Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 33 articles for you...
89

Fedora 42: gnutls 3.8.11 Update Severity Important Fix CVE-2025-9820

Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b346087f6b 2025-12-02 01:30:54.608271+00:00 -------------------------------------------------------------------------------- Name : gnutls Product : Fedora 42 Version : 3.8.11 Release : 1.fc42 URL : http://www.gnutls.org/ Summary : A TLS protocol implementation Description : GnuTLS is a secure communications library implementing the SSL, TLS and DTLS protocols and technologies around them. It provides a simple C language application programming interface (API) to access the secure communications protocols as well as APIs to parse and write X.509, PKCS #12, OpenPGP and other required structures. -------------------------------------------------------------------------------- Update Information: Update to the 3.8.11 release with a fix for CVE-2025-9820 and several enhancements. -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 22 2025 Daiki Ueno - 3.8.11-1 - Update to 3.8.11 upstream release - Resolves: rhbz#2416041 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b346087f6b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Ensure your Fedora 42 system is secure by updating gnutls to version 3.8.11, addressing CVE-2025-9820, along with key performance improvements. GnuTLS update Fedora 42 TLS enhancements fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 02, 2025 Important Fedora
219

Rocky Linux 8 RLEA-2025:0734 Moderate: Node.js Update for Bug Fixes

nodejs:22 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2025:0734","synopsis":"nodejs:22 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for module.nodejs-packaging, nodejs-nodemon, nodejs-packaging, module.nodejs-nodemon, nodejs, module.nodejs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nBug Fix(es) and Enhancement(s):\n\n* Add Node.js v22 to Rocky Linux8 AppStream (JIRA:Rocky Linux-35991)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-02-13T20:34:26.141542Z","rpms":{"Rocky Linux8":{"nvras":["nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.src.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-docs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.noarch.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 setup by integrating the latest Node.js v22 enhancements, featuring essential bug resolutions and performance improvements.. Node.js Update, Rocky Linux Security Fix, Bug Fixes,Enhancements. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2025 Rocky Linux
98

Red Hat VolSync 0.5.4 Moderate Advisory: Security Fixes and Enhancements

VolSync v0.5.4 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: VolSync 0.5.4 security fixes and enhancements Advisory ID: RHSA-2023:4575-01 Product: Red Hat ACM Advisory URL: https://access.redhat.com/errata/RHSA-2023:4575 Issue date: 2023-08-08 CVE Names: CVE-2020-24736 CVE-2022-36227 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-26604 CVE-2023-27535 CVE-2023-38408 ===================================================================== 1. Summary: VolSync v0.5.4 security fixes and enhancements Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. 2. Description: VolSync is a Kubernetes operator that enables asynchronous replication of persistent volumes within a cluster, or across clusters. After deploying the VolSync operator, it can create and maintain copies of your persistent data. For more information about VolSync, see: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/add-ons/add-ons-overview#volsync or the VolSync open source community website at: https://volsync.readthedocs.io/en/stable/. This advisory contains enhancements and updates to the VolSync container images. Security fix(es): * CVE-2023-3089 openshift: OCP & FIPS mode 3. Solution: For details on how to install VolSync, referto: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.6/html/add-ons/add-ons-overview#volsync-rep 4. Bugs fixed (https://bugzilla.redhat.com/): 2212085 - CVE-2023-3089 openshift: OCP & FIPS mode 5. References: https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-36227 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/cve/CVE-2023-27535 https://access.redhat.com/security/cve/CVE-2023-38408 https://access.redhat.com/security/updates/classification#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk0qN6AAoJENzjgjWX9erETT4P/jVK3VSrR8KdFizXGwnuczFA 0gRx22ceAB0VrjvEUCSlM+Qlcn0WknT6cMWckoC0G9KzehbLcBbSsT5IOlm+MQ2R 6qRBz6QMnY+d/7eMBnXY4h2EDXMKLD31Wj5DOjy4G6GbfaxPSgWUkNR1x+wKmcms uZTCZmsiRjwXJ0lG/Wx+Hf3N/Y8txhIAPi6PQ7C2kMqjEwWN87a0rRgg7JgccBGt Vibfd+a+AdcUcfMOUiPnHBFckTC6kLxCsaCY8mgsz0/B0RtU7XzeX7uHWxzYGQuc 2C2Py9XhRpIEG9SsXLFTNc3nu3IjPWkLU0TCMgb7+K1MqKqhmuOyYBd9Bt+4/3tE 2RkRdT3usUCr/jPSEJpxZs7ykb+7MNgMG54dDXQyPIBvw2AEL3p/0eHZ4wSIhsqK cUgsYCfzoXs5FS6xDfxKB8fohUxOTH1QLD5vx1Yob7yZ8wz+YeNH3pGIW5gLbWOd VopcJo3kl8zDABnD9nKDMpyiKM5yla3ql6oj4u89Stgi/2MObeqSF7VL06C68YLT SjEVcoPxR+LMFRx9PuiI4m7yGveQ0K0GUqvMv8H3z1CZn+K+BAIO4/Oi6jEGXsy2 erTvAcG5NyEaUrh6UhEGGYNcIYMGDR9IJDf8TzSYkglhDNjLHeeJsNCpG8BjjD2u lmL1i5Wt+SLRbBa8q/MV =AN0W -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Red Hat notice emphasizes important security updates for VolSync version 0.5.4, including improvements tailored for Kubernetesoperators.. VolSync Security Fixes, Red Hat Updates, Kubernetes Security Advisory. . LinuxSecurity.com Team

