MGAA-2026-0004 - Updated nvidia470 packages fix bug. MGAA-2026-0004 - Updated nvidia470 packages fix bug Publication date: 11 Jan 2026 URL: https://advisories.mageia.org/MGAA-2026-0004.html Type: bugfix Affected Mageia releases: 9 Description: This package provide a fixed/patched version for kernel modules built with dkms-nvidia470 under kernel 6.18.x available in backports References: - https://bugs.mageia.org/show_bug.cgi?id=34961 SRPMS: - 9/nonfree/nvidia470-470.256.02-4.mga9.nonfree . Updated nvidia470 packages for Mageia 9 resolve critical bugs in kernel modules. Get the fix now!. Mageia nvidia470 bug fix kernel module. . Severity: Informational. LinuxSecurity.com Team
ppp could be made to load arbitrary kernel modules and possibly run programs.. =========================================================================Ubuntu Security Notice USN-4451-2 August 06, 2020 ppp vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: ppp could be made to load arbitrary kernel modules and possibly run programs. Software Description: - ppp: Point-to-Point Protocol (PPP) Details: USN-4451-1 fixed a vulnerability in ppp. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: Thomas Chauchefoin discovered that ppp incorrectly handled module loading. A local attacker could use this issue to load arbitrary kernel modules and possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: ppp 2.4.5-5.1ubuntu2.3+esm2 Ubuntu 12.04 ESM: ppp 2.4.5-5ubuntu1.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4451-2 https://ubuntu.com/security/notices/USN-4451-1 CVE-2020-15704 . The Ubuntu Security Notice USN-4500-1 highlights a vulnerability in the gdm package that permits unauthorized access to system resources and potential escalation of privileges.. Ubuntu Security, ppp Update, Linux Kernel, Arbitrary Module Load, Security Notice. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for kernel modules packages ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1784-1 Rating: moderate References: #1068032 #926856 Cross-References: CVE-2017-5715 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Real Time Extension 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: The following kernel modules were rebuild with "retpoline" enablement to allow full mitigation of the Spectre Variant 2 (CVE-2017-5715, bsc#1068032) OFED was adjusted to add an entry to control the loading/unloading of cxgb4 to /etc/sysconf/infiniband (bsc#926856). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-kmps-20180611-13671=1 - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-kmps-20180611-13671=1 - SUSE Linux Enterprise Real Time Extension 11-SP4: zypper in -t patch slertesp4-kmps-20180611-13671=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-kmps-20180611-13671=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 x86_64): ofed-devel-1.5.4.1-22.3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): iscsitarget-1.4.20-0.43.2.1 iscsitarget-kmp-default-1.4.20_3.0.101_108.52-0.43.2.1 iscsitarget-kmp-trace-1.4.20_3.0.101_108.52-0.43.2.1 ofed-1.5.4.1-22.3.1 ofed-doc-1.5.4.1-22.3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 x86_64): ofed-kmp-default-1.5.4.1_3.0.101_108.52-22.3.1 ofed-kmp-trace-1.5.4.1_3.0.101_108.52-22.3.1 - SUSE Linux Enterprise Server 11-SP4 (i586 x86_64): iscsitarget-kmp-xen-1.4.20_3.0.101_108.52-0.43.2.1 - SUSE Linux Enterprise Server 11-SP4 (ppc64): iscsitarget-kmp-bigmem-1.4.20_3.0.101_108.52-0.43.2.1 iscsitarget-kmp-ppc64-1.4.20_3.0.101_108.52-0.43.2.1 ofed-kmp-bigmem-1.5.4.1_3.0.101_108.52-22.3.1 ofed-kmp-ppc64-1.5.4.1_3.0.101_108.52-22.3.1 - SUSE Linux Enterprise Server 11-SP4 (i586): iscsitarget-kmp-pae-1.4.20_3.0.101_108.52-0.43.2.1 ofed-kmp-pae-1.5.4.1_3.0.101_108.52-22.3.1 - SUSE Linux Enterprise Real Time Extension 11-SP4 (x86_64): iscsitarget-kmp-rt-1.4.20_3.0.101_rt130_69.24-0.43.2.1 iscsitarget-kmp-rt_trace-1.4.20_3.0.101_rt130_69.24-0.43.2.1 ofed-kmp-rt-1.5.4.1_3.0.101_rt130_69.24-22.3.1 ofed-kmp-rt_trace-1.5.4.1_3.0.101_rt130_69.24-22.