Upstream security and bugfix release. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-806d377171 2025-10-19 02:36:31.438165+00:00 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 42 Version : 7.0.12 Release : 1.fc42 URL : Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: Upstream security and bugfix release -------------------------------------------------------------------------------- ChangeLog: * Sun Oct 5 2025 Jason Taylor 7.0.12-1 - New security and bugfix release - Resolves CVE-2025-59147 - Update spec project URI -------------------------------------------------------------------------------- References: [ 1 ] Bug #2400928 - CVE-2025-59147 suricata: Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2400928 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-806d377171' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
MGASA-2025-0224 - Updated aide packages fix vulnerabilities. MGASA-2025-0224 - Updated aide packages fix vulnerabilities Publication date: 02 Sep 2025 URL: https://advisories.mageia.org/MGASA-2025-0224.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-54389, CVE-2025-54409 Description: Improper output neutralization (potential AIDE detection bypass). (CVE-2025-54389) Null pointer dereference after reading incorrectly encoded xattr attributes from database (local DoS). (CVE-2025-54409) References: - https://bugs.mageia.org/show_bug.cgi?id=34586 - https://www.openwall.com/lists/oss-security/2025/08/14/7 - https://www.openwall.com/lists/oss-security/2025/08/14/8 - https://www.cve.org/CVERecord?id=CVE-2025-54389 - https://www.cve.org/CVERecord?id=CVE-2025-54409 SRPMS: - 9/core/aide-0.18.6-1.1.mga9 . Mageia 9 maintenance updates applied to resolve severe security flaws and enhance overall system resilience against evasion techniques and local denial of service threats.. Mageia AIDE update vulnerabilities detection bypass local DoS. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.