Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
98

Important Security Fix for QEMU-KVM-RHEV in Red Hat OpenStack 13.0

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm-rhev security update Advisory ID: RHSA-2020:1296-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:1296 Issue date: 2020-04-02 CVE Names: CVE-2020-1711 CVE-2020-7039 ==================================================================== 1. Summary: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - ppc64le, x86_64 3. Description: KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Security Fix(es): * QEMU: block: iscsi: OOB heap access via an unexpected response of iSCSI Server (CVE-2020-1711) * QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() (CVE-2020-7039) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1791551 - CVE-2020-7039 QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() 1794290 - CVE-2020-1711 QEMU: block: iscsi: OOB heap access via an unexpected response of iSCSI Server 6. Package List: Red Hat OpenStack Platform 13.0: Source: qemu-kvm-rhev-2.12.0-44.el7.src.rpm ppc64le: qemu-img-rhev-2.12.0-44.el7.ppc64le.rpm qemu-kvm-common-rhev-2.12.0-44.el7.ppc64le.rpm qemu-kvm-rhev-2.12.0-44.el7.ppc64le.rpm qemu-kvm-rhev-debuginfo-2.12.0-44.el7.ppc64le.rpm qemu-kvm-tools-rhev-2.12.0-44.el7.ppc64le.rpm x86_64: qemu-img-rhev-2.12.0-44.el7.x86_64.rpm qemu-kvm-common-rhev-2.12.0-44.el7.x86_64.rpm qemu-kvm-rhev-2.12.0-44.el7.x86_64.rpm qemu-kvm-rhev-debuginfo-2.12.0-44.el7.x86_64.rpm qemu-kvm-tools-rhev-2.12.0-44.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-1711 https://access.redhat.com/security/cve/CVE-2020-7039 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXoW4XdzjgjWX9erEAQh/lQ/9HqFUAW6stlzVxHLIjcfT2fca9hZ+Hb3W 8ZIWbChxiPhWwUdhay7md9QCUGylZ9CmmJTXrpC9Tk4s5BiIIYAhYZGWtUceKXhM fi7oqnFc14ft2SkF6QIS2oRSfDl4ZScNynhPDlyk8ulc0Ev1ZOUIuxMLOlLGaniu mt9wNvwNrXMBikPsePTGrmJDITvkumtiex6BP/v1wJu3Ip616xMFfl5UcoDircjW A8oou3XcvSrqdQZPNtOvIwSW62aVPnxzQ+owicZPn5dE46WYAlOG8mqOet4w59IK +vYGNNs+0aSsBCz94tIxV4beQyLBDdT6Tastg8yWt0Q0Qj0rAoMfAZBoxycqmFSz hczMSaWxFi+3/AjyYYAa6j3VLZDAbkv0W97O0S7KSHGhMdDcjn4gmTw4MwBGJ2PL jzdnm4Y81BUOeq7NCeYoPhq3ZoiBYJ6sS7XZKnJPSdUMjjSkYceIszGH6oiGxajF 3o7JiwDRWe0vzCfh1bbOseXesVJu8iFSbhasFb8DLrkSOvJb75SunXmiZpqHzAWi +d0UBaNrhVbeNz+qUCAyOx1SfG10akaivJuzuh5o3Fu3i73nAFnp9r7szTbxyjSP Z3vToKxAdKI6hh0sHboApUxswbTG1Q6hC3zBouI1IERPBglu5TOLNqbiKbsc2VzO ahTJEJgwyIU=YCfb -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat OpenStack Platform 14.0 releases a significant security patch for qemu-kvm-rhev tackling severe vulnerabilities impacting customers.. Red Hat OpenStack, qemu-kvm, out of bounds access, security patch, important advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 02, 2020 Important Red Hat
98

