Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 25 articles for you...
89

Fedora 36: 2023-1c172e3264 Critical: Libldb & Samba Security Fixes

Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-1c172e3264 2023-04-16 02:06:21.124597 --------------------------------------------------------------------------------Name : libldb Product : Fedora 36 Version : 2.5.3 Release : 1.fc36 URL : / Summary : A schema-less, ldap like, API and database Description : An extensible library that implements an LDAP like API to access remote LDAP servers, or use local tdb databases. --------------------------------------------------------------------------------Update Information: Update to ldb 2.5.3 and samba 4.16.10 Security fixes for CVE-2023-0922, CVE-2023-0614 --------------------------------------------------------------------------------ChangeLog: * Wed Mar 29 2023 Guenther Deschner - 2.5.3-1 - Update to libldb-2.5.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #2182775 - CVE-2023-0922 samba: AD DC admin tool samba-tool sends passwords in cleartext [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182775 [ 2 ] Bug #2182777 - CVE-2023-0614 samba: Access controlled AD LDAP attributes can be discovered [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182777 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1c172e3264' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent upgrade to libldb version 2.5.3 along with samba 4.16.10 brings essential security patches addressing major vulnerabilities in Fedora 36.. Libldb Update,Fedora 36 Security,Samba Security Fixes,LDAP Access Control. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 16, 2023 Critical Fedora
89

Fedora 38: libldb Critical Samba Security Update 2023-7ac413b969 CVE-2023-0225, CVE-2023-0922, CVE-2023-0614

Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7ac413b969 2023-04-03 00:15:42.909644 --------------------------------------------------------------------------------Name : libldb Product : Fedora 38 Version : 2.7.2 Release : 1.fc38 URL : Summary : A schema-less, ldap like, API and database Description : An extensible library that implements an LDAP like API to access remote LDAP servers, or use local tdb databases. --------------------------------------------------------------------------------Update Information: Update to ldb 2.7.2 and samba 4.18.1 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614 --------------------------------------------------------------------------------ChangeLog: * Wed Mar 29 2023 Guenther Deschner - 2.7.2-1 - rhbz#2182738 - libldb-2.7.2 is available --------------------------------------------------------------------------------References: [ 1 ] Bug #2182738 - libldb-2.7.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2182738 [ 2 ] Bug #2182773 - CVE-2023-0225 samba: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182773 [ 3 ] Bug #2182775 - CVE-2023-0922 samba: AD DC admin tool samba-tool sends passwords in cleartext [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182775 [ 4 ] Bug #2182777 - CVE-2023-0614 samba: Access controlled AD LDAP attributes can be discovered [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182777 [ 5 ] Bug #2182787 - samba-4.18.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2182787 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su-c 'dnf upgrade --advisory FEDORA-2023-7ac413b969' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Upgrade libldb and samba on Fedora 38 to address crucial security vulnerabilities, enhancing your system's defenses against possible threats.. Fedora Update,Samba Security,Security Advisory,libldb Fix,Update Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 03, 2023 Critical Fedora
89

Fedora 37: FEDORA-2023-fca3bfed78 Critical Samba Access Control Fix

Update to ldb 2.6.2 and samba 4.17.7 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-fca3bfed78 2023-04-02 02:00:15.070761 --------------------------------------------------------------------------------Name : libldb Product : Fedora 37 Version : 2.6.2 Release : 1.fc37 URL : Summary : A schema-less, ldap like, API and database Description : An extensible library that implements an LDAP like API to access remote LDAP servers, or use local tdb databases. --------------------------------------------------------------------------------Update Information: Update to ldb 2.6.2 and samba 4.17.7 Security fixes for CVE-2023-0225, CVE-2023-0922, CVE-2023-0614 --------------------------------------------------------------------------------ChangeLog: * Wed Mar 29 2023 Guenther Deschner - 2.6.2-1 - Update to libldb-2.6.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2182773 - CVE-2023-0225 samba: AD DC "dnsHostname" attribute can be deleted by unprivileged authenticated users [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182773 [ 2 ] Bug #2182775 - CVE-2023-0922 samba: AD DC admin tool samba-tool sends passwords in cleartext [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182775 [ 3 ] Bug #2182777 - CVE-2023-0614 samba: Access controlled AD LDAP attributes can be discovered [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2182777 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-fca3bfed78' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 37 delivers critical updates to libldb and Samba, addressing security vulnerabilities that could lead to breaches, urging users to swiftly apply patches for safety. Fedora 37, libldb update, Samba fix, access control, security issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2023 Critical Fedora
98