Calendar%202 Aug 08, 2023 Red Hat
219

Rocky Linux 8: RXSA-2023:1566 Important Kernel Security Update

Important: kernel security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RX", "name": "RXSA-2023:1566", "synopsis": "Important: kernel security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for kernel.\nThis update affects Rocky Linux SIG Cloud 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: stack overflow in do_proc_dointvec and proc_skip_spaces (CVE-2022-4378)\n\n* ALSA: pcm: Move rwsem lock inside snd_ctl_elem_read to prevent UAF (CVE-2023-0266)\n\n* kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386)\n\n* kernel: net: CPU soft lockup in TC mirred egress-to-ingress action (CVE-2022-4269)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* kernel panic on reboot due to a bug in mei_wdt module (BZ#2139770)\n\n* Rocky Linux SIG Cloud8: Practically limit \"Dummy wait\" workaround to old Intel systems (BZ#2142170)\n\n* AMDSERVER 8.7: amdpstate driver incorrectly designed to load as default for Genoa (BZ#2151275)\n\n* Rocky Linux SIG Cloud-8.8: Update RDMA core to Linux v6.0 (BZ#2161750)\n\n* Kernel panic observed during VxFS module unload (BZ#2162763)\n\n* Client not able to connect to rhel server: SYN is answered by chalange ACK and RST is ignored (BZ#2165587)\n\n* Rocky Linux SIG Cloud8.4: s390/kexec: fix ipl report address for kdump (BZ#2166296)\n\n* kvm-unit-test reports unhandled exception on AMD (BZ#2166362)\n\n* Windows Server 2019 guest randomly pauses with \"KVM: entry failed, hardware error 0x80000021\" (BZ#2166368)\n\n* Unable to get QinQ working with ConnectX-4 Lx in SR-IOV scenario(BZ#2166665)\n\n* panic in fib6_rule_suppress+0x22 with custom xdp prog involved in (BZ#2167602)\n\n* net/mlx5e: Fix use-after-free when reverting termination table (BZ#2167640)\n\n* Rocky Linux SIG Cloud 8.7: EEH injection failed to recover on Mellanox adapter. (BZ#2167645)\n\n* mlx5: lag and sriov fixes (BZ#2167647)\n\n* Rocky Linux SIG Cloud8.4: dasd: fix no record found for raw_track_access (BZ#2167776)\n\n* GSS: Set of fixes in ceph kernel module to prevent OCS node kernel crash - blocklist the kclient when receiving corrupted snap trace (BZ#2168896)\n\n* Azure Rocky Linux SIG Cloud8 scsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM (BZ#2170228)\n\n* fast_isolate_freepages scans out of target zone (BZ#2170576)\n\n* Backport Request for locking/rwsem commits (BZ#2170939)\n\n* ipv6 traffic stop when an sriov vf have ipv6 address (BZ#2172550)\n\n* Hyper-V Rocky Linux SIG Cloud8.8: Update MANA driver (BZ#2173103)\n\nEnhancement(s):\n\n* Intel 8.8 FEAT SPR CPU: AMX: Improve the init_fpstate setup code (BZ#2168384)", "solution": null, "affectedProducts": ["Rocky Linux SIG Cloud 8"], "fixes": [{"ticket": "2150272", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2150272", "description": ""}, {"ticket": "2152548", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2152548", "description": ""}, {"ticket": "2159505", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2159505", "description": ""}, {"ticket": "2163379", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163379", "description": ""}], "cves": [{"name": "CVE-2022-4269", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-4269", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-833"}, {"name": "CVE-2022-4378", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-4378", "cvss3ScoringVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-120-> CWE-131-> CWE-787"}, {"name": "CVE-2023-0266", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0266", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}, {"name": "CVE-2023-0386", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-0386", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-282"}], "references": [], "publishedAt": "2023-05-05T15:42:05.003997Z", "rpms": {"Rocky Linux SIG Cloud 8": {"nvras": ["bpftool-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "bpftool-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "bpftool-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "bpftool-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.src.rpm", "kernel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-abi-stablelists-0:4.18.0-425.19.2.el8_7.cloud.noarch.rpm", "kernel-core-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-core-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-cross-headers-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-cross-headers-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-core-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-core-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm","kernel-debug-modules-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-modules-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-debug-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-debug-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-doc-0:4.18.0-425.19.2.el8_7.cloud.noarch.rpm", "kernel-headers-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-headers-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-modules-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-modules-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-modules-extra-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-libs-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-libs-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "kernel-tools-libs-devel-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "kernel-tools-libs-devel-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "perf-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "perf-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "python3-perf-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "python3-perf-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm", "python3-perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.aarch64.rpm", "python3-perf-debuginfo-0:4.18.0-425.19.2.el8_7.cloud.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Major kernel security patch released for Rocky Linux SIG Cloud 8, fixing significant vulnerabilities and improving functionality.. Rocky Linux Kernel Security, Important Kernel Fixes, Cloud 8Enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 05, 2023 Important Rocky Linux
219

