Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The 6.8.5 stable kernel update contains a number of important fixes across the tree. . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6d35739db7 2024-04-13 03:40:51.150308 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 40 Version : 6.8.5 Release : 301.fc40 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.8.5 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Justin M. Forbes [6.8.5-301] - nouveau: fix devinit paths to only handle display on GSP. (Dave Airlie) - Add bluetooth bug to Bugsfixed for 6.8.6 (Justin M. Forbes) - Bluetooth: l2cap: Don't double set the HCI_CONN_MGMT_CONNECTED bit (Archie Pusaka) * Wed Apr 10 2024 Justin M. Forbes [6.8.5-0] - Set configs for SPECTRE_BHI (Justin M. Forbes) - Add AMD PMF bug (Justin M. Forbes) - redhat/configs: Enable CONFIG_AMDTEE for x86 (David Arcari) - Add CVE fix for 6.8.5 (Justin M. Forbes) - Linux v6.8.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273968 - CVE-2024-26811 kernel: ksmbd: validate payload size in ipc response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2273968 [ 2 ] Bug #2274047 - Bluetooth headset partially connects under some circumstances with blues 5.73-3.fc40.x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=2274047 [ 3 ] Bug #2274069 - AMD-PMF driver fails to load on kernel- 6.8.4-300.fc40.x86_64. Resulting in GPU failing to use full gpu available watts. https://bugzilla.redhat.com/show_bug.cgi?id=2274069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6d35739db7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The updated packages fix a security vulnerability In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo . MGASA-2023-0336 - Updated audiofile packages fix a security vulnerability Publication date: 04 Dec 2023 URL: https://advisories.mageia.org/MGASA-2023-0336.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-24599 The updated packages fix a security vulnerability In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data. (CVE-2022-24599) References: - https://bugs.mageia.org/show_bug.cgi?id=32561 - https://lists.fedoraproject.org/archives/list/
Update to glib2-2.74.7.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-1a7e2b3dda 2023-06-16 02:13:40.625179 --------------------------------------------------------------------------------Name : mingw-glib2 Product : Fedora 37 Version : 2.74.7 Release : 1.fc37 URL : https://www.gtk.org/ Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. --------------------------------------------------------------------------------Update Information: Update to glib2-2.74.7. --------------------------------------------------------------------------------ChangeLog: * Tue Jun 6 2023 Sandro Mani - 2.74.7-1 - Update to 2.74.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2212693 - CVE-2023-32665 mingw-glib2: glib: GVariant deserialisation does not match spec for non-normal data [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212693 [ 2 ] Bug #2212697 - CVE-2023-32665 mingw-glib2: glib: GVariant deserialisation does not match spec for non-normal data [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212697 [ 3 ] Bug #2212701 - CVE-2023-29499 mingw-glib2: glib: GVariant offset table entry size is not checked in is_normal() [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212701 [ 4 ] Bug #2212707 - CVE-2023-29499 mingw-glib2: glib: GVariant offset table entry size is not checked in is_normal() [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212707 [ 5 ] Bug #2212710 - CVE-2023-32611 mingw-glib2: glib: g_variant_byteswap() can take a long time with some non-normal inputs [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212710 [ 6 ] Bug #2212712 - CVE-2023-32611 mingw-glib2: glib: g_variant_byteswap() can take a long time with some non-normal inputs [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212712 [ 7 ] Bug #2212718 - CVE-2023-32643 mingw-glib2: glib: fuzz_variant_binary_byteswap: Heap-buffer-overflow in g_variant_serialised_get_child [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212718 [ 8 ] Bug #2212723 - CVE-2023-32636 mingw-glib2: glib: fuzz_variant_text: Timeout in fuzz_variant_text [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212723 [ 9 ] Bug #2212728 - CVE-2023-32636 mingw-glib2: glib: fuzz_variant_text: Timeout in fuzz_variant_text [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212728 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1a7e2b3dda' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-7318 https://linux.oracle.com/errata/ELSA-2022-7318.