Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 40 - FEDORA-2024-69528c0ba6 moderate: podman file descriptor leak

release 1.13.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-69528c0ba6 2024-10-28 03:52:20.506230 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 40 Version : 1.13.3 Release : 1.fc40 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: release 1.13.3 -------------------------------------------------------------------------------- ChangeLog: * Sat Oct 19 2024 Navid Yaghoobi - 1.13.3-1 - release v1.13.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2317466 - CVE-2024-9675 prometheus-podman-exporter: Buildah allows arbitrary directory mount [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2317466 [ 2 ] Bug #2318177 - [Major Incident] CVE-2024-21626 prometheus-podman-exporter: file descriptor leak [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2318177 [ 3 ] Bug #2318188 - [Major Incident] CVE-2024-21626 prometheus-podman-exporter: file descriptor leak [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2318188 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-69528c0ba6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Enhancements for podman-exporter in Fedora boost security, tackling newly identified flaws in version 1.13.3.. prometheus podman exporter, Fedora updates, container security, security patches. . LinuxSecurity.com Team

Calendar%202 Oct 28, 2024 Fedora
89

Fedora 38: FEDORA-2024-9044c9eefa Critical: runc File Descriptor Leak

Security fix for CVE-2024-21626. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-9044c9eefa 2024-02-11 05:38:48.506188 -------------------------------------------------------------------------------- Name : runc Product : Fedora 38 Version : 1.1.12 Release : 1.fc38 URL : https://github.com/opencontainers/runc Summary : CLI for running Open Containers Description : The runc command can be used to start containers which are packaged in accordance with the Open Container Initiative's specifications, and to manage containers running under runc. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2024-21626 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 1 2024 Lokesh Mandvekar - 2:1.1.12-1 - bump to v1.1.12 * Thu Feb 1 2024 Davanum Srinivas - 2:1.1.9-1 - Update to runc 1.1.9 version -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258725 - CVE-2024-21626 runc: file descriptor leak https://bugzilla.redhat.com/show_bug.cgi?id=2258725 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-9044c9eefa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38 patches runc to address file descriptor leakage (CVE-2024-21626), rated high severity. Update using dnf.. Fedora 38 Update,runc security fix,file descriptor leak. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 11, 2024 Critical Fedora
100

SUSE Security Update 2022:0828-1 Addresses Glib2 File Leak Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for glib2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0828-1 Rating: moderate References: #1191489 Cross-References: CVE-2021-3800 CVSS scores: CVE-2021-3800 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for glib2 fixes the following issues: - CVE-2021-3800: Fixed a file content leak in pkexec due to charset aliases (bsc#1191489). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-828=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-828=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-828=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): glib2-debugsource-2.48.2-12.25.1 libgio-fam-2.48.2-12.25.1 libgio-fam-debuginfo-2.48.2-12.25.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): glib2-debugsource-2.48.2-12.25.1 glib2-devel-2.48.2-12.25.1 glib2-devel-debuginfo-2.48.2-12.25.1 glib2-devel-static-2.48.2-12.25.1 libgio-fam-2.48.2-12.25.1 libgio-fam-debuginfo-2.48.2-12.25.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): glib2-debugsource-2.48.2-12.25.1 glib2-tools-2.48.2-12.25.1 glib2-tools-debuginfo-2.48.2-12.25.1 libgio-2_0-0-2.48.2-12.25.1 libgio-2_0-0-debuginfo-2.48.2-12.25.1 libglib-2_0-0-2.48.2-12.25.1 libglib-2_0-0-debuginfo-2.48.2-12.25.1 libgmodule-2_0-0-2.48.2-12.25.1 libgmodule-2_0-0-debuginfo-2.48.2-12.25.1 libgobject-2_0-0-2.48.2-12.25.1 libgobject-2_0-0-debuginfo-2.48.2-12.25.1 libgthread-2_0-0-2.48.2-12.25.1 libgthread-2_0-0-debuginfo-2.48.2-12.25.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libgio-2_0-0-32bit-2.48.2-12.25.1 libgio-2_0-0-debuginfo-32bit-2.48.2-12.25.1 libglib-2_0-0-32bit-2.48.2-12.25.1 libglib-2_0-0-debuginfo-32bit-2.48.2-12.25.1 libgmodule-2_0-0-32bit-2.48.2-12.25.1 libgmodule-2_0-0-debuginfo-32bit-2.48.2-12.25.1 libgobject-2_0-0-32bit-2.48.2-12.25.1 libgobject-2_0-0-debuginfo-32bit-2.48.2-12.25.1 libgthread-2_0-0-32bit-2.48.2-12.25.1 libgthread-2_0-0-debuginfo-32bit-2.48.2-12.25.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): glib2-lang-2.48.2-12.25.1 References: https://www.suse.com/security/cve/CVE-2021-3800.html https://bugzilla.suse.com/1191489 . Ubuntu Security Patch: Update for libc6. Advisory ID: UBUNTU-SU-2022:1005-1, medium severity, more information below.. SUSE glib2 update, glib2 file leak patch, moderate advisory. . LinuxSecurity.com Team

