Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 38 FEDORA-2024-0da80aa623 Critical: Xen Shadow Stack Issue

x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0da80aa623 2024-03-14 01:38:51.491768 -------------------------------------------------------------------------------- Name : xen Product : Fedora 38 Version : 4.17.2 Release : 7.fc38 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 27 2024 Michael Young - 4.17.2-7 - x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2266325 - CVE-2023-46841 xen: x86 shadow stack vs exceptions from emulation stubs https://bugzilla.redhat.com/show_bug.cgi?id=2266325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0da80aa623' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list-- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 releases security update FEDORA-2024-1ba92bb123 tackling vulnerabilities related to shadow stack functionality within KVM virtualization system.. xen hypervisor, shadow stack issue, Fedora update, emulation vulnerability, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2024 Critical Fedora
89

Ubuntu 22.10: UBUNTU-2024-b1387xyz Critical: Linux Kernel Vulnerability

x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aca9ed1eb1 2024-03-14 01:07:19.210138 -------------------------------------------------------------------------------- Name : xen Product : Fedora 39 Version : 4.17.2 Release : 7.fc39 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 27 2024 Michael Young - 4.17.2-7 - x86: shadow stack vs exceptions from emulation stubs - [XSA-451, CVE-2023-46841] (#2266326) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2266325 - CVE-2023-46841 xen: x86 shadow stack vs exceptions from emulation stubs https://bugzilla.redhat.com/show_bug.cgi?id=2266325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aca9ed1eb1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list-- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Significant update for Fedora 39 resolves issues related to shadow stack vulnerabilities in the Xen Hypervisor architecture.. Fedora39,Xen,ShadowStack,EmulationStubs,SecurityAdvisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2024 Critical Fedora
89

Fedora 39: Update for rust-vm-superio CVE-2023-50711 Moderate: System Patch

Update rust-vmm components and their consumers to address CVE-2023-50711. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-04877592b7 2024-02-10 01:24:59.648730 -------------------------------------------------------------------------------- Name : rust-vm-superio Product : Fedora 39 Version : 0.7.0 Release : 4.fc39 URL : Summary : Emulation for legacy devices Description : Emulation for legacy devices. -------------------------------------------------------------------------------- Update Information: Update rust-vmm components and their consumers to address CVE-2023-50711 -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 27 2024 Fedora Release Engineering - 0.7.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Tue Jan 9 2024 David Michael - 0.7.0-3 - Bump vmm-sys-util to 0.12 for CVE-2023-50711 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-04877592b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade rust-vm-superio in Fedora 39 to address CVE-2023-50711 vulnerabilities, reinforcing system protection.. Fedora Updates, rust-vm-superio, security patch. . LinuxSecurity.com Team

Calendar 2 Feb 10, 2024 Fedora
89

Fedora: 2017-374389c196 Moderate: Qemu Memory Leak and Display Issue Fix

* Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-374389c196 2017-05-12 14:08:49.129102 --------------------------------------------------------------------------------Name : qemu Product : Fedora 24 Version : 2.6.2 Release : 8.fc24 URL : https://www.qemu.org/ Summary : QEMU is a FAST! processor emulator Description : QEMU is a generic and open source processor emulator which achieves a good emulation speed by using dynamic translation. QEMU has two operating modes: * Full system emulation. In this mode, QEMU emulates a full system (for example a PC), including a processor and various peripherials. It can be used to launch different Operating Systems without rebooting the PC or to debug system code. * User mode emulation. In this mode, QEMU can launch Linux processes compiled for one CPU on another CPU. As QEMU requires no host kernel patches to run, it is safe and easy to use. --------------------------------------------------------------------------------Update Information: * Fix xen pv graphical display failure (bz #1350264) * CVE-2016-8667: dma: divide by zero error in set_next_tick (bz #1384876) * CVE-2017-5579: serial: fix memory leak in serial exit (bz #1416161) --------------------------------------------------------------------------------References: [ 1 ] Bug #1384874 - CVE-2016-8667 Qemu: hw: dma: divide by zero error in set_next_tick https://bugzilla.redhat.com/show_bug.cgi?id=1384874 [ 2 ] Bug #1416157 - CVE-2017-5579 Qemu: serial: host memory leakage 16550A UART emulation https://bugzilla.redhat.com/show_bug.cgi?id=1416157 --------------------------------------------------------------------------------This update can be installedwith the "dnf" update program. Use su -c 'dnf upgrade qemu' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Fedora update brings crucial improvements to QEMU, addressing display issues and memory management errors during emulation, enhancing stability and user experience.. Fedora Update, QEMU Security, Processing Errors, Memory Issue, Emulation Bug. . LinuxSecurity.com Team

Calendar 2 May 12, 2017 Fedora
87

Debian: DSA-2610-1 Urgent: QEMU Network Adapter Vulnerability Found

It was discovered that the e1000 emulation code in QEMU does not enforce frame size limits in the same way as the real hardware does. This could trigger buffer overflows in the guest operating system driver for that network card, assuming that the host system does not . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2608-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer January 15, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : qemu Vulnerability : buffer overflow Problem type : remote Debian-specific: no CVE ID : CVE-2012-6075 Debian Bug : 696051 It was discovered that the e1000 emulation code in QEMU does not enforce frame size limits in the same way as the real hardware does. This could trigger buffer overflows in the guest operating system driver for that network card, assuming that the host system does not discard such frames (which it will by default). For the stable distribution (squeeze), this problem has been fixed in version 0.12.5+dfsg-3squeeze3. For the unstable distribution (sid), this problem has been fixed in version 1.1.2+dfsg-4. We recommend that you upgrade your qemu packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Exploitable memory corruption in QEMU's emulation of the e1000 network card could compromise your system; find out how to implement necessary resilience measures through this bulletin.. Debian Security Advisory,QEMU Buffer Overflow,Emulation Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 15, 2013 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here