Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
202

openSUSE: glib2 Moderate Memory Corruption Fix CVE-2025-4373 2025:02375-1

An update that solves one vulnerability can now be installed.. # Security update for glib2 Announcement ID: SUSE-SU-2025:02375-1 Release Date: 2025-07-18T13:16:28Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2375=1 ## Package List: * openSUSE Leap 15.4 (noarch) * gio-branding-upstream-2.70.5-150400.3.23.1 * glib2-lang-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tests-devel-2.70.5-150400.3.23.1 * glib2-doc-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-2.70.5-150400.3.23.1 * glib2-devel-2.70.5-150400.3.23.1 * glib2-devel-static-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (x86_64) * glib2-tools-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-32bit-2.70.5-150400.3.23.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib2-tools-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.23.1 *glib2-devel-64bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.23.1 * glib2-tools-64bit-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 *libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . Significant notice regarding glib2 addresses potential integer overflow and memory corruption vulnerabilities on openSUSE systems. Suggested patch is ready for implementation.. glib2 update, openSUSE patch, memory corruption fix, security fix. . LinuxSecurity.com Team

Calendar%202 Jul 18, 2025 OpenSUSE
100

openSUSE Leap 15.4: glib2 Moderate Memory Corruption Risk CVE-2025-4373

* bsc#1242844 Cross-References: * CVE-2025-4373 . # Security update for glib2 Announcement ID: SUSE-SU-2025:02375-1 Release Date: 2025-07-18T13:16:28Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2375=1 ## Package List: * openSUSE Leap 15.4 (noarch) * gio-branding-upstream-2.70.5-150400.3.23.1 * glib2-lang-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tests-devel-2.70.5-150400.3.23.1 * glib2-doc-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-2.70.5-150400.3.23.1 * glib2-devel-2.70.5-150400.3.23.1 * glib2-devel-static-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (x86_64) * glib2-tools-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-32bit-2.70.5-150400.3.23.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib2-tools-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.23.1 *glib2-devel-64bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.23.1 * glib2-tools-64bit-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 *libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . A critical security alert has been issued for openSUSE regarding a notable glib2 memory leak vulnerability, CVE-2025-4374. Immediate measures recommended!. SUSE Security, glib2 Update, CVE-2025-4373, Buffer Underwrite Fix, openSUSE Advisory. . LinuxSecurity.com Team

Calendar%202 Jul 18, 2025 SuSE
100

SUSE: 2025:01880-1 moderate: glib2 buffer underwrite vulnerability

* bsc#1242844 Cross-References: * CVE-2025-4373 . # Security update for glib2 Announcement ID: SUSE-SU-2025:01880-1 Release Date: 2025-06-11T05:41:48Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-1880=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1880=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1880=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 *libgio-2_0-0-2.62.6-150200.3.30.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 * libgio-2_0-0-2.62.6-150200.3.30.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 * libgio-2_0-0-2.62.6-150200.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . SUSE Linux Enterprise Micro has issued an important update for glib2, addressing a significant integer overflow vulnerability to enhance system security and stability. glib2 update,SUSE security advisory,buffer underwrite fix,SUSE Linux Micro. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2025 SuSE
98

Red Hat Software: RHSA-2023-4039-01 Important: c-ares Denial of Service

An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs security update Advisory ID: RHSA-2023:4039-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2023:4039 Issue date: 2023-07-12 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for RHEL Workstation(v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for RHEL(v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Software Collections for RHEL Workstation(v. 7): Source: rh-nodejs14-nodejs-14.21.3-4.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.21.3-4.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.s390x.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.x86_64.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.x86_64.rpm Red Hat Software Collections for RHEL(v. 7): Source: rh-nodejs14-nodejs-14.21.3-4.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.21.3-4.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.x86_64.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkrqzNAAoJENzjgjWX9erESuAP/ibSBdF1DR/I/vUgD2OqpvaH evULtjwOdp31vlestbl+DM3DrhyUb1fbscYHSVwK+PHC0nHlhUmSUghjLKQS2JU/ udMBSUbDfLw950fGcS3lp/DT5sAvchPXQy2GYjOdjwZVJAsE52ecetzdd3G2xc+0 cNn0XcRuSPFtkS47sPkeZdlHd17RDy2fgIHsTrJ9wm4lO7az3pqNqSegrLpIVbXr Y+S+I+yVmlasQ9/l6BUG3JTp5zsQpItWF8DkXvPrv59saLRLo+Vz8ursOjWW0ihE DnMg0hznfknP0FmEr1o70AcEzhSBSvA0X4qlUttORdhoaN8KLtaXjNiMVMke4asw prvDiJCoPO7y2pZFIw2oRt0d92/xZRE5T6t0UhGw1hejMPPKP7tcTsTpzoGtWHw3 VzgD322B7I6hSqJP1q18Q1bG2m7hm4QtxTSF+557VjBFMpqPSiKDRkUnb7CigJuz wgaKN2IP1iTeIOpjZpnBa0EiPszUmSN+FxSqo/1BchQSGomaONWk5XJtVYSO4ZYm Uo4qiM6p1EE5jMuBgkHwml5uY4EAemyHfGWobyjrylF4aGYZ11iYJayTIcZktmzC bTT3Mwdj4d2l+fgyf7s38tA5hgpD3fgdF9TH+FTtEJUmJucBF47P/A01v5RypfAC wcnuYaT1q7Bg8mySBCqN =FTmv -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch for rh-nodejs14-nodejs from Red Hat resolves critical issues including DoS attacks and buffer underflow vulnerabilities.. Red Hat Software, Node.js Security Patch, c-ares Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 12, 2023 Important Red Hat
98

