Fri, 03 Jul 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.5
- Resolves: RHEL-191778 - nginx: "HTTP/2 bomb" nginx fix breaks module ABI
  causing crashes
- Resolves: RHEL-188402 - nginx: NGINX: Arbitrary code execution or.
  Denial of Service via heap-based buffer overflow with crafted HTTP/2
  headers (CVE-2026-42055)

Mon, 08 Jun 2026 GMT - Luboš Uhliarik &amp;lt;luhliari@redhat.com&amp;gt; - 2:1.26.3-6.4
- Resolves: RHEL-178669 - nginx: code execution and denial of
  service (CVE-2026-9256)
- Resolves: RHEL-182544 - nginx: HTTP/2: Remote Denial of Service via
  compression bomb and Slowloris-style attack

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3.14-tkinter-3.14.7-2.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:23:28 PM GMT</pubDate>
      <guid isPermaLink="false">af45d39f6edc0193b3869684cb3d46868c0567feae88fc0012d71c1df0bb4b68</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3.14-tkinter-3.14.7-2.el10_2.aarch64.rpm</link>
      <description><p><strong>python3.14-tkinter</strong> - A GUI toolkit for Python&lt;br /&gt;</p>

<p>The Tkinter (Tk interface) library is a graphical user interface toolkit for&lt;br /&gt;
the Python programming language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Miro Hrončok &amp;lt;mhroncok@redhat.com&amp;gt; - 3.14.7-2
- On RHEL 9, also supports reparse deferral in expat
Related: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.7-1
- Update to Python 3.14.7, security fix for CVE-2026-11940
Resolves: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.6-1
- Update to Python 3.14.6
Related: RHEL-227190

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3.14-libs-3.14.7-2.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:23:28 PM GMT</pubDate>
      <guid isPermaLink="false">2ede6f32145ee62113350668193b430d7b82aaad4ad74f0b094485cec15ec7fd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3.14-libs-3.14.7-2.el10_2.aarch64.rpm</link>
      <description><p><strong>python3.14-libs</strong> - Python runtime libraries&lt;br /&gt;</p>

<p>This package contains runtime libraries for use by Python:&lt;br /&gt;
- the majority of the Python standard library&lt;br /&gt;
- a dynamically linked library for use by applications that embed Python as&lt;br /&gt;
  a scripting language, and by the main "python3.14" executable</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Miro Hrončok &amp;lt;mhroncok@redhat.com&amp;gt; - 3.14.7-2
- On RHEL 9, also supports reparse deferral in expat
Related: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.7-1
- Update to Python 3.14.7, security fix for CVE-2026-11940
Resolves: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.6-1
- Update to Python 3.14.6
Related: RHEL-227190

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3.14-devel-3.14.7-2.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:23:28 PM GMT</pubDate>
      <guid isPermaLink="false">c5ac9ce0894bc7d5c67a788c1ce13847fb0a94b66562ffc32970850ca476ce3f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3.14-devel-3.14.7-2.el10_2.aarch64.rpm</link>
      <description><p><strong>python3.14-devel</strong> - Libraries and header files needed for Python development&lt;br /&gt;</p>

<p>This package contains the header files and configuration needed to compile&lt;br /&gt;
Python extension modules (typically written in C or C++), to embed Python&lt;br /&gt;
into other programs, and to make binary distributions for Python libraries.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Miro Hrončok &amp;lt;mhroncok@redhat.com&amp;gt; - 3.14.7-2
- On RHEL 9, also supports reparse deferral in expat
Related: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.7-1
- Update to Python 3.14.7, security fix for CVE-2026-11940
Resolves: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.6-1
- Update to Python 3.14.6
Related: RHEL-227190

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3.14-3.14.7-2.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:23:28 PM GMT</pubDate>
      <guid isPermaLink="false">ae531ee572544e741ab40ae4dbfd3a397f8c386c0ca9f7abdb6b2a970f9bed88</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3.14-3.14.7-2.el10_2.aarch64.rpm</link>
      <description><p><strong>python3.14</strong> - Version 3.14 of the Python interpreter&lt;br /&gt;</p>

<p>Python 3.14 is an accessible, high-level, dynamically typed, interpreted&lt;br /&gt;
programming language, designed with an emphasis on code readability.&lt;br /&gt;
It includes an extensive standard library, and has a vast ecosystem of&lt;br /&gt;
third-party libraries.&lt;br /&gt;
&lt;br /&gt;
The python3.14 package provides the "python3.14" executable: the reference&lt;br /&gt;
interpreter for the Python language, version 3.&lt;br /&gt;
The majority of its standard library is provided in the python3.14-libs package,&lt;br /&gt;
which should be installed automatically along with python3.14.&lt;br /&gt;
The remaining parts of the Python standard library are broken out into the&lt;br /&gt;
python3.14-tkinter and python3.14-test packages, which may need to be installed&lt;br /&gt;
separately.&lt;br /&gt;
&lt;br /&gt;
Documentation for Python is provided in the python3.14-docs package.&lt;br /&gt;
&lt;br /&gt;
Packages containing additional libraries for Python are generally named with&lt;br /&gt;
the "python3.14-" prefix.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Miro Hrončok &amp;lt;mhroncok@redhat.com&amp;gt; - 3.14.7-2
- On RHEL 9, also supports reparse deferral in expat
Related: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.7-1
- Update to Python 3.14.7, security fix for CVE-2026-11940
Resolves: RHEL-227190

Mon, 17 Aug 2026 GMT - Lumír Balhar &amp;lt;lbalhar@redhat.com&amp;gt; - 3.14.6-1
- Update to Python 3.14.6
Related: RHEL-227190

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>sqlite-devel-3.46.1-6.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:08:57 PM GMT</pubDate>
      <guid isPermaLink="false">7bf6564f4e903cef9c35ec822ed9bedd377cc13edca0304dcb8d6c6e4f0e6f3e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/sqlite-devel-3.46.1-6.el10_2.aarch64.rpm</link>
      <description><p><strong>sqlite-devel</strong> - Development tools for the sqlite3 embeddable SQL database engine&lt;br /&gt;</p>

<p>This package contains the header files and development documentation&lt;br /&gt;
for sqlite. If you like to develop programs using sqlite, you will need&lt;br /&gt;
to install sqlite-devel.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.46.1-6
- Fixes CVE-2026-11822
- Fixes CVE-2026-11824
- Resolves: RHEL-218247
- Resolves: RHEL-218282

Wed, 16 Jul 2025 GMT - Ales Nezbeda &amp;lt;anezbeda@redhat.com&amp;gt; - 3.46.1-5
- Fix CVE-2025-6965
- Resolves: RHEL-103827

Tue, 15 Apr 2025 GMT - Ales Nezbeda &amp;lt;anezbeda@redhat.com&amp;gt; - 3.46.1-4
- Fix for CVE-2025-3277
- Resolves: RHEL-87295

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>sqlite-3.46.1-6.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 03:08:57 PM GMT</pubDate>
      <guid isPermaLink="false">539104c85498baad55eafcd0bfed3cf14a7a88eca37180332cc211d34e8c5764</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/s/sqlite-3.46.1-6.el10_2.aarch64.rpm</link>
      <description><p><strong>sqlite</strong> - Library that implements an embeddable SQL database engine&lt;br /&gt;</p>

<p>SQLite is a C library that implements an SQL database engine. A large&lt;br /&gt;
subset of SQL92 is supported. A complete database is stored in a&lt;br /&gt;
single disk file. The API is designed for convenience and ease of use.&lt;br /&gt;
Applications that link against SQLite can enjoy the power and&lt;br /&gt;
flexibility of an SQL database without the administrative hassles of&lt;br /&gt;
supporting a separate database server.  Version 2 and version 3 binaries&lt;br /&gt;
are named to permit each to be installed on a single host</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 3.46.1-6
- Fixes CVE-2026-11822
- Fixes CVE-2026-11824
- Resolves: RHEL-218247
- Resolves: RHEL-218282

Wed, 16 Jul 2025 GMT - Ales Nezbeda &amp;lt;anezbeda@redhat.com&amp;gt; - 3.46.1-5
- Fix CVE-2025-6965
- Resolves: RHEL-103827

Tue, 15 Apr 2025 GMT - Ales Nezbeda &amp;lt;anezbeda@redhat.com&amp;gt; - 3.46.1-4
- Fix for CVE-2025-3277
- Resolves: RHEL-87295

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>firefox-140.14.0-1.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 02:09:51 PM GMT</pubDate>
      <guid isPermaLink="false">5c094f4d29df3b17be13cbee53612eb4d3e79a146d70b25c9703d32d3c77e62d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/f/firefox-140.14.0-1.el10_2.aarch64.rpm</link>
      <description><p><strong>firefox</strong> - Mozilla Firefox Web browser&lt;br /&gt;</p>

<p>Mozilla Firefox is an open-source web browser, designed for standards&lt;br /&gt;
compliance, performance and portability.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 24 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 140.14.0-1
- Add custom Rocky Linux firefox prefs (Louis Abel)
- Ensure mozilla API key is set for Rocky Linux (Mustafa Gezen)
- Ensure s390x and riscv64 are locked to 3 CPU's (Louis Abel)

Wed, 12 Aug 2026 GMT - Jan Grulich &amp;lt;jgrulich@redhat.com&amp;gt; - 140.14.0-1
- Update to 140.14.0 ESR

Thu, 16 Jul 2026 GMT - Jan Horak &amp;lt;jhorak@redhat.com&amp;gt; - 140.13.0-1
- Update to 140.13.0 ESR

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-tkinter-3.12.14-1.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 12:02:34 PM GMT</pubDate>
      <guid isPermaLink="false">13d1789d67b04bf3e88cc6a25cf965c4c5259e90fcdbb4301b9c2a60559ee4bb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-tkinter-3.12.14-1.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-tkinter</strong> - A GUI toolkit for Python&lt;br /&gt;</p>

<p>The Tkinter (Tk interface) library is a graphical user interface toolkit for&lt;br /&gt;
the Python programming language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Karolina Surma &amp;lt;ksurma@redhat.com&amp;gt; - 3.12.14-1
- Update to Python 3.12.14
Resolves: RHEL-227203

Fri, 10 Jul 2026 GMT - Lukáš Zachar &amp;lt;lzachar@redhat.com&amp;gt; - 3.12.13-2.1
- Security fix for CVE-2026-15308
Resolves: RHEL-193771

Thu, 16 Apr 2026 GMT - Charalampos Stratakis &amp;lt;cstratak@redhat.com&amp;gt; - 3.12.13-2
- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224
Resolves: RHEL-167886, RHEL-168120

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-devel-3.12.14-1.el10_2.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 12:02:34 PM GMT</pubDate>
      <guid isPermaLink="false">9672ec6b5bda5708d6437111b0622bec72d4c5f3570d535066550059e4f7a87b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-devel-3.12.14-1.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-devel</strong> - Libraries and header files needed for Python development&lt;br /&gt;</p>

<p>This package contains the header files and configuration needed to compile&lt;br /&gt;
Python extension modules (typically written in C or C++), to embed Python&lt;br /&gt;
into other programs, and to make binary distributions for Python libraries.&lt;br /&gt;
&lt;br /&gt;
It also contains the necessary macros to build RPM packages with Python modules&lt;br /&gt;
and 2to3 tool, an automatic source converter from Python 2.X.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Karolina Surma &amp;lt;ksurma@redhat.com&amp;gt; - 3.12.14-1
- Update to Python 3.12.14
Resolves: RHEL-227203

Fri, 10 Jul 2026 GMT - Lukáš Zachar &amp;lt;lzachar@redhat.com&amp;gt; - 3.12.13-2.1
- Security fix for CVE-2026-15308
Resolves: RHEL-193771

Thu, 16 Apr 2026 GMT - Charalampos Stratakis &amp;lt;cstratak@redhat.com&amp;gt; - 3.12.13-2
- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224
Resolves: RHEL-167886, RHEL-168120

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python-unversioned-command-3.12.14-1.el10_2.noarch</title>
      <pubDate>Mon, 24 Aug 2026 12:02:30 PM GMT</pubDate>
      <guid isPermaLink="false">46ac190dbd8e45fda8be5ed726278950f41638d2ae6caaa9cbbb867adbb9bf24</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python-unversioned-command-3.12.14-1.el10_2.noarch.rpm</link>
      <description><p><strong>python-unversioned-command</strong> - The "python" command that runs Python 3&lt;br /&gt;</p>

<p>This package contains /usr/bin/python - the "python" command that runs Python 3.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Karolina Surma &amp;lt;ksurma@redhat.com&amp;gt; - 3.12.14-1
- Update to Python 3.12.14
Resolves: RHEL-227203

Fri, 10 Jul 2026 GMT - Lukáš Zachar &amp;lt;lzachar@redhat.com&amp;gt; - 3.12.13-2.1
- Security fix for CVE-2026-15308
Resolves: RHEL-193771

Thu, 16 Apr 2026 GMT - Charalampos Stratakis &amp;lt;cstratak@redhat.com&amp;gt; - 3.12.13-2
- Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE-2026-3644, CVE-2026-4224
Resolves: RHEL-167886, RHEL-168120

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-pr-helper-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">8d9d2eae74abed68b4affe6e1f97c0532fa1407966dfccd7c1d5669c96f7cf89</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-pr-helper-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-pr-helper</strong> - qemu-pr-helper utility for qemu-kvm&lt;br /&gt;</p>

<p>This package provides the qemu-pr-helper utility that is required for certain&lt;br /&gt;
SCSI features.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-tools-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">c10c75679024c9f6c9539731f66622fa91cbb042b5ef631f353719e6acd75bad</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-tools-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-tools</strong> - qemu-kvm support tools&lt;br /&gt;</p>

<p>qemu-kvm-tools provides various tools related to qemu-kvm usage.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-docs-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">f7640ca54153f44a3a92e7adef6aa442e09cd2ad883e39895bb2adc6e81de653</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-docs-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-docs</strong> - qemu-kvm documentation&lt;br /&gt;</p>

<p>qemu-kvm-docs provides documentation files regarding qemu-kvm.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-device-usb-redirect-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">6e724bb072f5febf3faccf4c6a34c48370111bd04bce0238551c9be53c160103</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-device-usb-redirect-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-device-usb-redirect</strong> - QEMU usbredir support&lt;br /&gt;</p>

<p>This package provides usbredir support.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-device-usb-host-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">39451ec292d4aba5993c0805c9500b24c66da810e79ac32e7b9f44910ecd8d5f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-device-usb-host-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-device-usb-host</strong> - QEMU usb host device&lt;br /&gt;</p>

<p>This package provides the USB pass through driver for QEMU.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-device-display-virtio-gpu-pci-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">c9384575da8da26ca7a7b3b1c3c0997ac76897187f0c5cd2ac0b23a3d9fa6737</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-device-display-virtio-gpu-pci-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-device-display-virtio-gpu-pci</strong> - QEMU virtio-gpu-pci display device&lt;br /&gt;</p>

<p>This package provides the virtio-gpu-pci display device for QEMU.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-device-display-virtio-gpu-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">22afcf6bbe73c6bdabfe05c87c1676336944074b6a6492bf8af5f370fa650a9c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-device-display-virtio-gpu-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-device-display-virtio-gpu</strong> - QEMU virtio-gpu display device&lt;br /&gt;</p>

<p>This package provides the virtio-gpu display device for QEMU.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-core-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">a76e23d1ed9a251400b57c378a21e953f7b92c849dc28e2f02806945f8fb4ef0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-core-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-core</strong> - qemu-kvm core components&lt;br /&gt;</p>

<p>qemu-kvm is an open source virtualizer that provides hardware&lt;br /&gt;
emulation for the KVM hypervisor. qemu-kvm acts as a virtual&lt;br /&gt;
machine monitor together with the KVM kernel modules, and emulates the&lt;br /&gt;
hardware for a full system such as a PC and its associated peripherals.&lt;br /&gt;
This is a minimalistic installation of qemu-kvm. Functionality provided by&lt;br /&gt;
this package is not ensured and it can change in a future version as some&lt;br /&gt;
functionality can be split out to separate package.&lt;br /&gt;
Before updating this package, it is recommended to check the package&lt;br /&gt;
changelog for information on functionality which might have been moved to&lt;br /&gt;
a separate package to prevent issues due to the moved functionality.&lt;br /&gt;
If apps opt-in to minimalist packaging by depending on qemu-kvm-core, they&lt;br /&gt;
explicitly accept that features may disappear from qemu-kvm-core in future&lt;br /&gt;
updates.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-common-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">305607f62bea83a8b172a6c7846adb54906aca4b9a7500db989eb34bd60b4766</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-common-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-common</strong> - QEMU common files needed by all QEMU targets&lt;br /&gt;</p>

