Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 19 articles for you...
197

Debian 10: DLA-3813-1 moderate: shim bootloader security fix

This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3813-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès May 13, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : shim Version : 15.8-1~deb10u1 CVE ID : CVE-2023-40546 CVE-2023-40547 CVE-2023-40548 CVE-2023-40549 CVE-2023-40550 CVE-2023-40551 Debian Bug : 1046268 1069054 This release fixes various issues in shim bootloader and updates it to a supported version. Older versions of the shim may eventually be blocked by Secure Boot, so it is strongly advised for Secure Boot enabled systems to upgrade to this newer version to keep the system bootable. For Debian 10 buster, this problem has been fixed in version 15.8-1~deb10u1. We recommend that you upgrade your shim packages. For the detailed security status of shim please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/shim Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS Notification USN-1234-1 provides patches for kernel vulnerabilities to enhance system security and performance.. Debian LTS, shim update, secure boot, bootloader fixes, Linux security. . LinuxSecurity.com Team

Calendar 2 May 14, 2024 Debian LTS
89

Fedora 39: FEDORA-2024-d09797f550 Critical GRUB2 Out-of-Bounds Fix

Security fix for CVE-2023-4692 Security fix for CVE-2023-4693 Fri Apr 12 2024 Nicolas Frayer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-120 fs/xfs: Handle non-continuous data blocks in directory extents Related: #2254370. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d09797f550 2024-04-29 01:55:07.473291 -------------------------------------------------------------------------------- Name : grub2 Product : Fedora 39 Version : 2.06 Release : 120.fc39 URL : Summary : Bootloader with support for Linux, Multiboot and more Description : The GRand Unified Bootloader (GRUB) is a highly configurable and customizable bootloader with modular architecture. It supports a rich variety of kernel formats, file systems, computer architectures and hardware devices. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-4692 Security fix for CVE-2023-4693 Fri Apr 12 2024 Nicolas Frayer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-120 fs/xfs: Handle non-continuous data blocks in directory extents Related: #2254370 Fri Mar 08 2024 Nicolas Frayer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-119 GRUB2 NTFS driver vulnerabilities (CVE-2023-4692) (CVE-2023-4693) Resolves: #2236613 Resolves: #2241978 Resolves: #2241976 Resolves: #2238343 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 12 2024 Nicolas Frayer - 2.06-120 - fs/xfs: Handle non-continuous data blocks in directory extents - Related: #2254370 * Fri Mar 8 2024 Nicolas Frayer - 2.06-119 - GRUB2 NTFS driver vulnerabilities - (CVE-2023-4692) - (CVE-2023-4693) - Resolves: #2236613 - Resolves: #2241978 - Resolves: #2241976 - Resolves: #2238343 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236613 - CVE-2023-4692 grub2: Out-of-bounds write at fs/ntfs.c may lead to unsigned codeexecution https://bugzilla.redhat.com/show_bug.cgi?id=2236613 [ 2 ] Bug #2238343 - CVE-2023-4693 grub2: out-of-bounds read at fs/ntfs.c https://bugzilla.redhat.com/show_bug.cgi?id=2238343 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d09797f550' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Ubuntu 23 updates critical kernel vulnerabilities for enhanced protection and system reliability.. Fedora Grub2 Updates, Security Fix, Bootloader Vulnerabilities, Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 29, 2024 Critical Fedora
89

