Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
172

Ubuntu 25.10: Major Authentication Vulnerability in KDE Connect USN-7905-1

KDE Connect could allow authentication of impersonated devices.. ========================================================================== Ubuntu Security Notice USN-7905-1 December 03, 2025 kdeconnect vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: KDE Connect could allow authentication of impersonated devices. Software Description: - kdeconnect: connect smartphones to your desktop devices Details: It was discovered that KDE Connect incorrectly handled device IDs. An attacker could possibly use this issue to bypass authentication and connect an unpaired device. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 kdeconnect 25.08.1-0ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7905-1 CVE-2025-66270 Package Information: https://launchpad.net/ubuntu/+source/kdeconnect/25.08.1-0ubuntu2.1 . KDE Connect vulnerability in Ubuntu allows impersonated device authentication, a security issue requiring immediate updates.. KDE Connect security, Ubuntu security update, authentication bypass. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 03, 2025 Important Ubuntu
87

Debian: gnome-shell-extension-gsconnect Critical Impersonation Fix DSA-6066-1

It was discovered that missing validation of the device ID during handshakes in KDE Connect, a tool to integrate smart phones to a desktop, could allow an attacker to impersonate another device. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6066-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff November 30, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gnome-shell-extension-gsconnect CVE ID : CVE-2025-66270 It was discovered that missing validation of the device ID during handshakes in KDE Connect, a tool to integrate smart phones to a desktop, could allow an attacker to impersonate another device. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 62-1+deb13u1. We recommend that you upgrade your gnome-shell-extension-gsconnect packages. For the detailed security status of gnome-shell-extension-gsconnect please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gnome-shell-extension-gsconnect Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Gnome-shell-extension-gsconnect on Debian has a serious impersonation issue fixed now. Update your systems immediately.. Debian security advisory, gnome-shell-extension, KDE Connect security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 30, 2025 Critical Debian
100

SUSE: Icinga2 Important CVE-2025-48057 Impersonation Threat Advisory

* bsc#1243747 Cross-References: * CVE-2025-48057 . # Security update for icinga2 Announcement ID: SUSE-SU-2025:02783-1 Release Date: 2025-08-13T08:53:45Z Rating: important References: * bsc#1243747 Cross-References: * CVE-2025-48057 CVSS scores: * CVE-2025-48057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L * CVE-2025-48057 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-48057 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for icinga2 fixes the following issues: * CVE-2025-48057: A certificate incorrectly treated as valid can allow an attacker to impersonate a trusted node (bsc#1243747). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2025-2783=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * icinga2-libs-2.8.2-3.11.2 * icinga2-ido-mysql-debuginfo-2.8.2-3.11.2 * icinga2-common-2.8.2-3.11.2 * icinga2-bin-debuginfo-2.8.2-3.11.2 * icinga2-debugsource-2.8.2-3.11.2 * icinga2-libs-debuginfo-2.8.2-3.11.2 * icinga2-doc-2.8.2-3.11.2 * icinga2-bin-2.8.2-3.11.2 * icinga2-ido-pgsql-debuginfo-2.8.2-3.11.2 * icinga2-ido-pgsql-2.8.2-3.11.2 * vim-icinga2-2.8.2-3.11.2 * icinga2-2.8.2-3.11.2 * icinga2-ido-mysql-2.8.2-3.11.2 ## References: * https://www.suse.com/security/cve/CVE-2025-48057.html * https://bugzilla.suse.com/show_bug.cgi?id=1243747 . SUSE unveiled a crucial patch for icinga2 to mitigate CVE-2025-48058, reinforcing defenses against spoofing vulnerabilities.. Icinga2 Update,SUSE Important Patch,CVE-2025-48057,SUSE Security Fix,Impersonation Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 13, 2025 Important SuSE
219

