Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for glib2 Announcement ID: SUSE-SU-2025:02375-1 Release Date: 2025-07-18T13:16:28Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2375=1 ## Package List: * openSUSE Leap 15.4 (noarch) * gio-branding-upstream-2.70.5-150400.3.23.1 * glib2-lang-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tests-devel-2.70.5-150400.3.23.1 * glib2-doc-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-2.70.5-150400.3.23.1 * glib2-devel-2.70.5-150400.3.23.1 * glib2-devel-static-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (x86_64) * glib2-tools-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-32bit-2.70.5-150400.3.23.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib2-tools-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.23.1 *glib2-devel-64bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.23.1 * glib2-tools-64bit-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 *libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . Significant notice regarding glib2 addresses potential integer overflow and memory corruption vulnerabilities on openSUSE systems. Suggested patch is ready for implementation.. glib2 update, openSUSE patch, memory corruption fix, security fix. . LinuxSecurity.com Team
* bsc#1242844 Cross-References: * CVE-2025-4373 . # Security update for glib2 Announcement ID: SUSE-SU-2025:02375-1 Release Date: 2025-07-18T13:16:28Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2375=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2375=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2375=1 ## Package List: * openSUSE Leap 15.4 (noarch) * gio-branding-upstream-2.70.5-150400.3.23.1 * glib2-lang-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) *libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tests-devel-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tests-devel-2.70.5-150400.3.23.1 * glib2-doc-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * libgthread-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-2.70.5-150400.3.23.1 * glib2-devel-2.70.5-150400.3.23.1 * glib2-devel-static-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (x86_64) * glib2-tools-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-32bit-2.70.5-150400.3.23.1 * glib2-devel-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-2.70.5-150400.3.23.1 * libgthread-2_0-0-32bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-32bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-32bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-32bit-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-32bit-2.70.5-150400.3.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib2-tools-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgio-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-2.70.5-150400.3.23.1 * libgobject-2_0-0-64bit-2.70.5-150400.3.23.1 *glib2-devel-64bit-debuginfo-2.70.5-150400.3.23.1 * glib2-devel-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-2.70.5-150400.3.23.1 * libgmodule-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-2.70.5-150400.3.23.1 * glib2-tools-64bit-2.70.5-150400.3.23.1 * libglib-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * libgthread-2_0-0-64bit-debuginfo-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 *libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgio-2_0-0-debuginfo-2.70.5-150400.3.23.1 * glib2-tools-2.70.5-150400.3.23.1 * glib2-tools-debuginfo-2.70.5-150400.3.23.1 * libglib-2_0-0-2.70.5-150400.3.23.1 * libgmodule-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgmodule-2_0-0-2.70.5-150400.3.23.1 * libglib-2_0-0-debuginfo-2.70.5-150400.3.23.1 * libgobject-2_0-0-2.70.5-150400.3.23.1 * glib2-debugsource-2.70.5-150400.3.23.1 * libgio-2_0-0-2.70.5-150400.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . A critical security alert has been issued for openSUSE regarding a notable glib2 memory leak vulnerability, CVE-2025-4374. Immediate measures recommended!. SUSE Security, glib2 Update, CVE-2025-4373, Buffer Underwrite Fix, openSUSE Advisory. . LinuxSecurity.com Team
