An update for nss-softokn is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: nss-softokn security update Advisory ID: RHSA-2021:1026-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1026 Issue date: 2021-03-30 CVE Names: CVE-2019-11756 CVE-2019-17006 CVE-2020-12403 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Use-after-free in sftk_FreeSession due to improper refcounting (CVE-2019-11756) * nss: Check length of inputs for cryptographic primitives (CVE-2019-17006) * nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read (CVE-2020-12403) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to applythis update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1774835 - CVE-2019-11756 nss: Use-after-free in sftk_FreeSession due to improper refcounting 1775916 - CVE-2019-17006 nss: Check length of inputs for cryptographic primitives 1868931 - CVE-2020-12403 nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7): Source: nss-softokn-3.44.0-9.el7_7.src.rpm x86_64: nss-softokn-3.44.0-9.el7_7.i686.rpm nss-softokn-3.44.0-9.el7_7.x86_64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-3.44.0-9.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): x86_64: nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-devel-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.7): Source: nss-softokn-3.44.0-9.el7_7.src.rpm ppc64: nss-softokn-3.44.0-9.el7_7.ppc.rpm nss-softokn-3.44.0-9.el7_7.ppc64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc64.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc64.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc64.rpm ppc64le: nss-softokn-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc64le.rpm s390x: nss-softokn-3.44.0-9.el7_7.s390.rpm nss-softokn-3.44.0-9.el7_7.s390x.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.s390.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.s390x.rpm nss-softokn-devel-3.44.0-9.el7_7.s390.rpm nss-softokn-devel-3.44.0-9.el7_7.s390x.rpm nss-softokn-freebl-3.44.0-9.el7_7.s390.rpm nss-softokn-freebl-3.44.0-9.el7_7.s390x.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.s390.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.s390x.rpm x86_64: nss-softokn-3.44.0-9.el7_7.i686.rpm nss-softokn-3.44.0-9.el7_7.x86_64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-devel-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2020-12403 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYGLw6tzjgjWX9erEAQil5RAAk4SQyOwg4jjHXl8KvhhYyhjeC6KIYb5g ojisBr4cVKjGo1fMVZTfpg8DE2OTHetZfiQ0BVSkEMXPxr+nuT+p+qxQIyiq2Idb uDzO+ttBUdPiTYEFMNodbrit0x9nhpgH6eJ4hQ90hRRBah6DxftOKde36MuozKkg GZ4+JHf8UoJo6LX7lwz4sMTWOtIdOo3fsknxiLAVC7IUFURm5wXNhhgobSQSpiou WFlMeTfqBT7A9ZNzh2DEAv80ltUDp/z6qEqRCvk1VkVfR/JYzUGbWZWjmbL0Srs2 kscz1yRIJSeeT5IlUsvZDTQYZ2XBJotynMPlDc4y51FraFuBZu5gg5lLqhQXhpnz 10H9xVKrDbXkHPFEzinE6WzcowTdlTlicPaWLtWpvDQO0n0dWZyX64wP3Ym7/8kK mdTaX5HS5YdHBWSy9FF4pVzJdM8TOkNKTqaMQikSAav3/UNAeL5l3SVgLXjSPgh9 Fe4GiPJG2PU6aPmYHzSZAPvoxCA6NXm+N4eNnZL7mMFQc33Y9QcbFJpNr8/5ROMm LZvGerUbwlLnavZFkhrr2Rvj9pdgXLWGCNP8SH/AiErfy+3dFOWQlAqy5CNnepBW Y/swsuMBspTe4aMqsefOnbCFrHbGYKgZPsLsLnzByBuqemtn5SrAgh1TWOAqfmHx +Pi1slDSt2U=Y2VV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for nss-softokn is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: nss-softokn security update Advisory ID: RHSA-2021:0758-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0758 Issue date: 2021-03-09 CVE Names: CVE-2019-11756 CVE-2019-17006 CVE-2020-12403 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server TUS (v. 7.4) - x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Use-after-free in sftk_FreeSession due to improper refcounting (CVE-2019-11756) * nss: Check length of inputs for cryptographic primitives (CVE-2019-17006) * nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read (CVE-2020-12403) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listedin the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1774835 - CVE-2019-11756 nss: Use-after-free in sftk_FreeSession due to improper refcounting 1775916 - CVE-2019-17006 nss: Check length of inputs for cryptographic primitives 1868931 - CVE-2020-12403 nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: nss-softokn-3.28.3-10.el7_4.src.rpm x86_64: nss-softokn-3.28.3-10.el7_4.i686.rpm nss-softokn-3.28.3-10.