Fedora 38: 2024-2aa28a4cfc critical: shim UEFI bootloader risk

Update to shim-15.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2aa28a4cfc 2024-03-18 02:16:41.812974 -------------------------------------------------------------------------------- Name : shim-unsigned-x64 Product : Fedora 38 Version : 15.8 Release : 2 URL : https://github.com/rhboot/shim Summary : First-stage UEFI bootloader Description : Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments. -------------------------------------------------------------------------------- Update Information: Update to shim-15.8 -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 20 2024 Peter Jones - 15.8-2 - Fix some minor problems caught in review. * Mon Dec 11 2023 Peter Jones - 15.8-1 - Update to shim-15.8 Resolves: CVE-2023-40546 Resolves: CVE-2023-40547 Resolves: CVE-2023-40548 Resolves: CVE-2023-40549 Resolves: CVE-2023-40550 Resolves: CVE-2023-40551 Resolves: rhbz#2113005 Resolves: rhbz#2189197 Resolves: rhbz#2238884 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2113005 - Live image made with BOOTX64.EFI from latest shim-x64-15.6-2 fails to boot on some boards https://bugzilla.redhat.com/show_bug.cgi?id=2113005 [ 2 ] Bug #2198977 - Secure boot shim cert seems to be out of date (exp. Dec. 2022) https://bugzilla.redhat.com/show_bug.cgi?id=2198977 [ 3 ] Bug #2238884 - Version bump to 15.7 https://bugzilla.redhat.com/show_bug.cgi?id=2238884 [ 4 ] Bug #2259264 - Fedora fails to boot via BOOT/bootaa64-> fbaa64 on UEFI machines with EFI_MEMORY_ATTRIBUTES_PROTOCOL https://bugzilla.redhat.com/show_bug.cgi?id=2259264 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2024-2aa28a4cfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest enhancement for shim-unsigned-x64 in Fedora 38 strengthens UEFI bootloader protection. Ensure your device is secure with this essential update.. Fedora 38, shim-unsigned-x64, UEFI, Bootloader Issue, System Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2024 Critical Fedora
89

Fedora 38: 2024-2aa28a4cfc Critical: shim UEFI Bootloader Update

Update to shim-15.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2aa28a4cfc 2024-03-18 02:16:41.812974 -------------------------------------------------------------------------------- Name : shim-unsigned-aarch64 Product : Fedora 38 Version : 15.8 Release : 2 URL : https://github.com/rhboot/shim Summary : First-stage UEFI bootloader Description : Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments. -------------------------------------------------------------------------------- Update Information: Update to shim-15.8 -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 7 2024 Peter Jones - 15.8-2 - Update to shim-15.8 Resolves: CVE-2023-40546 Resolves: CVE-2023-40547 Resolves: CVE-2023-40548 Resolves: CVE-2023-40549 Resolves: CVE-2023-40550 Resolves: CVE-2023-40551 Resolves: rhbz#2113005 Resolves: rhbz#2189197 Resolves: rhbz#2238884 Resolves: rhbz#2259264 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2113005 - Live image made with BOOTX64.EFI from latest shim-x64-15.6-2 fails to boot on some boards https://bugzilla.redhat.com/show_bug.cgi?id=2113005 [ 2 ] Bug #2198977 - Secure boot shim cert seems to be out of date (exp. Dec. 2022) https://bugzilla.redhat.com/show_bug.cgi?id=2198977 [ 3 ] Bug #2238884 - Version bump to 15.7 https://bugzilla.redhat.com/show_bug.cgi?id=2238884 [ 4 ] Bug #2259264 - Fedora fails to boot via BOOT/bootaa64-> fbaa64 on UEFI machines with EFI_MEMORY_ATTRIBUTES_PROTOCOL https://bugzilla.redhat.com/show_bug.cgi?id=2259264 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2024-2aa28a4cfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 security bulletin regarding shim-unsigned-aarch64 2024-2aa28a4cfc comprises essential updates and crucial patches.. shim-unsigned,aarch64,security advisory,Fedora 38,EFI bootloader. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2024 Critical Fedora
89