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): iscsitarget-debuginfo-1.4.20-0.43.2.1 iscsitarget-debugsource-1.4.20-0.43.2.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 x86_64): ofed-debuginfo-1.5.4.1-22.3.1 ofed-debugsource-1.5.4.1-22.3.1 References: https://www.suse.com/security/cve/CVE-2017-5715.html https://bugzilla.suse.com/1068032 https://bugzilla.suse.com/926856 . SUSE Security Alert addresses issue in kernel module packages, designated as SUSE-SU-2023:2045-1.. kernel modules security,SUSE Linux kernel,moderate security update,SUSE package update,software vulnerability. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for kernel modules ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1502-1 Rating: moderate References: #1068032 Cross-References: CVE-2017-5715 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update provides rebuilt kernel modules for openSUSE Leap 42.3 with retpoline enablement to address Spectre Variant 2 (CVE-2017-5715 bsc#1068032). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-551=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): crash-7.1.8-8.1 crash-debuginfo-7.1.8-8.1 crash-debugsource-7.1.8-8.1 crash-devel-7.1.8-8.1 crash-doc-7.1.8-8.1 crash-eppic-7.1.8-8.1 crash-eppic-debuginfo-7.1.8-8.1 crash-gcore-7.1.8-8.1 crash-gcore-debuginfo-7.1.8-8.1 - openSUSE Leap 42.3 (noarch): ftsteutates-sensors-20160601-4.4.1 - openSUSE Leap 42.3 (x86_64): bbswitch-0.8-12.4.1 bbswitch-debugsource-0.8-12.4.1 bbswitch-kmp-default-0.8_k4.4.132_53-12.4.1 bbswitch-kmp-default-debuginfo-0.8_k4.4.132_53-12.4.1 crash-kmp-default-7.1.8_k4.4.132_53-8.1 crash-kmp-default-debuginfo-7.1.8_k4.4.132_53-8.1 ftsteutates-debugsource-20160601-4.4.1 ftsteutates-kmp-default-20160601_k4.4.132_53-4.4.1 ftsteutates-kmp-default-debuginfo-20160601_k4.4.132_53-4.4.1 hdjmod-debugsource-1.28-27.4.1 hdjmod-kmp-default-1.28_k4.4.132_53-27.4.1 hdjmod-kmp-default-debuginfo-1.28_k4.4.132_53-27.4.1 ipset-6.29-4.4.1 ipset-debuginfo-6.29-4.4.1 ipset-debugsource-6.29-4.4.1 ipset-devel-6.29-4.4.1 ipset-kmp-default-6.29_k4.4.132_53-4.4.1 ipset-kmp-default-debuginfo-6.29_k4.4.132_53-4.4.1 libipset3-6.29-4.4.1 libipset3-debuginfo-6.29-4.4.1 lttng-modules-2.7.1-6.2.1 lttng-modules-debugsource-2.7.1-6.2.1 lttng-modules-kmp-default-2.7.1_k4.4.132_53-6.2.1 lttng-modules-kmp-default-debuginfo-2.7.1_k4.4.132_53-6.2.1 ndiswrapper-1.59-3.4.1 ndiswrapper-debuginfo-1.59-3.4.1 ndiswrapper-debugsource-1.59-3.4.1 ndiswrapper-kmp-default-1.59_k4.4.132_53-3.4.1 ndiswrapper-kmp-default-debuginfo-1.59_k4.4.132_53-3.4.1 pcfclock-0.44-272.4.1 pcfclock-debuginfo-0.44-272.4.1 pcfclock-debugsource-0.44-272.4.1 pcfclock-kmp-default-0.44_k4.4.132_53-272.4.1 pcfclock-kmp-default-debuginfo-0.44_k4.4.132_53-272.4.1 sysdig-0.17.0-12.1 sysdig-debuginfo-0.17.0-12.1 sysdig-debugsource-0.17.0-12.1 sysdig-kmp-default-0.17.0_k4.4.132_53-12.1 sysdig-kmp-default-debuginfo-0.17.0_k4.4.132_53-12.1 vhba-kmp-debugsource-20161009-9.4.1 vhba-kmp-default-20161009_k4.4.132_53-9.4.1 vhba-kmp-default-debuginfo-20161009_k4.4.132_53-9.4.1 xtables-addons-2.11-4.4.1 xtables-addons-debuginfo-2.11-4.4.1 xtables-addons-debugsource-2.11-4.4.1 xtables-addons-kmp-default-2.11_k4.4.132_53-4.4.1 xtables-addons-kmp-default-debuginfo-2.11_k4.4.132_53-4.4.1 References: https://www.suse.com/security/cve/CVE-2017-5715.html https://bugzilla.suse.com/1068032 -- . Fedora Update for Kernel Packages Mitigates Meltdown and Spectre Variant 1 Issue with announcement ID FEDORA-2020:1234-1.. openSUSE Sec Update,Spectre Mitigation,Kernel Module Patch. . LinuxSecurity.com Team
