Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 21 articles for you...
217

Oracle8: ELSA-2025-2686: libxml2 security Important Security Advisory Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-2686 http://linux.oracle.com/errata/ELSA-2025-2686.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libxml2-2.9.7-19.el8_10.i686.rpm libxml2-2.9.7-19.el8_10.x86_64.rpm libxml2-devel-2.9.7-19.el8_10.i686.rpm libxml2-devel-2.9.7-19.el8_10.x86_64.rpm python3-libxml2-2.9.7-19.el8_10.x86_64.rpm aarch64: libxml2-2.9.7-19.el8_10.aarch64.rpm libxml2-devel-2.9.7-19.el8_10.aarch64.rpm python3-libxml2-2.9.7-19.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//libxml2-2.9.7-19.el8_10.src.rpm Related CVEs: CVE-2024-56171 CVE-2025-24928 Description of changes: [2.9.7-19] - Fix CVE-2024-56171 (RHEL-80122) - Fix CVE-2025-24928 (RHEL-80137) [2.9.7.18.2] - Fix CVE-2022-49043 (RHEL-76289) [2.9.7-18.1] - Fix CVE-2024-25062 (RHEL-31056) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Important security updates for libxml2 in Oracle Linux 8 fix CVEs to enhance system integrity and performance.. linux, updated, oracle, unbreakable, network. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2025 Important Oracle
217

Oracle Linux 8 ELSA-2025-1736 Critical: PostgreSQL 13 Security Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1736 http://linux.oracle.com/errata/ELSA-2025-1736.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.x86_64.rpm pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.x86_64.rpm postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.x86_64.rpm postgresql-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-contrib-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-docs-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-plperl-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-plpython3-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-pltcl-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-server-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-server-devel-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-static-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-test-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-test-rpm-macros-13.20-1.module+el8.10.0+90526+050ec11b.noarch.rpm postgresql-upgrade-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm postgresql-upgrade-devel-13.20-1.module+el8.10.0+90526+050ec11b.x86_64.rpm aarch64: pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.aarch64.rpm pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.aarch64.rpm postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.aarch64.rpm postgresql-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-contrib-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-docs-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-plperl-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-plpython3-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-pltcl-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-server-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-server-devel-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-static-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-test-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-test-rpm-macros-13.20-1.module+el8.10.0+90526+050ec11b.noarch.rpm postgresql-upgrade-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm postgresql-upgrade-devel-13.20-1.module+el8.10.0+90526+050ec11b.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//pgaudit-1.5.0-1.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pg_repack-1.4.6-3.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgres-decoderbufs-0.10.0-2.module+el8.9.0+90098+1560b6c2.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgresql-13.20-1.module+el8.10.0+90526+050ec11b.src.rpm Related CVEs: CVE-2025-1094 Description of changes: pgaudit [1.5.0-1] - Update to version 1.5.0 Related: #1855776 pg_repack [1.4.6-3] - Release bump - enable gating postgres-decoderbufs [0.10.0-2] - Release bump for rebuild against libpq-12.1-3 postgresql [13.20-1] - Update to 13.20 - Fix CVE-2025-1094 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Advisory ELSA-2025-1737 provides crucial updates for postgresql, addressing significant vulnerabilities and enhancing system security.. Oracle Linux Updates, Critical PostgreSQL Fixes, RPM Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Oracle
217

Oracle Linux 8 ELSA-2025-1673: MySQL 8.0 Critical Security Fixes

