Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 58 articles for you...
172

Ubuntu 22.04 LTS: USN-7550-2 moderate: critical kernel flaws

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7550-2 June 03, 2025 linux-intel-iot-realtime, linux-realtime vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iot-realtime: Linux kernel for Intel IoT Real-time platforms - linux-realtime: Linux kernel for Real-time systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - Sun RPC protocol; (CVE-2024-56608, CVE-2024-56551, CVE-2024-53168) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1078-intel-iot-realtime 5.15.0-1078.80 Available with Ubuntu Pro linux-image-5.15.0-1085-realtime 5.15.0-1085.94 Available with Ubuntu Pro linux-image-intel-iot-realtime 5.15.0.1078.82 Available with Ubuntu Pro linux-image-realtime 5.15.0.1085.89 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7550-2 https://ubuntu.com/security/notices/USN-7550-1 CVE-2024-53168, CVE-2024-56551, CVE-2024-56608 Package Information: . Ubuntu 22.04 LTS has received crucial kernel updates to combat security vulnerabilities that threaten system integrity and data safety for users and their data. Ubuntu 22.04 LTS, Linux kernel, real-time systems, security notice. . LinuxSecurity.com Team

Calendar%202 Jun 03, 2025 Ubuntu
172

Ubuntu 24.04 LTS: USN-7515-1 critical: linux-gke kernel update

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7515-1 May 16, 2025 linux-gke vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gke: Linux kernel for Google Container Engine (GKE) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - x86 architecture; - Block layer subsystem; - Compute Acceleration Framework; - ACPI drivers; - Drivers core; - Ublk userspace block driver; - Virtio block driver; - DMA engine subsystem; - GPU drivers; - Microsoft Hyper-V drivers; - Hardware monitoring drivers; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - Multiple devices driver; - Media drivers; - Microchip PCI driver; - Network drivers; - Mellanox network drivers; - STMicroelectronics network drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Power supply drivers; - SCSI subsystem; - USB Gadget drivers; - TDX Guest driver; - AFS file system; - BTRFS file system; - Ceph distributed file system; - EROFS file system; - File systems infrastructure; - Network file systems library; - NILFS2 file system; - Overlay file system; - SMB network file system; - VLANs driver; - Memory management; - LAPB network protocol; - io_uring subsystem; - BPF subsystem; - Control group (cgroup); - Tracing infrastructure; - Workqueue subsystem; - Bluetooth subsystem; - Networking core; - IPv4networking; - IPv6 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - NET/ROM layer; - Packet sockets; - RDS protocol; - Network traffic control; - SCTP protocol; - SMC sockets; - Wireless networking; - SELinux security module; - ALSA framework; - SOF drivers; (CVE-2025-21660, CVE-2025-21659, CVE-2024-56718, CVE-2024-56675, CVE-2025-21631, CVE-2025-21664, CVE-2025-21655, CVE-2025-21662, CVE-2024-57804, CVE-2025-21656, CVE-2024-57910, CVE-2025-21647, CVE-2025-21634, CVE-2024-56716, CVE-2024-56709, CVE-2024-56770, CVE-2024-57888, CVE-2024-57793, CVE-2024-56670, CVE-2024-57931, CVE-2025-21640, CVE-2025-21648, CVE-2024-57913, CVE-2024-56710, CVE-2024-44964, CVE-2024-57911, CVE-2025-21654, CVE-2024-57890, CVE-2024-56654, CVE-2024-56767, CVE-2025-21650, CVE-2024-54460, CVE-2025-21635, CVE-2024-57791, CVE-2024-49568, CVE-2024-57879, CVE-2024-57929, CVE-2024-56715, CVE-2024-57899, CVE-2024-53687, CVE-2024-57900, CVE-2024-57903, CVE-2024-54455, CVE-2024-56763, CVE-2024-58087, CVE-2025-21638, CVE-2024-57892, CVE-2024-57884, CVE-2024-57792, CVE-2024-57904, CVE-2024-56759, CVE-2024-56659, CVE-2024-57885, CVE-2024-57889, CVE-2024-56657, CVE-2024-56667, CVE-2024-47408, CVE-2024-57805, CVE-2025-21637, CVE-2024-57893