Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 44 articles for you...
100

SUSE: 2023:5123-1 important: system package vulnerability patch

The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:4097-1 Container Tags : suse/sle-micro/5.5/toolbox:12.1 , suse/sle-micro/5.5/toolbox:12.1-2.2.117 , suse/sle-micro/5.5/toolbox:latest Container Release : 2.2.117 Severity : moderate Type : security References : 1216862 1217212 1217573 1217574 CVE-2023-46218 CVE-2023-46219 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4659-1 Released: Wed Dec 6 13:04:57 2023 Summary: Security update for curl Type: security Severity: moderate References: 1217573,1217574,CVE-2023-46218,CVE-2023-46219 This update for curl fixes the following issues: - CVE-2023-46218: Fixed cookie mixed case PSL bypass (bsc#1217573). - CVE-2023-46219: HSTS long file name clears contents (bsc#1217574). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4699-1 Released: Mon Dec 11 07:02:10 2023 Summary: Recommended update for gpg2 Type: recommended Severity: moderate References: 1217212 This update for gpg2 fixes the following issues: - `dirmngr-client --validate` is broken for DER-encoded files (bsc#1217212) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4723-1 Released: Tue Dec 12 09:57:51 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1216862 This update for libtirpc fixes the following issue: - fix sed parsing in specfile (bsc#1216862) The following package changes have been done: - gpg2-2.2.27-150300.3.8.1updated - libcurl4-8.0.1-150400.5.36.1 updated - libp11-kit0-0.23.22-150500.8.3.1 updated - libtirpc-netconfig-1.3.4-150300.3.23.1 updated - libtirpc3-1.3.4-150300.3.23.1 updated - system-group-hardware-20170617-150400.24.2.1 updated - container:sles15-image-15.0.0-36.5.63 updated . Important notice on critical security vulnerabilities in SUSE Container image suse/sle-micro/5.5. Review and update your deployments promptly for security. SUSE Container Update, security patches, CURL Fix, Toolbox SLE Micro. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 13, 2023 Important SuSE
100

