debootstrap has been updated to avoid pulling in usr-is-merged in testing and unstable. This fixes creating testing/unstable chroots after src:usrmerge is removed from the archive. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4005-1
The kernel update in MGASA-2021-0257 contained some security fixes that caused regressions in atleast some container and chroot setups. This update provides upstream 5.10.45 that adds follow-up fixes to resolve the regressions and other various security-related and other bugfixes. . MGASA-2021-0282 - Updated kernel packages fix security and other issues Publication date: 23 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0282.html Type: security Affected Mageia releases: 7, 8 The kernel update in MGASA-2021-0257 contained some security fixes that caused regressions in atleast some container and chroot setups. This update provides upstream 5.10.45 that adds follow-up fixes to resolve the regressions and other various security-related and other bugfixes. For more info about the upstream fixes, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=29151 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.44 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.45 SRPMS: - 8/core/kernel-5.10.45-2.mga8 - 8/core/kmod-virtualbox-6.1.22-1.8.mga8 - 8/core/kmod-xtables-addons-3.18-1.8.mga8 - 7/core/kernel-5.10.45-2.mga7 - 7/core/kmod-virtualbox-6.1.22-1.8.mga7 - 7/core/kmod-xtables-addons-3.13-30.mga7 . Stay informed about crucial news regarding Mageia kernel packages that tackle security vulnerabilities and resolve bugs with the most recent patches.. Mageia Kernel Update, Security Fixes, Bug Resolution. . Severity: Important. LinuxSecurity.com Team
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that . Package : sssd Version : 1.11.7-3+deb8u2 CVE ID : CVE-2019-3811 Debian Bug : 919051 A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of ' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. For Debian 8 "Jessie", this problem has been fixed in version 1.11.7-3+deb8u2. We recommend that you upgrade your sssd packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail:
- Update to bind-9.11.4-P2 - Add /dev/urandom to chroot (#1631515) - Fix multilib conflicts of devel package - Add support for OpenSSL provided random data. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a54e46032f 2018-10-02 19:26:59.108539 --------------------------------------------------------------------------------Name : bind Product : Fedora 29 Version : 9.11.4 Release : 10.P2.fc29 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. --------------------------------------------------------------------------------Update Information: - Update to bind-9.11.4-P2 - Add /dev/urandom to chroot (#1631515) - Fix multilib conflicts of devel package - Add support for OpenSSL provided random data --------------------------------------------------------------------------------References: [ 1 ] Bug #1631131 - CVE-2018-5741 bind: Incorrect documentation of krb5-subdomain and ms-subdomain update policies https://bugzilla.redhat.com/show_bug.cgi?id=1631131 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a54e46032f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.