Red Hat Enterprise Linux 9.0: RHSA-2023-4036-01 Important Node.js Update

An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs security update Advisory ID: RHSA-2023:4036-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4036 Issue date: 2023-07-12 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update,which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.9.0): Source: nodejs-16.18.1-4.el9_0.src.rpm aarch64: nodejs-16.18.1-4.el9_0.aarch64.rpm nodejs-debuginfo-16.18.1-4.el9_0.aarch64.rpm nodejs-debugsource-16.18.1-4.el9_0.aarch64.rpm nodejs-full-i18n-16.18.1-4.el9_0.aarch64.rpm nodejs-libs-16.18.1-4.el9_0.aarch64.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.aarch64.rpm npm-8.19.2-1.16.18.1.4.el9_0.aarch64.rpm noarch: nodejs-docs-16.18.1-4.el9_0.noarch.rpm ppc64le: nodejs-16.18.1-4.el9_0.ppc64le.rpm nodejs-debuginfo-16.18.1-4.el9_0.ppc64le.rpm nodejs-debugsource-16.18.1-4.el9_0.ppc64le.rpm nodejs-full-i18n-16.18.1-4.el9_0.ppc64le.rpm nodejs-libs-16.18.1-4.el9_0.ppc64le.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.ppc64le.rpm npm-8.19.2-1.16.18.1.4.el9_0.ppc64le.rpm s390x: nodejs-16.18.1-4.el9_0.s390x.rpm nodejs-debuginfo-16.18.1-4.el9_0.s390x.rpm nodejs-debugsource-16.18.1-4.el9_0.s390x.rpm nodejs-full-i18n-16.18.1-4.el9_0.s390x.rpm nodejs-libs-16.18.1-4.el9_0.s390x.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.s390x.rpm npm-8.19.2-1.16.18.1.4.el9_0.s390x.rpm x86_64: nodejs-16.18.1-4.el9_0.x86_64.rpm nodejs-debuginfo-16.18.1-4.el9_0.i686.rpm nodejs-debuginfo-16.18.1-4.el9_0.x86_64.rpm nodejs-debugsource-16.18.1-4.el9_0.i686.rpm nodejs-debugsource-16.18.1-4.el9_0.x86_64.rpm nodejs-full-i18n-16.18.1-4.el9_0.x86_64.rpm nodejs-libs-16.18.1-4.el9_0.i686.rpm nodejs-libs-16.18.1-4.el9_0.x86_64.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.i686.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.x86_64.rpm npm-8.19.2-1.16.18.1.4.el9_0.x86_64.rpm Thesepackages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkrqy8AAoJENzjgjWX9erEKJ8QAJxKxAA+Y+Pv8URTAy4Q9Hby E+tojNCd1nX9i1+8CWk62BDjYUujxE4URawpZi5XhLY4DvNYxlkExR6VouoKumno fJoBiAAPsjLnNfUECQpSrwfwmdB6b8q0LQQGNYIuKXdKYW/udBddDtXVrlCFjAsK FCQbBL4/a/TWnT7AXU513p845+d8zeGQ6gEw4mstTbnGsg/jj69h6H7TYdsW1Eq3 BnF/0GtDyiNKv3GgvWuXe8WQili1kYTZLDUnsm2onljuGJzQGxrmXkR8GZ/131+6 oFB0exQWwyru5kUu76LFSDjyABpsd4rP2Jjdk7x4nlrmIEvxqzRgW+dF43Ucvxau RiDltNUnSuEI1yoT11Safd2qojfRA7PCl6D28cUG0fgVIzhqlWGIOvNkhBp05wS0 gmuAL15WJzF+9o77/ZPqbWjB6xDYRgHrKtMYLHRCdrPSCu5ErafLggggUi60D1yq WCioRmMjBtuklklb/z8g+E7XrCSXff4usCDldJc7IhikQc2IKpkkGi44M6ELntdI ujOhsZjH0bmW6wz88RKEigCT6icHrwX3uElUYdj56WLwB8NKDmUgn11WijbTg7+T /arXJ7L93JuaJ9v9OR4+AO2jx5cME/vMtXaFhJzXhuMx2RTiXdNSCQG9Yh/FeO5v 1OyLwi0IsLapSJL6mjTN =0cqs -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat releases a critical notice regarding a security patch for nodejs impacting various architectures on RHEL 9.0 EUS.. Red Hat nodejs security update, enterprise Linux security, important nodejs fix, software update advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 12, 2023 Important Red Hat
219

