Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Hi Robert, please take a look at it. I do not use epel.
Dear reporter. i do not see any version for epel10 at https://src.fedoraproject.org/rpms/atril What version do you blame?
This issue has been fixed in Atril 1.26.3 (read https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f). Robert can you bump the epel versions? Also the RH CVE (https://access.redhat.com/security/cve/cve-2026-46529) only shows Evince in the component list table.
Yes, I will work on this RHBZ tonight or so.
FEDORA-EPEL-2026-abc540be8b (atril-1.26.4-1.el9) has been submitted as an update to Fedora EPEL 9. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-abc540be8b
FEDORA-EPEL-2026-c0bb6674c7 (atril-1.26.4-1.el8) has been submitted as an update to Fedora EPEL 8. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-c0bb6674c7
FEDORA-EPEL-2026-abc540be8b has been pushed to the Fedora EPEL 9 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-abc540be8b See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-c0bb6674c7 has been pushed to the Fedora EPEL 8 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-c0bb6674c7 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-abc540be8b (atril-1.26.4-1.el9) has been pushed to the Fedora EPEL 9 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-EPEL-2026-c0bb6674c7 (atril-1.26.4-1.el8) has been pushed to the Fedora EPEL 8 stable repository. If problem still persists, please make note of it in this bug report.