Red Hat Enterprise Linux 9 RHSA-2022:8318-01 Moderate: libldb LDAP Issue

An update for libldb is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libldb security, bug fix, and enhancement update Advisory ID: RHSA-2022:8318-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8318 Issue date: 2022-11-15 CVE Names: CVE-2022-32746 ==================================================================== 1. Summary: An update for libldb is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases. The following packages have been upgraded to a later upstream version: libldb (2.5.2). (BZ#2077490) Security Fix(es): * samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request (CVE-2022-32746) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the RedHat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2077490 - Rebase libldb to the version required by Samba 2108215 - CVE-2022-32746 samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request 6. Package List: Red Hat Enterprise Linux BaseOS (v. 9): Source: libldb-2.5.2-1.el9.src.rpm aarch64: ldb-tools-2.5.2-1.el9.aarch64.rpm ldb-tools-debuginfo-2.5.2-1.el9.aarch64.rpm libldb-2.5.2-1.el9.aarch64.rpm libldb-debuginfo-2.5.2-1.el9.aarch64.rpm libldb-debugsource-2.5.2-1.el9.aarch64.rpm python3-ldb-2.5.2-1.el9.aarch64.rpm python3-ldb-debuginfo-2.5.2-1.el9.aarch64.rpm ppc64le: ldb-tools-2.5.2-1.el9.ppc64le.rpm ldb-tools-debuginfo-2.5.2-1.el9.ppc64le.rpm libldb-2.5.2-1.el9.ppc64le.rpm libldb-debuginfo-2.5.2-1.el9.ppc64le.rpm libldb-debugsource-2.5.2-1.el9.ppc64le.rpm python3-ldb-2.5.2-1.el9.ppc64le.rpm python3-ldb-debuginfo-2.5.2-1.el9.ppc64le.rpm s390x: ldb-tools-2.5.2-1.el9.s390x.rpm ldb-tools-debuginfo-2.5.2-1.el9.s390x.rpm libldb-2.5.2-1.el9.s390x.rpm libldb-debuginfo-2.5.2-1.el9.s390x.rpm libldb-debugsource-2.5.2-1.el9.s390x.rpm python3-ldb-2.5.2-1.el9.s390x.rpm python3-ldb-debuginfo-2.5.2-1.el9.s390x.rpm x86_64: ldb-tools-2.5.2-1.el9.x86_64.rpm ldb-tools-debuginfo-2.5.2-1.el9.i686.rpm ldb-tools-debuginfo-2.5.2-1.el9.x86_64.rpm libldb-2.5.2-1.el9.i686.rpm libldb-2.5.2-1.el9.x86_64.rpm libldb-debuginfo-2.5.2-1.el9.i686.rpm libldb-debuginfo-2.5.2-1.el9.x86_64.rpm libldb-debugsource-2.5.2-1.el9.i686.rpm libldb-debugsource-2.5.2-1.el9.x86_64.rpm python3-ldb-2.5.2-1.el9.i686.rpm python3-ldb-2.5.2-1.el9.x86_64.rpm python3-ldb-debuginfo-2.5.2-1.el9.i686.rpm python3-ldb-debuginfo-2.5.2-1.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v.9): aarch64: ldb-tools-debuginfo-2.5.2-1.el9.aarch64.rpm libldb-debuginfo-2.5.2-1.el9.aarch64.rpm libldb-debugsource-2.5.2-1.el9.aarch64.rpm libldb-devel-2.5.2-1.el9.aarch64.rpm python3-ldb-debuginfo-2.5.2-1.el9.aarch64.rpm ppc64le: ldb-tools-debuginfo-2.5.2-1.el9.ppc64le.rpm libldb-debuginfo-2.5.2-1.el9.ppc64le.rpm libldb-debugsource-2.5.2-1.el9.ppc64le.rpm libldb-devel-2.5.2-1.el9.ppc64le.rpm python3-ldb-debuginfo-2.5.2-1.el9.ppc64le.rpm s390x: ldb-tools-debuginfo-2.5.2-1.el9.s390x.rpm libldb-debuginfo-2.5.2-1.el9.s390x.rpm libldb-debugsource-2.5.2-1.el9.s390x.rpm libldb-devel-2.5.2-1.el9.s390x.rpm python3-ldb-debuginfo-2.5.2-1.el9.s390x.rpm x86_64: ldb-tools-debuginfo-2.5.2-1.el9.i686.rpm ldb-tools-debuginfo-2.5.2-1.el9.x86_64.rpm libldb-debuginfo-2.5.2-1.el9.i686.rpm libldb-debuginfo-2.5.2-1.el9.x86_64.rpm libldb-debugsource-2.5.2-1.el9.i686.rpm libldb-debugsource-2.5.2-1.el9.x86_64.rpm libldb-devel-2.5.2-1.el9.i686.rpm libldb-devel-2.5.2-1.el9.x86_64.rpm python3-ldb-debuginfo-2.5.2-1.el9.i686.rpm python3-ldb-debuginfo-2.5.2-1.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-32746 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY3Pgy9zjgjWX9erEAQghug/+OQBl4A3VyyHPTwY3OD4sm26TeQYULibW SWVMdbhbzAoDfhuaumy4HelsRse5qC8UvURdVG7F83r8ptyxs0C4lbMiuIXJnS0R FJ/5PsukouFHinq07rVoZcCscr1R4KpuI5Z/IuFkXuY4OeDlY35dgS77O84yoIah YYTvoCPS+4aYUYpeT/4LeGm/5iSWmwQqoozXXlw1+sF/SO7SaPXPz/Olc9dMYEc9 8q2o49EjvXtHuhV+hnGty0Lee7Y0o/8xmeLQvKAxNoNthcNDBv5quzNhJORiCzHO uP4lbsTWCXhcC2mZCrr2yMyZwcvm7f3dfneIQQ7Gnazpr0eu34m/SootVFpTxu2M X0uJP1mXiredjSP8PM4ihZBzLMK5mkCsOWHhULeLV0HbV6IVrODHzxFgSUTqOyky p7e5A3D+oICJ+qlLmc1/9qFwfShV6itAbqJt/w4QzlmQOr5ZxgXJ+tdNHK8a/o2j NrDRv8pM/4oVeztPAfJw64ZO+suYVCCGC4fTTPa8E/HITnjGcBqImgFyo9RnWMgT eBhWX41Ih6HiY5d832+ybB9dqeq4079Wm6RKBDhsqMNFsXIjR8x9kP4ZTuV3Uduv HQ8gSCIfR2hj7zXCBdfi8wqNU0064Exj33GtsTjX7MBt7gm57BMBDE0KiaYN+UTV uh1TQmB/i7E=S0qx -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Security patch for libldb on Red Hat Enterprise Linux 9 addressing moderate vulnerabilities and crucial bug resolutions for LDAP.. libldb security update, Red Hat advisory, LDAP bug fix, moderate security impact, samba vulnerability. . LinuxSecurity.com Team

