Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 20.04 LTS: Severe DoS Vulnerability in Linux Kernel 6767-1

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-6767-1 May 07, 2024 linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-iot: Linux kernel for IoT platforms - linux-kvm: Linux kernel for cloud environments - linux-oracle: Linux kernel for Oracle Cloud systems - linux-raspi: Linux kernel for Raspberry Pi systems - linux-xilinx-zynqmp: Linux kernel for Xilinx ZynqMP processors - linux-aws-5.4: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.4: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.4: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.4: Linux hardware enablement (HWE) kernel - linux-ibm-5.4: Linux kernel for IBM cloud systems - linux-oracle-5.4: Linux kernel for Oracle Cloud systems - linux-raspi-5.4: Linux kernel for Raspberry Pi systems Details: Chenyuan Yang discovered that the RDS Protocol implementation in the Linux kernel contained an out-of-bounds read vulnerability. An attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-23849) Several securityissues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - S390 architecture; - Block layer subsystem; - Android drivers; - Hardware random number generator core; - GPU drivers; - Hardware monitoring drivers; - I2C subsystem; - IIO Magnetometer sensors drivers; - InfiniBand drivers; - Network drivers; - PCI driver for MicroSemi Switchtec; - PHY drivers; - Ceph distributed file system; - Ext4 file system; - JFS file system; - NILFS2 file system; - Pstore file system; - Core kernel; - Memory management; - CAN network layer; - Networking core; - IPv4 networking; - Logical Link layer; - Netfilter; - NFC subsystem; - SMC sockets; - Sun RPC protocol; - TIPC protocol; - Realtek audio codecs; (CVE-2024-26696, CVE-2023-52583, CVE-2024-26720, CVE-2023-52615, CVE-2023-52599, CVE-2023-52587, CVE-2024-26635, CVE-2024-26704, CVE-2024-26625, CVE-2024-26825, CVE-2023-52622, CVE-2023-52435, CVE-2023-52617, CVE-2023-52598, CVE-2024-26645, CVE-2023-52619, CVE-2024-26593, CVE-2024-26685, CVE-2023-52602, CVE-2023-52486, CVE-2024-26697, CVE-2024-26675, CVE-2024-26600, CVE-2023-52604, CVE-2024-26664, CVE-2024-26606, CVE-2023-52594, CVE-2024-26671, CVE-2024-26598, CVE-2024-26673, CVE-2024-26920, CVE-2024-26722, CVE-2023-52601, CVE-2024-26602, CVE-2023-52637, CVE-2023-52623, CVE-2024-26702, CVE-2023-52597, CVE-2024-26684, CVE-2023-52606, CVE-2024-26679, CVE-2024-26663, CVE-2024-26910, CVE-2024-26615, CVE-2023-52595, CVE-2023-52607, CVE-2024-26636) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1036-iot 5.4.0-1036.37 linux-image-5.4.0-1043-xilinx-zynqmp 5.4.0-1043.47 linux-image-5.4.0-1071-ibm 5.4.0-1071.76 linux-image-5.4.0-1091-gkeop 5.4.0-1091.95 linux-image-5.4.0-1108-raspi 5.4.0-1108.120 linux-image-5.4.0-1112-kvm 5.4.0-1112.119 linux-image-5.4.0-1123-oracle 5.4.0-1123.132 linux-image-5.4.0-1124-aws 5.4.0-1124.134 linux-image-5.4.0-1128-gcp 5.4.0-1128.137 linux-image-5.4.0-1129-azure 5.4.0-1129.136 linux-image-5.4.0-181-generic 5.4.0-181.201 linux-image-5.4.0-181-generic-lpae 5.4.0-181.201 linux-image-5.4.0-181-lowlatency 5.4.0-181.201 linux-image-aws-lts-20.04 5.4.0.1124.121 linux-image-azure-lts-20.04 5.4.0.1129.123 linux-image-gcp-lts-20.04 5.4.0.1128.130 linux-image-generic 5.4.0.181.179 linux-image-generic-lpae 5.4.0.181.179 linux-image-gkeop 5.4.0.1091.89 linux-image-gkeop-5.4 5.4.0.1091.89 linux-image-ibm-lts-20.04 5.4.0.1071.100 linux-image-kvm 5.4.0.1112.108 linux-image-lowlatency 5.4.0.181.179 linux-image-oem 5.4.0.181.179 linux-image-oem-osp1 5.4.0.181.179 linux-image-oracle-lts-20.04 5.4.0.1123.116 linux-image-raspi 5.4.0.1108.138 linux-image-raspi2 5.4.0.1108.138 linux-image-virtual 5.4.0.181.179 linux-image-xilinx-zynqmp 5.4.0.1043.43 Ubuntu 18.04 LTS linux-image-5.4.0-1071-ibm 5.4.0-1071.76~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1108-raspi 5.4.0-1108.120~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1123-oracle 5.4.0-1123.132~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1124-aws 5.4.0-1124.134~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1128-gcp 5.4.0-1128.137~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-1129-azure 5.4.0-1129.136~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-181-generic 5.4.0-181.201~18.04.1 Available with Ubuntu Pro linux-image-5.4.0-181-lowlatency 5.4.0-181.201~18.04.1 Available with Ubuntu Pro linux-image-aws 5.4.0.1124.134~18.04.1 Available with Ubuntu Pro linux-image-azure 5.4.0.1129.136~18.04.1 Available with Ubuntu Pro linux-image-gcp 5.4.0.1128.137~18.04.1 Available with Ubuntu Pro linux-image-generic-hwe-18.04 5.4.0.181.201~18.04.1 Available with Ubuntu Pro linux-image-ibm 5.4.0.1071.76~18.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-18.04 5.4.0.181.201~18.04.1 Available with Ubuntu Pro linux-image-oem 5.4.0.181.201~18.04.1 Available with Ubuntu Pro linux-image-oem-osp1 5.4.0.181.201~18.04.1 Available with Ubuntu Pro linux-image-oracle 5.4.0.1123.132~18.04.1 Available with Ubuntu Pro linux-image-raspi-hwe-18.04 5.4.0.1108.120~18.04.1 Available with Ubuntu Pro linux-image-snapdragon-hwe-18.04 5.4.0.181.201~18.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-18.04 5.4.0.181.201~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third partykernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6767-1 CVE-2023-52435, CVE-2023-52486, CVE-2023-52583, CVE-2023-52587, CVE-2023-52594, CVE-2023-52595, CVE-2023-52597, CVE-2023-52598, CVE-2023-52599, CVE-2023-52601, CVE-2023-52602, CVE-2023-52604, CVE-2023-52606, CVE-2023-52607, CVE-2023-52615, CVE-2023-52617, CVE-2023-52619, CVE-2023-52622, CVE-2023-52623, CVE-2023-52637, CVE-2024-23849, CVE-2024-26593, CVE-2024-26598, CVE-2024-26600, CVE-2024-26602, CVE-2024-26606, CVE-2024-26615, CVE-2024-26625, CVE-2024-26635, CVE-2024-26636, CVE-2024-26645, CVE-2024-26663, CVE-2024-26664, CVE-2024-26671, CVE-2024-26673, CVE-2024-26675, CVE-2024-26679, CVE-2024-26684, CVE-2024-26685, CVE-2024-26696, CVE-2024-26697, CVE-2024-26702, CVE-2024-26704, CVE-2024-26720, CVE-2024-26722, CVE-2024-26825, CVE-2024-26910, CVE-2024-26920 Package Information: https://launchpad.net/ubuntu/+source/linux/5.4.0-181.201 https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1124.134 https://launchpad.net/ubuntu/+source/linux-azure/5.4.0-1129.136 https://launchpad.net/ubuntu/+source/linux-gcp/5.4.0-1128.137 https://launchpad.net/ubuntu/+source/linux-gkeop/5.4.0-1091.95 https://launchpad.net/ubuntu/+source/linux-ibm/5.4.0-1071.76 https://launchpad.net/ubuntu/+source/linux-iot/5.4.0-1036.37 https://launchpad.net/ubuntu/+source/linux-kvm/5.4.0-1112.119 https://launchpad.net/ubuntu/+source/linux-oracle/5.4.0-1123.132 https://launchpad.net/ubuntu/+source/linux-raspi/5.4.0-1108.120 https://launchpad.net/ubuntu/+source/linux-xilinx-zynqmp/5.4.0-1043.47 . The latest patches for Ubuntu tackle significant vulnerabilities within the Linux core that may result in unauthorized access to the system..Linux Kernel Update, Ubuntu Security, System Compromise. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2024 Critical Ubuntu
89

Fedora 37: FEDORA-2022-dacf699829 Critical: qpress Directory Traversal

Security fix for CVE-2022-45866. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-dacf699829 2022-12-04 00:28:03.934099 --------------------------------------------------------------------------------Name : qpress Product : Fedora 37 Version : 20220819 Release : 1.fc37 URL : Summary : A portable file archiver using QuickLZ Description : qpress is a portable file archiver using QuickLZ and designed to utilize fast storage systems to their max. It's often faster than file copy because the destination is smaller than the source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-45866 --------------------------------------------------------------------------------ChangeLog: * Fri Nov 25 2022 Davide Cavalca 20220819-1 - Switch to new upstream and update to 20220819 (Fixes: RHBZ#2147535, RHBZ#2147537) --------------------------------------------------------------------------------References: [ 1 ] Bug #2147535 - CVE-2022-45866 qpress: directory traversal via ../ in a .qp file https://bugzilla.redhat.com/show_bug.cgi?id=2147535 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-dacf699829' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 37 addresses a vulnerability in qpress related to directory traversal, detailed in advisory FEDORA-2022-dacf699829.. Fedora 37, qpress update, directory traversal fix, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 04, 2022 Critical Fedora
91

Gentoo: GLSA-202209-04 Critical: OpenJPEG Arbitrary Code Execution

Multiple vulnerabilities have been discovered in OpenJPEG, the worst of which could result in arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202209-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: OpenJPEG: Multiple Vulnerabilities Date: September 07, 2022 Bugs: #783513, #836969, #844064 ID: 202209-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in OpenJPEG, the worst of which could result in arbitrary code execution. Background ========= OpenJPEG is an open-source JPEG 2000 library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/openjpeg < 2.5.0 > = 2.5.0 Description ========== Multiple vulnerabilities have been discovered in OpenJPEG. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All OpenJPEG 2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/openjpeg-2.5.0" References ========= [ 1 ] CVE-2021-29338 https://nvd.nist.gov/vuln/detail/CVE-2021-29338 [ 2 ] CVE-2022-1122 https://nvd.nist.gov/vuln/detail/CVE-2022-1122 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202209-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous security flaws discovered in OpenJPEG may result in unauthorized code execution. Implement system defenses urgently.. OpenJPEG Vulnerabilities, Gentoo Advisory, Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 Sep 06, 2022 Gentoo
202

openSUSE Leap 15.3 and 15.4: 2022:0366-1 Critical Kernel Fixes

An update that solves 27 vulnerabilities and has 23 fixes is now available. . openSUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0366-1 Rating: critical References: #1071995 #1124431 #1167162 #1169514 #1172073 #1179599 #1184804 #1185377 #1186207 #1186222 #1187167 #1189305 #1189841 #1190358 #1190428 #1191229 #1191241 #1191384 #1191731 #1192032 #1192267 #1192740 #1192845 #1192847 #1192877 #1192946 #1193306 #1193440 #1193442 #1193575 #1193669 #1193727 #1193731 #1193767 #1193861 #1193864 #1193867 #1193927 #1194001 #1194048 #1194087 #1194227 #1194302 #1194516 #1194529 #1194880 #1194888 #1194985 #1195166 #1195254 Cross-References: CVE-2018-25020 CVE-2019-15126 CVE-2020-27820 CVE-2021-0920 CVE-2021-0935 CVE-2021-28711 CVE-2021-28712 CVE-2021-28713 CVE-2021-28714 CVE-2021-28715 CVE-2021-33098 CVE-2021-3564 CVE-2021-39648 CVE-2021-39657 CVE-2021-4002 CVE-2021-4083 CVE-2021-4135 CVE-2021-4149 CVE-2021-4197 CVE-2021-4202 CVE-2021-43975 CVE-2021-43976 CVE-2021-44733 CVE-2021-45095 CVE-2021-45486 CVE-2022-0322 CVE-2022-0330 CVSS scores: CVE-2018-25020 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2019-15126 (NVD) : 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2019-15126 (SUSE): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2020-27820 (SUSE): 3.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L CVE-2021-0920 (NVD) : 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0920 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-0935 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-28711 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-28711 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28712 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-28712 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28713 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-28713 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28714 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-28714 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-28715 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVE-2021-28715 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-33098 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-33098 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-3564 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-3564 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-39648 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2021-39657 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVE-2021-4002 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2021-4083 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-4135 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-4149 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-4197 (SUSE): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2021-4202 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-43975 (SUSE): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-43976 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-44733 (SUSE): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L CVE-2021-45095 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-45095 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE-2021-45486 (NVD) : 3.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVE-2021-45486 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-0322 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves 27 vulnerabilities and has 23 fixes is now available. Description: The SUSE Linux Enterprise 15 SP1 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-0435: Fixed remote stack overflow in net/tipc module that validate domain record count on input (bsc#1195254). - CVE-2022-0330: Fixed flush TLBs before releasing backing store (bsc#1194880). - CVE-2021-45486: Fixed an information leak because the hash table is very small in net/ipv4/route.c (bnc#1194087). - CVE-2021-45095: Fixed refcount leak in pep_sock_accept in net/phonet/pep.c (bnc#1193867). - CVE-2021-44733: Fixed a use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem, that could have occured because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object (bnc#1193767). - CVE-2021-43976: Fixed aflaw that could allow an attacker (who can connect a crafted USB device) to cause a denial of service. (bnc#1192847) - CVE-2021-43975: Fixed a flaw in hw_atl_utils_fw_rpc_wait that could allow an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. (bsc#1192845) - CVE-2021-4202: Fixed NFC race condition by adding NCI_UNREG flag (bsc#1194529). - CVE-2021-4197: Use cgroup open-time credentials for process migraton perm checks (bsc#1194302). - CVE-2021-4159: Fixed kernel ptr leak vulnerability via BPF in coerce_reg_to_size (bsc#1194227). - CVE-2021-4149: Fixed btrfs unlock newly allocated extent buffer after error (bsc#1194001). - CVE-2021-4135: Fixed zero-initialize memory inside netdevsim for new map's value in function nsim_bpf_map_alloc (bsc#1193927). - CVE-2021-4083: Fixed a read-after-free memory flaw inside the garbage collection for Unix domain socket file handlers when users call close() and fget() simultaneouslyand can potentially trigger a race condition (bnc#1193727). - CVE-2021-4002: Fixed incorrect TLBs flush in hugetlbfs after huge_pmd_unshare (bsc#1192946). - CVE-2021-39657: Fixed out of bounds read due to a missing bounds check in ufshcd_eh_device_reset_handler of ufshcd.c. This could lead to local information disclosure with System execution privileges needed (bnc#1193864). - CVE-2021-39648: Fixed possible disclosure of kernel heap memory due to a race condition in gadget_dev_desc_UDC_show of configfs.c. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation (bnc#1193861). - CVE-2021-3564: Fixed double-free memory corruption in the Linux kernel HCI device initialization subsystem that could have been used by attaching malicious HCI TTY Bluetooth devices. A local user could use this flaw to crash the system (bnc#1186207). -CVE-2021-33098: Fixed a potential denial of service in Intel(R) Ethernet ixgbe driver due to improper input validation. (bsc#1192877) - CVE-2021-28715: Fixed issue with xen/netback to do not queue unlimited number of packages (XSA-392) (bsc#1193442). - CVE-2021-28714: Fixed issue with xen/netback to handle rx queue stall detection (XSA-392) (bsc#1193442). - CVE-2021-28713: Fixed issue with xen/console to harden hvc_xen against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-28712: Fixed issue with xen/netfront to harden netfront against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-28711: Fixed issue with xen/blkfront to harden blkfront against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-0935: Fixed possible out of bounds write in ip6_xmit of ip6_output.c due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation (bnc#1192032). - CVE-2021-0920: Fixed a local privilege escalation due to an use after free bug in unix_gc (bsc#1193731). - CVE-2020-27820: Fixed a vulnerability where a use-after-frees in nouveau's postclose() handler could happen if removing device (bsc#1179599). - CVE-2019-15126: Fixed a vulnerability in Broadcom and Cypress Wi-Fi chips, used in RPi family of devices aka "Kr00k". (bsc#1167162) - CVE-2018-25020: Fixed an overflow in the BPF subsystem due to a mishandling of a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions. This affects kernel/bpf/core.c and net/core/filter.c (bnc#1193575). The following non-security bugs were fixed: - Bluetooth: fix the erroneous flush_work() order (git-fixes). - Build: Add obsolete_rebuilds_subpackage (boo#1172073 bsc#1191731). - ICMPv6: Add ICMPv6 Parameter Problem, code 3 definition (bsc#1191241 bsc#1195166). - IPv6:reply ICMP error if the first fragment do not include all headers (bsc#1191241). - elfcore: fix building with clang (bsc#1169514). - hv_netvsc: Set needed_headroom according to VF (bsc#1193506). - ipv6/netfilter: Discard first fragment not including all headers (bsc#1191241 bsc#1195166). - kernel-*-subpackage: Add dependency on kernel scriptlets (bsc#1192740). - kernel-binary.spec.in Stop templating the scriptlets for subpackages (bsc#1190358). - kernel-binary.spec.in: add zstd to BuildRequires if used - kernel-binary.spec.in: make sure zstd is supported by kmod if used - kernel-binary.spec: Check for no kernel signing certificates. Also remove unused variable. - kernel-binary.spec: Define $image as rpm macro (bsc#1189841). - kernel-binary.spec: Do not fail silently when KMP is empty (bsc#1190358). Copy the code from kernel-module-subpackage that deals with empty KMPs. - kernel-binary.spec: Do not sign kernel when no key provided (bsc#1187167). - kernel-binary.spec: Fix kernel-default-base scriptlets after packaging merge. - kernel-binary.spec: Require dwarves for kernel-binary-devel when BTF is enabled (jsc#SLE-17288). - kernel-binary.spec: suse-kernel-rpm-scriptlets required for uninstall as well. - kernel-cert-subpackage: Fix certificate location in scriptlets (bsc#1189841). - kernel-source.spec: install-kernel-tools also required on 15.4 - kernel-spec-macros: Since rpm 4.17 %verbose is unusable (bsc#1191229). The semantic changed in an incompatible way so invoking the macro now causes a build failure. - kprobes: Limit max data_size of the kretprobe instances (bsc#1193669). - livepatch: Avoid CPU hogging with cond_resched (bsc#1071995). - memstick: rtsx_usb_ms: fix UAF (bsc#1194516). - moxart: fix potential use-after-free on remove path (bsc#1194516). - net, xdp: Introduce xdp_init_buff utility routine (bsc#1193506). - net, xdp: Introduce xdp_prepare_buff utility routine(bsc#1193506). - net: Using proper atomic helper (bsc#1186222). - net: ipv6: Discard next-hop MTU less than minimum link MTU (bsc#1191241). - net: mana: Add RX fencing (bsc#1193506). - net: mana: Add XDP support (bsc#1193506). - net: mana: Allow setting the number of queues while the NIC is down (bsc#1193506). - net: mana: Fix spelling mistake "calledd" -> "called" (bsc#1193506). - net: mana: Fix the netdev_err()'s vPort argument in mana_init_port() (bsc#1193506). - net: mana: Improve the HWC error handling (bsc#1193506). - net: mana: Support hibernation and kexec (bsc#1193506). - net: mana: Use kcalloc() instead of kzalloc() (bsc#1193506). - objtool: Support Clang non-section symbols in ORC generation (bsc#1169514). - post.sh: detect /usr mountpoint too - recordmcount.pl: fix typo in s390 mcount regex (bsc#1192267). - recordmcount.pl: look for jgnop instruction as well as bcrl on s390 (bsc#1192267). - rpm/kernel-binary.spec.in: Use kmod-zstd provide. This makes it possible to use kmod with ZSTD support on non-Tumbleweed. - rpm/kernel-binary.spec.in: avoid conflicting suse-release suse-release had arbitrary values in staging, we can't use it for dependencies. The filesystem one has to be enough (boo#1184804). - rpm/kernel-binary.spec.in: do not strip vmlinux again (bsc#1193306). - rpm/kernel-binary.spec: Use only non-empty certificates. - rpm/kernel-obs-build.spec.in: make builds reproducible (bsc#1189305). - rpm/kernel-source.rpmlintrc: ignore new include/config files. - rpm/kernel-source.spec.in: do some more for vanilla_only. - rpm: Abolish image suffix (bsc#1189841). - rpm: Abolish scritplet templating (bsc#1189841). Outsource kernel-binary and KMP scriptlets to suse-module-tools. - rpm: Define $certs as rpm macro (bsc#1189841). - rpm: Fold kernel-devel and kernel-source scriptlets into spec files (bsc#1189841). - rpm: fix kmp install path - rpm: use _rpmmacrodir (boo#1191384) -tty: hvc: replace BUG_ON() with negative return value. - vfs: check fd has read access in kernel_read_file_from_fd() (bsc#1194888). - x86/xen: Mark cpu_bringup_and_idle() as dead_end_function (bsc#1169514). - xen/blkfront: do not take local copy of a request from the ring page (git-fixes). - xen/blkfront: do not trust the backend response data blindly (git-fixes). - xen/blkfront: read response from backend only once (git-fixes). - xen/netfront: disentangle tx_skb_freelist (git-fixes). - xen/netfront: do not read data from request on the ring page (git-fixes). - xen/netfront: do not trust the backend response data blindly (git-fixes). - xen/netfront: read response from backend only once (git-fixes). - xen: sync include/xen/interface/io/ring.h with Xen's newest version (git-fixes). - xfrm: fix MTU regression (bsc#1185377, bsc#1194048). Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-366=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-366=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): kernel-default-base-debuginfo-4.12.14-197.105.1 kernel-vanilla-4.12.14-197.105.1 kernel-vanilla-base-4.12.14-197.105.1 kernel-vanilla-base-debuginfo-4.12.14-197.105.1 kernel-vanilla-debuginfo-4.12.14-197.105.1 kernel-vanilla-debugsource-4.12.14-197.105.1 kernel-vanilla-devel-4.12.14-197.105.1 kernel-vanilla-devel-debuginfo-4.12.14-197.105.1 kernel-vanilla-livepatch-devel-4.12.14-197.105.1 - openSUSE Leap 15.4 (ppc64le x86_64): kernel-debug-base-4.12.14-197.105.1 kernel-debug-base-debuginfo-4.12.14-197.105.1 - openSUSELeap 15.4 (x86_64): kernel-kvmsmall-base-4.12.14-197.105.1 kernel-kvmsmall-base-debuginfo-4.12.14-197.105.1 - openSUSE Leap 15.4 (s390x): kernel-default-man-4.12.14-197.105.1 kernel-zfcpdump-man-4.12.14-197.105.