Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8244-1 May 07, 2026 linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17, linux-hwe-6.17, linux-oracle, linux-realtime, linux-realtime-6.17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-realtime: Linux kernel for Real-time systems - linux-aws-6.17: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp-6.17: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-6.17: Linux hardware enablement (HWE) kernel - linux-realtime-6.17: Linux kernel for Real-time systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - NVME drivers; - Netfilter; (CVE-2026-23112, CVE-2026-23231, CVE-2026-23273) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 linux-image-6.17.0-1011-realtime 6.17.0-1011.12 linux-image-6.17.0-1012-oracle 6.17.0-1012.12 linux-image-6.17.0-1012-oracle-64k 6.17.0-1012.12 linux-image-6.17.0-1013-aws 6.17.0-1013.13 linux-image-6.17.0-1013-aws-64k 6.17.0-1013.13 linux-image-6.17.0-1013-gcp 6.17.0-1013.13 linux-image-6.17.0-1013-gcp-64k 6.17.0-1013.13 linux-image-6.17.0-23-generic 6.17.0-23.23 linux-image-6.17.0-23-generic-64k 6.17.0-23.23 linux-image-aws 6.17.0-1013.13 linux-image-aws-6.17 6.17.0-1013.13 linux-image-aws-64k 6.17.0-1013.13 linux-image-aws-64k-6.17 6.17.0-1013.13 linux-image-gcp 6.17.0-1013.13 linux-image-gcp-6.17 6.17.0-1013.13 linux-image-gcp-64k 6.17.0-1013.13 linux-image-gcp-64k-6.17 6.17.0-1013.13 linux-image-generic 6.17.0-23.23 linux-image-generic-6.17 6.17.0-23.23 linux-image-generic-64k 6.17.0-23.23 linux-image-generic-64k-6.17 6.17.0-23.23 linux-image-oracle 6.17.0-1012.12 linux-image-oracle-6.17 6.17.0-1012.12 linux-image-oracle-64k 6.17.0-1012.12 linux-image-oracle-64k-6.17 6.17.0-1012.12 linux-image-realtime 6.17.0-1011.12 linux-image-realtime-6.17 6.17.0-1011.12 linux-image-virtual 6.17.0-23.23 linux-image-virtual-6.17 6.17.0-23.23 Ubuntu 24.04 LTS linux-image-6.17.0-1011-realtime 6.17.0-1011.12~24.04.1 Available with Ubuntu Pro linux-image-6.17.0-1013-aws 6.17.0-1013.13~24.04.1 linux-image-6.17.0-1013-aws-64k 6.17.0-1013.13~24.04.1 linux-image-6.17.0-1013-gcp 6.17.0-1013.13~24.04.1 linux-image-6.17.0-1013-gcp-64k 6.17.0-1013.13~24.04.1 linux-image-6.17.0-23-generic 6.17.0-23.23~24.04.1 linux-image-6.17.0-23-generic-64k 6.17.0-23.23~24.04.1 linux-image-aws 6.17.0-1013.13~24.04.1 linux-image-aws-6.17 6.17.0-1013.13~24.04.1 linux-image-aws-64k 6.17.0-1013.13~24.04.1 linux-image-aws-64k-6.17 6.17.0-1013.13~24.04.1 linux-image-gcp 6.17.0-1013.13~24.04.1 linux-image-gcp-6.17 6.17.0-1013.13~24.04.1 linux-image-gcp-64k 6.17.0-1013.13~24.04.1 linux-image-gcp-64k-6.17 6.17.0-1013.13~24.04.1 linux-image-generic-6.17 6.17.0-23.23~24.04.1 linux-image-generic-64k-6.17 6.17.0-23.23~24.04.1 linux-image-generic-64k-hwe-24.04 6.17.0-23.23~24.04.1 linux-image-generic-hwe-24.04 6.17.0-23.23~24.04.1 linux-image-realtime-6.17 6.17.0-1011.12~24.04.1 Available with Ubuntu Pro linux-image-realtime-hwe-24.04 6.17.0-1011.12~24.04.1 Available with Ubuntu Pro linux-image-virtual-6.17 6.17.0-23.23~24.04.1 linux-image-virtual-hwe-24.04 6.17.0-23.23~24.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8244-1 CVE-2026-23112, CVE-2026-23231, CVE-2026-23273 Package Information: https://launchpad.net/ubuntu/+source/linux/6.17.0-23.23 https://launchpad.net/ubuntu/+source/linux-aws/6.17.0-1013.13 https://launchpad.net/ubuntu/+source/linux-gcp/6.17.0-1013.13 https://launchpad.net/ubuntu/+source/linux-oracle/6.17.0-1012.12 https://launchpad.net/ubuntu/+source/linux-realtime/6.17.0-1011.12 https://launchpad.net/ubuntu/+source/linux-aws-6.17/6.17.0-1013.13~24.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-6.17/6.17.0-1013.13~24.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-6.17/6.17.0-23.23~24.04.1 https://launchpad.net/ubuntu/+source/linux-realtime-6.17/6.17.0-1011.12~24.04.1 . Several security issues fixed in the Linux kernel for Ubuntu 25.10 and 24.04 LTS with updates recommended to protect systems.. Linux kernel security issues, Ubuntu kernel updates, system security fixes, Linux kernel vulnerabilities, Ubuntu system patching. . Severity: Important. LinuxSecurity.com Team