Rocky Linux 9 RLSA-2023:3577 Important Nodejs Denial of Service Threat

Important: nodejs:18 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:3577", "synopsis": "Important: nodejs:18 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067)\n\n* c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130)\n\n* c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147)\n\n* c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2209494", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209494", "description": ""}, {"ticket": "2209497", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209497", "description": ""}, {"ticket": "2209501", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209501", "description": ""}, {"ticket": "2209502", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209502", "description": ""}], "cves": [{"name": "CVE-2023-31124", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31124", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-31130","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31130", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-31147", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31147", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-32067", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-32067", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-06-24T18:53:41.228929Z", "rpms": {"Rocky Linux 9": {"nvras": ["nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-docs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm","nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-nodemon-0:2.0.20-2.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-nodemon-0:2.0.20-2.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-packaging-0:2021.06-4.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-packaging-0:2021.06-4.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-packaging-bundler-0:2021.06-4.module+el9.2.0+14843+acebbfea.noarch.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.s390x.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Urgent security patch for nodejs:18 on Rocky Linux resolves various vulnerabilities, providing crucial improvements.. Nodejs Security Update, Rocky Linux Security, Nodejs Issues, Important Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2023 Important Rocky Linux
98

Red Hat Enterprise Linux 9 RHSA-2023:3586-01 Important Node.js Update

An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs security update Advisory ID: RHSA-2023:3586-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3586 Issue date: 2023-06-14 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: nodejs-16.19.1-2.el9_2.src.rpm aarch64: nodejs-16.19.1-2.el9_2.aarch64.rpm nodejs-debuginfo-16.19.1-2.el9_2.aarch64.rpm nodejs-debugsource-16.19.1-2.el9_2.aarch64.rpm nodejs-full-i18n-16.19.1-2.el9_2.aarch64.rpm nodejs-libs-16.19.1-2.el9_2.aarch64.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.aarch64.rpm npm-8.19.3-1.16.19.1.2.el9_2.aarch64.rpm noarch: nodejs-docs-16.19.1-2.el9_2.noarch.rpm ppc64le: nodejs-16.19.1-2.el9_2.ppc64le.rpm nodejs-debuginfo-16.19.1-2.el9_2.ppc64le.rpm nodejs-debugsource-16.19.1-2.el9_2.ppc64le.rpm nodejs-full-i18n-16.19.1-2.el9_2.ppc64le.rpm nodejs-libs-16.19.1-2.el9_2.ppc64le.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.ppc64le.rpm npm-8.19.3-1.16.19.1.2.el9_2.ppc64le.rpm s390x: nodejs-16.19.1-2.el9_2.s390x.rpm nodejs-debuginfo-16.19.1-2.el9_2.s390x.rpm nodejs-debugsource-16.19.1-2.el9_2.s390x.rpm nodejs-full-i18n-16.19.1-2.el9_2.s390x.rpm nodejs-libs-16.19.1-2.el9_2.s390x.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.s390x.rpm npm-8.19.3-1.16.19.1.2.el9_2.s390x.rpm x86_64: nodejs-16.19.1-2.el9_2.x86_64.rpm nodejs-debuginfo-16.19.1-2.el9_2.i686.rpm nodejs-debuginfo-16.19.1-2.el9_2.x86_64.rpm nodejs-debugsource-16.19.1-2.el9_2.i686.rpm nodejs-debugsource-16.19.1-2.el9_2.x86_64.rpm nodejs-full-i18n-16.19.1-2.el9_2.x86_64.rpm nodejs-libs-16.19.1-2.el9_2.i686.rpm nodejs-libs-16.19.1-2.el9_2.x86_64.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.i686.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.x86_64.rpm npm-8.19.3-1.16.19.1.2.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIm3NNzjgjWX9erEAQi54Q/9EZNTfzn3FhZnN0dcNC+35JzC3SvI4yOZ nzwZpGoBgDmwaiYeQHDyMtz3saiw2FpnuQ017X8a9RhWm0CT6GsSXGDO9VDrEGBq ZlxqkeVedwFDATpzDS5TbvPcmoMwlzlu5kUHdx7yuxRwaYHwo/nVzU5DvSYifMsS ddT8yaRhFkYbBMwsihsrS1ej+BVtRHomrukNi3hcVHvEWEqTtbxfCBRbUCY0uVWa R7qhcHyT9HoRkiHvEb1V803tAQQOWeiUnFqQ6FMEMPRUEfTtGCYpS9uiGRkG3iyT 5+NJbeE7W/mGY7clAjjmg+PDVgm8F37p5pazaPs2pNQ2hGZHrCgLBIBd0bd8Bho/ q9P6/CgiRqz5WCs3/bKI38VC2LEz2HBMvR/iRlA6JgmKJ/RvXb74C+oWLaHiHDN9 NMavfp4WlD4NbkdhbaFG9a5wguj3ehLhUTZ9Zc9OtwpoBi+uXjVwtxQcR4nZ4sSh w3/CJ/bTYpTTeT5SkDwn8T4P5Nb3xqPVlfKafXi+t3dL2DkZieG14BykYS33tLlb U/RbzFrpN+5St3QWqS3ZDqvijKaWqIWuWYyyoYlV472SADexTDfuRIgaaTBtb55o T/5BZkBwLyTTeZNwHNWMsqlC5ufDZzoAKPN2mv7zqKGEA1hakrNWtWkfmqbUo4Iq fitA5BLFCJA=LPTx -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important Node.js security enhancement for Red Hat Enterprise Linux 9 addresses significant flaws and provides GPG verified packages.. nodejs security update, important vulnerabilities, Red Hat advisory, software updates, security impact. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 14, 2023 Important Red Hat
98

