Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
197

Debian 12 Linux Base Update Brings Important Security Fix DLA-4628-1

. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4628-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Ben Hutchings June 12, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : linux-base Version : 4.12.1~deb12u1 The linux-base package has been updated to support installation of a backport of Linux 6.12. For Debian 12 bookworm, the new version is 4.12.1~deb12u1. For the detailed security status of linux-base please refer to its security tracker page at: https://security-tracker.debian.org/tracker/linux-base Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update your linux-base package to support installation of Linux 6.12 on Debian 12. Important security advisory details included.. Debian Security Advisory, Linux Base Update, Linux Security, Linux Administration. . Severity: Informational. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 Informational Debian LTS
172

Ubuntu 26.04 LTS haveged Critical Exec Privilege Escalation USN-8358-1

haveged could be made to run programs as an administrator.. ========================================================================== Ubuntu Security Notice USN-8358-1 June 01, 2026 haveged vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: haveged could be made to run programs as an administrator. Software Description: - haveged: userspace entropy daemon Details: It was discovered that haveged incorrectly handled credential checks on its control socket. A local attacker could possibly use this issue to execute privileged commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS haveged 1.9.19-14ubuntu0.1 libhavege2 1.9.19-14ubuntu0.1 Ubuntu 25.10 haveged 1.9.19-12+deb13u1build0.25.10.1 libhavege2 1.9.19-12+deb13u1build0.25.10.1 Ubuntu 24.04 LTS haveged 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu2+esm1~24.04.1 Available with Ubuntu Pro Ubuntu 22.04 LTS haveged 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro libhavege2 1.9.14-1ubuntu1+esm1~22.04.1 Available with Ubuntu Pro After a standard system update you need to restart haveged to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8358-1 CVE-2026-41054 Package Information: https://launchpad.net/ubuntu/+source/haveged/1.9.19-14ubuntu0.1 https://launchpad.net/ubuntu/+source/haveged/1.9.19-12+deb13u1build0.25.10.1 . A critical security issue in haveged for Ubuntuallows local attackers to run commands as administrators.. Ubuntu Security Notice, haveged vulnerability, privilege escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 01, 2026 Critical Ubuntu
100

SUSE Linux Micro 6.0 Kernel RT Important Fix Advisory 20470-1

An update that solves four vulnerabilities and has two fixes can now be installed.. # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20470-1 Release Date: 2026-02-19T09:19:11Z Rating: important References: * bsc#1249205 * bsc#1249241 * bsc#1249480 * bsc#1253439 * bsc#1253473 * bsc#1256928 Cross-References: * CVE-2025-38352 * CVE-2025-39742 * CVE-2025-40129 * CVE-2025-40186 CVSS scores: * CVE-2025-38352 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38352 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38352 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39742 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-39742 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39742 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40129 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40129 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40186 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40186 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has two fixes can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-38352: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (bsc#1249205). * CVE-2025-39742: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (bsc#1249480). * CVE-2025-40129: sunrpc: fix null pointer dereference on zero-length checksum (bsc#1253473). * CVE-2025-40186: tcp: Don't callreqsk_fastopen_remove() in tcp_conn_request() (bsc#1253439). The following non security issue was fixed: * bsc#1249241: fix addr_bit_set() issue on big-endian machines BITOP_BE32_SWIZZLE ought to be defined depending on the target's endianess, but the livepatch includes only the little-endian variant. Fix that. (bsc#1249241 bsc#1256928). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-267=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-10-1.1 * kernel-livepatch-6_4_0-34-rt-10-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38352.html * https://www.suse.com/security/cve/CVE-2025-39742.html * https://www.suse.com/security/cve/CVE-2025-40129.html * https://www.suse.com/security/cve/CVE-2025-40186.html * https://bugzilla.suse.com/show_bug.cgi?id=1249205 * https://bugzilla.suse.com/show_bug.cgi?id=1249241 * https://bugzilla.suse.com/show_bug.cgi?id=1249480 * https://bugzilla.suse.com/show_bug.cgi?id=1253439 * https://bugzilla.suse.com/show_bug.cgi?id=1253473 * https://bugzilla.suse.com/show_bug.cgi?id=1256928 . SUSE Linux Micro 6.0 patch resolves important vulnerabilities in kernel RT, enhancing system security and stability.. kernel update, SUSE Linux security, vulnerability patching. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 26, 2026 Important SuSE
172