Fedora 38: FEDORA-2024-2aa28a4cfc critical: shim secure boot update

Update to shim-15.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2aa28a4cfc 2024-03-18 02:16:41.812974 -------------------------------------------------------------------------------- Name : shim Product : Fedora 38 Version : 15.8 Release : 2 URL : https://github.com/rhboot/shim/ Summary : First-stage UEFI bootloader Description : Initial UEFI bootloader that handles chaining to a trusted full bootloader under secure boot environments. This package contains the version signed by the UEFI signing service. -------------------------------------------------------------------------------- Update Information: Update to shim-15.8 -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 12 2024 Peter Jones - 15.8-2 - Update to shim-15.8 Resolves: CVE-2023-40546 Resolves: CVE-2023-40547 Resolves: CVE-2023-40548 Resolves: CVE-2023-40549 Resolves: CVE-2023-40550 Resolves: CVE-2023-40551 Resolves: rhbz#2113005 Resolves: rhbz#2189197 Resolves: rhbz#2238884 Resolves: rhbz#2259264 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2113005 - Live image made with BOOTX64.EFI from latest shim-x64-15.6-2 fails to boot on some boards https://bugzilla.redhat.com/show_bug.cgi?id=2113005 [ 2 ] Bug #2198977 - Secure boot shim cert seems to be out of date (exp. Dec. 2022) https://bugzilla.redhat.com/show_bug.cgi?id=2198977 [ 3 ] Bug #2238884 - Version bump to 15.7 https://bugzilla.redhat.com/show_bug.cgi?id=2238884 [ 4 ] Bug #2259264 - Fedora fails to boot via BOOT/bootaa64-> fbaa64 on UEFI machines with EFI_MEMORY_ATTRIBUTES_PROTOCOL https://bugzilla.redhat.com/show_bug.cgi?id=2259264 -------------------------------------------------------------------------------- This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2024-2aa28a4cfc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent update for shim-15.8 in Fedora 38 resolves several security vulnerabilities and improves secure boot functionalities.. Fedora 38 Security, Shim Update, Secure Boot, Bootloader Enhancement. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2024 Critical Fedora
89

Fedora 2024-633dc7e183: Critical Grub2 Bypass Vulnerability Detected

Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer - 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin - 2.06-113 Switch memdisk compression to lzop . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-633dc7e183 2024-02-05 01:45:31.502538 -------------------------------------------------------------------------------- Name : grub2 Product : Fedora 38 Version : 2.06 Release : 114.fc38 URL : Summary : Bootloader with support for Linux, Multiboot and more Description : The GRand Unified Bootloader (GRUB) is a highly configurable and customizable bootloader with modular architecture. It supports a rich variety of kernel formats, file systems, computer architectures and hardware devices. -------------------------------------------------------------------------------- Update Information: Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer - 2.06-114 grub- core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin - 2.06-113 Switch memdisk compression to lzop Thu Jan 11 2024 Daan De Meyer - 2.06-112 Don't obsolete the tools package with minimal Mon Jan 8 2024 Nicolas Frayer - 2.06-111 xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches Resolves: #2254370 Tue Dec 19 2023 Nicolas Frayer - 2.06-110 normal: fix prefix when loading modules Resolves: #2209435 Resolves: #2173015 Tue Dec 12 2023 leo sandoval - 2.06-109 chainloader: remove device path debug message``` -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 15 2024 Nicolas Frayer - 2.06-114 - grub-core/commands: add flag to only search root dev - Resolves: #2223437 - Resolves: #2224951 - Resolves: #2258096 - Resolves: CVE-2023-4001 * Sat Jan 13 2024 Hector Martin - 2.06-113 - Switch memdisk compression to lzop * Thu Jan 11 2024 Daan De Meyer - 2.06-112 - Don't obsolete the tools package with minimal * Mon Jan 8 2024 Nicolas Frayer - 2.06-111 - xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches - Resolves: #2254370 * Tue Dec 19 2023 Nicolas Frayer - 2.06-110 - normal: fix prefix when loading modules - Resolves: #2209435 - Resolves: #2173015 * Tue Dec 12 2023 leo sandoval - 2.06-109 - chainloader: remove device path debug message -------------------------------------------------------------------------------- References: [ 1 ] Bug #2224951 - CVE-2023-4001 grub2: bypass the GRUB password protection feature https://bugzilla.redhat.com/show_bug.cgi?id=2224951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-633dc7e183' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora's latest update tackles serious grub2 vulnerabilities, specifically the CVE-2023-4001 bypass. Follow the commands to update, reinstall grub2, and regenerate the config.. Fedora Updates, Grub2 Security Fix, Fedora Bootloader Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 05, 2024 Critical Fedora
89

