Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

The container suse/nginx was updated. The following patches have been included in this update:

Security fix for CVE-2023-48795

https://security-tracker.debian.org/tracker/DSA-5608-1

Several vulnerabilities were discovered in the Slurm Workload Manager, a cluster resource management and job scheduling system, which may result in privilege escalation, denial of service, bypass of message hash checks or opening files with an incorrect set of extended groups.

The container bci/ruby was updated. The following patches have been included in this update:

The container bci/python was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container suse/postgres was updated. The following patches have been included in this update:

The container bci/php was updated. The following patches have been included in this update:

https://security-tracker.debian.org/tracker/DSA-5609-1

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container suse/rmt-server was updated. The following patches have been included in this update:

The container bci/php-apache was updated. The following patches have been included in this update:

The container bci/dotnet-runtime was updated. The following patches have been included in this update:

The container bci/dotnet-sdk was updated. The following patches have been included in this update:

* bsc#1218571 Cross-References: * CVE-2023-7207

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218802 Cross-References: * CVE-2023-51257

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

What’s next on the horizon for telecommunications service providers? A look at 2024 with Red Hat.
Enabling Peer Pods on IBM Z and LinuxONE with Red Hat OpenShift sandboxed containers

Update to 115.7.0 * https://www.mozilla.org/en- US/security/advisories/mfsa2024-04/ * https://www.thunderbird.net/en- US/thunderbird/115.7.0/releasenotes/

https://security-tracker.debian.org/tracker/DSA-5607-1

* bsc#1205463 * bsc#1218189 Cross-References: * CVE-2022-45047

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

* bsc#1218955 Cross-References: * CVE-2024-0741 * CVE-2024-0742

The chromium-browser-stable package has been updated to the 120.0.6099.224 release. 4 vulnerabilities are fixed; some of them are listed below: High CVE-2024-0517: Out of bounds write in V8. Reported by Toan (suto) Pham of Qrious Secure on 2024-01-06.

The updated packages fix security vulnerabilities: A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record. (CVE-2023-38469) A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function. (CVE-2023-38470)

Patch management needs a revolution, part 3: Vulnerability scores and the concept of trust

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

https://security-tracker.debian.org/tracker/DSA-5604-1

https://security-tracker.debian.org/tracker/DSA-5603-1

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

A vulnerability has been discovered in sudo which can lead to execution manipulation through rowhammer-style memory manipulation.

Multiple vulnerabilities have been discovered in GOCR, the worst of which could lead to arbitrary code execution.

Multiple vulnerabilities have been discovered in Ruby, the worst of which could lead to execution of arbitrary code.

Backport fix for CVE-2023-51257.

Mitigate CVE-2024-0690

https://security-tracker.debian.org/tracker/DSA-5605-1

https://security-tracker.debian.org/tracker/DSA-5606-1

Leveraging Red Hat Service Mesh to encrypt AMQ communication on OpenShift
Unlocking the power of generative AI with Cloudera Data Platform and Red Hat OpenShift

The container suse/sle15 was updated. The following patches have been included in this update:

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/rust was updated. The following patches have been included in this update:

The container bci/ruby was updated. The following patches have been included in this update:

The container suse/rmt-mariadb-client was updated. The following patches have been included in this update:

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585 * bsc#1218845

Patch management needs a revolution, part 2: The flood of vulnerabilities

The container suse/rmt-mariadb was updated. The following patches have been included in this update:

The container bci/php-fpm was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk was updated. The following patches have been included in this update:

The container bci/openjdk-devel was updated. The following patches have been included in this update:

https://security-tracker.debian.org/tracker/DSA-5602-1

* bsc#1218728 Cross-References: * CVE-2024-23301

* bsc#1217000 * bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218475 Cross-References: * CVE-2024-22365

* bsc#1218413 Cross-References: * CVE-2023-51714

* bsc#1211188 * bsc#1211190 * bsc#1218126 * bsc#1218186 * bsc#1218209

* bsc#1108281 * bsc#1179610 * bsc#1183045 * bsc#1211162 * bsc#1211226

IPv6 approach for TCP SYN Flood attack over VoIP, Part II
IPv6 approach for TCP SYN Flood attack over VoIP, Part III
Unveiling the Future of Open-Source Generative AI
XOrg Server and Xwayland Patched Against Multiple Security Vulnerabilities

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1211226 * bsc#1215237 * bsc#1215375 * bsc#1217250

* bsc#1218176 * bsc#1218240 * bsc#1218582 * bsc#1218583 * bsc#1218584

* bsc#1179610 * bsc#1205762 * bsc#1210778 * bsc#1212051 * bsc#1212703

* bsc#1108281 * bsc#1109837 * bsc#1179610 * bsc#1202095 * bsc#1211226

* bsc#1218582 * bsc#1218583 * bsc#1218584 * bsc#1218585

Xerces-C++ could be made to crash or run programs if it opened a specially crafted file.

A buffer overread vulnerability has been found in libuv.

An update that fixes one vulnerability is now available.

An update that fixes 17 vulnerabilities is now available.

There were security issues in hplip’s `hpps` program due to fixed /tmp path usage in prnt/hpps/hppsfilter.c This update fixes these issues. References:

Several security issues were fixed in MySQL.

Patch management needs a revolution, part 1: Surveying cybersecurity’s lineage
Supercharging chaos testing using AI
Red Hat Enterprise Linux 9 STIG automation released
High automation coverage for Center for Information Security in Red Hat Enterprise Linux 9

https://security-tracker.debian.org/tracker/DSA-5601-1

https://security-tracker.debian.org/tracker/DSA-5599-1

https://security-tracker.debian.org/tracker/DSA-5600-1

https://security-tracker.debian.org/tracker/DSA-5598-1

https://security-tracker.debian.org/tracker/DSA-5597-1

https://security-tracker.debian.org/tracker/DSA-5596-1

https://security-tracker.debian.org/tracker/DSA-5595-1

https://security-tracker.debian.org/tracker/DSA-5594-1

https://security-tracker.debian.org/tracker/DSA-5593-1

https://security-tracker.debian.org/tracker/DSA-5592-1

https://security-tracker.debian.org/tracker/DSA-5589-1

https://security-tracker.debian.org/tracker/DSA-5590-1

https://security-tracker.debian.org/tracker/DSA-5591-1

https://security-tracker.debian.org/tracker/DSA-5588-1

https://security-tracker.debian.org/tracker/DSA-5587-1