Ubuntu 14.04 LTS Linux Kernel Security Notice USN-7986-1

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7986-1 January 29, 2026 linux vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Ceph distributed file system; - JFFS2 file system; - Timer subsystem; - USB sound devices; (CVE-2024-26689, CVE-2024-53197, CVE-2024-57850, CVE-2025-38352) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS linux-image-3.13.0-210-generic 3.13.0-210.261 Available with Ubuntu Pro linux-image-3.13.0-210-lowlatency 3.13.0-210.261 Available with Ubuntu Pro linux-image-generic 3.13.0.210.220 Available with Ubuntu Pro linux-image-generic-lts-trusty 3.13.0.210.220 Available with Ubuntu Pro linux-image-lowlatency 3.13.0.210.220 Available with Ubuntu Pro linux-image-server 3.13.0.210.220 Available with Ubuntu Pro linux-image-virtual 3.13.0.210.220 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you mighthave installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7986-1 CVE-2024-26689, CVE-2024-53197, CVE-2024-57850, CVE-2025-38352 . Fixes for critical Linux kernel issues affecting Ubuntu 14.04 LTS. Ensure your systems are secure and updated.. Linux kernel updates, Ubuntu security fix, Linux administration. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2026 Important Ubuntu
100

SUSE: 2025:01752-1 important: slurm_23_02 permission issue

* bsc#1243666 Cross-References: * CVE-2025-43904 . # Security update for slurm_23_02 Announcement ID: SUSE-SU-2025:01752-1 Release Date: 2025-05-29T12:54:31Z Rating: important References: * bsc#1243666 Cross-References: * CVE-2025-43904 CVSS scores: * CVE-2025-43904 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-43904 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for slurm_23_02 fixes the following issues: * CVE-2025-43904: an issue with permission handling for Coordinators within the accounting system allowed Coordinators to promote a user to Administrator (bsc#1243666). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2025-1752=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * perl-slurm_23_02-23.02.7-3.19.1 * slurm_23_02-sview-23.02.7-3.19.1 * slurm_23_02-cray-debuginfo-23.02.7-3.19.1 * slurm_23_02-pam_slurm-23.02.7-3.19.1 * slurm_23_02-auth-none-debuginfo-23.02.7-3.19.1 *slurm_23_02-debugsource-23.02.7-3.19.1 * slurm_23_02-devel-23.02.7-3.19.1 * slurm_23_02-debuginfo-23.02.7-3.19.1 * slurm_23_02-sql-23.02.7-3.19.1 * libslurm39-debuginfo-23.02.7-3.19.1 * slurm_23_02-plugins-debuginfo-23.02.7-3.19.1 * slurm_23_02-torque-23.02.7-3.19.1 * slurm_23_02-sql-debuginfo-23.02.7-3.19.1 * libnss_slurm2_23_02-23.02.7-3.19.1 * slurm_23_02-munge-debuginfo-23.02.7-3.19.1 * slurm_23_02-node-23.02.7-3.19.1 * libpmi0_23_02-debuginfo-23.02.7-3.19.1 * slurm_23_02-plugin-ext-sensors-rrd-23.02.7-3.19.1 * slurm_23_02-slurmdbd-debuginfo-23.02.7-3.19.1 * slurm_23_02-plugins-23.02.7-3.19.1 * slurm_23_02-auth-none-23.02.7-3.19.1 * libnss_slurm2_23_02-debuginfo-23.02.7-3.19.1 * slurm_23_02-pam_slurm-debuginfo-23.02.7-3.19.1 * libslurm39-23.02.7-3.19.1 * libpmi0_23_02-23.02.7-3.19.1 * slurm_23_02-node-debuginfo-23.02.7-3.19.1 * slurm_23_02-torque-debuginfo-23.02.7-3.19.1 * perl-slurm_23_02-debuginfo-23.02.7-3.19.1 * slurm_23_02-lua-23.02.7-3.19.1 * slurm_23_02-23.02.7-3.19.1 * slurm_23_02-lua-debuginfo-23.02.7-3.19.1 * slurm_23_02-cray-23.02.7-3.19.1 * slurm_23_02-slurmdbd-23.02.7-3.19.1 * slurm_23_02-plugin-ext-sensors-rrd-debuginfo-23.02.7-3.19.1 * slurm_23_02-munge-23.02.7-3.19.1 * slurm_23_02-sview-debuginfo-23.02.7-3.19.1 * HPC Module 12 (noarch) * slurm_23_02-doc-23.02.7-3.19.1 * slurm_23_02-webdoc-23.02.7-3.19.1 * slurm_23_02-config-man-23.02.7-3.19.1 * slurm_23_02-config-23.02.7-3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43904.html * https://bugzilla.suse.com/show_bug.cgi?id=1243666 . The latest update addresses a crucial permission management flaw in SLURM 23.02 impacting various SUSE OS releases.. SUSE Linux, SLURM, HPC security, permission issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2025 Important SuSE
100

