An update for kernel-rt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which
Update to the latest bugfixes (1-5) against 5.4.4. Includes fixes for CVE-2022-28805 and CVE-2022-33099.
Bottle could be made to leak sensitive information if it received a specially crafted request.
It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code or escalate privileges. For the oldstable distribution (buster), this problem has been fixed
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/389-ds was updated. The following patches have been included in this update:
security update
security update
Simon Josefsson discovered an out-of-bounds memory read in GNU SASL, an implementation of the Simple Authentication and Security Layer framework, which could result in denial of service.
An update that contains security fixes can now be installed.
PHP could be made to crash or run programs if it processed specially crafted data.
This update provides the upstream 6.1.36 maintenance release that fixes at least the following security vulnerabilities: A vulnerability in the Oracle VM VirtualBox prior to 6.1.36 contains an easily exploitable vulnerability that allows a high privileged attacker
Apply proposed patch for CVE-2022-28506.
An update that solves 8 vulnerabilities and has one errata is now available.
An update that solves 8 vulnerabilities and has one errata is now available.
security update
security update
The container suse/pcp was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sles12sp4 was updated. The following patches have been included in this update:
**Changelog** “` * Thu Jul 07 2022 Clemens Lang – 1:1.1.1q-1 – Upgrade to 1.1.1q Resolves: CVE-2022-2097 “` —- “` * Thu Jun 30 2022 Clemens Lang – 1:1.1.1p-1 – Upgrade to 1.1.1p Resolves: CVE-2022-2068 Related: rhbz#2099975 “` Security fix for CVE-2022-2068
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
security update
This update fixes many bugs some of which are security relevant.
Security fixes for CVE-2022-2257, CVE-2022-2284, CVE-2022-2285, CVE-2022-2286, CVE-2022-2287, CVE-2022-2288, CVE-2022-2289, CVE-2022-2264, CVE-2022-2304, CVE-2022-2345, CVE-2022-2344, CVE-2022-2343.
This update fixes many bugs some of which are security relevant.
An update that solves 9 vulnerabilities and has four fixes is now available.
The container bci/nodejs was updated. The following patches have been included in this update:
An update that fixes three vulnerabilities is now available.
Red Hat OpenStack Platform 16.2 (Train) director operator containers, with several Important security fixes, are available for technology preview. 2. Description: Release osp-director-operator images
Apache XML Security for Java could be made to expose sensitive information.
An update that fixes one vulnerability is now available.
Several security issues were fixed in FreeType.
Several security issues were fixed in Checkmk.
The container suse-sles-15-sp3-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
An update that fixes one vulnerability is now available.
HarfBuzz could be made to crash if it opened specially crafted data.
The container sles-15-sp2-chost-byos-v20220718-x86-64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp2-chost-byos-v20220718-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp2-chost-byos-v20220718-x86_64-gen2 was updated. The following patches have been included in this update:
Several security issues were fixed in LibTIFF.
HTTP-Daemon could allow HTTP Request Smuggling attacks.
An update that solves 11 vulnerabilities and has 44 fixes is now available.
An update that fixes four vulnerabilities is now available.
An update that solves 10 vulnerabilities, contains one feature and has 43 fixes is now available.
An update that solves 9 vulnerabilities and has 9 fixes is now available.
The container sles-15-sp1-chost-byos-v20220715-x86-64 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]
Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs — This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: – CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode – CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar […]
security update
security update
An update that fixes 5 vulnerabilities is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container bci/bci-init was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
**Version 2.13.0** Enhancement * 106: Refined types as per laminas/laminas- coding-standard:2.3.x upgrades thanks to @Ocramius * 103: Update to laminas/laminas-coding-standard:2.3.x, improved types and internal API thanks to @gsteel —- **Version 2.12.0** Bug * 99: Merge release 2.11.3 into 2.12.x thanks to @github-actions[bot] * 92: Fix typo in property name in
An update that solves 15 vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
The container bci/dotnet-sdk was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
security update
The 5.18.11 stable kernel update contains a number of important fixes across the tree. In addition to the 5.18.11 stable patches, this build contains the retbleed patches scheduled for 5.18.12 kernels.
– fix unpreserved file permissions (CVE-2022-32207) – fix Set-Cookie denial of service (CVE-2022-32205) – fix HTTP compression denial of service (CVE-2022-32206) – fix FTP-KRB bad message verification (CVE-2022-32208)
security update
An update that solves one vulnerability and has three fixes is now available.
An update that solves 21 vulnerabilities and has 6 fixes is now available.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
Python could be made to run arbitrary code if it received a specially crafted input.
HTTP-Daemon could allow HTTP Request Smuggling attacks.
An update that solves 9 vulnerabilities and has four fixes is now available.
An update that solves 15 vulnerabilities and has 22 fixes is now available.
An update that fixes one vulnerability is now available.
uriparser could be made to crash if it received specially crafted input.
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
security update
Several security issues were fixed in X.Org X Server.