<p>qemu-kvm is an open source virtualizer that provides hardware emulation for&lt;br /&gt;
the KVM hypervisor.&lt;br /&gt;
&lt;br /&gt;
This package provides documentation and auxiliary programs used with qemu-kvm.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-block-rbd-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">eca9bddbaf0f6640f1da00133795ee4ea3832f1f0e6a642da1622a2db2d111cf</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-block-rbd-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-block-rbd</strong> - QEMU Ceph/RBD block driver&lt;br /&gt;</p>

<p>This package provides the additional Ceph/RBD block driver for QEMU.&lt;br /&gt;
&lt;br /&gt;
Install this package if you want to access remote Ceph volumes&lt;br /&gt;
using the rbd protocol.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-block-curl-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">7f9cbb9941fd2593ed7dcceb4f630a4ac595779917d933903134ecd5ef811a48</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-block-curl-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-block-curl</strong> - QEMU CURL block driver&lt;br /&gt;</p>

<p>This package provides the additional CURL block driver for QEMU.&lt;br /&gt;
&lt;br /&gt;
Install this package if you want to access remote disks over&lt;br /&gt;
http, https, ftp and other transports provided by the CURL library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-block-blkio-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">7c44e6b25fbbf54423027fa39c6a4a86c2b02af1b02d6f71063d392b2f3cafbe</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-block-blkio-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-block-blkio</strong> - QEMU libblkio block drivers&lt;br /&gt;</p>

<p>This package provides the additional libblkio block drivers for QEMU.&lt;br /&gt;
&lt;br /&gt;
Install this package if you want to use virtio-blk-vdpa-blk,&lt;br /&gt;
virtio-blk-vfio-pci, virtio-blk-vhost-user, io_uring, and nvme-io_uring block&lt;br /&gt;
drivers provided by libblkio.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-audio-pa-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">2a48d8708f9c131d47170d02f44a5e06ff0357330b0ba54f37cec6a33c553e77</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-audio-pa-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm-audio-pa</strong> - QEMU PulseAudio audio driver&lt;br /&gt;</p>

<p>This package provides the additional PulseAudio audio driver for QEMU.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-kvm-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">ac4ecf9e847284999c4fe96c69f5217378db66454fa9b98c98d192231e3d2885</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-kvm-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-kvm</strong> - QEMU is a machine emulator and virtualizer&lt;br /&gt;</p>

<p>qemu-kvm is an open source virtualizer that provides hardware&lt;br /&gt;
emulation for the KVM hypervisor. qemu-kvm acts as a virtual&lt;br /&gt;
machine monitor together with the KVM kernel modules, and emulates the&lt;br /&gt;
hardware for a full system such as a PC and its associated peripherals.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-img-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">56b23ebdd81334dec02b3609519e70038fc09f1133f79079d4d9772ceaed1e20</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-img-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-img</strong> - QEMU command line tool for manipulating disk images&lt;br /&gt;</p>

<p>This package provides a command line tool for manipulating disk images.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>qemu-guest-agent-18:10.1.0-16.el10_2.5.aarch64</title>
      <pubDate>Mon, 24 Aug 2026 09:01:10 AM GMT</pubDate>
      <guid isPermaLink="false">2b2f84844056c3db76e61e973fb9de1a213497c4dbcecb6de132e5ee7c1416bc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/q/qemu-guest-agent-10.1.0-16.el10_2.5.aarch64.rpm</link>
      <description><p><strong>qemu-guest-agent</strong> - QEMU guest agent&lt;br /&gt;</p>

<p>qemu-kvm is an open source virtualizer that provides hardware emulation for&lt;br /&gt;
the KVM hypervisor.&lt;br /&gt;
&lt;br /&gt;
This package provides an agent to run inside guests, which communicates&lt;br /&gt;
with the host over a virtio-serial channel named "org.qemu.guest_agent.0"&lt;br /&gt;
&lt;br /&gt;
This package does not need to be installed on the host OS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 04 Aug 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.5
- kvm-file-posix-populate-pwrite_zeroes_alignment.patch [RHEL-207389]
- kvm-block-use-pwrite_zeroes_alignment-when-writing-first.patch [RHEL-207389]
- kvm-iotests-add-Linux-loop-device-image-creation-test.patch [RHEL-207389]
- Resolves: RHEL-207389
  (qemu-img create/convert fails on target block device with 4k sector size [rhel-10.2.z])

Thu, 09 Jul 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.4
- kvm-blkdebug-Add-delay-ns-option.patch [RHEL-190702]
- kvm-block-Add-blk_co_start-end_request-and-BDRV_REQ_NO_Q.patch [RHEL-190702]
- kvm-block-Add-flags-parameter-to-blk_-_pdiscard.patch [RHEL-190702]
- kvm-ide-Minimal-fix-for-deadlock-between-TRIM-and-drain.patch [RHEL-190702]
- kvm-ide-Clean-up-ide_trim_co_entry-to-be-idiomatic-corou.patch [RHEL-190702]
- kvm-ide-test-Factor-out-wait_dma_completion.patch [RHEL-190702]
- kvm-ide-test-Test-reset-during-TRIM.patch [RHEL-190702]
- kvm-spec-Install-qtests-into-qemu-kvm-tests-package.patch [RHEL-190702]
- Resolves: RHEL-190702
  (qemu-kvm hung during drain after double pause [rhel-10.2.z])

Fri, 19 Jun 2026 GMT - Miroslav Rezanina &amp;lt;mrezanin@redhat.com&amp;gt; - 10.1.0-16.el10_2.3
- kvm-virtio-blk-add-missing-VIRTIO_BLK_T_SCSI_CMD-size-ch.patch [RHEL-184529]
- Resolves: RHEL-184529
  (CVE-2026-48914 qemu-kvm: Heap buffer overflow in virtio-blk SCSI request handling [rhel-10.2.z])

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-static-libs-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">8c739765e735138b6148624e0a6aeab53004f87e3244cfe750c45d20c2a9113d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-static-libs-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-static-libs</strong> - OpenJDK 21 libraries for static linking&lt;br /&gt;</p>

<p>The OpenJDK 21 libraries for static linking.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-src-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">cac425c90337f499134a02dbd55a70d90b31a4a387e6ef7a4a8146b172b82551</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-src-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-src</strong> - OpenJDK 21 Source Bundle&lt;br /&gt;</p>

<p>The java-21-openjdk-src sub-package contains the complete OpenJDK 21&lt;br /&gt;
class library source code for use by IDE indexers and debuggers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-jmods-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">31a430bef9abaf9b1de39acf9dd1dbf88d1ffd00b6ebcb2d13f111cedce46b5b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-jmods-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-jmods</strong> - JMods for OpenJDK 21&lt;br /&gt;</p>

<p>The JMods for OpenJDK 21.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-javadoc-zip-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">927920af222558af4eea3db8b74e099305fe7a82be56aba3d3eae9b56aac4149</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-javadoc-zip-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-javadoc-zip</strong> - OpenJDK 21 API documentation compressed in a single archive&lt;br /&gt;</p>

<p>The OpenJDK 21 API documentation compressed in a single archive.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-javadoc-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">c4fe9c2b77ecbe806c0fc33e59734253e37050f70f18bd45830289274bbf252e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-javadoc-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-javadoc</strong> - OpenJDK 21 API documentation&lt;br /&gt;</p>

<p>The OpenJDK 21 API documentation.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-headless-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">e4f1c3b941cc85c25c3783b85eb5045c4edbd8d68d9de52b7d1114b67b4d4852</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-headless-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-headless</strong> - OpenJDK 21 Headless Runtime Environment&lt;br /&gt;</p>

<p>The OpenJDK 21 runtime environment without audio and video support.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-devel-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">83989348dbc3da44cc16ce8f25827a5cf429a8f5806fb4cac4a339fee53b1098</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-devel-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-devel</strong> - OpenJDK 21 Development Environment&lt;br /&gt;</p>

<p>The OpenJDK 21 development tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-demo-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">c36cd28be91ccc877fbdac4c5bd9727b1a76bd4cb20a302a3decabdbd2fcc50a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-demo-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk-demo</strong> - OpenJDK 21 Demos&lt;br /&gt;</p>

<p>The OpenJDK 21 demos.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-21-openjdk-1:21.0.12.1.1-1.2.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 11:24:32 PM GMT</pubDate>
      <guid isPermaLink="false">02aba2fa0e7ad6a4272a5e799cfa5d80cc9f7243b9fc58631fca96d86214d7b6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-21-openjdk-21.0.12.1.1-1.2.el10_2.aarch64.rpm</link>
      <description><p><strong>java-21-openjdk</strong> - OpenJDK 21 Runtime Environment&lt;br /&gt;</p>

<p>The OpenJDK 21 runtime environment.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:21.0.12.1.1-1.2
- Build for Rocky Linux 10 using our own portable

Wed, 12 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:21.0.12.1.1-1.2
- Bump release for PQC build
- Related: RHEL-235622

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-static-libs-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">17f1f0d178b03f909be8831f1bbf3af7cf6f82d93496f14e1cd5129453770920</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-static-libs-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-static-libs</strong> - OpenJDK 25 libraries for static linking&lt;br /&gt;</p>

<p>The OpenJDK 25 libraries for static linking.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-src-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">991213f25ddb0dbab26d37922287971d40aa650c10158c417ddf6e7e17cfec25</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-src-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-src</strong> - OpenJDK 25 Source Bundle&lt;br /&gt;</p>

<p>The java-25-openjdk-src sub-package contains the complete OpenJDK 25&lt;br /&gt;
class library source code for use by IDE indexers and debuggers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-jmods-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">ae58ca623f0bb7310109045ade24196a15996b60e14baf058dc25ab73cc2fdcc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-jmods-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-jmods</strong> - JMods for OpenJDK 25&lt;br /&gt;</p>

<p>The JMods for OpenJDK 25.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-javadoc-zip-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">4a59bc2ee5b836590609c45262c29e14e786e974ba838198871f61a6e1554669</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-javadoc-zip-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-javadoc-zip</strong> - OpenJDK 25 API documentation compressed in a single archive&lt;br /&gt;</p>

<p>The OpenJDK 25 API documentation compressed in a single archive.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-javadoc-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">1eedee234de9b2a286c327ecb29b88329e6e7de6ff9df07564bd6c1b6b7329a9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-javadoc-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-javadoc</strong> - OpenJDK 25 API documentation&lt;br /&gt;</p>

<p>The OpenJDK 25 API documentation.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-headless-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">e301c148d93ed3b779d310bc66a5ec66d284b39f30aaa268657d02535250dff9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-headless-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-headless</strong> - OpenJDK 25 Headless Runtime Environment&lt;br /&gt;</p>

<p>The OpenJDK 25 runtime environment without audio and video support.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-devel-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">9c477023e37ec73685f3a5276a5f73bc9f4508c67a41fc76ab31a61222804839</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-devel-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-devel</strong> - OpenJDK 25 Development Environment&lt;br /&gt;</p>

<p>The OpenJDK 25 development tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-demo-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">50b67b8cf556f1cc824ad1a002ecac66c357c46efcc53d63146b274cbd294f49</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-demo-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-demo</strong> - OpenJDK 25 Demos&lt;br /&gt;</p>

<p>The OpenJDK 25 demos.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-crypto-adapter-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">30f4314be2c14a6e4c7d75e24b95b9d76beace3b01a688104101587b721e7f90</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-crypto-adapter-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk-crypto-adapter</strong> - OpenJDK 25 Cryptography Adapter Library&lt;br /&gt;</p>

<p>The OpenJDK 25 cryptography adapter library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>java-25-openjdk-1:25.0.4.1.1-1.1.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:29:12 PM GMT</pubDate>
      <guid isPermaLink="false">42748e430bf661e409e392e705f9cab5e92e6d793f643c56df4d126f9955a347</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/j/java-25-openjdk-25.0.4.1.1-1.1.el10_2.aarch64.rpm</link>
      <description><p><strong>java-25-openjdk</strong> - OpenJDK 25 Runtime Environment&lt;br /&gt;</p>

<p>The OpenJDK 25 runtime environment.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Add riscv64 to debug_arches

Thu, 20 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 1:25.0.4.1.1-1.1
- Build for Rocky Linux 10 using our own portable

Fri, 07 Aug 2026 GMT - Andrew Hughes &amp;lt;gnu.andrew@redhat.com&amp;gt; - 1:25.0.4.1.1-1.1
- Update to jdk-25.0.4.1+1 (GA)
- Update release notes to 25.0.4.1+1
- Report pkgos value during build
- Sync the copy of the portable specfile with the latest update
- ** This tarball is embargoed until 2026-08-18 @ 1pm PT. **
- Resolves: RHEL-235627

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mrtg-2.17.10-12.el10_2.1.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 07:31:01 PM GMT</pubDate>
      <guid isPermaLink="false">1932a5b747eaaedb35d8b3f08f3cc2543113623383204e9bc1d35eaadac7163d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mrtg-2.17.10-12.el10_2.1.aarch64.rpm</link>
      <description><p><strong>mrtg</strong> - Multi Router Traffic Grapher&lt;br /&gt;</p>

<p>The Multi Router Traffic Grapher (MRTG) is a tool to monitor the traffic&lt;br /&gt;
load on network-links. MRTG generates HTML pages containing PNG&lt;br /&gt;
images which provide a LIVE visual representation of this traffic.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 11 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.17.10-12.1
- Fix symlink-following chown of pid file in daemon mode (CVE-2026-72694)
  Resolves: RHEL-236045

Mon, 26 Jan 2026 GMT - Vitezslav Crhonek &amp;lt;vcrhonek@redhat.com&amp;gt; - 2.17.10-12
- Add support for Image Mode
  Resolves: RHEL-142231

Wed, 15 Jan 2025 GMT - Vitezslav Crhonek &amp;lt;vcrhonek@redhat.com&amp;gt; - 2.17.10-11
- Remove redundand restorecon call, redirect safe to ignore output
  to /dev/null, mark module directory to avoid rpm verification
  Resolves: RHEL-67894

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mrtg-selinux-2.17.10-12.el10_2.1.noarch</title>
      <pubDate>Thu, 20 Aug 2026 07:30:58 PM GMT</pubDate>
      <guid isPermaLink="false">4a250ed1928deb97c7e9478eabb338c5ec835c56f1163f792aa0825f0aa21863</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mrtg-selinux-2.17.10-12.el10_2.1.noarch.rpm</link>
      <description><p><strong>mrtg-selinux</strong> - mrtg SELinux policy&lt;br /&gt;</p>

<p>Custom SELinux policy module</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 11 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.17.10-12.1
- Fix symlink-following chown of pid file in daemon mode (CVE-2026-72694)
  Resolves: RHEL-236045

Mon, 26 Jan 2026 GMT - Vitezslav Crhonek &amp;lt;vcrhonek@redhat.com&amp;gt; - 2.17.10-12
- Add support for Image Mode
  Resolves: RHEL-142231

Wed, 15 Jan 2025 GMT - Vitezslav Crhonek &amp;lt;vcrhonek@redhat.com&amp;gt; - 2.17.10-11
- Remove redundand restorecon call, redirect safe to ignore output
  to /dev/null, mark module directory to avoid rpm verification
  Resolves: RHEL-67894

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-util-devel-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">c56c7b204546c946d7cf827535b928c43812cee1ce87c07746e6b5b943cdffae</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-util-devel-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-util-devel</strong> - Development libraries for Network Security Services Utilities&lt;br /&gt;</p>

<p>Header and library files for doing development with Network Security Services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-util-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">f1a46f851383ebb1106ef11aa9358f98a5e41029b419f8e6fe0dd1d9806bd361</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-util-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-util</strong> - Network Security Services Utilities Library&lt;br /&gt;</p>

