Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795

Multiple vulnerabilities were discovered in Node.js, a JavaScript runtime environment, which could result in memory corruption, invalid certificate validation, prototype pollution or command injection.

Enterprise Encryption for Linux: Improve Manageability & Compliance

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Rocky Linux Security Advisories Are Now on LinuxSecurity.com!

security update

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

This update includes the changes in tzdata 2022d for the Perl bindings. For the list of changes, see DLA-3134-1. For Debian 10 buster, this problem has been fixed in version

This update includes the changes in tzdata 2022d. Notable changes are: – – Palestine now switches back to standard time on October 29.

An invalid HTTP request (websocket handshake) may cause a NULL pointer dereference in the wstunnel module. For Debian 10 buster, this problem has been fixed in version

Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706

Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

The container bci/python was updated. The following patches have been included in this update:

The container bci/nodejs was updated. The following patches have been included in this update:

The container bci/bci-init was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

An update that fixes two vulnerabilities is now available.

The container suse/sles12sp4 was updated. The following patches have been included in this update:

Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.

thenify is a Promisify a callback-based function using any-promise. Affected versions of this package are vulnerable to Arbitrary Code Execution. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval

Update to 102.3.1 * https://www.mozilla.org/en- US/security/advisories/mfsa2022-43/ * https://www.thunderbird.net/en- US/thunderbird/102.3.1/releasenotes/

security update

An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in TiXmlParsingData::Stamp(), which results in a denial of service.

An issue has been found in libhttp-daemon-perl, a simple http server class. Due to insufficient Content-Length: handling in HTTP-header an attacker

Connecting to the RHEL web console, part 2: Running the Cockpit web server

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

This update upgrades Thunderbird to version 102.3.0. * Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033) * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 […]

This update upgrades Firefox to version 102.3.0 ESR. * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962) * Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure pref [More…]

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

Red Hat Shares ― Edge computing: Security

security update

security update

Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint. CVE-2022-37797

An update that fixes two vulnerabilities is now available.

It was discovered that the Commandline class in maven-shared-utils, a collection of various utility classes for the Maven build system, can emit double-quoted strings without proper escaping, allowing shell injection attacks.

An update that solves 20 vulnerabilities and has 8 fixes is now available.

Memory-related security fixes, BZ 2127755

The container suse/sle15 was updated. The following patches have been included in this update:

security update

security update

An update that fixes 6 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Edge solutions in rail transportation deliver efficiencies, security and flexibility with open source solutions
Official Guide on Rocky Linux & How to Install It

Several security issues were fixed in Ghostscript.

An update that solves 11 vulnerabilities and has 21 fixes is now available.

Several security issues were fixed in WebKitGTK.

Several security issues were fixed in Squid.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

An update that solves one vulnerability and has two fixes is now available.

Expat could be made to crash or execute arbitrary code.

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been found in Oracle JDK and JRE, the worst of which could result in the arbitrary execution of code.

Multiple vulnerabilities have been discovered in Fetchmail, the worst of which could result in email disclosure to third parties.

Multiple vulnerabilities have been discovered in libaacplus, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in GRUB, the worst of which may allow for secureboot bypass.

Multiple vulnerabilities have been discovered in HarfBuzz, the worst of which could result in arbitrary code execution.

security update

How to integrate Red Hat Advanced Cluster Security for Kubernetes with ServiceNow

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.

Update to bugfix/security release 2022-07-29a. Includes security fix for CVE-2022-3123.

security update

security update

security update

security update

Several security issues were fixed in the Linux kernel.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

Connecting to the RHEL web console, part 1: SSH access methods
Role-based access control for Red Hat Hybrid Cloud Console
Business VPNs: Now More Important Than Ever

An update that fixes two vulnerabilities is now available.

The container suse/sles/15.4/virt-operator was updated. The following patches have been included in this update: