Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20113 http://linux.oracle.com/errata/ELSA-2025-20113.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: NetworkManager-cloud-setup-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-adsl-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-bluetooth-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-config-connectivity-oracle-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-config-server-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-dispatcher-routing-rules-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-libnm-1.40.16-18.0.3.el8_10.i686.rpm NetworkManager-libnm-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-ovs-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-ppp-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-team-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-tui-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-wifi-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-wwan-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-libnm-devel-1.40.16-18.0.3.el8_10.i686.rpm NetworkManager-libnm-devel-1.40.16-18.0.3.el8_10.x86_64.rpm NetworkManager-initscripts-updown-1.40.16-18.0.3.el8_10.noarch.rpm aarch64: NetworkManager-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-adsl-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-bluetooth-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-config-connectivity-oracle-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-config-server-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-dispatcher-routing-rules-1.40.16-18.0.3.el8_10.noarch.rpm NetworkManager-libnm-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-ovs-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-ppp-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-team-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-tui-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-wifi-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-wwan-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-libnm-devel-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-cloud-setup-1.40.16-18.0.3.el8_10.aarch64.rpm NetworkManager-initscripts-updown-1.40.16-18.0.3.el8_10.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//NetworkManager-1.40.16-18.0.3.el8_10.src.rpm Description of changes: [1:1.40.16-18.0.3] - Drop 777 permissions from Networkmanager-dispatcher drop-in directory [Orabug: 37581862] [1:1.40.16-18.0.2] - Add a dropin file to make Networkmanager-dispatcher persistent [Orabug: 36989910] _______________________________________________ El-errata mailing list
* bsc#1231353 * bsc#1232637 * bsc#1233712 Cross-References: . # Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4) Announcement ID: SUSE-SU-2025:0185-1 Release Date: 2025-01-17T22:13:28Z Rating: important References: * bsc#1231353 * bsc#1232637 * bsc#1233712 Cross-References: * CVE-2022-48956 * CVE-2024-50264 CVSS scores: * CVE-2022-48956 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48956 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-50264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_136 fixes several issues. The following security issues were fixed: * CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk-> trans (bsc#1233712). * CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-186=1 SUSE-SLE- Module-Live-Patching-15-SP4-2025-185=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-185=1 SUSE-2025-186=1 ## Package List: *SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_133-default-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-2-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_31-debugsource-2-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_133-default-debuginfo-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_136-default-2-150400.9.6.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_133-default-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_136-default-debuginfo-2-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_31-debugsource-2-150400.9.6.1 * kernel-livepatch-SLE15-SP4_Update_32-debugsource-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_133-default-debuginfo-2-150400.9.6.1 * kernel-livepatch-5_14_21-150400_24_136-default-2-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48956.html * https://www.suse.com/security/cve/CVE-2024-50264.html * https://bugzilla.suse.com/show_bug.cgi?id=1231353 * https://bugzilla.suse.com/show_bug.cgi?id=1232637 * https://bugzilla.suse.com/show_bug.cgi?id=1233712 . SUSE unveils critical kernel update tackling dual security vulnerabilities, complete with setup guidelines.. SUSE Linux Kernel, Important Security Patch, Live Patching Updates. . Severity: Important. LinuxSecurity.com Team
* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python Announcement ID: SUSE-SU-2024:0329-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-329=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-329=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python-debuginfo-2.7.18-150000.60.1 * python-idle-2.7.18-150000.60.1 * python-base-2.7.18-150000.60.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.60.1 * python-devel-2.7.18-150000.60.1 * python-tk-2.7.18-150000.60.1 * python-tk-debuginfo-2.7.18-150000.60.1 * libpython2_7-1_0-2.7.18-150000.60.1 * python-2.7.18-150000.60.1 * python-debugsource-2.7.18-150000.60.1 * python-xml-debuginfo-2.7.18-150000.60.1 * python-base-debugsource-2.7.18-150000.60.1 * python-gdbm-2.7.18-150000.60.1 *python-base-debuginfo-2.7.18-150000.60.1 * python-demo-2.7.18-150000.60.1 * python-xml-2.7.18-150000.60.1 * python-curses-2.7.18-150000.60.1 * python-gdbm-debuginfo-2.7.18-150000.60.1 * python-curses-debuginfo-2.7.18-150000.60.1 * openSUSE Leap 15.5 (x86_64) * python-base-32bit-2.7.18-150000.60.1 * libpython2_7-1_0-32bit-debuginfo-2.7.18-150000.60.1 * libpython2_7-1_0-32bit-2.7.18-150000.60.1 * python-base-32bit-debuginfo-2.7.18-150000.60.1 * python-32bit-2.7.18-150000.60.1 * python-32bit-debuginfo-2.7.18-150000.60.1 * openSUSE Leap 15.5 (noarch) * python-doc-2.7.18-150000.60.1 * python-doc-pdf-2.7.18-150000.60.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * python-debuginfo-2.7.18-150000.60.1 * python-base-2.7.18-150000.60.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.60.1 * python-devel-2.7.18-150000.60.1 * libpython2_7-1_0-2.7.18-150000.60.1 * python-2.7.18-150000.60.1 * python-debugsource-2.7.18-150000.60.1 * python-xml-debuginfo-2.7.18-150000.60.1 * python-base-debugsource-2.7.18-150000.60.1 * python-gdbm-2.7.18-150000.60.1 * python-base-debuginfo-2.7.18-150000.60.1 * python-xml-2.7.18-150000.60.1 * python-curses-2.7.18-150000.60.1 * python-gdbm-debuginfo-2.7.18-150000.60.1 * python-curses-debuginfo-2.7.18-150000.60.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . SUSE has released a security patch for Python that rectifies a problem with email parsing, classified as moderate in severity.. SUSE Linux Enterprise, Python Issue, Email Parsing, Security Update, Installation Guide. . Severity: Important. LinuxSecurity.com Team
* bsc#1212475 * bsc#1216005 Affected Products: * Containers Module 15-SP4 . # Security update for buildah Announcement ID: SUSE-SU-2023:4098-1 Rating: important References: * bsc#1212475 * bsc#1216005 Affected Products: * Containers Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has two security fixes can now be installed. ## Description: This update of buildah fixes the following issues: * rebuild the package with the go 1.21 security release (bsc#1212475). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Containers-15-SP4-2023-4098=1 ## Package List: * Containers Module 15-SP4 (aarch64 ppc64le s390x x86_64) * buildah-1.29.1-150400.3.22.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1212475 * https://bugzilla.suse.com/show_bug.cgi?id=1216005 . Ubuntu issues critical patch for podman, addressing vulnerabilities in Container Package 20.04. Update immediately!. Buildah Security Fix, SUSE Update, Containers Module, Security Advisory. . Severity: Important. LinuxSecurity.com Team
This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolves multiple CVEs: * \#1397493 - CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a98c560116 2016-12-14 17:57:21.207035 -------------------------------------------------------------------------------- Name : tomcat Product : Fedora 24 Version : 8.0.39 Release : 1.fc24 URL : https://tomcat.apache.org/ Summary : Apache Servlet/JSP Engine, RI for Servlet 3.1/JSP 2.3 API Description : Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. -------------------------------------------------------------------------------- Update Information: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolves multiple CVEs: * \#1397493 - CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397493 - CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1397493 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tomcat' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-428 2006-04-20 ---------------------------------------------------------------------Product : Fedora Core 4 Name : qt Version : 3.3.4 Release : 15.5 Summary : The shared library for the Qt GUI toolkit. Description : Qt is a GUI software toolkit which simplifies the task of writing and maintaining GUI (Graphical User Interface) applications for the X Window System. Qt is written in C++ and is fully object-oriented. This package contains the shared library needed to run qt applications, as well as the README files for qt. ---------------------------------------------------------------------* Mon Sep 26 2005 Than Ngo 1:3.3.4-15.5 - export QTINC/QTLIB, thanks to Rex Dieter (#169132) ---------------------------------------------------------------------This update can be downloaded from: b4f41a379ef87877f2b55851f8e5a50c65ceaec7 SRPMS/qt-3.3.4-15.5.src.rpm 0510f8623819c5d2679d931a7a18f235a59b91c4 ppc/qt-3.3.4-15.5.ppc.rpm 1c25b62821cce1e8ccd79d6ae7f62a081d349f80 ppc/qt-config-3.3.4-15.5.ppc.rpm 8451d7f78836e9e871620c3c73a28a6cb6be1416 ppc/qt-devel-3.3.4-15.5.ppc.rpm a6b2fd390c4481129fb83220433efe1060ff0dc3 ppc/qt-ODBC-3.3.4-15.5.ppc.rpm 220ca04d8909b61f4c923f84ea19fc6b76ad2aaa ppc/qt-MySQL-3.3.4-15.5.ppc.rpm a9795520eee6fcb701314d36163d8a41a6ba1820 ppc/qt-PostgreSQL-3.3.4-15.5.ppc.rpm 46767af6db17e5e58357a5ef3c131e057385994c ppc/qt-designer-3.3.4-15.5.ppc.rpm be5a355b13c4eb487b8c254998995c0f34a7497e ppc/debug/qt-debuginfo-3.3.4-15.5.ppc.rpm 9dc875b58a8f38e068aeeadfc238817f1fd1e203 x86_64/qt-3.3.4-15.5.x86_64.rpm 39258666044036869798d0da7aaa3e1b04ac3ce5 x86_64/qt-config-3.3.4-15.5.x86_64.rpm 9c3eaae4ba10164b914bc877d907e0169bae07b1 x86_64/qt-devel-3.3.4-15.5.x86_64.rpm c5e8aed19edfd5670ed1244cf5e22ba65f1fa4b0 x86_64/qt-ODBC-3.3.4-15.5.x86_64.rpm b0518be776461d7f71dd86339afb17a625739a80 x86_64/qt-MySQL-3.3.4-15.5.x86_64.rpm f60dddbe1af21e0430acaa16141de9ac89d748d2 x86_64/qt-PostgreSQL-3.3.4-15.5.x86_64.rpm 4850b53780ddaad80ba63c6fa3509b33a3f19437 x86_64/qt-designer-3.3.4-15.5.x86_64.rpm ca39c098dddca204dbe12e5109f9b808ed7807b7 x86_64/debug/qt-debuginfo-3.3.4-15.5.x86_64.rpm 5f80da24982e8238ad4683cdd04bc51108f9fdcf i386/qt-3.3.4-15.5.i386.rpm e5c0f424f8cf8911298d8305bfc44b385a1a378e i386/qt-config-3.3.4-15.5.i386.rpm 19b5a560d7bcb41d114bccf72411fde0c3bfce22 i386/qt-devel-3.3.4-15.5.i386.rpm 1e8e680afd83267484168fb8342619cacdb5afd9 i386/qt-ODBC-3.3.4-15.5.i386.rpm 85d23055f1206eab46e0fbd373d5498ceb54654f i386/qt-MySQL-3.3.4-15.5.i386.rpm 78f0498d5558c707310cf2c910859c1e678c6ed5 i386/qt-PostgreSQL-3.3.4-15.5.i386.rpm 3e120926f5fb2c4823b17a10db0ee000f7c0dc97 i386/qt-designer-3.3.4-15.5.i386.rpm 6618b535d04c9371327e1d212688697d3d4e9dd1 i386/debug/qt-debuginfo-3.3.4-15.5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.