Update to 1.26.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-8327c1ad81 2025-08-19 04:14:40.703697+00:00 -------------------------------------------------------------------------------- Name : mingw-gstreamer1-plugins-base Product : Fedora 42 Version : 1.26.3 Release : 1.fc42 URL : http://gstreamer.freedesktop.org/ Summary : Cross compiled GStreamer1 media framework base plug-ins Description : GStreamer is a streaming media framework, based on graphs of filters which operate on media data. Applications using this library can do anything from real-time sound processing to playing videos, and just about anything else media-related. Its plugin-based architecture means that new data types or processing capabilities can be added simply by installing new plug-ins. This package contains a set of well-maintained base plug-ins. -------------------------------------------------------------------------------- Update Information: Update to 1.26.3. -------------------------------------------------------------------------------- ChangeLog: * Sun Jun 29 2025 Sandro Mani - 1.26.3-1 - Update to 1.26.3 * Sat May 31 2025 Sandro Mani - 1.26.2-1 - Update to 1.26.2 * Sat Apr 26 2025 Sandro Mani - 1.26.1-1 - Update to 1.26.1 * Sun Mar 16 2025 Sandro Mani - 1.26.0-1 - Update to 1.26.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2387233 - CVE-2025-47183 CVE-2025-47219 mingw-gstreamer1-plugins-good: various flaws [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2387233 [ 2 ] Bug #2387236 - CVE-2025-47806 CVE-2025-47807 CVE-2025-47808 mingw-gstreamer1-plugins-base: various flaws [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2387236 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2025-8327c1ad81' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7291-1 February 25, 2025 linux-gcp, linux-gcp-5.15, linux-gke vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - x86 architecture; - Block layer subsystem; - ACPI drivers; - GPU drivers; - HID subsystem; - I2C subsystem; - IIO ADC drivers; - IIO subsystem; - InfiniBand drivers; - IOMMU subsystem; - IRQ chip drivers; - Multiple devices driver; - Media drivers; - Network drivers; - STMicroelectronics network drivers; - Parport drivers; - Pin controllers subsystem; - Direct Digital Synthesis drivers; - TCM subsystem; - TTY drivers; - USB Dual Role (OTG-ready) Controller drivers; - USB Serial drivers; - USB Type-C support driver; - USB Type-C Connector System Software Interface driver; - BTRFS file system; - File systems infrastructure; - Network file system (NFS) client; - NILFS2 file system; - NTFS3 file system; - SMB network file system; - User-space API (UAPI); - io_uring subsystem; - BPF subsystem; - Timer substystem drivers; - Tracing infrastructure; - Closures library; - Memory management; - Amateur Radio drivers; - Bluetooth subsystem; - Networking core; - IPv4 networking; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Network traffic control; - SCTP protocol; - XFRM subsystem; - Key management; - FireWire sound drivers; - HD-audio driver; - QCOM ASoC drivers; - STMicroelectronics