, CVE-2024-57946, CVE-2024-57806, CVE-2024-36476, CVE-2025-21646, CVE-2024-56369, CVE-2024-57917, CVE-2025-21649, CVE-2024-54193, CVE-2024-56717, CVE-2024-41013, CVE-2024-55916, CVE-2024-57933, CVE-2024-57907, CVE-2024-54683, CVE-2024-57887, CVE-2024-56760, CVE-2024-56652, CVE-2024-57940, CVE-2024-57906, CVE-2024-57939, CVE-2024-56372, CVE-2024-56665, CVE-2024-57925, CVE-2025-21938, CVE-2024-57895, CVE-2024-58237, CVE-2024-56664, CVE-2024-56660, CVE-2024-55639, CVE-2025-21632, CVE-2024-57841, CVE-2024-39282, CVE-2025-21651, CVE-2024-53125, CVE-2024-57807, CVE-2025-21643, CVE-2024-57883, CVE-2024-57898, CVE-2024-57897, CVE-2024-53179, CVE-2024-57932, CVE-2024-57916, CVE-2024-53685, CVE-2024-57908, CVE-2025-21652,CVE-2025-21658, CVE-2024-57926, CVE-2024-57801, CVE-2024-55881, CVE-2024-57901, CVE-2025-21653, CVE-2025-21642, CVE-2024-57882, CVE-2024-57912, CVE-2024-56662, CVE-2025-21639, CVE-2025-21971, CVE-2024-47736, CVE-2024-56761, CVE-2024-57945, CVE-2025-21663, CVE-2024-49571, CVE-2024-56758, CVE-2024-53690, CVE-2024-38608, CVE-2024-56656, CVE-2025-21645, CVE-2024-56764, CVE-2024-57896, CVE-2024-57938, CVE-2024-57902, CVE-2025-21636, CVE-2024-56769, CVE-2024-57802) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1025-gke 6.8.0-1025.29 linux-image-gke 6.8.0-1025.29 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7515-1 CVE-2024-36476, CVE-2024-38608, CVE-2024-39282, CVE-2024-41013, CVE-2024-44964, CVE-2024-47408, CVE-2024-47736, CVE-2024-49568, CVE-2024-49571, CVE-2024-53125, CVE-2024-53179, CVE-2024-53685, CVE-2024-53687, CVE-2024-53690, CVE-2024-54193, CVE-2024-54455, CVE-2024-54460, CVE-2024-54683, CVE-2024-55639, CVE-2024-55881, CVE-2024-55916, CVE-2024-56369, CVE-2024-56372, CVE-2024-56652, CVE-2024-56654, CVE-2024-56656, CVE-2024-56657, CVE-2024-56659, CVE-2024-56660, CVE-2024-56662, CVE-2024-56664, CVE-2024-56665, CVE-2024-56667, CVE-2024-56670, CVE-2024-56675, CVE-2024-56709, CVE-2024-56710, CVE-2024-56715, CVE-2024-56716, CVE-2024-56717, CVE-2024-56718, CVE-2024-56758, CVE-2024-56759,CVE-2024-56760, CVE-2024-56761, CVE-2024-56763, CVE-2024-56764, CVE-2024-56767, CVE-2024-56769, CVE-2024-56770, CVE-2024-57791, CVE-2024-57792, CVE-2024-57793, CVE-2024-57801, CVE-2024-57802, CVE-2024-57804, CVE-2024-57805, CVE-2024-57806, CVE-2024-57807, CVE-2024-57841, CVE-2024-57879, CVE-2024-57882, CVE-2024-57883, CVE-2024-57884, CVE-2024-57885, CVE-2024-57887, CVE-2024-57888, CVE-2024-57889, CVE-2024-57890, CVE-2024-57892, CVE-2024-57893, CVE-2024-57895, CVE-2024-57896, CVE-2024-57897, CVE-2024-57898, CVE-2024-57899, CVE-2024-57900, CVE-2024-57901, CVE-2024-57902, CVE-2024-57903, CVE-2024-57904, CVE-2024-57906, CVE-2024-57907, CVE-2024-57908, CVE-2024-57910, CVE-2024-57911, CVE-2024-57912, CVE-2024-57913, CVE-2024-57916, CVE-2024-57917, CVE-2024-57925, CVE-2024-57926, CVE-2024-57929, CVE-2024-57931, CVE-2024-57932, CVE-2024-57933, CVE-2024-57938, CVE-2024-57939, CVE-2024-57940, CVE-2024-57945, CVE-2024-57946, CVE-2024-58087, CVE-2024-58237, CVE-2025-21631, CVE-2025-21632, CVE-2025-21634, CVE-2025-21635, CVE-2025-21636, CVE-2025-21637, CVE-2025-21638, CVE-2025-21639, CVE-2025-21640, CVE-2025-21642, CVE-2025-21643, CVE-2025-21645, CVE-2025-21646, CVE-2025-21647, CVE-2025-21648, CVE-2025-21649, CVE-2025-21650, CVE-2025-21651, CVE-2025-21652, CVE-2025-21653, CVE-2025-21654, CVE-2025-21655, CVE-2025-21656, CVE-2025-21658, CVE-2025-21659, CVE-2025-21660, CVE-2025-21662, CVE-2025-21663, CVE-2025-21664, CVE-2025-21938, CVE-2025-21971 Package Information: https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1025.29 . Numerous vulnerabilities addressed in the Ubuntu kernel, safeguarding GKE environments against possible threats. System update advised for enhanced security.. Linux Kernel, Ubuntu Security, GKE Systems Update, System Patching. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 16, 2025 Critical Ubuntu
172

