Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE Leap 15.6 firewalld Moderate Local Auth Issue SUSE-SU-2026-1872-1

An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:1872-1 Release Date: 2026-05-15T15:22:47Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1872=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1872=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1872=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1872=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-1872=1 ## Package List: * openSUSE Leap 15.6 (noarch) * firewall-macros-2.0.1-150600.3.15.1 *firewalld-test-2.0.1-150600.3.15.1 * python3-firewall-2.0.1-150600.3.15.1 * python311-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewall-applet-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Basesystem Module 15-SP7 (noarch) * python3-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Desktop Applications Module 15-SP7 (noarch) * firewall-applet-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * Development Tools Module 15-SP7 (noarch) * firewall-macros-2.0.1-150600.3.15.1 * Python 3 Module 15-SP7 (noarch) * python311-firewall-2.0.1-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . # Security update for firewalld Announcement ID: SUSE-SU-2026:1872-1 Release Date: 2026-05-15T15:22:. update, solves, vulnerability, installed, security, firewalld, announ. . LinuxSecurity.com Team

Calendar 2 May 15, 2026 OpenSUSE
100

SUSE Firewalld Moderate Threat CVE-2026-4948 Advisory 2026-1872-1

An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:1872-1 Release Date: 2026-05-15T15:22:47Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1872=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1872=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-1872=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-1872=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-1872=1 ## Package List: * openSUSE Leap 15.6 (noarch) * firewall-macros-2.0.1-150600.3.15.1 *firewalld-test-2.0.1-150600.3.15.1 * python3-firewall-2.0.1-150600.3.15.1 * python311-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewall-applet-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Basesystem Module 15-SP7 (noarch) * python3-firewall-2.0.1-150600.3.15.1 * firewalld-lang-2.0.1-150600.3.15.1 * firewalld-2.0.1-150600.3.15.1 * firewalld-zsh-completion-2.0.1-150600.3.15.1 * firewalld-bash-completion-2.0.1-150600.3.15.1 * Desktop Applications Module 15-SP7 (noarch) * firewall-applet-2.0.1-150600.3.15.1 * firewall-config-2.0.1-150600.3.15.1 * Development Tools Module 15-SP7 (noarch) * firewall-macros-2.0.1-150600.3.15.1 * Python 3 Module 15-SP7 (noarch) * python311-firewall-2.0.1-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . Local unprivileged users may alter the firewall state due to misauthorized D-Bus methods. Update firewalld now.. firewalld update, SUSE security, D-Bus authentication, moderate threat, Linux firewall. . LinuxSecurity.com Team

Calendar 2 May 15, 2026 SuSE
197

Debian 11 Firewalld Important Unauthorized Access DLA-4585-1 CVE-2026-4948

A flaw was found in firewalld where a local unprivileged user can modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. For Debian 11 bullseye, this problem has been fixed in version 0.9.3-2+deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4585-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Henriksson May 15, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : firewalld Version : 0.9.3-2+deb11u1 CVE ID : CVE-2026-4948 Debian Bug : A flaw was found in firewalld where a local unprivileged user can modify the runtime firewall state without proper authentication, leading to unauthorized changes in network security configurations. For Debian 11 bullseye, this problem has been fixed in version 0.9.3-2+deb11u1. We recommend that you upgrade your firewalld packages. For the detailed security status of firewalld please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firewalld Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A flaw in firewalld allows unauthorized changes to firewall settings by unprivileged users. Update recommended for Debian 11.. firewalld, Debian security, network configuration, unauthorized access, security updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 15, 2026 Important Debian LTS
100

SUSE Linux Micro 6.0 Firewalld Moderate Threat CVE-2026-4948

An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:21418-1 Release Date: 2026-04-29T11:32:57Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issues: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-694=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * python3-firewall-2.0.0-2.1 * firewalld-2.0.0-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . SUSE updates firewalld to address CVE-2026-4948 with moderate severity, enhancing protection against unauthorized access.. SUSE Firewalld Security Update Authentication Vulnerability. . LinuxSecurity.com Team