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-devel-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.4): Source: nss-softokn-3.28.3-10.el7_4.src.rpm ppc64le: nss-softokn-3.28.3-10.el7_4.ppc64le.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.ppc64le.rpm nss-softokn-devel-3.28.3-10.el7_4.ppc64le.rpm nss-softokn-freebl-3.28.3-10.el7_4.ppc64le.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.ppc64le.rpm x86_64: nss-softokn-3.28.3-10.el7_4.i686.rpm nss-softokn-3.28.3-10.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-devel-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.x86_64.rpm Red Hat Enterprise Linux Server TUS (v.7.4): Source: nss-softokn-3.28.3-10.el7_4.src.rpm x86_64: nss-softokn-3.28.3-10.el7_4.i686.rpm nss-softokn-3.28.3-10.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-10.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-devel-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-3.28.3-10.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-10.el7_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2020-12403 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYEc+RNzjgjWX9erEAQg4mQ/+MCpmmYSEI6SYvndSaGpNdO8n7hGXNjAM VmFgQ8T3HABcaoKX78x2lhSeFZypFdwLDac2fL7pOoxxY9KZKUJqDCZc1Q6UggmQ CWUgRNzngnZhkwGaZw3al+/371NN/dfj7kAkEuQTt/PSH0gdiyAdwYthZ0Ke+EOV wIW+8w1x2NxJFrTWIvBSP+w3HHn0d2dCRJicemPkPd25ptHsDzwer2ySDuRI7HJI OlVt5mop/Yq0xXEWlujB7qUhD3gH4ebwHHIgtce7Ffwi1Y/JBGeV9/V2xMbhCNBk 4jhK3AWRNw9ByI0vH4EfyxAuRlolUGR3T/z2ApemyV6pfrulr2KuWeKzF5AEEe1F 9VPuhZ2L+b1xlU3dkZWBO7KH97/c8FJDH2A6j6Lz+M4OtlDziFAPUkabo83AKSSq kv7K2LRL/rm2+dJbSRu9G/3H61jtwVLuGxWUfH6+f8j+NjIeY2BsPFGmCJRGMavI 37MpSDMeYcikHrxgcd49N/xYGNtJKuSQnaO2mQRM5KK7yfeZ8qKOprmC7nE5RKp7 zlIKxq3Py1S53zIzuXzyT5PnvM2nwI3EpBGrcQiiBLlRH7EBAW6eWUCcIQaZklW9 llkYRNyJ+qct5YItP7SjRMUyEJ6Zfn1fxNiJ3vGA4s1dsrBF097H+sqr/OuTEXM8 FTKK9cP2NpU=9QSj -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for nss-softokn is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss-softokn security update Advisory ID: RHSA-2020:1345-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1345 Issue date: 2020-04-07 CVE Names: CVE-2018-0495 CVE-2019-11745 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server TUS (v. 7.4) - x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) * ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries (CVE-2018-0495) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1591163 - CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries 1774831 - CVE-2019-11745 nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: nss-softokn-3.28.3-9.el7_4.src.rpm x86_64: nss-softokn-3.28.3-9.el7_4.i686.rpm nss-softokn-3.28.3-9.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-devel-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.4): Source: nss-softokn-3.28.3-9.el7_4.src.rpm ppc64le: nss-softokn-3.28.3-9.el7_4.ppc64le.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.ppc64le.rpm nss-softokn-devel-3.28.3-9.el7_4.ppc64le.rpm nss-softokn-freebl-3.28.3-9.el7_4.ppc64le.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.ppc64le.rpm x86_64: nss-softokn-3.28.3-9.el7_4.i686.rpm nss-softokn-3.28.3-9.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-devel-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.x86_64.rpm Red Hat Enterprise Linux Server TUS (v.7.4): Source: nss-softokn-3.28.3-9.el7_4.src.rpm x86_64: nss-softokn-3.28.3-9.el7_4.i686.rpm nss-softokn-3.28.3-9.el7_4.x86_64.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.i686.rpm nss-softokn-debuginfo-3.28.3-9.el7_4.x86_64.rpm nss-softokn-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-devel-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-3.28.3-9.el7_4.x86_64.