SUSE 5.1 Toolbox: 2023:3683-1 Important Security Update

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.1/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3683-1 Container Tags : suse/sle-micro/5.1/toolbox:12.1 , suse/sle-micro/5.1/toolbox:12.1-2.2.487 , suse/sle-micro/5.1/toolbox:latest Container Release : 2.2.487 Severity : important Type : security References : 1196647 1206480 1206684 1210557 1211427 1212101 1213915 1214052 1214460 1215215 1216123 1216174 1216378 CVE-2023-4039 CVE-2023-44487 CVE-2023-45853 ----------------------------------------------------------------- The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4162-1 Released: Mon Oct 23 15:33:03 2023 Summary: Security update for gcc13 Type: security Severity: important References: 1206480,1206684,1210557,1211427,1212101,1213915,1214052,1214460,CVE-2023-4039 This update for gcc13 fixes the following issues: This update ship the GCC 13.2 compiler suite and its base libraries. The compiler base libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 12 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP4 and SP5, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc13 compilers use: - install 'gcc13' or 'gcc13-c++' or one of the other 'gcc13-COMPILER' frontend packages. - override your Makefile to use CC=gcc13, CXX=g++13 and similar overrides for the other languages. For a full changelog with all new GCC13 features, check out https://gcc.gnu.org/gcc-13/changes.html Detailed changes: * CVE-2023-4039: Fixed -fstack-protector issues on aarch64 with variable length stack allocations. (bsc#1214052) - Turn cross compiler to s390x to a glibc cross. [bsc#1214460] - Also handle -static-pie in the default-PIE specs - Fixed missed optimization in Skia resulting in Firefox crashes when building with LTO. [bsc#1212101] - Make libstdc++6-devel packages own their directories since they can be installed standalone. [bsc#1211427] - Add new x86-related intrinsics (amxcomplexintrin.h). - RISC-V: Add support for inlining subword atomic operations - Use --enable-link-serialization rather that --enable-link-mutex, the benefit of the former one is that the linker jobs are not holding tokens of the make's jobserver. - Add cross-bpf packages. See https://gcc.gnu.org/wiki/BPFBackEnd for the general state of BPF with GCC. - Add bootstrap conditional to allow --without=bootstrap to be specified to speed up local builds for testing. - Bump included newlib to version 4.3.0. - Also package libhwasan_preinit.o on aarch64. - Configure external timezone database provided by the timezone package. Make libstdc++6 recommend timezone to get a fully working std::chrono. Install timezone when running the testsuite. - Package libhwasan_preinit.o on x86_64. - Fixed unwinding on aarch64 with pointer signing. [bsc#1206684] - Enable PRU flavour for gcc13 - update floatn fixinclude pickup to check each header separately (bsc#1206480) - Redo floatn fixinclude pick-up to simply keep what is there. - Bump libgo SONAME to libgo22. - Do not package libhwasan for biarch (32-bit architecture) as the extension depends on 64-bit pointers. - Adjust floatn fixincludes guard to work with SLE12 and earlier SLE15. - Depend on at least LLVM 13 for GCN cross compiler. - Update embedded newlib to version 4.2.0 - Allow cross-pru-gcc12-bootstrap for armv7l architecture. PRU architecture is used for real-time MCUs embedded into TI armv7l and aarch64 SoCs. Weneed to have cross-pru-gcc12 for armv7l in order to build both host applications and PRU firmware during the same build. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4200-1 Released: Wed Oct 25 12:04:29 2023 Summary: Security update for nghttp2 Type: security Severity: important References: 1216123,1216174,CVE-2023-44487 This update for nghttp2 fixes the following issues: - CVE-2023-44487: Fixed HTTP/2 Rapid Reset attack. (bsc#1216174) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4217-1 Released: Thu Oct 26 12:20:27 2023 Summary: Security update for zlib Type: security Severity: moderate References: 1216378,CVE-2023-45853 This update for zlib fixes the following issues: - CVE-2023-45853: Fixed an integer overflow that would lead to a buffer overflow in the minizip subcomponent (bsc#1216378). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4226-1 Released: Fri Oct 27 11:14:10 2023 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1215215 This update for openssl-1_1 fixes the following issues: - Displays 'fips' in the version string (bsc#1215215) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4310-1 Released: Tue Oct 31 14:10:47 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1196647 This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467) * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessarysleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage Update to 1.3.3: * Fix DoS vulnerability in libtirpc - replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch * _rpc_dtablesize: use portable system call * libtirpc: Fix use-after-free accessing the error number * Fix potential memory leak of parms.r_addr - replaces 0001-fix-parms.r_addr-memory-leak.patch * rpcb_clnt.c add mechanism to try v2 protocol first - preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch * Eliminate deadlocks in connects with an MT environment * clnt_dg_freeres() uncleared set active state may deadlock * thread safe clnt destruction * SUNRPC: mutexed access blacklist_read state variable * SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c Update to 1.3.2: * Replace the final SunRPC licenses with BSD licenses * blacklist: Add a few more well known ports * libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS Update to 1.3.1: * Remove AUTH_DES interfaces from auth_des.h The unsupported AUTH_DES authentication has be compiled out since commit d918e41d889 (Wed Oct 9 2019) replaced by API routines that return errors. * svc_dg: Free xp_netid during destroy * Fix memory management issues of fd locks * libtirpc: replace array with list for per-fd locks * __svc_vc_dodestroy: fix double free of xp_ltaddr.buf * __rpc_dtbsize: rlim_cur instead of rlim_max * pkg-config: use the correct replacements for libdir/includedir The following package changes have been done: - libgcc_s1-13.2.1+git7813-150000.1.3.3 updated - libnghttp2-14-1.40.0-150200.12.1 updated - libopenssl1_1-hmac-1.1.1d-150200.11.79.1 updated - libopenssl1_1-1.1.1d-150200.11.79.1 updated - libstdc++6-13.2.1+git7813-150000.1.3.3 updated - libtirpc-netconfig-1.3.4-150300.3.20.1 updated - libtirpc3-1.3.4-150300.3.20.1 updated - libz1-1.2.11-150000.3.48.1 updated - openssl-1_1-1.1.1d-150200.11.79.1 updated - container:sles15-image-15.0.0-17.20.207 updated .SUSE container update advisory for toolbox includes essential security updates addressing critical issues.. SUSE Toolbox Update,GCC Security Fix,Container Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 02, 2023 Important SuSE
100