Calendar 2 Apr 30, 2026 SuSE
219

Rocky Linux 8 RLBA-2021:2580 UnknownSeverity: Firewalld Bug Fix

firewalld bug fix and enhancement update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:2580', 'synopsis': 'firewalld bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for firewalld is now available for Rocky Linux 8.', 'description': 'firewalld is a firewall service daemon that provides a dynamic customizable\nfirewall with a D-Bus interface.\ninterfaces can be) (BZ#1955594)', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1955594'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:2580:::RHBA-2021:2580'], 'references': [], 'publishedAt': '2021-07-22T18:25:24.366568Z', 'rpms': ['firewall-applet-0.8.2-7.el8_4.noarch.rpm', 'firewall-config-0.8.2-7.el8_4.noarch.rpm', 'firewalld-0.8.2-7.el8_4.noarch.rpm', 'firewalld-0.8.2-7.el8_4.src.rpm', 'firewalld-filesystem-0.8.2-7.el8_4.noarch.rpm', 'python3-firewall-0.8.2-7.el8_4.noarch.rpm']}\. AlmaLinux OS 8 has unveiled a fresh update for firewalld featuring various bug resolutions and improvements. Keep your system safe!. Rocky Linux 8, Firewalld Bug Fix, Firewall Service Update. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2022 Rocky Linux
100

SUSE: 2022:1435-1 Important Firewalld Update for Denial of Service

An update that solves one vulnerability, contains three features and has one errata is now available. . SUSE Security Update: Security update for firewalld, golang-github-prometheus-prometheus ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1435-1 Rating: important References: #1196338 #1197042 SLE-24373 SLE-24374 SLE-24375 Cross-References: CVE-2022-21698 CVSS scores: CVE-2022-21698 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-21698 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Enterprise Storage 6 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Micro 5.1 SUSE Linux Enterprise Micro 5.2 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2 SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability, contains three features and has one errata is now available. Description: This update for firewalld, golang-github-prometheus-prometheus fixes the following issues: Security fixes for golang-github-prometheus-prometheus: - CVE-2022-21698: Denial of Service through unbounded cardinality, and potential memory exhaustion, when handling requests with non-standard HTTP methods (bsc#1196338). Other non security changes for golang-github-prometheus-prometheus: - Build `firewalld-prometheus-config` only for SUSE Linux Enterprise 15, 15-SP1 and 15-SP2, and require `firewalld`. - Only recommends `firewalld-prometheus-config` as prometheus does not require it to run. - Create `firewalld-prometheus-config` subpackage (bsc#1197042, jsc#SLE-24373, jsc#SLE-24374, jsc#SLE-24375) Other non security changes for firewalld: - Provide dummy `firewalld-prometheus-config` package (bsc#1197042) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1435=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1435=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2022-1435=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.2-2022-1435=1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.1-2022-1435=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP3-2022-1435=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-1435=1 - SUSE Linux Enterprise Micro 5.2: zypper in -t patch SUSE-SUSE-MicroOS-5.2-2022-1435=1 - SUSE Linux Enterprise Micro 5.1: zypper in -t patchSUSE-SUSE-MicroOS-5.1-2022-1435=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-1435=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 - openSUSE Leap 15.3 (noarch): firewall-applet-0.9.3-150300.3.6.1 firewall-config-0.9.3-150300.3.6.1 firewall-macros-0.9.3-150300.3.6.1 firewalld-0.9.3-150300.3.6.1 firewalld-lang-0.9.3-150300.3.6.1 python3-firewall-0.9.3-150300.3.6.1 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.3 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.2 (aarch64 ppc64le s390x x86_64): golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 - SUSE Linux Enterprise Module for SUSE Manager Proxy 4.1 (aarch64 ppc64le s390x x86_64): firewalld-prometheus-config-0.1-150100.4.9.2 golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (noarch): firewall-applet-0.9.3-150300.3.6.1 firewall-config-0.9.3-150300.3.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (noarch): firewall-macros-0.9.3-150300.3.6.1 firewalld-0.9.3-150300.3.6.1 firewalld-lang-0.9.3-150300.3.6.1 python3-firewall-0.9.3-150300.3.6.1 - SUSE Linux Enterprise Micro 5.2 (noarch): firewalld-0.9.3-150300.3.6.1 python3-firewall-0.9.3-150300.3.6.1 - SUSE Linux Enterprise Micro 5.1 (noarch): firewalld-0.9.3-150300.3.6.1 python3-firewall-0.9.3-150300.3.6.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): firewalld-prometheus-config-0.1-150100.4.9.2 golang-github-prometheus-prometheus-2.32.1-150100.4.9.2 References: https://www.suse.com/security/cve/CVE-2022-21698.html https://bugzilla.suse.com/1196338 https://bugzilla.suse.com/1197042 . SUSE Security Notice for firewalld resolves a severe vulnerability in golang-github-prometheus-prometheus. Immediate action required!. firewalld Update, Denial of Service, SUSE Security Fix, Prometheus Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 27, 2022 Important SuSE
200