Rocky Linux 8 RLSA-2022:7457 Moderate Security Update for Container Tools

Moderate: container-tools:rhel8 security, bug fix, and enhancement update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2022:7457","synopsis":"Moderate: container-tools:rhel8 security, bug fix, and enhancement update","severity":"SEVERITY_MODERATE","topic":"An update for the container-tools:rhel8 module is now available for Rocky Linux 8.\nRocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","description":"The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"1820551","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1820551","description":"Automatically starting a container on boot is not possible through cockpit WebUI"},{"ticket":"1941727","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1941727","description":"Module meta data is wrong"},{"ticket":"1945929","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1945929","description":"Every podman run invocation generates two \"Couldn't stat device \/dev\/char\/10:200: No such file or directory\" lines in the journal"},{"ticket":"1974423","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1974423","description":"No equivalent buildah bud argument to docker build --ssh"},{"ticket":"1995656","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1995656","description":"CVE-2021-36221 golang: net\/http\/httputil: panic due to racy read of persistConn after handler panic"},{"ticket":"1996050","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=1996050","description":"[RFE] podman to create a rootless container that attempts to publish ports from a host with static IPv6 address."},{"ticket":"2005866","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2005866","description":"Udica was rebased prematurely"},{"ticket":"2009264","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2009264","description":"Cannot get logs with --follow"},{"ticket":"2009346","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2009346","description":"Podman name resolution not working as expected"},{"ticket":"2024938","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2024938","description":"CVE-2021-41190 opencontainers: OCI manifest and index parsing confusion"},{"ticket":"2027662","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2027662","description":"Udica crashes when processing inspect file without capabilities"},{"ticket":"2028408","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2028408","description":"Podman healthcheck fails if the command contains unicode characters."},{"ticket":"2030195","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2030195","description":"Add restart-sec option to systemd generate"},{"ticket":"2039045","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2039045","description":"\/etc\/containers\/registries.conf missing registry.redhat.io terms-based registry definition"},{"ticket":"2052697","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2052697","description":"Inconsistencyin how the podman service behaves depending on whether it is providing API via UNIX or TCP socket."},{"ticket":"2053990","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2053990","description":"runc has unversioned dependency on libseccomp"},{"ticket":"2055313","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2055313","description":"Creating a pod uses bad infra_image registry in podman"},{"ticket":"2059666","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2059666","description":"There is no man page for Containerfile provided by containers-common"},{"ticket":"2062697","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2062697","description":"[cockpit-podman] RHEL 8.7 Tier 0 Localization"},{"ticket":"2064702","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2064702","description":"CVE-2022-27191 golang: crash in a golang.org\/x\/crypto\/ssh server"},{"ticket":"2066145","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2066145","description":"The results showed significant difference between with and without --no-stream option for podman stats"},{"ticket":"2068006","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2068006","description":"CentOS Stream 8 podman: symbol lookup error: podman: undefined symbol: seccomp_notify_fd [rhel-8.7.0]"},{"ticket":"2072452","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2072452","description":"error during chown: storage-chown-by-maps: lgetxattr usr\/bin\/ping: value too large for defined data type"},{"ticket":"2073958","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2073958","description":"Podman v3.4.2 regression with hosts file breaks getHostAddress() call"},{"ticket":"2078925","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2078925","description":"podman command crash with segment fault in rootless user mode"},{"ticket":"2079759","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2079759","description":"skopeo segfaults after rebuild with golang-1.18"},{"ticket":"2079761","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2079761","description":"podman fails to build with golang-1.18"},{"ticket":"2081836","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2081836","description":"networking is broken when building containers due to missing container networking package dependencies"},{"ticket":"2083570","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2083570","description":"symlinks