Ubuntu 14.04 LTS USN-7049-3: Critical PHP Threats Mitigated

Several security issues were fixed in PHP.. ========================================================================== Ubuntu Security Notice USN-7049-3 February 26, 2025 php5 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php5: HTML-embedded scripting language interpreter Details: USN-7049-1 fixed vulnerabilities in PHP. This update provides the corresponding updates for Ubuntu 14.04 LTS. Original advisory details: It was discovered that PHP incorrectly handled parsing multipart form data.A remote attacker could possibly use this issue to inject payloads and cause PHP to ignore legitimate data. (CVE-2024-8925) It was discovered that PHP incorrectly handled the cgi.force_redirect configuration option due to environment variable collisions. In certain configurations, an attacker could possibly use this issue bypass force_redirect restrictions. (CVE-2024-8927) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.29+esm16 Available with Ubuntu Pro php5 5.5.9+dfsg-1ubuntu4.29+esm16 Available with Ubuntu Pro php5-cgi 5.5.9+dfsg-1ubuntu4.29+esm16 Available with Ubuntu Pro php5-cli 5.5.9+dfsg-1ubuntu4.29+esm16 Available with Ubuntu Pro php5-fpm 5.5.9+dfsg-1ubuntu4.29+esm16 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7049-3 https://ubuntu.com/security/notices/USN-7049-2 https://ubuntu.com/security/notices/USN-7049-1 CVE-2024-8925, CVE-2024-8927 . Enhancements for PHP security vulnerabilities in Ubuntu 14.04 LTS to mitigate risks of attacks and data breaches. Discover more!. PHP Security Updates, Ubuntu 14.04, Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 27, 2025 Critical Ubuntu
89

Fedora 41: FEDORA-2025-18cb3f852d critical: OpenSSH Match Directive Issue

Fix regression of Match directive processing. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-18cb3f852d 2025-02-20 02:26:22.548385+00:00 -------------------------------------------------------------------------------- Name : openssh Product : Fedora 41 Version : 9.9p1 Release : 3.fc41 URL : https://www.openssh.org/portable.html Summary : An open source implementation of SSH protocol version 2 Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both. -------------------------------------------------------------------------------- Update Information: Fix regression of Match directive processing -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 18 2025 Dmitry Belyavskiy - 9.9p1-3 - Fix regression of Match directive processing - Fix missing error codes set and invalid error code checks in OpenSSH. It prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS is on (CVE-2025-26465, CVE-2025-26466). -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-18cb3f852d' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Recent updates on the OpenSSH security advisory for Fedora 41 address match directive vulnerabilities, enhancing security and mitigating risks from misconfigurations. Fedora 41 OpenSSH, security advisory, match processing regression. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 20, 2025 Critical Fedora
172

Ubuntu 24.10: USN-7199-1 critical: libxmltok denial of service

Several security issues were fixed in libxmltok.. ========================================================================== Ubuntu Security Notice USN-7199-1 January 13, 2025 libxmltok vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in libxmltok. Software Description: - libxmltok: XML Parser Toolkit, runtime libraries Details: It was discovered that Expat, contained within the xmltok library, incorrectly handled malformed XML data. If a user or application were tricked into opening a crafted XML file, an attacker could cause a denial of service, or possibly execute arbitrary code. (CVE-2015-1283, CVE-2016-0718, CVE-2016-4472, CVE-2019-15903) It was discovered that Expat, contained within the xmltok library, incorrectly handled XML data containing a large number of colons, which could lead to excessive resource consumption. If a user or application were tricked into opening a crafted XML file, an attacker could possibly use this issue to cause a denial of service. (CVE-2018-20843) It was discovered that Expat, contained within the xmltok library, incorrectly handled certain input, which could lead to an integer overflow. If a user or application were tricked into opening a crafted XML file, an attacker could possibly use this issue to cause a denial of service. (CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libxmltok1t64 1.2-4.1ubuntu3.1 Ubuntu 24.04 LTS libxmltok1t64 1.2-4.1ubuntu2.24.0.4.1+esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS libxmltok1 1.2-4ubuntu0.22.04.1~esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS libxmltok1 1.2-4ubuntu0.20.04.1~esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS libxmltok1 1.2-4ubuntu0.18.04.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7199-1 CVE-2015-1283, CVE-2016-0718, CVE-2016-4472, CVE-2018-20843, CVE-2019-15903, CVE-2021-46143, CVE-2022-22822, CVE-2022-22823, CVE-2022-22824, CVE-2022-22825, CVE-2022-22826, CVE-2022-22827 Package Information: https://launchpad.net/ubuntu/+source/libxmltok/1.2-4.1ubuntu3.1 . Recent assessments show security vulnerabilities in libxmltok affecting Ubuntu releases. Users should upgrade to patched versions to enhance security and stability. libxmltok vulnerabilities, Ubuntu security updates, XML data exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 13, 2025 Critical Ubuntu
219

Rocky Linux 8: RLSA-2024:5258 Critical: Security Patch for Container-Tools

Important: container-tools:rhel8 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:5258", "synopsis": "Important: container-tools:rhel8 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for podman, buildah, module.toolbox, module.podman, cockpit-podman, containers-common, module.criu, module.conmon, module.aardvark-dns, module.containers-common, module.python-podman, oci-seccomp-bpf-hook, module.fuse-overlayfs, module.oci-seccomp-bpf-hook, module.udica, module.crun, container-selinux, module.runc, crun, conmon, module.netavark, module.containernetworking-plugins, module.cockpit-podman, toolbox, module.skopeo, criu, runc, module.slirp4netns, netavark, slirp4netns, udica, skopeo, libslirp, fuse-overlayfs, python-podman, module.buildah, module.container-selinux, module.libslirp, containernetworking-plugins, aardvark-dns.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\n\nSecurity Fix(es):\n\n* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)\n\n* golang: net/http: memory exhaustion in Request.ParseMultipartForm (CVE-2023-45290)\n\n* golang: crypto/x509: Verify panics on certificates with an unknown public key algorithm (CVE-2024-24783)\n\n* golang: net/mail: comments in display names are incorrectly handled (CVE-2024-24784)\n\n* containers/image: digest type does not guarantee valid type (CVE-2024-3727)\n\n* golang: archive/zip: Incorrect handling of certain ZIP files (CVE-2024-24789)\n\n* go-retryablehttp: url might write sensitive information to log file (CVE-2024-6104)\n\n* gorilla/schema: Potential memory exhaustion attack due to sparse slice deserialization (CVE-2024-37298)\n\nFor more details about the security issue(s), includingthe impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2262921", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2262921", "description": ""}, {"ticket": "2268017", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2268017", "description": ""}, {"ticket": "2268019", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2268019", "description": ""}, {"ticket": "2268021", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2268021", "description": ""}, {"ticket": "2274767", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2274767", "description": ""}, {"ticket": "2292668", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2292668", "description": ""}, {"ticket": "2294000", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2294000", "description": ""}, {"ticket": "2295010", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295010", "description": ""}], "cves": [{"name": "CVE-2023-45290", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-45290", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-1394", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-1394", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-24783", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-24783", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-24784", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-24784", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe":"UNKNOWN"}, {"name": "CVE-2024-24789", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-24789", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-3727", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3727", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-37298", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-37298", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-6104", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-6104", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-21T14:52:31.100489Z", "rpms": {"Rocky Linux 8": {"nvras": ["aardvark-dns-2:1.10.0-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "aardvark-dns-2:1.10.0-1.module+el8.10.0+1815+5fe7415e.src.rpm", "aardvark-dns-2:1.10.0-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "buildah-2:1.33.8-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "buildah-2:1.33.8-4.module+el8.10.0+1843+6892ab28.src.rpm", "buildah-2:1.33.8-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "buildah-debuginfo-2:1.33.8-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "buildah-debuginfo-2:1.33.8-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "buildah-debugsource-2:1.33.8-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "buildah-debugsource-2:1.33.8-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "buildah-tests-2:1.33.8-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "buildah-tests-2:1.33.8-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "buildah-tests-debuginfo-2:1.33.8-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "buildah-tests-debuginfo-2:1.33.8-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "cockpit-podman-0:84.1-1.module+el8.10.0+1815+5fe7415e.noarch.rpm", "cockpit-podman-0:84.1-1.module+el8.10.0+1815+5fe7415e.src.rpm","conmon-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "conmon-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.src.rpm", "conmon-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "conmon-debuginfo-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "conmon-debuginfo-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "conmon-debugsource-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "conmon-debugsource-3:2.1.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "containernetworking-plugins-1:1.4.0-5.module+el8.10.0+1843+6892ab28.aarch64.rpm", "containernetworking-plugins-1:1.4.0-5.module+el8.10.0+1843+6892ab28.src.rpm", "containernetworking-plugins-1:1.4.0-5.module+el8.10.0+1843+6892ab28.x86_64.rpm", "containernetworking-plugins-debuginfo-1:1.4.0-5.module+el8.10.0+1843+6892ab28.aarch64.rpm", "containernetworking-plugins-debuginfo-1:1.4.0-5.module+el8.10.0+1843+6892ab28.x86_64.rpm", "containernetworking-plugins-debugsource-1:1.4.0-5.module+el8.10.0+1843+6892ab28.aarch64.rpm", "containernetworking-plugins-debugsource-1:1.4.0-5.module+el8.10.0+1843+6892ab28.x86_64.rpm", "containers-common-2:1-82.module+el8.10.0+1843+6892ab28.aarch64.rpm", "containers-common-2:1-82.module+el8.10.0+1843+6892ab28.src.rpm", "containers-common-2:1-82.module+el8.10.0+1843+6892ab28.x86_64.rpm", "container-selinux-2:2.229.0-2.module+el8.10.0+1815+5fe7415e.noarch.rpm", "container-selinux-2:2.229.0-2.module+el8.10.0+1815+5fe7415e.src.rpm", "crit-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "crit-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "criu-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-0:3.18-5.module+el8.10.0+1815+5fe7415e.src.rpm", "criu-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "criu-debuginfo-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-debuginfo-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "criu-debugsource-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-debugsource-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm","criu-devel-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-devel-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "criu-libs-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-libs-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "criu-libs-debuginfo-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "criu-libs-debuginfo-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "crun-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "crun-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.src.rpm", "crun-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "crun-debuginfo-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "crun-debuginfo-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "crun-debugsource-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "crun-debugsource-0:1.14.3-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "fuse-overlayfs-0:1.13-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "fuse-overlayfs-0:1.13-1.module+el8.10.0+1815+5fe7415e.src.rpm", "fuse-overlayfs-0:1.13-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "fuse-overlayfs-debuginfo-0:1.13-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "fuse-overlayfs-debuginfo-0:1.13-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "fuse-overlayfs-debugsource-0:1.13-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "fuse-overlayfs-debugsource-0:1.13-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "libslirp-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "libslirp-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.src.rpm", "libslirp-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "libslirp-debuginfo-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "libslirp-debuginfo-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "libslirp-debugsource-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "libslirp-debugsource-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "libslirp-devel-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "libslirp-devel-0:4.4.0-2.module+el8.10.0+1815+5fe7415e.x86_64.rpm","netavark-2:1.10.3-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "netavark-2:1.10.3-1.module+el8.10.0+1815+5fe7415e.src.rpm", "netavark-2:1.10.3-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "oci-seccomp-bpf-hook-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "oci-seccomp-bpf-hook-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.src.rpm", "oci-seccomp-bpf-hook-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "oci-seccomp-bpf-hook-debuginfo-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "oci-seccomp-bpf-hook-debuginfo-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "oci-seccomp-bpf-hook-debugsource-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "oci-seccomp-bpf-hook-debugsource-0:1.2.10-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "podman-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-4:4.9.4-12.module+el8.10.0+1843+6892ab28.src.rpm", "podman-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-catatonit-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-catatonit-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-catatonit-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-catatonit-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-debugsource-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-debugsource-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-docker-4:4.9.4-12.module+el8.10.0+1843+6892ab28.noarch.rpm", "podman-gvproxy-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-gvproxy-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-gvproxy-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-gvproxy-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-plugins-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm","podman-plugins-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-plugins-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-plugins-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-remote-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-remote-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-remote-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-remote-debuginfo-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "podman-tests-4:4.9.4-12.module+el8.10.0+1843+6892ab28.aarch64.rpm", "podman-tests-4:4.9.4-12.module+el8.10.0+1843+6892ab28.x86_64.rpm", "python3-criu-0:3.18-5.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "python3-criu-0:3.18-5.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "python3-podman-0:4.9.0-2.module+el8.10.0+1843+6892ab28.noarch.rpm", "python-podman-0:4.9.0-2.module+el8.10.0+1843+6892ab28.src.rpm", "runc-1:1.1.12-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "runc-1:1.1.12-4.module+el8.10.0+1843+6892ab28.src.rpm", "runc-1:1.1.12-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "runc-debuginfo-1:1.1.12-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "runc-debuginfo-1:1.1.12-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "runc-debugsource-1:1.1.12-4.module+el8.10.0+1843+6892ab28.aarch64.rpm", "runc-debugsource-1:1.1.12-4.module+el8.10.0+1843+6892ab28.x86_64.rpm", "skopeo-2:1.14.5-3.module+el8.10.0+1843+6892ab28.aarch64.rpm", "skopeo-2:1.14.5-3.module+el8.10.0+1843+6892ab28.src.rpm", "skopeo-2:1.14.5-3.module+el8.10.0+1843+6892ab28.x86_64.rpm", "skopeo-tests-2:1.14.5-3.module+el8.10.0+1843+6892ab28.aarch64.rpm", "skopeo-tests-2:1.14.5-3.module+el8.10.0+1843+6892ab28.x86_64.rpm", "slirp4netns-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "slirp4netns-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.src.rpm", "slirp4netns-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "slirp4netns-debuginfo-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm","slirp4netns-debuginfo-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "slirp4netns-debugsource-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.aarch64.rpm", "slirp4netns-debugsource-0:1.2.3-1.module+el8.10.0+1815+5fe7415e.x86_64.rpm", "toolbox-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.aarch64.rpm", "toolbox-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.src.rpm", "toolbox-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.x86_64.rpm", "toolbox-debuginfo-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.aarch64.rpm", "toolbox-debuginfo-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.x86_64.rpm", "toolbox-debugsource-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.aarch64.rpm", "toolbox-debugsource-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.x86_64.rpm", "toolbox-tests-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.aarch64.rpm", "toolbox-tests-0:0.0.99.5-2.module+el8.10.0+1815+5fe7415e.rocky.0.2.rocky.0.2.x86_64.rpm", "udica-0:0.2.6-21.module+el8.10.0+1815+5fe7415e.noarch.rpm", "udica-0:0.2.6-21.module+el8.10.0+1815+5fe7415e.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 8 has rolled out an update for container-tools that addresses critical security vulnerabilities and boosts system resilience, urging users to update promptly. Rocky Linux, container security, memory leak, RLSA update, important fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 21, 2024 Important Rocky Linux
217

Oracle Linux 9 ELSA-2024-4573 Important: Java Security Fix

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4573 http://linux.oracle.com/errata/ELSA-2024-4573.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: java-21-openjdk-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-javadoc-zip-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-src-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-demo-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-devel-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-headless-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-jmods-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-src-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-src-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-fastdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm java-21-openjdk-static-libs-slowdebug-21.0.4.0.7-1.0.1.el9.x86_64.rpm aarch64: java-21-openjdk-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-javadoc-zip-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-src-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-demo-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-devel-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-headless-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-jmods-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-src-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-src-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-fastdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm java-21-openjdk-static-libs-slowdebug-21.0.4.0.7-1.0.1.el9.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//java-21-openjdk-21.0.4.0.7-1.0.1.el9.src.rpm Related CVEs: CVE-2024-21131 CVE-2024-21138 CVE-2024-21140 CVE-2024-21145 CVE-2024-21147 Description of changes: [1:21.0.4.0.7-1.0.1] - Add Oracle vendor bug URL [Orabug: 34340155] [1:21.0.4.0.7-1] - Update to jdk-21.0.4+7 (GA) - Update release notes to 21.0.4+7 - Switch to GA mode. - Sync the copy of the portable specfile with the latest update - Add missing section headers in NEWS - ** This tarball is embargoed until 2024-07-16 @ 1pm PT. ** - Resolves: RHEL-47022 [1:21.0.4.0.5-0.1.ea] - Update to jdk-21.0.4+5 (EA) - Update release notes to 21.0.4+5 - Limit Java only tests to one architecture using jdk_test_arch - Actually require tzdata 2024a now it is available in the buildroot - Resolves: RHEL-45356 - Resolves: RHEL-47399 [1:21.0.4.0.1-0.1.ea] - Update to jdk-21.0.4+1 (EA) - Update release notes to 21.0.4+1 - Switch to EA mode - Bump LCMS 2 version to 2.16.0 following JDK-8321489 - Add zlib build requirement or bundled version (1.3.1), depending on system_libs setting - Restore NEWS file so portable can be rebuilt - Sync the copy of the portable specfile with the latest update - Related: RHEL-45356 - Resolves:RHEL-46028 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . CentOS Update ELSA-2024-9143 highlights vital improvements for Python packages. Review immediately for important stability enhancements.. Oracle Linux, Java update, Security Fixes, ELSA-2024-4573, RPM Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 19, 2024 Important Oracle
100