Calendar%202 Mar 14, 2022 SuSE
98

Red Hat: RHSA-2022-0712-01 Important: Kernel Sec. Update for RHEL 7.7

An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2022:0712-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:0712 Issue date: 2022-03-01 CVE Names: CVE-2020-0466 CVE-2021-4155 CVE-2022-0330 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux Server E4S (v. 7.7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.6) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.7) - noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: use after free in eventpoll.c may lead to escalation of privilege (CVE-2020-0466) * kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL (CVE-2021-4155) * kernel: possible privileges escalation due to missingTLB flush (CVE-2022-0330) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1920480 - CVE-2020-0466 kernel: use after free in eventpoll.c may lead to escalation of privilege 2034813 - CVE-2021-4155 kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL 2042404 - CVE-2022-0330 kernel: possible privileges escalation due to missing TLB flush 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.7): Source: kernel-3.10.0-1062.63.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.63.1.el7.noarch.rpm kernel-doc-3.10.0-1062.63.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1062.63.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.63.1.el7.x86_64.rpm perf-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm Red Hat Enterprise Linux Server E4S (v.7.7): Source: kernel-3.10.0-1062.63.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.63.1.el7.noarch.rpm kernel-doc-3.10.0-1062.63.1.el7.noarch.rpm ppc64le: bpftool-3.10.0-1062.63.1.el7.ppc64le.rpm bpftool-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-bootwrapper-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debug-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-devel-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-headers-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-tools-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-tools-libs-3.10.0-1062.63.1.el7.ppc64le.rpm perf-3.10.0-1062.63.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm python-perf-3.10.0-1062.63.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm x86_64: bpftool-3.10.0-1062.63.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.63.1.el7.x86_64.rpm perf-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm Red Hat Enterprise Linux Server TUS (v.7.7): Source: kernel-3.10.0-1062.63.1.el7.src.rpm noarch: kernel-abi-whitelists-3.10.0-1062.63.1.el7.noarch.rpm kernel-doc-3.10.0-1062.63.1.el7.noarch.rpm x86_64: bpftool-3.10.0-1062.63.1.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-devel-3.10.0-1062.63.1.el7.x86_64.rpm kernel-headers-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-1062.63.1.el7.x86_64.rpm perf-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.7): x86_64: bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v.7.6): ppc64le: bpftool-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debug-devel-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-debuginfo-common-ppc64le-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm kernel-tools-libs-devel-3.10.0-1062.63.1.el7.ppc64le.rpm perf-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.ppc64le.rpm x86_64: bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 7.7): x86_64: bpftool-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1062.63.1.el7.x86_64.rpm perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1062.63.1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-0466 https://access.redhat.com/security/cve/CVE-2021-4155 https://access.redhat.com/security/cve/CVE-2022-0330 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version:GnuPG v1 iQIVAwUBYh5GXtzjgjWX9erEAQi+0Q/+Lhu3wDa3K93uMd6Ej1BVD1DRdTGOvUvP kyjA3/0mYViassI4mqHqcZrmL/kmSe/kA5CiY70IhrsmH0y/zPICdGKDUbjoU+/g DQDAjBw7hio6/kJsEG/EtuZQ+ElLpv/V9pkmU1S6lRsH3+s/ALwAPrv26MkpMtMC V5y6ySLa/cnOiuN+rw54TFY/1k0ys5yG2YKYjRnZSCQSNZYQZExc3EVBH226dxyW wsN4BbYSzL8oYxuFr4Rr2UgO+L3UHp/dMs5rmWQMMsZaj0qeq4nmi9a+gxyFYvbG 4mjXDfjczJWymiRY39mqM9SxIuHZBzF2RB23239unTVmrtiAqw9Ks5RndjtUEg1K AEl9eoWsdYl3KCyGP6zjMfuGjo3OrZ55f3j1crAzqU5OWevzyOyalFZaGq7jN5d0 UCNWGfwDCdBdhXBJCK9bkTMseFe8nMCUyLGWyKvj35OAYwkw1mzsMnZlTgw8y751 yLZgAv7ShOYiOjaj6qVdJDCpMIN7wflzswIim9k7kwnXCFA6pO2Vp1NhYdjuw5B0 2AYrNeSNQtMJ1UWzkpIBLm/RPL5Nr1KIgkmmeDcRXDSkoN2eeDeEJeBBf8AUf1gL dP/zsHyXIgHx7aelsg1MiKRhD48INTBXBjxWc3veQPomC5PVUgGDE7808569sTmg B6UzAX7QUoY=Hrxq -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial kernel patch for Red Hat Enterprise Linux 7.7 resolves significant vulnerabilities. Implement it immediately!. Red Hat Security Advisory,kernel security,privilege escalation,xfs leak. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 01, 2022 Important Red Hat
89