<p>Utilities for Network Security Services and the Softoken module</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-tools-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">c8b155cc55efce60f79a148f3f5e91b20d6943b8e689e1d4afecccda1bd24aff</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-tools-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-tools</strong> - Tools for the Network Security Services&lt;br /&gt;</p>

<p>Network Security Services (NSS) is a set of libraries designed to&lt;br /&gt;
support cross-platform development of security-enabled client and&lt;br /&gt;
server applications. Applications built with NSS can support SSL v2&lt;br /&gt;
and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509&lt;br /&gt;
v3 certificates, and other security standards.&lt;br /&gt;
&lt;br /&gt;
Install the nss-tools package if you need command-line tools to&lt;br /&gt;
manipulate the NSS certificate and key database.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-sysinit-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">2f93d2f8c18ad07ef6110f45a4da43bb7c0c3982ad84eb32c9758390bd6ff545</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-sysinit-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-sysinit</strong> - System NSS Initialization&lt;br /&gt;</p>

<p>Default Operating System module that manages applications loading&lt;br /&gt;
NSS globally on the system. This module loads the system defined&lt;br /&gt;
PKCS #11 modules for NSS and chains with other NSS modules to load&lt;br /&gt;
any system or user configured modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-softokn-freebl-devel-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">aaf32a58d503388e476830aa61201382d0e20fa9754741f2fd2374f044c1fb2e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-softokn-freebl-devel-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-softokn-freebl-devel</strong> - Header and Library files for doing development with the Freebl library for NSS&lt;br /&gt;</p>

<p>NSS Softoken Cryptographic Module Freebl Library Development Tools&lt;br /&gt;
This package supports special needs of some PKCS #11 module developers and&lt;br /&gt;
is otherwise considered private to NSS. As such, the programming interfaces&lt;br /&gt;
may change and the usual NSS binary compatibility commitments do not apply.&lt;br /&gt;
Developers should rely only on the officially supported NSS public API.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-softokn-freebl-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">6a57e644eb34c4e0848d9ef115958e864a6351836d6f796db56f30d19c3b565d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-softokn-freebl-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-softokn-freebl</strong> - Freebl library for the Network Security Services&lt;br /&gt;</p>

<p>NSS Softoken Cryptographic Module Freebl Library&lt;br /&gt;
&lt;br /&gt;
Install the nss-softokn-freebl package if you need the freebl library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-softokn-devel-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">6fec0d2306fa401ade5dc01205301a18e06015e505c51594ffb9c98ed08e758f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-softokn-devel-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-softokn-devel</strong> - Development libraries for Network Security Services&lt;br /&gt;</p>

<p>Header and library files for doing development with Network Security Services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-softokn-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">ca6ddc92c12f12a67b1c3201a22119413a7f8910890ec1653f5a31e77941c5f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-softokn-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-softokn</strong> - Network Security Services Softoken Module&lt;br /&gt;</p>

<p>Network Security Services Softoken Cryptographic Module</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-devel-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">a727b1d11efd92c54be72fa52c1b887e9cbf08aa0bf186a70321a825f94f2095</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-devel-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss-devel</strong> - Development libraries for Network Security Services&lt;br /&gt;</p>

<p>Header and Library files for doing development with Network Security Services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nss-3.124.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">6352d8df4ee85f26097d57661cd66942dbde0a2fa2fc6d9ce1d57e1022cb236c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nss-3.124.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nss</strong> - Network Security Services&lt;br /&gt;</p>

<p>Network Security Services (NSS) is a set of libraries designed to&lt;br /&gt;
support cross-platform development of security-enabled client and&lt;br /&gt;
server applications. Applications built with NSS can support SSL v2&lt;br /&gt;
and v3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509&lt;br /&gt;
v3 certificates, and other security standards.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nspr-devel-4.39.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">01f538fcfcc54c11efc793f01180d5b44d4d59d35af5d6d389292097b74afeca</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nspr-devel-4.39.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nspr-devel</strong> - Development libraries for the Netscape Portable Runtime&lt;br /&gt;</p>

<p>Header files for doing development with the Netscape Portable Runtime.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>nspr-4.39.0-5.el10_2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 09:33:23 AM GMT</pubDate>
      <guid isPermaLink="false">c37ef49a754e0b08fc45adb0d9602125b33ca9c2eaa076cfec6f88036e65911e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/n/nspr-4.39.0-5.el10_2.aarch64.rpm</link>
      <description><p><strong>nspr</strong> - Netscape Portable Runtime&lt;br /&gt;</p>

<p>NSPR provides platform independence for non-GUI operating system&lt;br /&gt;
facilities. These facilities include threads, thread synchronization,&lt;br /&gt;
normal file and network I/O, interval timing and calendar time, basic&lt;br /&gt;
memory management (malloc and free) and shared library linking.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 22 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-5
- full fix to pss issues

Tue, 16 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-4
- fix pkcs12 defaults
- fix pss issues
- remove crmf

Tue, 09 Jun 2026 GMT - Bob Relyea &amp;lt;rrelyea@redhat.com&amp;gt; - 3.124.0-2
- rebase fixes
- restore mlkem aliases
- add mlkem key lengths to the mechanism info
- fix crash if you try to encapsulate with an unimported
  public key
- restore distrusted certs to certdata.txt even though we
  never reference them to make tests happy.

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>yggdrasil-0.4.9.2-1.el10_2.2.aarch64</title>
      <pubDate>Thu, 20 Aug 2026 02:12:50 AM GMT</pubDate>
      <guid isPermaLink="false">621202a0e885ec8515fee8ee7b255e583ed0fa87d63b5cc442fbe0ef458317bb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/y/yggdrasil-0.4.9.2-1.el10_2.2.aarch64.rpm</link>
      <description><p><strong>yggdrasil</strong> - Remote data transmission and processing client&lt;br /&gt;</p>

<p>yggdrasil is a system daemon that subscribes to topics on an MQTT broker and&lt;br /&gt;
routes any data received on the topics to an appropriate child "worker" process,&lt;br /&gt;
exchanging data with its worker processes through a D-Bus message broker.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 12 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 0.4.9.2-2
- Rebuild yggdrasil against updated golang

Mon, 13 Jul 2026 GMT - Jason Jerome &amp;lt;jajerome@redhat.com&amp;gt; - 0.4.9.2-1
- Update yggdrasil to 0.4.9.2

Wed, 01 Jul 2026 GMT - Jason Jerome &amp;lt;jajerome@redhat.com&amp;gt; - 0.4.9.1-1
- Update yggdrasil to 0.4.9.1

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>ansible-test-1:2.16.16-2.el10_2.1.noarch</title>
      <pubDate>Thu, 20 Aug 2026 02:10:06 AM GMT</pubDate>
      <guid isPermaLink="false">b0e71243f4b1efd9acd76fa333732a4b1a54599d7b25696e42fc7f97f44dae80</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/ansible-test-2.16.16-2.el10_2.1.noarch.rpm</link>
      <description><p><strong>ansible-test</strong> - Tool for testing ansible plugin and module code&lt;br /&gt;</p>

<p>Ansible is a radically simple model-driven configuration management,&lt;br /&gt;
multi-node deployment, and remote task execution system. Ansible works&lt;br /&gt;
over SSH and does not require any software or daemons to be installed&lt;br /&gt;
on remote nodes. Extension modules can be written in any language and&lt;br /&gt;
are transferred to managed machines automatically.&lt;br /&gt;
&lt;br /&gt;
This package installs the ansible-test command for testing modules and plugins&lt;br /&gt;
developed for ansible.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sat, 11 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1:2.16.16-2.1
- Fix CVE-2026-11332 (ansible-galaxy role installs could allow
  arbitrary git configuration injection via malformed role
  requirements) (RHEL-194128)

Tue, 10 Feb 2026 GMT - Dimitri Savineau &amp;lt;dsavinea@redhat.com&amp;gt; - 1:2.16.16-2
- Fix selinux AVC denial when telemetry is enabled (RHEL-148292)

Tue, 03 Feb 2026 GMT - Dimitri Savineau &amp;lt;dsavinea@redhat.com&amp;gt; - 1:2.16.16-1
- ansible-core 2.16.16 release (RHEL-145990)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>ansible-core-1:2.16.16-2.el10_2.1.noarch</title>
      <pubDate>Thu, 20 Aug 2026 02:10:06 AM GMT</pubDate>
      <guid isPermaLink="false">3abd7abf089f8abdafb3a185d24117f120ad3b02cdf5797154e3679262b5d9b0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/ansible-core-2.16.16-2.el10_2.1.noarch.rpm</link>
      <description><p><strong>ansible-core</strong> - A radically simple IT automation system&lt;br /&gt;</p>

<p>Ansible is a radically simple model-driven configuration management,&lt;br /&gt;
multi-node deployment, and remote task execution system. Ansible works&lt;br /&gt;
over SSH and does not require any software or daemons to be installed&lt;br /&gt;
on remote nodes. Extension modules can be written in any language and&lt;br /&gt;
are transferred to managed machines automatically.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sat, 11 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1:2.16.16-2.1
- Fix CVE-2026-11332 (ansible-galaxy role installs could allow
  arbitrary git configuration injection via malformed role
  requirements) (RHEL-194128)

Tue, 10 Feb 2026 GMT - Dimitri Savineau &amp;lt;dsavinea@redhat.com&amp;gt; - 1:2.16.16-2
- Fix selinux AVC denial when telemetry is enabled (RHEL-148292)

Tue, 03 Feb 2026 GMT - Dimitri Savineau &amp;lt;dsavinea@redhat.com&amp;gt; - 1:2.16.16-1
- ansible-core 2.16.16 release (RHEL-145990)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-xml-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">f00412ac3d51eda898370a4c44fb1fd587bf8d81432c4c741ee63e69f74d7f75</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-xml-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-xml</strong> - A module for PHP applications which use XML&lt;br /&gt;</p>

<p>The php8.4-xml package contains dynamic shared objects which add support&lt;br /&gt;
to PHP for manipulating XML documents using the DOM tree,&lt;br /&gt;
and performing XSL transformations on XML documents.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-soap-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">1160bd9314567929682eae922739172ece2741e16f678810112a339a79b318c0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-soap-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-soap</strong> - A module for PHP applications that use the SOAP protocol&lt;br /&gt;</p>

<p>The php8.4-soap package contains a dynamic shared object that will add&lt;br /&gt;
support to PHP for using the SOAP web services protocol.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-snmp-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">a9b904f6e0bc48ca7b91c1895488ce889cb48de4d012ee6b548ad8654446360a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-snmp-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-snmp</strong> - A module for PHP applications that query SNMP-managed devices&lt;br /&gt;</p>

<p>The php8.4-snmp package contains a dynamic shared object that will add&lt;br /&gt;
support for querying SNMP devices to PHP.  PHP is an HTML-embeddable&lt;br /&gt;
scripting language. If you need SNMP support for PHP applications, you&lt;br /&gt;
will need to install this package and the php package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-process-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">1fbe365638e23b522352f7183d9570a376978dc6fc53cb19051be18f8329e0e6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-process-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-process</strong> - Modules for PHP script using system process interfaces&lt;br /&gt;</p>

<p>The php8.4-process package contains dynamic shared objects which add&lt;br /&gt;
support to PHP using system interfaces for inter-process&lt;br /&gt;
communication.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-pgsql-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">a86dcf77bdacabac6565217c74b6a3f48eb059283880ca57c6f7a9a59b55fa6c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-pgsql-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-pgsql</strong> - A PostgreSQL database module for PHP&lt;br /&gt;</p>

<p>The php8.4-pgsql package add PostgreSQL database support to PHP.&lt;br /&gt;
PostgreSQL is an object-relational database management&lt;br /&gt;
system that supports almost all SQL constructs. PHP is an&lt;br /&gt;
HTML-embedded scripting language. If you need back-end support for&lt;br /&gt;
PostgreSQL, you should install this package in addition to the main&lt;br /&gt;
php package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-pdo-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">b84faf5fea8130502c603ec90281afbbbef7ae77d0841c27a966f8553b630cf9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-pdo-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-pdo</strong> - A database access abstraction module for PHP applications&lt;br /&gt;</p>

<p>The php8.4-pdo package contains a dynamic shared object that will add&lt;br /&gt;
a database access abstraction layer to PHP.  This module provides&lt;br /&gt;
a common interface for accessing MySQL, PostgreSQL or other&lt;br /&gt;
databases.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-opcache-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">05f260d83622f41376e979e21279eee036aac929f7dfdf36e17bb0955a90694e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-opcache-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-opcache</strong> - The Zend OPcache&lt;br /&gt;</p>

<p>The Zend OPcache provides faster PHP execution through opcode caching and&lt;br /&gt;
optimization. It improves PHP performance by storing precompiled script&lt;br /&gt;
bytecode in the shared memory. This eliminates the stages of reading code from&lt;br /&gt;
the disk and compiling it on future access. In addition, it applies a few&lt;br /&gt;
bytecode optimization patterns that make code execution faster.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-odbc-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">1f58e9b53738e0cbeece199218423dacb2ed5beaf8a52302bc89fb804fae5319</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-odbc-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-odbc</strong> - A module for PHP applications that use ODBC databases&lt;br /&gt;</p>

<p>The php8.4-odbc package contains a dynamic shared object that will add&lt;br /&gt;
database support through ODBC to PHP. ODBC is an open specification&lt;br /&gt;
which provides a consistent API for developers to use for accessing&lt;br /&gt;
data sources (which are often, but not always, databases). PHP is an&lt;br /&gt;
HTML-embeddable scripting language. If you need ODBC support for PHP&lt;br /&gt;
applications, you will need to install this package and the php&lt;br /&gt;
package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-mysqlnd-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">aa5c39602edd287e72a06eb4a82607f8e52c96f91331cff08ad0fb8eaf6972f4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-mysqlnd-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-mysqlnd</strong> - A module for PHP applications that use MySQL databases&lt;br /&gt;</p>

<p>The php8.4-mysqlnd package contains a dynamic shared object that will add&lt;br /&gt;
MySQL database support to PHP. MySQL is an object-relational database&lt;br /&gt;
management system. PHP is an HTML-embeddable scripting language. If&lt;br /&gt;
you need MySQL support for PHP applications, you will need to install&lt;br /&gt;
this package and the php package.&lt;br /&gt;
&lt;br /&gt;
This package use the MySQL Native Driver</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-mbstring-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">cdb883dec2b0e50e33f1f22ad6d2425b7a2e26ab9fe0e098001897c6170aece9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-mbstring-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-mbstring</strong> - A module for PHP applications which need multi-byte string handling&lt;br /&gt;</p>

<p>The php8.4-mbstring package contains a dynamic shared object that will add&lt;br /&gt;
support for multi-byte string handling to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-ldap-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">e47d822bb620ecfea4699ab667e649fbc2689b022eaf114ee59d7704c57f379a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-ldap-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-ldap</strong> - A module for PHP applications that use LDAP&lt;br /&gt;</p>

<p>The php8.4-ldap adds Lightweight Directory Access Protocol (LDAP)&lt;br /&gt;
support to PHP. LDAP is a set of protocols for accessing directory&lt;br /&gt;
services over the Internet. PHP is an HTML-embedded scripting&lt;br /&gt;
language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-intl-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">ee5b3c70e35d218d8ae5fd29f21ce8557cb273a3724e5339e104a14bfb1feaa3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-intl-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-intl</strong> - Internationalization extension for PHP applications&lt;br /&gt;</p>

<p>The php8.4-intl package contains a dynamic shared object that will add&lt;br /&gt;
support for using the ICU library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-gmp-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">df63b4c54d7fd751a62ebdffd6adf773fa97ec54ba361bc65f34ef48a49ede1a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-gmp-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-gmp</strong> - A module for PHP applications for using the GNU MP library&lt;br /&gt;</p>

<p>These functions allow you to work with arbitrary-length integers&lt;br /&gt;
using the GNU MP library.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-gd-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">8e2ab3d0667116946114ddc5167941d617e5793a37a8cf3c82ad4b54d2e617de</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-gd-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-gd</strong> - A module for PHP applications for using the gd graphics library&lt;br /&gt;</p>