Scientific Linux SL7: 2016-2597-2 Moderate: firewalld Unauthorized Access

Moderate: firewalld security, bug fix, and enhancement update. Date: Wed, 14 Dec 2016 18:14:01 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Scott Reid Subject: Security ERRATA Moderate: firewalld on SL7.x (noarch) MIME-Version: 1.0 Message-ID: Synopsis: Moderate: firewalld security, bug fix, and enhancement update Advisory ID: SLSA-2016:2597-2 Issue Date: 2016-11-03 CVE Numbers: CVE-2016-5410 -- The following packages have been upgraded to a newer upstream version: firewalld (0.4.3.2). Security Fix(es): * A flaw was found in the way firewalld allowed certain firewall configurations to be modified by unauthenticated users. Any locally logged in user could use this flaw to tamper or change firewall settings. (CVE-2016-5410) Additional Changes: -- SL7 noarch firewall-config-0.4.3.2-8.el7.noarch.rpm firewalld-0.4.3.2-8.el7.noarch.rpm firewalld-filesystem-0.4.3.2-8.el7.noarch.rpm python-firewall-0.4.3.2-8.el7.noarch.rpm firewall-applet-0.4.3.2-8.el7.noarch.rpm - Scientific Linux Development Team . Recent firewalld security patch resolves unintended configuration alterations on SL7.x systems.. firewalld enhancement, Scientific Linux update, security fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 14, 2016 Important Scientific Linux
98

