Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in OpenSSH.. ========================================================================== Ubuntu Security Notice USN-6565-1 January 03, 2024 openssh vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in OpenSSH. Software Description: - openssh: secure shell (SSH) for secure access to remote machines Details: It was discovered that OpenSSH incorrectly handled supplemental groups when running helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand as a different user. An attacker could possibly use this issue to escalate privileges. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-41617) It was discovered that OpenSSH incorrectly added destination constraints when PKCS#11 token keys were added to ssh-agent, contrary to expectations. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2023-51384) It was discovered that OpenSSH incorrectly handled user names or host names with shell metacharacters. An attacker could possibly use this issue to perform OS command injection. (CVE-2023-51385) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: openssh-client 1:9.3p1-1ubuntu3.2 openssh-server 1:9.3p1-1ubuntu3.2 Ubuntu 23.04: openssh-client 1:9.0p1-1ubuntu8.7 openssh-server 1:9.0p1-1ubuntu8.7 Ubuntu 22.04 LTS: openssh-client 1:8.9p1-3ubuntu0.6 openssh-server 1:8.9p1-3ubuntu0.6 Ubuntu 20.04 LTS: openssh-client 1:8.2p1-4ubuntu0.11 openssh-server 1:8.2p1-4ubuntu0.11 In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-6565-1 CVE-2021-41617, CVE-2023-51384, CVE-2023-51385 Package Information: https://launchpad.net/ubuntu/+source/openssh/1:9.3p1-1ubuntu3.2 https://launchpad.net/ubuntu/+source/openssh/1:8.2p1-4ubuntu0.11 . Fedora stable releases have patched various OpenSSH security flaws, enhancing protected access from afar. Upgrade promptly for protection.. OpenSSH Update, Remote Access Issues, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team
An update for flatpak is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: flatpak security update Advisory ID: RHSA-2021:1068-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1068 Issue date: 2021-04-06 CVE Names: CVE-2021-21381 ==================================================================== 1. Summary: An update for flatpak is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Security Fix(es): * flatpak: "file forwarding" feature can be used to gain unprivileged access to files (CVE-2021-21381) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1936985 - CVE-2021-21381 flatpak: "file forwarding" feature can be used to gain unprivileged access to files 6. Package List: RedHat Enterprise Linux AppStream (v. 8): Source: flatpak-1.6.2-6.el8_3.src.rpm aarch64: flatpak-1.6.2-6.el8_3.aarch64.rpm flatpak-debuginfo-1.6.2-6.el8_3.aarch64.rpm flatpak-debugsource-1.6.2-6.el8_3.aarch64.rpm flatpak-libs-1.6.2-6.el8_3.aarch64.rpm flatpak-libs-debuginfo-1.6.2-6.el8_3.aarch64.rpm flatpak-session-helper-1.6.2-6.el8_3.aarch64.rpm flatpak-session-helper-debuginfo-1.6.2-6.el8_3.aarch64.rpm flatpak-tests-debuginfo-1.6.2-6.el8_3.aarch64.rpm noarch: flatpak-selinux-1.6.2-6.el8_3.noarch.rpm ppc64le: flatpak-1.6.2-6.el8_3.ppc64le.rpm flatpak-debuginfo-1.6.2-6.el8_3.ppc64le.rpm flatpak-debugsource-1.6.2-6.el8_3.ppc64le.rpm flatpak-libs-1.6.2-6.el8_3.ppc64le.rpm flatpak-libs-debuginfo-1.6.2-6.el8_3.ppc64le.rpm flatpak-session-helper-1.6.2-6.el8_3.ppc64le.rpm flatpak-session-helper-debuginfo-1.6.2-6.el8_3.ppc64le.rpm flatpak-tests-debuginfo-1.6.2-6.el8_3.ppc64le.rpm s390x: flatpak-1.6.2-6.el8_3.s390x.rpm flatpak-debuginfo-1.6.2-6.el8_3.s390x.rpm flatpak-debugsource-1.6.2-6.el8_3.s390x.rpm