An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for HA kernel modules ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1486-1 Rating: moderate References: #1068032 #936517 #962257 Cross-References: CVE-2017-5715 Affected Products: SUSE Linux Enterprise High Availability 12 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update provides rebuilds of HA kernel modules with retpoline support to mitigate Spectre Variant 2 (CVE-2017-5715 bsc#1068032) cluster fs also received these bugfixes: - backport patch to fix dlmglue false deadlock (bnc#962257) - Fix for online increase of filesystem in kernel mode fails (bsc#936517). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise High Availability 12: zypper in -t patch SUSE-SLE-HA-12-2018-1014=1 Package List: - SUSE Linux Enterprise High Availability 12 (s390x x86_64): cluster-network-kmp-default-1.4_k3.12.61_52.133-26.4.1 cluster-network-kmp-default-debuginfo-1.4_k3.12.61_52.133-26.4.1 dlm-kmp-default-4.0.2_k3.12.61_52.133-22.5.1 dlm-kmp-default-debuginfo-4.0.2_k3.12.61_52.133-22.5.1 drbd-8.4.4.7-9.11.1 drbd-debuginfo-8.4.4.7-9.11.1 drbd-debugsource-8.4.4.7-9.11.1 drbd-kmp-default-8.4.4.7_k3.12.61_52.133-9.11.1 drbd-kmp-default-debuginfo-8.4.4.7_k3.12.61_52.133-9.11.1 gfs2-kmp-default-3.1.6_k3.12.61_52.133-22.5.1 gfs2-kmp-default-debuginfo-3.1.6_k3.12.61_52.133-22.5.1 ocfs2-kmp-default-1.8.2_k3.12.61_52.133-22.5.1 ocfs2-kmp-default-debuginfo-1.8.2_k3.12.61_52.133-22.5.1 - SUSE Linux Enterprise High Availability 12 (x86_64): cluster-network-kmp-xen-1.4_k3.12.61_52.133-26.4.1 cluster-network-kmp-xen-debuginfo-1.4_k3.12.61_52.133-26.4.1 dlm-kmp-xen-4.0.2_k3.12.61_52.133-22.5.1 dlm-kmp-xen-debuginfo-4.0.2_k3.12.61_52.133-22.5.1 drbd-kmp-xen-8.4.4.7_k3.12.61_52.133-9.11.1 drbd-kmp-xen-debuginfo-8.4.4.7_k3.12.61_52.133-9.11.1 gfs2-kmp-xen-3.1.6_k3.12.61_52.133-22.5.1 gfs2-kmp-xen-debuginfo-3.1.6_k3.12.61_52.133-22.5.1 ocfs2-kmp-xen-1.8.2_k3.12.61_52.133-22.5.1 ocfs2-kmp-xen-debuginfo-1.8.2_k3.12.61_52.133-22.5.1 References: https://www.suse.com/security/cve/CVE-2017-5715.html https://bugzilla.suse.com/1068032 https://bugzilla.suse.com/936517 https://bugzilla.suse.com/962257 . Debian Security Patch: Enhancement for kernel components addresses significant concerns including Spectre vulnerabilities.. SUSE Security Update, HA Kernel, Spectre Mitigation, Linux Updates, Security Patch. . LinuxSecurity.com Team
Multiple vulnerabilities have been found in BusyBox, allowing context dependent attackers to load arbitrary kernel modules, execute arbitrary files, or cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201503-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: BusyBox: Multiple vulnerabilities Date: March 29, 2015 Bugs: #515254, #537978 ID: 201503-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in BusyBox, allowing context dependent attackers to load arbitrary kernel modules, execute arbitrary files, or cause a Denial of Service condition. Background ========= BusyBox is set of tools for embedded systems and is a replacement for GNU Coreutils. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/busybox < 1.23.1 > = 1.23.1 Description ========== Multiple vulnerabilities have been discovered in BusyBox. Please review the CVE identifiers referenced below for details. Impact ===== A context-dependent attacker can load kernel modules without privileges by nullifying enforced module prefixes. Execution of arbitrary files or a Denial of Service can be caused through the included vulnerable LZO library. Workaround ========= There is no known workaround at this time. Resolution ========= All BusyBox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/busybox-1.23.1" References ========= [1 ] CVE-2014-4607 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-4607 [ 2 ] CVE-2014-9645 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9645 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201503-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Low: openafs Bug Fix. Date: Mon, 11 Jan 2010 11:44:38 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: openafs on SL5.x i386/x86_64 Comments: To: "
Low: GFS bug-fix update. Date: Wed, 4 Feb 2009 13:49:21 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: GFS on SL3.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.