Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
197

Debian 9: DLA-2966-1 Moderate Advisory: Libgc Integer Overflow Issue

libgc, a conservative garbage collector, is vulnerable to integer overflows in multiple places. In some cases, when asked to allocate a huge quantity of memory, instead of failing the request, it will return a . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2966-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz March 30, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libgc Version : 1:7.4.2-8+deb9u1 CVE ID : CVE-2016-9427 libgc, a conservative garbage collector, is vulnerable to integer overflows in multiple places. In some cases, when asked to allocate a huge quantity of memory, instead of failing the request, it will return a pointer to a small amount of memory possibly tricking the application into a buffer overwrite. For Debian 9 stretch, this problem has been fixed in version 1:7.4.2-8+deb9u1. We recommend that you upgrade your libgc packages. For the detailed security status of libgc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libgc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-2022-1252-1 highlights a buffer overflow in libxyz. Ensure your system is updated to mitigate possible risks.. libgc security, debian lts advisories, integer overflow fix, memory management, buffer overwrite. . LinuxSecurity.com Team

Calendar 2 Mar 30, 2022 Debian LTS
100

SUSE: 2021:3456-2 Critical: System Memory Leak Resolution

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP2) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2537-1 Rating: important References: #1174247 Cross-References: CVE-2020-14331 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for the Linux Kernel 5.3.18-24_9 fixes one issue. The following security issue was fixed: - CVE-2020-14331: Fixed a buffer over-write in vgacon_scroll (bsc#1174247). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP2: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2020-2537=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP2 (ppc64le s390x x86_64): kernel-livepatch-5_3_18-24_9-default-2-2.3 kernel-livepatch-5_3_18-24_9-default-debuginfo-2-2.3 kernel-livepatch-SLE15-SP2_Update_1-debugsource-2-2.3 References: https://www.suse.com/security/cve/CVE-2020-14331.html https://bugzilla.suse.com/1174247 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Notification for the Linux Kernel addresses a critical buffer overflow vulnerability. Follow the guidelines for applying the update.. SUSE Security Update, Linux Kernel Fix, Live Patching. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2020 Important SuSE
100

SUSE: 2020:2561-1 Critical: Memory Corruption and TLS Vulnerability

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2534-1 Rating: important References: #1165631 #1174247 Cross-References: CVE-2020-14331 CVE-2020-1749 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Live Patching 12-SP5 SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-197_48 fixes several issues. The following security issues were fixed: - CVE-2020-14331: Fixed a buffer over-write in vgacon_scroll (bsc#1174247). - CVE-2020-1749: Fixed a flaw in IPsec where some IPv6 protocols were not encrypted (bsc#1165631). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2020-2534=1 SUSE-SLE-Module-Live-Patching-15-SP1-2020-2535=1 - SUSE Linux Enterprise Live Patching 12-SP5: zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2020-2518=1 SUSE-SLE-Live-Patching-12-SP5-2020-2519=1 - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2020-2510=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_48-default-2-2.2 kernel-livepatch-4_12_14-197_51-default-2-2.2 - SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64): kgraft-patch-4_12_14-122_29-default-2-2.2 kgraft-patch-4_12_14-122_32-default-2-2.2 - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le s390x x86_64): kgraft-patch-4_12_14-95_57-default-2-2.2 References: https://www.suse.com/security/cve/CVE-2020-14331.html https://www.suse.com/security/cve/CVE-2020-1749.html https://bugzilla.suse.com/1165631 https://bugzilla.suse.com/1174247 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Advisory: Updates addressing two urgent kernel vulnerabilities in Live Patch 13 for SLE 15 SP1 are now released. Click for more information.. SUSE Live Patching, Kernel Update, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2020 Important SuSE
100

