Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

https://security-tracker.debian.org/tracker/DSA-5800-1

https://security-tracker.debian.org/tracker/DSA-5799-1

FIPS 140-3 changes for PKCS #12

https://security-tracker.debian.org/tracker/DSA-5798-1

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The updated package provides Firefox 128 for all mandatory arches of Mageia (x86_64, i586 and aarch64), fixing several bugs, including security vulnerabilities, for i586 and aarch64: Fullscreen notification dialog can be obscured by document content. (CVE-2024-7518)

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1220262 Cross-References: * CVE-2023-50782

Strengthen DevSecOps with Red Hat Trusted Software Supply Chain
Secure design principles in the age of artificial intelligence
Confidential Containers with IBM Secure Execution for Linux

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by calling fchown in the presence of a symlink. (CVE-2024-47191)

fix CVE-2024-7006 (rhbz#2302997) fix CVE-2023-52356 (rhbz#2260112) fix CVE-2023-6228 (rhbz#2251863)

https://security-tracker.debian.org/tracker/DSA-5797-1

https://security-tracker.debian.org/tracker/DSA-5796-1

* bsc#1231294 Cross-References: * CVE-2024-47850

* bsc#1224038 * bsc#1224051 * bsc#1229013 Cross-References:

* bsc#1231039 Cross-References: * CVE-2024-23213 * CVE-2024-23271

* bsc#1231039 Cross-References: * CVE-2024-23206 * CVE-2024-23213

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1231698 Cross-References: * CVE-2024-9676

* bsc#1230683 Cross-References: * CVE-2024-45405

libheif could be made to crash or read sensitive data if it opened a specially crafted file

Several security issues were fixed in Go.

Various security, performance, accuracy, and stability issues have been fixed.

New version 4.2.8 Fix for CVE-2024-9781

It was discovered that there was a potential out-of-bounds read vulnerability in libheif, a decoder and encoder for the HEIF and AVIF image formats.

https://security-tracker.debian.org/tracker/DSA-5795-1

Unbound could be made to stop responding if it received specially crafted DNS traffic.

Understanding Linux Persistence Mechanisms and Detection Tools

A heap-based pointer disclosure problem was found in Ghostscript, an interpreter for the PostScript language and for PDF. This could lead to information disclosure.

Firefox could be made to crash or run programs as your login

Multiple vulnerabilities were discovered in libsepol, a set of userspace utilities and libraries for manipulating SELinux policies. CVE-2021-36084, CVE-2021-36085, CVE-2021-36086

New openssl packages are available for Slackware 15.0 to fix a security issue.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Boost Your Linux Server Security with SSH Mastery

AMD processors may allow a privileged local attacker to further escalate their privileged and execute arbitrary code within the processor’s firmware layer.

https://security-tracker.debian.org/tracker/DSA-5794-1

Two issues have been found in asterisk, an Open Source Private Branch Exchange.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fixes possible denial of service attack on untrusted input

https://security-tracker.debian.org/tracker/DSA-5793-1

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Automatic update for buildah-1.37.5-1.fc41. Changelog for buildah * Fri Oct 18 2024 Packit – 2:1.37.5-1 – Update to 1.37.5 upstream release Fixes CVE-2024-9341, CVE-2024-9675 and CVE-2024-9676.

Update to 130.0.6723.58 * High CVE-2024-9954: Use after free in AI * Medium CVE-2024-9955: Use after free in Web Authentication * Medium CVE-2024-9956: Inappropriate implementation in Web Authentication * Medium CVE-2024-9957: Use after free in UI

Fix for CVE-2024-48957 Automatic update for libarchive-3.7.2-6.fc40.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1229910 Cross-References: * CVE-2024-42934

* bsc#1231689 Cross-References: * CVE-2024-47874

* bsc#1231651 Cross-References: * CVE-2024-8184

The fixes for CVE-2024-38474 and CVE-2024-39884 introduced two regressions in mod_rewrite and mod_proxy. For Debian 11 bullseye, these problems have been fixed in version

* bsc#1228349 * bsc#1228786 Cross-References: * CVE-2024-40909

* bsc#1227651 * bsc#1228573 Cross-References: * CVE-2021-47291

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1228573 * bsc#1228786 Cross-References: * CVE-2024-40954

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

Prevent command injection by quoting template strings in activation scripts

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1231284 Cross-References: * CVE-2024-8508

* bsc#1095184 * bsc#1118897 * bsc#1118898 * bsc#1118899 * bsc#1121850

* bsc#1225312 * bsc#1226325 * bsc#1227651 * bsc#1228573

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1223059 * bsc#1223363

* bsc#1210619 * bsc#1218487 * bsc#1220145 * bsc#1220537 * bsc#1221302

https://security-tracker.debian.org/tracker/DSA-5792-1

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1228123 Cross-References: * CVE-2024-41184

* bsc#1225312 * bsc#1225739 * bsc#1226325 * bsc#1228573 * bsc#1228786

* bsc#1219296 * bsc#1220145 * bsc#1220211 * bsc#1220828 * bsc#1220832

* bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225099 * bsc#1225312

* bsc#1223683 * bsc#1225099 * bsc#1225739 * bsc#1228349 * bsc#1228573

An update that fixes two vulnerabilities is now available.

Python could me made to bypass some restrictions if it received specially crafted input.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Update to 129.0.6668.100 * CVE-2024-9602: Type Confusion in V8 * CVE-2024-9603: Type Confusion in V

Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman

Automatic update for buildah-1.37.4-1.fc41, podman-5.2.4-1.fc41. Changelog for buildah * Mon Oct 07 2024 Packit – 2:1.37.4-1 – Update to 1.37.4 upstream release Changelog for podman

https://security-tracker.debian.org/tracker/DSA-5790-1

https://security-tracker.debian.org/tracker/DSA-5791-1

Various file formats are based on the zip file format. In cases of corruption of the underlying zip’s central directory, LibreOffice offers a “repair mode” which will attempt to recover the zip file structure by scanning for secondary local

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For the stable distribution (bookworm), these problems have been fixed in

Update to 2.0.19

Redis Community Edition 7.2.6 Released Wed 02 Oct 2024 20:17:04 IDT Upgrade urgency SECURITY: See security fixes below. Security fixes CVE-2024-31449 Lua library commands may lead to stack overflow and potential RCE.

Update rust-brotli-decompressor to 4.0.1, rust-brotli to 7.0.0, and rust-async- compression to 0.4.13. Patch dependent packages as needed to avoid compat packages. Rebuild with the latest Rust crate dependency versions; fix automatic provides on Python extension due to SONAME when built with Rust 1.81 or later.