* bsc#1242844 Cross-References: * CVE-2025-4373 . # Security update for glib2 Announcement ID: SUSE-SU-2025:01880-1 Release Date: 2025-06-11T05:41:48Z Rating: moderate References: * bsc#1242844 Cross-References: * CVE-2025-4373 CVSS scores: * CVE-2025-4373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4373 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-4373 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability can now be installed. ## Description: This update for glib2 fixes the following issues: * CVE-2025-4373: integer overflow in the `g_string_insert_unichar()` function can lead to buffer underwrite and memory corruption (bsc#1242844). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-1880=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1880=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1880=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 *libgio-2_0-0-2.62.6-150200.3.30.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 * libgio-2_0-0-2.62.6-150200.3.30.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libgobject-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libgobject-2_0-0-2.62.6-150200.3.30.1 * libgmodule-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-debugsource-2.62.6-150200.3.30.1 * libglib-2_0-0-2.62.6-150200.3.30.1 * libgio-2_0-0-debuginfo-2.62.6-150200.3.30.1 * libglib-2_0-0-debuginfo-2.62.6-150200.3.30.1 * glib2-tools-debuginfo-2.62.6-150200.3.30.1 * libgmodule-2_0-0-2.62.6-150200.3.30.1 * glib2-tools-2.62.6-150200.3.30.1 * libgio-2_0-0-2.62.6-150200.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4373.html * https://bugzilla.suse.com/show_bug.cgi?id=1242844 . SUSE Linux Enterprise Micro has issued an important update for glib2, addressing a significant integer overflow vulnerability to enhance system security and stability. glib2 update,SUSE security advisory,buffer underwrite fix,SUSE Linux Micro. . LinuxSecurity.com Team
An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-nodejs14-nodejs security update Advisory ID: RHSA-2023:4039-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2023:4039 Issue date: 2023-07-12 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for rh-nodejs14-nodejs is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for RHEL Workstation(v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for RHEL(v. 7) - noarch, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Software Collections for RHEL Workstation(v. 7): Source: rh-nodejs14-nodejs-14.21.3-4.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.21.3-4.el7.noarch.rpm ppc64le: rh-nodejs14-nodejs-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.ppc64le.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.ppc64le.rpm s390x: rh-nodejs14-nodejs-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.s390x.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.s390x.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.s390x.rpm x86_64: rh-nodejs14-nodejs-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.x86_64.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.x86_64.rpm Red Hat Software Collections for RHEL(v. 7): Source: rh-nodejs14-nodejs-14.21.3-4.el7.src.rpm noarch: rh-nodejs14-nodejs-docs-14.21.3-4.el7.noarch.rpm x86_64: rh-nodejs14-nodejs-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-debuginfo-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-devel-14.21.3-4.el7.x86_64.rpm rh-nodejs14-nodejs-full-i18n-14.21.3-4.el7.x86_64.rpm rh-nodejs14-npm-6.14.18-14.21.3.4.