Important: .NET 8.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:4454", "synopsis": "Important: .NET 8.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet8.0.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.125 and .NET Runtime 8.0.25.Security Fix(es):\n\n* asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-26130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2446134", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2446134", "description": ""}], "cves": [{"name": "CVE-2026-26130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-26130", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}], "references": [], "publishedAt": "2026-03-13T12:03:59.563415Z", "rpms": {"Rocky Linux 9": {"nvras": ["aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-runtime-dbg-8.0-0:8.0.25-1.el9_7.x86_64.rpm","aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "aspnetcore-targeting-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet8.0-0:8.0.125-1.el9_7.src.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.s390x.rpm", "dotnet8.0-debuginfo-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.s390x.rpm", "dotnet8.0-debugsource-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-apphost-pack-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-hostfxr-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-runtime-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.s390x.rpm","dotnet-runtime-8.0-debuginfo-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-runtime-dbg-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-debuginfo-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-8.0-source-built-artifacts-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-sdk-dbg-8.0-0:8.0.125-1.el9_7.x86_64.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.aarch64.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.ppc64le.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.s390x.rpm", "dotnet-targeting-pack-8.0-0:8.0.25-1.el9_7.x86_64.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.aarch64.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.ppc64le.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.s390x.rpm", "dotnet-templates-8.0-0:8.0.125-1.el9_7.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical .NET 8.0 update for Rocky Linux addresses a denial of service threat. Explore the details of this important patch.. Rocky Linux .NET security update, ASP.NET core fix, DoS vulnerability patch. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for ucode-intel Announcement ID: SUSE-SU-2026:0668-1 Release Date: 2026-02-26T15:21:26Z Rating: important References: * bsc#1229129 * bsc#1258046 Cross-References: * CVE-2024-24853 * CVE-2025-31648 CVSS scores: * CVE-2024-24853 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2024-24853 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2025-31648 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N * CVE-2025-31648 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31648 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 *SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260210 release (bsc#1258046) * CVE-2024-24853: Updated fix for incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access. (bsc#1229129) * CVE-2025-31648: Improper handling of values in the microcode flow for some Intel Processor Family may allow an escalation of privilege. (bsc#1258046) ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-668=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-668=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-668=1 *SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-668=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-668=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-668=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-668=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-668=1 ## Package List: * SUSE Linux Enterprise Micro 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * ucode-intel-20260210-150200.62.1 * openSUSE Leap 15.6 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux EnterpriseMicro 5.4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260210-150200.62.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260210-150200.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260210-150200.62.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24853.html * https://www.suse.com/security/cve/CVE-2025-31648.html * https://bugzilla.suse.com/show_bug.cgi?id=1229129 * https://bugzilla.suse.com/show_bug.cgi?id=1258046 . Critical update for ucode-intel fixing important vulnerabilities, enhancing system security for SUSE systems. Install now!. SUSE update, ucode-intel, escalation of privilege, security advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities and has one fix can now be installed.. # Security update for go1.24 Announcement ID: SUSE-SU-2026:20429-1 Release Date: 2026-02-13T11:53:30Z Rating: critical References: * bsc#1236217 * bsc#1256818 * bsc#1256820 * bsc#1257692 Cross-References: * CVE-2025-61732 * CVE-2025-68119 * CVE-2025-68121 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-68119 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68119 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-68119 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-68121 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for go1.24 fixes the following issues: Update to version 1.24.13. Security issues fixed: * CVE-2025-61732: cmd/go: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2025-68119: cmd/go: unexpected code execution when invoking toolchain (bsc1256820). Other updates and bugfixes: * version updateto 1.24.13: * go#77323 crypto/x509: single-label excluded DNS name constraints incorrectly match all wildcard SANs * go#77424 crypto/tls: CL 737700 broke session resumption on macOS ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-270=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * go1.24-race-1.24.13-160000.1.1 * go1.24-1.24.13-160000.1.1 * go1.24-doc-1.24.13-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (x86_64) * go1.24-libstd-debuginfo-1.24.13-160000.1.1 * go1.24-libstd-1.24.13-160000.1.1 * go1.24-debuginfo-1.24.