Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Rebase to 20.18.2 Resolves: CVE-2025-22150 CVE-2025-23085 CVE-2025-23083

Update to version 18.20.6 (rhbz#2341760) (rhbz#2340936) (rhbz#2300997) Resolves CVE-2025-23084

New ASPA support is now always compiled in and available if enable-aspa is set. The aspa Cargo feature has been removed. (#990) If merging mutliple ASPA objects for a single customer ASN results in more than 16,380 provider ASNs, the ASPA is dropped. (Note that ASPA objects with more

An update that fixes one vulnerability is now available.

Multiple vulnerabilities have been fixed in DCMTK, a collection of libraries and applications implementing large parts the DICOM standard for medical images.

Vanilla upstream kernel version 6.6.74 fixes bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33968

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5854-1

https://security-tracker.debian.org/tracker/DSA-5853-1

* bsc#1236518 Cross-References: * CVE-2023-45288

Streamline the connectivity between your environment and Red Hat Insights services

* bsc#1228770 Cross-References: * CVE-2013-4235

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Tomcat could be made to run programs if it received specially crafted network traffic.

Several security issues were fixed in jinja2.

VLC could be made to crash or run programs if it received specially crafted network traffic.

https://security-tracker.debian.org/tracker/DSA-5855-1

https://security-tracker.debian.org/tracker/DSA-5856-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5851-1

* bsc#1214612 * bsc#1215807 * bsc#1215926 * bsc#1217828 * bsc#1221677

Multiple vulnerabilities were discovered in git, a fast, scalable and distributed revision control system. CVE-2024-50349

FRR could be made to crash or exhibit degraded performance if it received specially crafted network traffic.

Quagga could be made to crash if it received specially crafted network traffic.

* bsc#1225819 * bsc#1227369 * bsc#1227781 * bsc#1227784 * bsc#1228349

* bsc#1226324 Cross-References: * CVE-2024-36971

* bsc#1226324 * bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

An update that fixes two vulnerabilities is now available.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size. (CVE-2025-0395)

Timing side-channel in ECDSA signature computation. (CVE-2024-13176) References: – https://bugs.mageia.org/show_bug.cgi?id=33942 – https://openssl-library.org/news/secadv/20250120.txt

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

Update to 132.0.6834.110 High CVE-2025-0611: Object corruption in V8 High CVE-2025-0612: Out of bounds memory access in V8

https://lists.wikimedia.org/hyperkitty/list/wikitech- l@lists.wikimedia.org/thread/PFTE5RHUERS6KTUGGRZO7XXV5THNJ77E/ https://lists.wikimedia.org/hyperkitty/list/mediawiki- announce@lists.wikimedia.org/thread/5NYC4UZLY3MWQZ6DYJAUQRJG2ZHZFBJ6/

https://security-tracker.debian.org/tracker/DSA-5850-1

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

New version 3.4.1, a couple of fixes for the 3.4.0 release.

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Security fix for CVE-2024-11218 – fixed in buildah 1.38.1, podman 5.3.2 Automatic update for buildah-1.38.1-1.fc41, containers-common-0.61.1-1.fc41, podman-5.3.2-1.fc41. Changelog for buildah * Tue Jan 21 2025 Packit – 2:1.38.1-1

Includes security fixes to the crypto/x509 and net/http packages

Update to latest version Fix CVE-2024-53263

pam-u2f 1.3.1 includes a fix to resolve CVE-2025-23013 (Partial Authentication Bypass). CVSS score 7.3. 1.3.2 is a fix for a regression that could impact existing use cases.

Update to latest version Fix CVE-2024-53263

PCL could be made to crash if it received specially crafted input.

https://security-tracker.debian.org/tracker/DSA-5849-1

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

https://security-tracker.debian.org/tracker/DSA-5847-1

OpenJPEG could be made to crash or run programs if it opened a specially crafted file.

Django could be made to cause a denial of service if it received a specially crafted IPv6 string.

In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket’s buffer size, default 4K on most OSes.

Multiple vulnerabilities have been discovered in PHP, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.

https://security-tracker.debian.org/tracker/DSA-5848-1

A Sysadmin’s Guide to Securing the Linux Kernel
EMEA blog [DUTCH] | Red Hat closes Master Agreement with SLM Rijk to strengthen digital autonomy within Dutch government
Introducing confidential containers on bare metal

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* bsc#1232762 * jsc#PED-10545 Affected Products: * Containers Module 15-SP6

Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

https://security-tracker.debian.org/tracker/DSA-5846-1

A Linux Admin’s Guide to Ensuring Data Privacy in 2025
Passwords: a thin line between love and hate

Important: thunderbird security update

Important: raptor2 security update

Important: rsync security update

https://security-tracker.debian.org/tracker/DSA-5843-2

Migrating from .NET Framework to .NET Core: Security and Open Source Benefits

https://security-tracker.debian.org/tracker/DSA-5845-1

The update for rsync announced in DSA 5843-1 introduced a regression when using the -H option to preserve hard links. Updated packages are now available to correct this issue.

* bsc#1235856 Cross-References: * CVE-2024-56374

* bsc#1220145 * bsc#1221302 * bsc#1222882 * bsc#1223059 * bsc#1223363

USN-7206-1 caused some regression in rsync.

* bsc#1228693 Cross-References: * CVE-2024-40779

* bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202