An update that solves 2 vulnerabilities can now be installed.. # go1.24-1.24rc3-1.1 on GA media Announcement ID: openSUSE-SU-2025:14735-1 Rating: moderate Cross-References: * CVE-2025-22866 * CVE-2025-22867 CVSS scores: * CVE-2025-22866 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22866 ( SUSE ): 6 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-22867 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the go1.24-1.24rc3-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * go1.24 1.24rc3-1.1 * go1.24-doc 1.24rc3-1.1 * go1.24-libstd 1.24rc3-1.1 * go1.24-race 1.24rc3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22866.html * https://www.suse.com/security/cve/CVE-2025-22867.html . An essential notice for openSUSE addresses moderate vulnerabilities present in the go1.24-1.24rc3-1.1 package, with comprehensive information provided.. openSUSE advisory, go application update, moderate security issues, security advisory, security update. . LinuxSecurity.com Team
Upstream details at : https://access.redhat.com/errata/RHSA-2023:7279. CentOS Errata and Security Advisory 2023:7279 Important Upstream details at : https://access.redhat.com/errata/RHSA-2023:7279 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: ee831a9a421c3f86e21ee19ee0a9cf5254cfb534d32e86d6e52c61dba58a55f3 open-vm-tools-11.0.5-3.el7_9.9.x86_64.rpm 6a423d2e3e4b4b0cd81b2df3ad65109a6c7e435cf5f4d7b65f79f895ac7dd281 open-vm-tools-desktop-11.0.5-3.el7_9.9.x86_64.rpm 53d8438b425a4358f4349cb5b43de3ceb51d10df527995c1c37a7d1598e8e8ee open-vm-tools-devel-11.0.5-3.el7_9.9.x86_64.rpm c567a821a6580c7066f9d12f98b47ff92838fdd821cc89005118e82149703252 open-vm-tools-test-11.0.5-3.el7_9.9.x86_64.rpm Source: 4503e101261195b5ff7f3452637e067dfd40d2fa84912a59488b67b62ce3fb62 open-vm-tools-11.0.5-3.el7_9.9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.2 (openstack-tripleo-heat-templates) security update Advisory ID: RHSA-2022:0995-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:0995 Issue date: 2022-03-23 CVE Names: CVE-2021-4180 ==================================================================== 1. Summary: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.2 - noarch 3. Description: Heat templates for TripleO Security Fix(es): * Data leak of internal URL through keystone_authtoken (CVE-2021-4180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1855678 - Configure Ceph Messenger for encryption OTW 1869587 - Octavia and LB issues after OSP13z11 and OSP16.x upgrade 1886762 - [RFE] support NFS mount at the conversion directory 1921112 - [OSP13-> OSP16.2]nova-consoleauth still present in cli after upgrade. 1949673 - [RHOSP16.2] [rsyslog] Miss configuration generated in 50_openstack_logs.conf 1949675 - [RHOSP16.2] [rsyslog] rsyslog containers does not forward logs to elasticsearch 1955562 - Backup and Restore: Backup openstack client integration - openstack backup using bad nfs server address is not erroring out 1962304 - cinder volume at DCN unable to read central cephx keyring 1965233 - [FFU 13 -> 16.x] xinetd is running after upgrade, blocking swift_rsync container 1969411 - [RFE]: allow for the deployment of RHCS dashboard on any composable network 1975271 - Minor update does not restart ha resource when it is in failed stated 1976055 - Configuration of Memcached TLS requires the user to duplicate configuration entries 1978228 - [OSP13-> OSP16.2] Leapp upgrade failed with TLSEverywhere 1980542 - [16.2] LC_CTYPE: cannot change locale (C.UTF-8) during OC upgrade 13 to 16.2 seems to fail upgrade 1983748 - NeutronL3AgentAvailabilityZone does not set specified value for Availability zone of Neutron L3 agent 1984555 - [RHOSP16.2] Smart plugin doesn't work for CAP_SYS_RAWIO capability missing. 1984875 - [OSP13-> 16.2] the leapp persistentnetnamesdisable actor should be removed so that a reboot can be avoided 1992506 - [RHOSP16.2] dpdk ovs vhost postcopy requires to start ovs with --mlockall=no 1999324 - NovaLiveMigrationPermitAutoConverge should default to true to match NovaLiveMigrationPermitPostCopy 1999725 - [RFE] Allow for the deployment of Ganesha on the overcloud "external" network 2000582 - ceph ssl radosgw port is closed for tempest (undercloud node) 2002346 - [OSP-16.2] [Upgrades][TripleO] Revert of the TSX change in tripleoclient 2003176 - [OSP16.2] ovn-dbs pacemaker update_tasks can race with pacemaker update_tasks 2005086 - Unable to disable gateway validation on deployment 2005680 - Cinder __DEFAULT__ volume type is installed but *tripleo* volume type is the real default 