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): kernel-default-base-debuginfo-4.12.14-197.105.1 kernel-vanilla-4.12.14-197.105.1 kernel-vanilla-base-4.12.14-197.105.1 kernel-vanilla-base-debuginfo-4.12.14-197.105.1 kernel-vanilla-debuginfo-4.12.14-197.105.1 kernel-vanilla-debugsource-4.12.14-197.105.1 kernel-vanilla-devel-4.12.14-197.105.1 kernel-vanilla-devel-debuginfo-4.12.14-197.105.1 kernel-vanilla-livepatch-devel-4.12.14-197.105.1 - openSUSE Leap 15.3 (ppc64le x86_64): kernel-debug-base-4.12.14-197.105.1 kernel-debug-base-debuginfo-4.12.14-197.105.1 - openSUSE Leap 15.3 (x86_64): kernel-kvmsmall-base-4.12.14-197.105.1 kernel-kvmsmall-base-debuginfo-4.12.14-197.105.1 - openSUSE Leap 15.3 (s390x): kernel-default-man-4.12.14-197.105.1 kernel-zfcpdump-man-4.12.14-197.105.1 References: https://www.suse.com/security/cve/CVE-2018-25020.html https://www.suse.com/security/cve/CVE-2019-15126.html https://www.suse.com/security/cve/CVE-2020-27820.html https://www.suse.com/security/cve/CVE-2021-0920.html https://www.suse.com/security/cve/CVE-2021-0935.html https://www.suse.com/security/cve/CVE-2021-28711.html https://www.suse.com/security/cve/CVE-2021-28712.html https://www.suse.com/security/cve/CVE-2021-28713.html https://www.suse.com/security/cve/CVE-2021-28714.html https://www.suse.com/security/cve/CVE-2021-28715.html https://www.suse.com/security/cve/CVE-2021-33098.html https://www.suse.com/security/cve/CVE-2021-3564.html https://www.suse.com/security/cve/CVE-2021-39648.html https://www.suse.com/security/cve/CVE-2021-39657.html https://www.suse.com/security/cve/CVE-2021-4002.html https://www.suse.com/security/cve/CVE-2021-4083.html https://www.suse.com/security/cve/CVE-2021-4135.html https://www.suse.com/security/cve/CVE-2021-4149.html https://www.suse.com/security/cve/CVE-2021-4197.html https://www.suse.com/security/cve/CVE-2021-4202.html https://www.suse.com/security/cve/CVE-2021-43975.html https://www.suse.com/security/cve/CVE-2021-43976.html https://www.suse.com/security/cve/CVE-2021-44733.html https://www.suse.com/security/cve/CVE-2021-45095.html https://www.suse.com/security/cve/CVE-2021-45486.html https://www.suse.com/security/cve/CVE-2022-0322.html https://www.suse.com/security/cve/CVE-2022-0330.html https://bugzilla.suse.com/1071995 https://bugzilla.suse.com/1124431 https://bugzilla.suse.com/1167162 https://bugzilla.suse.com/1169514 https://bugzilla.suse.com/1172073 https://bugzilla.suse.com/1179599 https://bugzilla.suse.com/1184804 https://bugzilla.suse.com/1185377 https://bugzilla.suse.com/1186207 https://bugzilla.suse.com/1186222 https://bugzilla.suse.com/1187167 https://bugzilla.suse.com/1189305 https://bugzilla.suse.com/1189841 https://bugzilla.suse.com/1190358 https://bugzilla.suse.com/1190428 https://bugzilla.suse.com/1191229 https://bugzilla.suse.com/1191241 https://bugzilla.suse.com/1191384 https://bugzilla.suse.com/1191731 https://bugzilla.suse.com/1192032 https://bugzilla.suse.com/1192267 https://bugzilla.suse.com/1192740 https://bugzilla.suse.com/1192845 https://bugzilla.suse.com/1192847 https://bugzilla.suse.com/1192877 https://bugzilla.suse.com/1192946 https://bugzilla.suse.com/1193306 https://bugzilla.suse.com/1193440 https://bugzilla.suse.com/1193442 https://bugzilla.suse.com/1193575 https://bugzilla.suse.com/1193669 https://bugzilla.suse.com/1193727 https://bugzilla.suse.com/1193731 https://bugzilla.suse.com/1193767 https://bugzilla.suse.com/1193861 https://bugzilla.suse.com/1193864 https://bugzilla.suse.com/1193867 https://bugzilla.suse.com/1193927 https://bugzilla.suse.com/1194001 https://bugzilla.suse.com/1194048 https://bugzilla.suse.com/1194087 https://bugzilla.suse.com/1194227 https://bugzilla.suse.com/1194302 https://bugzilla.suse.com/1194516 https://bugzilla.suse.com/1194529 https://bugzilla.suse.com/1194880 https://bugzilla.suse.com/1194888 https://bugzilla.suse.com/1194985 https://bugzilla.suse.com/1195166 https://bugzilla.suse.com/1195254 . Important security patch released for the openSUSE Linux kernel rectifying 27 security flaws, with various solutions provided.. Linux Kernel Update, openSUSE Security Patch, Critical Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 10, 2022 Critical OpenSUSE
89