Important Security Fix for QEMU-KVM-MA in Red Hat Enterprise Linux 7

An update for qemu-kvm-ma is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm-ma security update Advisory ID: RHSA-2020:1150-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1150 Issue date: 2020-03-31 CVE Names: CVE-2020-1711 CVE-2020-7039 ==================================================================== 1. Summary: An update for qemu-kvm-ma is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x Red Hat Enterprise Linux Server Optional (v. 7) - ppc64 3. Description: Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-ma packages provide the user-space component for running virtual machines that use KVM on the IBM z Systems, IBM Power, and 64-bit ARM architectures. Security Fix(es): * QEMU: block: iscsi: OOB heap access via an unexpected response of iSCSI Server (CVE-2020-1711) * QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() (CVE-2020-7039) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. AdditionalChanges: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1791551 - CVE-2020-7039 QEMU: slirp: OOB buffer access while emulating tcp protocols in tcp_emu() 1794290 - CVE-2020-1711 QEMU: block: iscsi: OOB heap access via an unexpected response of iSCSI Server 6. Package List: Red Hat Enterprise Linux Server (v. 7): Source: qemu-kvm-ma-2.12.0-44.el7.src.rpm ppc64: qemu-img-ma-2.12.0-44.el7.ppc64.rpm qemu-kvm-ma-debuginfo-2.12.0-44.el7.ppc64.rpm ppc64le: qemu-img-ma-2.12.0-44.el7.ppc64le.rpm qemu-kvm-common-ma-2.12.0-44.el7.ppc64le.rpm qemu-kvm-ma-2.12.0-44.el7.ppc64le.rpm qemu-kvm-ma-debuginfo-2.12.0-44.el7.ppc64le.rpm qemu-kvm-tools-ma-2.12.0-44.el7.ppc64le.rpm s390x: qemu-img-ma-2.12.0-44.el7.s390x.rpm qemu-kvm-common-ma-2.12.0-44.el7.s390x.rpm qemu-kvm-ma-2.12.0-44.el7.s390x.rpm qemu-kvm-ma-debuginfo-2.12.0-44.el7.s390x.rpm qemu-kvm-tools-ma-2.12.0-44.el7.s390x.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: qemu-kvm-common-ma-2.12.0-44.el7.ppc64.rpm qemu-kvm-ma-2.12.0-44.el7.ppc64.rpm qemu-kvm-ma-debuginfo-2.12.0-44.el7.ppc64.rpm qemu-kvm-tools-ma-2.12.0-44.el7.ppc64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-1711 https://access.redhat.com/security/cve/CVE-2020-7039 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/7/html/7.8_release_notes/index 8.Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXoOcmNzjgjWX9erEAQif7Q/9FTUtfkc53GUGFOfjpJFakvnY+n3+/CaR MFXf3RSrtXDR/qD99uyFJ3PmjTeiCwYNbgIYTDWuJ6aiArfHf9EntGc4Uuo6gzlb f8gdwYYHyLdWBDKgbMisZojSbj9nY20Dlw1w6wNY6QLl4ply9trFYQ0aw65v6+49 G+4IOBod/hMZa7vZQFGEDjUawgv5RDDiAIuYb1f9KC4HypsKiFOBiq+K1vMLb5n9 WjrTp2yPnq9PMf3bKRnEyt/u8uPgTodymrMCLvEA6I5UQKkZ9eO3AL2LkCLCbQQ5 fJLGqizyDoadM4usZYeBvPS9uHa1vaWEdGohnwbPBkuIh/OyhAdVexs1yWy8hOsj HIgPLMW5vkkk5GhPRpIAmPML4J2ZldZjpaVohOQhMtqYSVFweH1u1YP40KDBsfGe U+NJ4xh9GV80JdgJbtSZp+OoaPC2IqSCaDJ5LOfzYkFmYk4yh4TxX/D/n0GqPi75 R8KTg6sFkEuH4JBo5ZRibfp7jzEP3eSI3Qe4zYq32fkTccHGR+vAthCnnZ8Rjlwn Ze+hvXuZBlPns/9nqD/9HyUZWOXewLipjAsRpIJOSlB9nD4pbmBIjv4SV4jGDj7x QkaSoyyWEDnnIe5eJz6+UxB8xlwC5P3bYw+4WWC714vSxsbdgEfe+RXXiO2UdRIq XASlVuF0GWA=tSy9 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security notice for Red Hat related to the qemu-kvm-ma patch to rectify buffer overflow and heap exploitation vulnerabilities.. Red Hat Enterprise Linux, qemu-kvm-ma, Linux Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 31, 2020 Important Red Hat
217