2008418 - Stack reconfiguration failed because ha-proxy container crashed duringreconfiguration 2009422 - Deployment failing due to "Create /etc/openstack directory if it does not exist" task 2010114 - Openstack ceilometer archival policy is not taking effect 2010703 - rhosp-release package is removed during upgrade from all nodes 2010940 - ceph-nfs not coming up after the FFU 2013913 - Minion should be configured with same default tuning as Undercloud for atleast heat & ironic 2014758 - There's a typo in MySQLInodbBufferPoolSize as it should be MySQLInnodbBufferPoolSize 2021575 - [16.2] openstack overcloud upgrade run times out / HAProxy container fails to start 2022234 - Parameter 'ValidateGatewaysIcmp:false' is not working in OSP16.2 2022691 - [OSP16.2] qemu logs are not accessible on the host 2026290 - Some log files are not collected/relayed by rsyslog to remote log server 2027787 - Undercloud upgrade to 16.2 fails because of missing dependencies of swtpm 2030409 - [OSP16.2] Memcached if off for Heat, Keystone and Nova since caching backend is dogpile.cache.null 2031110 - Long t-h-t role name causes OVNMacAddressPort tag to exceed the neutron tag length limit 2032010 - [OSP16.2.0] neutron-dhcp-agent causes oom issues on controllers2034189 - Validation if NTP/Chrony is configured during at initial stage of deployment procedure 2034730 - Horizon log not collected/relayed by rsyslog to remote log server 2035793 - CVE-2021-4180 openstack-tripleo-heat-templates: data leak of internal URL through keystone_authtoken 2037940 - [OVN] Enable ovn-monitor-all to help with OVN scale 2038897 - [RHOSP16.2] [DCN] [STF] metrics_qdr containers failed to start with bind address error 2046185 - From time to time memcached stops processing requests and brings down OpenStack control plane 2046211 - [OSP13-> OSP16.2] Leapp actors directory change impacting in the upgrade 2050154 - [update] 16.1-> 16.2 experience a connectivity cut (ping loss) to FIP during update of the controllers. 6. Package List: Red Hat OpenStack Platform16.2: Source: openstack-tripleo-heat-templates-11.6.1-2.20220116004912.el8ost.src.rpm noarch: openstack-tripleo-heat-templates-11.6.1-2.20220116004912.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-4180 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYjvmKNzjgjWX9erEAQispxAAihi4ziFGX97tUuSGWQgConiT5Hewws7X 84GxTMJ82iW7M7bQBPW6+YaKsKqqt3Yd3+1qCJG2q4A1j8dR/9Cy9U93AHHqMZe+ HOALT/1JQzrmH/DZGkuj5buhaHLYxbeBv/3IlyoaZVPRhu8xZ6wD/1OnPPTkc0LA HrEc47t5bVTmAqMyTdnBi5+0FxmgabOErSZk2MaWfTiBUpDbZfgO4Nw6Kq0UZyG1 q72gOnR6ZPCZG3n+QDIZytifEW9wCpngF8H5lOYe+BLErmBySUGtQubWllBA02Go DXIb4pPmtc7O08CVywTfdxAFTdaE69pk7LhB9/XRRVeLMkHc7ICKqtJmNXkyYugW 6zI/F950TzTqHlx7cRnEOY44D3sHva3CMy2QQHgz93FPiSdnNktLimP116jJHUfZ R6BAg4nBU8T1scTf0SBTurJeVhmOh9r5zyGRSzdDKA/iS6qY0u/RTzaQKLZrM2fl BPKbyZwQPFvGYepjBtSbKEbdXihz+b03N2KDg7XI4RP7z6k/qHnUAJ9lNIt9t9gI hJmiKyGAzrHKNqkuzXrMRhOnbfgElzMI2epsfUtYSfx3cga6NB4fQafT+YVZotLJ 1DkCfWDmwr/6qVqMNfqLh4KhC1WjwwYKFeqz5VYbNagEhe2Zn7ALIBc+b4xjp+8E UKkhXd7aiwk=yB4a -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A Denial of Service vulnerability was discovered in Analog.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Analog: Denial of Service Date: March 29, 2009 Bugs: #249140 ID: 200903-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A Denial of Service vulnerability was discovered in Analog. Background ========= Analog is a a webserver log analyzer. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/analog < 6.0-r2 > = 6.0-r2 Description ========== Diego E. Petteno reported that the Analog package in Gentoo is built with its own copy of bzip2, making it vulnerable to CVE-2008-1372 (GLSA 200804-02). Impact ===== A local attacker could place specially crafted log files into a log directory being analyzed by analog, e.g. /var/log/apache, resulting in a crash when being processed by the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Analog users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/analog-6.0-r2" NOTE: Analog is now linked against the system bzip2 library. References ========= [ 1 ] CVE-2008-1372 https://www.cve.org/CVERecord?id=CVE-2008-1372 [ 2 ] GLSA 200804-02 https://security.gentoo.org/glsa/200804-02 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-40 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Important: thunderbird security update. Date: Fri, 7 Oct 2005 15:34:00 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for SL 40,41 x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.