Calendar%202 Nov 15, 2022 Red Hat
219

Rocky Linux 8 RLSA-2022:7730 Moderate: Libldb Security Update

Moderate: libldb security, bug fix, and enhancement update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2022:7730","synopsis":"Moderate: libldb security, bug fix, and enhancement update","severity":"SEVERITY_MODERATE","topic":"An update for libldb is now available for Rocky Linux 8.\nRocky Enterprise Software Foundation Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.","description":"The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases.\nThe following packages have been upgraded to a later upstream version: libldb (2.5.2). (BZ#2077484)\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.7 Release Notes linked from the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"2077484","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2077484","description":"Rebase libldb to the version required by Samba"},{"ticket":"2108215","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2108215","description":"CVE-2022-32746 samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request"},{"ticket":"2108998","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2108998","description":"python3-ldb-devel sub-package is missing from CRB"}],"cves":[{"name":"CVE-2022-32746","sourceBy":"RedHat","sourceLink":"https:\/\/access.redhat.com\/hydra\/rest\/securitydata\/cve\/CVE-2022-32746.json","cvss3ScoringVector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","cvss3BaseScore":"5.4","cwe":"CWE-416"}],"references":[],"publishedAt":"2022-11-13T07:54:11.979709Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}. Rocky Linux releases an updated version of libldb that includes a critical patch aimed at rectifying security vulnerabilities and functional glitches to ensure better efficiency.. Rocky Linux Security, libldb Update, LDAP Bug Fix. . LinuxSecurity.com Team