SUSE: 2025:01759-1 important: slurm permission issue patch

* bsc#1243666 Cross-References: * CVE-2025-43904 . # Security update for slurm Announcement ID: SUSE-SU-2025:01759-1 Release Date: 2025-05-29T14:54:09Z Rating: important References: * bsc#1243666 Cross-References: * CVE-2025-43904 CVSS scores: * CVE-2025-43904 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-43904 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * HPC Module 15-SP6 * HPC Module 15-SP7 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability can now be installed. ## Description: This update for slurm fixes the following issues: * CVE-2025-43904: an issue with permission handling for Coordinators within the accounting system allowed Coordinators to promote a user to Administrator (bsc#1243666). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-1759=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1759=1 * HPC Module 15-SP6 zypper in -t patch SUSE-SLE-Module-HPC-15-SP6-2025-1759=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2025-1759=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1759=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1759=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1759=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * libslurm39-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-hdf5-debuginfo-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-debuginfo-23.02.7-150500.5.18.1 * slurm-cray-debuginfo-23.02.7-150500.5.18.1 * slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 * slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 * slurm-sql-debuginfo-23.02.7-150500.5.18.1 * libslurm39-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-hdf5-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 *slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * slurm-testsuite-23.02.7-150500.5.18.1 * openSUSE Leap 15.5 (noarch) * slurm-doc-23.02.7-150500.5.18.1 * slurm-seff-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-openlava-23.02.7-150500.5.18.1 * slurm-config-man-23.02.7-150500.5.18.1 * slurm-sjstat-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * libslurm39-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-hdf5-debuginfo-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-debuginfo-23.02.7-150500.5.18.1 * slurm-cray-debuginfo-23.02.7-150500.5.18.1 * slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 * slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 *slurm-sql-debuginfo-23.02.7-150500.5.18.1 * libslurm39-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-hdf5-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * slurm-testsuite-23.02.7-150500.5.18.1 * openSUSE Leap 15.6 (noarch) * slurm-doc-23.02.7-150500.5.18.1 * slurm-seff-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-openlava-23.02.7-150500.5.18.1 * slurm-config-man-23.02.7-150500.5.18.1 * slurm-sjstat-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 * HPC Module 15-SP6 (aarch64 x86_64) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * libslurm39-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-debuginfo-23.02.7-150500.5.18.1 * slurm-cray-debuginfo-23.02.7-150500.5.18.1 * slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 *slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 * slurm-sql-debuginfo-23.02.7-150500.5.18.1 * libslurm39-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * HPC Module 15-SP6 (noarch) * slurm-config-man-23.02.7-150500.5.18.1 * slurm-doc-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 * HPC Module 15-SP7 (aarch64 x86_64) * slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * SUSE Package Hub 15 15-SP6 (ppc64le s390x) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-hdf5-debuginfo-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-debuginfo-23.02.7-150500.5.18.1 * slurm-cray-debuginfo-23.02.7-150500.5.18.1 *slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 * slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 * slurm-sql-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * slurm-hdf5-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 * SUSE Package Hub 15 15-SP6 (noarch) * slurm-doc-23.02.7-150500.5.18.1 * slurm-seff-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-openlava-23.02.7-150500.5.18.1 * slurm-config-man-23.02.7-150500.5.18.1 * slurm-sjstat-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * libslurm39-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-debuginfo-23.02.7-150500.5.18.1 *slurm-cray-debuginfo-23.02.7-150500.5.18.1 * slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 * slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 * slurm-sql-debuginfo-23.02.7-150500.5.18.1 * libslurm39-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * slurm-config-man-23.02.7-150500.5.18.1 * slurm-doc-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-slurm-23.02.7-150500.5.18.1 * slurm-auth-none-debuginfo-23.02.7-150500.5.18.1 * slurm-debugsource-23.02.7-150500.5.18.1 * slurm-plugins-23.02.7-150500.5.18.1 * slurm-slurmdbd-debuginfo-23.02.7-150500.5.18.1 * libslurm39-23.02.7-150500.5.18.1 * slurm-munge-23.02.7-150500.5.18.1 * slurm-23.02.7-150500.5.18.1 * libnss_slurm2-23.02.7-150500.5.18.1 * slurm-devel-23.02.7-150500.5.18.1 * slurm-pam_slurm-debuginfo-23.02.7-150500.5.18.1 * libpmi0-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-23.02.7-150500.5.18.1 * libpmi0-debuginfo-23.02.7-150500.5.18.1 * perl-slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-rest-debuginfo-23.02.7-150500.5.18.1 * slurm-auth-none-23.02.7-150500.5.18.1 * slurm-munge-debuginfo-23.02.7-150500.5.18.1 * slurm-lua-23.02.7-150500.5.18.1 * slurm-sql-23.02.7-150500.5.18.1 * slurm-torque-23.02.7-150500.5.18.1 * slurm-cray-23.02.7-150500.5.18.1 * slurm-rest-23.02.7-150500.5.18.1 * slurm-slurmdbd-23.02.7-150500.5.18.1 * slurm-plugins-debuginfo-23.02.7-150500.5.18.1 *slurm-sview-debuginfo-23.02.7-150500.5.18.1 * slurm-cray-debuginfo-23.02.7-150500.5.18.1 * slurm-pam_slurm-23.02.7-150500.5.18.1 * slurm-lua-debuginfo-23.02.7-150500.5.18.1 * slurm-torque-debuginfo-23.02.7-150500.5.18.1 * slurm-node-debuginfo-23.02.7-150500.5.18.1 * slurm-sview-23.02.7-150500.5.18.1 * slurm-sql-debuginfo-23.02.7-150500.5.18.1 * libslurm39-debuginfo-23.02.7-150500.5.18.1 * slurm-debuginfo-23.02.7-150500.5.18.1 * slurm-node-23.02.7-150500.5.18.1 * libnss_slurm2-debuginfo-23.02.7-150500.5.18.1 * slurm-plugin-ext-sensors-rrd-debuginfo-23.02.7-150500.5.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * slurm-config-man-23.02.7-150500.5.18.1 * slurm-doc-23.02.7-150500.5.18.1 * slurm-webdoc-23.02.7-150500.5.18.1 * slurm-config-23.02.7-150500.5.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43904.html * https://bugzilla.suse.com/show_bug.cgi?id=1243666 . Important security patch for SUSE Linux resolving slurm access vulnerability identified as CVE-2025-43904. Find more details.. SUSE Linux, slurm update, permission handling, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 29, 2025 Important SuSE
100

SUSE: 2025:1430-1 critical: python-h11 request smuggling

* bsc#1241872 Cross-References: * CVE-2025-43859 . # Security update for python-h11 Announcement ID: SUSE-SU-2025:1430-1 Release Date: 2025-05-02T08:11:00Z Rating: critical References: * bsc#1241872 Cross-References: * CVE-2025-43859 CVSS scores: * CVE-2025-43859 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-43859 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-43859 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python-h11 fixes the following issues: * CVE-2025-43859: leniency when parsing of line terminators in chunked-coding message bodies can lead to request smuggling. (bsc#1241872) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1430=1 * openSUSE Leap 15.6 zypper in -tpatch openSUSE-SLE-15.6-2025-1430=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-1430=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1430=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1430=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1430=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1430=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1430=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1430=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * openSUSE Leap 15.6 (noarch) * python311-h11-0.14.0-150400.9.6.1 * Python 3 Module 15-SP6 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) *python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-h11-0.14.0-150400.9.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-h11-0.14.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-43859.html * https://bugzilla.suse.com/show_bug.cgi?id=1241872 . Important patch for python-h11 on SUSE addresses cache poisoning issues. Protect your environment immediately.. python-h11 vulnerability, SUSE security update, request smuggling, openSUSE patch, Python module security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 02, 2025 Critical SuSE
98

Red Hat JBoss EAP: RHSA-2023-5484 Important Security Updates

A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat JBoss Enterprise Application Platform 7.4.13 security update on RHEL 7 Advisory ID: RHSA-2023:5484-01 Product: Red Hat JBoss Enterprise Application Platform Advisory URL: https://access.redhat.com/errata/RHSA-2023:5484 Issue date: 2023-10-05 CVE Names: CVE-2022-25883 CVE-2023-3171 CVE-2023-4061 CVE-2023-26136 CVE-2023-26464 CVE-2023-33201 CVE-2023-34462 ===================================================================== 1. Summary: A security update is now available for Red Hat JBoss Enterprise Application Platform 7.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat JBoss EAP 7.4 for RHEL 7 Server - noarch, x86_64 3. Description: Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.13 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.12 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.13 Release Notes for information about the most significant bug fixes and enhancements included in this release. Security Fix(es): * server: eap-7: heap exhaustion viadeserialization (CVE-2023-3171) * log4j: log4j1-chainsaw, log4j1-socketappender: DoS via hashmap logging (CVE-2023-26464) * nodejs-semver: Regular expression denial of service (CVE-2022-25883) * wildfly-core: Management User RBAC permission allows unexpected reading of system-properties to an Unauthorized actor (CVE-2023-4061) * tough-cookie: prototype pollution in cookie memstore (CVE-2023-26136) * bouncycastle: potential blind LDAP injection attack using a self-signed certificate (CVE-2023-33201) * netty: netty-handler: SniHandler 16MB allocation (CVE-2023-34462) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2182864 - CVE-2023-26464 log4j1-chainsaw, log4j1-socketappender: DoS via hashmap logging 2213639 - CVE-2023-3171 eap-7: heap exhaustion via deserialization 2215465 - CVE-2023-33201 bouncycastle: potential blind LDAP injection attack using a self-signed certificate 2216475 - CVE-2022-25883 nodejs-semver: Regular expression denial of service 2216888 - CVE-2023-34462 netty: SniHandler 16MB allocation leads to OOM 2219310 - CVE-2023-26136 tough-cookie: prototype pollution in cookie memstore 2228608 - CVE-2023-4061 wildfly-core: Management User RBAC permission allows unexpected reading of system-properties to an Unauthorized actor 6. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): JBEAP-24667 - (7.4.z) Upgrade Ironjacamar from 1.5.11.Final-redhat-00001 to 1.5.15.Final-redhat-00001 JBEAP-24797 - Tracker bug for the EAP 7.4.13 release for RHEL-7 JBEAP-24966 - [GSS](7.4.z) Upgrade RESTEasy from 3.15.7.Final-redhat-00001 to 3.15.8.Final-redhat-00001 JBEAP-24985 - (7.4.z) UpgradeArtemis from 2.16.0.redhat-00048 to 2.16.0.redhat-00049 JBEAP-25032 - (7.4.z) Upgrade Undertow from 2.2.25.SP3-redhat-00001 to 2.2.26.SP1-redhat-00001 JBEAP-25033 - (7.4.z) Upgrade WildFly Core from 15.0.29.Final-redhat-00001 to 15.0.30.Final-redhat-00001 JBEAP-25078 - (7.4.z) Upgrade netty from 4.1.86.Final-redhat-00001 to 4.1.94.Final-redhat-00001 (resolves CVE-2023-34462) JBEAP-25122 - (7.4.z) Upgrade jboss-marshalling from 2.0.13.Final-redhat-00001 to 2.0.13.SP1-redhat-00001 JBEAP-25135 - (7.4.z) Upgrade Elytron from 1.15.17.Final-redhat-00001 to 1.15.20.Final-redhat-00001 JBEAP-25186 - (7.4.z) Upgrade hal console from 3.3.18.Final-redhat-00001 to 3.3.19.Final-redhat-00001 JBEAP-25200 - (7.4.z) Upgrade Hibernate ORM from 5.3.30.Final-redhat-00001 to 5.3.31.Final-redhat-00001 JBEAP-25225 - (7.4.z) Upgrade mod_cluster from 1.4.4.Final-redhat-00001 to 1.4.5.Final-redhat-00001 JBEAP-25261 - (7.4.z) NettyConnection.batchBufferSize() is broken after upgrading netty to 4.1.94.Final JBEAP-25285 - [GSS](7.4.z) Upgrade JBoss Modules from 1.12.0.Final-redhat-00001 to 1.12.2.Final-redhat-00001 JBEAP-25312 - [GSS](7.4.z) Upgrade xnio from 3.8.9.Final-redhat-00001 to 3.8.10.Final-redhat-00001 7. Package List: Red Hat JBoss EAP 7.4 for RHEL 7Server: Source: eap7-activemq-artemis-2.16.0-15.redhat_00049.1.el7eap.src.rpm eap7-bouncycastle-1.76.0-4.redhat_00001.1.el7eap.src.rpm eap7-hal-console-3.3.19-1.Final_redhat_00001.1.el7eap.src.rpm eap7-hibernate-5.3.31-1.Final_redhat_00001.1.el7eap.src.rpm eap7-ironjacamar-1.5.15-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-marshalling-2.0.13-2.SP1_redhat_00001.1.el7eap.src.rpm eap7-jboss-modules-1.12.2-1.Final_redhat_00001.1.el7eap.src.rpm