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68119.html * https://www.suse.com/security/cve/CVE-2025-68121.html * https://bugzilla.suse.com/show_bug.cgi?id=1236217 * https://bugzilla.suse.com/show_bug.cgi?id=1256818 * https://bugzilla.suse.com/show_bug.cgi?id=1256820 * https://bugzilla.suse.com/show_bug.cgi?id=1257692 . Critical update for SUSE fixes three major issues in go1.24 ensuring better security and stability.. SUSE Linux, Security Update, Go Language, Critical Vulnerability, System Patch. . Severity: Critical. LinuxSecurity.com Team
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in execution of arbitrary code, erroneous parsing of invalid URLs or multipart form data, configuration setting bypass, or log pollution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3920-1
* bsc#1228105 Cross-References: * CVE-2024-6345 . # Security update for python-setuptools Announcement ID: SUSE-SU-2024:2900-1 Rating: important References: * bsc#1228105 Cross-References: * CVE-2024-6345 CVSS scores: * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Containers Module 12 * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-setuptools fixes the following issues: * CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 12 zypper in -t patch SUSE-SLE-Module-Containers-12-2024-2900=1 * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2024-2900=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patchSUSE-SLE-SDK-12-SP5-2024-2900=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-2900=1 ## Package List: * Containers Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * Public Cloud Module 12 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (noarch) * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * python-setuptools-40.6.2-4.24.1 * python3-setuptools-40.6.2-4.24.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6345.html * https://bugzilla.suse.com/show_bug.cgi?id=1228105 . Critical patch released for python-setuptools tackles potential code execution vulnerabilities in SUSE Linux versions 12 series.. python-setuptools security updates, SUSE Linux vulnerabilities, software security fixes. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Chromium, Google Chrome: Multiple vulnerabilities Date: September 10, 2020 Bugs: #741312 ID: 202009-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code. Background ========= Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web. Google Chrome is one fast, simple, and secure browser for all your devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/chromium < 85.0.4183.102 > = 85.0.4183.102 2 www-client/google-chrome < 85.0.4183.102 > = 85.0.4183.102 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in Chromium and Google Chrome. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Chromium users should upgrade to the latest version: # emerge --sync #emerge --ask --oneshot -v "> =www-client/chromium-85.0.4183.102" All Google Chrome users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v "> =www-client/google-chrome-85.0.4183.102" References ========= [ 1 ] CVE-2020-15959 https://nvd.nist.gov/vuln/detail/CVE-2020-15959 [ 2 ] CVE-2020-6573 https://nvd.nist.gov/vuln/detail/CVE-2020-6573 [ 3 ] CVE-2020-6575 https://nvd.nist.gov/vuln/detail/CVE-2020-6575 [ 4 ] CVE-2020-6576 https://nvd.nist.gov/vuln/detail/CVE-2020-6576 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202009-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libmicrodns: Multiple vulnerabilities Date: May 14, 2020 Bugs: #714606 ID: 202005-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libmicrodns, the worst of which could result in the arbitrary execution of code. Background ========= libmicrodns is an mDNS library, focused on being simple and cross-platform. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libmicrodns < 0.1.2 > = 0.1.2 Description ========== Multiple vulnerabilities have been discovered in libmicrodns. Please review the CVE identifiers and the upstream advisory referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libmicrodns users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/libmicrodns-0.1.2" References ========= [ 1 ] CVE-2020-6071 https://nvd.nist.gov/vuln/detail/CVE-2020-6071 [ 2 ] CVE-2020-6072 https://nvd.nist.gov/vuln/detail/CVE-2020-6072 [ 3 ] CVE-2020-6073 https://nvd.nist.gov/vuln/detail/CVE-2020-6073 [ 4 ] CVE-2020-6077 https://nvd.nist.gov/vuln/detail/CVE-2020-6077 [ 5 ] CVE-2020-6078 https://nvd.nist.gov/vuln/detail/CVE-2020-6078 [ 6 ] CVE-2020-6079 https://nvd.nist.gov/vuln/detail/CVE-2020-6079 [ 7 ] CVE-2020-6080 https://nvd.nist.gov/vuln/detail/CVE-2020-6080 [ 8 ] VideoLAN-SB-VLC-309 https://www.videolan.org/security/sb-vlc309.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202005-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1607-1
Get the latest Linux and open source security news straight to your inbox.