Fedora 39: FEDORA-2024-53d986312e moderate: grub2 Security Fix

Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-116 grub-core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-115 Switch memdisk compression to lzop Thu Jan. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-53d986312e 2024-02-05 01:23:58.726586 -------------------------------------------------------------------------------- Name : grub2 Product : Fedora 39 Version : 2.06 Release : 116.fc39 URL : Summary : Bootloader with support for Linux, Multiboot and more Description : The GRand Unified Bootloader (GRUB) is a highly configurable and customizable bootloader with modular architecture. It supports a rich variety of kernel formats, file systems, computer architectures and hardware devices. -------------------------------------------------------------------------------- Update Information: Combined update for several fixes as well as security fix for CVE-2023-4001 ``` Mon Jan 15 2024 Nicolas Frayer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-116 grub-core/commands: add flag to only search root dev Resolves: #2223437 Resolves: #2224951 Resolves: #2258096 Resolves: CVE-2023-4001 Sat Jan 13 2024 Hector Martin This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-115 Switch memdisk compression to lzop Thu Jan 11 2024 Daan De Meyer This email address is being protected from spambots. You need JavaScript enabled to view it. - 2.06-114 Don't obsolete the tools package with minimal Mon Jan 8 2024 Nicolas Frayer - 2.06-113 xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches Resolves: #2254370 Tue Dec 19 2023 Nicolas Frayer - 2.06-112 normal: fix prefix when loading modules Resolves: #2209435 Resolves: #2173015 Tue Dec 12 2023 leo sandoval - 2.06-111 chainloader: remove device pathdebug message ``` -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 15 2024 Nicolas Frayer - 2.06-116 - grub-core/commands: add flag to only search root dev - Resolves: #2223437 - Resolves: #2224951 - Resolves: #2258096 - Resolves: CVE-2023-4001 * Sat Jan 13 2024 Hector Martin - 2.06-115 - Switch memdisk compression to lzop * Thu Jan 11 2024 Daan De Meyer - 2.06-114 - Don't obsolete the tools package with minimal * Mon Jan 8 2024 Nicolas Frayer - 2.06-113 - xfs: some bios systems with /boot partition created with xfsprog < 6.5.0 can't boot with one of the xfs upstream patches - Resolves: #2254370 * Tue Dec 19 2023 Nicolas Frayer - 2.06-112 - normal: fix prefix when loading modules - Resolves: #2209435 - Resolves: #2173015 * Tue Dec 12 2023 leo sandoval - 2.06-111 - chainloader: remove device path debug message -------------------------------------------------------------------------------- References: [ 1 ] Bug #2224951 - CVE-2023-4001 grub2: bypass the GRUB password protection feature https://bugzilla.redhat.com/show_bug.cgi?id=2224951 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-53d986312e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Comprehensive revision for Fedora 39 tackling improvements and a vulnerability in grub2, boosting overall system reliability and protection.. Fedora Update, Grub2 Fixes, Bootloader Security. . LinuxSecurity.com Team

