Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
219

Rocky Linux 9 RLSA-2024:8935 moderate: edk2 denial of service

Moderate: edk2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:8935", "synopsis": "Moderate: edk2 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for edk2.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. \n\nSecurity Fix(es):\n\n* openssl: Possible denial of service in X.509 name checks (CVE-2024-6119)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2306158", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2306158", "description": ""}], "cves": [{"name": "CVE-2024-6119", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-6119", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-11-08T15:57:54.689249Z", "rpms": {"Rocky Linux 9": {"nvras": ["edk2-0:20231122-6.el9_4.4.src.rpm", "edk2-aarch64-0:20231122-6.el9_4.4.noarch.rpm", "edk2-ovmf-0:20231122-6.el9_4.4.noarch.rpm", "edk2-tools-0:20231122-6.el9_4.4.aarch64.rpm", "edk2-tools-0:20231122-6.el9_4.4.x86_64.rpm", "edk2-tools-debuginfo-0:20231122-6.el9_4.4.aarch64.rpm", "edk2-tools-debuginfo-0:20231122-6.el9_4.4.x86_64.rpm", "edk2-tools-doc-0:20231122-6.el9_4.4.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Fedora 39 releases a significant security patch for OpenSSL, mitigating potential vulnerabilities in certificate validation processes.. edk2 security update, Rocky Linux vulnerabilities, DoS security fix. .LinuxSecurity.com Team

Calendar 2 Nov 08, 2024 Rocky Linux
98

Red Hat Enterprise Linux 8.6 RHSA-2023:4128-01 Critical: Edk2 Update

An update for edk2 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: edk2 security update Advisory ID: RHSA-2023:4128-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4128 Issue date: 2023-07-18 CVE Names: CVE-2022-4304 CVE-2023-0215 CVE-2023-0286 ==================================================================== 1. Summary: An update for edk2 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - noarch 3. Description: EDK (Embedded Development Kit) is a project to enable UEFI support for Virtual Machines. This package contains a sample 64-bit UEFI firmware for QEMU and KVM. Security Fix(es): * openssl: X.400 address type confusion in X.509 GeneralName (CVE-2023-0286) * openssl: timing attack in RSA Decryption implementation (CVE-2022-4304) * openssl: use-after-free following BIO_new_NDEF (CVE-2023-0215) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 2164440 - CVE-2023-0286 openssl: X.400 address type confusion in X.509 GeneralName 2164487 - CVE-2022-4304 openssl: timing attack in RSA Decryption implementation 2164492 - CVE-2023-0215 openssl: use-after-free following BIO_new_NDEF 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.6): Source: edk2-20220126gitbb1bba3d77-2.el8_6.1.src.rpm noarch: edk2-aarch64-20220126gitbb1bba3d77-2.el8_6.1.noarch.rpm edk2-ovmf-20220126gitbb1bba3d77-2.el8_6.1.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0286 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJktmv1AAoJENzjgjWX9erEFcoQAJTzG4roJ6kbvvqMOY2ghpO4 IhSAfGvAf7Opuahtv+VqJcxWtcW8TVGRwaQlLWv70f8rgUUYJH7Ll3k3Wa76UPQd Z91cvsKKrh1XP47bPlcU5zVuNRxuqT3TLTeT9WeEyVxh/JkFBkuSkn36PCPR6fuM ii+ppKALwEuNlHT99ebAgL9tUVvUiPVPkvwmJBITxCqgTR3ddyDR+6V7fXrXnT/4 UybIF6lv7l+N2yHI5u9vEsph9yb/qUFFWbC81NAqCjHe+Ko4aitAW2AZJMt4qWPb mR9+cJHyNf4+/fWxjJwlKjKoWNqSmqsg2MzwEng0qqTrlJ2DGpIEBaVXxjFDhhGI 3LpGHNzipP9jD+QyPd1fqEmGdSuiWdf7UU7BA7uTvTqOBrowjxOiQbN+7/cn2+9V yg3Ik6KxTap2vesbTBoOZFId9Z1VPrMoOx9Cvz4atEjqlqBak4jNjnBe4kV52m26 gIVgvmWxaXOd2L/X3nzNY3z9WpXnfYh/1gQtaUgopNBsVclX+GNT0leDIuh8LRVz c/MohxUqW/Xz9bbb90AqhUoxIQWhmZFcWxsmpORWALl18kssXHluEugNf5GgkA3s 7DbUVhHEEK/vMeNteaI6tW8le5ik377DfQ4vFbyeJ/gR/fcfDTywL96hL3Mc2oaK +FUJnnzz277KjTWripMk =xPii -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A significant edk2 enhancement has just been released for Red Hat Linux 8.6. Essential securityupdates resolve various vulnerabilities associated with OpenSSL.. edk2 update, Red Hat Enterprise Linux, OpenSSL fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 18, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here