Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1223356 Cross-References: * CVE-2024-0090 * CVE-2024-0091

* bsc#1219273 Cross-References: * CVE-2023-27534

* bsc#1065729 * bsc#1141539 * bsc#1174585 * bsc#1181674 * bsc#1187716

* bsc#1225365 Cross-References: * CVE-2024-35235

* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235

https://security-tracker.debian.org/tracker/DSA-5709-1

Several security issues were fixed in the Linux kernel.

* bsc#1223375 Cross-References: * CVE-2024-4141

* bsc#1224262 Cross-References: * CVE-2024-26306

* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219854

* bsc#1065729 * bsc#1101816 * bsc#1141539 * bsc#1181674 * bsc#1185902

* bsc#1218501 Cross-References: * CVE-2023-50711

https://security-tracker.debian.org/tracker/DSA-5707-1

https://security-tracker.debian.org/tracker/DSA-5708-1

An update that fixes 16 vulnerabilities is now available.

* bsc#1225417 Cross-References: * CVE-2024-33427

* bsc#1222584 * bsc#1223849 Cross-References: * CVE-2024-4418

* bsc#1221401 * bsc#1222330 * bsc#1222332 Cross-References:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

* bsc#1218424 * bsc#1225973 * bsc#1225974 Cross-References:

* bsc#1212475 * bsc#1225973 * bsc#1225974 Cross-References:

* bsc#1224788 Cross-References: * CVE-2024-35195

Exploring security by design and loosening guides
Easily integrate Secrets Management System with Ansible Automation Platform to update systems passwords

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5706-1

USN-6567-1 introduced a regression in QEMU.

Update to upstream 1.3.2, including fix for CVE-2024-3727

Several security issues were fixed in OpenJDK 21.

Several security issues were fixed in OpenJDK 17.

Several security issues were fixed in OpenJDK 11.

Several security issues were fixed in OpenJDK 8.

* bsc#1225070 Cross-References: * CVE-2024-36039

Fix CVE-2024-36048

This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

Qt 5.15.14 bugfix update. Fix CVE-2024-36048

https://security-tracker.debian.org/tracker/DSA-5704-1

https://security-tracker.debian.org/tracker/DSA-5705-1

* bsc#1217405 Cross-References: * CVE-2023-22084

* bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826

An update that fixes one vulnerability is now available.

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

* bsc#1225417 Cross-References: * CVE-2024-33427

* bsc#1212233 Cross-References: * CVE-2023-3164

* bsc#1224806 Cross-References: * CVE-2024-4453

* bsc#1219823 * bsc#1219826 * bsc#1219851 Cross-References:

* bsc#1221940 * bsc#1223423 * bsc#1223424 * bsc#1223425

fix CVE-2023-36308

CVE-2024-36041

update to 125.0.6422.141 High CVE-2024-5493: Heap buffer overflow in WebRTC High CVE-2024-5494: Use after free in Dawn High CVE-2024-5495: Use after free in Dawn High CVE-2024-5496: Use after free in Media Session

Security fix for CVE-2024-21501

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority

https://security-tracker.debian.org/tracker/DSA-5703-1

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

The updated packages fix security vulnerabilities: Excessive time spent checking DSA keys and parameters. (CVE-2024-4603) Use After Free with SSL_free_buffers. (CVE-2024-4741) References:

It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack.

Several security issues were fixed in GNU C Library.

New Research Reveals Linux Vulnerability Exploitation Has Doubled

An integer overflow in the EXIF metadata parsing was discovered in the GStreamer media framework, which may result in denial of service or potentially the execution of arbitrary code if a malformed file is processed.

https://security-tracker.debian.org/tracker/DSA-5702-1

Practical Ways to Integrate Linux Security Automation With Ansible
How to Send Encrypted or Secure Email on Linux: A Comprehensive Guide

* bsc#1224806 Cross-References: * CVE-2024-4453

Microsoft Reveals Recent Changes & Security Improvements in Windows Subsystem for Linux (WSL)

* bsc#1187446 * bsc#1224410 Cross-References: * CVE-2021-33813

* bsc#1224788 Cross-References: * CVE-2024-35195

* bsc#1224806 Cross-References: * CVE-2024-4453

New version 4.2.5. Includes fixes for CVE-2024-4853, CVE-2024-4854, CVE-2024-4855.

Release 1.6.7 Makefile: Use phpDocumentor v3.4 for the Framework docs (#9313) Fix bug where HTML entities in URLs were not decoded on HTML to plain text conversion (#9312) Fix bug in collapsing/expanding folders with some special characters in names

https://security-tracker.debian.org/tracker/DSA-5701-1

browserify-sign could allow unintended access if it opened a specially crafted file.

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

Update to 115.11.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-23/ https://www.thunderbird.net/en-US/thunderbird/115.11.0/releasenotes/ https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/

Update to requests-2.32.0, fixes CVE-2024-35195.

update to 125.0.6422.112 High CVE-2024-5274: Type Confusion in V8

Update to requests-2.32.0, fixes CVE-2024-35195.

* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775

* bsc#1221465 * bsc#1222155 * bsc#1222277 * bsc#1222731 * jsc#MSQA-775

* bsc#1223858 * bsc#1224169 * bsc#1224340 Affected Products:

Jinja2 could allow cross-site scripting (XSS) attacks.

* bsc#1223110 Cross-References: * CVE-2024-32462

* bsc#1224168 * bsc#1224170 * bsc#1224171 * bsc#1224172 * bsc#1224173

https://security-tracker.debian.org/tracker/DSA-5700-1

Unbound could be made to take part in a denial of service attack.

amavisd-new could be made to bypass security measures.