doesn't work on volumes under podman when SELINUX is enabled"},{"ticket":"2083997","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2083997","description":"catatonit not found when starting pod (podman 4.0 under RHEL 8.6)"},{"ticket":"2085361","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2085361","description":"CVE-2022-1708 cri-o: memory exhaustion on the node when access to the kube api"},{"ticket":"2086398","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086398","description":"CVE-2022-29162 runc: incorrect handling of inheritable capabilities"},{"ticket":"2086757","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2086757","description":"Error: plugin type=\"bridge\" failed (add): failed to find plugin \"bridge\" in path"},{"ticket":"2090609","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2090609","description":"ERRO[0009] Error forwarding signal 18 to container using rootless user with timeout+sleep in the podman run command"},{"ticket":"2090920","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2090920","description":"Podman load keeps stale files in TMPDIR"},{"ticket":"2093079","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2093079","description":"Podman does not detect volume from the volume plugin, unlike docker"},{"ticket":"2094610","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2094610","description":"Healthcheck does not get executed if --interval not specified in Dockerfile"},{"ticket":"2094875","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2094875","description":"podman not being able to mount devices during podman build"},{"ticket":"2095097","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2095097","description":"[RFE] Podman copying the entries of \/etc\/hosts in the container"},{"ticket":"2096264","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2096264","description":"podman images --format incompatibility with docker"},{"ticket":"2097865","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2097865","description":"Removing podman-2:4.0.2-6.module+el8.6.0+14877+f643d2d6.x86_64 does not remove podman socket if sudo systemctl enable podman.socket has been run prior to yum remove podman"},{"ticket":"2100740","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2100740","description":"podman can not force remove paused container"},{"ticket":"2102140","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102140","description":"ADD Dockerfile reference is not validating HTTP status code [rhel8]"},{"ticket":"2102361","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102361","description":"Mostly-confined containers which create their own user and mount namespaces can't mount overlay filesystems"},{"ticket":"2102381","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2102381","description":"podman image failed with ERRO[0000] Unmounting \/home\/maor\/.local\/share\/containers\/storage\/overlay\/XX\/merged: invalid argument"},{"ticket":"2113941","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2113941","description":"podman did not set selinux labels to symbolic links"},{"ticket":"2117699","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2117699","description":"podman 4.2 version bump"},{"ticket":"2117928","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2117928","description":"Error: runc: exec failed: unable to start container process: open \/dev\/pts\/0: operation not permitted: OCI permission denied"},{"ticket":"2118231","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2118231","description":"mount through procfd: operation not permitted: OCI permission denied"},{"ticket":"2119072","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2119072","description":"podman gating test issues in RHEL8.7"},{"ticket":"2120651","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2120651","description":"Add beta keys to default-policy.json"},{"ticket":"2121453","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2121453","description":"CVE-2022-2990 buildah: possible information disclosure and modification"}],"cves":[{"name":"CVE-2021-41190","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2021-41190.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:N\/I:L\/A:N","cvss3BaseScore":"5.0","cwe":"CWE-843"},{"name":"CVE-2022-1708","sourceBy":"RedHat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-1708.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:N\/I:N\/A:H","cvss3BaseScore":"6.8","cwe":"CWE-400-> CWE-770"},{"name":"CVE-2022-27191","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-27191.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","cvss3BaseScore":"7.5","cwe":"CWE-327"},{"name":"CVE-2022-29162","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-29162.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:L","cvss3BaseScore":"5.6","cwe":"CWE-276"},{"name":"CVE-2022-2990","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-2990.json","cvss3ScoringVector":"CVSS:3.1\/AV:L\/AC:H\/PR:L\/UI:N\/S:U\/C:L\/I:L\/A:N","cvss3BaseScore":"3.6","cwe":"CWE-842"}],"references":[],"publishedAt":"2022-11-13T07:55:49.626183Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}. Rocky Linux 8 release introduces improvements and minor updates for the container-tools module, enhancing security protocols.. Rocky Linux, Container Security, Module Update, Bug Fix. . LinuxSecurity.com Team