SUSE: 2023:3677-1 Important: container-suseconnect Security Fix

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3677-1 Container Tags : bci/bci-base:15.5 , bci/bci-base:15.5.36.5.52 , suse/sle15:15.5 , suse/sle15:15.5.36.5.52 Container Release : 36.5.52 Severity : important Type : security References : 1196647 1212475 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4309-1 Released: Tue Oct 31 14:09:03 2023 Summary: Security update for container-suseconnect Type: security Severity: important References: 1212475 This update of container-suseconnect fixes the following issues: - rebuild the package with the go 1.21 security release (bsc#1212475). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4310-1 Released: Tue Oct 31 14:10:47 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1196647 This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467) * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage Update to 1.3.3: * Fix DoS vulnerability in libtirpc - replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch * _rpc_dtablesize:use portable system call * libtirpc: Fix use-after-free accessing the error number * Fix potential memory leak of parms.r_addr - replaces 0001-fix-parms.r_addr-memory-leak.patch * rpcb_clnt.c add mechanism to try v2 protocol first - preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch * Eliminate deadlocks in connects with an MT environment * clnt_dg_freeres() uncleared set active state may deadlock * thread safe clnt destruction * SUNRPC: mutexed access blacklist_read state variable * SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c Update to 1.3.2: * Replace the final SunRPC licenses with BSD licenses * blacklist: Add a few more well known ports * libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS Update to 1.3.1: * Remove AUTH_DES interfaces from auth_des.h The unsupported AUTH_DES authentication has be compiled out since commit d918e41d889 (Wed Oct 9 2019) replaced by API routines that return errors. * svc_dg: Free xp_netid during destroy * Fix memory management issues of fd locks * libtirpc: replace array with list for per-fd locks * __svc_vc_dodestroy: fix double free of xp_ltaddr.buf * __rpc_dtbsize: rlim_cur instead of rlim_max * pkg-config: use the correct replacements for libdir/includedir The following package changes have been done: - container-suseconnect-2.4.0-150000.4.42.1 updated - libtirpc-netconfig-1.3.4-150300.3.20.1 updated - libtirpc3-1.3.4-150300.3.20.1 updated . Critical patch released for SUSE package container-suseconnect and libtirpc to resolve significant vulnerabilities and bolster overall security.. SUSE Container, Security Update, Libtirpc, Important Patches, Container Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 02, 2023 Important SuSE
100