Rocky Linux SIG Cloud 8 RXSA-2024:4211 Important: Kernel Security Fixes

Important: kernel security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RX", "name": "RXSA-2024:4211", "synopsis": "Important: kernel security and bug fix update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for kernel.\nThis update affects Rocky Linux SIG Cloud 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: Bluetooth BR/EDR PIN Pairing procedure is vulnerable to an impersonation attack (CVE-2020-26555)\n\n* kernel: TCP-spoofed ghost ACKs and leak leak initial sequence number (CVE-2023-52881,RHV-2024-1001)\n\n* kernel: ovl: fix leaked entry (CVE-2021-46972)\n\n* kernel: platform/x86: dell-smbios-wmi: Fix oops on rmmod dell_smbios (CVE-2021-47073)\n\n* kernel: gro: fix ownership transfer (CVE-2024-35890)\n\n* kernel: tls: (CVE-2024-26584, CVE-2024-26583, CVE-2024-26585)\n\n* kernel: wifi: (CVE-2024-35789, CVE-2024-27410, CVE-2024-35838, CVE-2024-35845)\n\n* kernel: mlxsw: (CVE-2024-35855, CVE-2024-35854, CVE-2024-35853, CVE-2024-35852, CVE-2024-36007)\n\n* kernel: PCI interrupt mapping cause oops [rhel-8] (CVE-2021-46909)\n\n* kernel: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry (CVE-2021-47069)\n\n* kernel: hwrng: core - Fix page fault dead lock on mmap-ed hwrng [rhel-8] (CVE-2023-52615)\n\n* kernel: net/mlx5e: (CVE-2023-52626, CVE-2024-35835, CVE-2023-52667, CVE-2024-35959)\n\n* kernel: drm/amdgpu: use-after-free vulnerability (CVE-2024-26656)\n\n* kernel: Bluetooth: Avoid potential use-after-free in hci_error_reset [rhel-8] (CVE-2024-26801)\n\n* kernel: Squashfs: check the inode number is not the invalid value of zero (CVE-2024-26982)\n\n* kernel: netfilter: nf_tables: use timestamp to check for set element timeout [rhel-8.10] (CVE-2024-27397)\n\n* kernel: mm/damon/vaddr-test: memory leak indamon_do_test_apply_three_regions() (CVE-2023-52560)\n\n* kernel: ppp_async: limit MRU to 64K (CVE-2024-26675)\n\n* kernel: x86/mm/swap: (CVE-2024-26759, CVE-2024-26906)\n\n* kernel: tipc: fix kernel warning when sending SYN message [rhel-8] (CVE-2023-52700)\n\n* kernel: RDMA/mlx5: Fix fortify source warning while accessing Eth segment (CVE-2024-26907)\n\n* kernel: erspan: make sure erspan_base_hdr is present in skb-> head (CVE-2024-35888)\n\n* kernel: powerpc/imc-pmu/powernv: (CVE-2023-52675, CVE-2023-52686)\n\n* kernel: KVM: SVM: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs (CVE-2023-5090)\n\n* kernel: EDAC/thunderx: Incorrect buffer size in drivers/edac/thunderx_edac.c (CVE-2023-52464)\n\n* kernel: ipv6: sr: fix possible use-after-free and null-ptr-deref (CVE-2024-26735)\n\n* kernel: mptcp: fix data re-injection from stale subflow (CVE-2024-26826)\n\n* kernel: crypto: (CVE-2024-26974, CVE-2023-52669, CVE-2023-52813)\n\n* kernel: net/mlx5/bnx2x/usb: (CVE-2024-35960, CVE-2024-35958, CVE-2021-47310, CVE-2024-26804, CVE-2021-47311, CVE-2024-26859, CVE-2021-47236, CVE-2023-52703)\n\n* kernel: i40e: Do not use WQ_MEM_RECLAIM flag for workqueue (CVE-2024-36004)\n\n* kernel: perf/core: Bail out early if the request AUX area is out of bound (CVE-2023-52835)\n\n* kernel: USB/usbnet: (CVE-2023-52781, CVE-2023-52877, CVE-2021-47495)\n\n* kernel: can: (CVE-2023-52878, CVE-2021-47456)\n\n* kernel: mISDN: fix possible use-after-free in HFC_cleanup() (CVE-2021-47356)\n\n* kernel: udf: Fix NULL pointer dereference in udf_symlink function (CVE-2021-47353)\n\nBug Fix(es):\n\n* Kernel panic - kernel BUG at mm/slub.c:376! (JIRA:Rocky Linux SIG Cloud-29783)\n\n* Temporary values in FIPS integrity test should be zeroized [rhel-8.10.z] (JIRA:Rocky Linux SIG Cloud-35361)\n\n* Rocky Linux SIG Cloud8.6 - kernel: s390/cpum_cf: make crypto counters upward compatible (JIRA:Rocky Linux SIG Cloud-36048)\n\n* [Rocky Linux SIG Cloud8] blktests block/024 failed (JIRA:Rocky Linux SIGCloud-8130)\n\n* Rocky Linux SIG Cloud8.9: EEH injections results Error: Power fault on Port 0 and other call traces(Everest/1050/Shiner) (JIRA:Rocky Linux SIG Cloud-14195)\n\n* Latency spikes with Matrox G200 graphic cards (JIRA:Rocky Linux SIG Cloud-36172)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux SIG Cloud 8"], "fixes": [{"ticket": "1918601", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=1918601", "description": ""}, {"ticket": "2248122", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2248122", "description": ""}, {"ticket": "2258875", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2258875", "description": ""}, {"ticket": "2265517", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265517", "description": ""}, {"ticket": "2265519", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265519", "description": ""}, {"ticket": "2265520", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265520", "description": ""}, {"ticket": "2265800", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265800", "description": ""}, {"ticket": "2266408", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2266408", "description": ""}, {"ticket": "2266831", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2266831", "description": ""}, {"ticket": "2267513", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2267513", "description": ""}, {"ticket": "2267518", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2267518", "description": ""}, {"ticket": "2267730", "sourceBy": "RedHat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2267730", "description": ""}, {"ticket": "2270093", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2270093", "description": ""}, {"ticket": "2271680", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2271680", "description": ""}, {"ticket": "2272692", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2272692", "description": ""}, {"ticket": "2272829", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2272829", "description": ""}, {"ticket": "2273204", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2273204", "description": ""}, {"ticket": "2273278", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2273278", "description": ""}, {"ticket": "2273423", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2273423", "description": ""}, {"ticket": "2273429", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2273429", "description": ""}, {"ticket": "2275604", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2275604", "description": ""}, {"ticket": "2275633", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2275633", "description": ""}, {"ticket": "2275635", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2275635", "description": ""}, {"ticket": "2275733", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2275733", "description": ""}, {"ticket": "2278337", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2278337", "description": ""}, {"ticket": "2278354", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2278354", "description": ""}, {"ticket": "2280434", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2280434", "description": ""}, {"ticket": "2281057", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281057", "description": ""}, {"ticket": "2281113", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281113", "description": ""}, {"ticket": "2281157", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281157", "description": ""}, {"ticket": "2281165", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281165", "description": ""}, {"ticket": "2281251", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281251", "description": ""}, {"ticket": "2281253", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281253", "description": ""}, {"ticket": "2281255", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281255", "description": ""}, {"ticket": "2281257", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281257", "description": ""}, {"ticket": "2281272", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281272", "description": ""}, {"ticket": "2281311", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281311", "description": ""}, {"ticket": "2281334", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281334", "description": ""}, {"ticket": "2281346", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281346", "description": ""}, {"ticket": "2281350", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281350", "description": ""}, {"ticket": "2281689", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281689", "description": ""}, {"ticket": "2281693", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2281693", "description": ""}, {"ticket": "2281920", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281920", "description": ""}, {"ticket": "2281923", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281923", "description": ""}, {"ticket": "2281925", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281925", "description": ""}, {"ticket": "2281953", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281953", "description": ""}, {"ticket": "2281986", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2281986", "description": ""}, {"ticket": "2282394", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282394", "description": ""}, {"ticket": "2282400", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282400", "description": ""}, {"ticket": "2282471", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282471", "description": ""}, {"ticket": "2282472", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282472", "description": ""}, {"ticket": "2282581", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282581", "description": ""}, {"ticket": "2282609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282609", "description": ""}, {"ticket": "2282612", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282612", "description": ""}, {"ticket": "2282653", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282653", "description": ""}, {"ticket": "2282680", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282680", "description": ""}, {"ticket": "2282698", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2282698", "description": ""}, {"ticket": "2282712", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282712", "description": ""}, {"ticket": "2282735", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282735", "description": ""}, {"ticket": "2282902", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282902", "description": ""}, {"ticket": "2282920", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2282920", "description": ""}], "cves": [{"name": "CVE-2020-26555", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2020-26555", "cvss3ScoringVector": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N", "cvss3BaseScore": "5.4", "cwe": "CWE-400"}, {"name": "CVE-2021-46909", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-46909", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.4", "cwe": "CWE-391"}, {"name": "CVE-2021-46972", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-46972", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "5.5", "cwe": "CWE-402"}, {"name": "CVE-2021-47069", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47069", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-362"}, {"name": "CVE-2021-47073", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47073", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "2.3", "cwe": "CWE-99"}, {"name": "CVE-2021-47236", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47236", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2021-47310", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2021-47310", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2021-47311", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47311", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2021-47353", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47353", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-476"}, {"name": "CVE-2021-47356", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47356", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "6.7", "cwe": "CWE-416"}, {"name": "CVE-2021-47456", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47456", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2021-47495", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2021-47495", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2023-5090", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5090", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H", "cvss3BaseScore": "6.0", "cwe": "CWE-755"}, {"name": "CVE-2023-52464", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52464", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L", "cvss3BaseScore": "2.9", "cwe": "CWE-805"}, {"name": "CVE-2023-52560", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52560", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "3.3", "cwe": "CWE-401"}, {"name": "CVE-2023-52615", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2023-52615", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.4", "cwe": "CWE-400"}, {"name": "CVE-2023-52626", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52626", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H", "cvss3BaseScore": "6.0", "cwe": "CWE-125"}, {"name": "CVE-2023-52667", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52667", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2023-52669", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52669", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2023-52675", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52675", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2023-52686", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52686", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2023-52700", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52700", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-20"}, {"name": "CVE-2023-52703", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52703", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "cvss3BaseScore": "3.3", "cwe": "CWE-15"}, {"name": "CVE-2023-52781", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52781", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.4", "cwe": "CWE-20"}, {"name": "CVE-2023-52813", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2023-52813", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-833"}, {"name": "CVE-2023-52835", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52835", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-125"}, {"name": "CVE-2023-52877", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52877", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.4", "cwe": "CWE-476"}, {"name": "CVE-2023-52878", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52878", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.4", "cwe": "CWE-125"}, {"name": "CVE-2023-52881", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-52881", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "UNKNOWN"}, {"name": "CVE-2024-26583", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26583", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.1", "cwe": "CWE-362-> CWE-416"}, {"name": "CVE-2024-26584", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26584", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-393"}, {"name": "CVE-2024-26585", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26585", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "CWE-362"}, {"name": "CVE-2024-26656", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26656", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.7", "cwe": "CWE-416"}, {"name": "CVE-2024-26675", "sourceBy": "MITRE","sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26675", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-20"}, {"name": "CVE-2024-26735", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26735", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-416-> CWE-476"}, {"name": "CVE-2024-26759", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26759", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-362"}, {"name": "CVE-2024-26801", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26801", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-26804", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26804", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-26826", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26826", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-20"}, {"name": "CVE-2024-26859", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26859", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "4.1", "cwe": "CWE-362"}, {"name": "CVE-2024-26906", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26906", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "CWE-20"}, {"name": "CVE-2024-26907", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26907", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "6.7", "cwe": "CWE-99"}, {"name": "CVE-2024-26974", "sourceBy":"MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26974", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H", "cvss3BaseScore": "5.8", "cwe": "UNKNOWN"}, {"name": "CVE-2024-26982", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-26982", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-27397", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-27397", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.0", "cwe": "UNKNOWN"}, {"name": "CVE-2024-27410", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-27410", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35789", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35789", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35835", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35835", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35838", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35838", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35845", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35845", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35852", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35852", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35853", "sourceBy":"MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35853", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35854", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35854", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35855", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35855", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35888", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35888", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35890", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35890", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35958", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35958", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35959", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35959", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-35960", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-35960", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-36004", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-36004", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}, {"name": "CVE-2024-36007", "sourceBy":"MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-36007", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.5", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-07-15T12:20:09.524479Z", "rpms": {"Rocky Linux SIG Cloud 8": {"nvras": ["bpftool-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "bpftool-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "bpftool-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "bpftool-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-abi-stablelists-0:4.18.0-553.8.1.el8_10.cloud.0.1.noarch.rpm", "kernel-core-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-core-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-cross-headers-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-cross-headers-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-core-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-core-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-modules-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-modules-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm","kernel-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-doc-0:4.18.0-553.8.1.el8_10.cloud.0.1.noarch.rpm", "kernel-headers-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-headers-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-modules-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-modules-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-modules-extra-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-modules-extra-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-tools-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-tools-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-tools-libs-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-tools-libs-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "kernel-tools-libs-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "kernel-tools-libs-devel-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "perf-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "perf-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "perf-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "perf-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "python3-perf-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "python3-perf-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm", "python3-perf-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.aarch64.rpm", "python3-perf-debuginfo-0:4.18.0-553.8.1.el8_10.cloud.0.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The latest update for Rocky Linux kernel addresses critical vulnerabilities and bugs, enhancing system robustness and overall stability.. Rocky Linux Kernel Update, Kernel Bug Fix, Security Advisories, System Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2024 Important Rocky Linux
197

