Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Update to qt-5.15.12.

Update to qt-5.15.12.

* bsc#1210638 Cross-References: * CVE-2023-27043

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

New upstream release (123.0)

update to 122.0.6261.57 High CVE-2024-1669: Out of bounds memory access in Blink High CVE-2024-1670: Use after free in Mojo Medium CVE-2024-1671: Inappropriate implementation in Site Isolation Medium CVE-2024-1672: Inappropriate implementation in Content Security Policy

Update to latest upstream. Fixes CVE-2023-50387 and CVE-2023-50868

https://security-tracker.debian.org/tracker/DSA-5629-1

https://security-tracker.debian.org/tracker/DSA-5630-1

* bsc#1218564 Cross-References: * CVE-2023-52323

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1219267 * bsc#1219268 * bsc#1219438 Cross-References:

* bsc#1188609 * bsc#1212850 * bsc#1213210 * bsc#1213925 * bsc#1215311

Imagemagick a graphical software suite for displaying, creating and modifying images was vulnerable. CVE-2023-1289

Several security issues were fixed in Firefox.

https://security-tracker.debian.org/tracker/DSA-5628-1

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

Patch for CVE-2024-24258 and CVE-2024-24259

Update to version 1.27.3. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.27.3 This update also addresses CVE-2023-49295 in quic-go: https://github.com/quic- go/quic-go/security/advisories/GHSA-ppxx-5m9h-6vxf

https://security-tracker.debian.org/tracker/DSA-5627-1

New libuv packages are available for Slackware 15.0 and -current to fix a security issue.

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

The updated packages fix security vulnerabilities: RTPS dissector memory leak. (CVE-2023-5371) SSH dissector invalid read of memory blocks. (CVE-2023-6174) NetScreen File Parsing Heap-based Buffer Overflow. (CVE-2023-6175) GVCP dissector crash via packet injection or crafted capture file.

Stack buffer overflow in virtio_net_flush_tx (CVE-2023-6693) (rhbz#2256436)

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

Update the git2 crate to version 0.18.2. Update the libgit2-sys crate to version 0.16.2. Version 0.16.2 of the libgit2-sys crate includes an update of the bundled copy of libgit2 to version 1.7.2 to address CVE-2024-24575 and CVE-2024-24577. Since the libgit2 bindings cause applications that use them to statically link

* bsc#1219059 Cross-References: * CVE-2024-22563

* bsc#1202903 * bsc#1219187 Cross-References: * CVE-2022-2132

* bsc#1158095 * bsc#1168699 * bsc#1174713 * bsc#1189608 * bsc#1211188

* bsc#1219059 Cross-References: * CVE-2024-22563

Multiple vulnerabilities have been discovered in Samba, the worst of which can lead to remote code execution.

A vulnerability has been discovered in Glade which can lead to a denial of service.

Multiple vulnerabilities have been discovered in QtNetwork, the worst of which could lead to execution of arbitrary code.

A vulnerability has been discovered in Thunar which may lead to arbitrary code execution

A vulnerability has been discovered in libcaca which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Exim, the worst of which can lead to remote code execution.

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can

Multiple vulnerabilities have been discovered in CUPS, the worst of which can lead to arbitrary code execution.

https://security-tracker.debian.org/tracker/DSA-5626-1

https://security-tracker.debian.org/tracker/DSA-5625-1

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 2.11.5

Update to 1.6.5 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Update to 1.7.2 Resolves: CVE-2024-24577 Resolves: CVE-2024-24575

Rebase to version 2.6.0

Update to 2.28.7 Release notes: https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.7 Security Advisories: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-

Several security issues were fixed in the Linux kernel.

* bsc#1218429 Cross-References: * CVE-2023-6879

* bsc#1218690 * bsc#1218810 * bsc#1219243 Cross-References:

* bsc#1219113 * bsc#1219604 Cross-References: * CVE-2014-1745

* bsc#1219679 Cross-References: * CVE-2024-0985

https://security-tracker.debian.org/tracker/DSA-5624-1

https://security-tracker.debian.org/tracker/DSA-5623-1

https://security-tracker.debian.org/tracker/DSA-5622-1

The updated packages fix security vulnerabilities: Parsing large DNS messages may cause excessive CPU load. (CVE-2023-4408) Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled. (CVE-2023-5517) Enabling both DNS64 and serve-stale may cause an assertion failure

* bsc#1108281 * bsc#1193285 * bsc#1215275 * bsc#1216702 * bsc#1217987

Manage smartcards with new p11-kit subcommands

Several security issues were fixed in UltraJSON.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in EDK II.

update to 1.26.2

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several vulnerabilities were discovered in BIND, a DNS server implementation, which may result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed

Two vulnerabilities were discovered in unbound, a validating, recursive, caching DNS resolver. Specially crafted DNSSEC answers could lead unbound down a very CPU intensive and time costly DNSSEC (CVE-2023-50387) or NSEC3 hash (CVE-2023-50868) validation path,

UltraJSON could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5620-1

https://security-tracker.debian.org/tracker/DSA-5621-1

Several security issues were fixed in WebKitGTK.

Glance_store could be made to expose sensitive information.

Several security issues were fixed in OpenSSL.

* bsc#1217654 * bsc#1219131 Cross-References: * CVE-2023-50269

Update to 1.0.5

* bsc#1218174 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5

Deploying Red Hat OpenShift Dedicated clusters on Shielded Virtual Machines

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Update to 121.0.6167.160 High CVE-2024-1284: Use after free in Mojo High CVE-2024-1283: Heap buffer overflow in Skia

Apply fix for CVE-2023-28531

Update to the latest stable version: Features Implement a new plugin manager from scratch to replace Yapsy, which does not work on Python 3.12 due to Python 3.12 carelessly removing parts of the standard library (Issue #3719)

Fix webkit_web_context_allow_tls_certificate_for_host to handle IPv6 URIs produced by SoupURI. Ignore stops with offset zero before last one when rendering gradients with cairo. Write bwrapinfo.json to disk for xdg-desktop-portal.

New version 4.0.12. Includes fixes for CVE-2023-5371, CVE-2023-6174, CVE-2023-6175, CVE-2024-0208.

Security fix for CVE-2024-21626

The updated packages fix security vulnerabilities: Logic bug in text extractor led to invalid memory access. (CVE-2022-30524) Integer overflow in rasterizer. (CVE-2022-30775) PDF object loop in Catalog::countPageTree. (CVE-2022-33108)

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

Update rust-vmm components and their consumers to address CVE-2023-50711

https://security-tracker.debian.org/tracker/DSA-5618-1

Closing the Security Gap: Navigating Modern Technology and Outdated Systems in Linux Security

* bsc#1219048 Cross-References: * CVE-2023-50447

Several security issues were fixed in the Linux kernel.

Running Windows 11 and 2022 Server Virtual Machines in Red Hat OpenShift with persistent vTPM