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-abi-stablelists-5.14.0-70.30.1.0.1.el9_0.noarch.rpm kernel-core-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-core-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-devel-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-devel-matched-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-modules-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-debug-modules-extra-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-devel-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-devel-matched-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-doc-5.14.0-70.30.1.0.1.el9_0.noarch.rpm kernel-headers-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-modules-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-modules-extra-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-tools-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-tools-libs-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm perf-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm python3-perf-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-cross-headers-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm kernel-tools-libs-devel-5.14.0-70.30.1.0.1.el9_0.x86_64.rpm aarch64: bpftool-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm kernel-headers-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm kernel-tools-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm kernel-tools-libs-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm perf-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm python3-perf-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm kernel-cross-headers-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm kernel-tools-libs-devel-5.14.0-70.30.1.0.1.el9_0.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates/kernel-5.14.0-70.30.1.0.1.el9_0.src.rpm Related CVEs: CVE-2022-2585 CVE-2022-30594 Descriptionof changes: [5.14.0-70.30.1.0.1.el9_0.OL9] - lockdown: also lock down previous kgdb use (Daniel Thompson) [Orabug: 34290418] {CVE-2022-21499} [5.14.0-70.30.1.el9_0.OL9] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64 < 15.3-1.0.4] - Remove nmap references from kernel (Mridula Shastry) [Orabug: 34313944] [5.14.0-70.30.1.el9_0] - random: trigger reseeding DRBG on more occasions (Daiki Ueno) [2128970 2125257] - random: allow reseeding DRBG with getrandom (Daiki Ueno) [2121129 2114854] - nvme-tcp: handle number of queue changes (John Meneghini) [2131360 2112025] - nvmet: expose max queues to configfs (John Meneghini) [2131360 2112025] - nvme-fabrics: parse nvme connect Linux error codes (John Meneghini) [2131360 2112025] - nvmet: revert "nvmet: make discovery NQN configurable" (Gopal Tiwari) [2131360 2066146] - vfio/type1: Unpin zero pages (Alex Williamson) [2128791 2121855] - cifs: fix bad fids sent over wire (Ronnie Sahlberg) [2127858 2088775] - SMB3: EBADF/EIO errors in rename/open caused by race condition in smb2_compound_op (Ronnie Sahlberg) [2127858 2088775] - cifs: verify that tcon is valid before dereference in cifs_kill_sb (Ronnie Sahlberg) [2127858 2048823] - cifs: release cached dentries only if mount is complete (Ronnie Sahlberg) [2127858 2048823] - cifs: we do not need a spinlock around the tree access during umount (Ronnie Sahlberg) [2127858 2048823] - cifs: fix handlecache and multiuser (Ronnie Sahlberg) [2127858 2048823] - cifs: fix workstation_name for multiuser mounts (Ronnie Sahlberg) [2127858 2048823] - cifs: free ntlmsspblob allocated in negotiate (Ronnie Sahlberg) [2127858 2048823] - cifs: fix ntlmssp auth when there is no key exchange (Ronnie Sahlberg) [2127858 2048823] - cifs: send workstation name during ntlmssp session setup (Ronnie Sahlberg)[2127858 2048823] - cifs: Fix crash on unload of cifs_arc4.ko (Ronnie Sahlberg) [2127858 