SoC drivers; - KVM core; (CVE-2024-50083, CVE-2024-50134, CVE-2024-53063, CVE-2024-50131, CVE-2024-53104, CVE-2024-50182, CVE-2024-50279, CVE-2024-50185, CVE-2024-42252, CVE-2024-50247, CVE-2024-50128, CVE-2024-53088, CVE-2024-50082, CVE-2024-50160, CVE-2024-50103, CVE-2024-50259, CVE-2024-35887, CVE-2024-53064, CVE-2024-50251, CVE-2024-50150, CVE-2024-53066, CVE-2024-50262, CVE-2024-41066, CVE-2024-50086, CVE-2024-42291, CVE-2024-53061, CVE-2024-50245, CVE-2024-41080, CVE-2024-50244, CVE-2024-50198, CVE-2024-50282, CVE-2024-50074, CVE-2024-50195, CVE-2024-50010, CVE-2024-50202, CVE-2024-50295, CVE-2024-50162, CVE-2024-50273, CVE-2024-50233, CVE-2024-50302, CVE-2024-50201, CVE-2024-50278, CVE-2024-50036, CVE-2024-50296, CVE-2024-53058, CVE-2024-50116, CVE-2024-50163, CVE-2024-50292, CVE-2024-53097, CVE-2024-50196, CVE-2024-50058, CVE-2024-53042, CVE-2024-53059, CVE-2024-50110, CVE-2024-50151, CVE-2024-26718, CVE-2024-50099, CVE-2024-50115, CVE-2024-50171, CVE-2024-50237, CVE-2024-50154, CVE-2024-50199, CVE-2024-50192, CVE-2024-50167, CVE-2024-50127, CVE-2024-50142, CVE-2024-50229, CVE-2024-50269, CVE-2024-53055, CVE-2024-40965, CVE-2024-50265, CVE-2024-50143, CVE-2024-40953, CVE-2024-50117, CVE-2024-50156, CVE-2024-50193, CVE-2024-50072, CVE-2024-50230, CVE-2024-50287, CVE-2024-50148, CVE-2024-50208, CVE-2024-50267, CVE-2024-50290, CVE-2024-50274, CVE-2024-50085, CVE-2024-50168, CVE-2024-50205, CVE-2024-50232, CVE-2024-50153, CVE-2024-39497, CVE-2024-50194, CVE-2024-50101, CVE-2024-50257, CVE-2024-50249, CVE-2024-50299, CVE-2024-50234, CVE-2024-50209, CVE-2024-50141, CVE-2023-52913, CVE-2024-50301, CVE-2024-50236, CVE-2024-53052, CVE-2024-53101, CVE-2024-50268, CVE-2024-50218) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1075-gke 5.15.0-1075.81 linux-image-5.15.0-1077-gcp 5.15.0-1077.86 linux-image-gcp-lts-22.04 5.15.0.1077.73 linux-image-gke 5.15.0.1075.74 linux-image-gke-5.15 5.15.0.1075.74 Ubuntu 20.04 LTS linux-image-5.15.0-1077-gcp 5.15.0-1077.86~20.04.1 linux-image-gcp 5.15.0.1077.86~20.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7291-1 CVE-2023-52913, CVE-2024-26718, CVE-2024-35887, CVE-2024-39497, CVE-2024-40953, CVE-2024-40965, CVE-2024-41066, CVE-2024-41080, CVE-2024-42252, CVE-2024-42291, CVE-2024-50010, CVE-2024-50036, CVE-2024-50058, CVE-2024-50072, CVE-2024-50074, CVE-2024-50082, CVE-2024-50083, CVE-2024-50085, CVE-2024-50086, CVE-2024-50099, CVE-2024-50101, CVE-2024-50103, CVE-2024-50110, CVE-2024-50115, CVE-2024-50116, CVE-2024-50117, CVE-2024-50127, CVE-2024-50128, CVE-2024-50131, CVE-2024-50134, CVE-2024-50141, CVE-2024-50142, CVE-2024-50143, CVE-2024-50148, CVE-2024-50150, CVE-2024-50151, CVE-2024-50153, CVE-2024-50154, CVE-2024-50156, CVE-2024-50160, CVE-2024-50162, CVE-2024-50163, CVE-2024-50167, CVE-2024-50168, CVE-2024-50171, CVE-2024-50182, CVE-2024-50185, CVE-2024-50192, CVE-2024-50193, CVE-2024-50194, CVE-2024-50195, CVE-2024-50196, CVE-2024-50198, CVE-2024-50199, CVE-2024-50201, CVE-2024-50202, CVE-2024-50205, CVE-2024-50208, CVE-2024-50209, CVE-2024-50218, CVE-2024-50229, CVE-2024-50230, CVE-2024-50232, CVE-2024-50233, CVE-2024-50234, CVE-2024-50236,CVE-2024-50237, CVE-2024-50244, CVE-2024-50245, CVE-2024-50247, CVE-2024-50249, CVE-2024-50251, CVE-2024-50257, CVE-2024-50259, CVE-2024-50262, CVE-2024-50265, CVE-2024-50267, CVE-2024-50268, CVE-2024-50269, CVE-2024-50273, CVE-2024-50274, CVE-2024-50278, CVE-2024-50279, CVE-2024-50282, CVE-2024-50287, CVE-2024-50290, CVE-2024-50292, CVE-2024-50295, CVE-2024-50296, CVE-2024-50299, CVE-2024-50301, CVE-2024-50302, CVE-2024-53042, CVE-2024-53052, CVE-2024-53055, CVE-2024-53058, CVE-2024-53059, CVE-2024-53061, CVE-2024-53063, CVE-2024-53064, CVE-2024-53066, CVE-2024-53088, CVE-2024-53097, CVE-2024-53101, CVE-2024-53104 