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1673 http://linux.oracle.com/errata/ELSA-2025-1673.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-devel-0.996-2.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mecab-ipadic-EUCJP-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-common-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-devel-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-errmsg-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-libs-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-server-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm mysql-test-8.0.41-1.module+el8.10.0+90521+d5cc5c65.x86_64.rpm aarch64: mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-devel-0.996-2.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mecab-ipadic-EUCJP-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-common-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-devel-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-errmsg-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-libs-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-server-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm mysql-test-8.0.41-1.module+el8.10.0+90521+d5cc5c65.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//mecab-0.996-2.module+el8.10.0+90521+d5cc5c65.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//mecab-ipadic-2.7.0.20070801-17.0.1.module+el8.10.0+90521+d5cc5c65.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//mysql-8.0.41-1.module+el8.10.0+90521+d5cc5c65.src.rpm RelatedCVEs: CVE-2024-5535 CVE-2024-7264 CVE-2024-11053 CVE-2024-21193 CVE-2024-21194 CVE-2024-21196 CVE-2024-21197 CVE-2024-21198 CVE-2024-21199 CVE-2024-21201 CVE-2024-21203 CVE-2024-21212 CVE-2024-21213 CVE-2024-21218 CVE-2024-21219 CVE-2024-21230 CVE-2024-21231 CVE-2024-21236 CVE-2024-21237 CVE-2024-21238 CVE-2024-21239 CVE-2024-21241 CVE-2024-21247 CVE-2024-37371 CVE-2025-21490 CVE-2025-21491 CVE-2025-21494 CVE-2025-21497 CVE-2025-21500 CVE-2025-21501 CVE-2025-21503 CVE-2025-21504 CVE-2025-21505 CVE-2025-21518 CVE-2025-21519 CVE-2025-21520 CVE-2025-21521 CVE-2025-21522 CVE-2025-21523 CVE-2025-21525 CVE-2025-21529 CVE-2025-21531 CVE-2025-21534 CVE-2025-21536 CVE-2025-21540 CVE-2025-21543 CVE-2025-21546 CVE-2025-21555 CVE-2025-21559 Description of changes: mecab [0.996-2.12] - Bump version for 'mysql' module rebuild We are moving the 'mecab-devel' RPM from the 'buildroot' repo to the 'AppStream' repo - Resolves: #2180411 mecab-ipadic [2.7.0.20070801-17.0.1] - Rename the LICENSE.Fedora to LICENSE.oracle [2.7.0.20070801-17] - Bump the release - Resolves: RHEL-24525 mysql [8.0.41-1] - Update to MySQL 8.0.41 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux ELSA-2025-1681 provides significant patches for PostgreSQL 14.0 tackling various vulnerabilities. Discover further details.. Oracle Linux, MySQL Updates, Security Deficiencies. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2025 Critical Oracle
217

Oracle Linux 8 ELSA-2025-1372 critical: container tools security update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1372 http://linux.oracle.com/errata/ELSA-2025-1372.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.x86_64.rpm buildah-tests-1.33.12-1.module+el8.10.0+90509+b5e1e789.x86_64.rpm cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.x86_64.rpm container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.noarch.rpm crit-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-devel-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm criu-libs-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90449+0b7c8529.x86_64.rpm netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-catatonit-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-docker-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.noarch.rpm podman-gvproxy-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-plugins-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-remote-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm podman-tests-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.x86_64.rpm python3-criu-3.18-5.module+el8.10.0+90449+0b7c8529.x86_64.rpm python3-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.noarch.rpm runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.x86_64.rpm skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.x86_64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90449+0b7c8529.x86_64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.x86_64.rpm udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.noarch.rpm aarch64: aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.aarch64.rpm buildah-tests-1.33.12-1.module+el8.10.0+90509+b5e1e789.aarch64.rpm cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.aarch64.rpm container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.noarch.rpm crit-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-devel-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm criu-libs-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90449+0b7c8529.aarch64.rpm netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-catatonit-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-docker-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.noarch.rpm podman-gvproxy-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-plugins-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-remote-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm podman-tests-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.aarch64.rpm python3-criu-3.18-5.module+el8.10.0+90449+0b7c8529.aarch64.rpm python3-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.noarch.rpm runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.aarch64.rpm skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.aarch64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90449+0b7c8529.aarch64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.aarch64.rpm udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//aardvark-dns-1.10.1-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//buildah-1.33.12-1.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//cockpit-podman-84.1-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//conmon-2.1.10-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containernetworking-plugins-1.4.0-5.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containers-common-1-82.0.1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//container-selinux-2.229.0-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//criu-3.18-5.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//crun-1.14.3-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//fuse-overlayfs-1.13-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//libslirp-4.4.0-2.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//netavark-1.10.3-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//podman-4.9.4-19.0.1.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-podman-4.9.0-3.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//runc-1.1.12-6.module+el8.10.0+90509+b5e1e789.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//skopeo-1.14.5-3.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//slirp4netns-1.2.3-1.module+el8.10.0+90449+0b7c8529.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//udica-0.2.6-21.module+el8.10.0+90449+0b7c8529.src.rpm Related CVEs: CVE-2024-11218 Description of changes: aardvark-dns buildah [2:1.33.12-1] -update to the latest content of https://github.com/containers/buildah/tree/release-1.33 (https://github.com/containers/buildah/commit/58af1cd) - Resolves: RHEL-67612 cockpit-podman conmon containernetworking-plugins containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - remove references to RedHat registry (Nikita Gerasimov) container-selinux criu crun fuse-overlayfs libslirp netavark oci-seccomp-bpf-hook podman [4.9.4-19.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-19] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/bfdd4c2) - Resolves: RHEL-67601 python-podman [4.9.0-3] - sync with release-4.9 branch - Resolves: RHEL-31069 runc [1:1.1.12-6] - Add CPU affinity feature from Kir Kolishkin - Resolves: RHEL-74865 skopeo slirp4netns udica _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Announcement ELSA-2025-1391 emphasizes significant revisions for virtualization utilities. Discover the specifics today.. Oracle Linux Security Advisory, Container Tools Update, Important Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 14, 2025 Critical Oracle
217

Oracle Linux 8 ELSA-2025-0314: critical raptor2 integer underflow fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0314 http://linux.oracle.com/errata/ELSA-2025-0314.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: raptor2-2.0.15-17.el8_10.i686.rpm raptor2-2.0.15-17.el8_10.x86_64.rpm raptor2-devel-2.0.15-17.el8_10.i686.rpm raptor2-devel-2.0.15-17.el8_10.x86_64.rpm aarch64: raptor2-2.0.15-17.el8_10.aarch64.rpm raptor2-devel-2.0.15-17.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//raptor2-2.0.15-17.el8_10.src.rpm Related CVEs: CVE-2024-57823 Description of changes: [2.0.15-17] - Resolves: CVE-2024-57823 integer underflow when normalizing a URI with the turtle parser _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . CentOS RHEL ELSA-2023-0456 addresses significant vulnerability in kernel module for improved performance. Learn more for specifics.. Oracle Linux Updates, Security Advisory, Raptor2 Security, Linux RPMs, Linux Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 17, 2025 Critical Oracle
217

Oracle6: ELSA-2025-20007 critical: kernel memory leak fix