SUSE: 2020:2517-1 Important: Kernel Live Patch 6 Critical Fixes Overview

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 6 for SLE 12 SP5) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2517-1 Rating: important References: #1165631 #1174186 #1174247 Cross-References: CVE-2020-14331 CVE-2020-15780 CVE-2020-1749 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Live Patching 12-SP5 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-122_26 fixes several issues. The following security issues were fixed: - CVE-2020-14331: Fixed a buffer over-write in vgacon_scroll (bsc#1174247). - CVE-2020-15780: Fixed a lockdown bypass via injection of malicious ACPI tables via configfs (bsc#1174186). - CVE-2020-1749: Fixed a flaw in IPsec where some IPv6 protocols were not encrypted (bsc#1165631). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2020-2533=1 - SUSE Linux Enterprise Live Patching 12-SP5: zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2020-2516=1 SUSE-SLE-Live-Patching-12-SP5-2020-2517=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_45-default-2-2.2 - SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64): kgraft-patch-4_12_14-122_23-default-2-2.2 kgraft-patch-4_12_14-122_26-default-2-2.2 References: https://www.suse.com/security/cve/CVE-2020-14331.html https://www.suse.com/security/cve/CVE-2020-15780.html https://www.suse.com/security/cve/CVE-2020-1749.html https://bugzilla.suse.com/1165631 https://bugzilla.suse.com/1174186 https://bugzilla.suse.com/1174247 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has issued a crucial Security Update addressing three vulnerabilities within Linux Kernel Live Patch 6 for SLE 12 SP5.. Live Patching, Kernel Patch Issues, SUSE Security Fixes, Linux Kernel Updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2020 Important SuSE
100

SUSE: 2020:2502-1 Important: Kernel Patch Fixes Memory Issues

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2502-1 Rating: important References: #1165631 #1173659 #1173942 #1174247 Cross-References: CVE-2019-16746 CVE-2020-11668 CVE-2020-14331 CVE-2020-1749 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP2-LTSS ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for the Linux Kernel 4.4.180-94_127 fixes several issues. The following security issues were fixed: - CVE-2020-14331: Fixed a buffer over-write in vgacon_scroll (bsc#1174247). - CVE-2019-16746: Fixed a buffer overflow in net/wireless/nl80211.c (bsc#1173659). - CVE-2020-11668: Fixed a memory corruption issue in the Xirlink camera USB driver (bsc#1173942). - CVE-2020-1749: Fixed a flaw in IPsec where some IPv6 protocols were not encrypted (bsc#1165631). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-2500=1 SUSE-SLE-SAP-12-SP3-2020-2501=1 SUSE-SLE-SAP-12-SP3-2020-2502=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-2494=1 SUSE-SLE-SAP-12-SP2-2020-2495=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-2500=1SUSE-SLE-SERVER-12-SP3-2020-2501=1 SUSE-SLE-SERVER-12-SP3-2020-2502=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-2494=1 SUSE-SLE-SERVER-12-SP2-2020-2495=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): kgraft-patch-4_4_180-94_121-default-2-2.2 kgraft-patch-4_4_180-94_121-default-debuginfo-2-2.2 kgraft-patch-4_4_180-94_124-default-2-2.2 kgraft-patch-4_4_180-94_124-default-debuginfo-2-2.2 kgraft-patch-4_4_180-94_127-default-2-2.2 kgraft-patch-4_4_180-94_127-default-debuginfo-2-2.2 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): kgraft-patch-4_4_121-92_135-default-2-2.2 kgraft-patch-4_4_121-92_138-default-2-2.2 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le x86_64): kgraft-patch-4_4_180-94_121-default-2-2.2 kgraft-patch-4_4_180-94_121-default-debuginfo-2-2.2 kgraft-patch-4_4_180-94_124-default-2-2.2 kgraft-patch-4_4_180-94_124-default-debuginfo-2-2.2 kgraft-patch-4_4_180-94_127-default-2-2.2 kgraft-patch-4_4_180-94_127-default-debuginfo-2-2.2 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le x86_64): kgraft-patch-4_4_121-92_135-default-2-2.2 kgraft-patch-4_4_121-92_138-default-2-2.2 References: https://www.suse.com/security/cve/CVE-2019-16746.html https://www.suse.com/security/cve/CVE-2020-11668.html https://www.suse.com/security/cve/CVE-2020-14331.html https://www.suse.com/security/cve/CVE-2020-1749.html https://bugzilla.suse.com/1165631 https://bugzilla.suse.com/1173659 https://bugzilla.suse.com/1173942 https://bugzilla.suse.com/1174247 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a Security Update targeting multiple vulnerabilities in the Linux Kernel, which encompasses corrections for memory corruptionand resolves buffer overflow concerns.. SUSE Linux Enterprise, Kernel Patch, Security Update, Memory Corruption, Buffer Overflow. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2020 Important SuSE
100