Calendar%202 Nov 13, 2022 Rocky Linux
98

Red Hat Enterprise Linux 8 RHSA-2022:7730-01 Moderate: libldb LDAP Flaw

An update for libldb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libldb security, bug fix, and enhancement update Advisory ID: RHSA-2022:7730-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7730 Issue date: 2022-11-08 CVE Names: CVE-2022-32746 ==================================================================== 1. Summary: An update for libldb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libldb packages provide an extensible library that implements an LDAP-like API to access remote LDAP servers, or use local TDB databases. The following packages have been upgraded to a later upstream version: libldb (2.5.2). (BZ#2077484) Security Fix(es): * samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request (CVE-2022-32746) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the RedHat Enterprise Linux 8.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2077484 - Rebase libldb to the version required by Samba 2108215 - CVE-2022-32746 samba: AD users can induce a use-after-free in the server process with an LDAP add or modify request 2108998 - python3-ldb-devel sub-package is missing from CRB 6. Package List: Red Hat Enterprise Linux BaseOS (v.8): Source: libldb-2.5.2-2.el8.src.rpm aarch64: ldb-tools-2.5.2-2.el8.aarch64.rpm ldb-tools-debuginfo-2.5.2-2.el8.aarch64.rpm libldb-2.5.2-2.el8.aarch64.rpm libldb-debuginfo-2.5.2-2.el8.aarch64.rpm libldb-debugsource-2.5.2-2.el8.aarch64.rpm libldb-devel-2.5.2-2.el8.aarch64.rpm python3-ldb-2.5.2-2.el8.aarch64.rpm python3-ldb-debuginfo-2.5.2-2.el8.aarch64.rpm ppc64le: ldb-tools-2.5.2-2.el8.ppc64le.rpm ldb-tools-debuginfo-2.5.2-2.el8.ppc64le.rpm libldb-2.5.2-2.el8.ppc64le.rpm libldb-debuginfo-2.5.2-2.el8.ppc64le.rpm libldb-debugsource-2.5.2-2.el8.ppc64le.rpm libldb-devel-2.5.2-2.el8.ppc64le.rpm python3-ldb-2.5.2-2.el8.ppc64le.rpm python3-ldb-debuginfo-2.5.2-2.el8.ppc64le.rpm s390x: ldb-tools-2.5.2-2.el8.s390x.rpm ldb-tools-debuginfo-2.5.2-2.el8.s390x.rpm libldb-2.5.2-2.el8.s390x.rpm libldb-debuginfo-2.5.2-2.el8.s390x.rpm libldb-debugsource-2.5.2-2.el8.s390x.rpm libldb-devel-2.5.2-2.el8.s390x.rpm python3-ldb-2.5.2-2.el8.s390x.rpm python3-ldb-debuginfo-2.5.2-2.el8.s390x.rpm x86_64: ldb-tools-2.5.2-2.el8.x86_64.rpm ldb-tools-debuginfo-2.5.2-2.el8.i686.rpm ldb-tools-debuginfo-2.5.2-2.el8.x86_64.rpm libldb-2.5.2-2.el8.i686.rpm libldb-2.5.2-2.el8.x86_64.rpm libldb-debuginfo-2.5.2-2.el8.i686.rpm libldb-debuginfo-2.5.2-2.el8.x86_64.rpm libldb-debugsource-2.5.2-2.el8.i686.rpm libldb-debugsource-2.5.2-2.el8.x86_64.rpm libldb-devel-2.5.2-2.el8.i686.rpm