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.i686.rpm nss-softokn-freebl-devel-3.28.3-9.el7_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-0495 https://access.redhat.com/security/cve/CVE-2019-11745 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoxI5dzjgjWX9erEAQiD+hAAkAnoav5FMltQo/IdtfRZMwhxS9N0Y6W4 H/xwgg/jipCZ61vE/STaMM44zJWSzTayme8nslELtqRsijY9GdhZwH0lLrtYbVEJ sdWliYxfPwzlqokaIi9HcnbDok2xYrhbM5wfzSMcvE2Coq8yoo4++Nrlv0m7cxNE dAVJZNi594WBeiNdffFfoGBLFewr+qcfLwd20hQpjji74V/r+Q6fj4BHp7ilU5qU 0s/0lEFzCr4vOXYrIe58P4DRhcO4C8W5qAVDAtjx4cXGkUPIjbcO2JJE7ywlFajp 5EBgZeJK9f7MbWGXMjEOGJhPDt0uykj2f8AGZKZxh4Az4GyijMQMYKRkiwBy4HRd BBb0hCti/phfzx2enk5Z39e1tAX91h3nlzAbWQbcEOmvrcudxjnxkM9DTh9h5nQZ eHN9kE18KrYExvJXA5seWD/p/LBW5DXaaumKcHXiKoS6d+O+D43DwvUpzdl2JP+e 57xTskKOrZzk1h7O+1LoEstTI7bqTnYH7VCfIQEdgKBG3AQ2t5O8vfWFLKF7AjXX CoYdmT0cMtu2r00Scr7JSs45hQ/Yy0bBiUSlvDKNnVhsr45EscG5pAVVzID5DlCh cMol1vhCBoV53UfQ3wkZiqMcxsJxNC5ajN9Q7lZgejg2zA1bGySrXALlg13t3ZIH olEFz/LzYms=XO4i -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for nss-softokn is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss-softokn security update Advisory ID: RHSA-2020:1267-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1267 Issue date: 2020-04-01 CVE Names: CVE-2018-0495 CVE-2019-11745 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64, ppc64le, s390x, x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) * ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries (CVE-2018-0495) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1591163 - CVE-2018-0495 ROHNP: Key Extraction Side Channel in Multiple Crypto Libraries 1774831 - CVE-2019-11745 nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5): Source: nss-softokn-3.36.0-6.el7_5.src.rpm x86_64: nss-softokn-3.36.0-6.el7_5.i686.rpm nss-softokn-3.36.0-6.el7_5.x86_64.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.i686.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.x86_64.rpm nss-softokn-freebl-3.36.0-6.el7_5.i686.rpm nss-softokn-freebl-3.36.0-6.el7_5.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5): x86_64: nss-softokn-debuginfo-3.36.0-6.el7_5.i686.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.x86_64.rpm nss-softokn-devel-3.36.0-6.el7_5.i686.rpm nss-softokn-devel-3.36.0-6.el7_5.x86_64.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.i686.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.5): Source: nss-softokn-3.36.0-6.el7_5.src.rpm ppc64: nss-softokn-3.36.0-6.el7_5.ppc.rpm nss-softokn-3.36.0-6.el7_5.ppc64.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.ppc.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.ppc64.rpm nss-softokn-devel-3.36.0-6.el7_5.ppc.rpm nss-softokn-devel-3.36.0-6.el7_5.ppc64.rpm nss-softokn-freebl-3.36.0-6.el7_5.ppc.rpm nss-softokn-freebl-3.36.0-6.el7_5.ppc64.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.ppc.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.ppc64.rpm ppc64le: nss-softokn-3.36.0-6.el7_5.ppc64le.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.ppc64le.rpm nss-softokn-devel-3.36.0-6.el7_5.ppc64le.rpm nss-softokn-freebl-3.36.0-6.el7_5.ppc64le.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.ppc64le.rpm s390x: nss-softokn-3.36.0-6.el7_5.s390.rpm nss-softokn-3.36.0-6.el7_5.s390x.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.s390.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.s390x.rpm nss-softokn-devel-3.36.0-6.el7_5.s390.rpm nss-softokn-devel-3.36.0-6.el7_5.s390x.rpm nss-softokn-freebl-3.36.0-6.el7_5.s390.rpm nss-softokn-freebl-3.36.0-6.el7_5.s390x.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.s390.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.s390x.rpm x86_64: nss-softokn-3.36.0-6.el7_5.i686.rpm nss-softokn-3.36.0-6.el7_5.x86_64.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.i686.rpm nss-softokn-debuginfo-3.36.0-6.el7_5.x86_64.rpm nss-softokn-devel-3.36.0-6.el7_5.i686.rpm nss-softokn-devel-3.36.0-6.el7_5.x86_64.rpm nss-softokn-freebl-3.36.0-6.el7_5.i686.rpm nss-softokn-freebl-3.36.0-6.el7_5.x86_64.