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20007 http://linux.oracle.com/errata/ELSA-2025-20007.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.93.1.el6uek.noarch.rpm kernel-uek-firmware-4.1.12-124.93.1.el6uek.noarch.rpm kernel-uek-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-devel-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-debug-4.1.12-124.93.1.el6uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.93.1.el6uek.x86_64.rpm Related CVEs: CVE-2024-26840 Description of changes: [4.1.12-124.93.1.el6uek] - cachefiles: fix memory leak in cachefiles_add_cache() (Baokun Li) [Orabug: 36544657] {CVE-2024-26840} _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The latest Oracle Linux Security Notice ELSA-2025-20008 delivers essential patches for the kernel, targeting vulnerabilities associated with resource management and system stability.. Oracle Linux, Security Advisory, Kernel Updates, Extended Lifecycle Support. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 11, 2025 Critical Oracle
217

Oracle Linux 6 ELSA-2024-12606 Important Kernel Security Advisory

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12606 http://linux.oracle.com/errata/ELSA-2024-12606.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.89.4.el6uek.noarch.rpm kernel-uek-firmware-4.1.12-124.89.4.el6uek.noarch.rpm kernel-uek-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-devel-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-debug-4.1.12-124.89.4.el6uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.89.4.el6uek.x86_64.rpm Related CVEs: CVE-2021-46939 CVE-2021-47118 CVE-2021-47153 CVE-2021-47171 CVE-2021-47236 CVE-2021-47284 CVE-2021-47310 CVE-2021-47353 CVE-2021-47356 CVE-2022-48627 CVE-2023-52445 CVE-2023-52477 CVE-2023-52574 CVE-2023-52594 CVE-2023-52615 CVE-2023-52620 CVE-2023-52628 CVE-2023-52703 CVE-2023-52809 CVE-2023-52881 CVE-2023-6040 CVE-2024-26635 CVE-2024-26651 CVE-2024-26675 CVE-2024-26679 CVE-2024-26704 CVE-2024-26772 CVE-2024-26778 CVE-2024-26801 CVE-2024-26805 CVE-2024-26816 CVE-2024-26859 CVE-2024-26880 CVE-2024-26903 CVE-2024-35922 CVE-2024-35944 CVE-2024-35978 CVE-2024-35982 CVE-2024-36016 CVE-2024-36883 CVE-2024-36919 CVE-2024-36950 CVE-2024-36960 Description of changes: [4.1.12-124.89.4.el6uek] - isdn: mISDN: netjet: Fix crash in nj_probe: (Zheyu Ma) [Orabug: 36940405] {CVE-2021-47284} - tracing: Restructure trace_clock_global() to never block (Steven Rostedt (VMware)) [Orabug: 36940388] {CVE-2021-46939} - udf: Fix NULL pointer dereference in udf_symlink function (Arturo Giusti) [Orabug: 36806640] {CVE-2021-47353} - media: pvrusb2: fix use after free on context disconnection (Ricardo B. Marliere) [Orabug: 36802294] {CVE-2023-52445} - vt: fix memory overlapping when deleting chars in the buffer (Yangxi Xiang) [Orabug: 36802212] {CVE-2022-48627} - tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (Daniel Starke) [Orabug: 36678070] {CVE-2024-36016} - netfilter: nftables: exthdr: fix 4-byte stack OOB write (Florian Westphal) [Orabug: 36654631] {CVE-2023-52628} - dm: call the resume method on internal suspend (Mikulas Patocka) [Orabug: 36544879] {CVE-2024-26880} - net/bnx2x: Prevent access to a freed page in page_pool (Thinh Tran) [Orabug: 36544783] {CVE-2024-26859} - x86, relocs: Ignore relocations in .notes section (Kees Cook) [Orabug: 36531115] {CVE-2024-26816} - netlink: Fix kernel-infoleak-after-free in __skb_datagram_iter (Ryosuke Yasuoka) [Orabug: 36531057] {CVE-2024-26805} - fbdev: savage: Error out if pixclock equals zero (Fullway Wang) [Orabug: 36530913] {CVE-2024-26778} - ext4: fix double-free of blocks due to wrong extents moved_len (Baokun Li) [Orabug: 36530519] {CVE-2024-26704} - sr9800: Add check for usbnet_get_endpoints (Chen Ni) [Orabug: 36530183] {CVE-2024-26651} - llc: Drop support for ETH_P_TR_802_2. (Kuniyuki Iwashima) [Orabug: 36530047] {CVE-2024-26635} - netfilter: nf_tables: Reject tables of unsupported family (Phil Sutter) [Orabug: 36192155] {CVE-2023-6040} [4.1.12-124.89.3.el6uek] - wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() (Minsuk Kang) [Orabug: 36802321] {CVE-2023-52594} - batman-adv: Avoid infinite loop trying to resize local TT (Sven Eckelmann) [Orabug: 36643464] {CVE-2024-35982} - Bluetooth: Fix memory leak in hci_req_sync_complete() (Dmitry Antipov) [Orabug: 36643456] {CVE-2024-35978} - VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host() (Harshit Mogalapalli) [Orabug: 36643323] {CVE-2024-35944} - fbmon: prevent division by zero in fb_videomode_from_videomode() (Roman Smirnov) [Orabug: 36643194] {CVE-2024-35922} [4.1.12-124.89.2.el6uek] - scsi: libfc: Fix potential NULL pointer dereference in fc_lport_ptp_setup() (Wenchao Hao) [Orabug: 36901390] {CVE-2023-52809} - net: usb: fix memory leak in smsc75xx_bind (Pavel Skripkin) [Orabug: 36802200] {CVE-2021-47171} - i2c: i801: Don't generate an