Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1198880 * bsc#1214678 Cross-References: * CVE-2022-28506

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

Backport upstream patch for CVE-2023-49606.

Update to v1.29.7 for FC40. Resolves CVE-2024-5321: Incorrect permissions on Windows containers logs. Additional bug and regression fixes from upstream.

Update to version 1.11.2 to fix CVE-2023-49606.

An update that fixes one vulnerability is now available.

Security fix for CVE-2024-5569 (rhbz#2297117)

New libxml2 packages are available for Slackware XXX 15.0 and -current to fix a security issue.

New htdig packages are available for Slackware 15.0 and -current to fix a security issue.

Update to 1.3.3 https://github.com/hyprwm/xdg-desktop-portal-hyprland/releases/tag/v1.3.3

Security fix for CVE-2024-5569 (rhbz#2297118)

Security fix for CVE-2024-33869 Security fixes for CVE-2024-29509, CVE-2024-29508, CVE-2024-29507, CVE-2024-29506

update xmedcon to 0.24.0 fixes: Bug 2283157 – xmedcon-0.24.0 is available Bug 2283100 – CVE-2024-29421 xmedcon: Heap overview when parsing DICOM medical files [fedora-all]

provd could be made to run programs as an administrator.

A vulnerability has been discovered in Freenet, which can lead to deanonymization due to path folding.

Multiple vulnerabilities have been discovered in ExifTool, the worst of which could lead to arbitrary code execution.

A vulnerability has been discovered in Dmidecode, which can lead to privilege escalation.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1227268 * bsc#1227269 * bsc#1227272 Cross-References:

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1219660 Cross-References: * CVE-2024-24577

* bsc#1214980 * bsc#1222804 * bsc#1222807 * bsc#1222811 * bsc#1222813

An update that fixes 8 vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

* bsc#1205628 Cross-References: * CVE-2022-4065

Several security issues were fixed in Thunderbird.

Update to 115.13.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-31/ https://www.thunderbird.net/en-US/thunderbird/115.13.0/releasenotes/

The Risks Inherent in Including Security Modules At Kernel Level: Lessons From CrowdStrike Incident

Memory corruption in WebGL API. (CVE-2024-6600) Race condition in permission assignment. (CVE-2024-6601) Memory corruption in thread creation. (CVE-2024-6603) Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13, and Thunderbird 115.13. (CVE-2024-6604)

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Announcing v4.5.1 This release contains contributions from a record number of new contributors. This is greatly appreciated since I am a team of one, and do Tcpreplay maintenance in my spare time. There are many bug fixes and new features. Most notable features:

An update that fixes 22 vulnerabilities is now available.

update to 126.0.6478.182 High CVE-2024-6772: Inappropriate implementation in V8 High CVE-2024-6773: Type Confusion in V8 High CVE-2024-6774: Use after free in Screen Capture High CVE-2024-6775: Use after free in Media Stream

Update to 3.0.4

New bugfix and security update

Rebase to v2.19.5

Update to 3.24.43

Update to 3.0.4

https://security-tracker.debian.org/tracker/DSA-5733-1

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

This is the July 2024 security update for .NET 6. Release Notes SDK: https://github.com/dotnet/core/blob/main/release- notes/6.0/6.0.32/6.0.132.md Runtime: https://github.com/dotnet/core/blob/main/release-

Fix for CVE-2024-38517.

Security fixes for https://nvd.nist.gov/vuln/detail/CVE-2024-38875 https://nvd.nist.gov/vuln/detail/CVE-2024-39329 https://nvd.nist.gov/vuln/detail/CVE-2024-3930 https://nvd.nist.gov/vuln/detail/CVE-2024-39614

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683 * bsc#1225211

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1210619 * bsc#1220537 * bsc#1223363 * bsc#1223683 * bsc#1225211

Red Hat Enterprise Linux and Secure Boot in the cloud
Red Hat Advanced Cluster Security Cloud Service is now Generally Available
Red Hat’s path to post-quantum cryptography

stunnel could allow unintended access to network services.

* bsc#1224122 Cross-References: * CVE-2024-3727

Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.

https://security-tracker.debian.org/tracker/DSA-5732-1

https://security-tracker.debian.org/tracker/DSA-5731-1

Exim 4.98 Addresses Critical Vulnerabilities, Bolsters Email Server Security

* bsc#1227399 Cross-References: * CVE-2024-34750

* bsc#1225771 Cross-References: * CVE-2024-5564

* bsc#1222665 * bsc#1227554 * bsc#1227560 Cross-References:

* bsc#1227554 * bsc#1227560 * bsc#1227561 * bsc#1227562 * bsc#1227563

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

This update fixes CVE-2024-24791

https://security-tracker.debian.org/tracker/DSA-5730-1

Exploring Linux 6.10: Guide to Key Security Enhancements & Updates for Admins
Securing IT Assets: Practical Strategies for Linux Admins & IT Teams

Several security issues were fixed in the Linux kernel.

* bsc#1220145 * bsc#1223363 * bsc#1223681 * bsc#1223683

How to Secure Your Data Warehouse in a Linux System

Several security issues were fixed in the Linux kernel.

An update that fixes three vulnerabilities is now available.

Several security issues were fixed in the Linux kernel.

* bsc#1215420 * bsc#1220833 * bsc#1221656 * bsc#1221659 * bsc#1222005

* bsc#1221530 Cross-References: * CVE-2024-21503

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828

* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786

Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374

Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:

This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to ¢”superuser¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.

* bsc#1216377 Cross-References: * CVE-2023-45803

* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:

Red Hat VEX files for CVEs are now generally available

Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.

This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732

Backport fix for CVE-2024-4067.

Backport security fixes for CVE-2024-4216, CVE-2024-4068, CVE-2024-4067.

https://security-tracker.debian.org/tracker/DSA-5729-1

* bsc#1226448 Cross-References: * CVE-2024-4032

* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703

Several security issues were fixed in the Linux kernel.

Backport fix for CVE-2024-4032.

Backport fix for CVE-2024-4032.

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5728-1

https://security-tracker.debian.org/tracker/DSA-5727-1

* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828