Debian LTS: DLA-3551-1 Moderate: OTRS2 Multiple Threats Advisory

Multiple vulnerabilities were found in otrs2, the Open-Source Ticket Request System, which could lead to impersonation, denial of service, information disclosure, or execution of arbitrary code. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3551-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin August 31, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : otrs2 Version : 6.0.16-2+deb10u1 CVE ID : CVE-2019-11358 CVE-2019-12248 CVE-2019-12497 CVE-2019-12746 CVE-2019-13458 CVE-2019-16375 CVE-2019-18179 CVE-2019-18180 CVE-2020-1765 CVE-2020-1766 CVE-2020-1767 CVE-2020-1769 CVE-2020-1770 CVE-2020-1771 CVE-2020-1772 CVE-2020-1773 CVE-2020-1774 CVE-2020-1776 CVE-2020-11022 CVE-2020-11023 CVE-2021-21252 CVE-2021-21439 CVE-2021-21440 CVE-2021-21441 CVE-2021-21443 CVE-2021-36091 CVE-2021-36100 CVE-2021-41182 CVE-2021-41183 CVE-2021-41184 CVE-2022-4427 CVE-2023-38060 Debian Bug : 945251 959448 980891 989992 991593 Multiple vulnerabilities were found in otrs2, the Open-Source Ticket Request System, which could lead to impersonation, denial of service, information disclosure, or execution of arbitrary code. CVE-2019-11358 A Prototype Pollution vulnerability was discovered in OTRS' embedded jQuery 3.2.1 copy, which could allow sending drafted messages as wrong agent. This vulnerability is also known as OSA-2020-05. CVE-2019-12248 Matthias Terlinde discovered that when an attacker sends a malicious email to an OTRS system and a logged in agent user later quotes it, the email could cause the browser to load external image resources. A new configuration setting‘Ticket::Frontend::BlockLoadingRemoteContent’ has been added as part of the fix. It controls whether external content should be loaded, and it is disabled by default. This vulnerability is also known as OSA-2019-08. CVE-2019-12497 Jens Meister discovered that in the customer or external frontend, personal information of agents, like Name and mail address in external notes, could be disclosed. New configuration settings ‘Ticket::Frontend::CustomerTicketZoom###DisplayNoteFrom’ has been added as part of the fix. It controls if agent information should be displayed in external note sender field, or be substituted with a different generic name. Another option named ‘Ticket::Frontend::CustomerTicketZoom###DefaultAgentName’ can then be used to define the generic agent name used in the latter case. By default, previous behavior is preserved, in which agent information is divulged in the external note From field, for the sake of backwards compatibility. This vulnerability is also known as OSA-2019-09. CVE-2019-12746 A user logged into OTRS as an agent might unknowingly disclose their session ID by sharing the link of an embedded ticket article with third parties. This identifier can be then potentially abused in order to impersonate the agent user. This vulnerability is also known as OSA-2019-10. CVE-2019-13458 An attacker who is logged into OTRS as an agent user with appropriate permissions can leverage OTRS tags in templates in order to disclose hashed user passwords. This vulnerability is also known as OSA-2019-12. CVE-2019-16375 An attacker who is logged into OTRS as an agent or customer user with appropriate permissions can create a carefully crafted string containing malicious JavaScript code as an article body. This malicious code is executed when an agent compose an answer to the original article. This vulnerability is also known as OSA-2019-13. CVE-2019-18179 An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, which are in the queue where attacker doesn't have permissions. This vulnerability is also known as OSA-2019-14. CVE-2019-18180 OTRS can be put into an endless loop by providing filenames with overly long extensions. This applies to the PostMaster (sending in email) and also upload (attaching files to mails, for example). This vulnerability is also known as OSA-2019-15. CVE-2020-1765 Sebastian Renker and Jonas Becker discovered an improper control of parameters, which allows the spoofing of the From fields in several screens, namely AgentTicketCompose, AgentTicketForward, AgentTicketBounce and AgentTicketEmailOutbound. This vulnerability is also known as OSA-2020-01. CVE-2020-1766 Anton Astaf'ev discovered that due to improper handling of uploaded images, it is possible — in very unlikely and rare conditions — to force the agents browser to execute malicious JavaScript from a special crafted SVG file rendered as inline jpg file. This vulnerability is also known as OSA-2020-02. CVE-2020-1767 Agent A is able to save a draft (i.e., for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This vulnerability is also known as OSA-2020-03. CVE-2020-1769 Martin Møller discovered that in the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered as security issue. A new configuration setting ‘DisableLoginAutocomplete’ has been added as part of the fix. It controls whether to disable autocompletion in the login forms, by setting the autocomplete="off" attribute to the login input fields. Note that some browsers ignore it by default (usually it can be changed in the browser configuration). This vulnerability is also known as OSA-2020-06. CVE-2020-1770 Matthias Terlinde discovered that the support bundle generated files could contain sensitive information, such