libldb-devel-2.5.2-2.el8.x86_64.rpm python3-ldb-2.5.2-2.el8.i686.rpm python3-ldb-2.5.2-2.el8.x86_64.rpm python3-ldb-debuginfo-2.5.2-2.el8.i686.rpm python3-ldb-debuginfo-2.5.2-2.el8.x86_64.rpm Red Hat CodeReady Linux Builder (v.8): aarch64: ldb-tools-debuginfo-2.5.2-2.el8.aarch64.rpm libldb-debuginfo-2.5.2-2.el8.aarch64.rpm libldb-debugsource-2.5.2-2.el8.aarch64.rpm python-ldb-devel-common-2.5.2-2.el8.aarch64.rpm python3-ldb-debuginfo-2.5.2-2.el8.aarch64.rpm python3-ldb-devel-2.5.2-2.el8.aarch64.rpm ppc64le: ldb-tools-debuginfo-2.5.2-2.el8.ppc64le.rpm libldb-debuginfo-2.5.2-2.el8.ppc64le.rpm libldb-debugsource-2.5.2-2.el8.ppc64le.rpm python-ldb-devel-common-2.5.2-2.el8.ppc64le.rpm python3-ldb-debuginfo-2.5.2-2.el8.ppc64le.rpm python3-ldb-devel-2.5.2-2.el8.ppc64le.rpm s390x: ldb-tools-debuginfo-2.5.2-2.el8.s390x.rpm libldb-debuginfo-2.5.2-2.el8.s390x.rpm libldb-debugsource-2.5.2-2.el8.s390x.rpm python-ldb-devel-common-2.5.2-2.el8.s390x.rpm python3-ldb-debuginfo-2.5.2-2.el8.s390x.rpm python3-ldb-devel-2.5.2-2.el8.s390x.rpm x86_64: ldb-tools-debuginfo-2.5.2-2.el8.i686.rpm ldb-tools-debuginfo-2.5.2-2.el8.x86_64.rpm libldb-debuginfo-2.5.2-2.el8.i686.rpm libldb-debuginfo-2.5.2-2.el8.x86_64.rpm libldb-debugsource-2.5.2-2.el8.i686.rpm libldb-debugsource-2.5.2-2.el8.x86_64.rpm python-ldb-devel-common-2.5.2-2.el8.i686.rpm python-ldb-devel-common-2.5.2-2.el8.x86_64.rpm python3-ldb-debuginfo-2.5.2-2.el8.i686.rpm python3-ldb-debuginfo-2.5.2-2.el8.x86_64.rpm python3-ldb-devel-2.5.2-2.el8.i686.rpm python3-ldb-devel-2.5.2-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-32746 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY2pSQNzjgjWX9erEAQiDtQ//cIMALnWIeOXkHirq8760pINVM2KwchN8 Uqi9a8UrIWP1HoHAc8Q4+v1lJPtP1t66E51MfdKhWBuG68Hxdryg/YqDkUsQrki7 P92UQ18vGXNDPjZGlhwjtW2sIcicDjfPaw+NnhaTxsvWSAvPPV/oMa5Ix+jDbVQq 78IfVhoBKXK7+JZiRkR3xWB50qWnne6CZ3z4SJFKo4622FkgEMOYFfECkBUOKb+4 HjGrnT1yj4OhLgDBxKdPx8VRqUI8zPdmrxuyxZt737P2uzoqpUtUkK9LZhTPrbrU mcTiEGXV2Nn9ai6fNsAcTLxUn2RVi/JqPNan55WKml49M5rp+A0Kc3W47mdHSdmG 4PtAlKEQh2Mwqx3MkptOI5kQ8uV0xHfFScyo0jfQS/wIWyJUR0W9kKg1hGRO1151 hpDDNch9+Hdw8v6DHJxwiomf0ze4XDXpphaYC42mL+SlVul8SAifBzXpohEGqQ8k o02KufNjZ0Prt/U2/9lmswQvqeV13Qx6Gpkclfc1h6joxqH0vA9gv1zPjcUEPatK 8SmqIRb7Rj6wVEsze9Cgx4xRGoeMe7VZoh74GE5TpepY4F2VU+YP1dCoUYhOswzq aNJVaj5HCQmRfjvMMDvMHZwqBKb72bHG7nk9HAyH9foSUTlg5Gl0/yAQiNkY62Zg zAX/oAk2JlY=URvV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical issued a critical security notification for libfoo, tackling a buffer overflow vulnerability and various enhancements.. libldb Security, Red Hat Advisory, Bug Fix, LDAP Flaw, Software Update. . LinuxSecurity.com Team