Fedora 35: 2022-353b7254fd Critical: Polkit File Leak Crash Fix

Security fix for CVE-2021-4115. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-353b7254fd 2022-02-19 01:30:44.345783 --------------------------------------------------------------------------------Name : polkit Product : Fedora 35 Version : 0.120 Release : 1.fc35.2 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4115 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 16 2022 Jan Rybar - 0.120-1.2 - file descriptor exhaustion (GHSL-2021-077) - Resolves: CVE-2021-4115 --------------------------------------------------------------------------------References: [ 1 ] Bug #2007534 - CVE-2021-4115 polkit: file descriptor leak allows an unprivileged user to cause a crash https://bugzilla.redhat.com/show_bug.cgi?id=2007534 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-353b7254fd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. FedoraCode of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35's latest polkit update is crucial, addressing CVE-2021-4115 vulnerabilities that permit unauthorized privilege escalation, enhancing stability and security.. Fedora Security Update, polkit Framework, file Leak Issue, polkit Authorization. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 18, 2022 Critical Fedora
197

Debian 8: DLA-1658-1 Critical: phpMyAdmin XSS & File Leak

A couple of vulnerabilities have been discovered in phpmyadmin, MySQL web administration tool. . Package : phpmyadmin Version : 4:4.2.12-2+deb8u4 CVE ID : CVE-2018-19968 CVE-2018-19970 A couple of vulnerabilities have been discovered in phpmyadmin, MySQL web administration tool. CVE-2018-19968 An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker must have access to the phpMyAdmin Configuration Storage tables, although these can easily be created in any database to which the attacker has access. An attacker must have valid credentials to log in to phpMyAdmin; this vulnerability does not allow an attacker to circumvent the login system. CVE-2018-19970 A XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. For Debian 8 "Jessie", these problems have been fixed in version 4:4.2.12-2+deb8u4. We recommend that you upgrade your phpmyadmin packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : phpmyadmin Version : 4:4.2.12-2+deb8u4 CVE ID : CVE-2018-19968 CVE-2018-19970 A couple of . couple, vulnerabilities, phpmyadmin, mysql, administration, packa. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 01, 2019 Critical Debian LTS
98