Calendar 2 Feb 05, 2024 Fedora
172

Ubuntu 22.04 LTS USN-6355-1 Moderate: GRUB2 Security Flaws

Several security issues were fixed in GRUB2.. ========================================================================== Ubuntu Security Notice USN-6355-1 September 08, 2023 grub2-signed, grub2-unsigned, shim, and shim-signed vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in GRUB2. Software Description: - grub2-signed: GRand Unified Bootloader - grub2-unsigned: GRand Unified Bootloader - shim: boot loader to chain-load signed boot loaders under Secure Boot - shim-signed: Secure Boot chain-loading bootloader (Microsoft-signed binary) Details: Daniel Axtens discovered that specially crafted images could cause a heap-based out-of-bonds write. A local attacker could possibly use this to circumvent secure boot protections. (CVE-2021-3695) Daniel Axtens discovered that specially crafted images could cause out-of-bonds read and write. A local attacker could possibly use this to circumvent secure boot protections. (CVE-2021-3696) Daniel Axtens discovered that specially crafted images could cause buffer underwrite which allows arbitrary data to be written to a heap. A local attacker could possibly use this to circumvent secure boot protections. (CVE-2021-3697) It was discovered that GRUB2 configuration files were created with the wrong permissions. An attacker could possibly use this to leak encrypted passwords. (CVE-2021-3981) Daniel Axtens discovered that specially crafted IP packets could cause an integer underflow and write past the end of a bugger. An attacker could possibly use this to circumvent secure boot protections. (CVE-2022-28733) Daniel Axtens discovered that specially crafted HTTP headers can cause an out-of-bounds write of a NULL byte. An attacker could possibly use this to corrupt GRUB2's internal data. (CVE-2022-28734) Julian Andres Klodediscovered that GRUB2 shim_lock allowed non- kernel files to be loaded. A local attack could possibly use this to circumvent secure boot protections. (CVE-2022-28735) Chris Coulson discovered that executing chainloaders more than once caused a use-after-free vulnerability. A local attack could possibly use this to circumvent secure boot protections. (CVE-2022-28736) Chris Coulson discovered that specially crafted executables could cause shim to make out-of-bound writes. A local attack could possibly use this to circumvent secure boot protections. (CVE-2022-28737) Zhang Boyang discovered that specially crafted unicode sequences could lead to an out-of-bounds write to a heap. A local attacker could possibly use this to circumvent secure boot protections. (CVE-2022-3775) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: grub-efi-amd64 2.06-2ubuntu14.1 grub-efi-amd64-bin 2.06-2ubuntu14.1 grub-efi-amd64-signed 1.187.3~22.04.1+2.06-2ubuntu14.1 grub-efi-arm64 2.06-2ubuntu14.1 grub-efi-arm64-bin 2.06-2ubuntu14.1 grub-efi-arm64-signed 1.187.3~22.04.1+2.06-2ubuntu14.1 shim 15.7-0ubuntu1 shim-signed 1.51.3+15.7-0ubuntu1 Ubuntu 20.04 LTS: grub-efi-amd64 2.06-2ubuntu14.1 grub-efi-amd64-bin 2.06-2ubuntu14.1 grub-efi-amd64-signed 1.187.3~20.04.1+2.06-2ubuntu14.1 grub-efi-arm64 2.06-2ubuntu14.1 grub-efi-arm64-bin 2.06-2ubuntu14.1 grub-efi-arm64-signed 1.187.3~20.04.1+2.06-2ubuntu14.1 shim 15.7-0ubuntu1 shim-signed 1.40.9+15.7-0ubuntu1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6355-1 CVE-2021-3695, CVE-2021-3696,CVE-2021-3697, CVE-2021-3981, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735, CVE-2022-28736, CVE-2022-28737, CVE-2022-3775,https://bugs.launchpad.net/ubuntu/+source/grub2-unsigned/+bug/2029518 Package Information: https://launchpad.net/ubuntu/+source/grub2-signed/1.187.3~22.04.1 https://launchpad.net/ubuntu/+source/grub2-unsigned/2.06-2ubuntu14.1 https://launchpad.net/ubuntu/+source/shim/15.7-0ubuntu1 https://launchpad.net/ubuntu/+source/shim-signed/1.51.3 https://launchpad.net/ubuntu/+source/grub2-signed/1.187.3~20.04.1 https://launchpad.net/ubuntu/+source/grub2-unsigned/2.06-2ubuntu14.1 https://launchpad.net/ubuntu/+source/shim/15.7-0ubuntu1 https://launchpad.net/ubuntu/+source/shim-signed/1.40.9 . Multiple security flaws found in GRUB2 patched in Ubuntu security advisory USN-6355-1. Ensure your system's safety by updating immediately.. grub2 update, Ubuntu security, bootloader vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 08, 2023 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here