Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

An update that fixes one vulnerability is now available.

This is a security and bug fix release.

Security fix for CVE-2024-3727 Automatic update for buildah-1.35.4-1.fc39. Changelog for buildah * Fri May 10 2024 Packit – 1.35.4-1 – Update to 1.35.4 upstream release

This is a security and bug fix release.

Backport fix for CVE-2024-34069.

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

new upstream update (126.0)

* bsc#1216644 * bsc#1218259 * bsc#1220211 * bsc#1220832 * bsc#1221302

* bsc#1220211 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1222882

Two vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. CVE-2023-50387

Automating fapolicyd with RHEL system roles

* bsc#1180833 * bsc#1183101 * bsc#1183102 * bsc#1183103 * bsc#1183105

* bsc#1222992 * bsc#1223423 * bsc#1223424 * bsc#1223425

new upstream update (126.0)

update to 125.0.6422.60 * High CVE-2024-4947: Type Confusion in V8 * High CVE-2024-4948: Use after free in Dawn * Medium CVE-2024-4949: Use after free in V8 * Low CVE-2024-4950: Inappropriate implementation in Downloads

Security fix for CVE-2024-3727

https://security-tracker.debian.org/tracker/DSA-5693-1

https://security-tracker.debian.org/tracker/DSA-5694-1

https://security-tracker.debian.org/tracker/DSA-5692-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in .NET.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1224038 * bsc#1224051 Cross-References: * CVE-2024-4317

* bsc#1219559 Cross-References: * CVE-2023-52425

* bsc#1190576 * bsc#1192145 * bsc#1204614 * bsc#1211592 * bsc#1218562

https://security-tracker.debian.org/tracker/DSA-5689-1

https://security-tracker.debian.org/tracker/DSA-5690-1

https://security-tracker.debian.org/tracker/DSA-5691-1

New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1222548 Cross-References: * CVE-2024-2511

* bsc#1223690 Cross-References: * CVE-2024-29040

* bsc#1223687 * bsc#1223689 Cross-References: * CVE-2024-29038

Fraudulent security certificates could allow access controls to be bypassed.

Getting started with Red Hat Insights and FedRAMP

This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.

* bsc#1094832 * bsc#1200551 Cross-References: * CVE-2018-11490

* bsc#1218862 * bsc#1218865 Cross-References: * CVE-2024-0553

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

An update that fixes four vulnerabilities is now available.

An update that fixes 35 vulnerabilities is now available.

It was discovered that missing input sanitising in the Atril document viewer could result in writing arbitrary files in the users home directory if a malformed epub document is opened.

Multiple vulnerabilities have been discovered in PoDoFo, the worst of which could lead to code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Kubelet, which can lead to privilege escalation.

A vulnerability has been discovered in Rebar3, which can lead to command injection.

update to 124.0.6367.201 * High CVE-2024-4671: Use after free in Visuals

https://security-tracker.debian.org/tracker/DSA-5688-1

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

Security fix for CVE-2023-45681 / CVE-2023-47212

Security fix for CVE-2023-45681 / CVE-2023-47212

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

Fix for CVE-2024-2397

https://www.mediawiki.org/wiki/Release_notes/1.41

* bsc#1222849 Cross-References: * CVE-2024-32487

* bsc#1216644 * bsc#1219079 * bsc#1219435 * bsc#1220828

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

* bsc#1212475 * bsc#1224017 Cross-References: * CVE-2024-24787

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1223979 Cross-References: * CVE-2024-34069

https://security-tracker.debian.org/tracker/DSA-5687-1

RHEL 9.4 Unveiled: Elevating Enterprise Security with Cutting-Edge Features

https://security-tracker.debian.org/tracker/DSA-5685-1

* bsc#1223100 Cross-References: * CVE-2023-3758

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1216853 Cross-References: * CVE-2023-38472

* bsc#1222492 Cross-References: * CVE-2024-21506

* bsc#1223979 Cross-References: * CVE-2024-34069

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

Unleashing the potential of IntelĀ® IPU with Red Hat OpenShift

https://security-tracker.debian.org/tracker/DSA-5682-2

https://security-tracker.debian.org/tracker/DSA-5686-1

https://security-tracker.debian.org/tracker/DSA-5684-1

https://security-tracker.debian.org/tracker/DSA-5682-1

* bsc#1189495 * bsc#1211301 * bsc#1219559 * bsc#1219666 * bsc#1221260

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in root privilege escalation.

A vulnerability has been discovered in Epiphany, which can lead to a buffer overflow.

Multiple vulnerabilities have been discovered in qtsvg, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in MariaDB, the worst fo which can lead to arbitrary execution of code.

https://security-tracker.debian.org/tracker/DSA-5683-1

Fortifying Email Security with Infosec Through the SDLC

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1221984 * bsc#1222302 * bsc#1222453 Cross-References:

* bsc#1027519 * bsc#1221984 * bsc#1222302 * bsc#1222453

* bsc#1216644 * bsc#1219079 * bsc#1219435 Cross-References:

Multiple vulnerabilities have been discovered in libjpeg-turbo, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Xpdf, the worst of which could possibly lead to arbitrary code execution.

* bsc#1215947 * bsc#1216853 Cross-References: * CVE-2023-38470

* bsc#1170848 * bsc#1208572 * bsc#1214340 * bsc#1214387 * bsc#1216085

* bsc#1219912 * bsc#1221465 * bsc#1222155 * jsc#MSQA-760 * jsc#PED-7893

* bsc#1008037 * bsc#1008038 * bsc#1010940 * bsc#1019021 * bsc#1038785

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001