SUSE: 2020:2507-1 Important: Kernel Live Patch For SLE 12 SP4

An update that fixes 5 vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 12 for SLE 12 SP4) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2507-1 Rating: important References: #1173659 #1173942 #1173963 #1174186 #1174247 Cross-References: CVE-2019-16746 CVE-2019-9458 CVE-2020-11668 CVE-2020-14331 CVE-2020-15780 Affected Products: SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-95_48 fixes several issues. The following security issues were fixed: - CVE-2020-14331: Fixed a buffer over-write in vgacon_scroll (bsc#1174247). - CVE-2020-15780: Fixed a lockdown bypass via injection of malicious ACPI tables via configfs (bsc#1174186). - CVE-2019-16746: Fixed a buffer overflow in net/wireless/nl80211.c (bsc#1173659). - CVE-2019-9458: Fixed a use-after-free in media/v4l (bsc#1173963). - CVE-2020-11668: Fixed a memory corruption issue in the Xirlink camera USB driver (bsc#1173942). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2020-2507=1 Package List: - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le x86_64): kgraft-patch-4_12_14-95_48-default-5-2.2 References: https://www.suse.com/security/cve/CVE-2019-16746.html https://www.suse.com/security/cve/CVE-2019-9458.html https://www.suse.com/security/cve/CVE-2020-11668.html https://www.suse.com/security/cve/CVE-2020-14331.html https://www.suse.com/security/cve/CVE-2020-15780.html https://bugzilla.suse.com/1173659 https://bugzilla.suse.com/1173942 https://bugzilla.suse.com/1173963 https://bugzilla.suse.com/1174186 https://bugzilla.suse.com/1174247 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Enhance your security measures by applying this critical patch for the Linux Kernel, which resolves numerous threats and concerns.. Linux Kernel Update, SUSE Security Advisory, Important Patch, Kernel Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2020 Important SuSE
172

Ubuntu 14.04 LTS: 0046-1 Moderate: Linux Kernel Security Issues

Several security issues were fixed in the kernel.. =========================================================================Kernel Live Patch Security Notice 0046-1 December 20, 2018 linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu: | Series | Base kernel | Arch | flavors | |------------------+--------------+----------+------------------| | Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic | | Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic | | Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | generic | | Ubuntu 18.04 LTS | 4.15.0 | amd64 | lowlatency | Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: It was discovered that an integer overflow vulnerability existed in the CDRom driver of the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-18710) It was discovered that a race condition existed in the raw MIDI driver for the Linux kernel, leading to a double free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-10902) It was discovered that the BPF verifier in the Linux kernel did not correctly compute numeric bounds in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-18445) Noam Rathaus discovered that a use-after-free vulnerability existed in the Infiniband implementation in the Linux kernel. An attacker could use this to cause a denial of service (system crash). (CVE-2018-14734) Wen Xu discovered that the ext4 filesystem implementation in the Linux kernel did not properly ensure that xattr information remained ininode bodies. An attacker could use this to construct a malicious ext4 image that, when mounted, could cause a denial of service (system crash). (CVE-2018-10880) Kanda Motohiro discovered that writing extended attributes to an XFS file system in the Linux kernel in certain situations could cause an error condition to occur. A local attacker could use this to cause a denial of service. (CVE-2018-18690) It was discovered that an integer overflow existed in the HID Bluetooth implementation in the Linux kernel that could lead to a buffer overwrite. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-9363) Jann Horn discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5753) It was discovered that the YUREX USB device driver for the Linux kernel did not properly restrict user space reads or writes. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-16276) It was discovered that an integer overflow existed in the CD-ROM driver of the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2018-16658) Update instructions: The problem can be corrected by updating your livepatches to the following versions: | Kernel | Version | flavors | |--------------------------+----------+--------------------------| | 4.4.0-133.159 | 46.3 | generic, lowlatency | | 4.4.0-133.159~14.04.1 | 46.3 | lowlatency, generic | | 4.4.0-134.160 | 46.3 | generic, lowlatency | | 4.4.0-134.160~14.04.1 | 46.3 | lowlatency, generic | | 4.4.0-135.161~14.04.1 | 46.3 | lowlatency, generic | | 4.4.0-137.163 | 46.3 | generic, lowlatency | | 4.4.0-137.163~14.04.1 | 46.3 | generic, lowlatency | | 4.4.0-138.164 | 46.3 | generic, lowlatency | | 4.4.0-138.164~14.04.1 | 46.3 | lowlatency, generic | | 4.4.0-139.165 | 46.3 | generic, lowlatency | | 4.4.0-139.165~14.04.1 | 46.3 | lowlatency, generic | | 4.4.0-140.166 | 46.3 | lowlatency, generic | | 4.4.0-140.166~14.04.1 | 46.3 | lowlatency, generic | | 4.15.0-32.35 | 46.3 | lowlatency, generic | | 4.15.0-33.36 | 46.3 | lowlatency, generic | | 4.15.0-34.37 | 46.3 | generic, lowlatency | | 4.15.0-36.39 | 46.3 | generic, lowlatency | | 4.15.0-38.41 | 46.3 | lowlatency, generic | | 4.15.0-39.42 | 46.3 | generic, lowlatency | | 4.15.0-42.45 | 46.3 | lowlatency, generic | References: CVE-2018-18710, CVE-2018-10902, CVE-2018-18445, CVE-2018-14734, CVE-2018-10880, CVE-2018-18690, CVE-2018-9363, CVE-2017-5753, CVE-2018-16276, CVE-2018-16658 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . The latest Ubuntu security advisory reveals critical vulnerabilities in the kernel, necessitating immediate user action to protect against potential exploits. Linux Kernel Security Update, Ubuntu Kernel Fix, System Vulnerability Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 20, 2018 Important Ubuntu
202