Package Information: https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1077.86 https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1075.81 https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1077.86~20.04.1 . Ubuntu Security Notice USN-7292-1 announces essential patches addressing severe vulnerabilities in the linux-gcp and linux-gke kernels to improve defense mechanisms.. Ubuntu kernel update, linux-gcp vulnerabilities, linux-gke security. . Severity: Critical. LinuxSecurity.com Team
**MySQL 8.0.32** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-32.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d332f0b6a3 2023-02-16 02:02:01.630824 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 37 Version : 8.0.32 Release : 1.fc37 URL : http://www.mysql.com Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.32** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-32.html --------------------------------------------------------------------------------ChangeLog: * Thu Jan 26 2023 Lars Tangvald - 8.0.32-1 - Update to MySQL 8.0.32 * Thu Jan 19 2023 Fedora Release Engineering - 8.0.31-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Dec 31 2022 Pete Walter - 8.0.31-2 - Rebuild for ICU 72 --------------------------------------------------------------------------------References: [ 1 ] Bug #2142972 - CVE-2022-21594 CVE-2022-21599 CVE-2022-21604 CVE-2022-21608 CVE-2022-21611 CVE-2022-21617 CVE-2022-21625 CVE-2022-21632 CVE-2022-21633 CVE-2022-21637 CVE-2022-21640 CVE-2022-39400 CVE-2022-39408 CVE-2022-39410 community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2142972 [ 2 ] Bug #2161587 - community-mysql-8.0.32 is available https://bugzilla.redhat.com/show_bug.cgi?id=2161587 [ 3 ] Bug #2162320 - CVE-2023-21836 CVE-2023-21863 CVE-2023-21867 CVE-2023-21868 CVE-2023-21869CVE-2023-21870 CVE-2023-21871 CVE-2023-21873 CVE-2023-21875 CVE-2023-21876 CVE-2023-21877 CVE-2023-21878 CVE-2023-21879 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2162320 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d332f0b6a3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-46dc82116b 2021-11-10 02:52:52.381127 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 35 Version : 8.0.27 Release : 1.fc35 URL : https://www.mysql.com/ Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.27** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-27.html --------------------------------------------------------------------------------ChangeLog: * Sun Oct 31 2021 Lars Tangvald - 8.0.27-1 - Update to MySQL 8.0.27 --------------------------------------------------------------------------------References: [ 1 ] Bug #2015421 - community-mysql-8.0.27 is available https://bugzilla.redhat.com/show_bug.cgi?id=2015421 [ 2 ] Bug #2016141 - CVE-2021-2478 CVE-2021-2479 CVE-2021-2481 CVE-2021-35546 CVE-2021-35575 CVE-2021-35577 CVE-2021-35591 CVE-2021-35596 CVE-2021-35597 CVE-2021-35602 CVE-2021-35604 CVE-2021-35607 CVE-2021-35608 CVE-2021-35610 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2016141 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-46dc82116b' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**MySQL 8.0.26** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-df40c41094 2021-08-25 19:52:55.203534 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 34 Version : 8.0.26 Release : 1.fc34 URL : http://www.mysql.com Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: **MySQL 