2048823] - Documentation, arch: Remove leftovers from CIFS_WEAK_PW_HASH (Ronnie Sahlberg) [2127858 2048823] - cifs: fix the cifs_reconnect path for DFS (Ronnie Sahlberg) [2127858 2048823] - cifs: sanitize multiple delimiters in prepath (Ronnie Sahlberg) [2127858 2048823] - cifs: ignore resource_id while getting fscache super cookie (Ronnie Sahlberg) [2127858 2048823] - cifs: avoid use of dstaddr as key for fscache client cookie (Ronnie Sahlberg) [2127858 2048823] - cifs: add server conn_id to fscache client cookie (Ronnie Sahlberg) [2127858 2048823] - cifs: wait for tcon resource_id before getting fscache super (Ronnie Sahlberg) [2127858 2048823] - cifs: fix missed refcounting of ipc tcon (Ronnie Sahlberg) [2127858 2048823] - cifs: update internal version number (Ronnie Sahlberg) [2127858 2048823] - smb2: clarify rc initialization in smb2_reconnect (Ronnie Sahlberg) [2127858 2048823] - cifs: populate server_hostname for extra channels (Ronnie Sahlberg) [2127858 2048823] - cifs: nosharesock should be set on new server (Ronnie Sahlberg) [2127858 2048823] - cifs: introduce cifs_ses_mark_for_reconnect() helper (Ronnie Sahlberg) [2127858 2048823] - cifs: protect srv_count with cifs_tcp_ses_lock (Ronnie Sahlberg) [2127858 2048823] - cifs: move debug print out of spinlock (Ronnie Sahlberg) [2127858 2048823] - cifs: do not duplicate fscache cookie for secondary channels (Ronnie Sahlberg) [2127858 2048823] - cifs: connect individual channel servers to primary channel server (Ronnie Sahlberg) [2127858 2048823] - cifs: protect session channel fields with chan_lock (Ronnie Sahlberg) [2127858 2048823] - cifs: do not negotiate session if session already exists (Ronnie Sahlberg) [2127858 2048823] - smb3: do not setup the fscache_super_cookie until fsinfo initialized (Ronnie Sahlberg) [2127858 2048823] - cifs: fix potential use-after-free bugs (Ronnie Sahlberg) [2127858 2048823] - cifs: fix memory leak ofsmb3_fs_context_dup::server_hostname (Ronnie Sahlberg) [2127858 2048823] - smb3: add additional null check in SMB311_posix_mkdir (Ronnie Sahlberg) [2127858 2048823] - cifs: release lock earlier in dequeue_mid error case (Ronnie Sahlberg) [2127858 2048823] - smb3: add additional null check in SMB2_tcon (Ronnie Sahlberg) [2127858 2048823] - smb3: add additional null check in SMB2_open (Ronnie Sahlberg) [2127858 2048823] - smb3: add additional null check in SMB2_ioctl (Ronnie Sahlberg) [2127858 2048823] - smb3: remove trivial dfs compile warning (Ronnie Sahlberg) [2127858 2048823] - cifs: support nested dfs links over reconnect (Ronnie Sahlberg) [2127858 2048823] - smb3: do not error on fsync when readonly (Ronnie Sahlberg) [2127858 2048823] - cifs: for compound requests, use open handle if possible (Ronnie Sahlberg) [2127858 2048823] - cifs: set a minimum of 120s for next dns resolution (Ronnie Sahlberg) [2127858 2048823] - cifs: split out dfs code from cifs_reconnect() (Ronnie Sahlberg) [2127858 2048823] - cifs: convert list_for_each to entry variant (Ronnie Sahlberg) [2127858 2048823] - cifs: introduce new helper for cifs_reconnect() (Ronnie Sahlberg) [2127858 2048823] - cifs: fix print of hdr_flags in dfscache_proc_show() (Ronnie Sahlberg) [2127858 2048823] - cifs: nosharesock should not share socket with future sessions (Ronnie Sahlberg) [2127858 2048823] - smb3: add dynamic trace points for socket connection (Ronnie Sahlberg) [2127858 2048823] - cifs: Move SMB2_Create definitions to the shared area (Ronnie Sahlberg) [2127858 2048823] - cifs: Move more definitions into the shared area (Ronnie Sahlberg) [2127858 2048823] - cifs: move NEGOTIATE_PROTOCOL definitions out into the common area (Ronnie Sahlberg) [2127858 2048823] - cifs: Create a new shared file holding smb2 pdu definitions (Ronnie Sahlberg) [2127858 2048823] - cifs: add mount parameter tcpnodelay (Ronnie Sahlberg) [2127858 2048823] - cifs: To match file servers, make sure the server hostname matches (Ronnie Sahlberg) [2127858 2048823] - cifs: fixincorrect check for null pointer in header_assemble (Ronnie Sahlberg) [2127858 2048823] - smb3: correct server pointer dereferencing check to be more consistent (Ronnie Sahlberg) [2127858 2048823] - smb3: correct smb3 ACL security descriptor (Ronnie Sahlberg) [2127858 