openSUSE Leap 15.0 Security Notice: Moderate Severity glibc Buffer Overflow

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for glibc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1633-1 Rating: moderate References: #1092877 #1094154 Cross-References: CVE-2018-11237 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for glibc fixes the following issues: This security issue was fixed: - Fixed an buffer overwrite issue in memcpy for Knights Landing CPUs (boo#1092877, CVE-2018-11237) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-600=1 Package List: - openSUSE Leap 15.0 (i586 i686 x86_64): glibc-2.26-lp150.11.3.2 glibc-debuginfo-2.26-lp150.11.3.2 glibc-debugsource-2.26-lp150.11.3.2 glibc-devel-2.26-lp150.11.3.2 glibc-devel-debuginfo-2.26-lp150.11.3.2 glibc-devel-static-2.26-lp150.11.3.2 glibc-locale-2.26-lp150.11.3.2 glibc-locale-debuginfo-2.26-lp150.11.3.2 glibc-profile-2.26-lp150.11.3.2 - openSUSE Leap 15.0 (i586 x86_64): glibc-extra-2.26-lp150.11.3.2 glibc-extra-debuginfo-2.26-lp150.11.3.2 glibc-utils-2.26-lp150.11.3.2 glibc-utils-debuginfo-2.26-lp150.11.3.2 glibc-utils-src-debugsource-2.26-lp150.11.3.2 nscd-2.26-lp150.11.3.2 nscd-debuginfo-2.26-lp150.11.3.2 - openSUSE Leap 15.0 (noarch): glibc-html-2.26-lp150.11.3.2 glibc-i18ndata-2.26-lp150.11.3.2 glibc-info-2.26-lp150.11.3.2 - openSUSE Leap 15.0 (x86_64): glibc-32bit-2.26-lp150.11.3.2 glibc-32bit-debuginfo-2.26-lp150.11.3.2 glibc-devel-32bit-2.26-lp150.11.3.2 glibc-devel-32bit-debuginfo-2.26-lp150.11.3.2 glibc-devel-static-32bit-2.26-lp150.11.3.2 glibc-locale-32bit-2.26-lp150.11.3.2 glibc-locale-32bit-debuginfo-2.26-lp150.11.3.2 glibc-profile-32bit-2.26-lp150.11.3.2 glibc-utils-32bit-2.26-lp150.11.3.2 glibc-utils-32bit-debuginfo-2.26-lp150.11.3.2 References: https://www.suse.com/security/cve/CVE-2018-11237.html https://bugzilla.suse.com/1092877 https://bugzilla.suse.com/1094154 -- . An announcement regarding openSUSE Leap 15.0 highlights a significant security vulnerability discovered in glibc. Please check the patch details immediately!. openSUSE glibc update, security patch glibc, buffer overwrite fix. . LinuxSecurity.com Team

Calendar 2 Jun 09, 2018 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here