* bsc#1221530 Cross-References: * CVE-2024-21503
* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828
* bsc#1224122 * bsc#1226136 Cross-References: * CVE-2024-24786
The issue of whether to ban ransomware payments is a hotly debated topic in cybersecurity and policy circles. What are the implications of outlawing these payments, and would the ban be effective?
Vanilla upstream kernel version 6.6.37 fix bugs and vulnerabilities. For information about the vulnerabilities see the links. References: – https://bugs.mageia.org/show_bug.cgi?id=33374
Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. (CVE-2024-37894) References:
This vulnerability allows an attacker performing a meddler-in-the-middle attack between Palo Alto Networks PAN-OS firewall and a RADIUS server to bypass authentication and escalate privileges to ¢”superuser¢” when RADIUS authentication is in use and either CHAP or PAP is selected in the RADIUS server profile.
* bsc#1216377 Cross-References: * CVE-2023-45803
* bsc#1189936 * bsc#1190531 * bsc#935380 Cross-References:
Upstream kernel version 6.6.37 fix bugs and vulnerabilities. The dwarves, kmod-virtualbox and kmod-xtables-addons packages have been updated to work with this new kernel. For information about the vulnerabilities see the links.
This update fixes multiple CVEs and rebases to the latest upstream version: * Tue Jul 09 2024 Julien Rische – 1.21.3-1 – New upstream version (1.21.3) – CVE-2024-26458: Memory leak in src/lib/rpc/pmap_rmt.c Resolves: rhbz#2266732
Backport fix for CVE-2024-4067.
Backport security fixes for CVE-2024-4216, CVE-2024-4068, CVE-2024-4067.
https://security-tracker.debian.org/tracker/DSA-5729-1
As security challenges loom large on the IoT landscape, how can we effectively counter the risks of integrating our physical and digital worlds?
* bsc#1226448 Cross-References: * CVE-2024-4032
* bsc#1226495 * bsc#1227239 Cross-References: * CVE-2024-34703
Several security issues were fixed in the Linux kernel.
Backport fix for CVE-2024-4032.
Backport fix for CVE-2024-4032.
Several security issues were fixed in the Linux kernel.
https://security-tracker.debian.org/tracker/DSA-5728-1
https://security-tracker.debian.org/tracker/DSA-5727-1
* bsc#1223363 * bsc#1223683 Cross-References: * CVE-2024-26828
* bsc#1220145 * bsc#1223363 * bsc#1223683 * bsc#1225211
Updated to latest upstream (128.0)
Fix CVE-2024-39936.
Security fix for CVE-2024-5187
This is the May 2024 release for .NET 8. This is a security update for .NET 8. Release notes: https://github.com/dotnet/core/blob/main/release- notes/8.0/8.0.5/8.0.5.md
* bsc#1224123 Cross-References: * CVE-2024-3727
* bsc#1220145 * bsc#1220832 * bsc#1221302 * bsc#1222685 * bsc#1223059
* bsc#1119113 * bsc#1191958 * bsc#1195065 * bsc#1195254 * bsc#1195775
Several security issues were fixed in Firefox.
Multiple vulnerabilities have been discovered in Buildah, the worst of which could lead to privilege escalation.
Several security issues were fixed in dotnet6, dotnet8.
