Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
217

Oracle Linux: ELSA-2023-12355 Critical Update for Istio and Kubelet

The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Cloud Native Environment Security Advisory ELSA-2023-12355 https://linux.oracle.com/errata/ELSA-2023-12355.html The following updated rpms for Oracle Linux Cloud Native Environment 1.6 have been uploaded to the Unbreakable Linux Network: x86_64: istio-1.16.4-1.el7.x86_64.rpm istio-istioctl-1.16.4-1.el7.x86_64.rpm kubelet-1.25.7-2.el7.x86_64.rpm kubectl-1.25.7-2.el7.x86_64.rpm kubeadm-1.25.7-2.el7.x86_64.rpm olcnectl-1.6.1-8.el7.x86_64.rpm olcne-agent-1.6.1-8.el7.x86_64.rpm olcne-api-server-1.6.1-8.el7.x86_64.rpm olcne-utils-1.6.1-8.el7.x86_64.rpm olcne-nginx-1.6.1-8.el7.x86_64.rpm olcne-prometheus-chart-1.6.1-8.el7.x86_64.rpm olcne-grafana-chart-1.6.1-8.el7.x86_64.rpm olcne-istio-chart-1.6.1-8.el7.x86_64.rpm olcne-olm-chart-1.6.1-8.el7.x86_64.rpm olcne-gluster-chart-1.6.1-8.el7.x86_64.rpm olcne-oci-ccm-chart-1.6.1-8.el7.x86_64.rpm olcne-metallb-chart-1.6.1-8.el7.x86_64.rpm olcne-calico-chart-1.6.1-8.el7.x86_64.rpm olcne-multus-chart-1.6.1-8.el7.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//istio-1.16.4-1.el7.src.rpm https://oss.oracle.com:443/ol7/SRPMS-updates//kubernetes-1.25.7-2.el7.src.rpm https://oss.oracle.com:443/ol7/SRPMS-updates//olcne-1.6.1-8.el7.src.rpm Related CVEs: CVE-2022-27487 CVE-2022-27488 CVE-2022-27491 CVE-2022-27492 CVE-2022-27493 CVE-2022-27496 Description of changes: istio [1.16.4-1] - Added Oracle specific files for 1.16.4-1 kubernetes [1.25.7-2] - libct/cg: add misc controller to v1 drivers (upstream runc patch) olcne [1.6.1-8] - Update Istio config to include 1.15.7 to support upgrade from 1.5.x to 1.6.x [1.6.1-7] - Bugfix:Append a slash in oci-instance-metada query url [1.6.1-6] - Fixed helm installation in OLCNE upgrade [1.6.1-5] - Deprecate oci-private-key in favour of oci-private-key-file - Updated olcne_version argument in olcnectl provision to support [1.6.1-4] - Update Istio version to 1.16.4 to addressCVE's - CVE-2022-27496 - CVE-2022-27488 - CVE-2022-27493 - CVE-2022-27492 - CVE-2022-27491 - CVE-2022-27487 [1.6.1-3] - Resolved the issue to install multiple network cards using multus [1.6.1-2] - Update kubelet for upstream runc misc cgroups patch [1.6.1-1] - Fix the bug olcnectl provision fails if ol8_developer does not exist _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Newly released rpms for Oracle Linux Cloud Native Environment tackle significant security vulnerabilities found in istio and kubelet components.. Oracle Linux Updates, Istio Security, Cloud Native Environment, Network Security, Kubernetes Enhancement. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 26, 2023 Critical Oracle
198

Arch Linux: ASA-202107-3 Critical: Istio Info Disclosure

The package istio before version 1.10.2-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202107-3 ======================================== Severity: Critical Date : 2021-07-01 CVE-ID : CVE-2021-34824 Package : istio Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-2113 Summary ====== The package istio before version 1.10.2-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 1.10.2-1. # pacman -Syu "istio> =1.10.2-1" The problem has been fixed upstream in version 1.10.2. Workaround ========= This vulnerability can be mitigated by disabling Istiod caching. Caching is disabled by setting an Istiod environment variable PILOT_ENABLE_XDS_CACHE=false. System and Istiod performance may be impacted as this disables XDS caching. Description ========== Istio before version 1.10.2 contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces. The Istio Gateway and DestinationRule can load private keys and certificates from Kubernetes secrets via the credentialName configuration. For Istio 1.8 and above, the secrets are conveyed from Istiod to gateways or workloads via the XDS API. In the above approach, a gateway or workload deployment should only be able to access credentials (TLS certificates and private keys) stored in the Kubernetes secrets within its namespace. However, a bug in Istiod permits an authorized client the ability to access and retrieve any TLS certificate and private key cached in Istiod. Impact ===== An authorized client could retrieve any TLS certificate and private key cached in Istiod outside of its ownnamespace. References ========= https://istio.io/latest/news/security/istio-security-2021-007/ https://github.com/istio/istio/commit/10674c9a86ece93dcd40efd8e4b9147bc8604460 https://github.com/istio/istio/commit/f58f789f8e0d1580d00b68b76b1132163939b9ef https://security.archlinux.org/CVE-2021-34824 . Debian Security Advisory DSA-2023-005 alerts to a high-severity privilege escalation vulnerability in kernel before 5.10.46.. Arch Linux, Istio, Information Disclosure, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 03, 2021 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here