Calendar%202 Nov 13, 2022 Rocky Linux
219

Rocky Linux 8 RLBA-2021:4091 Medium: Vulkan Validation Layers Fix

vulkan-validation-layers bug fix and enhancement update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:4091', 'synopsis': 'vulkan-validation-layers bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for vulkan-validation-layers is now available for Rocky Linux 8.', 'description': 'The vulkan-validation-layers package provides Vulkan validation layers that can be enabled to assist development by enabling verification of applications' correct use of the Vulkan application programming interfaces (API).', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1991465'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:4091:::RHBA-2021:4091'], 'references': [], 'publishedAt': '2021-11-03T05:22:57.565232Z', 'rpms': ['vulkan-validation-layers-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-1.2.182.0-2.el8_4.src.rpm', 'vulkan-validation-layers-1.2.182.0-2.el8_4.x86_64.rpm', 'vulkan-validation-layers-debuginfo-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-debuginfo-1.2.182.0-2.el8_4.x86_64.rpm', 'vulkan-validation-layers-debugsource-1.2.182.0-2.el8_4.aarch64.rpm', 'vulkan-validation-layers-debugsource-1.2.182.0-2.el8_4.x86_64.rpm']}\. Fedora Linux rolls out a patch for gnome-software, improving user interface responsiveness and system performance.. Vulkan Validation Layers, Rocky Linux Update, Bug Fixes. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Medium Rocky Linux
89

Fedora 36: FEDORA-2022-d165104234 Moderate: Weechat SSL Fixes

Update to new upstream version.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-d165104234 2022-06-01 01:23:04.303735 --------------------------------------------------------------------------------Name : weechat Product : Fedora 36 Version : 3.5 Release : 2.fc36 URL : https://weechat.org/ Summary : Portable, fast, light and extensible IRC client Description : WeeChat (Wee Enhanced Environment for Chat) is a portable, fast, light and extensible IRC client. Everything can be done with a keyboard. It is customizable and extensible with scripts. --------------------------------------------------------------------------------Update Information: Update to new upstream version. --------------------------------------------------------------------------------ChangeLog: * Sun May 22 2022 Paul Komkoff 3.5-2 - Update to new upstream version 3.5 * Sun May 22 2022 Paul Komkoff 3.5-1 - Update to new upstream version 3.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2063588 - weechat-3.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2063588 [ 2 ] Bug #2063855 - weechat: SSL verification vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2063855 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-d165104234' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The latest release of WeeChat, version 3.5, addresses critical SSL vulnerabilities for Fedora 36. Discover more about the upgrades and resolutions.. WeeChat Update, Fedora 36 Security, IRC Client Improvements. . LinuxSecurity.com Team

Calendar%202 May 31, 2022 Fedora
89

Fedora 34 Firefox 89.0 Update with Critical Enhancements

- Updated to Firefox 89.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-af55f610eb 2021-06-10 01:12:59.750823 --------------------------------------------------------------------------------Name : firefox Product : Fedora 34 Version : 89.0 Release : 1.fc34 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. --------------------------------------------------------------------------------Update Information: - Updated to Firefox 89.0 --------------------------------------------------------------------------------ChangeLog: * Tue Jun 1 2021 Martin Stransky - 89.0-1 - Updated to latest upstream (89.0) --------------------------------------------------------------------------------References: [ 1 ] Bug #1966933 - Update to 89.0 https://bugzilla.redhat.com/show_bug.cgi?id=1966933 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-af55f610eb' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Discover the latest Firefox 89.0 update for Fedora 34 featuring performance improvements, privacy enhancements, a sleek new interface, and better tab management. Firefox Update, Browser Upgrade, Open Source Browser. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2021 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200