2048823] - cifs: Clear modified attribute bit from inode flags (Ronnie Sahlberg) [2127858 2048823] - cifs: Deal with some warnings from W=1 (Ronnie Sahlberg) [2127858 2048823] - cifs: fix a sign extension bug (Ronnie Sahlberg) [2127858 2048823] - cifs: Not to defer close on file when lock is set (Ronnie Sahlberg) [2127858 2048823] - cifs: Fix soft lockup during fsstress (Ronnie Sahlberg) [2127858 2048823] - cifs: Deferred close performance improvements (Ronnie Sahlberg) [2127858 2048823] - cifs: fix incorrect kernel doc comments (Ronnie Sahlberg) [2127858 2048823] - cifs: remove pathname for file from SPDX header (Ronnie Sahlberg) [2127858 2048823] - cifs: properly invalidate cached root handle when closing it (Ronnie Sahlberg) [2127858 2048823] - cifs: move SMB FSCTL definitions to common code (Ronnie Sahlberg) [2127858 2048823] - cifs: rename cifs_common to smbfs_common (Ronnie Sahlberg) [2127858 2048823] - cifs: cifs_md4 convert to SPDX identifier (Ronnie Sahlberg) [2127858 2048823] - cifs: create a MD4 module and switch cifs.ko to use it (Ronnie Sahlberg) [2127858 2048823] - cifs: fork arc4 and create a separate module for it for cifs and other users (Ronnie Sahlberg) [2127858 2048823] - cifs: remove support for NTLM and weaker authentication algorithms (Ronnie Sahlberg) [2127858 2048823] - cifs: update FSCTL definitions (Ronnie Sahlberg) [2127858 2048823] - cifs: Do not leak EDEADLK to dgetents64 for STATUS_USER_SESSION_DELETED (Ronnie Sahlberg) [2127858 2048823] - cifs: enable fscache usage even for files opened as rw (Ronnie Sahlberg) [2127858 2048823] - smb3: fix posix extensions mount option (Ronnie Sahlberg) [2127858 2048823] - cifs: fix wrong release in sess_alloc_buffer() failed path (Ronnie Sahlberg) [2127858 2048823] - CIFS: Fix apotencially linear read overflow (Ronnie Sahlberg) [2127858 2048823] - drm/mgag200: Select clock in PLL update functions (Herton R. Krzesinski) [2112017 2043115] - mt76: mt7921: Fix the error handling path of mt7921_pci_probe() (Íñigo Huguet) [2095653 2096777] - mt76: mt7921e: fix possible probe failure after reboot (Íñigo Huguet) [2095653 2065633] [5.14.0-70.29.1.el9_0] - configs: enable CONFIG_HP_ILO for aarch64 (Mark Salter) [2129453 2126153] - KVM: x86/mmu: Don't advance iterator after restart due to yielding (Nico Pache) [2127859 2055725] - scsi: csiostor: Add module softdep on cxgb4 (Rahul Lakkireddy) [2127857 1977553] - ptrace: Check PTRACE_O_SUSPEND_SECCOMP permission on PTRACE_SEIZE (Oleg Nesterov) [2127875 2121271] {CVE-2022-30594} [5.14.0-70.28.1.el9_0] - powerpc: Enable execve syscall exit tracepoint (Steve Best) [2106661 2095526] [5.14.0-70.27.1.el9_0] - posix-cpu-timers: Cleanup CPU timers before freeing them during exec (Wander Lairson Costa) [2116967 2116968] {CVE-2022-2585} - fix race between exit_itimers() and /proc/pid/timers (Wander Lairson Costa) [2116967 2116968] {CVE-2022-2585} _______________________________________________ El-errata mailing list
Update to Jetty 9.4.40 (fixes multiple CVEs). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-35f06984d7 2021-04-29 00:56:23.403143 --------------------------------------------------------------------------------Name : jetty Product : Fedora 33 Version : 9.4.40 Release : 1.fc33 URL : https://jetty.org/ Summary : Java Webserver and Servlet Container Description : Jetty is a 100% Java HTTP Server and Servlet Container. This means that you do not need to configure and run a separate web server (like Apache) in order to use Java, servlets and JSPs to generate dynamic content. Jetty is a fully featured web server for static and dynamic content. Unlike separate server/container solutions, this means that your web server and web application run in the same process, without interconnection overheads and complications. Furthermore, as a pure java component, Jetty can be simply included in your application for demonstration, distribution or deployment. Jetty is available on all Java supported platforms. --------------------------------------------------------------------------------Update Information: Update to Jetty 9.4.40 (fixes multiple CVEs) --------------------------------------------------------------------------------ChangeLog: * Wed Apr 