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkrqzNAAoJENzjgjWX9erESuAP/ibSBdF1DR/I/vUgD2OqpvaH evULtjwOdp31vlestbl+DM3DrhyUb1fbscYHSVwK+PHC0nHlhUmSUghjLKQS2JU/ udMBSUbDfLw950fGcS3lp/DT5sAvchPXQy2GYjOdjwZVJAsE52ecetzdd3G2xc+0 cNn0XcRuSPFtkS47sPkeZdlHd17RDy2fgIHsTrJ9wm4lO7az3pqNqSegrLpIVbXr Y+S+I+yVmlasQ9/l6BUG3JTp5zsQpItWF8DkXvPrv59saLRLo+Vz8ursOjWW0ihE DnMg0hznfknP0FmEr1o70AcEzhSBSvA0X4qlUttORdhoaN8KLtaXjNiMVMke4asw prvDiJCoPO7y2pZFIw2oRt0d92/xZRE5T6t0UhGw1hejMPPKP7tcTsTpzoGtWHw3 VzgD322B7I6hSqJP1q18Q1bG2m7hm4QtxTSF+557VjBFMpqPSiKDRkUnb7CigJuz wgaKN2IP1iTeIOpjZpnBa0EiPszUmSN+FxSqo/1BchQSGomaONWk5XJtVYSO4ZYm Uo4qiM6p1EE5jMuBgkHwml5uY4EAemyHfGWobyjrylF4aGYZ11iYJayTIcZktmzC bTT3Mwdj4d2l+fgyf7s38tA5hgpD3fgdF9TH+FTtEJUmJucBF47P/A01v5RypfAC wcnuYaT1q7Bg8mySBCqN =FTmv -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs security update Advisory ID: RHSA-2023:4036-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4036 Issue date: 2023-07-12 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update,which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.9.0): Source: nodejs-16.18.1-4.el9_0.src.rpm aarch64: nodejs-16.18.1-4.el9_0.aarch64.rpm nodejs-debuginfo-16.18.1-4.el9_0.aarch64.rpm nodejs-debugsource-16.18.1-4.el9_0.aarch64.rpm nodejs-full-i18n-16.18.1-4.el9_0.aarch64.rpm nodejs-libs-16.18.1-4.el9_0.aarch64.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.aarch64.rpm npm-8.19.2-1.16.18.1.4.el9_0.aarch64.rpm noarch: nodejs-docs-16.18.1-4.el9_0.noarch.rpm ppc64le: nodejs-16.18.1-4.el9_0.ppc64le.rpm nodejs-debuginfo-16.18.1-4.el9_0.ppc64le.rpm nodejs-debugsource-16.18.1-4.el9_0.ppc64le.rpm nodejs-full-i18n-16.18.1-4.el9_0.ppc64le.rpm nodejs-libs-16.18.1-4.el9_0.ppc64le.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.ppc64le.rpm npm-8.19.2-1.16.18.1.4.el9_0.ppc64le.rpm s390x: nodejs-16.18.1-4.el9_0.s390x.rpm nodejs-debuginfo-16.18.1-4.el9_0.s390x.rpm nodejs-debugsource-16.18.1-4.el9_0.s390x.rpm nodejs-full-i18n-16.18.1-4.el9_0.s390x.rpm nodejs-libs-16.18.1-4.el9_0.s390x.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.s390x.rpm npm-8.19.2-1.16.18.1.4.el9_0.s390x.rpm x86_64: nodejs-16.18.1-4.el9_0.x86_64.rpm nodejs-debuginfo-16.18.1-4.el9_0.i686.rpm nodejs-debuginfo-16.18.1-4.el9_0.x86_64.rpm nodejs-debugsource-16.18.1-4.el9_0.i686.rpm nodejs-debugsource-16.18.1-4.el9_0.x86_64.rpm nodejs-full-i18n-16.18.1-4.el9_0.x86_64.rpm nodejs-libs-16.18.1-4.el9_0.i686.rpm nodejs-libs-16.18.1-4.el9_0.x86_64.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.i686.rpm nodejs-libs-debuginfo-16.18.1-4.el9_0.x86_64.rpm npm-8.19.2-1.16.18.1.4.el9_0.x86_64.rpm Thesepackages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkrqy8AAoJENzjgjWX9erEKJ8QAJxKxAA+Y+Pv8URTAy4Q9Hby E+tojNCd1nX9i1+8CWk62BDjYUujxE4URawpZi5XhLY4DvNYxlkExR6VouoKumno fJoBiAAPsjLnNfUECQpSrwfwmdB6b8q0LQQGNYIuKXdKYW/udBddDtXVrlCFjAsK FCQbBL4/a/TWnT7AXU513p845+d8zeGQ6gEw4mstTbnGsg/jj69h6H7TYdsW1Eq3 BnF/0GtDyiNKv3GgvWuXe8WQili1kYTZLDUnsm2onljuGJzQGxrmXkR8GZ/131+6 oFB0exQWwyru5kUu76LFSDjyABpsd4rP2Jjdk7x4nlrmIEvxqzRgW+dF43Ucvxau RiDltNUnSuEI1yoT11Safd2qojfRA7PCl6D28cUG0fgVIzhqlWGIOvNkhBp05wS0 gmuAL15WJzF+9o77/ZPqbWjB6xDYRgHrKtMYLHRCdrPSCu5ErafLggggUi60D1yq WCioRmMjBtuklklb/z8g+E7XrCSXff4usCDldJc7IhikQc2IKpkkGi44M6ELntdI ujOhsZjH0bmW6wz88RKEigCT6icHrwX3uElUYdj56WLwB8NKDmUgn11WijbTg7+T /arXJ7L93JuaJ9v9OR4+AO2jx5cME/vMtXaFhJzXhuMx2RTiXdNSCQG9Yh/FeO5v 1OyLwi0IsLapSJL6mjTN =0cqs -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Important: nodejs:18 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:3577", "synopsis": "Important: nodejs:18 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067)\n\n* c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130)\n\n* c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147)\n\n* c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2209494", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209494", "description": ""}, {"ticket": "2209497", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209497", "description": ""}, {"ticket": "2209501", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209501", "description": ""}, {"ticket": "2209502", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209502", "description": ""}], "cves": [{"name": "CVE-2023-31124", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31124", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-31130","sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31130", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-31147", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-31147", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-32067", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-32067", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-06-24T18:53:41.228929Z", "rpms": {"Rocky