<p>The php8.4-gd package contains a dynamic shared object that will add&lt;br /&gt;
support for using the gd graphics library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-fpm-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">143cf0a731cd32b6d516503814093d0bdcc2c53bc1563b07c175cab7cc5032bb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-fpm-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-fpm</strong> - PHP FastCGI Process Manager&lt;br /&gt;</p>

<p>PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI&lt;br /&gt;
implementation with some additional features useful for sites of&lt;br /&gt;
any size, especially busier sites.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-ffi-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">7180a9e0b12676419b639f7468ab83bd28f7b7897d4907339012565cfe0e2db4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-ffi-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-ffi</strong> - Foreign Function Interface&lt;br /&gt;</p>

<p>FFI is one of the features that made Python and LuaJIT very useful for fast&lt;br /&gt;
prototyping. It allows calling C functions and using C data types from pure&lt;br /&gt;
scripting language and therefore develop “system code” more productively.&lt;br /&gt;
&lt;br /&gt;
For PHP, FFI opens a way to write PHP extensions and bindings to C libraries&lt;br /&gt;
in pure PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-enchant-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">ece54ad389d21277ac995434cfb3f5930ed3a9482bdcc55e8573e05c7700a1d1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-enchant-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-enchant</strong> - Enchant spelling extension for PHP applications&lt;br /&gt;</p>

<p>The php8.4-enchant package contains a dynamic shared object that will add&lt;br /&gt;
support for using the enchant library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-embedded-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">4cd4bca333067081d105a8fca23a2b3e0881f9d2353bc6133b18526291357f96</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-embedded-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-embedded</strong> - PHP library for embedding in applications&lt;br /&gt;</p>

<p>The php8.4-embedded package contains a library which can be embedded&lt;br /&gt;
into applications to provide PHP scripting language support.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-devel-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">74fc2cd230969c8c81fdc289804246541bbb854b9110b07f85db0f2cadc8edb1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-devel-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-devel</strong> - Files needed for building PHP extensions&lt;br /&gt;</p>

<p>The php8.4-devel package contains the files needed for building PHP&lt;br /&gt;
extensions. If you need to compile your own PHP extensions, you will&lt;br /&gt;
need to install this package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-dbg-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">6a8e26d4d4d7b27ffe01f2d930ce92bdcddb35b2b3fbd1b9d99075f006bd06f1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-dbg-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-dbg</strong> - The interactive PHP debugger&lt;br /&gt;</p>

<p>The php8.4-dbg package contains the interactive PHP debugger.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-dba-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">211fe7eb1ba0880e5e0756996b5313c5761f46c83d2d4b0bbc32134eb4ee96a7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-dba-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-dba</strong> - A database abstraction layer module for PHP applications&lt;br /&gt;</p>

<p>The php8.4-dba package contains a dynamic shared object that will add&lt;br /&gt;
support for using the DBA database abstraction layer to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-common-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">7e0a373de0bed6ca1ec90b4144a9afca93e4e21c0f0dbd6358ee4677c3d0d6b4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-common-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-common</strong> - Common files for PHP&lt;br /&gt;</p>

<p>The php8.4-common package contains files used by both the php8.4&lt;br /&gt;
package and the php8.4-cli package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-cli-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">3dddafecdada9478a067b8756706cb43a2286f70ba31276a6886823bfda646ca</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-cli-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-cli</strong> - Command-line interface for PHP&lt;br /&gt;</p>

<p>The php8.4-cli package contains the command-line interface&lt;br /&gt;
executing PHP scripts, /usr/bin/php, and the CGI interface.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-bcmath-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">3ea1754a9231174b61aece902a6bbe0de45c3d0728d0b8da478b253ff71b92ec</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-bcmath-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4-bcmath</strong> - A module for PHP applications for using the bcmath library&lt;br /&gt;</p>

<p>The php8.4-bcmath package contains a dynamic shared object that will add&lt;br /&gt;
support for using the bcmath library to PHP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>php8.4-8.4.24-1.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:48 PM GMT</pubDate>
      <guid isPermaLink="false">6f3a066d303398542a86a62f04c641b2a1c70cddcfeaa595f103b2ca8509732e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/php8.4-8.4.24-1.el10_2.aarch64.rpm</link>
      <description><p><strong>php8.4</strong> - PHP scripting language for creating dynamic web sites&lt;br /&gt;</p>

<p>PHP is an HTML-embedded scripting language. PHP attempts to make it&lt;br /&gt;
easy for developers to write dynamically generated web pages. PHP also&lt;br /&gt;
offers built-in database integration for several commercial and&lt;br /&gt;
non-commercial database management systems, so writing a&lt;br /&gt;
database-enabled webpage with PHP is fairly simple. The most common&lt;br /&gt;
use of PHP coding is probably as a replacement for CGI scripts.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.24-2
- rebase to 8.4.24

Wed, 08 Jul 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.23-1
- rebase to 8.4.23

Tue, 26 May 2026 GMT - Remi Collet &amp;lt;rcollet@redhat.com&amp;gt; - 8.4.21-1
- rebase to 8.4.21

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libcupsfilters-1:2.0.0-13.el10_2.aarch64</title>
      <pubDate>Wed, 19 Aug 2026 03:03:17 PM GMT</pubDate>
      <guid isPermaLink="false">a26614f2e5c8f19e4b89be58f99a69b06de613e372f5e5e327591de69afce47d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libcupsfilters-2.0.0-13.el10_2.aarch64.rpm</link>
      <description><p><strong>libcupsfilters</strong> - Library for developing printing filters&lt;br /&gt;</p>

<p>Libcupsfilters provides a library, which implements common functions used&lt;br /&gt;
in cups-browsed daemon and printing filters, and additional files&lt;br /&gt;
as banner templates and character sets. The filters are used in CUPS daemon&lt;br /&gt;
and in printer applications.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1:2.0.0-13
- RHEL-214027 CVE-2026-64611 libcupsfilters: Fix infinite loop and
  empty device_ids in ieee1284

Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1:2.0.0-12
- RHEL-212655 CVE-2026-64612 libcupsfilters: Handle libpng errors
  via longjmp()/setjmp() to prevent process abort on malformed PNG

Mon, 04 Aug 2025 GMT - Zdenek Dohnal &amp;lt;zdohnal@redhat.com&amp;gt; - 1:2.0.0-11
- RHEL-68430 texttopdf omits Chinese characters when creating PDF documents

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-Date-Manip-6.94-5.el10_2.1.noarch</title>
      <pubDate>Wed, 19 Aug 2026 03:03:10 PM GMT</pubDate>
      <guid isPermaLink="false">d02826cbdda862762e33f007711157ed7443fd122c9e546af669d71afae3d360</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-Date-Manip-6.94-5.el10_2.1.noarch.rpm</link>
      <description><p><strong>perl-Date-Manip</strong> - Date manipulation routines&lt;br /&gt;</p>

<p>Date::Manip is a series of modules designed to make any common date/time&lt;br /&gt;
operation easy to do. Operations such as comparing two times, determining&lt;br /&gt;
a data a given amount of time from another, or parsing international times&lt;br /&gt;
are all easily done. It deals with time as it is used in the Gregorian&lt;br /&gt;
calendar (the one currently in use) with full support for time changes due&lt;br /&gt;
to daylight saving time.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 6.94-5.1
- Fix CVE-2026-60075: prevent quadratic-cost regex DoS in date/time
  parsing by rejecting overly long input strings
  Resolves: RHEL-239790

Tue, 29 Oct 2024 GMT - Troy Dawson &amp;lt;tdawson@redhat.com&amp;gt; - 6.94-5
- Bump release for October 2024 mass rebuild:
  Resolves: RHEL-64018

&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mysql8.4-errmsg-8.4.11-1.el10_2.rocky.0.1.noarch</title>
      <pubDate>Tue, 18 Aug 2026 11:16:34 PM GMT</pubDate>
      <guid isPermaLink="false">7906622ae3bc6ecb423119e077a37b85d3582b01040239b537df12661b1595bb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mysql8.4-errmsg-8.4.11-1.el10_2.rocky.0.1.noarch.rpm</link>
      <description><p><strong>mysql8.4-errmsg</strong> - The error messages files required by MySQL server&lt;br /&gt;</p>

<p>The package provides error messages files for the MySQL daemon</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 8.4.11-1.rocky.0.1
- Ensure riscv64 support is there

Tue, 28 Jul 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.4.11-1
- Rebase to 8.4.11

Wed, 06 May 2026 GMT - Michal Schorm &amp;lt;mschorm@redhat.com&amp;gt; - 8.4.9-1
- Rebase to 8.4.9

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mysql8.4-common-8.4.11-1.el10_2.rocky.0.1.noarch</title>
      <pubDate>Tue, 18 Aug 2026 11:16:34 PM GMT</pubDate>
      <guid isPermaLink="false">676a05962415357b1939f6e215649298d444b2dd517606a8f59e67b272d81a72</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mysql8.4-common-8.4.11-1.el10_2.rocky.0.1.noarch.rpm</link>
      <description><p><strong>mysql8.4-common</strong> - The shared files required for MySQL server and client&lt;br /&gt;</p>

<p>The mysql-common package provides the essential shared files for any&lt;br /&gt;
MySQL program. You will need to install this package to use any other&lt;br /&gt;
MySQL package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 8.4.11-1.rocky.0.1
- Ensure riscv64 support is there

Tue, 28 Jul 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.4.11-1
- Rebase to 8.4.11

Wed, 06 May 2026 GMT - Michal Schorm &amp;lt;mschorm@redhat.com&amp;gt; - 8.4.9-1
- Rebase to 8.4.9

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mysql8.4-server-8.4.11-1.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 11:16:29 PM GMT</pubDate>
      <guid isPermaLink="false">62fb63abe524ca8036b6282e6bfaacf6f52cff6890474f7a92183e8f1ab72cb3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mysql8.4-server-8.4.11-1.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>mysql8.4-server</strong> - The MySQL server and related files&lt;br /&gt;</p>

<p>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a&lt;br /&gt;
client/server implementation consisting of a server daemon (mysqld)&lt;br /&gt;
and many different client programs and libraries. This package contains&lt;br /&gt;
the MySQL server and some accompanying files and directories.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 8.4.11-1.rocky.0.1
- Ensure riscv64 support is there

Tue, 28 Jul 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.4.11-1
- Rebase to 8.4.11

Wed, 06 May 2026 GMT - Michal Schorm &amp;lt;mschorm@redhat.com&amp;gt; - 8.4.9-1
- Rebase to 8.4.9

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mysql8.4-libs-8.4.11-1.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 11:16:29 PM GMT</pubDate>
      <guid isPermaLink="false">94607897b430f924f24ed5e15f76d9f2c26ebe10061e45bdca32606ceca64bfd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mysql8.4-libs-8.4.11-1.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>mysql8.4-libs</strong> - The shared libraries required for MySQL clients&lt;br /&gt;</p>

<p>The mysql-libs package provides the essential shared libraries for any&lt;br /&gt;
MySQL client program or interface. You will need to install this package&lt;br /&gt;
to use any other MySQL package or any clients that need to connect to a&lt;br /&gt;
MySQL server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 8.4.11-1.rocky.0.1
- Ensure riscv64 support is there

Tue, 28 Jul 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.4.11-1
- Rebase to 8.4.11

Wed, 06 May 2026 GMT - Michal Schorm &amp;lt;mschorm@redhat.com&amp;gt; - 8.4.9-1
- Rebase to 8.4.9

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>mysql8.4-8.4.11-1.el10_2.rocky.0.1.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 11:16:29 PM GMT</pubDate>
      <guid isPermaLink="false">ade6dbaf0b0cc7a540d1be15f7ae58f5b95bf526ab4e43b2b21bfb3c3a40165e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/m/mysql8.4-8.4.11-1.el10_2.rocky.0.1.aarch64.rpm</link>
      <description><p><strong>mysql8.4</strong> - MySQL client programs and shared libraries&lt;br /&gt;</p>

<p>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a&lt;br /&gt;
client/server implementation consisting of a server daemon (mysqld)&lt;br /&gt;
and many different client programs and libraries. The base package&lt;br /&gt;
contains the standard MySQL client programs and generic MySQL files.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Tue, 18 Aug 2026 GMT - Release Engineering &amp;lt;releng@rockylinux.org&amp;gt; - 8.4.11-1.rocky.0.1
- Ensure riscv64 support is there

Tue, 28 Jul 2026 GMT - Petr Khartskhaev &amp;lt;pkhartsk@redhat.com&amp;gt; - 8.4.11-1
- Rebase to 8.4.11

Wed, 06 May 2026 GMT - Michal Schorm &amp;lt;mschorm@redhat.com&amp;gt; - 8.4.9-1
- Rebase to 8.4.9

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-unbound-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">f4f4b864556c431ec2b9ef5d6d608b7ca22abea2179f0a374616d674f513d35a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-unbound-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>python3-unbound</strong> - Python 3 modules and extensions for unbound&lt;br /&gt;</p>

<p>Python 3 modules and extensions for unbound</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>unbound-utils-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">553497778fab63c5209cdadffd30f6d4785806a30bbb5b7a5b4b6e32b09dba85</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/u/unbound-utils-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>unbound-utils</strong> - Unbound DNS lookup utilities&lt;br /&gt;</p>

<p>Contains tools for making DNS queries. Can make queries to DNS servers&lt;br /&gt;
also over TLS connection or validate DNSSEC signatures. Similar to&lt;br /&gt;
bind-utils.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>unbound-libs-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">df5c7ad2517f81bf39704d43067d48be6bec9e690fc83d78f872b6ecd6aeb366</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/u/unbound-libs-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>unbound-libs</strong> - Libraries used by the unbound server and client applications&lt;br /&gt;</p>

<p>Contains libraries used by the unbound server and client applications.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>unbound-dracut-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">8ef707ff74cbfcc5ef109a50abc2bb7ade547386c0b39c65a067ba66d55facf1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/u/unbound-dracut-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>unbound-dracut</strong> - Unbound dracut module&lt;br /&gt;</p>

<p>Unbound dracut module allowing use of Unbound for name resolution&lt;br /&gt;
in initramfs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>unbound-anchor-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">56f864000ea364742d1bbb74343dd6b7f9a912f2eb836520d7d361ad19c0d819</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/u/unbound-anchor-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>unbound-anchor</strong> - DNSSEC trust anchor maintaining tool&lt;br /&gt;</p>

<p>Contains tool maintaining trust anchor using RFC 5011 key rollover algorithm.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>unbound-1.24.2-7.el10_2.4.aarch64</title>
      <pubDate>Tue, 18 Aug 2026 03:07:07 AM GMT</pubDate>
      <guid isPermaLink="false">6c9b2a94d7dc758c1f6cc766141668ad6404d4d4d572f438675ba4332acae321</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/u/unbound-1.24.2-7.el10_2.4.aarch64.rpm</link>
      <description><p><strong>unbound</strong> - Validating, recursive, and caching DNS(SEC) resolver&lt;br /&gt;</p>

<p>Unbound is a validating, recursive, and caching DNS(SEC) resolver.&lt;br /&gt;
&lt;br /&gt;
The C implementation of Unbound is developed and maintained by NLnet&lt;br /&gt;
Labs. It is based on ideas and algorithms taken from a java prototype&lt;br /&gt;
developed by Verisign labs, Nominet, Kirei and ep.net.&lt;br /&gt;
&lt;br /&gt;
Unbound is designed as a set of modular components, so that also&lt;br /&gt;
DNSSEC (secure DNS) validation and stub-resolvers (that do not run&lt;br /&gt;
as a server, but are linked into an application) are easily possible.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 05 Aug 2026 GMT - Fedor Vorobev &amp;lt;fvorobev@redhat.com&amp;gt; - 1.24.2-18
- Add unit tests for CVE-2026-{44690,55973}

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-17
- Fix CVE-2026-55973: dns-error-reporting stack buffer overflow

Wed, 05 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.24.2-16
- Fix CVE-2026-44690 - Cross-zone wildcard cache poisoning

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-templates-10.0-10.0.111-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">d6fae6797739cb1b25602e57f5fe54d7002d0907a06dcc34f2b7fa95914a5893</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-templates-10.0-10.0.111-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-templates-10.0</strong> - .NET 10.0 templates&lt;br /&gt;</p>