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.i686.rpm nss-softokn-freebl-devel-3.36.0-6.el7_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-0495 https://access.redhat.com/security/cve/CVE-2019-11745 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoRSIdzjgjWX9erEAQiVqQ//TH1K6R0uTAuq11Q7PXmGjTPUa2/clEuk c008m2G1x4AWmPocvtPpPhKe0BUviGxFtAGTrhJx5f2be2YmRZ+JHFRYwHI3lKM2 YJjMwSW0vohBhVXudOvG7+cWfbkKt1i0a8N+2IaSH0VcgUEOvhyPVZ/22HwNUeaS loPZFyJOJZy76heQNzenvXLj1CRIlkGsxsvr0fxVHqNrNXn/k3jzPfBHtFxbawk1 QjwkAND/s8x9Qj8T7zby/2NXXi5y8yuI4PksOb2rmyjaPLtcAGujHtHsEGziyinW BJAyh7tkMxAcWxxMNEdRAZjVcErp99ZNaa4Ck+u9rEW7vPWYn6EunPnqnL1y9nCZ f/ZKICjXVkMqZq8Jp7WOmupmT1fGt1LSUYnJIiyn1u/6fZANh6BzgmR74RkX5OWc 2QSyU3FcZXT7ttaKtaGslCaT9ZLIn1grKhoTrqTrc1Z9IekJNBBm/5/FIzutNqd/ D6TIJbH82G03j1DXG2fvsRLfaDu0GTt6HXLEsK0JPlJZeXOwJdrGvJz3XYX1jo2o CF1R9lEXhkJXoxXn7e5EJ5Egl04vqqJ16qsWyynolhETK/dUkXf1x4Cdg3HeZ3CB m1EgllecBP+OLntAqaHihCzwpZEJaARI/xxKHpYd96KcsfqLtPKcc1uWDFHk64Tk rIqDkBJPd4A=xNcH -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for nss-softokn is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss-softokn security update Advisory ID: RHSA-2019:4152-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:4152 Issue date: 2019-12-10 CVE Names: CVE-2019-11745 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate (CVE-2019-11745) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1774831 - CVE-2019-11745 nss: Out-of-bounds write when passing an output buffer smaller than the block size to NSC_EncryptUpdate 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: nss-softokn-3.44.0-6.el6_10.src.rpm i386: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm x86_64: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm x86_64: nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: nss-softokn-3.44.0-6.el6_10.src.rpm x86_64: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): x86_64: nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: nss-softokn-3.44.0-6.el6_10.src.rpm i386: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm ppc64: nss-softokn-3.44.0-6.el6_10.ppc.rpm nss-softokn-3.44.0-6.el6_10.ppc64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.ppc.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.ppc64.rpm nss-softokn-devel-3.44.0-6.el6_10.ppc.rpm nss-softokn-devel-3.44.0-6.el6_10.ppc64.rpm nss-softokn-freebl-3.44.0-6.el6_10.ppc.rpm nss-softokn-freebl-3.44.0-6.el6_10.ppc64.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.ppc.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.ppc64.rpm s390x: nss-softokn-3.44.0-6.el6_10.s390.rpm nss-softokn-3.44.0-6.el6_10.s390x.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.s390.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.s390x.rpm nss-softokn-devel-3.44.0-6.el6_10.s390.rpm nss-softokn-devel-3.44.0-6.el6_10.s390x.rpm nss-softokn-freebl-3.44.0-6.el6_10.s390.rpm nss-softokn-freebl-3.44.0-6.el6_10.s390x.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.s390.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.s390x.rpm x86_64: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: nss-softokn-3.44.0-6.el6_10.src.rpm i386: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm x86_64: nss-softokn-3.44.0-6.el6_10.i686.rpm nss-softokn-3.44.0-6.el6_10.x86_64.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.i686.rpm nss-softokn-debuginfo-3.44.0-6.el6_10.x86_64.rpm nss-softokn-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-devel-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-3.44.0-6.el6_10.x86_64.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.i686.rpm nss-softokn-freebl-devel-3.44.0-6.el6_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-11745 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXe+MiNzjgjWX9erEAQiepQ/7BesVlTbWtK/e4tqUqQ2WADoCPilxvBo5 lQ/zdsIXw069qAzU/GutaUM3DN7qvxSDCtxOTeQy605jkHYnV1HPjIXxYkug6ETV atrTxcph7BwV5w3sS4D+/N7FvYaGfluSQL65lihS3VNvtiA3excFw3hyaPeI/miM N7+ZHE+kD3vFL2DL6gOMTa/FGfa2w55ka0ODEpL9xCm+vBwVEyNAYVZqzfDQdWwz 5gWlJd7NEJq1qqrNlMuwOrn3YYd2R9VPcrYEvoNRW/Dcf5BNstDmadIPAVcsG1rT Me5PeII3MRIHLEkgYGFNmrxcctWSdC1VIuMsSUdC1lKnqZSpHMq4JjaNfjh3TAtg 2Avl2Jyhm1N56h6OsQo/UX2A7vRdGfgmVlv5jkFBYvjdilLmFQRCzouyJMAXmbZu