21 2021 Alexander Kurtakov 9.4.40-1 - Update to Jetty 9.4.40 (fixes multiple CVEs) --------------------------------------------------------------------------------References: [ 1 ] Bug #1945710 - CVE-2021-28163 jetty: Symlink directory exposes webapp directory contents https://bugzilla.redhat.com/show_bug.cgi?id=1945710 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-35f06984d7' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fixes for CVE-2020-36323, CVE-2021-28876, CVE-2021-28878, CVE-2021-28879, and CVE-2021-31162. These are memory safety bugs in the Rust standard library. Because it is statically linked, affected applications will need to be rebuilt to benefit from the fixes. The actual security implications will depend on how these APIs are used in each particular case.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-d0ba1901ca 2021-04-24 20:00:51.081384 --------------------------------------------------------------------------------Name : rust Product : Fedora 34 Version : 1.51.0 Release : 3.fc34 URL : https://rust-lang.org/ Summary : The Rust Programming Language Description : Rust is a systems programming language that runs blazingly fast, prevents segfaults, and guarantees thread safety. This package includes the Rust compiler and documentation generator. --------------------------------------------------------------------------------Update Information: Security fixes for CVE-2020-36323, CVE-2021-28876, CVE-2021-28878, CVE-2021-28879, and CVE-2021-31162. These are memory safety bugs in the Rust standard library. Because it is statically linked, affected applications will need to be rebuilt to benefit from the fixes. The actual security implications will depend on how these APIs are used in each particular case. --------------------------------------------------------------------------------ChangeLog: * Fri Apr 16 2021 Josh Stone - 1.51.0-3 - Security fixes for CVE-2020-36323, CVE-2021-31162 * Wed Apr 14 2021 Josh Stone - 1.51.0-2 - Security fixes for CVE-2021-28876, CVE-2021-28878, CVE-2021-28879 - Fix bootstrap for stage0 rust 1.51 --------------------------------------------------------------------------------References: [ 1 ] Bug #1949198 - CVE-2021-28876 rust: panic safety issue in Zip implementation https://bugzilla.redhat.com/show_bug.cgi?id=1949198 [ 2] Bug #1949207 - CVE-2021-28878 rust: memory safety violation in Zip implementation when next_back() and next() are used together https://bugzilla.redhat.com/show_bug.cgi?id=1949207 [ 3 ] Bug #1949211 - CVE-2021-28879 rust: integer overflow in the Zip implementation can lead to a buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1949211 [ 4 ] Bug #1950396 - CVE-2020-36323 rust: optimization for joining strings can cause uninitialized bytes to be exposed https://bugzilla.redhat.com/show_bug.cgi?id=1950396 [ 5 ] Bug #1950398 - CVE-2021-31162 rust: double free in Vec::from_iter function if freeing the element panics https://bugzilla.redhat.com/show_bug.cgi?id=1950398 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-d0ba1901ca' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update for fapolicyd is now available for Red Hat Enterprise Linux 8. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description:. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: fapolicyd bug fix update Advisory ID: RHSA-2020:5607-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:5607 Issue date: 2020-12-17 ==================================================================== 1. Summary: An update for fapolicyd is now available for Red Hat Enterprise Linux 8. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: The fapolicyd software framework introduces a form of file access control based on a user-defined policy. The application file access control feature provides one of the most efficient ways to prevent running untrusted and possibly malicious applications on the system. Bug Fix(es): * When an update replaces the binary of a running application, the kernel modifies the application binary path in memory by appending the " (deleted)" suffix. Previously, the fapolicyd file access policy daemon treated such applications as untrusted, and prevented them from opening and executing any other files. As a consequence, the system was sometimes unable to boot after applying updates. With this update, fapolicyd ignores the suffix in the binary path so the binary can match the trust database. As a result, fapolicyd enforces the rules correctly and the update process can finish. (BZ#1906472) * Adding DISA STIG during OS installation causes 'ipa-server-install' to fail (BZ#1905895) Note: The issue from BZ#1906472 was previously addressed in erratum RHBA-2020:5242 linked to from the References section. Due to the high impact of theissue that can cause systems to become unable to boot, we are releasing the same fix again in a security erratum to ensure proper visibility to users who only install security updates. This fix has not been changed in any way since the original bug fix erratum. This erratum does not provide any security fixes. For more details about the issue, see the Knowledgebase article linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1905895 - Adding DISA STIG during OS installation causes 'ipa-server-install' to fail [rhel-8.3.0.z] 1906472 - Erratum RHBA-2020:4969 is of no help when upgrading partially RHEL 8.2 systems [rhel-8.3.0.z] 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: fapolicyd-1.0-3.el8_3.4.src.rpm aarch64: fapolicyd-1.0-3.el8_3.4.aarch64.rpm fapolicyd-debuginfo-1.0-3.el8_3.4.aarch64.rpm fapolicyd-debugsource-1.0-3.el8_3.4.aarch64.rpm noarch: fapolicyd-selinux-1.0-3.el8_3.4.noarch.rpm ppc64le: fapolicyd-1.0-3.el8_3.4.ppc64le.rpm fapolicyd-debuginfo-1.0-3.el8_3.4.ppc64le.rpm fapolicyd-debugsource-1.0-3.el8_3.4.ppc64le.rpm s390x: fapolicyd-1.0-3.el8_3.4.s390x.rpm fapolicyd-debuginfo-1.0-3.el8_3.4.s390x.rpm fapolicyd-debugsource-1.0-3.el8_3.4.s390x.rpm x86_64: fapolicyd-1.0-3.el8_3.4.x86_64.rpm fapolicyd-debuginfo-1.0-3.el8_3.4.x86_64.rpm fapolicyd-debugsource-1.0-3.el8_3.4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/errata/RHBA-2020:5242 https://access.redhat.com/solutions/5542661 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGINPGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX9sNQdzjgjWX9erEAQiM2RAAh86ks3RrW8QLPyRBwXh9/EQjKrAHxNeT S3ttKdPuJOdtPsJniXeJdZtODNRVZnZQet/aJUlQ+5xrmYXPmlhwf0r9+2HpnLap WtUYEczIPkf5siZrX6crnB4x2m6Nf4vYhUviSQDf/C49lhH3R8v9Xj4aTi43lPYF I8pBFjyZLgFeQR8tKhBuZOQpgtPHUOZumqC0jLXAL12/TpY3OIDLzJ0QjciEhk7v TtDeOp9wYw8NYyV76mYnVVVR1TXrjIGUOQm2BvSYZAL7lFtrEeiSMZeqS63FWvAH dKb5O8S8blL2c8Zx/djyjm8iCXoFULxeclkePbBl8waRZssX3EbLqrUrxs3GJd3w /EhKqpP8qdB07W2I47HZf2ggfoxva7vG2U91YyMSsm1ria2YJr9pqjm5ZSGjTVMK M6QYUfhQnkczZ+Dg18AS0o/ElkY+fP3z/W80oNBRclo+r9qZ6aB6Bccnr344MtCf c6chiBdeNpfpuayvPu6zpfKgo7tTJWMxWGkMpagOdVZaDjrumQIBbc0L1SLvs9UP fzclbR8hmb7MGDcE1s1dMZy2nBh7vN43unLlQmRsboEJGcll9rIvh1LZz2OON53L AuyPhGGw9/qN96MVBxo+RuC5EMfyNySonuYFzU/IFEBLdY4vl5V9g//Lkme6bddf YZqFLp6PfoE=RXdS -----END PGP SIGNATURE----- -- RHSA-announce mailing list
New upstream release * This fixes the security bug known as CVE-2018-5345 * Add new API for fwupd * Do not encode timezone in generated files * Fix countless memory leaks when parsing corrupt files * Fix the calculation of the checksum on big endian machines * Switch to the Meson buildsystem. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-87971e3c98 2018-01-30 17:59:49.778389 --------------------------------------------------------------------------------Name : gcab Product : Fedora 27 Version : 1.0 Release : 1.fc27 URL : https://download.gnome.org/sources/gcab/ Summary : Cabinet file library and tool Description : gcab is a tool to manipulate Cabinet archive. --------------------------------------------------------------------------------Update Information: New upstream release * This fixes the security bug known as CVE-2018-5345 * Add new API for fwupd * Do not encode timezone in generated files * Fix countless memory leaks when parsing corrupt files * Fix the calculation of the checksum on big endian machines * Switch to the Meson buildsystem --------------------------------------------------------------------------------References: [ 1 ] Bug #1527062 https://bugzilla.redhat.com/show_bug.cgi?id=1527062 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade gcab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.