<p>This package contains templates used by the .NET SDK.&lt;br /&gt;
&lt;br /&gt;
.NET is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-targeting-pack-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">8a1d17385ef6f8adf3d4c1e8306365c1b22033178cdcfeb5a5dbf480c0c2fc74</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-targeting-pack-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-targeting-pack-10.0</strong> - Targeting Pack for Microsoft.NETCore.App 10.0&lt;br /&gt;</p>

<p>This package provides a targeting pack for Microsoft.NETCore.App 10.0&lt;br /&gt;
that allows developers to compile against and target Microsoft.NETCore.App 10.0&lt;br /&gt;
applications using the .NET SDK.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-sdk-dbg-10.0-10.0.111-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">4d0736acbaa35e426335c6fbf91bbabae3083ac0529208a64817c7156f7a74f8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-sdk-dbg-10.0-10.0.111-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-sdk-dbg-10.0</strong> - Managed debug symbols for the .NET 10.0 Software Development Kit&lt;br /&gt;</p>

<p>This package contains the managed symbol (pdb) files useful to debug the .NET&lt;br /&gt;
Software Development Kit (SDK) itself.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-sdk-aot-10.0-10.0.111-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">57e64cab6f7bf21bc18580154d1007da76e0f93cff50e375908649b66e86e476</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-sdk-aot-10.0-10.0.111-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-sdk-aot-10.0</strong> - Ahead-of-Time (AOT) support for the .NET 10.0 Software Development Kit&lt;br /&gt;</p>

<p>This package provides Ahead-of-time (AOT) compilation support for the .NET SDK.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-sdk-10.0-10.0.111-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">7c633460a6a78b361ec1ab6d77cbe401bdde0d853d8eaa571ecc65eff2eef6e9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-sdk-10.0-10.0.111-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-sdk-10.0</strong> - .NET 10.0 Software Development Kit&lt;br /&gt;</p>

<p>The .NET SDK is a collection of command line applications to&lt;br /&gt;
create, build, publish and run .NET applications.&lt;br /&gt;
&lt;br /&gt;
.NET is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-runtime-dbg-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">0c4f94df921269a382b49e90759d4f6b7e59164fa4556eed6c89acfefd53993a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-runtime-dbg-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-runtime-dbg-10.0</strong> - Managed debug symbols NET 10.0 runtime&lt;br /&gt;</p>

<p>This package contains the managed symbol (pdb) files useful to debug the&lt;br /&gt;
managed parts of the .NET runtime itself.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-runtime-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">0457bf15c9b78d54aedfa3797ff5905ef6a8578d6132746e2de5ce55335c6b28</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-runtime-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-runtime-10.0</strong> - NET 10.0 runtime&lt;br /&gt;</p>

<p>The .NET runtime contains everything needed to run .NET applications.&lt;br /&gt;
It includes a high performance Virtual Machine as well as the framework&lt;br /&gt;
libraries used by .NET applications.&lt;br /&gt;
&lt;br /&gt;
.NET is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-hostfxr-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">028e85cdf79570e57249de9531af59e89c24ccd1650a9b0647850605e829fa90</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-hostfxr-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-hostfxr-10.0</strong> - .NET command line host resolver&lt;br /&gt;</p>

<p>The .NET host resolver contains the logic to resolve and select&lt;br /&gt;
the right version of the .NET SDK or runtime to use.&lt;br /&gt;
&lt;br /&gt;
.NET is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-host-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">1739eef4b3d3d3ed79dd9f85b4136fdfa4d1af1e8a0aba3162f3ab59835fb98f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-host-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-host</strong> - .NET command line launcher&lt;br /&gt;</p>

<p>The .NET host is a command line program that runs a standalone&lt;br /&gt;
.NET application or launches the SDK.&lt;br /&gt;
&lt;br /&gt;
.NET is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>dotnet-apphost-pack-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">c528026d65224414e2756efac259a019a412676a5cc0ef3dd1503613523fccc8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/d/dotnet-apphost-pack-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>dotnet-apphost-pack-10.0</strong> - Targeting Pack for Microsoft.NETCore.App 10.0&lt;br /&gt;</p>

<p>This package provides a targeting pack for Microsoft.NETCore.App 10.0&lt;br /&gt;
that allows developers to compile against and target Microsoft.NETCore.App 10.0&lt;br /&gt;
applications using the .NET SDK.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>aspnetcore-targeting-pack-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">061751258cd6f0fbbd5b8be9d2b8a5a006c2455c933ab141a545133507804c8a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/aspnetcore-targeting-pack-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>aspnetcore-targeting-pack-10.0</strong> - Targeting Pack for Microsoft.AspNetCore.App 10.0&lt;br /&gt;</p>

<p>This package provides a targeting pack for Microsoft.AspNetCore.App 10.0&lt;br /&gt;
that allows developers to compile against and target Microsoft.AspNetCore.App 10.0&lt;br /&gt;
applications using the .NET SDK.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>aspnetcore-runtime-dbg-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">a57d7d971a0d5eb1f95a418a72a998af8be9d8a9d1f0a6274e106365d077c4f0</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/aspnetcore-runtime-dbg-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>aspnetcore-runtime-dbg-10.0</strong> - Managed debug symbols for the ASP.NET Core 10.0 runtime&lt;br /&gt;</p>

<p>This package contains the managed symbol (pdb) files useful to debug the&lt;br /&gt;
managed parts of the ASP.NET Core runtime itself.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>aspnetcore-runtime-10.0-10.0.11-1.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:52:35 PM GMT</pubDate>
      <guid isPermaLink="false">807418c36040a5d8230a1b22705d22d9ef3e447ab83d96a0bec15acafa68cf91</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/a/aspnetcore-runtime-10.0-10.0.11-1.el10_2.aarch64.rpm</link>
      <description><p><strong>aspnetcore-runtime-10.0</strong> - ASP.NET Core 10.0 runtime&lt;br /&gt;</p>

<p>The ASP.NET Core runtime contains everything needed to run .NET&lt;br /&gt;
web applications. It includes a high performance Virtual Machine as&lt;br /&gt;
well as the framework libraries used by .NET applications.&lt;br /&gt;
&lt;br /&gt;
ASP.NET Core is a fast, lightweight and modular platform for creating&lt;br /&gt;
cross platform web applications that work on Linux, Mac and Windows.&lt;br /&gt;
&lt;br /&gt;
It particularly focuses on creating console applications, web&lt;br /&gt;
applications and micro-services.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Sun, 09 Aug 2026 GMT - Omair Majid &amp;lt;omajid@redhat.com&amp;gt; - 10.0.111-1
- Update to .NET SDK 10.0.111 and Runtime 10.0.11
- Resolves: RHEL-235482

Wed, 08 Jul 2026 GMT - Satish Mane &amp;lt;satmane@redhat.com&amp;gt; - 10.0.110-1
- Update to .NET SDK 10.0.110 and Runtime 10.0.10
- Resolves: RHEL-192463

Thu, 02 Jul 2026 GMT - Tom Deseyn &amp;lt;tdeseyn@redhat.com&amp;gt; - 10.0.109-2
- Reduce time to detect hanging builds
- Resolves: RHEL-191640

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libssh-devel-0.12.0-3.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:49:19 PM GMT</pubDate>
      <guid isPermaLink="false">37f27642eaace8a6853b719a1170e1f0c19d402eff4abdbca122fa7dead75d3c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libssh-devel-0.12.0-3.el10_2.aarch64.rpm</link>
      <description><p><strong>libssh-devel</strong> - Development files for libssh&lt;br /&gt;</p>

<p>The libssh-devel package contains libraries and header files for developing&lt;br /&gt;
applications that use libssh.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 22 Jul 2026 GMT - Pavol Žáčik &amp;lt;pzacik@redhat.com&amp;gt; - 0.12.0-3
- Backport CVE fixes from 0.12.2
  Resolves: RHEL-213004
  Resolves: RHEL-213029
  Resolves: RHEL-213032
  Resolves: RHEL-213039
  Resolves: RHEL-213046
  Resolves: RHEL-213079
  Resolves: RHEL-213112
  Resolves: RHEL-213117
  Resolves: RHEL-213148
  Resolves: RHEL-213150
  Resolves: RHEL-213175

Thu, 19 Feb 2026 GMT - Pavol Žáčik &amp;lt;pzacik@redhat.com&amp;gt; - 0.12.0-2
- Fix the verbosity of some new logs added in 0.12.0
  Resolves: RHEL-93748

Tue, 10 Feb 2026 GMT - Pavol Žáčik &amp;lt;pzacik@redhat.com&amp;gt; - 0.12.0-1
- Rebase to 0.12.0
  Resolves: RHEL-133421, RHEL-70825, RHEL-130042
- Add a Requires for crypto-policies instead of a Recommends
  Resolves: RHEL-139045

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">a5e8e23cd18c5eeb070b3658c21b5efee3b3f5f5715f53aa1c1a5ccae2a441e2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-pcp</strong> - Performance Co-Pilot (PCP) Python3 bindings and documentation&lt;br /&gt;</p>

<p>This python PCP module contains the language bindings for&lt;br /&gt;
Performance Metric API (PMAPI) monitor tools and Performance&lt;br /&gt;
Metric Domain Agent (PMDA) collector tools written in Python3.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-PCP-PMDA-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">8aa46c5bd6e4d5520e5b978147bee1b63c6195f5e57615c1d828a799b063d9a1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-PCP-PMDA-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>perl-PCP-PMDA</strong> - Performance Co-Pilot (PCP) Perl bindings and documentation&lt;br /&gt;</p>

<p>The PCP::PMDA Perl module contains the language bindings for&lt;br /&gt;
building Performance Metric Domain Agents (PMDAs) using Perl.&lt;br /&gt;
Each PMDA exports performance data for one specific domain, for&lt;br /&gt;
example the operating system kernel, Cisco routers, a database,&lt;br /&gt;
an application, etc.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-PCP-MMV-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">0cc18ad90cfe12dd39af042e564264c3361a089a77b7fb20809890b316accf05</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-PCP-MMV-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>perl-PCP-MMV</strong> - Performance Co-Pilot (PCP) Perl bindings for PCP Memory Mapped Values&lt;br /&gt;</p>

<p>The PCP::MMV module contains the Perl language bindings for&lt;br /&gt;
building scripts instrumented with the Performance Co-Pilot&lt;br /&gt;
(PCP) Memory Mapped Value (MMV) mechanism.&lt;br /&gt;
This mechanism allows arbitrary values to be exported from an&lt;br /&gt;
instrumented script into the PCP infrastructure for monitoring&lt;br /&gt;
and analysis with pmchart, pmie, pmlogger and other PCP tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-PCP-LogSummary-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">dc0e7739b9ab7d99ba14042f5b53d13f914fa7815f3ad444c44b318273f0f2ca</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-PCP-LogSummary-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>perl-PCP-LogSummary</strong> - Performance Co-Pilot (PCP) Perl bindings for post-processing output of pmlogsummary&lt;br /&gt;</p>

<p>The PCP::LogSummary module provides a Perl module for using the&lt;br /&gt;
statistical summary data produced by the Performance Co-Pilot&lt;br /&gt;
pmlogsummary utility.  This utility produces various averages,&lt;br /&gt;
minima, maxima, and other calculations based on the performance&lt;br /&gt;
data stored in a PCP archive.  The Perl interface is ideal for&lt;br /&gt;
exporting this data into third-party tools (e.g. spreadsheets).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-PCP-LogImport-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">3841bc621bd96cb31dd1a4c9b4bc99cd64395bd23aad08ad628717e1cae97efc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-PCP-LogImport-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>perl-PCP-LogImport</strong> - Performance Co-Pilot (PCP) Perl bindings for importing external data into PCP archives&lt;br /&gt;</p>

<p>The PCP::LogImport module contains the Perl language bindings for&lt;br /&gt;
importing data in various 3rd party formats into PCP archives so&lt;br /&gt;
they can be replayed with standard PCP monitoring tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-zeroconf-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">443e49c5004383d14865611cb3234bd52f482a0a5da74fcba460931f48ea7f68</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-zeroconf-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-zeroconf</strong> - Performance Co-Pilot (PCP) Zeroconf Package&lt;br /&gt;</p>

<p>This package contains configuration tweaks and files to increase metrics&lt;br /&gt;
gathering frequency, several extended pmlogger configurations, as well as&lt;br /&gt;
automated pmie diagnosis, alerting and self-healing for the localhost.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-system-tools-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">457dd1755015c3843174b0d0b6c21acc82e279e33698aa0339ba2bd97bc78c99</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-system-tools-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-system-tools</strong> - Performance Co-Pilot (PCP) System and Monitoring Tools&lt;br /&gt;</p>

<p>This PCP module contains additional system monitoring tools written&lt;br /&gt;
in the Python language.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-selinux-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">cbdb8ce3d4f16f50a6037381a54bf58302e60d42cf16d30443d820726027060e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-selinux-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-selinux</strong> - Selinux policy package&lt;br /&gt;</p>

