Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":556,"type":"x","order":1,"pct":78.75,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.25,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.18,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 10 Buster DLA-3369-1 Critical Runc Security Update

Multiple vulnerabilities were discovered in runc, the Open Container Project runtime, which is often used with virtualization environments such as Docker. Malicious Docker images or OCI bundles could breach isolation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3369-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler March 27, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : runc Version : 1.0.0~rc6+dfsg1-3+deb10u2 CVE ID : CVE-2019-16884 CVE-2019-19921 CVE-2021-30465 CVE-2022-29162 CVE-2023-27561 Debian Bug : 942026 988768 Multiple vulnerabilities were discovered in runc, the Open Container Project runtime, which is often used with virtualization environments such as Docker. Malicious Docker images or OCI bundles could breach isolation. CVE-2019-16884 runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. CVE-2019-19921 runc has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.) CVE-2021-30465 runc allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition. CVE-2022-29162 `runc exec --cap`created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set never contained more capabilities than were included in the container's bounding set. CVE-2023-27561 CVE-2019-19921 was re-introduced by the fix for CVE-2021-30465. For Debian 10 buster, this problem has been fixed in version 1.0.0~rc6+dfsg1-3+deb10u2. We recommend that you upgrade your runc packages. For the detailed security status of runc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/runc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important notice regarding runc fixes for various vulnerabilities. Safeguard your Debian environment by updating runc components.. Debian Security, Runc Update, Container Isolation, Privilege Escalation, Process Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 27, 2023 Critical Debian LTS
89

Fedora 23 LXC Security Update: Critical Directory Traversal Issue

Update LXC to the latest stable release. The full list of changes can be found [here](https://linuxcontainers.org/lxc/news/#lxc-114-release-announcement6th-of-october-2015).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9f8f4b182a 2015-11-01 01:51:21.166430 -------------------------------------------------------------------------------- Name : lxc Product : Fedora 23 Version : 1.1.4 Release : 2.fc23 URL : https://linuxcontainers.org/ Summary : Linux Resource ContainersDescription : Linux Resource Containers provide process and resource isolation without the overhead of full virtualization. -------------------------------------------------------------------------------- Update Information: Update LXC to the latest stable release. The full list of changes can be found [here](https://linuxcontainers.org/lxc/news/#lxc-114-release-announcement6th-of-october-2015). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1267844 - CVE-2015-1335 lxc: Directory traversal flaw when lxc-start is initially setting up the mounts for a container https://bugzilla.redhat.com/show_bug.cgi?id=1267844 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lxc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 23's LXC security patch addresses a criticalpath traversal vulnerability, enhancing the overall resource containment for containers. Discover additional details here.. LXC Security Update, Fedora Resource Isolation, Directory Traversal Flaw, Linux Containers Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 01, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":556,"type":"x","order":1,"pct":78.75,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.25,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.18,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here