Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2669 http://linux.oracle.com/errata/ELSA-2025-2669.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-apphost-pack-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-hostfxr-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-runtime-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-sdk-8.0-8.0.114-1.0.1.el9_5.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.114-1.0.1.el9_5.x86_64.rpm dotnet-targeting-pack-8.0-8.0.14-1.0.1.el9_5.x86_64.rpm dotnet-templates-8.0-8.0.114-1.0.1.el9_5.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.114-1.0.1.el9_5.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-apphost-pack-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-hostfxr-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-runtime-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-sdk-8.0-8.0.114-1.0.1.el9_5.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.114-1.0.1.el9_5.aarch64.rpm dotnet-targeting-pack-8.0-8.0.14-1.0.1.el9_5.aarch64.rpm dotnet-templates-8.0-8.0.114-1.0.1.el9_5.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.114-1.0.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//dotnet8.0-8.0.114-1.0.1.el9_5.src.rpm Related CVEs: CVE-2025-24070 Description of changes: [8.0.114-1.0.1] - Add support for Oracle Linux [8.0.114-1] - Update to .NET SDK 8.0.114 and Runtime 8.0.14 - Resolves: RHEL-81640 _______________________________________________ El-errata mailinglist
This is major rework of alternatives usage. We are (finally!) dropping the parallel installs support, and moving back to good, old "java-xyz-openjdk" major alternatives target January CPU 2025. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-15a818859e 2025-02-28 01:45:23.364639+00:00 -------------------------------------------------------------------------------- Name : java-17-openjdk Product : Fedora 40 Version : 17.0.14.0.7 Release : 6.fc40 URL : https://openjdk.org/ Summary : OpenJDK 17 Runtime Environment Description : The OpenJDK 17 runtime environment. -------------------------------------------------------------------------------- Update Information: This is major rework of alternatives usage. We are (finally!) dropping the parallel installs support, and moving back to good, old "java-xyz-openjdk" major alternatives target January CPU 2025 -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 12 2025 Jiri - 1:17.0.14.0.7-2 - Removed parallel installs support * Tue Jan 28 2025 Jiri Vanek - 1:17.0.14.0.7-1 - January CPU 2025 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-15a818859e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in Git.. ========================================================================== Ubuntu Security Notice USN-7207-2 February 27, 2025 git vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-7207-1 fixed vulnerabilities in Git. This update provides the corresponding updates for Ubuntu 20.04 LTS. Original advisory details: It was discovered that Git incorrectly handled certain URLs when asking for credentials. An attacker could possibly use this issue to mislead the user into typing passwords for trusted sites that would then be sent to untrusted sites instead. (CVE-2024-50349) It was discovered that git incorrectly handled line endings when using credential helpers. (CVE-2024-52006) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS git 1:2.25.1-1ubuntu3.14 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7207-2 https://ubuntu.com/security/notices/USN-7207-1 CVE-2024-50349, CVE-2024-52006 Package Information: https://launchpad.net/ubuntu/+source/git/1:2.25.1-1ubuntu3.14 . The Ubuntu Security Notice USN-7208-3 outlines critical patches for vulnerabilities in Git impacting Ubuntu 22.04 LTS.. Ubuntu Git Update, Security Fix, Credential Management, Threat Assessment. . Severity: Critical. LinuxSecurity.com Team
Important: nodejs:22 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:1611", "synopsis": "Important: nodejs:22 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for module.nodejs-packaging, nodejs-nodemon, nodejs-packaging, module.nodejs-nodemon, nodejs, module.nodejs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* undici: Undici Uses Insufficiently Random Values (CVE-2025-22150)\n\n* nodejs: Node.js Worker Thread Exposure via Diagnostics Channel (CVE-2025-23083)\n\n* nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2339176", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2339176", "description": ""}, {"ticket": "2339392", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2339392", "description": ""}, {"ticket": "2342618", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2342618", "description": ""}], "cves": [{"name": "CVE-2025-22150", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-22150", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-23083", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-23083", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2025-23085", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-23085", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2025-02-26T19:09:52.852483Z", "rpms": {"Rocky Linux 8": {"nvras": ["nodejs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.src.rpm", "nodejs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-debuginfo-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-debuginfo-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-debugsource-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-debugsource-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-devel-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-devel-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-docs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.noarch.rpm", "nodejs-full-i18n-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-full-i18n-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-libs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-libs-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-libs-debuginfo-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "nodejs-libs-debuginfo-1:22.13.1-1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.src.rpm", "nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm", "nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.src.rpm", "nodejs-packaging-bundler-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm", "npm-1:10.9.2-1.22.13.1.1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm", "npm-1:10.9.2-1.22.13.1.1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm", "v8-12.4-devel-3:12.4.254.21-1.22.13.1.1.module+el8.10.0+1935+d3cbe60f.aarch64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.13.1.1.module+el8.10.0+1935+d3cbe60f.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Latest Node.js security updates for Rocky Linux tackle serious vulnerabilities related to resource handling and randomness deficiencies.. NodeJS Security Update, Rocky Linux Advisories, Important Software Patches. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7289-3 February 25, 2025 linux-ibm vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-ibm: Linux kernel for IBM cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Network drivers; - STMicroelectronics network drivers; - Parport drivers; - Pin controllers subsystem; - Direct Digital Synthesis drivers; - TCM subsystem; - TTY drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - BTRFS file system; - File systems infrastructure; - Network file system (NFS) client; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Timer substystem drivers; - Tracing infrastructure; - Closures library; - Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Network traffic control; - SCTP protocol; - XFRM subsystem; - Key management; - FireWire sound drivers; - HD-audio driver; - QCOM ASoC drivers; - STMicroelectronics SoCdrivers; - KVM core; (CVE-2024-50117, CVE-2024-50230, CVE-2024-50131, CVE-2024-50128, CVE-2024-50142, CVE-2024-50141, CVE-2024-50267, CVE-2024-41066, CVE-2024-50236, CVE-2024-50205, CVE-2024-50202, CVE-2024-50209, CVE-2024-50148, CVE-2024-50171, CVE-2024-50074, CVE-2024-50268, CVE-2024-50265, CVE-2024-50160, CVE-2024-50143, CVE-2024-50296, CVE-2024-50101, CVE-2024-50103, CVE-2024-39497, CVE-2024-50151, CVE-2024-50127, CVE-2024-50150, CVE-2024-50229, CVE-2024-50115, CVE-2024-50058, CVE-2024-50292, CVE-2024-50010, CVE-2024-50247, CVE-2024-50110, CVE-2024-53088, CVE-2024-50116, CVE-2024-26718, CVE-2024-53097, CVE-2024-50192, CVE-2024-50234, CVE-2024-41080, CVE-2024-42291, CVE-2024-50195, CVE-2024-40965, CVE-2024-50278, CVE-2024-50290, CVE-2024-50162, CVE-2024-53066, CVE-2024-50085, CVE-2024-50099, CVE-2024-50237, CVE-2024-50156, CVE-2024-50185, CVE-2024-50273, CVE-2024-50302, CVE-2024-50249, CVE-2024-50208, CVE-2024-50232, CVE-2024-50287, CVE-2024-50262, CVE-2024-50194, CVE-2024-40953, CVE-2024-50083, CVE-2024-50082, CVE-2024-53063, CVE-2024-50086, CVE-2024-50193, CVE-2024-50282, CVE-2024-50201, CVE-2024-50134, CVE-2024-53061, CVE-2024-50299, CVE-2024-50279, CVE-2024-50198, CVE-2024-53104, CVE-2024-50244, CVE-2024-50167, CVE-2024-53052, CVE-2024-50196, CVE-2024-50182, CVE-2024-35887, CVE-2024-53042, CVE-2023-52913, CVE-2024-53055, CVE-2024-50301, CVE-2024-42252, CVE-2024-50259, CVE-2024-50218, CVE-2024-50168, CVE-2024-50245, CVE-2024-50163, CVE-2024-50036, CVE-2024-50154, CVE-2024-53059, CVE-2024-50257, CVE-2024-53101, CVE-2024-50295, CVE-2024-50269, CVE-2024-53058, CVE-2024-50072, CVE-2024-50251, CVE-2024-50153, CVE-2024-50233, CVE-2024-50199) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1070-ibm 