Red Hat Enterprise Linux: RHSA-2005:175-01 Low: Kdenetwork File Leak

Updated kdenetwork packages that fix a file descriptor leak are now available. This update has been rated as having low security impact by the Red Hat Security Response Team. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: kdenetwork security update Advisory ID: RHSA-2005:175-01 Advisory URL: https://access.redhat.com/errata/RHSA-2005:175.html Issue date: 2005-03-03 Updated on: 2005-03-03 Product: Red Hat Enterprise Linux CVE Names: CAN-2005-0205 - ---------------------------------------------------------------------1. Summary: Updated kdenetwork packages that fix a file descriptor leak are now available. This update has been rated as having low security impact by the Red Hat Security Response Team 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The kdenetwork packages contain a collection of networking applications for the K Desktop Environment. A bug was found in the way kppp handles privileged file descriptors. A malicious local user could make use of this flaw to modify the /etc/hosts or /etc/resolv.conf files, which could be used to spoof domain information. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0205 to this issue. Please note that the default installation of kppp on Red Hat Enterprise Linux uses consolehelper and is not vulnerable to this issue. However, the kppp FAQ provides instructions for removingconsolehelper and running kppp suid root, which is a vulnerable configuration. Users of kdenetwork should upgrade to these updated packages, which contain a backported patch, and are not vulnerable to this issue. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 148912 - CAN-2005-0205 kppp local domain name hijacking 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: 6d45b649fdbf409ee1cac80df44cbaf3 kdenetwork-2.2.2-3.1.src.rpm i386: f77d0b1ec8454d5e9db1ac68075dd40a kdenetwork-2.2.2-3.1.i386.rpm e9ad587c10388c19b57de53297a56fc1 kdenetwork-ppp-2.2.2-3.1.i386.rpm ia64: ff112935f6c2c6993703ef942bdbce45 kdenetwork-2.2.2-3.1.ia64.rpm 6e6f090bf6e50e1357d05744eca2c04a kdenetwork-ppp-2.2.2-3.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: 6d45b649fdbf409ee1cac80df44cbaf3 kdenetwork-2.2.2-3.1.src.rpm ia64: ff112935f6c2c6993703ef942bdbce45 kdenetwork-2.2.2-3.1.ia64.rpm 6e6f090bf6e50e1357d05744eca2c04a kdenetwork-ppp-2.2.2-3.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: 6d45b649fdbf409ee1cac80df44cbaf3 kdenetwork-2.2.2-3.1.src.rpm i386: f77d0b1ec8454d5e9db1ac68075dd40a kdenetwork-2.2.2-3.1.i386.rpm e9ad587c10388c19b57de53297a56fc1 kdenetwork-ppp-2.2.2-3.