Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

nodejs:22 bug fix and enhancement update

Important: postgresql:15 security update

Important: ruby:3.1 security update

https://security-tracker.debian.org/tracker/DSA-5833-1

Automatically acquire and renew certificates using mod_md and Automated Certificate Management Environment (ACME) in Identity Management (IdM)

EditorConfig could be made to crash or run programs as your login if it received specially crafted input.

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

A buffer overflow was discovered in the vhost code of DPDK, a set of libraries for fast packet processing, which could result in denial of service or the execution of arbitrary code by malicious guests/containers.

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229345

* bsc#1218644 * bsc#1220382 * bsc#1221309 * bsc#1222590 * bsc#1229808

* bsc#1233813 Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3

* bsc#1225462 Cross-References: * CVE-2024-54661

* bsc#1233285 * bsc#1233287 * bsc#1233292 Cross-References:

Mitigating Spectre: The Ongoing Security Challenge with Qualcomm CPUs
Defeating Chinese Telecom Hacking with Open Source
Balancing Security with Transparency in Open-Source AI
Decoding PUMAKIT: A Deep Dive into Multi-Stage Malware and Advanced Evasion Techniques in Linux

Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197

* bsc#1217070 * bsc#1228324 * bsc#1228553 * bsc#1229806 * bsc#1230294

Fix CVE-2024-45337

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.

https://security-tracker.debian.org/tracker/DSA-5832-1

3 key features in Red Hat Advanced Cluster Security for Kubernetes 4.6

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

This release contains a fix for a security issue: CVE-2024-46901 See https://subversion.apache.org/security/CVE-2024-46901-advisory.txt for more information. Changes in this release are: Fix printf-format build warnings in swig-rb (r1921264)

Update to pytest 8.3.4

An update that fixes one vulnerability is now available.

Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened.

Multiple vulnerabilities have been discovered in NVIDIA Drivers, the worst of which could result in privilege escalation.

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

Python 3.10.16 security release. Security content in this release gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to consistently use the mapped IPv4 address value for deciding properties. Properties which have their behavior fixed are is_multicast, is_reserved, is_link_local, is_global, and

https://security-tracker.debian.org/tracker/DSA-5831-1

USN-7157-1 introduced a regression in PHP.

Several security issues were fixed in PHP.

https://security-tracker.debian.org/tracker/DSA-5830-1

Open Source AI: Risks & Mitigation Strategies for Security Admins
Do software security features matter in the world of vulnerability remediation?

Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332

CVE-2024-52805, CVE-2024-52815, CVE-2024-53863 Backport fixes from v1.120.1

Update to 131.0.6778.139 High CVE-2024-12381: Type Confusion in V8 High CVE-2024-12382: Use after free in Translate

Update to 128.5.2 https://www.thunderbird.net/en-US/thunderbird/128.5.2esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-69/

Update to upstream 20241210 Update firmware file for Intel BlazarU core amdgpu: numerous firmware updates upstream amdnpu firmware QCA: Add Bluetooth nvm files for WCN785x

Update to 1.4.8

https://security-tracker.debian.org/tracker/DSA-5828-1

No Command Line, No Problem: Practical Linux Security Tips for New Sysadmins

https://security-tracker.debian.org/tracker/DSA-5829-1

https://security-tracker.debian.org/tracker/DSA-5827-1

The Critical Role of Open-Source Encryption Apps in Combating Chinese Telecom Hacking

https://security-tracker.debian.org/tracker/DSA-5826-1

Configuring SELinux: An In-Depth Guide to Securing Your Linux System

Multiple vulnerabilities have been fixed in the graphics debugger RenderDoc. CVE-2023-33863

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in denial of service, authorization bypass, or information disclosure.

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially among other effects allowing denial of service, information disclosure, use-after-free or remote code inclusion.

Multiple vulnerabilities have been discovered in HashiCorp Consul, the worst of which could result in denial of service.

Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to arbitrary code execution.

Update to 131.0.6778.108 High CVE-2024-12053: Type Confusion in V8

Buffer overflow when calculating the quantile value has been fixed in the GNU Scientific Library (GSL). For Debian 11 bullseye, this problem has been fixed in version

A vulnerability has been discovered in OATH Toolkit, which could lead to local root privilege escalation.

Multiple vulnerabilities have been discovered in Dnsmasq, the worst of which could lead to a denial of service.

Multiple vulnerabilities have been discovered in Salt, the worst of which can lead to arbitrary code execution.

Confidential cluster: Running Red Hat OpenShift clusters on confidential nodes

Multiple vulnerabilities have been discovered in Icinga2, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in OpenJDK, the worst of which could lead to remote code execution.

Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.

* bsc#1233420 Cross-References: * CVE-2024-52616

* bsc#1210619 * bsc#1220145 * bsc#1220537 * bsc#1222685 * bsc#1223059

* bsc#1225429 * bsc#1225733 * bsc#1229273 * bsc#1229553

* bsc#1223683 * bsc#1225099 * bsc#1225429 * bsc#1225733 * bsc#1225739

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1223683 * bsc#1225309 * bsc#1225310 * bsc#1225311 * bsc#1225312

https://security-tracker.debian.org/tracker/DSA-5824-1

https://security-tracker.debian.org/tracker/DSA-5825-1

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1234115 Cross-References: * CVE-2024-53981

* bsc#1225733 * bsc#1229553 Cross-References: * CVE-2024-36904

* bsc#1210619 * bsc#1223363 * bsc#1223683 * bsc#1225013 * bsc#1225202

Improve memory consumption and performance of Canvas getImageData. Fix preserve-3D intersection rendering. Fix video dimensions since GStreamer 1.24.9. Fix the HTTP-based remote Web Inspector not loading in Chromium. Fix content filters not working on about:blank iframes.

Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1232747 * bsc#1233631 * bsc#1233632 Cross-References:

* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168

* bsc#1027519 * bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

* bsc#1227471 * bsc#1227651 * bsc#1228573 * bsc#1229553

https://security-tracker.debian.org/tracker/DSA-5815-2

https://security-tracker.debian.org/tracker/DSA-5823-1

* bsc#1233773 Cross-References: * CVE-2024-10524

* bsc#1233651 * bsc#1233702 * bsc#1233703 Cross-References:

* bsc#1233650 * bsc#1233695 Cross-References: * CVE-2024-11691

* bsc#1227378 * bsc#1231795 * bsc#1233307 Cross-References:

* bsc#1233815 Cross-References: * CVE-2024-53849

* bsc#1231795 * bsc#1232750 * bsc#1233307 Cross-References: