Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 37 articles for you...
217

Oracle Linux 8 ELSA-2025-1675 critical: bind security patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1675 http://linux.oracle.com/errata/ELSA-2025-1675.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bind-9.11.36-16.el8_10.4.x86_64.rpm bind-chroot-9.11.36-16.el8_10.4.x86_64.rpm bind-devel-9.11.36-16.el8_10.4.i686.rpm bind-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-export-devel-9.11.36-16.el8_10.4.i686.rpm bind-export-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-export-libs-9.11.36-16.el8_10.4.i686.rpm bind-export-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-libs-9.11.36-16.el8_10.4.i686.rpm bind-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-libs-lite-9.11.36-16.el8_10.4.i686.rpm bind-libs-lite-9.11.36-16.el8_10.4.x86_64.rpm bind-license-9.11.36-16.el8_10.4.noarch.rpm bind-lite-devel-9.11.36-16.el8_10.4.i686.rpm bind-lite-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.i686.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.i686.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.x86_64.rpm bind-pkcs11-utils-9.11.36-16.el8_10.4.x86_64.rpm bind-sdb-9.11.36-16.el8_10.4.x86_64.rpm bind-sdb-chroot-9.11.36-16.el8_10.4.x86_64.rpm bind-utils-9.11.36-16.el8_10.4.x86_64.rpm python3-bind-9.11.36-16.el8_10.4.noarch.rpm aarch64: bind-9.11.36-16.el8_10.4.aarch64.rpm bind-chroot-9.11.36-16.el8_10.4.aarch64.rpm bind-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-export-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-export-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-libs-lite-9.11.36-16.el8_10.4.aarch64.rpm bind-license-9.11.36-16.el8_10.4.noarch.rpm bind-lite-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-devel-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-libs-9.11.36-16.el8_10.4.aarch64.rpm bind-pkcs11-utils-9.11.36-16.el8_10.4.aarch64.rpm bind-sdb-9.11.36-16.el8_10.4.aarch64.rpm bind-sdb-chroot-9.11.36-16.el8_10.4.aarch64.rpm bind-utils-9.11.36-16.el8_10.4.aarch64.rpm python3-bind-9.11.36-16.el8_10.4.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//bind-9.11.36-16.el8_10.4.src.rpm Related CVEs: CVE-2024-11187 Description ofchanges: [32:9.11.36-16.4] - Change patches applying to use -P parameter [32:9.11.36-16.3] - Limit additional section records CPU processing (CVE-2024-11187) - Correct ANY queries to not have additional data appended _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2025-1675 addresses critical BIND vulnerabilities, detailing patches to mitigate security risks and enhance defenses. Oracle Linux Updates, Bind Security Advisory, ELSA-2025-1675. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Oracle
100

SUSE 2025:0337-1 important: bind CPU exhaustion security issue

* bsc#1236596 Cross-References: * CVE-2024-11187 . # Security update for bind Announcement ID: SUSE-SU-2025:0337-1 Release Date: 2025-02-03T15:10:35Z Rating: important References: * bsc#1236596 Cross-References: * CVE-2024-11187 CVSS scores: * CVE-2024-11187 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-11187 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-11187 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Manager Client Tools for SLE Micro 5 An update that solves one vulnerability can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2024-11187: Fixes CPU exhaustion caused by many records in the additional section (bsc#1236596) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2025-337=1 ## Package List: * SUSE Manager Client Tools for SLE Micro 5 (aarch64 s390x x86_64) * libirs1601-9.16.6-150000.12.80.1 * libbind9-1600-9.16.6-150000.12.80.1 * libisccc1600-9.16.6-150000.12.80.1 * libisc1606-9.16.6-150000.12.80.1 * bind-utils-9.16.6-150000.12.80.1 * libns1604-debuginfo-9.16.6-150000.12.80.1 * libns1604-9.16.6-150000.12.80.1 * libdns1605-9.16.6-150000.12.80.1 * libisccfg1600-9.16.6-150000.12.80.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64_ilp32) * libisccc1600-64bit-9.16.6-150000.12.80.1 * libisccfg1600-64bit-9.16.6-150000.12.80.1 * libbind9-1600-64bit-9.16.6-150000.12.80.1 * libisc1606-64bit-9.16.6-150000.12.80.1 * libdns1605-64bit-9.16.6-150000.12.80.1 * libirs1601-64bit-9.16.6-150000.12.80.1 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.80.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11187.html * https://bugzilla.suse.com/show_bug.cgi?id=1236596 . SUSE: 2025:0542-3 critical upgrade addresses memory leak issue in apache. Apply suggested updates for enhanced security.. SUSE Security Update, CVE Protection, Software Vulnerability Fixes, Bind Security Advisory, SUSE Manager Tools. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 03, 2025 Important SuSE
219

Rocky Linux 9 RLSA-2024:5231 Important Bind Security Threat Fix

Important: bind and bind-dyndb-ldap security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:5231", "synopsis": "Important: bind and bind-dyndb-ldap security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for bind-dyndb-ldap, bind.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.\n\nSecurity Fix(es):\n\n* bind: bind9: BIND's database will be slow if a very large number of RRs exist at the same nam (CVE-2024-1737)\n\n* bind9: bind: SIG(0) can be used to exhaust CPU resources (CVE-2024-1975)\n\n* bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content (CVE-2024-4076)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2298893", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2298893", "description": ""}, {"ticket": "2298901", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2298901", "description": ""}, {"ticket": "2298904", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2298904", "description": ""}], "cves": [{"name": "CVE-2024-1737", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-1737", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-1975", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2024-1975", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4076", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4076", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-21T14:53:26.062670Z", "rpms": {"Rocky Linux 9": {"nvras": ["bind-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-32:9.16.23-18.el9_4.6.src.rpm", "bind-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-chroot-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-chroot-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-chroot-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-chroot-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-debuginfo-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-debuginfo-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-debuginfo-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-debuginfo-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-debugsource-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-debugsource-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-debugsource-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-debugsource-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-devel-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-devel-32:9.16.23-18.el9_4.6.i686.rpm", "bind-devel-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-devel-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-devel-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-dnssec-doc-32:9.16.23-18.el9_4.6.noarch.rpm", "bind-dnssec-utils-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-dnssec-utils-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-dnssec-utils-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-dnssec-utils-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-dnssec-utils-debuginfo-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-doc-32:9.16.23-18.el9_4.6.noarch.rpm","bind-dyndb-ldap-0:11.9-10.el9_4.aarch64.rpm", "bind-dyndb-ldap-0:11.9-10.el9_4.ppc64le.rpm", "bind-dyndb-ldap-0:11.9-10.el9_4.s390x.rpm", "bind-dyndb-ldap-0:11.9-10.el9_4.src.rpm", "bind-dyndb-ldap-0:11.9-10.el9_4.x86_64.rpm", "bind-dyndb-ldap-debuginfo-0:11.9-10.el9_4.aarch64.rpm", "bind-dyndb-ldap-debuginfo-0:11.9-10.el9_4.ppc64le.rpm", "bind-dyndb-ldap-debuginfo-0:11.9-10.el9_4.s390x.rpm", "bind-dyndb-ldap-debuginfo-0:11.9-10.el9_4.x86_64.rpm", "bind-dyndb-ldap-debugsource-0:11.9-10.el9_4.aarch64.rpm", "bind-dyndb-ldap-debugsource-0:11.9-10.el9_4.ppc64le.rpm", "bind-dyndb-ldap-debugsource-0:11.9-10.el9_4.s390x.rpm", "bind-dyndb-ldap-debugsource-0:11.9-10.el9_4.x86_64.rpm", "bind-libs-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-libs-32:9.16.23-18.el9_4.6.i686.rpm", "bind-libs-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-libs-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-libs-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-libs-debuginfo-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-libs-debuginfo-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-libs-debuginfo-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-libs-debuginfo-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-license-32:9.16.23-18.el9_4.6.noarch.rpm", "bind-utils-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-utils-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-utils-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-utils-32:9.16.23-18.el9_4.6.x86_64.rpm", "bind-utils-debuginfo-32:9.16.23-18.el9_4.6.aarch64.rpm", "bind-utils-debuginfo-32:9.16.23-18.el9_4.6.ppc64le.rpm", "bind-utils-debuginfo-32:9.16.23-18.el9_4.6.s390x.rpm", "bind-utils-debuginfo-32:9.16.23-18.el9_4.6.x86_64.rpm", "python3-bind-32:9.16.23-18.el9_4.6.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Notice: A crucial security patch for bind and bind-dyndb-ldap on Rocky Linux 9 has been released to tackle severe vulnerabilities.. bind update, security advisory, Rocky Linux, bind-dyndb-ldap, CPU resources. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 21, 2024 Important Rocky Linux
217

Oracle Linux 7 ELSA-2024-3741 Critical: Bind And DHCP Security Fixes

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-3741 http://linux.oracle.com/errata/ELSA-2024-3741.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: bind-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-export-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-libs-lite-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-license-9.11.4-26.P2.el7_9.16.noarch.rpm bind-pkcs11-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-libs-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-utils-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-export-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-lite-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-pkcs11-devel-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-sdb-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-sdb-chroot-9.11.4-26.P2.el7_9.16.aarch64.rpm bind-dyndb-ldap-11.1-7.el7_9.1.aarch64.rpm dhclient-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-common-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-libs-4.2.5-83.0.3.el7_9.2.aarch64.rpm dhcp-devel-4.2.5-83.0.3.el7_9.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.16.src.rpm http://oss.oracle.com/ol7/SRPMS-updates//bind-dyndb-ldap-11.1-7.el7_9.1.src.rpm http://oss.oracle.com/ol7/SRPMS-updates//dhcp-4.2.5-83.0.3.el7_9.2.src.rpm Related CVEs: CVE-2023-4408 CVE-2023-50387 CVE-2023-50868 Description of changes: bind [32:9.11.4-26.P2.16] - Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387 CVE-2023-50868) - Add missing design by contract tests to dns_catz* - Speed up parsing of DNS messages with many different names (CVE-2023-4408) - Do not use header_prev in expire_lru_headers bind-dyndb-ldap [11.1-7.1] - Rebuild required for BIND changes for KeyTrap change(CVE-2023-50387) dhcp [12:4.2.5-83.0.3.2] - Update bug reporting URL [Orabug: 35496820] - Direct users to Oracle Linux support site. [12:4.2.5-83.2] - Rebuild because of bind ABI changes related to CVE-2023-50387 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux enhancements for bind and dhcp tackle urgent security vulnerabilities, boosting functionality and reliability.. Oracle Linux Updates, Bind Security Fix, DHCP Advanced Security, ELSA-2024-3741 Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 13, 2024 Critical Oracle
217

Oracle Linux 9 ELSA-2024-1789 Critical: BIND Network Threat Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1789 https://linux.oracle.com/errata/ELSA-2024-1789.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.16.23-14.el9_3.4.x86_64.rpm bind-chroot-9.16.23-14.el9_3.4.x86_64.rpm bind-dnssec-doc-9.16.23-14.el9_3.4.noarch.rpm bind-dnssec-utils-9.16.23-14.el9_3.4.x86_64.rpm bind-dyndb-ldap-11.9-8.el9_3.3.x86_64.rpm bind-libs-9.16.23-14.el9_3.4.x86_64.rpm bind-license-9.16.23-14.el9_3.4.noarch.rpm bind-utils-9.16.23-14.el9_3.4.x86_64.rpm python3-bind-9.16.23-14.el9_3.4.noarch.rpm bind-devel-9.16.23-14.el9_3.4.i686.rpm bind-devel-9.16.23-14.el9_3.4.x86_64.rpm bind-doc-9.16.23-14.el9_3.4.noarch.rpm bind-libs-9.16.23-14.el9_3.4.i686.rpm aarch64: bind-9.16.23-14.el9_3.4.aarch64.rpm bind-chroot-9.16.23-14.el9_3.4.aarch64.rpm bind-dnssec-doc-9.16.23-14.el9_3.4.noarch.rpm bind-dnssec-utils-9.16.23-14.el9_3.4.aarch64.rpm bind-dyndb-ldap-11.9-8.el9_3.3.aarch64.rpm bind-libs-9.16.23-14.el9_3.4.aarch64.rpm bind-license-9.16.23-14.el9_3.4.noarch.rpm bind-utils-9.16.23-14.el9_3.4.aarch64.rpm python3-bind-9.16.23-14.el9_3.4.noarch.rpm bind-devel-9.16.23-14.el9_3.4.aarch64.rpm bind-doc-9.16.23-14.el9_3.4.noarch.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//bind-9.16.23-14.el9_3.4.src.rpm https://oss.oracle.com:443/ol9/SRPMS-updates//bind-dyndb-ldap-11.9-8.el9_3.3.src.rpm Related CVEs: CVE-2023-4408 CVE-2023-5517 CVE-2023-5679 CVE-2023-6516 CVE-2023-50387 CVE-2023-50868 Description of changes: bind [32:9.16.23-14.4] - Rebuild with correct z-stream tag again [32:9.16.23-14.3] - Rebuild together with bind-dyndb-ldap to adjust ABI changes [32:9.16.23-14.2] - Import tests for large DNS messages fix - Add downstream change complementing CVE-2023-50387 [32:9.16.23-14.1] - Prevent increased CPU load on large DNS messages (CVE-2023-4408) - Prevent assertion failure when nxdomain-redirect is used with RFC 1918reverse zones (CVE-2023-5517) - Prevent assertion failure if DNS64 and serve-stale is used (CVE-2023-5679) - Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) - Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387 CVE-2023-50868) bind-dyndb-ldap [11.9-8.3] - Rebuild with correct z-stream tag again [11.9-8.2] - Rebuild required for BIND changes for KeyTrap change (CVE-2023-50387) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The latest advisory from Oracle Linux 9, ELSA-2024-1790, provides essential patches for OpenSSL, addressing various vulnerabilities.. Oracle Linux Bind Update, Security Advisory ELSA-2024-1789, Network Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 12, 2024 Critical Oracle
99

Slackware 15.0: 2024-044-01 Critical: Bind Denial Of Service

New bind packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bind (SSA:2024-044-01) New bind packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/bind-9.16.48-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and security issues: Specific DNS answers could cause a denial-of-service condition due to DNS validation taking a long time. Query patterns that continuously triggered cache database maintenance could exhaust all available memory on the host running named. Restore DNS64 state when handling a serve-stale timeout. Specific queries could trigger an assertion check with nxdomain-redirect enabled. Speed up parsing of DNS messages with many different names. For more information, see: https://kb.isc.org/docs/cve-2023-50387 https://www.cve.org/CVERecord?id=CVE-2023-50387 https://kb.isc.org/docs/cve-2023-6516 https://www.cve.org/CVERecord?id=CVE-2023-6516 https://kb.isc.org/docs/cve-2023-5679 https://www.cve.org/CVERecord?id=CVE-2023-5679 https://kb.isc.org/docs/cve-2023-5517 https://www.cve.org/CVERecord?id=CVE-2023-5517 https://kb.isc.org/docs/cve-2023-4408 https://www.cve.org/CVERecord?id=CVE-2023-4408 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 688d05942acae07ca040a07057f107af bind-9.16.48-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 72ec1aa452c6b37046e74b90797be3e8 bind-9.16.48-x86_64-1_slack15.0.txz Slackware -current package: 8e3c11dba6a01af76aa89531c2e2d62a n/bind-9.18.24-i586-1.txz Slackware x86_64 -current package: 8a9d10f4a4f1501ffc7f087dec4e281e n/bind-9.18.24-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg bind-9.16.48-i586-1_slack15.0.txz Then, restart the name server: # /etc/rc.d/rc.bind restart +-----+ . A fresh bind update has been released for Slackware 15.0 to resolve urgent security vulnerabilities and improve the reliability of DNS services.. Slackware Bind Security Update, Slackware 15.0 Security, DNS Denial Of Service, Bind Package Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 13, 2024 Critical Slackware
217

Oracle Linux 9: ELSA-2023-5689 Critical: Bind DoS Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-5689 https://linux.oracle.com/errata/ELSA-2023-5689.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.16.23-11.el9_2.2.x86_64.rpm bind-chroot-9.16.23-11.el9_2.2.x86_64.rpm bind-dnssec-doc-9.16.23-11.el9_2.2.noarch.rpm bind-dnssec-utils-9.16.23-11.el9_2.2.x86_64.rpm bind-libs-9.16.23-11.el9_2.2.x86_64.rpm bind-license-9.16.23-11.el9_2.2.noarch.rpm bind-utils-9.16.23-11.el9_2.2.x86_64.rpm python3-bind-9.16.23-11.el9_2.2.noarch.rpm bind-devel-9.16.23-11.el9_2.2.i686.rpm bind-devel-9.16.23-11.el9_2.2.x86_64.rpm bind-doc-9.16.23-11.el9_2.2.noarch.rpm bind-libs-9.16.23-11.el9_2.2.i686.rpm aarch64: bind-9.16.23-11.el9_2.2.aarch64.rpm bind-chroot-9.16.23-11.el9_2.2.aarch64.rpm bind-dnssec-doc-9.16.23-11.el9_2.2.noarch.rpm bind-dnssec-utils-9.16.23-11.el9_2.2.aarch64.rpm bind-libs-9.16.23-11.el9_2.2.aarch64.rpm bind-license-9.16.23-11.el9_2.2.noarch.rpm bind-utils-9.16.23-11.el9_2.2.aarch64.rpm python3-bind-9.16.23-11.el9_2.2.noarch.rpm bind-devel-9.16.23-11.el9_2.2.aarch64.rpm bind-doc-9.16.23-11.el9_2.2.noarch.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//bind-9.16.23-11.el9_2.2.src.rpm Related CVEs: CVE-2023-3341 Description of changes: [32:9.16.23-11.2] - stack exhaustion in control channel code may lead to DoS (CVE-2023-3341) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The Oracle Linux 9 ELSA-2023-5689 advisory features essential updates addressing critical vulnerabilities, including a significant bind DoS fix to enhance system security and prevent exploits. Oracle Linux Advisory, Bind Update, Important Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 16, 2023 Critical Oracle
217

Oracle Linux 7 ELSA-2023-5691 Critical Control Channel Limit CVE-2023-3341

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-5691 https://linux.oracle.com/errata/ELSA-2023-5691.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: bind-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-chroot-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-libs-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-export-libs-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-libs-lite-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-license-9.11.4-26.P2.el7_9.15.noarch.rpm bind-pkcs11-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-pkcs11-libs-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-pkcs11-utils-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-utils-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-export-devel-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-devel-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-lite-devel-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-pkcs11-devel-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-sdb-9.11.4-26.P2.el7_9.15.aarch64.rpm bind-sdb-chroot-9.11.4-26.P2.el7_9.15.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//bind-9.11.4-26.P2.el7_9.15.src.rpm Related CVEs: CVE-2023-3341 Description of changes: [32:9.11.4-26.P2.15] - Limit the amount of recursion possible in control channel (CVE-2023-3341) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Bulletin ELSA-2023-5691 delivers essential fixes for bind to address a vulnerability. Discover more details!. Oracle Linux Security, Bind Update, Important Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2023 Critical Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200