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: 6d45b649fdbf409ee1cac80df44cbaf3 kdenetwork-2.2.2-3.1.src.rpm i386: f77d0b1ec8454d5e9db1ac68075dd40a kdenetwork-2.2.2-3.1.i386.rpm e9ad587c10388c19b57de53297a56fc1 kdenetwork-ppp-2.2.2-3.1.i386.rpm Red Hat Enterprise Linux AS version 3: SRPMS: 0a726316b46482f984b35c9d1353c51a kdenetwork-3.1.3-1.8.src.rpm i386: 45731aeaf4549c038bb83fdca74fb4a3 kdenetwork-3.1.3-1.8.i386.rpm 53b0d4af942642630e09792d653c9db7 kdenetwork-devel-3.1.3-1.8.i386.rpm ia64: 7bc73bc084db2416a5a727106088e563 kdenetwork-3.1.3-1.8.ia64.rpm 4d1fc33723154ddac7b1621189bdb82f kdenetwork-devel-3.1.3-1.8.ia64.rpm ppc: 5a74bdef261122d6d5c2e32dbef559ec kdenetwork-3.1.3-1.8.ppc.rpm c78052b174f31955e99bc415e959398f kdenetwork-devel-3.1.3-1.8.ppc.rpm s390: 3ab0491c71719fa9da87cd341d6e8486 kdenetwork-3.1.3-1.8.s390.rpm d4110571eebc4978b073a3652726b763 kdenetwork-devel-3.1.3-1.8.s390.rpm s390x: 18cc2a9c00a999b43e652374e7037220 kdenetwork-3.1.3-1.8.s390x.rpm 9a67309561e157e455480193f40a0a59 kdenetwork-devel-3.1.3-1.8.s390x.rpm x86_64: e078407491bbef5814ee0a610859ecc5 kdenetwork-3.1.3-1.8.x86_64.rpm dfa39b122c1ae9352b01962d4f530254 kdenetwork-devel-3.1.3-1.8.x86_64.rpm Red Hat Desktop version 3: SRPMS: 0a726316b46482f984b35c9d1353c51a kdenetwork-3.1.3-1.8.src.rpm i386: 45731aeaf4549c038bb83fdca74fb4a3 kdenetwork-3.1.3-1.8.i386.rpm 53b0d4af942642630e09792d653c9db7 kdenetwork-devel-3.1.3-1.8.i386.rpm x86_64: e078407491bbef5814ee0a610859ecc5 kdenetwork-3.1.3-1.8.x86_64.rpm dfa39b122c1ae9352b01962d4f530254 kdenetwork-devel-3.1.3-1.8.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 0a726316b46482f984b35c9d1353c51a kdenetwork-3.1.3-1.8.src.rpm i386: 45731aeaf4549c038bb83fdca74fb4a3 kdenetwork-3.1.3-1.8.i386.rpm 53b0d4af942642630e09792d653c9db7 kdenetwork-devel-3.1.3-1.8.i386.rpm ia64: 7bc73bc084db2416a5a727106088e563 kdenetwork-3.1.3-1.8.ia64.rpm 4d1fc33723154ddac7b1621189bdb82f kdenetwork-devel-3.1.3-1.8.ia64.rpm x86_64: e078407491bbef5814ee0a610859ecc5 kdenetwork-3.1.3-1.8.x86_64.rpm dfa39b122c1ae9352b01962d4f530254 kdenetwork-devel-3.1.3-1.8.x86_64.rpm Red Hat Enterprise Linux WS version3: SRPMS: 0a726316b46482f984b35c9d1353c51a kdenetwork-3.1.3-1.8.src.rpm i386: 45731aeaf4549c038bb83fdca74fb4a3 kdenetwork-3.1.3-1.8.i386.rpm 53b0d4af942642630e09792d653c9db7 kdenetwork-devel-3.1.3-1.8.i386.rpm ia64: 7bc73bc084db2416a5a727106088e563 kdenetwork-3.1.3-1.8.ia64.rpm 4d1fc33723154ddac7b1621189bdb82f kdenetwork-devel-3.1.3-1.8.ia64.rpm x86_64: e078407491bbef5814ee0a610859ecc5 kdenetwork-3.1.3-1.8.x86_64.rpm dfa39b122c1ae9352b01962d4f530254 kdenetwork-devel-3.1.3-1.8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-CAN-2005-0205 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2005 Red Hat, Inc. . Red Hat recommends upgrading kdenetwork components to address a minor vulnerability. Further information is available in the security advisory issued.. Kdenetwork Package Update, Red Hat Advisory, File Descriptor Leak, Low Impact Security, Local User Exploits. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Mar 03, 2005 Low Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200