as user credentials. This vulnerability is also known as OSA-2020-07. CVE-2020-1771 Christoph Wuetschne discovered that an attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This vulnerability is also known as OSA-2020-08. CVE-2020-1772 Fabian Henneke discovered that it is possible to craft Lost Password requests with wildcards in the Token value, which allows an attacker to retrieve valid Token(s), generated by users which already requested new passwords. This vulnerability is also known as OSA-2020-09. CVE-2020-1773 Fabian Henneke discovered that an attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting CVE-2020-1772, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. The fix adds ‘libmath-random-secure-perl’ to otrs2's Depends:. This vulnerability is also known as OSA-2020-10. CVE-2020-1774 When a user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. It is therefore possible to mix them and to send private key to the third-party instead of public key. This vulnerability is also known as OSA-2020-11. CVE-2020-1776 When an agent user is renamed or set to invalid the session belonging to the user is keept active. The session can not be used toaccess ticket data in the case the agent is invalid. This vulnerability is also known as OSA-2020-13. CVE-2020-11022 Masato Kinugawa discovered a Potential XSS vulnerability in OTRS' embedded jQuery 3.2.1's htmlPrefilter and related methods. The fix requires patching embedded copies of fullcalendar (3.4.0), fullcalendar-scheduler (1.6.2) and spectrum (1.8.0). This vulnerability is also known as OSA-2020-14. CVE-2020-11023 Masato Kinugawa discovered a Potential XSS vulnerability in OTRS' embedded jQuery 3.2.1 copy when appending HTML containing option elements. This vulnerability is also known as OSA-2020-14. CVE-2021-21252 Erik Krogh Kristensen and Alvaro Muñoz from the GitHub Security Lab team discovered a Regular Expression Denial of Service (ReDoS) vulnerability in OTRS' embedded jQuery-validate 1.16.0 copy. CVE-2021-21439 A Denial of Service (DoS) attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This vulnerability is also known as OSA-2021-09 or ZSA-2021-03. CVE-2021-21440 Julian Droste and Mathias Terlinde discovered that the Generated Support Bundles contains private S/MIME and PGP keys when the parent directory is not hidden. Furthermore, secrets and PIN for the keys are not masked properly. This vulnerability is also known as OSA-2021-10 or ZSA-2021-08. CVE-2021-21441 There is a Cross-Site Scripting (XSS) vulnerability in the ticket overview screens. It is possible to collect various information by having an e-mail shown in the overview screen. An attack can be performed by sending specially crafted e-mail to the system, which does not require any user interaction. This vulnerability is also known as OSA-2021-11 or ZSA-2021-06. CVE-2021-21443 Agents areable to list customer user emails without required permissions in the bulk action screen. This vulnerability is also known as OSA-2021-13 or ZSA-2021-09. CVE-2021-36091 Agents are able to list appointments in the calendars without required permissions. This vulnerability is also known as OSA-2021-14 or ZSA-2021-10. CVE-2021-36100 Rayhan Ahmed and Maxime Brigaudeau discovered that a specially crafted string in the system configuration allows execution of arbitrary system command. The fix 1/ removes configurable system commands from generic agents; 2/ removes the ‘MIME-Viewer###…’ settings (the system command in SysConfig option "MIME-Viewer" is now only configurable via Kernel/Config.pm); 3/ removes dashboard widget support for execution of system commands; and 4/ deactivates support for execution of configurable system commands from Sendmail and PostMaster pre-filter configurations. This vulnerability is also known as OSA-2022-03 or ZSA-2022-02. CVE-2021-41182 Esben Sparre Andreasen discovered an XSS vulnerability in the `altField` option of the Datepicker widget in OTRS' embedded jQuery-UI 1.12.1 copy. This vulnerability is also known as ZSA-2022-01. CVE-2021-41183 Esben Sparre Andreasen discovered an XSS vulnerability in the `*Text` options of the Datepicker widget in OTRS' embedded jQuery-UI 1.12.1 copy. This vulnerability is also known as ZSA-2022-01. CVE-2021-41184 Esben Sparre Andreasen discovered an XSS vulnerability in the `of` option of the `.position()` util in OTRS' embedded jQuery-UI 1.12.1 copy. This vulnerability is also known as ZSA-2022-01. CVE-2022-4427 Tim Püttmanns discovered an SQL injection vulnerability in Kernel::System::Ticket::TicketSearch, which can be exploited using the web service operation "TicketSearch". This vulnerability is also known asZSA-2022-07. CVE-2023-38060 Tim Püttmanns discovered an Improper Input Validation vulnerability in the ContentType parameter for attachments on TicketCreate or TicketUpdate operations. For Debian 10 buster, these problems have been fixed in version 6.0.16-2+deb10u1. We recommend that you upgrade your otrs2 packages. For the detailed security status of otrs2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/otrs2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . OTRS2 on Debian LTS has vulnerabilities that may allow impersonation, denial of service, and arbitrary code execution.. OTRS2 Security Update, Debian LTS, Open-Source Ticket Request System. . LinuxSecurity.com Team