Calendar%202 Nov 08, 2022 Red Hat
89

Fedora 35: 2022-1479911a38 Moderate: Libldb Memory Leak Update

Update to version 4.15.9 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1479911a38 2022-08-14 03:00:28.871061 --------------------------------------------------------------------------------Name : libldb Product : Fedora 35 Version : 2.4.4 Release : 1.fc35 URL : Summary : A schema-less, ldap like, API and database Description : An extensible library that implements an LDAP like API to access remote LDAP servers, or use local tdb databases. --------------------------------------------------------------------------------Update Information: Update to version 4.15.9 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 29 2022 Andreas Schneider - 2.4.4-1 - Rebase to version 2.4.4 - related: rhbz#2111734 - Fix CVE-2022-32745 --------------------------------------------------------------------------------References: [ 1 ] Bug #2108196 - CVE-2022-32742 samba: server memory information leak via SMB1 https://bugzilla.redhat.com/show_bug.cgi?id=2108196 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1479911a38' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent libldb update in Fedora 35 addresses multiple vulnerabilities including critical memory handling flaws. For comprehensive insights, consult the official security advisory.. Fedora 35 Update, libldb Security, Memory Leak Fixes, Linux Security Update. . LinuxSecurity.com Team

Calendar%202 Aug 13, 2022 Fedora
89

Ubuntu 22.04: 2022-22345d4b39 Low: libfoo Security Breach

Update to version 4.16.4 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-19600c9743 2022-07-31 01:30:22.785007 --------------------------------------------------------------------------------Name : libldb Product : Fedora 36 Version : 2.5.2 Release : 1.fc36 URL : / Summary : A schema-less, ldap like, API and database Description : An extensible library that implements an LDAP like API to access remote LDAP servers, or use local tdb databases. --------------------------------------------------------------------------------Update Information: Update to version 4.16.4 to address security fixes for CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746 --------------------------------------------------------------------------------ChangeLog: * Wed Jul 27 2022 Andreas Schneider - 2.5.2-1 - Update to version 2.5.2 - related: rhbz#2111734 - Fixes CVE-2022-32746 --------------------------------------------------------------------------------References: [ 1 ] Bug #2108196 - CVE-2022-32742 samba: server memory information leak via SMB1 https://bugzilla.redhat.com/show_bug.cgi?id=2108196 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-19600c9743' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade libldb on Fedora 36 to mitigate several security vulnerabilities and maintain system integrity. Keep your system secure with the most recent patches.. Fedora Update, libldb Security, System Integrity, Security Fixes. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jul 30, 2022 Low Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200