flatpak-libs-1.6.2-6.el8_3.s390x.rpm flatpak-libs-debuginfo-1.6.2-6.el8_3.s390x.rpm flatpak-session-helper-1.6.2-6.el8_3.s390x.rpm flatpak-session-helper-debuginfo-1.6.2-6.el8_3.s390x.rpm flatpak-tests-debuginfo-1.6.2-6.el8_3.s390x.rpm x86_64: flatpak-1.6.2-6.el8_3.x86_64.rpm flatpak-debuginfo-1.6.2-6.el8_3.i686.rpm flatpak-debuginfo-1.6.2-6.el8_3.x86_64.rpm flatpak-debugsource-1.6.2-6.el8_3.i686.rpm flatpak-debugsource-1.6.2-6.el8_3.x86_64.rpm flatpak-libs-1.6.2-6.el8_3.i686.rpm flatpak-libs-1.6.2-6.el8_3.x86_64.rpm flatpak-libs-debuginfo-1.6.2-6.el8_3.i686.rpm flatpak-libs-debuginfo-1.6.2-6.el8_3.x86_64.rpm flatpak-session-helper-1.6.2-6.el8_3.x86_64.rpm flatpak-session-helper-debuginfo-1.6.2-6.el8_3.i686.rpm flatpak-session-helper-debuginfo-1.6.2-6.el8_3.x86_64.rpm flatpak-tests-debuginfo-1.6.2-6.el8_3.i686.rpm flatpak-tests-debuginfo-1.6.2-6.el8_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-21381 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYGwadtzjgjWX9erEAQiNEBAAkVBAYVHz5y9EbP9AAXxHPyy6hPQNaed3 FsmtLFlFJR7ZSBQMqBd0mNd9wGsKbggivr2FRscjiK6hrgJN6CXCpUNbby/an1K7 cOjbZAAOZw70hwqjcky0CnZ3b0IwRs83GOSfLBnmNjWWXzO9nlYLzC7YB4VWqLXI YppFrwF0XfrslAgkNHPICkYO40oyz7vigvdNgmlTp2YOo8IYIXsOL+e6WM38NngA aadUeVefcsajpWubIgh7D1smR4vyeUhm8I9f+bXIu6DGrcz3QWdlf5IkHB3u7xt1 xLXjf0Y/Wk1NKfm31NqOZvf36xo0imCkjkP/vyvTVIOSxQBqL9FQH/34RQJIWDdH d+B/GDX1tWbpV1TlbhqH6a+kOrHWK4wmhDzTfdwGS+wt6PC9vL4MDD91Op3jqSY5 atPOmdLQ9NlFiz3rbG+UjBvnqUC18K4a3KXS37EzZJzSXH7SwDpF7M9pmZkHE8Xc dAgUqhYh2OH470aIMrD4uxvzAJilGrZEDIuGIxkcWx9J9JIzKvh8LTNCJNpUxhvh eDfinblTS1BwfCAEl5oov+KKXP/iD8Nq3BwMlath8pSjTaA8lCiwiVAAz5UAauWw kYtlT1Uy1fnF2HXjARTjaMYguwlY/93A93iBFsbuSZyqTRaPYlxjVQ9c3ozYWL3B 6UypsuwD7RU=pV4r -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: runc security and bug fix update Advisory ID: RHSA-2017:0127-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2017:0127.html Issue date: 2017-01-17 CVE Names: CVE-2016-9962 ==================================================================== 1. Summary: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - x86_64 3. Description: The runC tool is a lightweight, portable implementation of the Open Container Format (OCF) that provides container runtime. Security Fix(es): * The runc component used by `docker exec` feature of docker allowed additional container processes via to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain low-level access to these new processes during initialization. An attacker can, depending on the nature of the incoming process, leverage this to elevate access to the host. This ranges from accessing host content through the file descriptors of the incoming process to, potentially, a complete container escape by leveraging memory access or syscall interception. (CVE-2016-9962) Red Hat would liketo thank the Docker project for reporting this issue. Upstream acknowledges Aleksa Sarai (SUSE) and Tonis Tiigi (Docker) as the original reporters. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1409531 - CVE-2016-9962 docker: insecure opening of file-descriptor allows privilege escalation 6. Package List: Red Hat Enterprise Linux 7 Extras: Source: runc-1.0.0-1.rc2.el7.src.rpm x86_64: runc-1.0.0-1.rc2.el7.x86_64.rpm Red Hat Enterprise Linux 7 Extras: Source: runc-1.0.0-1.rc2.el7.src.rpm x86_64: runc-1.0.0-1.rc2.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-9962 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYfyLBXlSAg2UNWIIRAmorAJ4yKTxWYeAieLAWdRZ7EaIAEFyCigCgiplm ySKB7xuuqECCEuGgNAnnn2E=MNoW -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
Get the latest Linux and open source security news straight to your inbox.