eap7-jboss-server-migration-1.10.0-31.Final_redhat_00030.1.el7eap.src.rpm eap7-jboss-xnio-base-3.8.10-1.Final_redhat_00001.1.el7eap.src.rpm eap7-mod_cluster-1.4.5-1.Final_redhat_00001.1.el7eap.src.rpm eap7-netty-4.1.94-1.Final_redhat_00001.1.el7eap.src.rpm eap7-netty-transport-native-epoll-4.1.94-1.Final_redhat_00001.1.el7eap.src.rpm eap7-resteasy-3.15.8-1.Final_redhat_00001.1.el7eap.src.rpm eap7-undertow-2.2.26-1.SP1_redhat_00001.1.el7eap.src.rpm eap7-wildfly-7.4.13-8.GA_redhat_00001.1.el7eap.src.rpm eap7-wildfly-elytron-1.15.20-1.Final_redhat_00001.1.el7eap.src.rpm noarch: eap7-activemq-artemis-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-cli-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-commons-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-core-client-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-dto-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-hornetq-protocol-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-hqclient-protocol-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-jdbc-store-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-jms-client-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-jms-server-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-journal-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-ra-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-selector-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-server-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-service-extensions-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-activemq-artemis-tools-2.16.0-15.redhat_00049.1.el7eap.noarch.rpm eap7-bouncycastle-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-bouncycastle-mail-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-bouncycastle-pg-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-bouncycastle-pkix-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-bouncycastle-prov-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-bouncycastle-util-1.76.0-4.redhat_00001.1.el7eap.noarch.rpm eap7-hal-console-3.3.19-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-5.3.31-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-core-5.3.31-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-entitymanager-5.3.31-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-envers-5.3.31-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-hibernate-java8-5.3.31-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-api-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-impl-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-common-spi-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-core-api-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-core-impl-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-deployers-common-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-jdbc-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-ironjacamar-validator-1.5.15-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-marshalling-2.0.13-2.SP1_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-marshalling-river-2.0.13-2.SP1_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-modules-1.12.2-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-jboss-server-migration-1.10.0-31.Final_redhat_00030.1.el7eap.noarch.rpm eap7-jboss-server-migration-cli-1.10.0-31.Final_redhat_00030.1.el7eap.noarch.rpm eap7-jboss-server-migration-core-1.10.0-31.Final_redhat_00030.1.el7eap.noarch.rpm eap7-jboss-xnio-base-3.8.10-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-mod_cluster-1.4.5-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-all-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-buffer-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-dns-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-haproxy-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-http-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-http2-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-memcache-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-mqtt-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-redis-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-smtp-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-socks-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-stomp-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-codec-xml-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-common-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