Red Hat Enterprise Linux 7 RHSA-2016:2597-02 Moderate Firewalld Bug Fix

An update for firewalld is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: firewalld security, bug fix, and enhancement update Advisory ID: RHSA-2016:2597-02 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2016:2597.html Issue date: 2016-11-03 CVE Names: CVE-2016-5410 ==================================================================== 1. Summary: An update for firewalld is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch Red Hat Enterprise Linux Client Optional (v. 7) - noarch Red Hat Enterprise Linux ComputeNode (v. 7) - noarch Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Enterprise Linux Server Optional (v. 7) - noarch Red Hat Enterprise Linux Workstation (v. 7) - noarch Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch 3. Description: firewalld is a firewall service daemon that provides a dynamic customizable firewall with a D-Bus interface. The following packages have been upgraded to a newer upstream version: firewalld (0.4.3.2). (BZ#1302802) Security Fix(es): * A flaw was found in the way firewalld allowed certain firewall configurations to be modified by unauthenticated users. Anylocally logged in user could use this flaw to tamper or change firewall settings. (CVE-2016-5410) Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1066037 - firewall-config should allow unspecifying zone binding for interface 1136801 - a rule added into IN_ _allow chain with 'permanent direct' interface doesn't exist after reload 1147500 - RFE: add command to firewall-cmd showing details of a service 1147951 - firewall-cmd should support a default logging option. 1219717 - Add radius TCP to policy. 1220196 - Firewalld missing policies for imap and smtps 1220467 - Option '--quiet' is needed in firewall-offline-cmd command line. 1237242 - Error: RT_TO_PERM_FAILED: zone 'dmz' : ZONE_CONFLICT when doing --runtime-to-permanent 1273296 - [ALL_LANG][firewalld] Translation incomplete 1273888 - Firewalld DefaultZone change breaking on --reload 1281416 - Headless firewall-config over ssh. firewall-config missing dependencies 1285769 - Fails to start without ip6t_rpfilter module 1292926 - firewalld --new-service & malformed xml ?? 1296573 - xsd specification nor service daemon checks whether tags are specified more than once if they must not 1301573 - firewalld reporting errors in logs for failed iptables commands 1302802 - Rebase to the new upstream and new release 1303026 - firewalld - mistake in renders ports remain closed, silently. 1305434 - Firewalld hangs with a NIS configuration 1313023 - command "systemctl reload firewalld" stops firewalld 1313845 - Backport After=dbus.service 1325335 - [RFE] allow negation of icmp-blocks zone configuration field 1326130 - firewalld stops traffic from/to 127.0.0.1 when masquerading is enabled in default zone 1326462 - rich rule with destination and no elementgive error 1347530 - Add port for corosync-qnetd to high-availability service 1349903 - FirewallD fails to parse direct rules with a lot of destination addresses 1357050 - exit codes don't match error messages in firewall-cmd 1360135 - CVE-2016-5410 firewalld: Firewall configuration can be modified by any logged in user 1360894 - Print errors and warnings to stderr 1365198 - firewall-cmd ipset --add-entries-from-file broken 1367038 - firewall-cmd crashes if /run/dbus/system_bus_socket does not exist 1368949 - Trying to get the description for a firewalld zone from command line throws error and prints traceback information. 1371116 - Load helper modules in FirewallZoneTransaction 1373260 - An error in the permanent direct rules will make all other direct rules using a table other than the filter table not applicable. 1374799 - exclude firewallctl from firewalld v0.4.3.2 update 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: firewalld-0.4.3.2-8.el7.src.rpm noarch: firewall-config-0.4.3.2-8.el7.noarch.rpm firewalld-0.4.3.2-8.el7.noarch.rpm firewalld-filesystem-0.4.3.2-8.el7.noarch.rpm python-firewall-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux Client Optional (v. 7): noarch: firewall-applet-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: firewalld-0.4.3.2-8.el7.src.rpm noarch: firewalld-0.4.3.2-8.el7.noarch.rpm firewalld-filesystem-0.4.3.2-8.el7.noarch.rpm python-firewall-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: firewall-applet-0.4.3.2-8.el7.noarch.rpm firewall-config-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux Server (v. 7): Source: firewalld-0.4.3.2-8.el7.src.rpm noarch: firewall-config-0.4.3.2-8.el7.noarch.rpm firewalld-0.4.3.2-8.el7.noarch.rpm firewalld-filesystem-0.4.3.2-8.el7.noarch.rpm python-firewall-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: firewall-applet-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux Workstation (v.7): Source: firewalld-0.4.3.2-8.el7.src.rpm noarch: firewall-config-0.4.3.2-8.el7.noarch.rpm firewalld-0.4.3.2-8.el7.noarch.rpm firewalld-filesystem-0.4.3.2-8.el7.noarch.rpm python-firewall-0.4.3.2-8.el7.noarch.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: firewall-applet-0.4.3.2-8.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-5410 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/7/html/7.3_Release_Notes/index.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYGvz+XlSAg2UNWIIRAnYNAKC+tOJpkB9nwgqe+K/AaoZBzPX3RQCeM8De T81FpcV1vTa45DoiZC5wdUk=+0pl -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS rolls out a significant patch for SELinux rectifying vulnerabilities and performance concerns for its Stream 8 installations.. firewalld Update, Red Hat Advisory, Security Fix, Linux Firewall Security, Bug Fixes. . LinuxSecurity.com Team

Calendar 2 Nov 03, 2016 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here