SUSE: 2024:1923-1 Important Security Advisory for Unbound DNS

* bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826 . # Security update for unbound Announcement ID: SUSE-SU-2024:1923-1 Rating: important References: * bsc#1202031 * bsc#1202033 * bsc#1203643 * bsc#1219823 * bsc#1219826 * jsc#PED-8333 Cross-References: * CVE-2022-30698 * CVE-2022-30699 * CVE-2022-3204 * CVE-2023-50387 * CVE-2023-50868 CVSS scores: * CVE-2022-30698 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2022-30698 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2022-30699 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2022-30699 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2022-3204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50387 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50387 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves five vulnerabilities and contains one feature can now be installed. ## Description: This update for unbound fixes the following issues: unbound was updated to 1.20.0: * A lot of bugfixes and added features. For a complete list take a look at the changelog located at: /usr/share/doc/packages/unbound/Changelog or https://www.nlnetlabs.nl/projects/unbound/download/ Some Noteworthy Changes: * Removed DLV. The DLV has been decommisioned since unbound 1.5.4 and has been advised to stop using it since. The use of dlv options displays a warning. * Remove EDNS lame procedure, do notre-query without EDNS after timeout. * Add DNS over HTTPS * libunbound has been upgraded to major version 8 Security Fixes: * CVE-2023-50387: DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers. [bsc#1219823] * CVE-2023-50868: NSEC3 closest encloser proof can exhaust CPU. [bsc#1219826] * CVE-2022-30698: Novel "ghost domain names" attack by introducing subdomain delegations. [bsc#1202033] * CVE-2022-30699: Novel "ghost domain names" attack by updating almost expired delegation information. [bsc#1202031] * CVE-2022-3204: NRDelegation attack leads to uncontrolled resource consumption (Non-Responsive Delegation Attack). [bsc#1203643] Packaging Changes: * Use prefixes instead of sudo in unbound.service * Remove no longer necessary BuildRequires: libfstrm-devel and libprotobuf-c- devel ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-1923=1 openSUSE-SLE-15.6-2024-1923=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-1923=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-1923=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libunbound-devel-mini-debugsource-1.20.0-150600.23.3.1 * unbound-1.20.0-150600.23.3.1 * libunbound8-1.20.0-150600.23.3.1 * libunbound-devel-mini-debuginfo-1.20.0-150600.23.3.1 * libunbound8-debuginfo-1.20.0-150600.23.3.1 * unbound-anchor-debuginfo-1.20.0-150600.23.3.1 * unbound-debugsource-1.20.0-150600.23.3.1 * unbound-debuginfo-1.20.0-150600.23.3.1 * unbound-devel-1.20.0-150600.23.3.1 * unbound-python-1.20.0-150600.23.3.1 * unbound-anchor-1.20.0-150600.23.3.1 * unbound-python-debuginfo-1.20.0-150600.23.3.1 *libunbound-devel-mini-1.20.0-150600.23.3.1 * openSUSE Leap 15.6 (noarch) * unbound-munin-1.20.0-150600.23.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * unbound-debugsource-1.20.0-150600.23.3.1 * libunbound8-1.20.0-150600.23.3.1 * unbound-anchor-debuginfo-1.20.0-150600.23.3.1 * libunbound8-debuginfo-1.20.0-150600.23.3.1 * unbound-devel-1.20.0-150600.23.3.1 * unbound-debuginfo-1.20.0-150600.23.3.1 * unbound-anchor-1.20.0-150600.23.3.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * unbound-1.20.0-150600.23.3.1 * unbound-debugsource-1.20.0-150600.23.3.1 * unbound-python-1.20.0-150600.23.3.1 * unbound-debuginfo-1.20.0-150600.23.3.1 * unbound-python-debuginfo-1.20.0-150600.23.3.1 ## References: * https://www.suse.com/security/cve/CVE-2022-30698.html * https://www.suse.com/security/cve/CVE-2022-30699.html * https://www.suse.com/security/cve/CVE-2022-3204.html * https://www.suse.com/security/cve/CVE-2023-50387.html * https://www.suse.com/security/cve/CVE-2023-50868.html * https://bugzilla.suse.com/show_bug.cgi?id=1202031 * https://bugzilla.suse.com/show_bug.cgi?id=1202033 * https://bugzilla.suse.com/show_bug.cgi?id=1203643 * https://bugzilla.suse.com/show_bug.cgi?id=1219823 * https://bugzilla.suse.com/show_bug.cgi?id=1219826 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-8333&page_caps=&user_role= . A significant safety enhancement for unbound tackles various vulnerabilities within SUSE's software solutions, enhancing reliability.. SUSE Security, Unbound Update, DNS Security, Patch Management, Attack Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 04, 2024 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200