Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Secure cloud bursting: Leveraging confidential computing for peace of mind
Recent improvements in Red Hat Enterprise Linux CoreOS security data
Strengthening security of the software supply chain for LLVM

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

New upstream build (132.0)

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Red Hat Insights expands its detection capabilities with CrowdStrike integration

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

Update to 128.4.0 https://www.thunderbird.net/en-US/thunderbird/128.4.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-58/

Update to version 1.28.0. Release notes: https://github.com/syncthing/syncthing/releases/tag/v1.28.0

Version 6.7.7 (2024-10-26) Update regular expression to avoid ReDoS (CVE-2024-22641) [PHP 8.4] Fix: Curl CURLOPT_BINARYTRANSFER deprecated #675 SVG detection fix for inline data images #646 Fix count svg #647

https://security-tracker.debian.org/tracker/DSA-5803-1

https://security-tracker.debian.org/tracker/DSA-5802-1

Guide to Automating Third-Party Risk Management in Linux Environments
Red Hat Insights collaborated with Vulcan Cyber to provide a seamless integration for effective exposure management

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, cross-site scripting, spoofing or information disclosure.

* bsc#1227471 * bsc#1228349 * bsc#1228573 * bsc#1228786

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

* bsc#1225011 * bsc#1225012 * bsc#1225309 * bsc#1225311 * bsc#1225819

Several security issues were fixed in the Linux kernel.

* bsc#1223363 * bsc#1223683 * bsc#1225011 * bsc#1225012 * bsc#1225013

Enhancing Cybersecurity with Breach and Attack Simulation in Linux Environments
Comprehensive Guide to Fixing and Securing MySQL InnoDB Table Corruption

https://security-tracker.debian.org/tracker/DSA-5801-1

https://security-tracker.debian.org/tracker/DSA-5800-1

https://security-tracker.debian.org/tracker/DSA-5799-1

FIPS 140-3 changes for PKCS #12

https://security-tracker.debian.org/tracker/DSA-5798-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1220262 Cross-References: * CVE-2023-50782

Strengthen DevSecOps with Red Hat Trusted Software Supply Chain
Secure design principles in the age of artificial intelligence
Confidential Containers with IBM Secure Execution for Linux

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)

fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)

https://security-tracker.debian.org/tracker/DSA-5797-1

https://security-tracker.debian.org/tracker/DSA-5796-1

* bsc#1231294 Cross-References: * CVE-2024-47850

* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:

* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271

* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1230683 Cross-References: * CVE-2024-45405

libheif could be made to crash or read sensitive data if it opened a specially crafted file

Several security issues were fixed in Go.

Various security, performance, accuracy, and stability issues have been fixed.

New version 4.2.8 Fix for CVE-2024-9781

It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.

https://security-tracker.debian.org/tracker/DSA-5795-1

Unbound could be made to stop responding if it received specially crafted DNS traffic.

Understanding Linux Persistence Mechanisms and Detection Tools

A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.

Firefox could be made to crash or run programs as your login

Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

New openssl packages are available for Slackware 15.0 to fix a security issue.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Boost Your Linux Server Security with SSH Mastery

AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.

https://security-tracker.debian.org/tracker/DSA-5794-1

Two issues have been found in asterisk, an Open Source Private Branch Exchange.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fixes possible denial of service attack on untrusted input

https://security-tracker.debian.org/tracker/DSA-5793-1

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI