Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225202 Cross-References: * CVE-2021-47378

* bsc#1225202 * bsc#1225302 Cross-References: * CVE-2021-47378

Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397

* bsc#1225983 Cross-References: * CVE-2024-21096

* bsc#1225202 Cross-References: * CVE-2021-47378

https://security-tracker.debian.org/tracker/DSA-5759-1

The Future-Proof Server: Antivirus and Beyond for Linux Admins

* bsc#1027519 * bsc#1227355 * bsc#1228574 * bsc#1228575

Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or request smuggling.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

https://security-tracker.debian.org/tracker/DSA-5758-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

* bsc#1224188 Cross-References: * CVE-2021-36386

* bsc#1129596 Cross-References: * CVE-2019-9656

An update that fixes 20 vulnerabilities is now available.

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

* bsc#1226316 * bsc#1228648 Cross-References: * CVE-2024-6600

* bsc#1219559 * bsc#1221563 Cross-References: * CVE-2023-52425

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695 * bsc#1228696

Bump to version 5.9.4

https://security-tracker.debian.org/tracker/DSA-5757-1

* bsc#1224044 Cross-References: * CVE-2024-34397

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Authentication and Authorization in Red Hat OpenShift and Microservices Architectures
Deployment considerations for Red Hat OpenShift Confidential Containers solution

Several security issues were fixed in QEMU.

Fix web process cache suspend/resume when sandbox is enabled. Fix accelerated images disappearing after scrolling. Fix video flickering with DMA-BUF sink. Fix pointer lock on X11. Fix movement delta on mouse events in GTK3.

Several security issues were fixed in the Linux kernel.

* bsc#1177179 Cross-References: * CVE-2020-26159

* bsc#1228574 * bsc#1228575 Cross-References: * CVE-2024-31145

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Martin Kaesberger discovered a vulnerability which affects multiple OpenStack components (Nova, Glance and Cinder): Malformed QCOW2 disk images may result in the disclosure of arbitrary files.

https://security-tracker.debian.org/tracker/DSA-5752-1

https://security-tracker.debian.org/tracker/DSA-5753-1

https://security-tracker.debian.org/tracker/DSA-5754-1

https://security-tracker.debian.org/tracker/DSA-5755-1

https://security-tracker.debian.org/tracker/DSA-5756-1

Several security issues were fixed in Cacti.

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222986 * bsc#1222987

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1228046 * bsc#1228047 * bsc#1228048 * bsc#1228050 * bsc#1228051

* bsc#1212968 * bsc#1215311 * bsc#1227322 Cross-References:

* bsc#1228143 Cross-References: * CVE-2024-1013

* bsc#1011205 * bsc#1093641 * bsc#1125882 * bsc#1167400 * bsc#1207973

* bsc#1223155 Cross-References: * CVE-2024-31744

* bsc#1192145 * bsc#1209657 * bsc#1218336 * bsc#1218447 * bsc#1218479

* bsc#1222835 * bsc#1222837 * jsc#SLE-23879 Cross-References:

* bsc#1184942 * bsc#1186060 * bsc#1192145 * bsc#1194516 * bsc#1208995

* bsc#1160688 * bsc#1223100 * jsc#PED-7677 * jsc#SLE-9298

https://security-tracker.debian.org/tracker/DSA-5751-1

https://security-tracker.debian.org/tracker/DSA-5750-1

* bsc#1082555 * bsc#1193454 * bsc#1193554 * bsc#1193787 * bsc#1194324

* bsc#1065729 * bsc#1179610 * bsc#1186463 * bsc#1216834 * bsc#1218820

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1229129 Cross-References: * CVE-2023-42667 * CVE-2023-49141

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1229069 Cross-References: * CVE-2023-31315

* bsc#1214327 * bsc#1218413 * bsc#1222120 * bsc#1227426 * bsc#1227513

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1082555 * bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454

https://security-tracker.debian.org/tracker/DSA-5749-1

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228535 Cross-References: * CVE-2024-7264

* bsc#1226463 * bsc#1227138 Cross-References: * CVE-2024-5535

* bsc#1225907 * bsc#1226463 * bsc#1227138 Cross-References:

* bsc#1227178 Cross-References: * CVE-2024-39134

* bsc#1227178 Cross-References: * CVE-2024-39134

https://security-tracker.debian.org/tracker/DSA-5743-2

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1065729 * bsc#1088701 * bsc#1149446 * bsc#1179610 * bsc#1186463

* bsc#1156395 * bsc#1190336 * bsc#1191958 * bsc#1193454 * bsc#1193554

* bsc#1228105 Cross-References: * CVE-2024-6345

* bsc#1228613 * bsc#1228693 * bsc#1228694 * bsc#1228695

Improved vulnerability reporting on Quay.io

https://security-tracker.debian.org/tracker/DSA-5748-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

BlackHat USA 2024: Key Takeaways for Linux Admins & InfoSec Pros
Staying a Step Ahead of Adversaries: Mitigating Chromium’s Security Flaws on Linux
5 Key Benefits Of Code Signing Solutions
5 Open-Source Blockchain Technologies That Linux Users Need to Know About

Multiple vulnerabilities have been discovered in protobuf-c, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PHP, the worst of which can lead to a denial of service.

A vulnerability has been discovered in protobuf and protobuf-python, which can lead to a denial of service.