5.15.0-1070.73 linux-image-ibm 5.15.0.1070.66 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change thekernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7289-3 https://ubuntu.com/security/notices/USN-7289-2 https://ubuntu.com/security/notices/USN-7289-1 CVE-2023-52913, CVE-2024-26718, CVE-2024-35887, CVE-2024-39497, CVE-2024-40953, CVE-2024-40965, CVE-2024-41066, CVE-2024-41080, CVE-2024-42252, CVE-2024-42291, CVE-2024-50010, CVE-2024-50036, CVE-2024-50058, CVE-2024-50072, CVE-2024-50074, CVE-2024-50082, CVE-2024-50083, CVE-2024-50085, CVE-2024-50086, CVE-2024-50099, CVE-2024-50101, CVE-2024-50103, CVE-2024-50110, CVE-2024-50115, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50128, CVE-2024-50131, CVE-2024-50134, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50153, CVE-2024-50154, CVE-2024-50156, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50182, CVE-2024-50185, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50198, CVE-2024-50199, CVE-2024-50201, CVE-2024-50202, CVE-2024-50205, CVE-2024-50208, CVE-2024-50209, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50232, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236, CVE-2024-50237, CVE-2024-50244, CVE-2024-50245, CVE-2024-50247, CVE-2024-50249, CVE-2024-50251, CVE-2024-50257, CVE-2024-50259, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50273, CVE-2024-50278, CVE-2024-50279, CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50292,CVE-2024-50295, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53042, CVE-2024-53052, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53066, CVE-2024-53088, CVE-2024-53097, CVE-2024-53101, CVE-2024-53104 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1070.73 . Recent patches addressing numerous vulnerabilities in the Linux kernel for Ubuntu 22.04 LTS on IBM hardware have been released. This update is essential for maintaining system security.. Linux Kernel Fixes, Ubuntu 22.04 LTS, Linux-IBM Security. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1737 http://linux.oracle.com/errata/ELSA-2025-1737.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-13.20-1.el8_10.i686.rpm libpq-13.20-1.el8_10.x86_64.rpm libpq-devel-13.20-1.el8_10.i686.rpm libpq-devel-13.20-1.el8_10.x86_64.rpm aarch64: libpq-13.20-1.el8_10.aarch64.rpm libpq-devel-13.20-1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//libpq-13.20-1.el8_10.src.rpm Related CVEs: CVE-2025-1094 Description of changes: [13.20-1] - Update to 13.20 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1738 http://linux.oracle.com/errata/ELSA-2025-1738.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libpq-13.20-1.el9_5.i686.rpm libpq-13.20-1.el9_5.x86_64.rpm libpq-devel-13.20-1.el9_5.i686.rpm libpq-devel-13.20-1.el9_5.x86_64.rpm aarch64: libpq-13.20-1.el9_5.aarch64.rpm libpq-devel-13.20-1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//libpq-13.20-1.el9_5.src.rpm Related CVEs: CVE-2025-1094 Description of changes: [13.20-1] - Update to 13.20 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1670 http://linux.oracle.com/errata/ELSA-2025-1670.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind9.18-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-chroot-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-dnssec-utils-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-libs-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-utils-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-devel-9.18.29-1.el9_5.1.i686.rpm bind9.18-devel-9.18.29-1.el9_5.1.x86_64.rpm bind9.18-doc-9.18.29-1.el9_5.1.noarch.rpm bind9.18-libs-9.18.29-1.el9_5.1.i686.rpm aarch64: bind9.18-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-chroot-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-dnssec-utils-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-libs-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-utils-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-devel-9.18.29-1.el9_5.1.aarch64.rpm bind9.18-doc-9.18.29-1.el9_5.1.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//bind9.18-9.18.29-1.el9_5.1.src.rpm Related CVEs: CVE-2024-11187 CVE-2024-12705 Description of changes: [32:9.18.29-1.el9_5.1] - Fix CVE-2024-11187 bind: bind9: Many records in the additional section cause CPU exhaustion - Fix CVE-2024-12705 bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.