Red Hat Enterprise Linux 9 RHSA-2023:3577-01 Important Node.js Update

An update for the nodejs:18 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs:18 security update Advisory ID: RHSA-2023:3577-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3577 Issue date: 2023-06-14 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for the nodejs:18 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.src.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0.z+18497+a402347c.src.rpm nodejs-packaging-2021.06-4.module+el9.1.0+15718+e52ec601.src.rpm aarch64: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.aarch64.rpm noarch: nodejs-docs-18.14.2-3.module+el9.2.0.z+18964+42696395.noarch.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0.z+18497+a402347c.noarch.rpm nodejs-packaging-2021.06-4.module+el9.1.0+15718+e52ec601.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el9.1.0+15718+e52ec601.noarch.rpm ppc64le: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.ppc64le.rpm s390x: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.s390x.rpm x86_64: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIm3ENzjgjWX9erEAQjQ+w//XwePu+NM3an0O53dk410G2PMiLuAcVtJ vILnjHsi12A9uc9zVEl/3xZqwqhFnZXbBDWEKbz59HXkwgyrQfr8mmViq7qMrzRJ Mgu4QrqUMxqBtFh+ik2CiysCZmbvbEm5KyYcRpJ+sdd3cVnITJ5tYyrtVRMaTQ8o aG9HAooqJXXAF175rz0RirE7P3mVmL6a1i80hibDVTbNVrgMLLCqFm1bBqiEHL+K gOEhhTRoqzQYYyUA/orkxoRThsTY+no8y1jk0SVb2UO3p15QraLhCstQXyPCyrvX 7vaiGjRkuTjdXA8tN3f8PqN3ZAp6val1MzZBoxMxMFVrhepaM269Nh1qfKh27BE/ qznwc9iSyyfYR9e7TZYKglf/8ZJoeEEG41s0GfEbqfQf6lHVsY7VrMNmTgtl8hZo LldZN09eZt18Ula+QewJz5JTEf+VZGxA5UJSxHR1u8u8KkHPQ5pRLoF2XAKtAtzS I81xglme8W8SBhfc3wObk0t8OTVsLz+WF55y4xlynBMfGHOZcrL0vrD680NTKhiY cGUmkEGq2kdOa//e/dMX2qQAR8d71hMl+NeH0Xv/mrtQtkRB6/nC+mR7hKfb1KLM 1NsUpt/ccy69qfikxOacOdBdGJo0nmEsyXnYqSWd8nyh/Arcr7yuco4xgeGp6w06 vcOZetufh+I=BlvV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Node.js:18 release for Red Hat Enterprise Linux 9 classified as critical. Various security vulnerabilities resolved for improved security measures.. nodejs security update, Red Hat advisory, important updates, enterprise Linux security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 14, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200