Oracle Linux 5 ELSA-2012-1512 Critical: Libxml2 Heap Access Issue

The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2012-1512 https://access.redhat.com/errata/RHSA-2012:1512.html The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: libxml2-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm libxml2-devel-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm libxml2-python-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm x86_64: libxml2-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm libxml2-2.6.26-2.1.15.0.1.el5_8.6.x86_64.rpm libxml2-devel-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm libxml2-devel-2.6.26-2.1.15.0.1.el5_8.6.x86_64.rpm libxml2-python-2.6.26-2.1.15.0.1.el5_8.6.x86_64.rpm ia64: libxml2-2.6.26-2.1.15.0.1.el5_8.6.i386.rpm libxml2-2.6.26-2.1.15.0.1.el5_8.6.ia64.rpm libxml2-devel-2.6.26-2.1.15.0.1.el5_8.6.ia64.rpm libxml2-python-2.6.26-2.1.15.0.1.el5_8.6.ia64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/libxml2-2.6.26-2.1.15.0.1.el5_8.6.src.rpm Description of changes: [2.6.26-2.1.15.0.1.el5_8.6 ] - Add libxml2-enterprise.patch - Replaced docs/redhat.gif in tarball with updated image [2.6.26-2.1.15.el5_8.6] - fix out of range heap access (CVE-2012-5134) . A critical security patch for Oracle Linux 5 resolves a vulnerability related to memory management in libxml2. Review the comprehensive change log and update instructions.. Oracle Linux Security, Libxml2 Patch, Security Update, Heap Access Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 29, 2012 Critical Oracle
217

Oracle Linux 6 ELSA-2012-1512 Critical: Libxml2 Heap Access Issue

The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2012-1512 https://access.redhat.com/errata/RHSA-2012:1512.html The following updated rpms for Oracle Linux 6 have been uploaded to the Unbreakable Linux Network: i386: libxml2-2.7.6-8.0.1.el6_3.4.i686.rpm libxml2-devel-2.7.6-8.0.1.el6_3.4.i686.rpm libxml2-python-2.7.6-8.0.1.el6_3.4.i686.rpm libxml2-static-2.7.6-8.0.1.el6_3.4.i686.rpm x86_64: libxml2-2.7.6-8.0.1.el6_3.4.i686.rpm libxml2-2.7.6-8.0.1.el6_3.4.x86_64.rpm libxml2-devel-2.7.6-8.0.1.el6_3.4.i686.rpm libxml2-devel-2.7.6-8.0.1.el6_3.4.x86_64.rpm libxml2-python-2.7.6-8.0.1.el6_3.4.x86_64.rpm libxml2-static-2.7.6-8.0.1.el6_3.4.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol6/SRPMS-updates/libxml2-2.7.6-8.0.1.el6_3.4.src.rpm Description of changes: [2.7.6-8.0.1.el6_3.4 ] - Update doc/redhat.gif in tarball - Add libxml2-oracle-enterprise.patch and update logos in tarball [2.7.6-8.el6_3.4] - fix out of range heap access (CVE-2012-5134) . The Oracle Linux Security Advisory ELSA-2012-1512 presents essential patches for libxml2, resolving critical heap access vulnerabilities.. Oracle Linux, Libxml2 Update, Security Advisory, Critical Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 29, 2012 Critical Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here