Linux 9": {"nvras": ["nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-debuginfo-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-debugsource-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-devel-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-docs-1:18.14.2-3.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.aarch64.rpm","nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.s390x.rpm", "nodejs-full-i18n-1:18.14.2-3.module+el9.2.0+14843+acebbfea.x86_64.rpm", "nodejs-nodemon-0:2.0.20-2.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-nodemon-0:2.0.20-2.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-packaging-0:2021.06-4.module+el9.2.0+14843+acebbfea.noarch.rpm", "nodejs-packaging-0:2021.06-4.module+el9.2.0+14843+acebbfea.src.rpm", "nodejs-packaging-bundler-0:2021.06-4.module+el9.2.0+14843+acebbfea.noarch.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.aarch64.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.ppc64le.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.s390x.rpm", "npm-1:9.5.0-1.18.14.2.3.module+el9.2.0+14843+acebbfea.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Urgent security patch for nodejs:18 on Rocky Linux resolves various vulnerabilities, providing crucial improvements.. Nodejs Security Update, Rocky Linux Security, Nodejs Issues, Important Security Fix. . Severity: Important. LinuxSecurity.com Team
An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs security update Advisory ID: RHSA-2023:3586-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3586 Issue date: 2023-06-14 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: nodejs-16.19.1-2.el9_2.src.rpm aarch64: nodejs-16.19.1-2.el9_2.aarch64.rpm nodejs-debuginfo-16.19.1-2.el9_2.aarch64.rpm nodejs-debugsource-16.19.1-2.el9_2.aarch64.rpm nodejs-full-i18n-16.19.1-2.el9_2.aarch64.rpm nodejs-libs-16.19.1-2.el9_2.aarch64.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.aarch64.rpm npm-8.19.3-1.16.19.1.2.el9_2.aarch64.rpm noarch: nodejs-docs-16.19.1-2.el9_2.noarch.rpm ppc64le: nodejs-16.19.1-2.el9_2.ppc64le.rpm nodejs-debuginfo-16.19.1-2.el9_2.ppc64le.rpm nodejs-debugsource-16.19.1-2.el9_2.ppc64le.rpm nodejs-full-i18n-16.19.1-2.el9_2.ppc64le.rpm nodejs-libs-16.19.1-2.el9_2.ppc64le.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.ppc64le.rpm npm-8.19.3-1.16.19.1.2.el9_2.ppc64le.rpm s390x: nodejs-16.19.1-2.el9_2.s390x.rpm nodejs-debuginfo-16.19.1-2.el9_2.s390x.rpm nodejs-debugsource-16.19.1-2.el9_2.s390x.rpm nodejs-full-i18n-16.19.1-2.el9_2.s390x.rpm nodejs-libs-16.19.1-2.el9_2.s390x.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.s390x.rpm npm-8.19.3-1.16.19.1.2.el9_2.s390x.rpm x86_64: nodejs-16.19.1-2.el9_2.x86_64.rpm nodejs-debuginfo-16.19.1-2.el9_2.i686.rpm nodejs-debuginfo-16.19.1-2.el9_2.x86_64.rpm nodejs-debugsource-16.19.1-2.el9_2.i686.rpm nodejs-debugsource-16.19.1-2.el9_2.x86_64.rpm nodejs-full-i18n-16.19.1-2.el9_2.x86_64.rpm nodejs-libs-16.19.1-2.el9_2.i686.rpm nodejs-libs-16.19.1-2.el9_2.x86_64.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.i686.rpm nodejs-libs-debuginfo-16.19.1-2.el9_2.x86_64.rpm npm-8.19.3-1.16.19.1.2.