<p>This package contains SELinux support for PCP.  The package contains&lt;br /&gt;
interface rules, type enforcement and file context adjustments for an&lt;br /&gt;
updated policy package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-zswap-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">f49ecccd7d720b78ad710c8a20f6b197a9f5334e843b2f31f17ad69e76afbe0b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-zswap-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-zswap</strong> - Performance Co-Pilot (PCP) metrics for compressed swap&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about compressed swap.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-zimbra-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">0f22c1aacf7f17218c7fd3fc72e3368670f9cc7baf6ef0a028ae3728966c7783</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-zimbra-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-zimbra</strong> - Performance Co-Pilot (PCP) metrics for Zimbra&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Zimbra.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-weblog-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">bd1997a49b394b836fa09200cde5229e4310ee0509d36683564ea9ed3c8d2d06</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-weblog-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-weblog</strong> - Performance Co-Pilot (PCP) metrics from web server logs&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about web server logs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-uwsgi-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">5a0b14a4a28753d5a796810c2a576879031f5b8ec0b9a0c54192d85a1dcb3518</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-uwsgi-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-uwsgi</strong> - Performance Co-Pilot (PCP) metrics from uWSGI servers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from uWSGI servers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-unbound-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">c1bc6cc259e12faed77c33ab040e41c67f5bbd129d3c1ea99f7c8f128b7a3944</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-unbound-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-unbound</strong> - Performance Co-Pilot (PCP) metrics for the Unbound DNS Resolver&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Unbound DNS Resolver.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-trace-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">f14986e010d62f67c5d301946f0fa1efc1cc94e6893bed877efeca51db200c51</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-trace-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-trace</strong> - Performance Co-Pilot (PCP) metrics for application tracing&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about trace performance data in applications.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-systemd-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6d9ce2fb0b936c47e054a19119a97ad2a366d5721135c8db241f3d13b966e4ee</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-systemd-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-systemd</strong> - Performance Co-Pilot (PCP) metrics from the Systemd journal&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from the Systemd journal.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-summary-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">40473b8a4b255b7554c3e81442f65f3964e9ac2b3d917f101f8b266c33816a6a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-summary-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-summary</strong> - Performance Co-Pilot (PCP) summary metrics from pmie&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about other installed PMDAs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-statsd-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">8c2b6366959a3a0ff8e9551fddb8395fc297b5349288e5f8e2cfa420d702e8a9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-statsd-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-statsd</strong> - Performance Co-Pilot (PCP) metrics from statsd&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting statistics from the statsd daemon.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-sockets-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">98302c2586e278a7146b4ab5e99866f9a62123f460c9549cf1e64a2ee979a2d4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-sockets-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-sockets</strong> - Performance Co-Pilot (PCP) per-socket metrics&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metric Domain Agent (PMDA) for&lt;br /&gt;
collecting per-socket statistics, making use of utilities such as 'ss'.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-snmp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">466bb42a904bf43ce906ef91ca2ac517b5c2c4c8961316b2aa517d0ca67a9e82</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-snmp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-snmp</strong> - Performance Co-Pilot (PCP) metrics for Simple Network Management Protocol&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about SNMP.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-smart-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">fb38cfb1e5c3c109da61ab2e3c0c5477fa7e3117ae710019f94012130e7405c9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-smart-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-smart</strong> - Performance Co-Pilot (PCP) metrics for S.M.A.R.T values&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metric Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics of disk S.M.A.R.T values making use of data from the&lt;br /&gt;
smartmontools package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-slurm-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">4406e7ee7d7d75c1c29bfdb85fe3380169b5c5c3efc91c3081ef490583c7e05b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-slurm-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-slurm</strong> - Performance Co-Pilot (PCP) metrics for the SLURM Workload Manager&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from the SLURM Workload Manager.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-shping-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">076d793437aa075ababd93f493d3729b57736c427b26551f91efd912299818a8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-shping-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-shping</strong> - Performance Co-Pilot (PCP) metrics for shell command responses&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about quality of service and response time measurements of&lt;br /&gt;
arbitrary shell commands.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-sendmail-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">81b7ad6a34fa64ae945fd55bd01cca62faa008f8f68c40874ed52b2f22013582</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-sendmail-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-sendmail</strong> - Performance Co-Pilot (PCP) metrics for Sendmail&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Sendmail traffic.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-samba-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b839c43f02465a3d6b3f914a27afe4e0a4a9c0af0f57e8e1a2459ef2f9738ec9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-samba-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-samba</strong> - Performance Co-Pilot (PCP) metrics for Samba&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Samba.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-rsyslog-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">18fff23113626545f3394473fd6a5010a45f772bcaef3e559dbc9cfe62a46210</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-rsyslog-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-rsyslog</strong> - Performance Co-Pilot (PCP) metrics for Rsyslog&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Rsyslog.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-roomtemp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">3fc66ea8931623dd0f6b87f4b2ed4fd993fcc6966b2c0cf1d04731d3b673958a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-roomtemp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-roomtemp</strong> - Performance Co-Pilot (PCP) metrics for the room temperature&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the room temperature.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-rocestat-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">1f3c34dd58555a68a240e40b17d5c165c3692d01e47356693cea388a5d7ff723</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-rocestat-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-rocestat</strong> - Performance Co-Pilot (PCP) metrics for nVidia RoCE devices&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting statistics for nVidia RDMA over Converged Ethernet (RoCE) devices.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-redis-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">382382a0c9a97e40e51208472d778d14e02ceb35f8fc6c77c9c3981fc56168dc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-redis-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-redis</strong> - Performance Co-Pilot (PCP) metrics for Redis&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from Redis servers (redis.io).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-rabbitmq-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">a3308628c83a24494cee482044ac8b87beab2d956fe0e23df4620fe2a826ea5b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-rabbitmq-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-rabbitmq</strong> - Performance Co-Pilot (PCP) metrics for RabbitMQ queues&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about RabbitMQ message queues.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-postgresql-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">fb1112bed4706ed910edb84b6e1a3ec94a413c1065f9ce975ebba498191cf334</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-postgresql-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-postgresql</strong> - Performance Co-Pilot (PCP) metrics for PostgreSQL&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the PostgreSQL database.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-postfix-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b1526eb8283a3c2c1f7d28d825ad82ae5cf795e804da845f7da533af1451ea56</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-postfix-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-postfix</strong> - Performance Co-Pilot (PCP) metrics for the Postfix (MTA)&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Postfix (MTA).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-podman-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">9ddde09ef66c848bc7b19064c5724ae2b2637c4e653cf613f17ffbf62358a8ac</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-podman-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-podman</strong> - Performance Co-Pilot (PCP) metrics for podman containers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting podman container and pod statistics via the podman REST API.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-perfevent-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">aff4e8e58507bc1aab0496515007a038f04ea453fc46a37485860ed6d0bbf501</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-perfevent-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-perfevent</strong> - Performance Co-Pilot (PCP) metrics for hardware counters&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting hardware counters statistics through libpfm.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-pdns-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">49b0b6b4e16135640cd2dd72a6f95e4e47eeb61cc4d39819d7b1195fda887c96</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-pdns-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-pdns</strong> - Performance Co-Pilot (PCP) metrics for PowerDNS&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the PowerDNS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-oracle-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">d741debf320b59d2d41107a5f5a5fa4fc724adc5543ab3f178b3762cce4e84b7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-oracle-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-oracle</strong> - Performance Co-Pilot (PCP) metrics for the Oracle database&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Oracle database.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-openvswitch-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">c05fa6411026d59a4a55ccd60d391cb87a8269279fc460774118d6500de40458</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-openvswitch-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-openvswitch</strong> - Performance Co-Pilot (PCP) metrics for Open vSwitch&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from Open vSwitch.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-opentelemetry-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">3b5f71da8baf216f4b22f82600f0e3abab8c32046d0e2900c103556abc0d11fe</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-opentelemetry-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-opentelemetry</strong> - Performance Co-Pilot (PCP) metrics from OpenTelemetry endpoints&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting metrics from OpenTelemetry (https://opentelemetry.io/) endpoints.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-openmetrics-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">faa23dbbf2af5a37f6f3b9c93158b1b89092f732e70c7bfc899fb51af5db90f7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-openmetrics-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-openmetrics</strong> - Performance Co-Pilot (PCP) metrics from OpenMetrics endpoints&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting metrics from OpenMetrics (https://openmetrics.io/) endpoints.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-nvidia-gpu-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">7d030784dd7a8627998708133d6bae942f25195acce5421cf421f1c3cc6c3e0f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-nvidia-gpu-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-nvidia-gpu</strong> - Performance Co-Pilot (PCP) metrics for the Nvidia GPU&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Nvidia GPUs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-nginx-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">e499f2873fa1c3755594192b903b40d181aea476fcfe156347595693881a1673</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-nginx-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-nginx</strong> - Performance Co-Pilot (PCP) metrics for the Nginx Webserver&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Nginx Webserver.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-nfsclient-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">a12edd5b3b1fae9b5bfff63c2f516ec3e0ecf85460d8fdeb7e52dc47a83b69a5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-nfsclient-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-nfsclient</strong> - Performance Co-Pilot (PCP) metrics for NFS Clients&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics for NFS Clients.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-news-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6c84d7d5f84cb980f403fb6b766745c59049d386d968af8e12b1f1e6280f13c8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-news-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-news</strong> - Performance Co-Pilot (PCP) metrics for Usenet News&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Usenet News.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-netfilter-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">d819d4c5a38eced3f30e1f0877306e7d7695fbfec358fe36c2b06c5f7b01bb88</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-netfilter-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-netfilter</strong> - Performance Co-Pilot (PCP) metrics for Netfilter framework&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Netfilter packet filtering framework.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-netcheck-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">a0404afcbe2e13b1e4ee866be53615ff9e2087fdf45e0092cd1fc87cb24dc8fe</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-netcheck-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-netcheck</strong> - Performance Co-Pilot (PCP) metrics for simple network checks&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from simple network checks.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-named-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">02ff28d69a745e6bade9d8f105b9fc6ec99c3af75451b9ba28240bdfed2c0268</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-named-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-named</strong> - Performance Co-Pilot (PCP) metrics for Named&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Named nameserver.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-mysql-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6e658a618ec875d6a134036b4439a965463655469439a67617da93300cfc8438</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-mysql-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-mysql</strong> - Performance Co-Pilot (PCP) metrics for MySQL&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the MySQL database.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-mounts-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">cf052e6d271a72163a66ea24ac6fcccc5c09fbb9576675bc9a502abcb72abdd4</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-mounts-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-mounts</strong> - Performance Co-Pilot (PCP) metrics for filesystem mounts&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about filesystem mounts.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-mongodb-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">179fe9cf483b90261be26d22d9c36a21434e5a180c9dbe9551e85d068e9d4f9a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-mongodb-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-mongodb</strong> - Performance Co-Pilot (PCP) metrics for MongoDB&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from MongoDB.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-mic-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">809802e144031f9a7e13db2048b55ec2d2b2c3d22d6a27219b6442068a87b0a2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-mic-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-mic</strong> - Performance Co-Pilot (PCP) metrics for Intel MIC cards&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Intel MIC cards.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-memcache-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">157bed0e3bf48a7df23df3f06f7bddd7a7e0624e6e24a7a9367e0894890b059a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-memcache-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-memcache</strong> - Performance Co-Pilot (PCP) metrics for Memcached&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Memcached.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-mailq-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">50666246a8b40a67b21e4d4cd014b240f15f9f10471c6ebc31ddb8f34bce49f8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-mailq-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-mailq</strong> - Performance Co-Pilot (PCP) metrics for the sendmail queue&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about email queues managed by sendmail.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-lustrecomm-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">bfceb1f524fdb4d78f323a022065449b93013c151783281c6e26a2a36b465296</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-lustrecomm-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-lustrecomm</strong> - Performance Co-Pilot (PCP) metrics for the Lustre Filesytem Comms&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Lustre Filesystem Comms.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-lustre-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b32ca51dde18aa490ae99174dd20f97dc82d42436290d8da9d4aa018fa2a5c03</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-lustre-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-lustre</strong> - Performance Co-Pilot (PCP) metrics for the Lustre Filesytem&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Lustre Filesystem.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-logger-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">32840642aa6e66be7f8ba49a1cfaf1043dd6b802b164f0edf849a0568e7ada53</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-logger-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-logger</strong> - Performance Co-Pilot (PCP) metrics from arbitrary log files&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from a specified set of log files (or pipes).  The PMDA&lt;br /&gt;
supports both sampled and event-style metrics.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-lmsensors-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">32fa6570ffc01700645f8cd9e27b57cd0a4574e438bde693436c30205f3331c6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-lmsensors-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-lmsensors</strong> - Performance Co-Pilot (PCP) metrics for hardware sensors&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Linux hardware monitoring sensors.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-lio-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">fdb1f5f018855f5cd81322912c4e7ee8c6047ee46ba1266a396130f29fcc7991</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-lio-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-lio</strong> - Performance Co-Pilot (PCP) metrics for the LIO subsystem&lt;br /&gt;</p>

<p>This package provides a PMDA to gather performance metrics from the kernels&lt;br /&gt;
iSCSI target interface (LIO). The metrics are stored by LIO within the Linux&lt;br /&gt;
kernels configfs filesystem. The PMDA provides per LUN level stats, and a&lt;br /&gt;
summary instance per iSCSI target, which aggregates all LUN metrics within the&lt;br /&gt;
target.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-libvirt-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">e945a34355117f4299ffec18dc2148bd5c2064c68d97f5134f9f2f0067768b9d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-libvirt-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-libvirt</strong> - Performance Co-Pilot (PCP) metrics from virtual machines&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting virtualisation statistics from libvirt about behaviour of guest&lt;br /&gt;
and hypervisor machines.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-infiniband-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">e4c843a25ebc8323f53e3a54f8168d6ebe28e2c713b25d27ad057123fff76a51</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-infiniband-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-infiniband</strong> - Performance Co-Pilot (PCP) metrics for Infiniband HCAs and switches&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting Infiniband statistics.  By default, it monitors the local HCAs&lt;br /&gt;
but can also be configured to monitor remote GUIDs such as IB switches.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-hdb-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b2f4967bbc0c1677945daad4cef1800e441884892e29594dca9a8d504a99c006</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-hdb-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-hdb</strong> - Performance Co-Pilot (PCP) metrics for SAP HANA databases&lt;br /&gt;</p>

<p>This package provides a PMDA to export metric values about a SAP HANA&lt;br /&gt;
database (https://www.sap.com/products/data-cloud/hana.html).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-haproxy-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">91e63e0fbfd4bcb3964c6dec44394b9cb68a131c6d600c727e709230c9210e64</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-haproxy-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-haproxy</strong> - Performance Co-Pilot (PCP) metrics for HAProxy&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting performance metrics from HAProxy over the HAProxy stats socket.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-hacluster-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">0c5e117be11af3b8b9102ce6cf5ae8d961f3499a9318971b9aa77b04207a0da1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-hacluster-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-hacluster</strong> - Performance Co-Pilot (PCP) metrics for High Availability Clusters&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about linux High Availability (HA) Clusters.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-gpsd-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">d7287936f9488d1694a003fae859988cb77204060f0f0f35125acd28328c2918</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-gpsd-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-gpsd</strong> - Performance Co-Pilot (PCP) metrics for a GPS Daemon&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about a GPS Daemon.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-gpfs-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">94276fa9ef80103204590d8235f88bf1f235c613494827a727ba79322c45c322</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-gpfs-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-gpfs</strong> - Performance Co-Pilot (PCP) metrics for GPFS Filesystem&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the GPFS filesystem.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-gluster-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">077859b28cd33c934adf7477bdc6ebc6f37acc12dcafb279893750949e892510</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-gluster-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-gluster</strong> - Performance Co-Pilot (PCP) metrics for the Gluster filesystem&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the gluster filesystem.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-farm-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">97a8f3076425f75d1db13fc06f1650fff4b33c67ae2bd1de69b1840bb8708fb8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-farm-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-farm</strong> - Performance Co-Pilot (PCP) metrics for Seagate FARM Log metrics&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metric Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from Seagate Hard Drive vendor specific Field Accessible&lt;br /&gt;
Reliability Metrics (FARM) Log making use of data from the smartmontools&lt;br /&gt;
package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-elasticsearch-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">ca8b6bb82dbef44ac842986c3bfc36a3266aa7e4e0fc719472d300fe718cdd16</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-elasticsearch-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-elasticsearch</strong> - Performance Co-Pilot (PCP) metrics for Elasticsearch&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Elasticsearch.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-ds389log-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">430347d33f8ce9f9c0e6f2225dc6603d47d06d34a7773d56ff897bfe79f66892</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-ds389log-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-ds389log</strong> - Performance Co-Pilot (PCP) metrics for 389 Directory Server Loggers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from a 389 Directory Server log.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-ds389-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">2d4c2eae4f308985e6c1a2796de2effbc16c4e97ef42ec9235b36d59b6cd5944</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-ds389-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-ds389</strong> - Performance Co-Pilot (PCP) metrics for 389 Directory Servers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about a 389 Directory Server.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-docker-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">743f79190915dfe003c1d025e915503980fa413b45b45464036856344f366d30</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-docker-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-docker</strong> - Performance Co-Pilot (PCP) metrics from the Docker daemon&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics using the Docker daemon REST API.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-dm-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">bd1066c42e9ad23bee6abf9b04e923701c4b70d6dbe88c14d3f0cb37427791f5</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-dm-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-dm</strong> - Performance Co-Pilot (PCP) metrics for the Device Mapper Cache and Thin Client&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Device Mapper Cache and Thin Client.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-denki-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6a26e38e9680595247d9591e3c0b0da4fca4e18b88b4395cbf36c4985cb7faf6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-denki-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-denki</strong> - Performance Co-Pilot (PCP) metrics dealing with electrical power&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics related to the electrical power consumed by and inside&lt;br /&gt;
the system.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-dbping-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6626eb7ec75b270d090c328ad07913571c807852776bc450c73df5f795cc3b7d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-dbping-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-dbping</strong> - Performance Co-Pilot (PCP) metrics for Database response times and Availablility&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Database response times and Availablility.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-cisco-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">7fc534a5bd45b76ce4a35ce19c2fe7b4e7830e4bbb43a04b208efb7ab24a38f3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-cisco-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-cisco</strong> - Performance Co-Pilot (PCP) metrics for Cisco routers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about Cisco routers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-cifs-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">ca9449c794a679d3f378aafc559a69a120cf9ce43d247a69789f45ae6600f34c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-cifs-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-cifs</strong> - Performance Co-Pilot (PCP) metrics for the CIFS protocol&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Common Internet Filesytem.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bpftrace-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">500dedd8a8dd1d5e362600f57eeac800ce0acce1fb71bd9b6371e24e3240488e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bpftrace-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bpftrace</strong> - Performance Co-Pilot (PCP) metrics from bpftrace scripts&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting performance metrics from bpftrace scripts.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bpf-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">77ff51fb83d98d39a71aa509237f596f672a1869693a983f8c76a8d7325d6ad6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bpf-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bpf</strong> - Performance Co-Pilot (PCP) metrics from eBPF ELF modules&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting performance metrics from eBPF ELF modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bonding-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b9553102664e44e2eb4b707c96942f1d81b77a0eccab739ce142391e80c6bb89</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bonding-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bonding</strong> - Performance Co-Pilot (PCP) metrics for Bonded network interfaces&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about bonded network interfaces.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bind2-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b64a819cf50d9f759352f8902f8f0d54962f44b4cf20fb24db4f5d2ae7b8146e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bind2-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bind2</strong> - Performance Co-Pilot (PCP) metrics for BIND servers&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics from BIND (Berkeley Internet Name Domain).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bcc-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6cd8a19cca5a0494899d1f37f13b42fb06270f1fa789134227ed23cfc12bb6e7</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bcc-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bcc</strong> - Performance Co-Pilot (PCP) metrics from eBPF/BCC modules&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting performance metrics from eBPF/BCC Python modules.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-bash-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">ea291f17ba2e195d4ed878fbb7a8c8db2102e3fed59218f62899eb195a0447c3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-bash-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-bash</strong> - Performance Co-Pilot (PCP) metrics for the Bash shell&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Bash shell.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-apache-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">059cc0ba96f20b9a7df620d8242e408edaa135becb3f1306690e806267b5ca83</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-apache-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-apache</strong> - Performance Co-Pilot (PCP) metrics for the Apache webserver&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the Apache webserver.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-amdgpu-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b5ecc71979068e76286f29b8294454b3de33db6fbfc2117cc94a32c71dda9f4c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-amdgpu-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-amdgpu</strong> - Performance Co-Pilot (PCP) metrics from AMD GPU devices&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
extracting performance metrics from AMDGPU devices.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-pmda-activemq-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">aeb7174968dbdc98d2bccf322886e3fffb3dfa5e495a7bf89e0d88ee7a854aff</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-pmda-activemq-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-pmda-activemq</strong> - Performance Co-Pilot (PCP) metrics for ActiveMQ&lt;br /&gt;</p>