8.0.26** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html --------------------------------------------------------------------------------ChangeLog: * Wed Jul 21 2021 Lars Tangvald - 8.0.26-1 - Update to MySQL 8.0.26 * Wed Jul 21 2021 Fedora Release Engineering - 8.0.25-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1983926 - community-mysql-8.0.26 is available https://bugzilla.redhat.com/show_bug.cgi?id=1983926 [ 2 ] Bug #1992821 - CVE-2021-2339 CVE-2021-2340 CVE-2021-2342 CVE-2021-2352 CVE-2021-2354 CVE-2021-2356 CVE-2021-2357 CVE-2021-2367 CVE-2021-2370 CVE-2021-2372 CVE-2021-2374 CVE-2021-2383 CVE-2021-2384 CVE-2021-2385 ... community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1992821 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2021-df40c41094' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Chromium-browser 80.0.3987.122 fixes security issues: Multiple flaws were found in the way Chromium 79.0.3945.130 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose . MGASA-2020-0123 - Updated chromium-browser-stable packages fix security vulnerabilities Publication date: 06 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0123.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19923, CVE-2019-19925, CVE-2019-19926, CVE-2020-6381, CVE-2020-6382, CVE-2020-6383, CVE-2020-6384, CVE-2020-6385, CVE-2020-6386, CVE-2020-6387, CVE-2020-6388, CVE-2020-6389, CVE-2020-6390, CVE-2020-6391, CVE-2020-6392, CVE-2020-6393, CVE-2020-6394, CVE-2020-6395, CVE-2020-6396, CVE-2020-6397, CVE-2020-6398, CVE-2020-6399, CVE-2020-6400, CVE-2020-6401, CVE-2020-6402, CVE-2020-6403, CVE-2020-6404, CVE-2020-6405, CVE-2020-6406, CVE-2020-6407, CVE-2020-6408, CVE-2020-6409, CVE-2020-6410, CVE-2020-6411, CVE-2020-6412, CVE-2020-6413, CVE-2020-6414, CVE-2020-6415, CVE-2020-6416, CVE-2020-6418, CVE-2019-1819 Chromium-browser 80.0.3987.122 fixes security issues: Multiple flaws were found in the way Chromium 79.0.3945.130 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2020-6381, CVE-2020-6382, CVE-2020-6383, CVE-2020-6384, CVE-2020-6385, CVE-2020-6386, CVE-2020-6387, CVE-2020-6388, CVE-2020-6389, CVE-2020-6390, CVE-2020-6391, CVE-2020-6392, CVE-2020-6393, CVE-2020-6394, CVE-2020-6395, CVE-2020-6396, CVE-2020-6397, CVE-2020-6398, CVE-2020-6399, CVE-2020-6400, CVE-2020-6401, CVE-2020-6402, CVE-2020-6403, CVE-2020-6404, CVE-2020-6405, CVE-2020-6406, CVE-2020-6407,CVE-2020-6408, CVE-2020-6409, CVE-2020-6410, CVE-2020-6411, CVE-2020-6412, CVE-2020-6413, CVE-2020-6414, CVE-2020-6415, CVE-2020-6416, CVE-2020-6418, CVE-2019-18197, CVE-2019-19923, CVE-2019-19925, CVE-2019-19926) Upstream chromium 80.0.3987.122 also includes a fix for an integer overflow issue in ICU. Since the chromium-browser-stable package is linked against the icu packages instead of using the ICU source code bundled with chromium upstream, this issue is fixed in the icu package. References: - https://bugs.mageia.org/show_bug.cgi?id=26269 - https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_11.html - https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_13.html - https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_18.html - https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html - https://unicode-org.atlassian.net/browse/ICU-20958 - https://www.cve.org/CVERecord?id=CVE-2019-19923 - https://www.cve.org/CVERecord?id=CVE-2019-19925 - https://www.cve.org/CVERecord?id=CVE-2019-19926 - https://www.cve.org/CVERecord?id=CVE-2020-6381 - https://www.cve.org/CVERecord?id=CVE-2020-6382 - https://www.cve.org/CVERecord?id=CVE-2020-6383 - https://www.cve.org/CVERecord?id=CVE-2020-6384 - https://www.cve.org/CVERecord?id=CVE-2020-6385 - https://www.cve.org/CVERecord?id=CVE-2020-6386 - https://www.cve.org/CVERecord?id=CVE-2020-6387 - https://www.cve.org/CVERecord?id=CVE-2020-6388 - https://www.cve.org/CVERecord?id=CVE-2020-6389 - https://www.cve.org/CVERecord?id=CVE-2020-6390 - https://www.cve.org/CVERecord?id=CVE-2020-6391 - https://www.cve.org/CVERecord?id=CVE-2020-6392 - https://www.cve.org/CVERecord?id=CVE-2020-6393 - https://www.cve.org/CVERecord?id=CVE-2020-6394 - https://www.cve.org/CVERecord?id=CVE-2020-6395 - https://www.cve.org/CVERecord?id=CVE-2020-6396 - https://www.cve.org/CVERecord?id=CVE-2020-6397 -https://www.cve.org/CVERecord?id=CVE-2020-6398 - https://www.cve.org/CVERecord?id=CVE-2020-6399 - https://www.cve.org/CVERecord?id=CVE-2020-6400 - https://www.cve.org/CVERecord?id=CVE-2020-6401 - https://www.cve.org/CVERecord?id=CVE-2020-6402 - https://www.cve.org/CVERecord?id=CVE-2020-6403 - https://www.cve.org/CVERecord?id=CVE-2020-6404 - https://www.cve.org/CVERecord?id=CVE-2020-6405 - https://www.cve.org/CVERecord?id=CVE-2020-6406 - https://www.cve.org/CVERecord?id=CVE-2020-6407 - https://www.cve.org/CVERecord?id=CVE-2020-6408 - https://www.cve.org/CVERecord?id=CVE-2020-6409 - https://www.cve.org/CVERecord?id=CVE-2020-6410 - https://www.cve.org/CVERecord?id=CVE-2020-6411 - https://www.cve.org/CVERecord?id=CVE-2020-6412 - https://www.cve.org/CVERecord?id=CVE-2020-6413 - https://www.cve.org/CVERecord?id=CVE-2020-6414 - https://www.cve.org/CVERecord?id=CVE-2020-6415 - https://www.cve.org/CVERecord?id=CVE-2020-6416 - https://www.cve.org/CVERecord?id=CVE-2020-6418 - https://www.cve.org/CVERecord?id=CVE-2019-1819 SRPMS: - 7/core/chromium-browser-stable-80.0.3987.122-1.mga7 - 7/core/icu-63.1-1.2.mga7 . Recent security updates for the chromium-browser-stable packages in Mageia address numerous severe vulnerabilities that may lead to system crashes or unauthorized code execution.. chromium-browser, security update, Mageia, critical flaws. . Severity: Critical. LinuxSecurity.com Team
Resolves: #1695046 CVE-2019-0196 CVE-2019-0197 CVE-2019-0215 CVE-2019-0217 CVE-2019-0220 httpd: various flaws Resolves: #1694510 httpd-2.4.39 is available Resolves: #1694986 - CVE-2019-0211 httpd: privilege escalation from modules scripts. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-cf7695b470 2019-04-05 00:00:52.421563 --------------------------------------------------------------------------------Name : httpd Product : Fedora 30 Version : 2.4.39 Release : 2.fc30 URL : https://httpd.apache.org/ Summary : Apache HTTP Server Description : The Apache HTTP Server is a powerful, efficient, and extensible web server. --------------------------------------------------------------------------------Update Information: Resolves: #1695046 CVE-2019-0196 CVE-2019-0197 CVE-2019-0215 CVE-2019-0217 CVE-2019-0220 httpd: various flaws Resolves: #1694510 httpd-2.4.39 is available Resolves: #1694986 - CVE-2019-0211 httpd: privilege escalation from modules scripts --------------------------------------------------------------------------------References: [ 1 ] Bug #1694986 - CVE-2019-0211 httpd: privilege escalation from modules scripts [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1694986 [ 2 ] Bug #1695046 - CVE-2019-0215 CVE-2019-0217 CVE-2019-0220 httpd: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1695046 [ 3 ] Bug #1694510 - httpd-2.4.39 is available https://bugzilla.redhat.com/show_bug.cgi?id=1694510 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-cf7695b470' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.