Fedora 25 msgpuck Security Update: Critical DoS Threats Fixed

Security fix for CVE-2016-9036, CVE-2016-9037. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-2d0c8ba781 2016-12-22 02:23:28.605419 -------------------------------------------------------------------------------- Name : msgpuck Product : Fedora 25 Version : 1.1.3 Release : 1.fc25 URL : https://github.com/rtsisyk/msgpuck Summary : MsgPack binary serialization library in a self-contained header Description : MsgPack is a binary-based efficient object serialization library. It enables to exchange structured objects between many languages like JSON. But unlike JSON, it is very fast and small. msgpuck is very lightweight header-only library designed to be embedded to your application by the C/C++ compiler. The library is fully documented and covered by unit tests. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9036, CVE-2016-9037 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406682 - CVE-2016-9036 CVE-2016-9037 tarantool: Multiple DoS vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1406682 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade msgpuck' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patches for msgpuck in Fedora 25 aiming to fix several denial-of-service vulnerabilities. Make sure your system is protected.. Fedora MsgPack Update, DoS Security Fix, Binary Serialization Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 22, 2016 Critical Fedora
202

openSUSE 13.1: 2016:0529-1 Critical: Chromium Same-Origin Bypass

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for Chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:0529-1 Rating: critical References: Affected Products: openSUSE 13.1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update contains Chromium 48.0.2564.116 and fixes the following security flaw: - CVE-2016-1629: Same-origin bypass in Blink and Sandbox escape in Chrome. (boo#967376) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.1: zypper in -t patch 2016-249=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.1 (i586 x86_64): chromedriver-48.0.2564.116-129.1 chromedriver-debuginfo-48.0.2564.116-129.1 chromium-48.0.2564.116-129.1 chromium-debuginfo-48.0.2564.116-129.1 chromium-debugsource-48.0.2564.116-129.1 chromium-desktop-gnome-48.0.2564.116-129.1 chromium-desktop-kde-48.0.2564.116-129.1 chromium-ffmpegsumo-48.0.2564.116-129.1 chromium-ffmpegsumo-debuginfo-48.0.2564.116-129.1 References: -- . Important security patch released for Fedora's Firefox tackling cross-origin exploitation and confinement breach.. openSUSE Security Updates, Chromium Security Fixes, Same-Origin Bypass Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 20, 2016 Critical OpenSUSE
89

Fedora 22: 2015-11163 Critical: CUPS Filters DoS Security Fix

Fixes CVE-2015-3258 & CVE-2015-3279. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11163 2015-07-04 17:44:30 -------------------------------------------------------------------------------- Name : cups-filtersProduct : Fedora 22 Version : 1.0.71 Release : 1.fc22 URL : : OpenPrinting CUPS filters and backends Description : Contains backends, filters, and other software that was once part of the core CUPS distribution but is no longer maintained by Apple Inc. In addition it contains additional filters developed independently of Apple, especially filters for the PDF-centric printing workflow introduced by OpenPrinting. -------------------------------------------------------------------------------- Update Information: Fixes CVE-2015-3258 & CVE-2015-3279 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2015 Jiri Popelka - 1.0.71-1 - 1.0.71 * Mon Jun 29 2015 Jiri Popelka - 1.0.70-1 - 1.0.70 * Mon Jun 22 2015 Tim Waugh - 1.0.69-2 - Fixes for glib source handling (bug #1228555). * Thu Jun 11 2015 Jiri Popelka - 1.0.69-1 - 1.0.69 * Tue Apr 14 2015 Jiri Popelka - 1.0.68-1 - 1.0.68 * Wed Mar 11 2015 Jiri Popelka - 1.0.67-1 - 1.0.67 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update cups-filters' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . CUPS Software Patch Addresses Various Vulnerabilities in Fedora 22. Ensure Your System is Secured by Using YUM to Apply the Latest Updates.. CUPS Filters, Fedora Update, Critical Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 14, 2015 Critical Fedora
87

Ubuntu: 920-4 High: Python-Web-App Cross-Site Scripting Vulnerability

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 811-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze September 14th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : common-lisp-controller Vulnerability : design error Problem type : local Debian-specific: no CVE ID : CAN-2005-2657 François-René Rideau discovered a bug in common-lisp-controller, a Common Lisp source and compiler manager, that allows a local user to compile malicious code into a cache directory which is executed by another user if that user has not used Common Lisp before. The old stable distribution (woody) is not affected by this problem. For the stable distribution (sarge) this problem has been fixed in version 4.15sarge2. For the unstable distribution (sid) this problem has been fixed in version 4.18. We recommend that you upgrade your common-lisp-controller package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 599 bcb4fb7eb8c11f08446b6e4105f2a822 Size/MD5 checksum: 25058 cdcdf88a0ff8e5bf836769d623e25638 Architecture independent components: Size/MD5 checksum: 24090 156cd8800e862992ff0feed5d8f59a47 These files will probably be moved into the stable distribution on itsnext update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Document repository procedures and adopt best practices to secure user inputs. Sanitize and validate all inputs; implement access controls and conduct regular audits.. Debian, Common Lisp, Code Injection Advisory. . LinuxSecurity.com Team

Calendar 2 Sep 14, 2005 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here