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIm3NNzjgjWX9erEAQi54Q/9EZNTfzn3FhZnN0dcNC+35JzC3SvI4yOZ nzwZpGoBgDmwaiYeQHDyMtz3saiw2FpnuQ017X8a9RhWm0CT6GsSXGDO9VDrEGBq ZlxqkeVedwFDATpzDS5TbvPcmoMwlzlu5kUHdx7yuxRwaYHwo/nVzU5DvSYifMsS ddT8yaRhFkYbBMwsihsrS1ej+BVtRHomrukNi3hcVHvEWEqTtbxfCBRbUCY0uVWa R7qhcHyT9HoRkiHvEb1V803tAQQOWeiUnFqQ6FMEMPRUEfTtGCYpS9uiGRkG3iyT 5+NJbeE7W/mGY7clAjjmg+PDVgm8F37p5pazaPs2pNQ2hGZHrCgLBIBd0bd8Bho/ q9P6/CgiRqz5WCs3/bKI38VC2LEz2HBMvR/iRlA6JgmKJ/RvXb74C+oWLaHiHDN9 NMavfp4WlD4NbkdhbaFG9a5wguj3ehLhUTZ9Zc9OtwpoBi+uXjVwtxQcR4nZ4sSh w3/CJ/bTYpTTeT5SkDwn8T4P5Nb3xqPVlfKafXi+t3dL2DkZieG14BykYS33tLlb U/RbzFrpN+5St3QWqS3ZDqvijKaWqIWuWYyyoYlV472SADexTDfuRIgaaTBtb55o T/5BZkBwLyTTeZNwHNWMsqlC5ufDZzoAKPN2mv7zqKGEA1hakrNWtWkfmqbUo4Iq fitA5BLFCJA=LPTx -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for the nodejs:18 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nodejs:18 security update Advisory ID: RHSA-2023:3577-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3577 Issue date: 2023-06-14 CVE Names: CVE-2023-31124 CVE-2023-31130 CVE-2023-31147 CVE-2023-32067 ==================================================================== 1. Summary: An update for the nodejs:18 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * c-ares: 0-byte UDP payload Denial of Service (CVE-2023-32067) * c-ares: Buffer Underwrite in ares_inet_net_pton() (CVE-2023-31130) * c-ares: Insufficient randomness in generation of DNS query IDs (CVE-2023-31147) * c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation (CVE-2023-31124) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209494 - CVE-2023-31124 c-ares: AutoTools does not set CARES_RANDOM_FILE during cross compilation 2209497 - CVE-2023-31130 c-ares: Buffer Underwrite in ares_inet_net_pton() 2209501 - CVE-2023-31147 c-ares: Insufficient randomness in generation of DNS query IDs 2209502 - CVE-2023-32067 c-ares: 0-byte UDP payload Denial of Service 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.src.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0.z+18497+a402347c.src.rpm nodejs-packaging-2021.06-4.module+el9.1.0+15718+e52ec601.src.rpm aarch64: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.aarch64.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.aarch64.rpm noarch: nodejs-docs-18.14.2-3.module+el9.2.0.z+18964+42696395.noarch.rpm nodejs-nodemon-2.0.20-2.module+el9.2.0.z+18497+a402347c.noarch.rpm nodejs-packaging-2021.06-4.module+el9.1.0+15718+e52ec601.noarch.rpm nodejs-packaging-bundler-2021.06-4.module+el9.1.0+15718+e52ec601.noarch.rpm ppc64le: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.ppc64le.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.ppc64le.rpm s390x: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.s390x.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.s390x.rpm x86_64: nodejs-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-debuginfo-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-debugsource-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-devel-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm nodejs-full-i18n-18.14.2-3.module+el9.2.0.z+18964+42696395.x86_64.rpm npm-9.5.0-1.18.14.2.3.module+el9.2.0.z+18964+42696395.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-31124 https://access.redhat.com/security/cve/CVE-2023-31130 https://access.redhat.com/security/cve/CVE-2023-31147 https://access.redhat.com/security/cve/CVE-2023-32067 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZIm3ENzjgjWX9erEAQjQ+w//XwePu+NM3an0O53dk410G2PMiLuAcVtJ vILnjHsi12A9uc9zVEl/3xZqwqhFnZXbBDWEKbz59HXkwgyrQfr8mmViq7qMrzRJ Mgu4QrqUMxqBtFh+ik2CiysCZmbvbEm5KyYcRpJ+sdd3cVnITJ5tYyrtVRMaTQ8o aG9HAooqJXXAF175rz0RirE7P3mVmL6a1i80hibDVTbNVrgMLLCqFm1bBqiEHL+K gOEhhTRoqzQYYyUA/orkxoRThsTY+no8y1jk0SVb2UO3p15QraLhCstQXyPCyrvX 7vaiGjRkuTjdXA8tN3f8PqN3ZAp6val1MzZBoxMxMFVrhepaM269Nh1qfKh27BE/ qznwc9iSyyfYR9e7TZYKglf/8ZJoeEEG41s0GfEbqfQf6lHVsY7VrMNmTgtl8hZo LldZN09eZt18Ula+QewJz5JTEf+VZGxA5UJSxHR1u8u8KkHPQ5pRLoF2XAKtAtzS I81xglme8W8SBhfc3wObk0t8OTVsLz+WF55y4xlynBMfGHOZcrL0vrD680NTKhiY cGUmkEGq2kdOa//e/dMX2qQAR8d71hMl+NeH0Xv/mrtQtkRB6/nC+mR7hKfb1KLM 1NsUpt/ccy69qfikxOacOdBdGJo0nmEsyXnYqSWd8nyh/Arcr7yuco4xgeGp6w06 vcOZetufh+I=BlvV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.