Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b346087f6b 2025-12-02 01:30:54.608271+00:00 -------------------------------------------------------------------------------- Name : gnutls Product : Fedora 42 Version : 3.8.11 Release : 1.fc42 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. -------------------------------------------------------------------------------- Update Information: Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements. -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 22 2025 Daiki Ueno - 3.8.11-1 - Update to 3.8.11 upstream release - Resolves: rhbz#2416041 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b346087f6b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
nodejs:22 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2025:0734","synopsis":"nodejs:22 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for module.nodejs-packaging, nodejs-nodemon, nodejs-packaging, module.nodejs-nodemon, nodejs, module.nodejs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nBug Fix(es) and Enhancement(s):\n\n* Add Node.js v22 to Rocky Linux8 AppStream (JIRA:Rocky Linux-35991)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-02-13T20:34:26.141542Z","rpms":{"Rocky Linux8":{"nvras":["nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.src.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-docs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.noarch.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 setup by integrating the latest Node.js v22 enhancements, featuring essential bug resolutions and performance improvements.. Node.js Update, Rocky Linux Security Fix, Bug Fixes,Enhancements. . LinuxSecurity.com Team
VolSync v0.5.4 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: VolSync 0.5.4 security fixes and enhancements Advisory ID: RHSA-2023:4575-01 Product: Red Hat ACM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4575 Issue date: 2023-08-08 CVE Names: CVE-2020-24736 CVE-2022-36227 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-26604 CVE-2023-27535 CVE-2023-38408 ===================================================================== 1. Summary: VolSync v0.5.4 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. 2. Description: VolSync is a Kubernetes operator that enables asynchronous replication of persistent volumes within a cluster, or across clusters. After deploying the VolSync operator, it can create and maintain copies of your persistent data. For more information about VolSync, see: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/add-ons/add-ons-overview#volsync or the VolSync open source community website at: https://volsync.readthedocs.io/en/stable/. This advisory contains enhancements and updates to the VolSync container images. Security fix(es): * CVE-2023-3089 openshift: OCP & FIPS mode 3. Solution: For details on how to install VolSync, referto: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/add-ons/add-ons-overview#volsync-rep 4. Bugs fixed (https://bugzilla.redhat.com/): 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/cve/CVE-2023-38408 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk0qN6AAoJENzjgjWX9erETT4P/jVK3VSrR8KdFizXGwnuczFA 0gRx22ceAB0VrjvEUCSlM+Qlcn0WknT6cMWckoC0G9KzehbLcBbSsT5IOlm+MQ2R 6qRBz6QMnY+d/7eMBnXY4h2EDXMKLD31Wj5DOjy4G6GbfaxPSgWUkNR1x+wKmcms uZTCZmsiRjwXJ0lG/Wx+Hf3N/Y8txhIAPi6PQ7C2kMqjEwWN87a0rRgg7JgccBGt Vibfd+a+AdcUcfMOUiPnHBFckTC6kLxCsaCY8mgsz0/B0RtU7XzeX7uHWxzYGQuc 2C2Py9XhRpIEG9SsXLFTNc3nu3IjPWkLU0TCMgb7+K1MqKqhmuOyYBd9Bt+4/3tE 2RkRdT3usUCr/jPSEJpxZs7ykb+7MNgMG54dDXQyPIBvw2AEL3p/0eHZ4wSIhsqK cUgsYCfzoXs5FS6xDfxKB8fohUxOTH1QLD5vx1Yob7yZ8wz+YeNH3pGIW5gLbWOd VopcJo3kl8zDABnD9nKDMpyiKM5yla3ql6oj4u89Stgi/2MObeqSF7VL06C68YLT SjEVcoPxR+LMFRx9PuiI4m7yGveQ0K0GUqvMv8H3z1CZn+K+BAIO4/Oi6jEGXsy2 erTvAcG5NyEaUrh6UhEGGYNcIYMGDR9IJDf8TzSYkglhDNjLHeeJsNCpG8BjjD2u lmL1i5Wt+SLRbBa8q/MV =AN0W -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Important: kernel security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RX", "name": "RXSA-2023:1566", "synopsis": "Important: kernel security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for kernel.\nThis update affects Rocky Linux SIG Cloud 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)\n\n* ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)\n\n* kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386)\n\n* kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* kernel panic on reboot due to a bug in mei_wdt module (BZ#2139770)\n\n* Rocky Linux SIG Cloud8: Practically limit \"Dummy wait\" workaround to old Intel systems (BZ#2142170)\n\n* AMDSERVER 8.7: amdpstate driver incorrectly designed to load as default for Genoa (BZ#2151275)\n\n* Rocky Linux SIG Cloud-8.8: Update RDMA core to Linux v6.0 (BZ#2161750)\n\n* Kernel panic observed during VxFS module unload (BZ#2162763)\n\n* Client not able to connect to rhel server: SYN is answered by chalange ACK and RST is ignored (BZ#2165587)\n\n* Rocky Linux SIG Cloud8.4: s390/kexec: fix ipl report address for kdump (BZ#2166296)\n\n* kvm-unit-test reports unhandled exception on AMD (BZ#2166362)\n\n* Windows Server 2019 guest randomly pauses with \"KVM: entry failed, hardware error 0x80000021\" (BZ#2166368)\n\n* Unable to get QinQ working with ConnectX-4 Lx in SR-IOV scenario(BZ#2166665)\n\n* panic in fib6_rule_suppress+0x22 with custom xdp prog involved in (BZ#2167602)\n\n* net/mlx5e: Fix use-after-free when reverting termination table (BZ#2167640)\n\n* Rocky Linux SIG Cloud 8.7: EEH injection failed to recover on Mellanox adapter. (BZ#2167645)\n\n* mlx5: lag and sriov fixes (BZ#2167647)\n\n* Rocky Linux SIG Cloud8.4: dasd: fix no record found for raw_track_access (BZ#2167776)\n\n* GSS: Set of fixes in ceph kernel module to prevent OCS node kernel crash - blocklist the kclient when receiving corrupted snap trace (BZ#2168896)\n\n* Azure Rocky Linux SIG Cloud8 scsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM (BZ#2170228)\n\n* fast_isolate_freepages scans out of target zone (BZ#2170576)\n\n* Backport Request for locking/rwsem commits (BZ#2170939)\n\n* ipv6 traffic stop when an sriov vf have ipv6 address (BZ#2172550)\n\n* Hyper-V Rocky Linux SIG Cloud8.8: Update MANA driver (BZ#2173103)\n\nEnhancement(s):\n\n* Intel 8.8 FEAT SPR CPU: AMX: Improve the init_fpstate setup code (BZ#2168384)", "solution": null, "affectedProducts": ["Rocky Linux SIG Cloud 8"], "fixes": [{"ticket": "2150272", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2150272", "description": ""}, {"ticket": "2152548", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2152548", "description": ""}, {"ticket": "2159505", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2159505", "description": ""}, {"ticket": "2163379", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163379", "description": ""}], "cves": [{"name": "CVE-2022-4269", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-4269", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-833"}, {"name": "CVE-2022-4378", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-4378", "cvss3ScoringVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-120-> CWE-131-> CWE-787"}, {"name": "CVE-2023-0266", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0266", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}, {"name": "CVE-2023-0386", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0386", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-282"}], "references": [], "publishedAt": "2023-05-05T15:42:05.003997Z", "rpms": {"Rocky Linux SIG Cloud 8": {"nvras": ["bpftool-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "bpftool-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "bpftool-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "bpftool-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.src.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-abi-stablelists-0:4.18.0-425.19.2.el8_7.cloud.noarch.rpm", "kernel-core-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-core-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-cross-headers-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-cross-headers-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-core-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-core-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm","kernel-debug-modules-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-modules-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-doc-0:4.18.0-425.19.2.el8_7.cloud.noarch.rpm", "kernel-headers-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-headers-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-modules-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-modules-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-libs-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-libs-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-libs-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-libs-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "perf-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "perf-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "python3-perf-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "python3-perf-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "python3-perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "python3-perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Major kernel security patch released for Rocky Linux SIG Cloud 8, fixing significant vulnerabilities and improving functionality.. Rocky Linux Kernel Security, Important Kernel Fixes, Cloud 8Enhancements. . Severity: Important. LinuxSecurity.com Team
Moderate: container-tools:rhel8 security, bug fix, and enhancement update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2022:7457","synopsis":"Moderate: container-tools:rhel8 security, bug fix, and enhancement update","severity":"SEVERITY_MODERATE","topic":"An update for the container-tools:rhel8 module is now available for Rocky Linux 8.\nRocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","description":"The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"1820551","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1820551","description":"Automatically starting a container on boot is not possible through cockpit WebUI"},{"ticket":"1941727","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1941727","description":"Module meta data is wrong"},{"ticket":"1945929","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1945929","description":"Every podman run invocation generates two \"Couldn't stat device \/dev\/char\/10:200: No such file or directory\" lines in the journal"},{"ticket":"1974423","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1974423","description":"No equivalent buildah bud argument to docker build --ssh"},{"ticket":"1995656","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1995656","description":"CVE-2021-36221 golang: net\/http\/httputil: panic due to racy read of persistConn after handler panic"},{"ticket":"1996050","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1996050","description":"[RFE] podman to create a rootless container that attempts to publish ports from a host with static IPv6 address."},{"ticket":"2005866","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2005866","description":"Udica was rebased prematurely"},{"ticket":"2009264","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2009264","description":"Cannot get logs with --follow"},{"ticket":"2009346","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2009346","description":"Podman name resolution not working as expected"},{"ticket":"2024938","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2024938","description":"CVE-2021-41190 opencontainers: OCI manifest and index parsing confusion"},{"ticket":"2027662","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2027662","description":"Udica crashes when processing inspect file without capabilities"},{"ticket":"2028408","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2028408","description":"Podman healthcheck fails if the command contains unicode characters."},{"ticket":"2030195","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2030195","description":"Add restart-sec option to systemd generate"},{"ticket":"2039045","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2039045","description":"\/etc\/containers\/registries.conf missing registry.redhat.io terms-based registry definition"},{"ticket":"2052697","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2052697","description":"Inconsistencyin how the podman service behaves depending on whether it is providing API via UNIX or TCP socket."},{"ticket":"2053990","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2053990","description":"runc has unversioned dependency on libseccomp"},{"ticket":"2055313","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2055313","description":"Creating a pod uses bad infra_image registry in podman"},{"ticket":"2059666","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2059666","description":"There is no man page for Containerfile provided by containers-common"},{"ticket":"2062697","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2062697","description":"[cockpit-podman] RHEL 8.7 Tier 0 Localization"},{"ticket":"2064702","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2064702","description":"CVE-2022-27191 golang: crash in a golang.org\/x\/crypto\/ssh server"},{"ticket":"2066145","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2066145","description":"The results showed significant difference between with and without --no-stream option for podman stats"},{"ticket":"2068006","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2068006","description":"CentOS Stream 8 podman: symbol lookup error: podman: undefined symbol: seccomp_notify_fd [rhel-8.7.0]"},{"ticket":"2072452","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2072452","description":"error during chown: storage-chown-by-maps: lgetxattr usr\/bin\/ping: value too large for defined data type"},{"ticket":"2073958","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2073958","description":"Podman v3.4.2 regression with hosts file breaks getHostAddress() call"},{"ticket":"2078925","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2078925","description":"podman command crash with segment fault in rootless user mode"},{"ticket":"2079759","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2079759","description":"skopeo segfaults after rebuild with golang-1.18"},{"ticket":"2079761","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2079761","description":"podman fails to build with golang-1.18"},{"ticket":"2081836","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2081836","description":"networking is broken when building containers due to missing container networking package dependencies"},{"ticket":"2083570","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2083570","description":"symlinks doesn't work on volumes under podman when SELINUX is enabled"},{"ticket":"2083997","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2083997","description":"catatonit not found when starting pod (podman 4.0 under RHEL 8.6)"},{"ticket":"2085361","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2085361","description":"CVE-2022-1708 cri-o: memory exhaustion on the node when access to the kube api"},{"ticket":"2086398","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086398","description":"CVE-2022-29162 runc: incorrect handling of inheritable capabilities"},{"ticket":"2086757","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086757","description":"Error: plugin type=\"bridge\" failed (add): failed to find plugin \"bridge\" in path"},{"ticket":"2090609","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2090609","description":"ERRO[0009] Error forwarding signal 18 to container using rootless user with timeout+sleep in the podman run command"},{"ticket":"2090920","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2090920","description":"Podman load keeps stale files in TMPDIR"},{"ticket":"2093079","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2093079","description":"Podman does not detect volume from the volume plugin, unlike docker"},{"ticket":"2094610","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2094610","description":"Healthcheck does not get executed if --interval not specified in Dockerfile"},{"ticket":"2094875","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2094875","description":"podman not being able to mount devices during podman build"},{"ticket":"2095097","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2095097","description":"[RFE] Podman copying the entries of \/etc\/hosts in the container"},{"ticket":"2096264","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2096264","description":"podman images --format incompatibility with docker"},{"ticket":"2097865","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2097865","description":"Removing podman-2:4.0.2-6.module+el8.6.0+14877+f643d2d6.x86_64 does not remove podman socket if sudo systemctl enable podman.socket has been run prior to yum remove podman"},{"ticket":"2100740","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2100740","description":"podman can not force remove paused container"},{"ticket":"2102140","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102140","description":"ADD Dockerfile reference is not validating HTTP status code [rhel8]"},{"ticket":"2102361","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102361","description":"Mostly-confined containers which create their own user and mount namespaces can't mount overlay filesystems"},{"ticket":"2102381","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102381","description":"podman image failed with ERRO[0000] Unmounting \/home\/maor\/.local\/share\/containers\/storage\/overlay\/XX\/merged: invalid argument"},{"ticket":"2113941","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2113941","description":"podman did not set selinux labels to symbolic links"},{"ticket":"2117699","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2117699","description":"podman 4.2 version bump"},{"ticket":"2117928","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2117928","description":"Error: runc: exec failed: unable to start container process: open \/dev\/pts\/0: operation not permitted: OCI permission denied"},{"ticket":"2118231","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2118231","description":"mount through procfd: operation not permitted: OCI permission denied"},{"ticket":"2119072","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2119072","description":"podman gating test issues in RHEL8.7"},{"ticket":"2120651","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2120651","description":"Add beta keys to default-policy.json"},{"ticket":"2121453","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2121453","description":"CVE-2022-2990 buildah: possible information disclosure and modification"}],"cves":[{"name":"CVE-2021-41190","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2021-41190.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:N\/I:L\/A:N","cvss3BaseScore":"5.0","cwe":"CWE-843"},{"name":"CVE-2022-1708","sourceBy":"RedHat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-1708.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:N\/I:N\/A:H","cvss3BaseScore":"6.8","cwe":"CWE-400-> CWE-770"},{"name":"CVE-2022-27191","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-27191.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","cvss3BaseScore":"7.5","cwe":"CWE-327"},{"name":"CVE-2022-29162","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-29162.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","cvss3BaseScore":"5.6","cwe":"CWE-276"},{"name":"CVE-2022-2990","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-2990.json","cvss3ScoringVector":"CVSS:3.1\/AV:L\/AC:H\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","cvss3BaseScore":"3.6","cwe":"CWE-842"}],"references":[],"publishedAt":"2022-11-13T07:55:49.626183Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}. Rocky Linux 8 release introduces improvements and minor updates for the container-tools module, enhancing security protocols.. Rocky Linux, Container Security, Module Update, Bug Fix. . LinuxSecurity.com Team
vulkan-validation-layers bug fix and enhancement update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:4091', 'synopsis': 'vulkan-validation-layers bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for vulkan-validation-layers is now available for Rocky Linux 8.', 'description': 'The vulkan-validation-layers package provides Vulkan validation layers that can be enabled to assist development by enabling verification of applications' correct use of the Vulkan application programming interfaces (API).', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1991465'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:4091:::RHBA-2021:4091'], 'references': [], 'publishedAt': '2021-11-03T05:22:57.565232Z', 'rpms': ['vulkan-validation-layers-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-1.2.182.0-2.el8_4.src.rpm', 'vulkan-validation-layers-1.2.182.0-2.el8_4.x86_64.rpm', 'vulkan-validation-layers-debuginfo-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-debuginfo-1.2.182.0-2.el8_4.x86_64.rpm', 'vulkan-validation-layers-debugsource-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-debugsource-1.2.182.0-2.el8_4.x86_64.rpm']}\. Fedora Linux rolls out a patch for gnome-software, improving user interface responsiveness and system performance.. Vulkan Validation Layers, Rocky Linux Update, Bug Fixes. . Severity: Medium. LinuxSecurity.com Team
Update to new upstream version.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-d165104234 2022-06-01 01:23:04.303735 --------------------------------------------------------------------------------Name : weechat Product : Fedora 36 Version : 3.5 Release : 2.fc36 URL : https://weechat.org/ Summary : Portable, fast, light and extensible IRC client Description : WeeChat (Wee Enhanced Environment for Chat) is a portable, fast, light and extensible IRC client. Everything can be done with a keyboard. It is customizable and extensible with scripts. --------------------------------------------------------------------------------Update Information: Update to new upstream version. --------------------------------------------------------------------------------ChangeLog: * Sun May 22 2022 Paul Komkoff 3.5-2 - Update to new upstream version 3.5 * Sun May 22 2022 Paul Komkoff 3.5-1 - Update to new upstream version 3.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2063588 - weechat-3.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2063588 [ 2 ] Bug #2063855 - weechat: SSL verification vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2063855 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-d165104234' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- Updated to Firefox 89.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-af55f610eb 2021-06-10 01:12:59.750823 --------------------------------------------------------------------------------Name : firefox Product : Fedora 34 Version : 89.0 Release : 1.fc34 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to Firefox 89.0 --------------------------------------------------------------------------------ChangeLog: * Tue Jun 1 2021 Martin Stransky - 89.0-1 - Updated to latest upstream (89.0) --------------------------------------------------------------------------------References: [ 1 ] Bug #1966933 - Update to 89.0 https://bugzilla.redhat.com/show_bug.cgi?id=1966933 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-af55f610eb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.