<p>This package contains the PCP Performance Metrics Domain Agent (PMDA) for&lt;br /&gt;
collecting metrics about the ActiveMQ message broker.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-libs-devel-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">22d22b677cc35aeec4188349d26bdce2ea0024f4e87bad946d9a0814d0bc9ee3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-libs-devel-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-libs-devel</strong> - Performance Co-Pilot (PCP) development headers&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) headers for development.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-libs-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">63c804fcb21eb6311e7eebec3dd0f8c430ae25e3bab970871bc5c23097e79ccb</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-libs-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-libs</strong> - Performance Co-Pilot run-time libraries&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) run-time libraries</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-sar2pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">620de9293749abfaddfdda4a0ff75b15e416d146fe63062246ea76a3cb40787e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-sar2pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-sar2pcp</strong> - Performance Co-Pilot tools for importing sar data into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing sar data&lt;br /&gt;
into standard PCP archive logs for replay with any PCP monitoring tool.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-pmseries-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">273ea1ac83bce76b30b3ee938e495663a06d666d897d123df8fd4c7d48097a6d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-pmseries-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-pmseries</strong> - Performance Co-Pilot tools importing PCP archives for pmseries queries&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) tools for importing PCP archives into Valkey&lt;br /&gt;
or Redis for fast, scalable time series access via pmseries(1) queries.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-mrtg2pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">5a2e50ccf4c8ccf2000b5a9ff0243b9709319b5ed77628fe3b6c45ef142fd1de</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-mrtg2pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-mrtg2pcp</strong> - Performance Co-Pilot tools for importing MTRG data into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing MTRG data&lt;br /&gt;
into standard PCP archive logs for replay with any PCP monitoring tool.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-iostat2pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">7a67a1494225979c0d82367cbab025c9b2e6075130f1700e03c9d4d6cb24a8bc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-iostat2pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-iostat2pcp</strong> - Performance Co-Pilot tools for importing iostat data into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing iostat data&lt;br /&gt;
into standard PCP archive logs for replay with any PCP monitoring tool.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-ganglia2pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">b62617d148ac36390dd68cd5e9638be34d391fc6057044fb445a9319e59ad745</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-ganglia2pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-ganglia2pcp</strong> - Performance Co-Pilot tools for importing ganglia data into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing ganglia data&lt;br /&gt;
into standard PCP archive logs for replay with any PCP monitoring tool.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-collectl2pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">500c29c31bee5192a3a1641ab64f3e2f2eea9f2a4f09c70985724be73b2b8cce</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-collectl2pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-collectl2pcp</strong> - Performance Co-Pilot tools for importing collectl log files into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing collectl data&lt;br /&gt;
into standard PCP archive logs for replay with any PCP monitoring tool.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-import-benchmarks-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">0f54a12baf2807f396712c86f0dbe3d272e26cdd049efdfbccd2d29805875a8f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-import-benchmarks-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-import-benchmarks</strong> - Performance Co-Pilot tools importing benchmark results into PCP archive logs&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for importing JSON benchmark&lt;br /&gt;
results files into PCP archives for replay with PCP analysis tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-gui-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">f710dcd6667542bcccd73bcef15c1c66a0ab1b232752894f7b122ab68f8db406</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-gui-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-gui</strong> - Visualization tools for the Performance Co-Pilot toolkit&lt;br /&gt;</p>

<p>Visualization tools for the Performance Co-Pilot toolkit.&lt;br /&gt;
The pcp-gui package primarily includes visualization tools for&lt;br /&gt;
monitoring systems using live and archived Performance Co-Pilot&lt;br /&gt;
(PCP) sources.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-geolocate-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">600f0aa297b3962cc11468fcae099bfc533d23c22f003b91c353887f7011909e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-geolocate-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-geolocate</strong> - Performance Co-Pilot geographical location metric labels&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) tools that automatically apply metric labels&lt;br /&gt;
containing latitude and longitude, based on IP-address-based lookups.&lt;br /&gt;
Used with live maps to show metric values from different locations.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-zabbix-agent-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">e5b5cee4c4fb722b2b52ef73929303b73861b872384358f7900ed5ebb29fd7e9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-zabbix-agent-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-zabbix-agent</strong> - Module for exporting PCP metrics to Zabbix agent&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) module for exporting metrics from PCP to&lt;br /&gt;
Zabbix via the Zabbix agent - see zbxpcp(3) for further details.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2zabbix-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">9431bf64afed14b1b908ac5195570f7ebcee73a8ab0adc98311b433357b8ab98</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2zabbix-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2zabbix</strong> - Performance Co-Pilot tools for exporting PCP metrics to Zabbix&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
to the Zabbix (https://www.zabbix.org/) monitoring software.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2xml-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">d5a1e1036bd7c21522f2fc854136b792fda1248b4ad11b47261ca49d8577f4f9</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2xml-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2xml</strong> - Performance Co-Pilot tools for exporting PCP metrics in XML format&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
in XML format.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2spark-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">1921718786a6280d168fbb29762d78a72c979b768c53f35b8ba2a377d999faa6</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2spark-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2spark</strong> - Performance Co-Pilot tools for exporting PCP metrics to Apache Spark&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
in JSON format to Apache Spark. See https://spark.apache.org/ for&lt;br /&gt;
further details on Apache Spark.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2opentelemetry-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">2e44f49f97fba38b4e2cfbba4f5b50f0c2b8b5026d28af985f600d6a1e0ec549</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2opentelemetry-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2opentelemetry</strong> - Performance Co-Pilot tools for exporting PCP metrics in OpenTelemetry format&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
in OpenTelemetry (https://opentelemetry.io/) format.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2openmetrics-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">fd984c1c9bf587ba8c421d8864d15202c1a8e596d230b9bb864adc12347b4e13</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2openmetrics-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2openmetrics</strong> - Performance Co-Pilot tools for exporting PCP metrics in OpenMetrics format&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
in OpenMetrics (https://openmetrics.io/) format.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2json-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">032fc9cc4674109f0b1a953a822ab86a1aae27b0a5594df135dfc5df88a264bf</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2json-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2json</strong> - Performance Co-Pilot tools for exporting PCP metrics in JSON format&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
in JSON format.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2influxdb-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">df13083be1e4ca106e525229b7c320b09821c809ed50bedf59c1b6527cb9b0c1</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2influxdb-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2influxdb</strong> - Performance Co-Pilot tools for exporting PCP metrics to InfluxDB&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
to InfluxDB (https://influxdata.com/time-series-platform/influxdb).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2graphite-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">24fd7fe1a1758b15f8545bf45cbf24f94a253d1e2a54f6fc412708d99b067474</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2graphite-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2graphite</strong> - Performance Co-Pilot tools for exporting PCP metrics to Graphite&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
to graphite (http://graphite.readthedocs.org).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-export-pcp2elasticsearch-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">79ee44604733de9e8b51650a1bf2c6a2ca52470bc87aa5ce123a21331667ce9d</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-export-pcp2elasticsearch-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-export-pcp2elasticsearch</strong> - Performance Co-Pilot tools for exporting PCP metrics to ElasticSearch&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) front-end tools for exporting metric values&lt;br /&gt;
to Elasticsearch - a distributed, RESTful search and analytics engine.&lt;br /&gt;
See https://www.elastic.co/community for further details.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-devel-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">48390b290fcf7e269c8d6cdf4c266a1b3875812aed6d18ae6ef4b111af381cbd</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-devel-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-devel</strong> - Performance Co-Pilot (PCP) development tools and documentation&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) documentation and tools for development.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-conf-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">6d2651e7b64eadff4dfdf06d34a55bea6aea34e61c5584e85c9f5323b7c4a12b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-conf-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp-conf</strong> - Performance Co-Pilot run-time configuration&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) run-time configuration</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-7.0.3-5.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:39 PM GMT</pubDate>
      <guid isPermaLink="false">7c0aabc6febcabec0ea88d80d9dbbde5807efcc3d5cea0e7370d9f2f431a5bc8</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-7.0.3-5.el10_2.aarch64.rpm</link>
      <description><p><strong>pcp</strong> - System-level performance monitoring and performance management&lt;br /&gt;</p>

<p>Performance Co-Pilot (PCP) provides a framework and services to support&lt;br /&gt;
system-level performance monitoring and performance management.&lt;br /&gt;
&lt;br /&gt;
The PCP open source release provides a unifying abstraction for all of&lt;br /&gt;
the interesting performance data in a system, and allows client&lt;br /&gt;
applications to easily retrieve and process any subset of that data.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>pcp-doc-7.0.3-5.el10_2.noarch</title>
      <pubDate>Mon, 17 Aug 2026 09:03:35 PM GMT</pubDate>
      <guid isPermaLink="false">757a4161491cf30a033460691485424abf99b5d10f1ea4bf3cd53c6c8b154c70</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/pcp-doc-7.0.3-5.el10_2.noarch.rpm</link>
      <description><p><strong>pcp-doc</strong> - Documentation and tutorial for the Performance Co-Pilot&lt;br /&gt;</p>

<p>Documentation and tutorial for the Performance Co-Pilot&lt;br /&gt;
Performance Co-Pilot (PCP) provides a framework and services to support&lt;br /&gt;
system-level performance monitoring and performance management.&lt;br /&gt;
&lt;br /&gt;
The pcp-doc package provides useful information on using and&lt;br /&gt;
configuring the Performance Co-Pilot (PCP) toolkit for system&lt;br /&gt;
level performance management.  It includes tutorials, HOWTOs,&lt;br /&gt;
and other detailed documentation about the internals of core&lt;br /&gt;
PCP utilities and daemons, and the PCP graphical tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-5
- Fix CVE-2026-16530: __pmLogLoadInDom OOB pointer dereference (RHEL-213746)
- Fix CVE-2026-16531: pmproxy logger servlet path traversal (RHEL-213756)
- Backport remaining PCP security hardening fixes from private-pcp
- pmieconf and pmlogmv command injection hardening (CWE-78)
- libpcp PDU decode OOB read and overflow guards (CWE-125/190/195)
- timezone and zoneinfo string validation
- pmdaroot peer credential verification (CWE-403)
- pmproxy REST CERT_REQD enforcement and logger servlet authentication

Fri, 14 Aug 2026 GMT - Jan Kuřík &amp;lt;jkurik@redhat.com&amp;gt; - 7.0.3-4
- Fix CVE-2026-16524: linux_sockets PMDA command injection (RHEL-213659)
- Fix CVE-2026-16526: FD_CLOEXEC privilege escalation via pmdaroot (RHEL-213695)
- Fix CVE-2026-16527: pmproxy unauthenticated /store access (RHEL-213721)
- Fix CVE-2026-16529: __pmGetPDU signed integer overflow DoS (RHEL-213732)

Thu, 19 Feb 2026 GMT - William Cohen &amp;lt;wcohen@redhat.com&amp;gt; - 7.0.3-3
- Update selinux polices for rocestat and nvidia pmdas (RHEL-132402, RHEL-134388, RHEL-133519)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-inspect-icons-1:1.58.1-9.el10_2.noarch</title>
      <pubDate>Mon, 17 Aug 2026 09:03:22 PM GMT</pubDate>
      <guid isPermaLink="false">d5f97c12ae413ac6b1767c50132182c0ae26463359f6a651d3918db25713334a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-inspect-icons-1.58.1-9.el10_2.noarch.rpm</link>
      <description><p><strong>libguestfs-inspect-icons</strong> - Additional dependencies for inspecting guest icons&lt;br /&gt;</p>

<p>libguestfs-inspect-icons is a metapackage that pulls in additional&lt;br /&gt;
dependencies required by libguestfs to pull icons out of non-Linux&lt;br /&gt;
guests.  Install this package if you want libguestfs to be able to&lt;br /&gt;
inspect non-Linux guests and display icons from them.&lt;br /&gt;
&lt;br /&gt;
The only reason this is a separate package is to avoid core libguestfs&lt;br /&gt;
having to depend on Perl.  See https://bugzilla.redhat.com/1194158</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-bash-completion-1:1.58.1-9.el10_2.noarch</title>
      <pubDate>Mon, 17 Aug 2026 09:03:22 PM GMT</pubDate>
      <guid isPermaLink="false">4a4b636cc0699cae97dbe90b5ad8ebdefb949ba69e4e5a68a04ecf5687e88288</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-bash-completion-1.58.1-9.el10_2.noarch.rpm</link>
      <description><p><strong>libguestfs-bash-completion</strong> - Bash tab-completion scripts for libguestfs tools&lt;br /&gt;</p>

<p>Install this package if you want intelligent bash tab-completion&lt;br /&gt;
for guestfish, guestmount and various virt-* tools.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-xfs-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">c46fa1b3b59298cae10305457b66b1d61267d6091ea822a8c63956b877ac766b</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-xfs-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>libguestfs-xfs</strong> - XFS support for libguestfs&lt;br /&gt;</p>

<p>This adds XFS support to libguestfs.  Install it if you want to process&lt;br /&gt;
disk images containing XFS.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-rsync-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">5eb8953a6af63f230543fb2493368db94a73046b6d07d164f712c8b364597012</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-rsync-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>libguestfs-rsync</strong> - rsync support for libguestfs&lt;br /&gt;</p>

<p>This adds rsync support to libguestfs.  Install it if you want to use&lt;br /&gt;
rsync to upload or download files into disk images.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-rescue-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">1cd5abb2fc33a035fd7449dc5f8adc70dbbee1a7988501e741c39740a3b9ba25</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-rescue-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>libguestfs-rescue</strong> - virt-rescue shell&lt;br /&gt;</p>

<p>This adds the virt-rescue shell which is a "rescue disk" for virtual&lt;br /&gt;
machines, and additional tools to use inside the shell such as ssh,&lt;br /&gt;
network utilities, editors and debugging utilities.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-appliance-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">f8fe98c84f6cedfea053d09271e7c7a2c5cb3475b98121fedcf8c4762eb0dedc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-appliance-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>libguestfs-appliance</strong> - Appliance for libguestfs&lt;br /&gt;</p>

<p>libguestfs-appliance provides the appliance used by libguestfs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libguestfs-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">0c69bbf8356b05f3d5356ac9a23f93cf314ca11d3df942d4feed10ebeb68ce82</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libguestfs-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>libguestfs</strong> - Access and modify virtual machine disk images&lt;br /&gt;</p>