pUAqowHA9cN3RUYU7so7cU/4AKI3nlsHpH1o1ExICEUclsKn2rnxJquGMxhsVxEv rnv9JKH4IuGKBxt0KTUZRLYsSdHdbrAhlHvanLCi9px7KvqTNIMpblijHLe/1OqD 9mVJjZpCAIJ3et+qPKzfdnjd76UqWbndQlgAwlVN07XODHBLSZkh0iY1nT1Az/WN +wo3O48nWAzPvg2H5jy/+zq7mLI16W0t2mG8rUXHR2Don93Efomtbs7sFDxiiMOP Iowc4iq7Yac=lxBi -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c72d2d89ec 2018-09-21 05:19:39.107001 --------------------------------------------------------------------------------Name : nss-softokn Product : Fedora 29 Version : 3.39.0 Release : 2.fc29 URL : https://firefox-source-docs.mozilla.org/security/nss/index.html Summary : Network Security Services Softoken Module Description : Network Security Services Softoken Cryptographic Module --------------------------------------------------------------------------------Update Information: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes --------------------------------------------------------------------------------References: [ 1 ] Bug #1624704 - CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1624704 [ 2 ] Bug #1620207 - Enable SSLKEYLOGFILE support https://bugzilla.redhat.com/show_bug.cgi?id=1620207 [ 3 ] Bug #1578106 - Package version is invalid, or no Source URL provided https://bugzilla.redhat.com/show_bug.cgi?id=1578106 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c72d2d89ec' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1a7a5c54c2 2018-09-14 23:11:42.963781 --------------------------------------------------------------------------------Name : nss-softokn Product : Fedora 28 Version : 3.39.0 Release : 1.0.fc28 URL : https://firefox-source-docs.mozilla.org/security/nss/index.html Summary : Network Security Services Softoken Module Description : Network Security Services Softoken Cryptographic Module --------------------------------------------------------------------------------Update Information: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes --------------------------------------------------------------------------------ChangeLog: * Mon Sep 3 2018 Daiki Ueno - 3.39.0-1.0 - Update to NSS 3.39 * Tue Jul 3 2018 Daiki Ueno - 3.38.0-1.0 - Update to NSS 3.38 * Tue Jun 5 2018 Daiki Ueno - 3.37.3-1.1 - Fix partial injection of LDFLAGS (the original relro flags are also set by redhat-rpm-config) - Enable FIPS startup test * Tue Jun 5 2018 Daiki Ueno - 3.37.3-1.0 - Update to NSS 3.37.3 * Mon May 28 2018 Daiki Ueno - 3.37.1-1.0 - Update to NSS 3.37.1 * Thu May 3 2018 Kai Engert - 3.36.1-1.1 - Upstream patch to automatically enable SQL DB caching based on filesystem type, mozbz#1456888 * Wed Apr 11 2018 Daiki Ueno - 3.36.1-1.0 - Update to NSS 3.36.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1624704 - CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1624704 [ 2 ] Bug #1620207 - Enable SSLKEYLOGFILE support https://bugzilla.redhat.com/show_bug.cgi?id=1620207 [ 3 ] Bug #1578106 - Package version is invalid, or no Source URL provided https://bugzilla.redhat.com/show_bug.cgi?id=1578106 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1a7a5c54c2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updates the nss family of packages to upstream NSS 3.29.5. Note that, only nss- util and nss-softokn have changed since the previous upstream release 3.29.3.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-9042085060 2017-04-25 12:28:36.813085 --------------------------------------------------------------------------------Name : nss-softokn Product : Fedora 24 Version : 3.29.5 Release : 1.0.fc24 URL : https://firefox-source-docs.mozilla.org/security/nss/index.html Summary : Network Security Services Softoken Module Description : Network Security Services Softoken Cryptographic Module --------------------------------------------------------------------------------Update Information: Updates the nss family of packages to upstream NSS 3.29.5. Note that, only nss-util and nss-softokn have changed since the previous upstream release 3.29.3. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade nss-softokn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.