Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Changes with nginx 1.26.3 05 Feb 2025 *) Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification (CVE-2025-23419). *) Bugfix: in the ngx_http_mp4_module.

Transparency in AI: How Open-Source LLMs Can Prevent Hidden Vulnerabilities

* bsc#1236878 Cross-References: * CVE-2024-12133

Several security issues were fixed in Apache ActiveMQ.

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

* bsc#1212641 * bsc#1219912 * bsc#1229079 * bsc#1229104 * bsc#1231024

https://security-tracker.debian.org/tracker/DSA-5866-1

* bsc#1012628 * bsc#1194869 * bsc#1215199 * bsc#1216813 * bsc#1218470

* bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

* bsc#1228044 * bsc#1236282 Cross-References: * CVE-2025-0395

How to adopt platform engineering in 2025

* bsc#1229644 * bsc#1230998 * bsc#1231993 Cross-References:

* bsc#1229644 * bsc#1229663 * bsc#1230998 * bsc#1231993

* bsc#1230998 * bsc#1231993 Cross-References: * CVE-2024-45016

https://security-tracker.debian.org/tracker/DSA-5865-1

https://security-tracker.debian.org/tracker/DSA-5864-1

https://security-tracker.debian.org/tracker/DSA-5863-1

* bsc#1228165 * bsc#1236705 Cross-References: * CVE-2025-0938

* bsc#1227056 * bsc#1236483 Cross-References: * CVE-2023-45288

* bsc#1218879 * bsc#1218880 * bsc#1218881 * bsc#1218882 * bsc#1218883

Navigating AI-Driven Security Challenges in Linux Environments

* bsc#1236619 * jsc#PED-12018 Cross-References: * CVE-2025-24528

* bsc#1233760 Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6

How Secure Is Linux? Examining Features That Ensure Safety
Secure Your DevTools: Critical UAF Vulnerability Warning
Firefox 135 Released: Key Updates & Advanced Browser Protection Features
Tails 6.12: An Essential Privacy, Security, and Reliability Upgrade

USN-7206-3 caused some regression in rsync.

* bsc#1236596 Cross-References: * CVE-2024-11187

https://security-tracker.debian.org/tracker/DSA-5862-1

https://security-tracker.debian.org/tracker/DSA-5861-1

Vulnerabilities were found in sssd, a set of daemons to manage access to remote directories and authentication mechanisms, which could lead to privilege escalation.

update to 1.33.0

Security fix for CVE-2023-52892, CVE-2024-27354

Add code to deal with sched_setattr() not being exported in glibc 2.41 Address CVE-2024-54159 denial of services via symlink attack

Update to 1.17.3 Fixes CVE-2024-0134 or GHSA-7jm9-xpwx-v999 Fixes CVE-2024-0135 or GHSA-9v84-cc9j-pxr6, CVE-2024-0136 or GHSA- vcfp-63cx-4h59, and CVE-2024-0137 or GHSA-frhw-w3wm-6cw4

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

Updated to latest upstream (135.0)

Update to 0.8.4

xrdp allows an infinite number of login attempts. (CVE-2024-39917) References: – https://bugs.mageia.org/show_bug.cgi?id=33985 – https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/FMYGECEBC7XEBNQ2ZHXYRQBLCMHHXKP5/

When an input DER data contains a large number of SEQUENCE OF or SET OF elements, decoding the data and searching a specific element in it take quadratic time to complete. This could be utilized for a remote DoS attack by presenting a crafted certificate to the network peer.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

Update the openssl crate to version 0.10.70 and the openssl-sys crate to version 0.9.105. This includes a fix for RUSTSEC-2025-0004 / CVE-2025-0977 and rebuilds of all packages that statically link the openssl crate.

https://security-tracker.debian.org/tracker/DSA-5860-1

* bsc#1236270 Cross-References: * CVE-2024-11218

A vulnerability has been discovered in the OpenJDK Java runtime, which may result in authorisation bypass or information disclosure. For Debian 11 bullseye, this problem has been fixed in version

Updated to latest upstream (135.0)

Fix CVE-2025-0781

Fix CVE-2025-0781

https://security-tracker.debian.org/tracker/DSA-5859-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Ruby.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Several security issues were fixed in CKEditor.

Fix for CVE-2025-0781

Common Vulnerability Scoring System (CVSS) vs. Risk: Why are we still having this conversation?

OpenJDK 23 could be made to expose sensitive information over the network.

OpenJDK 21 could be made to expose sensitive information over the network.

OpenJDK 17 could be made to expose sensitive information over the network.

OpenJDK 11 could be made to expose sensitive information over the network.

USN-7096-1 caused some minor regressions in OpenJDK 8.

Rebuilt against golang-x-net 0.33.0 for CVE-2024-45338

https://security-tracker.debian.org/tracker/DSA-5858-1

* bsc#1236136 Cross-References: * CVE-2024-13176

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236460 Cross-References: * CVE-2022-49043

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Responding to Chrome’s Latest Security Vulnerabilities: Update to Chrome 132 Now!

* bsc#1236518 Cross-References: * CVE-2023-45288

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

* bsc#1236272 Cross-References: * CVE-2024-11218 * CVE-2024-9407

Matthias Gerstner reported that pam-u2f, a PAM module which allows to use U2F (Universal 2nd Factor) devices in the PAM authentication stack, does not properly handle PAM_IGNORE return values, allowing to bypass the second factor or password-less login without inserting the proper

https://security-tracker.debian.org/tracker/DSA-5857-1

Several issues have been found in ffmpeg, a package that contains tools for transcoding, streaming and playing of multimedia files Those issues are related to possible integer overflows, double-free on

Monitoring Red Hat Ansible Automation Platform using Performance Co-Pilot

update to 0.10.4

Updated to 132.0.6834.159 * Medium CVE-2025-0762: Use after free in DevTools

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084