-handler-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-handler-proxy-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-resolver-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-resolver-dns-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-resolver-dns-classes-macos-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-classes-epoll-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-classes-kqueue-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-native-unix-common-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-rxtx-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-sctp-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-netty-transport-udt-4.1.94-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-atom-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-cdi-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-client-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-crypto-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jackson-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jackson2-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jaxb-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jaxrs-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jettison-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jose-jwt-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-jsapi-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-json-binding-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-json-p-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-multipart-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-rxjava2-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-spring-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-validator-provider-11-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-resteasy-yaml-provider-3.15.8-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-undertow-2.2.26-1.SP1_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-7.4.13-8.GA_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-elytron-1.15.20-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-elytron-tool-1.15.20-1.Final_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-java-jdk11-7.4.13-8.GA_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-java-jdk8-7.4.13-8.GA_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-javadocs-7.4.13-8.GA_redhat_00001.1.el7eap.noarch.rpm eap7-wildfly-modules-7.4.13-8.GA_redhat_00001.1.el7eap.noarch.rpm x86_64: eap7-netty-transport-native-epoll-4.1.94-1.Final_redhat_00001.1.el7eap.x86_64.rpm eap7-netty-transport-native-epoll-debuginfo-4.1.94-1.Final_redhat_00001.1.el7eap.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 8. References: https://access.redhat.com/security/cve/CVE-2022-25883 https://access.redhat.com/security/cve/CVE-2023-3171 https://access.redhat.com/security/cve/CVE-2023-4061 https://access.redhat.com/security/cve/CVE-2023-26136 https://access.redhat.com/security/cve/CVE-2023-26464 https://access.redhat.com/security/cve/CVE-2023-33201 https://access.redhat.com/security/cve/CVE-2023-34462 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4 https://docs.redhat.com/en/documentation/red_hat_jboss_enterprise_application_platform/7.4/html-single/installation_guide/index 9. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlHyooAAoJENzjgjWX9erEk3sQAJrGRTFWV8XbaBnJsBa5mVmy qAQACfd9+QI4dLsdZnAFfBGIOBnpOjfjcwSYHYBrlduiB7riho0DwHvcUrthG5kC JrddaPIxj9/HbhKADu9T+YE7wb5mNth6rnsykaIfWqj4IRCkX7rmA+wgdYjvri9/ R/U/wqXBggR7tGiLXkk7dbZIkIZhJ3l8MUStoV6XLo9iHRonPn/3F77FiuX6xa51 KjR/f6LwKux8OGaoTNtE0ZJlA5BUfZikmRcOLo9oK/AezpHGByKUsmitUsFe6Jb+ YkuO0qq2UydWw3RC2ScluCkHoCRNhYmZ6ZwPUVXDO631M+hR26WIbPVfmfj2H3gt wKy89I9W8WUaKQZjAaNvf49PCvU1KFv925BXpeMjap4dhXRtXnXN7siEsWfervb5 kuY+XeHohaF7yeiH6+sVx+2RDNbYTFx6S6KXdaUOR6ATLW7tiSOLZpdMal3OG1hW PHWO/m9Kw6o9NDoqAc9GMWngEpW9QHI+NAs6ODVeQMzfmZng2YwMeuK/s6n1HU8m wbHqRbES1XNyJj0f4tNhiDIUElWxhro3c41cGR9OKMtbGgUQY2TTNtwu3pweMF36 cbcWgS4shPgBc++f1P0POBI2IW/n2/lFkeaZdMF2R0ptytaeRfsfFJSw+qkaYy3n H0k3RmJIQ97MEcmQ0XyG =A/BX -----END PGP SIGNATURE----- -- RHSA-announcemailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential security patch for JBoss EAP 7.4 on RHEL 7 tackling significant vulnerabilities and corrections.. Red Hat JBoss, security advisory, application security, Red Hat updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 05, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200