New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-83aa12829d 2025-08-09 03:07:08.046910+00:00 -------------------------------------------------------------------------------- Name : incus Product : Fedora 41 Version : 6.15 Release : 1.fc41 URL : https://linuxcontainers.org/incus Summary : Powerful system container and virtual machine manager Description : Container hypervisor based on LXC Incus offers a REST API to remotely manage containers over the network, using an image based work-flow and with support for live migration. This package contains the Incus daemon. -------------------------------------------------------------------------------- Update Information: New release of Incus. Release information: https://github.com/lxc/incus/releases/tag/v6.15.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 3 2025 Robby Callicotte - 6.15-1 - Updated to incus-6.15 * Thu Jul 24 2025 Fedora Release Engineering - 6.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jun 30 2025 Robby Callicotte - 6.14-1 - Updated to incus-6.14 - Added patch for non-constant format strings * Fri May 30 2025 Robby Callicotte - 6.13-1 - Updated to incus-6.13 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369373 - incus-6.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2369373 [ 2 ] Bug #2374808 - CVE-2025-52889 incus: Incus denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374808 [ 3 ] Bug #2374809 - CVE-2025-52889 incus: Incus denial of service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374809 [ 4 ] Bug #2374810 - CVE-2025-52890 incus: Incus firewall rule bypass[fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2374810 [ 5 ] Bug #2374811 - CVE-2025-52890 incus: Incus firewall rule bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2374811 [ 6 ] Bug #2375609 - incus: mapstructure May Leak Sensitive Information [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2375609 [ 7 ] Bug #2375625 - incus: mapstructure May Leak Sensitive Information [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2375625 [ 8 ] Bug #2384118 - incus: Host Header Injection in github.com/go-chi/chi [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384118 [ 9 ] Bug #2384130 - incus: Host Header Injection in github.com/go-chi/chi [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2384130 [ 10 ] Bug #2384144 - incus: go-viper information leak [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2384144 [ 11 ] Bug #2384160 - incus: go-viper information leak [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2384160 [ 12 ] Bug #2385075 - incus: FTBFS in Fedora rawhide/f43 https://bugzilla.redhat.com/show_bug.cgi?id=2385075 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-83aa12829d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for apache2-mod_security2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2023:0314-1 Rating: important References: #1207378 Cross-References: CVE-2022-48279 CVSS scores: CVE-2022-48279 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-48279 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for apache2-mod_security2 fixes the following issues: - CVE-2022-48279: Fixed a potential firewall bypass due to an incorrect parsing of HTTP multipart requests (bsc#1207378). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2023-314=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2023-314=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): apache2-mod_security2-2.9.4-150400.3.3.1 apache2-mod_security2-debuginfo-2.9.4-150400.3.3.1 apache2-mod_security2-debugsource-2.9.4-150400.3.3.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (aarch64 ppc64le s390x x86_64): apache2-mod_security2-2.9.4-150400.3.3.1 apache2-mod_security2-debuginfo-2.9.4-150400.3.3.1 apache2-mod_security2-debugsource-2.9.4-150400.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-48279.html https://bugzilla.suse.com/1207378 . Crucial notification regarding apache2-mod_security2 fixes significant vulnerability allowing firewall circumvention on SUSE platforms.. apache2 security update, SUSE patch instructions, firewall bypass fix. . Severity: Important. LinuxSecurity.com Team
The system's firewall could be bypassed by a remote attacker.. =========================================================================Ubuntu Security Notice USN-1661-1 December 11, 2012 linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.04 LTS Summary: The system's firewall could be bypassed by a remote attacker. Software Description: - linux: Linux kernel Details: Zhang Zuotao discovered a bug in the Linux kernel's handling of overlapping fragments in ipv6. A remote attacker could exploit this flaw to bypass firewalls and initial new network connections that should have been blocked by the firewall. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: linux-image-2.6.32-45-386 2.6.32-45.101 linux-image-2.6.32-45-generic 2.6.32-45.101 linux-image-2.6.32-45-generic-pae 2.6.32-45.101 linux-image-2.6.32-45-ia64 2.6.32-45.101 linux-image-2.6.32-45-lpia 2.6.32-45.101 linux-image-2.6.32-45-powerpc 2.6.32-45.101 linux-image-2.6.32-45-powerpc-smp 2.6.32-45.101 linux-image-2.6.32-45-powerpc64-smp 2.6.32-45.101 linux-image-2.6.32-45-preempt 2.6.32-45.101 linux-image-2.6.32-45-server 2.6.32-45.101 linux-image-2.6.32-45-sparc64 2.6.32-45.101 linux-image-2.6.32-45-sparc64-smp 2.6.32-45.101 linux-image-2.6.32-45-versatile 2.6.32-45.101 linux-image-2.6.32-45-virtual 2.6.32-45.101 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1661-1 CVE-2012-4444 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.32-45.101 . Ubuntu Security Notice USN-1661-1 highlights a critical kernel flaw allowing remote attackers to bypass firewalls in the 10.04 LTS version. Update is essential..Kernel Bug, Firewall Bypass, Remote Access. . Severity: Critical. LinuxSecurity.com Team
The system's firewall could be bypassed by a remote attacker.. =========================================================================Ubuntu Security Notice USN-1660-1 December 11, 2012 linux vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 8.04 LTS Summary: The system's firewall could be bypassed by a remote attacker. Software Description: - linux: Linux kernel Details: Zhang Zuotao discovered a bug in the Linux kernel's handling of overlapping fragments in ipv6. A remote attacker could exploit this flaw to bypass firewalls and initial new network connections that should have been blocked by the firewall. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 8.04 LTS: linux-image-2.6.24-32-386 2.6.24-32.107 linux-image-2.6.24-32-generic 2.6.24-32.107 linux-image-2.6.24-32-hppa32 2.6.24-32.107 linux-image-2.6.24-32-hppa64 2.6.24-32.107 linux-image-2.6.24-32-itanium 2.6.24-32.107 linux-image-2.6.24-32-lpia 2.6.24-32.107 linux-image-2.6.24-32-lpiacompat 2.6.24-32.107 linux-image-2.6.24-32-mckinley 2.6.24-32.107 linux-image-2.6.24-32-openvz 2.6.24-32.107 linux-image-2.6.24-32-powerpc 2.6.24-32.107 linux-image-2.6.24-32-powerpc-smp 2.6.24-32.107 linux-image-2.6.24-32-powerpc64-smp 2.6.24-32.107 linux-image-2.6.24-32-rt 2.6.24-32.107 linux-image-2.6.24-32-server 2.6.24-32.107 linux-image-2.6.24-32-sparc64 2.6.24-32.107 linux-image-2.6.24-32-sparc64-smp 2.6.24-32.107 linux-image-2.6.24-32-virtual 2.6.24-32.107 linux-image-2.6.24-32-xen 2.6.24-32.107 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1660-1 CVE-2012-4444 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.24-32.107 . A critical security issue allows attackers to bypass firewalls in Ubuntu 8.04 LTS systems. Fix it by applying updates quickly.. Ubuntu Kernel Security, Firewall Bypass, Linux Update, Kernel Exploit. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.