<p>Libguestfs is a library for accessing and modifying virtual machine&lt;br /&gt;
disk images.  http://libguestfs.org&lt;br /&gt;
&lt;br /&gt;
Libguestfs uses Linux kernel and qemu code, and can access any type of&lt;br /&gt;
guest filesystem that Linux and qemu can, including but not limited&lt;br /&gt;
to: ext2/3/4, btrfs, FAT and NTFS, LVM, many different disk partition&lt;br /&gt;
schemes, qcow, qcow2, vmdk.&lt;br /&gt;
&lt;br /&gt;
For enhanced features, install:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 libguestfs-inspect-icons  adds support for inspecting guest icons&lt;br /&gt;
        libguestfs-rescue  enhances virt-rescue shell with more tools&lt;br /&gt;
         libguestfs-rsync  rsync to/from guest filesystems&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
           libguestfs-xfs  adds XFS support&lt;br /&gt;
&lt;br /&gt;
For developers:&lt;br /&gt;
&lt;br /&gt;
         libguestfs-devel  C/C++ header files and library&lt;br /&gt;
&lt;br /&gt;
Language bindings:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   ocaml-libguestfs-devel  OCaml bindings&lt;br /&gt;
         perl-Sys-Guestfs  Perl bindings&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
       python3-libguestfs  Python 3 bindings</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>python3-libguestfs-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">a66054d7c1fdbaa1a47f4f327a4e6067ab2c30f08db7967a738c9c3be8d24d5a</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/python3-libguestfs-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>python3-libguestfs</strong> - Python 3 bindings for libguestfs&lt;br /&gt;</p>

<p>python3-libguestfs contains Python 3 bindings for libguestfs.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>perl-Sys-Guestfs-1:1.58.1-9.el10_2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:03:08 PM GMT</pubDate>
      <guid isPermaLink="false">2c8ba36c4d27efce92a6f28abacad17605e423b1df6bb930e51903e0a656d601</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/p/perl-Sys-Guestfs-1.58.1-9.el10_2.aarch64.rpm</link>
      <description><p><strong>perl-Sys-Guestfs</strong> - Perl bindings for libguestfs (Sys::Guestfs)&lt;br /&gt;</p>

<p>perl-Sys-Guestfs contains Perl bindings for libguestfs (Sys::Guestfs).</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 13 Aug 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-9
- Add setfiles optional excludes parameter to libguestfs
  resolves: RHEL-239808

Fri, 10 Jul 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-8
- Ignore RHEL 7 AGFL inconsistency in xfs_repair
  resolves: RHEL-192920
- Use bind mount to overwrite /etc/resolv.conf
  resolves: RHEL-192946

Mon, 11 May 2026 GMT - Richard W.M. Jones &amp;lt;rjones@redhat.com&amp;gt; - 1:1.58.1-6
- Fix binary LUKS keys
  resolves: RHEL-174519
- Use git to apply patches, since there is an unsupported binary patch

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>haproxy-3.0.5-6.el10_2.2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:02:23 PM GMT</pubDate>
      <guid isPermaLink="false">cd576d4eb6fcc4c35f2da916782e5f77be8d170a772195a770c78c76cd50dd05</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/h/haproxy-3.0.5-6.el10_2.2.aarch64.rpm</link>
      <description><p><strong>haproxy</strong> - HAProxy reverse proxy for high availability environments&lt;br /&gt;</p>

<p>HAProxy is a TCP/HTTP reverse proxy which is particularly suited for high&lt;br /&gt;
availability environments. Indeed, it can:&lt;br /&gt;
 - route HTTP requests depending on statically assigned cookies&lt;br /&gt;
 - spread load among several servers while assuring server persistence&lt;br /&gt;
   through the use of HTTP cookies&lt;br /&gt;
 - switch to backup servers in the event a main one fails&lt;br /&gt;
 - accept connections to special ports dedicated to service monitoring&lt;br /&gt;
 - stop accepting connections without breaking existing ones&lt;br /&gt;
 - add, modify, and delete HTTP headers in both directions&lt;br /&gt;
 - block requests matching particular patterns&lt;br /&gt;
 - report detailed status to authenticated users from a URI&lt;br /&gt;
   intercepted from the application</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - Oyvind Albrigtsen &amp;lt;oalbrigt@redhat.com&amp;gt; - 3.0.5-6.2
- Fix uint16_t overflow in FCGI demux record length (CVE-2026-55203)
  Resolves: RHEL-211068
- Fix NULL pointer dereference in hpack_dht_insert() (CVE-2026-55204)
  Resolves: RHEL-211081

Wed, 06 May 2026 GMT - Oyvind Albrigtsen &amp;lt;oalbrigt@redhat.com&amp;gt; - 3.0.5-6.1
- peers: fix OOB heap write in dictionary cache update
  Resolves: RHEL-173335

Thu, 06 Nov 2025 GMT - Oyvind Albrigtsen &amp;lt;oalbrigt@redhat.com&amp;gt; - 3.0.5-6
- Fix denial of service vulnerability in mjson library (CVE-2025-11230)
  Resolves: RHEL-126653

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libcurl-devel-8.12.1-4.el10_2.4.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:28:51 AM GMT</pubDate>
      <guid isPermaLink="false">93d9429544588804435f550b4f48c3f16c84617b30c602731835fe11bc3fa3c3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libcurl-devel-8.12.1-4.el10_2.4.aarch64.rpm</link>
      <description><p><strong>libcurl-devel</strong> - Files needed for building applications with libcurl&lt;br /&gt;</p>

<p>The libcurl-devel package includes header files and libraries necessary for&lt;br /&gt;
developing programs which use the libcurl library. It contains the API&lt;br /&gt;
documentation of the library, too.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Wed, 29 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 8.12.1-4.4
- fix proxy environment variable change detection (CVE-2026-8927)

Wed, 22 Jul 2026 GMT - Jacek Migacz &amp;lt;jmigacz@redhat.com&amp;gt; - 8.12.1-4.el10_2.3
- fix HTTP Negotiate connection reuse auth bypass (CVE-2026-1965)
- fix OAuth2 bearer token leak via redirect and netrc (CVE-2026-3783)
- fix proxy connection reuse with wrong credentials (CVE-2026-3784)

Mon, 13 Jul 2026 GMT - Jacek Migacz &amp;lt;jmigacz@redhat.com&amp;gt; - 8.12.1-4.2
- fix SSH host key mismatch on type difference (CVE-2026-9547)
- fix schemeless URL handling with --proto-default (CVE-2026-12064)
- fix TLS/STARTTLS connection reuse vulnerability (CVE-2026-8286)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-utils-32:9.18.33-15.el10_2.10.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:05:19 AM GMT</pubDate>
      <guid isPermaLink="false">a1436767db20ae707157579aa30b3c4a33181c814be5973bf0c70afd7b6188a2</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-utils-9.18.33-15.el10_2.10.aarch64.rpm</link>
      <description><p><strong>bind-utils</strong> - Utilities for querying DNS name servers&lt;br /&gt;</p>

<p>Bind-utils contains a collection of utilities for querying DNS (Domain&lt;br /&gt;
Name System) name servers to find out information about Internet&lt;br /&gt;
hosts. These tools will provide you with the IP addresses for given&lt;br /&gt;
host names, as well as other information about registered domains and&lt;br /&gt;
network addresses.&lt;br /&gt;
&lt;br /&gt;
You should install bind-utils if you need to get information from DNS name&lt;br /&gt;
servers.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-libs-32:9.18.33-15.el10_2.10.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:05:19 AM GMT</pubDate>
      <guid isPermaLink="false">d2cc967e0a23305052c5fa5281ac6adbb464c8cdccf9a171c6c68012661eee94</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-libs-9.18.33-15.el10_2.10.aarch64.rpm</link>
      <description><p><strong>bind-libs</strong> - Libraries used by the BIND DNS packages&lt;br /&gt;</p>

<p>Contains heavyweight version of BIND suite libraries used by both named DNS&lt;br /&gt;
server and utilities in bind-utils package.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-dnssec-utils-32:9.18.33-15.el10_2.10.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:05:19 AM GMT</pubDate>
      <guid isPermaLink="false">dedcddfb83d40c31aa0605924fa5e73fe5df86652ad03400b831dcafbdca520f</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-dnssec-utils-9.18.33-15.el10_2.10.aarch64.rpm</link>
      <description><p><strong>bind-dnssec-utils</strong> - DNSSEC keys and zones management utilities&lt;br /&gt;</p>

<p>bind-dnssec-utils contains a collection of utilities for editing&lt;br /&gt;
DNSSEC keys and BIND zone files. These tools provide generation,&lt;br /&gt;
revocation and verification of keys and DNSSEC signatures in zone files.&lt;br /&gt;
&lt;br /&gt;
You should install bind-dnssec-utils if you need to sign a DNS zone&lt;br /&gt;
or maintain keys for it.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-chroot-32:9.18.33-15.el10_2.10.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:05:19 AM GMT</pubDate>
      <guid isPermaLink="false">4ba64d0f0dc7318eac76a06f8f8571d54d752d62c7ded91794bccce19a6041ec</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-chroot-9.18.33-15.el10_2.10.aarch64.rpm</link>
      <description><p><strong>bind-chroot</strong> - A chroot runtime environment for the ISC BIND DNS server, named(8)&lt;br /&gt;</p>

<p>This package contains a tree of files which can be used as a&lt;br /&gt;
chroot(2) jail for the named(8) program from the BIND package.&lt;br /&gt;
Based on the code from Jan "Yenya" Kasprzak &lt;kas@fi.muni.cz&gt;</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-32:9.18.33-15.el10_2.10.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 10:05:19 AM GMT</pubDate>
      <guid isPermaLink="false">3a31b300f2d5039910665e7d17492f41ec21334d3baf296a4acba67c16a814ae</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-9.18.33-15.el10_2.10.aarch64.rpm</link>
      <description><p><strong>bind</strong> - The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server&lt;br /&gt;</p>

<p>BIND (Berkeley Internet Name Domain) is an implementation of the DNS&lt;br /&gt;
(Domain Name System) protocols. BIND includes a DNS server (named),&lt;br /&gt;
which resolves host names to IP addresses; a resolver library&lt;br /&gt;
(routines for applications to use when interfacing with DNS); and&lt;br /&gt;
tools for verifying that the DNS server is operating properly.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>bind-license-32:9.18.33-15.el10_2.10.noarch</title>
      <pubDate>Mon, 17 Aug 2026 10:05:08 AM GMT</pubDate>
      <guid isPermaLink="false">470321a2c37f6c39ee7f0684c36c00a139e950ddb2714a6ac3c706283b610ca3</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/b/bind-license-9.18.33-15.el10_2.10.noarch.rpm</link>
      <description><p><strong>bind-license</strong> - License of the BIND DNS suite&lt;br /&gt;</p>

<p>Contains license of the BIND DNS suite.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 27 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.10
- Validate NSEC3 signer matches owning zone (CVE-2026-10723)

Fri, 24 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.9
- Reject out-of-zone NSEC next owner names (CVE-2026-13321)

Thu, 23 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 32:9.18.33-15.7
- Fix reference-counted dns_slabheaders in cache (CVE-2026-11622)

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>libXfont2-2.0.6-5.el10_2.3.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:56:32 AM GMT</pubDate>
      <guid isPermaLink="false">767d0263c8969e599fd46d15d4749f5e874009896b0a9c7968b5a143b17d5fda</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/l/libXfont2-2.0.6-5.el10_2.3.aarch64.rpm</link>
      <description><p><strong>libXfont2</strong> - X.Org X11 libXfont2 runtime library&lt;br /&gt;</p>

<p>X.Org X11 libXfont2 runtime library</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Thu, 06 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.0.6-5.3
- CVE fix for: CVE-2026-59679
  Resolves: https://redhat.atlassian.net/browse/RHEL-221949

Thu, 06 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 2.0.6-5.2
- CVE fix for: CVE-2026-44950
  Resolves: https://redhat.atlassian.net/browse/RHEL-222024

Wed, 08 Jul 2026 GMT - Olivier Fourdan &amp;lt;ofourdan@redhat.com&amp;gt; - 2.0.6-5.1
- CVE fix for: CVE-2026-56001, CVE-2026-56002, CVE-2026-56003
  Resolves: https://redhat.atlassian.net/browse/RHEL-191882
  Resolves: https://redhat.atlassian.net/browse/RHEL-191930
  Resolves: https://redhat.atlassian.net/browse/RHEL-191949

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.7.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:53:06 AM GMT</pubDate>
      <guid isPermaLink="false">3f51f2095e19fd6eb82c8e50831c87928ee4614aac46019d86c75836e002812c</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-bad-free-libs-1.26.7-2.el10_2.7.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-bad-free-libs</strong> - Runtime libraries for the GStreamer media framework "bad" plug-ins&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of elements which&lt;br /&gt;
operate on media data.&lt;br /&gt;
&lt;br /&gt;
This package contains the runtime libraries for plugins that&lt;br /&gt;
aren't tested well enough, or the code is not of good enough quality.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.7
- Fix ADPCM decoder input validation (CVE-2026-19387)
  Resolves: RHEL-235500

Sat, 11 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.5
- Fix rfbsrc hextile and color read handling for non-32bpp
  pixel formats (CVE-2026-59691)
  Resolves: RHEL-193550

Tue, 23 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.4
- Fix bytes/bits confusion in AV1 tile data size parsing (CVE-2026-52718)
  Resolves: RHEL-184391

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-bad-free-1.26.7-2.el10_2.7.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:53:06 AM GMT</pubDate>
      <guid isPermaLink="false">ed264687c1487a841f42ad0a5695c928a45b360ff46e1460d4cc707938cb86dc</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-bad-free-1.26.7-2.el10_2.7.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-bad-free</strong> - GStreamer streaming media framework "bad" plugins&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of elements which&lt;br /&gt;
operate on media data.&lt;br /&gt;
&lt;br /&gt;
This package contains plug-ins that aren't tested well enough, or the code&lt;br /&gt;
is not of good enough quality.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.7
- Fix ADPCM decoder input validation (CVE-2026-19387)
  Resolves: RHEL-235500

Sat, 11 Jul 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.5
- Fix rfbsrc hextile and color read handling for non-32bpp
  pixel formats (CVE-2026-59691)
  Resolves: RHEL-193550

Tue, 23 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.4
- Fix bytes/bits confusion in AV1 tile data size parsing (CVE-2026-52718)
  Resolves: RHEL-184391

...&lt;/pre&gt;</description>
    </item>
    <item>
      <title>gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.aarch64</title>
      <pubDate>Mon, 17 Aug 2026 09:51:50 AM GMT</pubDate>
      <guid isPermaLink="false">5a252c96f4cc7a4bf0b9cc62ee92441c25e7670a56f9369ceea06ddb5b3a307e</guid>
      <link>https://dl.rockylinux.org/pub/rocky/10/AppStream/aarch64/os/Packages/g/gstreamer1-plugins-ugly-free-1.26.7-2.el10_2.2.aarch64.rpm</link>
      <description><p><strong>gstreamer1-plugins-ugly-free</strong> - GStreamer streaming media framework "ugly" plugins&lt;br /&gt;</p>

<p>GStreamer is a streaming media framework, based on graphs of elements which&lt;br /&gt;
operate on media data.&lt;br /&gt;
&lt;br /&gt;
This package contains plug-ins whose license is not fully compatible with LGPL.</p>

<p><strong>Change Log:</strong></p>

&lt;pre&gt;Mon, 10 Aug 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.2
- Fix CVE-2026-19389: integer overflow vulnerabilities in asfdemux
  Resolves: RHEL-235515

Tue, 23 Jun 2026 GMT - RHEL Packaging Agent &amp;lt;redhat-ymir-agent@redhat.com&amp;gt; - 1.26.7-2.1
- Fix CVE-2026-53703: multiple security issues in rmdemux
  Resolves: RHEL-184439

Tue, 31 Mar 2026 GMT - Wim Taymans &amp;lt;wtaymans@redhat.com&amp;gt; - 1.26.7-2
- Add patches for CVE-2026-2920 and CVE-2026-2922
  Resolves: RHEL-156044, RHEL-156165

...&lt;/pre&gt;</description>
    </item>
  </channel>
</rss>