interrupt on busreset (Jean Delvare) [Orabug: 36792714] {CVE-2021-47153} - pid: take a reference when initializing cad_pid (Mark Rutland) [Orabug: 36792687] {CVE-2021-47118} - drm/vmwgfx: Fix invalid reads in fence signaled events (Zack Rusin) [Orabug: 36691531] {CVE-2024-36960} - firewire: ohci: mask bus reset interrupts between ISR and bottom half (Adam Goldman) [Orabug: 36683507] {CVE-2024-36950} - scsi: bnx2fc: Remove spin_lock_bh while releasing resources after upload (Saurav Kashyap) [Orabug: 36683370] {CVE-2024-36919} - net: fix out-of-bounds access in ops_init (Thadeu Lima de Souza Cascardo) [Orabug: 36683115] {CVE-2024-36883} - netfilter: nf_tables: disallow timeout for anonymous sets (Pablo Neira Ayuso) [Orabug: 36654625] {CVE-2023-52620} - team: fix null-ptr-deref when team device type is changed (Ziyang Xuan) [Orabug: 36654606] {CVE-2023-52574} [4.1.12-124.89.1.el6uek] - tcp: do not accept ACK of bytes we never sent (Eric Dumazet) [Orabug: 36806731] {CVE-2023-52881} - net/usb: kalmia: Don't pass act_len in usb_bulk_msg error path (Miko Larsson) [Orabug: 36806698] {CVE-2023-52703} - hwrng: core - Fix page fault dead lock on mmap-ed hwrng (Herbert Xu) [Orabug: 36806668] {CVE-2023-52615} - mISDN: fix possible use-after-free in HFC_cleanup() (Zou Wei) [Orabug: 36806645] {CVE-2021-47356} - net: ti: fix UAF in tlan_remove_one (Pavel Skripkin) [Orabug: 36806628] {CVE-2021-47310} - net: cdc_eem: fix tx fixup skb leak (Linyu Yuan) [Orabug: 36806622] {CVE-2021-47236} - usb: hub: Guard against accesses to uninitialized BOS descriptors (Ricardo Cañuelo) [Orabug: 36802300] {CVE-2023-52477} - USB: add quirk for devices with broken LPM (Alan Stern) [Orabug: 36802300] {CVE-2023-52477} - Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security (Yuxuan Hu) [Orabug: 36544991] {CVE-2024-26903} - Bluetooth: Avoid potential use-after-free in hci_error_reset (Ying Hsu) [Orabug: 36531042] {CVE-2024-26801} - ext4: avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() (Baokun Li) [Orabug: 36530881] {CVE-2024-26772} - inet: read sk-> sk_family once in inet_recv_error() (Eric Dumazet) [Orabug: 36530348] {CVE-2024-26679} - ppp_async: limit MRU to 64K (Eric Dumazet) [Orabug: 36530335] {CVE-2024-26675} _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The updates in ELSA-2024-12607 for Oracle Linux feature essential security enhancements for the kernel along with advisory notes.. Oracle Linux Updates, Kernel Security Patches, Extended Lifecycle Support, Security Advisory Details. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 04, 2024 Important Oracle
217

Oracle8: ELSA-2024-12584 Important: Kernel-Container Security Fixes

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12584 http://linux.oracle.com/errata/ELSA-2024-12584.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-container-5.4.17-2136.334.6.el8.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.334.6.el8.x86_64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//kernel-uek-container-5.4.17-2136.334.6.el8.src.rpm Related CVEs: CVE-2024-41090 CVE-2024-41091 CVE-2024-39503 CVE-2024-40916 CVE-2024-38661 CVE-2024-39276 CVE-2024-35976 CVE-2024-36971 CVE-2024-39480 CVE-2024-39301 CVE-2024-39471 CVE-2024-39467 CVE-2024-38583 CVE-2024-36288 CVE-2024-38618 CVE-2024-33621 CVE-2024-36270 CVE-2024-38659 CVE-2024-38780 CVE-2024-36286 CVE-2024-37353 CVE-2024-39488 CVE-2024-37356 CVE-2024-39489 CVE-2024-38621 CVE-2024-39292 CVE-2024-36015 CVE-2024-38627 CVE-2024-38633 CVE-2024-38634 CVE-2024-38635 CVE-2024-38637 CVE-2024-38589 CVE-2024-36014 CVE-2024-38549 CVE-2024-38552 CVE-2024-38612 CVE-2024-38558 CVE-2024-38596 CVE-2024-38613 CVE-2024-38559 CVE-2024-38560 CVE-2024-38565 CVE-2024-38567 CVE-2024-38615 CVE-2024-38598 CVE-2024-38599 CVE-2024-38578 CVE-2024-38579 CVE-2024-38582 CVE-2024-38601 CVE-2024-36016 Description of changes: [5.4.17-2136.334.6.el8] - loop: Fix a race between loop detach and loop open (Gulam Mohamed) [Orabug: 36197800] - x86/bhi: Do not enable unnecessary BHI mitigation in OCI and Exadata VMs (Alexandre Chartre) [Orabug: 36672495] - x86/bhi: Avoid warning in #DB handler due to BHI mitigation (Alexandre Chartre) [Orabug: 36642472] - wifi: wilc1000: fix ies_len type in connect path (Jozef Hopko) - net/mlx5e: drop shorter ethernet frames (Manjunath Patil) [Orabug: 36879157] {CVE-2024-41090} {CVE-2024-41091} [5.4.17-2136.334.5.el8] - Fix incorrect syntax in UEK6 OL8 kernel-uek.spec (Sherry Yang) [Orabug: 36847358] - rds/ib: decrement ib_rx_total_incs after releasing associated cache(Arumugam Kolappan) [Orabug: 36722026] [5.4.17-2136.334.4.el8] - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ (Luiz Augusto von Dentz) - netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type (Jozsef