Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-12280 http://linux.oracle.com/errata/ELSA-2025-12280.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: pki-jackson-annotations-2.19.1-1.el9_6.noarch.rpm pki-jackson-core-2.19.1-1.el9_6.noarch.rpm pki-jackson-databind-2.19.1-1.el9_6.noarch.rpm pki-jackson-jaxrs-json-provider-2.19.1-1.el9_6.noarch.rpm pki-jackson-jaxrs-providers-2.19.1-1.el9_6.noarch.rpm pki-jackson-module-jaxb-annotations-2.19.1-1.el9_6.noarch.rpm aarch64: pki-jackson-annotations-2.19.1-1.el9_6.noarch.rpm pki-jackson-core-2.19.1-1.el9_6.noarch.rpm pki-jackson-databind-2.19.1-1.el9_6.noarch.rpm pki-jackson-jaxrs-json-provider-2.19.1-1.el9_6.noarch.rpm pki-jackson-jaxrs-providers-2.19.1-1.el9_6.noarch.rpm pki-jackson-module-jaxb-annotations-2.19.1-1.el9_6.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/jackson-annotations-2.19.1-1.el9_6.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/jackson-core-2.19.1-1.el9_6.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/jackson-databind-2.19.1-1.el9_6.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/jackson-jaxrs-providers-2.19.1-1.el9_6.src.rpm http://oss.oracle.com/ol9/SRPMS-updates/jackson-modules-base-2.19.1-1.el9_6.src.rpm Related CVEs: CVE-2025-52999 Description of changes: jackson-annotations [2.19.1-1] - Update to version 2.19.1 - Resolves: RHEL-100233 jackson-core [2.19.1-1] - Update to version 2.19.1 - Resolves: RHEL-103636 jackson-databind [2.19.1-1] - Update to version 2.19.1 - Resolves: RHEL-100233 jackson-jaxrs-providers [2.19.1-1] - Update to version 2.19.1 - Resolves: RHEL-100239 jackson-modules-base [2.19.1-1] - Update to version 2.19.1 - Resolves: RHEL-100245 _______________________________________________ El-errata mailing list
An update for jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: jackson security update Advisory ID: RHSA-2023:2312-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2312 Issue date: 2023-05-09 CVE Names: CVE-2020-36518 ==================================================================== 1. Summary: An update for jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - noarch 3. Description: Jackson is a suite of data-processing tools for Java, including the flagship streaming JSON parser / generator library, matching data-binding library, and additional modules to process data encoded in various other data formats. Security Fix(es): * jackson-databind: denial of service via a large depth of nested objects (CVE-2020-36518) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update,which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2064698 - CVE-2020-36518 jackson-databind: denial of service via a large depth of nested objects 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: jackson-annotations-2.14.1-1.el9.src.rpm jackson-core-2.14.1-2.el9.src.rpm jackson-databind-2.14.1-2.el9.src.rpm jackson-jaxrs-providers-2.14.1-2.el9.src.rpm jackson-modules-base-2.14.1-2.el9.src.rpm noarch: pki-jackson-annotations-2.14.1-1.el9.noarch.rpm pki-jackson-core-2.14.1-2.el9.noarch.rpm pki-jackson-databind-2.14.1-2.el9.noarch.rpm pki-jackson-jaxrs-json-provider-2.14.1-2.el9.noarch.rpm pki-jackson-jaxrs-providers-2.14.1-2.el9.noarch.rpm pki-jackson-module-jaxb-annotations-2.14.1-2.el9.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-36518 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZFo1ONzjgjWX9erEAQhQXA//RhJAsKLGfyB+T7HQRwsWYj9OoKCzMCkc ScXoI5eI1LYKZijOPfLHj63Zp/DO+pAJLCaHdb+S+OKRddCSsHRQPw4x0tBWNPPW FBcrbxITZEbyW3WWe7BSE9/HK0ckojEJIaxmBYTsRc8zErXMmPLKGAwODWC0ohjs 8RGmfV5Cj8OzhprS0MWKrbydlv/kUzr/vayM870hRGIwg1+vE3owWYLGN8ZAwqcs 3J/N3OMheZiUk3MxPCkk92sJmpuEmGQrPPL2+I5/lXMRo4SEq3sairxkAwER10i1 kXxF8aFwgHYv5oaD06B+PuIFEQ26Clc97oMMbYBEFDYVGa5pIPNZ0dG16QPO9HLT Co0oFQ/y77HrzmM5FCUI6Zlgt8fccvc2Cg4VGG473zTAkQ0JvsZtbIjH4PVfoMp8 5Rrvk2YZJCTKdjB+7RkgnTZBQ8Xar1XwMBTQ1Zq6Z1b+ERTc8s+ihIOjD86cd+J7 TLPf/fDiy6arGI13lCa81Ssyg2iWOzySHUEag0Fs1eYKWMSoKMuSuywH7e0hjFKG +AqSml6lTxNvwGZ13ieMGslOGRFk01GR6R2BbwnDicXXhqv1O2kuaDenf9HQBteR KsTKBi7dBqdoHwGBpVb8gRxntlKQQKsKv1wpA+A2yDFu4umBxcUoZ9fT2WnI12UH cvdlmKHSc9E=W5RJ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
- Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-99ff6aa32c 2019-09-18 00:01:15.683454 --------------------------------------------------------------------------------Name : jackson-bom Product : Fedora 31 Version : 2.9.9 Release : 1.fc31 URL : https://github.com/FasterXML/jackson-bom Summary : Bill of materials POM for Jackson projects Description : A "bill of materials" POM for Jackson dependencies. --------------------------------------------------------------------------------Update Information: - Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439. --------------------------------------------------------------------------------References: [ 1 ] Bug #1737518 - CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1737518 [ 2 ] Bug #1725808 - CVE-2019-12384 jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725808 [ 3 ] Bug #1725796 - CVE-2019-12814 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725796 [ 4 ] Bug #1713469 - CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files onthe server. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1713469 [ 5 ] Bug #1752964 - CVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1752964 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-99ff6aa32c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fixes CVE-2018-14718 CVE-2018-14719 CVE-2018-19360 CVE-2018-19361 CVE-2018-19362 CVE-2018-12022 CVE-2018-12023 CVE-2018-14720 CVE-2018-14721 and CVE-2016-7051.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-df57551f6d 2019-02-19 13:59:57.021257 --------------------------------------------------------------------------------Name : jackson-datatypes-collections Product : Fedora 29 Version : 2.9.8 Release : 1.fc29 URL : https://github.com/FasterXML/jackson-datatypes-collections Summary : Jackson datatypes: collections Description : This is a multi-module umbrella project for various Jackson Data-type modules to support 3rd party Collection libraries. Currently included are: * Guava data-type * HPPC data-type * PCollections data-type --------------------------------------------------------------------------------Update Information: Fixes CVE-2018-14718 CVE-2018-14719 CVE-2018-19360 CVE-2018-19361 CVE-2018-19362 CVE-2018-12022 CVE-2018-12023 CVE-2018-14720 CVE-2018-14721 and CVE-2016-7051. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 6 2019 Mat Booth - 2.9.8-1 - Update to latest upstream release * Fri Feb 1 2019 Fedora Release Engineering - 2.9.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1555900 - jackson-datatype-jdk8: FTBFS in F28 https://bugzilla.redhat.com/show_bug.cgi?id=1555900 [ 2 ] Bug #1604397 - jackson-datatype-jdk8: FTBFS in Fedora rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1604397 [ 3 ] Bug #1671098 - CVE-2018-12022 jackson-databind: improper polymorphic deserialization of types from Jodd-db library [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1671098 [ 4 ] Bug #1666490 - CVE-2018-19362 jackson-databind: improperpolymorphic deserialization in jboss-common-core class [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666490 [ 5 ] Bug #1666486 - CVE-2018-19361 jackson-databind: improper polymorphic deserialization in openjpa class [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666486 [ 6 ] Bug #1666483 - CVE-2018-19360 jackson-databind: improper polymorphic deserialization in axis2-transport-jms class [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666483 [ 7 ] Bug #1666429 - CVE-2018-14721 jackson-databind: server-side request forgery (SSRF) in axis2-jaxws class [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666429 [ 8 ] Bug #1666424 - CVE-2018-14720 jackson-databind: exfiltration/XXE in some JDK classes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666424 [ 9 ] Bug #1666419 - CVE-2018-14719 jackson-databind: arbitrary code execution in blaze-ds-opt and blaze-ds-core classes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666419 [ 10 ] Bug #1666416 - CVE-2018-14718 jackson-databind: arbitrary code execution in slf4j-ext class [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1666416 [ 11 ] Bug #1380206 - CVE-2016-7051 jackson-dataformat-xml: XmlMapper is vulnerable to SSRF attack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1380206 [ 12 ] Bug #1672925 - bouncycastle-1.61 is available https://bugzilla.redhat.com/show_bug.cgi?id=1672925 [ 13 ] Bug #1667118 - CVE-2018-1000873 jackson-datatype-jsr310: jackson-modules-java8: DoS due to an Improper Input Validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1667118 [ 14 ] Bug #1671099 - CVE-2018-12023 jackson-databind: improper polymorphic deserialization of types from Oracle JDBC driver [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1671099 --------------------------------------------------------------------------------This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-df57551f6d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.