Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

* bsc#1223687 * bsc#1223689 Cross-References: * CVE-2024-29038

Fraudulent security certificates could allow access controls to be bypassed.

Getting started with Red Hat Insights and FedRAMP

This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable.

* bsc#1094832 * bsc#1200551 Cross-References: * CVE-2018-11490

* bsc#1218862 * bsc#1218865 Cross-References: * CVE-2024-0553

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

An update that fixes four vulnerabilities is now available.

An update that fixes 35 vulnerabilities is now available.

It was discovered that missing input sanitising in the Atril document viewer could result in writing arbitrary files in the users home directory if a malformed epub document is opened.

Multiple vulnerabilities have been discovered in PoDoFo, the worst of which could lead to code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Kubelet, which can lead to privilege escalation.

A vulnerability has been discovered in Rebar3, which can lead to command injection.

update to 124.0.6367.201 * High CVE-2024-4671: Use after free in Visuals

https://security-tracker.debian.org/tracker/DSA-5688-1

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

Security fix for CVE-2023-45681 / CVE-2023-47212

Security fix for CVE-2023-45681 / CVE-2023-47212

update to 124.0.6367.155 High CVE-2024-4558: Use after free in ANGLE High CVE-2024-4559: Heap buffer overflow in WebAudio

Fix for CVE-2024-2397

https://www.mediawiki.org/wiki/Release_notes/1.41

* bsc#1222849 Cross-References: * CVE-2024-32487

* bsc#1216644 * bsc#1219079 * bsc#1219435 * bsc#1220828

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

* bsc#1212475 * bsc#1224017 Cross-References: * CVE-2024-24787

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1223979 Cross-References: * CVE-2024-34069

https://security-tracker.debian.org/tracker/DSA-5687-1

RHEL 9.4 Unveiled: Elevating Enterprise Security with Cutting-Edge Features

https://security-tracker.debian.org/tracker/DSA-5685-1

* bsc#1223100 Cross-References: * CVE-2023-3758

* bsc#1223852 Cross-References: * CVE-2023-52722

* bsc#1216853 Cross-References: * CVE-2023-38472

* bsc#1222492 Cross-References: * CVE-2024-21506

* bsc#1223979 Cross-References: * CVE-2024-34069

* bsc#1218424 * bsc#1224017 * bsc#1224018 Cross-References:

Unleashing the potential of Intel® IPU with Red Hat OpenShift

https://security-tracker.debian.org/tracker/DSA-5682-2

https://security-tracker.debian.org/tracker/DSA-5686-1

https://security-tracker.debian.org/tracker/DSA-5684-1

https://security-tracker.debian.org/tracker/DSA-5682-1

* bsc#1189495 * bsc#1211301 * bsc#1219559 * bsc#1219666 * bsc#1221260

* bsc#1189495 * bsc#1191175 * bsc#1218686 Cross-References:

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in root privilege escalation.

A vulnerability has been discovered in Epiphany, which can lead to a buffer overflow.

Multiple vulnerabilities have been discovered in qtsvg, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in MariaDB, the worst fo which can lead to arbitrary execution of code.

https://security-tracker.debian.org/tracker/DSA-5683-1

Fortifying Email Security with Infosec Through the SDLC

* bsc#1223252 Cross-References: * CVE-2024-30171

* bsc#1221984 * bsc#1222302 * bsc#1222453 Cross-References:

* bsc#1027519 * bsc#1221984 * bsc#1222302 * bsc#1222453

* bsc#1216644 * bsc#1219079 * bsc#1219435 Cross-References:

Multiple vulnerabilities have been discovered in libjpeg-turbo, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Xpdf, the worst of which could possibly lead to arbitrary code execution.

* bsc#1215947 * bsc#1216853 Cross-References: * CVE-2023-38470

* bsc#1170848 * bsc#1208572 * bsc#1214340 * bsc#1214387 * bsc#1216085

* bsc#1219912 * bsc#1221465 * bsc#1222155 * jsc#MSQA-760 * jsc#PED-7893

* bsc#1008037 * bsc#1008038 * bsc#1010940 * bsc#1019021 * bsc#1038785

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

* bsc#1211649 * bsc#1211888 * bsc#1216850 * bsc#1218482 * bsc#1219001

https://security-tracker.debian.org/tracker/DSA-5680-1

https://security-tracker.debian.org/tracker/DSA-5681-1

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to remote code execution.

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to remote code execution.

A vulnerability has been discovered in borgmatic, which can lead to shell injection.

Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in MIT krb5, the worst of which could lead to remote code execution.

A vulnerability has been discovered in Setuptools, which can lead to denial of service.

https://security-tracker.debian.org/tracker/DSA-5679-1

https://security-tracker.debian.org/tracker/DSA-5678-1

https://security-tracker.debian.org/tracker/DSA-5677-1

Multiple vulnerabilities have been found in MediaInfo and MediaInfoLib, the worst of which could allow user-assisted remote code execution.

Multiple vulnerabilities have been discovered in strongSwan, the worst of which could possibly lead to remote code execution.

Multiple vulnerabilities have been discovered in HTMLDOC, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in mujs, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in MPlayer, the worst of which can lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in systemd, the worst of which can lead to a denial of service.

Beyond the lingo: What does Red Hat Insights and FedRAMP mean for your workload?
Simplify hybrid cloud operations with Red Hat Enterprise Linux 9.4
Mitigating breaches on Red Hat OpenShift with the CrowdStrike Falcon Operator
Understanding Red Hat’s response to the XZ security incident

* bsc#1177529 * bsc#1192145 * bsc#1194869 * bsc#1200465 * bsc#1205316

update to 124.0.6367.118 * High CVE-2024-4331: Use after free in Picture In Picture * High CVE-2024-4368: Use after free in Dawn update to 124.0.6367.91 update to 124.0.6367.78

The 6.8.8 stable kernel update contains a number of important fixes across the tree.

Patch to fix CVE-2024-31031

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Update matrix-synapse to v1.105.1 (CVE-2024-31208) Update to v1.105.0

Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.

USN-6747-1 caused some minor regressions in Firefox.

Update to 6.2.8, fixing CVE-2022-48257 and CVE-2022-48258 Unbundle cpp-httlib, fixing CVE-2023-26130

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

tpm2-tss: Fixed CVE-2024-29040 tpm2-tools: Fixed CVE-2024-29038 Fixed CVE-2024-29039

Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4

https://security-tracker.debian.org/tracker/DSA-5676-1

Gerbv could be made to crash if it opened a specially crafted input file.

Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application

A bug that could allow an attacker with access to the machine to potentially access data in a temporary directory created by the Guava. (CVE-2020-8908) Predictable temporary files and directories used in FileBackedOutputStream. (CVE-2023-2976)

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. (CVE-2024-26458) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. (CVE-2024-26461)