The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-3844 http://linux.oracle.com/errata/ELSA-2025-3844.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: java-1.8.0-openjdk-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm java-1.8.0-openjdk-javadoc-1.8.0.442.b06-1.0.3.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.442.b06-1.0.3.el7_9.noarch.rpm java-1.8.0-openjdk-src-1.8.0.442.b06-1.0.3.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.442.b06-1.0.3.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//java-1.8.0-openjdk-1.8.0.442.b06-1.0.3.el7_9.src.rpm Related CVEs: CVE-2025-21587 CVE-2025-30691 CVE-2025-30698 Description of changes: [1:1.8.0.442.b06-1.0.3] - Fixed CVE-2025-21587, CVE-2025-30691 and CVE-2025-30698 [Orabug: 37840723] _______________________________________________ El-errata mailing list
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for systemd-presets-common-SUSE ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2866-1 Rating: moderate References: #1199524 #1200485 Cross-References: CVE-2022-1706 CVSS scores: CVE-2022-1706 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2022-1706 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Micro 5.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for systemd-presets-common-SUSE fixes the following issues: - CVE-2022-1706: Fixed accessible configs from unprivileged containers in VMs running on VMware products (bsc#1199524). The following non-security bugs were fixed: - Modify branding-preset-states to fix systemd-presets-common-SUSE not enabling new user systemd service preset configuration just as it handles system service presets. By passing an (optional) second parameter "user", the save/apply-changes commands now work with user services instead of system ones (bsc#1200485) - Add the wireplumber user service preset to enable it by default in SLE15-SP4 where it replaced pipewire-media-session, but keep pipewire-media-session preset so we don't have to branch the systemd-presets-common-SUSE package for SP4 (bsc#1200485) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2866=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2866=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-2866=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-2866=1 - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2022-2866=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patch SUSE-SUSE-MicroOS-5.1-2022-2866=1 Package List: - openSUSE Leap 15.4 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 - openSUSE Leap 15.3 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 - SUSE Linux Enterprise Micro 5.2 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 - SUSE Linux Enterprise Micro 5.1 (noarch): systemd-presets-common-SUSE-15-150100.8.17.1 References: https://www.suse.com/security/cve/CVE-2022-1706.html https://bugzilla.suse.com/1199524 https://bugzilla.suse.com/1200485 . SUSE Security Update: Resolutions for systemd-presets-common-SUSE addressing accessibility problems within virtual machines and configuration mistakes.. Linux Enterprise, security update, SUSE systemd, accessibility issues. . LinuxSecurity.com Team
Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f0d84ce004 2022-02-19 01:30:44.345793 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.34.6 Release : 1.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620 --------------------------------------------------------------------------------ChangeLog: * Thu Feb 17 2022 Michael Catanzaro 2.34.6-1 - Update to 2.34.6 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-f0d84ce004' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
This update upgrades Firefox to version 78.12.0 ESR. * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2021:2741-1 Issue Date: 2021-07-15 CVE Numbers: CVE-2021-30547 CVE-2021-29970 CVE-2021-29976 -- This update upgrades Firefox to version 78.12.0 ESR. Security Fix(es): * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 - firefox-78.12.0-1.el7_9.x86_64.rpm - firefox-debuginfo-78.12.0-1.el7_9.x86_64.rpm - firefox-78.12.0-1.el7_9.i686.rpm -- - Scientific Linux Development Team . Keep abreast of the significant Firefox enhancement tackling memory security and accessibility challenges within Scientific Linux 7.x.. firefox update, mozilla security, scientific linux, memory safety, accessibility fix. . Severity: Important. LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2018:1278. CentOS Errata and Security Advisory 2018:1278 Important Upstream details at : https://access.redhat.com/errata/RHSA-2018:1278 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 39d2b1d4651107d98c52c6f7a19c7d6924084321629bd3f50176e9af1bb5b2eb java-1.7.0-openjdk-1.7.0.181-2.6.14.5.el7.x86_64.rpm 50a949ab891b3acc0f34a68a565c4b5ca6c16da302d4193e7b91a83f5708bd9d java-1.7.0-openjdk-accessibility-1.7.0.181-2.6.14.5.el7.x86_64.rpm 727e9b624fad951fddef30bd0a5452d9fcc2d4f965153b61ebdd355ea4a35e56 java-1.7.0-openjdk-demo-1.7.0.181-2.6.14.5.el7.x86_64.rpm ba6c03472caf4c1c1e39511b03bcc1ff42d1a52cd4cca9cd35cbb6f0fabafdbe java-1.7.0-openjdk-devel-1.7.0.181-2.6.14.5.el7.x86_64.rpm 1922de489ba1a45ba8c6e6c07c8d38e13305b55a2520ac99661fd993bc34ffd5 java-1.7.0-openjdk-headless-1.7.0.181-2.6.14.5.el7.x86_64.rpm b454c44170036a8ebfef576e34b06d01dc803af7b99876006939638b7eeb685e java-1.7.0-openjdk-javadoc-1.7.0.181-2.6.14.5.el7.noarch.rpm 7213b1fd521d8dbe516f9b8ab7b4815d99fb68130145eb7af2e96cb87fe6a024 java-1.7.0-openjdk-src-1.7.0.181-2.6.14.5.el7.x86_64.rpm Source: 4830d84849592f034fd2835eb75cbcaeee225e9bebdec950b4d8fef65ad73b50 java-1.7.0-openjdk-1.7.0.181-2.6.14.5.el7.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Get the latest Linux and open source security news straight to your inbox.