Calendar%202 Aug 31, 2023 Debian LTS
197

Debian: DLA-3493-1 Critical Advisory on Symfony Impersonation Risks

Multiple security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to information disclosure or impersonation. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3493-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin July 11, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : symfony Version : 3.4.22+dfsg-2+deb10u2 CVE ID : CVE-2021-21424 CVE-2022-24894 CVE-2022-24895 Multiple security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lead to information disclosure or impersonation. CVE-2021-21424 James Isaac, Mathias Brodala and Laurent Minguet discovered that it was possible to enumerate users without relevant permissions due to different exception messages depending on whether the user existed or not. It was also possible to enumerate users by using a timing attack, by comparing time elapsed when authenticating an existing user and authenticating a non-existing user. 403s are now returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. CVE-2022-24894 Soner Sayakci discovered that when the Symfony HTTP cache system is enabled, the response header might be stored with a `Set-Cookie` header and returned to some other clients, thereby allowing an attacker to retrieve the victim's session. The `HttpStore` constructor now takes a parameter containing a list of private headers that are removed from the HTTP response headers. The default value for this parameter is `Set-Cookie`, but it can be overridden or extended by the application. CVE-2022-24895 Marco Squarcina discoveredthat CSRF tokens aren't cleared upon login, which could enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. For Debian 10 buster, these problems have been fixed in version 3.4.22+dfsg-2+deb10u2. We recommend that you upgrade your symfony packages. For the detailed security status of symfony please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/symfony Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance symfony components to mitigate severe vulnerabilities highlighted in the Debian LTS Advisory DLA-3493-1 by Guilhem Moulin.. Debian LTS, Symfony Framework, Security Fix, PHP Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 11, 2023 Critical Debian LTS
197

Debian 10 Buster DLA-3287-1 Critical: Lemonldap-NG Info Leak Risk

Two vulnerabilities were found in lemonldap-ng, an OpenID-Connect, CAS and SAML compatible Web-SSO system, that could result in information disclosure or impersonation. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3287-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin January 28, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : lemonldap-ng Version : 2.0.2+ds-7+deb10u8 CVE ID : CVE-2020-16093 CVE-2022-37186 Two vulnerabilities were found in lemonldap-ng, an OpenID-Connect, CAS and SAML compatible Web-SSO system, that could result in information disclosure or impersonation. CVE-2020-16093 Maxime Besson discovered that LemonLDAP::NG before 2.0.9 did not check validity of the X.509 certificate by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. This update changes the default behavior to require X.509 validation against the distribution bundle /etc/ssl/certs/ca-certificates.crt. Previous behavior can reverted by running `/usr/share/lemonldap-ng/bin/lemonldap-ng-cli set ldapVerify none`. If a session backend is set to Apache::Session::LDAP or Apache::Session::Browseable::LDAP, then the complete fix involves upgrading the corresponding Apache::Session module (libapache-session-ldap-perl resp. libapache-session-browseable-perl) to 0.4-1+deb10u1 (or ≥0.5) resp. 1.3.0-1+deb10u1 (or ≥1.3.8). See related advisories DLA-3284-1 and DLA-3285-1 for details. CVE-2022-37186 Mickael Bride discovered that under certain conditions the session remained valid on handlers after being destroyed on portal. For Debian 10 buster, these problems have been fixed in version 2.0.2+ds-7+deb10u8. We recommendthat you upgrade your lemonldap-ng packages. For the detailed security status of lemonldap-ng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/lemonldap-ng Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An update for Fedora addressing security flaws in gnome-shell resolves issues leading to data exposure and identity theft threats.. Lemonldap-ng, Debian Security, OpenID Connect, Web SSO, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 28, 2023 Critical Debian LTS
203

BetaOS 5: BETA-2022-1234 Notice: GDrive Account Vulnerability

Missing SAML signature validation in the SOGo groupware could result in impersonation attacks. (CVE-2021-33054) References: - https://bugs.mageia.org/show_bug.cgi?id=29255 . MGASA-2022-0481 - Updated sogo packages fix security vulnerability Publication date: 30 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0481.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-33054 Missing SAML signature validation in the SOGo groupware could result in impersonation attacks. (CVE-2021-33054) References: - https://bugs.mageia.org/show_bug.cgi?id=29255 - https://lists.debian.org/debian-lts-announce/2021/07/msg00007.html - https://lists.debian.org/debian-security-announce/2021/msg00215.html - https://www.cve.org/CVERecord?id=CVE-2021-33054 SRPMS: - 8/core/sogo-5.6.0-1.mga8 - 8/core/sope-5.6.0-1.1.mga8 . Mageia has released enhancements to its SOGo packages, tackling the absence of signature validation which mitigates impersonation threats. Discover the details here.. Mageia Security, SOGo Update, Impersonation Risk, Signature Validation Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 30, 2022 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200