Kadlecsik) - drm/exynos: hdmi: report safe 640x480 mode as a fallback when no EDID found (Marek Szyprowski) [5.4.17-2136.334.3.el8] - rds/rdma: Send info to userspace, even if connnection is down. (Juan Garcia) [Orabug: 36529562] - pci: add hotplug patch support for SOLIDIGM Aura10 AIC 0x025e:0x0b60 (Alan Adamson) [Orabug: 36762919] [5.4.17-2136.334.2.el8] - LTS tag: v5.4.278 (Alok Tiwari) - x86/tsc: Trust initial offset in architectural TSC-adjust MSRs (Daniel J Blueman) - io_uring: fail NOP if non-zero op flags is passed in (Ming Lei) - nfs: fix undefined behavior in nfs_block_bits() (Sergey Shtylyov) - s390/ap: Fix crash in AP internal function modify_bitmap() (Harald Freudenberger) - ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() (Baokun Li) - sparc: move struct termio to asm/termios.h (Mike Gilbert) - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING (Eric Dumazet) - net: fix __dst_negative_advice() race (Eric Dumazet) - kdb: Use format-specifiers rather than memset() for padding in kdb_read() (Daniel Thompson) - kdb: Merge identical case statements in kdb_read() (Daniel Thompson) - kdb: Fix console handling when editing and tab-completing commands (Daniel Thompson) - kdb: Use format-strings rather than '\0' injection in kdb_read() (Daniel Thompson) - kdb: Fix buffer overflow during tab-complete (Daniel Thompson) - sparc64: Fix number of online CPUs (Sam Ravnborg) - intel_th: pci: Add Meteor Lake-S CPU support (Alexander Shishkin) - net/9p: fix uninit-value in p9_client_rpc() (Nikita Zhandarovich) - net/ipv6: Fix route deleting failure when metric equals 0 (xu xin) - crypto: ecrdsa - Fix module auto-load on add_key (Vitaly Chikunov) - KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode (Marc Zyngier) - media:v4l2-core: hold videodev_lock until dev reg, finishes (Hans Verkuil) - media: mxl5xx: Move xpt structures off stack (Nathan Chancellor) - media: mc: mark the media devnode as registered from the, start (Hans Verkuil) - arm64: dts: hi3798cv200: fix the size of GICR (Yang Xiwen) - wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU (Bitterblue Smith) - arm64: tegra: Correct Tegra132 I2C alias (Krzysztof Kozlowski) - ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx (Christoffer Sandberg) - ata: pata_legacy: make legacy_exit() work again (Sergey Shtylyov) - drm/amdgpu: add error handle to avoid out-of-bounds (Bob Zhou) - media: lgdt3306a: Add a check against null-pointer-def (Zheyu Ma) - f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() (Chao Yu) - x86/mm: Remove broken vsyscall emulation code from the page fault code (Linus Torvalds) - nilfs2: fix use-after-free of timer for log writer thread (Ryusuke Konishi) - afs: Don't cross .backup mountpoint from backup volume (Marc Dionne) - mmc: core: Do not force a retune before RPMB switch (Jorge Ramirez-Ortiz) - binder: fix max_thread type inconsistency (Carlos Llamas) - SUNRPC: Fix loop termination condition in gss_free_in_token_pages() (Chuck Lever) - ALSA: timer: Set lower bound of start tick time (Takashi Iwai) - ipvlan: Dont Use skb-> sk in ipvlan_process_v{4,6}_outbound (Yue Haibing) - spi: stm32: Don't warn about spurious interrupts (Uwe Kleine-König) - kconfig: fix comparison to constant symbols, 'm', 'n' (Masahiro Yamada) - netfilter: tproxy: bail out if IP has been disabled on the device (Florian Westphal) - net:fec: Add fec_enet_deinit() (Xiaolei Wang) - net: usb: smsc95xx: fix changing LED_SEL bit value updated from EEPROM (Parthiban Veerasooran) - smsc95xx: use usbnet-> driver_priv (Andre Edich) - smsc95xx: remove redundant function arguments (Andre Edich) - enic: Validate length of nl attributes in enic_set_vf_port (Roded Zats) - dma-buf/sw-sync: don't enable IRQ from sync_print_obj() (Tetsuo Handa) - net/mlx5e: Userx_missed_errors instead of rx_dropped for reporting buffer exhaustion (Carolina Jubran) - nvmet: fix ns enable/disable possible hang (Sagi Grimberg) - spi: Don't mark message DMA mapped when no transfer in it is (Andy Shevchenko) - netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() (Eric Dumazet) - net: fec: avoid lock evasion when reading pps_enable (Wei Fang) - virtio: delete vq in vp_find_vqs_msix() when request_irq() fails (Jiri Pirko) - arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY (Jiangfeng Xiao) - openvswitch: Set the skbuff pkt_type for proper pmtud support. (Aaron Conole) - tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). (Kuniyuki Iwashima) - params: lift param_set_uint_minmax to common code (Sagi Grimberg) - ipv6: sr: fix memleak in seg6_hmac_init_algo (Hangbin Liu) - sunrpc: fix NFSACL RPC retry on soft mount (Dan Aloni) - x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y (Masahiro Yamada) - null_blk: Fix the WARNING: modpost: missing MODULE_DESCRIPTION() (Zhu Yanjun) - media: cec: cec-api: add locking in cec_release() (Hans Verkuil) - media: cec: cec-adap: always cancel work in cec_transmit_msg_fh (Hans Verkuil) - um: Fix the -Wmissing-prototypes warning for __switch_mm (Tiwei Bie) - powerpc/pseries: Add failure related checks for h_get_mpp and h_get_ppp (Shrikanth Hegde) - scsi: qla2xxx: Replace all non-returning strlcpy() with strscpy() (Azeem Shaikh) - media: stk1160: fix bounds checking in stk1160_copy_video() (Dan Carpenter) - um: Add winch to winch_handlers before registering winch IRQ (Roberto Sassu) - um: Fix return value in ubd_init() (Duoming Zhou) - drm/msm/dpu: Always flush the slave INTF on the CTL (Marijn Suijten) - Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation (Fenglin Wu) - Input: ims-pcu - fix printf string overflow (Arnd Bergmann) - libsubcmd: Fix parse-options memory leak (Ian Rogers) - serial: sh-sci: protect invalidating RXDMA on shutdown (Wolfram Sang) - f2fs: fix to release node block countin error path of f2fs_new_node_page() (Chao Yu) - extcon: max8997: select IRQ_DOMAIN instead of depending on it (Randy Dunlap) - ppdev: Add an error check in register_device (Huai-Yuan Liu) - ppdev: Remove usage of the deprecated ida_simple_xx() API (Christophe JAILLET) - stm class: Fix a double free in stm_register_device() (Dan Carpenter) - usb: gadget: u_audio: Clear uac pointer when freed. (Chris Wulff) - microblaze: Remove early printk call from cpuinfo-static.c (Michal Simek) - microblaze: Remove gcc flag for non existing early_printk.c file (Michal Simek) - iio: pressure: dps310: support negative temperature values (Thomas Haemmerle) - greybus: arche-ctrl: move device table to its right location (Arnd Bergmann) - serial: max3100: Fix bitwise types (Andy Shevchenko) - serial: max3100: Update uart_driver_registered on driver removal (Andy Shevchenko) - serial: max3100: Lock port-> lock when calling uart_handle_cts_change() (Andy Shevchenko) - firmware: dmi-id: add a release callback function (Arnd Bergmann) - dmaengine: idma64: Add check for dma_set_max_seg_size (Chen Ni) - soundwire: cadence: fix invalid PDI offset (Pierre-Louis Bossart) - soundwire: cadence_master: improve PDI allocation (Bard Liao) - soundwire: intel: don't filter out PDI0/1 (Pierre-Louis Bossart) - soundwire: cadence/intel: simplify PDI/port mapping (Pierre-Louis Bossart) - greybus: lights: check return of get_channel_from_mode (Rui Miguel Silva) - sched/fair: Allow disabling sched_balance_newidle with sched_relax_domain_level (Vitalii Bursov) - af_packet: do not call packet_read_pending() from tpacket_destruct_skb() (Eric Dumazet) - netrom: fix possible dead-lock in nr_rt_ioctl() (Eric Dumazet) - RDMA/IPoIB: Fix format truncation compilation errors (Leon Romanovsky) - selftests/kcmp: remove unused open mode (Edward Liaw) - selftests/kcmp: Make the test output consistent and clear (Gautam Menghani) - SUNRPC: Fix gss_free_in_token_pages() (Chuck Lever) - sunrpc: removed redundant procp check (Aleksandr Aprelkov) - ext4: avoid excessivecredit estimate in ext4_tmpfile() (Jan Kara) - x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map (Adrian Hunter) - RDMA/hns: Use complete parentheses in macros (Chengchang Tang) - drm/panel: simple: Add missing Innolux G121X1-L03 format, flags, connector (Marek Vasut) - ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value (Steven Rostedt) - drm/arm/malidp: fix a possible null pointer dereference (Huai-Yuan Liu) - fbdev: sh7760fb: allow modular build (Randy Dunlap) - platform/x86: wmi: Make two functions static (YueHaibing) - media: radio-shark2: Avoid led_names truncations (Ricardo Ribalda) - media: ngene: Add dvb_ca_en50221_init return value check (Aleksandr Burakov) - fbdev: sisfb: hide unused variables (Arnd Bergmann) - powerpc/fsl-soc: hide unused const variable (Arnd Bergmann) - drm/mediatek: Add 0 size check to mtk_drm_gem_obj (Justin Green) - fbdev: shmobile: fix snprintf truncation (Arnd Bergmann) - mtd: rawnand: hynix: fixed typo (Maxim Korotkov) - drm/amd/display: Fix potential index out of bounds in color transformation function (Srinivasan Shanmugam) - ipv6: sr: fix invalid unregister error path (Hangbin Liu) - ipv6: sr: add missing seg6_local_exit (Hangbin Liu) - net: openvswitch: fix overwriting ct original tuple for ICMPv6 (Ilya Maximets) - net: usb: smsc95xx: stop lying about skb-> truesize (Eric Dumazet) - af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg (Breno Leitao) - net: ethernet: cortina: Locking fixes (Linus Walleij) - m68k: mac: Fix reboot hang on Mac IIci (Finn Thain) - m68k: Fix spinlock race in kernel thread creation (Michael Schmitz) - net: usb: sr9700: stop lying about skb-> truesize (Eric Dumazet) - usb: aqc111: stop lying about skb-> truesize (Eric Dumazet) - wifi: mwl8k: initialize cmd-> addr[] properly (Dan Carpenter) - scsi: qedf: Ensure the copied buf is NUL terminated (Bui Quang Minh) - scsi: bfa: Ensure the copied buf is NUL terminated (Bui Quang Minh) - HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors (Chen Ni) - Revert "sh:Handle calling csum_partial with misaligned data" (Guenter Roeck) - sh: kprobes: Merge arch_copy_kprobe() into arch_prepare_kprobe() (Geert Uytterhoeven) - wifi: ar5523: enable proper endpoint verification (Nikita Zhandarovich) - wifi: carl9170: add a proper sanity check for endpoints (Nikita Zhandarovich) - macintosh/via-macii: Fix "BUG: sleeping function called from invalid context" (Finn Thain) - tcp: avoid premature drops in tcp_add_backlog() (Eric Dumazet) - tcp: fix a signed-integer-overflow bug in tcp_add_backlog() (Lu Wei) - tcp: minor optimization in tcp_add_backlog() (Eric Dumazet) - wifi: ath10k: populate board data for WCN3990 (Dmitry Baryshkov) - wifi: ath10k: Fix an error code problem in ath10k_dbg_sta_write_peer_debug_trigger() (Su Hui) - x86/purgatory: Switch to the position-independent small code model (Ard Biesheuvel) - scsi: hpsa: Fix allocation size for Scsi_Host private data (Yuri Karpov) - scsi: libsas: Fix the failure of adding phy with zero-address to port (Xingui Yang) - cpufreq: exit() callback is optional (Viresh Kumar) - cpufreq: Rearrange locking in cpufreq_remove_dev() (Rafael J. Wysocki) - cpufreq: Split cpufreq_offline() (Rafael J. Wysocki) - cpufreq: Reorganize checks in cpufreq_offline() (Rafael J. Wysocki) - ACPI: disable -Wstringop-truncation (Arnd Bergmann) - irqchip/alpine-msi: Fix off-by-one in allocation error path (Zenghui Yu) - scsi: ufs: core: Perform read back after disabling UIC_COMMAND_COMPL (Andrew Halaney) - scsi: ufs: core: Perform read back after disabling interrupts (Andrew Halaney) - scsi: ufs: cdns-pltfrm: Perform read back after writing HCLKDIV (Andrew Halaney) - scsi: ufs: qcom: Perform read back after writing reset bit (Andrew Halaney) - qed: avoid truncating work queue length (Arnd Bergmann) - wifi: ath10k: poll service ready message before failing (Baochen Qiang) - md: fix resync softlockup when bitmap size is less than array size (Yu Kuai) - null_blk: Fix missing mutex_destroy() at module removal (Zhu Yanjun) - jffs2: prevent xattr node from overflowingthe eraseblock (Ilya Denisyev) - s390/cio: fix tracepoint subchannel type field (Peter Oberparleiter) - crypto: ccp - drop platform ifdef checks (Arnd Bergmann) - parisc: add missing export of __cmpxchg_u8() (Al Viro) - nilfs2: fix out-of-range warning (Arnd Bergmann) - ecryptfs: Fix buffer size for tag 66 packet (Brian Kubisiak) - firmware: raspberrypi: Use correct device for DMA mappings (Laurent Pinchart) - crypto: bcm - Fix pointer arithmetic (Aleksandr Mishin) - openpromfs: finish conversion to the new mount API (Eric Sandeen) - nvme: find numa distance only if controller has valid numa id (Nilay Shroff) - drm/amdkfd: Flush the process wq before creating a kfd_process (Lancelot SIX) - ASoC: da7219-aad: fix usage of device_get_named_child_node() (Pierre-Louis Bossart) - ASoC: dt-bindings: rt5645: add cbj sleeve gpio property (Derek Fang) - ASoC: rt5645: Fix the electric noise due to the CBJ contacts floating (Derek Fang) - drm/amd/display: Set color_mgmt_changed to true on unsuspend (Joshua Ashton) - net: usb: qmi_wwan: add Telit FN920C04 compositions (Daniele Palmas) - wifi: cfg80211: fix the order of arguments for trace events of the tx_rx_evt class (Igor Artemiev) - nilfs2: fix potential hang in nilfs_detach_log_writer() (Ryusuke Konishi) - nilfs2: fix unexpected freezing of nilfs_segctor_sync() (Ryusuke Konishi) - net: smc91x: Fix m68k kernel compilation for ColdFire CPU (Thorsten Blum) - ring-buffer: Fix a race between readers and resize checks (Petr Pavlu) - tty: n_gsm: fix possible out-of-bounds in gsm0_receive() (Daniel Starke) [5.4.17-2136.334.1.el8] - rds/rdma: Track rds_message in send, retrans and recv queue (Juan Garcia) [Orabug: 36529583] - xfs: make sure sb_fdblocks is non-negative (Wengang Wang) [Orabug: 36596998] - xfs: fix sb write verify for lazysbcount (Long Li) [Orabug: 36596998] - rds/rdma: Clear rds_info_socket before use (Juan Garcia) [Orabug: 36613125] _______________________________________________ El-errata mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The recent advisory from Oracle Linux, identified as ELSA-2024-12584, delivers significant updates to kernel-container components, enhancing security measures.. Oracle Linux Security Advisory, Kernel Updates, Security Patches, Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 13, 2024 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200