SUSE: 2023:3640-1 Important: Update for Container SUSE/SLE15

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3640-1 Container Tags : bci/bci-base:15.4 , bci/bci-base:15.4.27.14.116 , suse/sle15:15.4 , suse/sle15:15.4.27.14.116 Container Release : 27.14.116 Severity : important Type : security References : 1196647 1212475 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4309-1 Released: Tue Oct 31 14:09:03 2023 Summary: Security update for container-suseconnect Type: security Severity: important References: 1212475 This update of container-suseconnect fixes the following issues: - rebuild the package with the go 1.21 security release (bsc#1212475). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4310-1 Released: Tue Oct 31 14:10:47 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1196647 This Update for libtirpc to 1.3.4, fixing the following issues: Update to 1.3.4 (bsc#1199467) * binddynport.c honor ip_local_reserved_ports - replaces: binddynport-honor-ip_local_reserved_ports.patch * gss-api: expose gss major/minor error in authgss_refresh() * rpcb_clnt.c: Eliminate double frees in delete_cache() * rpcb_clnt.c: memory leak in destroy_addr * portmapper: allow TCP-only portmapper * getnetconfigent: avoid potential DoS issue by removing unnecessary sleep * clnt_raw.c: fix a possible null pointer dereference * bindresvport.c: fix a potential resource leakage Update to 1.3.3: * Fix DoS vulnerability in libtirpc - replaces: 0001-Fix-DoS-vulnerability-in-libtirpc.patch *_rpc_dtablesize: use portable system call * libtirpc: Fix use-after-free accessing the error number * Fix potential memory leak of parms.r_addr - replaces 0001-fix-parms.r_addr-memory-leak.patch * rpcb_clnt.c add mechanism to try v2 protocol first - preplaces: 0001-rpcb_clnt.c-config-to-try-protocolversion-2-first.patch * Eliminate deadlocks in connects with an MT environment * clnt_dg_freeres() uncleared set active state may deadlock * thread safe clnt destruction * SUNRPC: mutexed access blacklist_read state variable * SUNRPC: MT-safe overhaul of address cache management in rpcb_clnt.c Update to 1.3.2: * Replace the final SunRPC licenses with BSD licenses * blacklist: Add a few more well known ports * libtirpc: disallow calling auth_refresh from clnt_call with RPCSEC_GSS Update to 1.3.1: * Remove AUTH_DES interfaces from auth_des.h The unsupported AUTH_DES authentication has be compiled out since commit d918e41d889 (Wed Oct 9 2019) replaced by API routines that return errors. * svc_dg: Free xp_netid during destroy * Fix memory management issues of fd locks * libtirpc: replace array with list for per-fd locks * __svc_vc_dodestroy: fix double free of xp_ltaddr.buf * __rpc_dtbsize: rlim_cur instead of rlim_max * pkg-config: use the correct replacements for libdir/includedir The following package changes have been done: - container-suseconnect-2.4.0-150000.4.42.1 updated - libtirpc-netconfig-1.3.4-150300.3.20.1 updated - libtirpc3-1.3.4-150300.3.20.1 updated . SUSE Container Update Advisory SUSE-CU-2023:3640-1 addresses critical security vulnerabilities, offering crucial patches and enhancements for better container performance and stability. SUSE Container Update, libtirpc Security Fix, SUSE Advisory, Container Update Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 01, 2023 Important SuSE
100

SUSE: 2023:104-2 Critical: suse/registry Vulnerability Resolution Notice

The container suse/registry was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:103-1 Container Tags : suse/registry:2.8 , suse/registry:2.8-4.7 , suse/registry:latest Container Release : 4.7 Severity : important Type : security References : 1199467 1205502 1206212 1206622 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:37-1 Released: Fri Jan 6 15:35:49 2023 Summary: Security update for ca-certificates-mozilla Type: security Severity: important References: 1206212,1206622 This update for ca-certificates-mozilla fixes the following issues: - Updated to 2.60 state of Mozilla SSL root CAs (bsc#1206622) Removed CAs: - Global Chambersign Root - EC-ACC - Network Solutions Certificate Authority - Staat der Nederlanden EV Root CA - SwissSign Platinum CA - G2 Added CAs: - DIGITALSIGN GLOBAL ROOT ECDSA CA - DIGITALSIGN GLOBAL ROOT RSA CA - Security Communication ECC RootCA1 - Security Communication RootCA3 Changed trust: - TrustCor certificates only trusted up to Nov 30 (bsc#1206212) - Removed CAs (bsc#1206212) as most code does not handle 'valid before nov 30 2022' and it is not clear how many certs were issued for SSL middleware by TrustCor: - TrustCor RootCert CA-1 - TrustCor RootCert CA-2 - TrustCor ECA-1 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:48-1 Released: Mon Jan 9 10:37:54 2023 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1199467 This update for libtirpc fixes the following issues: - Consider/proc/sys/net/ipv4/ip_local_reserved_ports, before binding to a random port (bsc#1199467) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:50-1 Released: Mon Jan 9 10:42:21 2023 Summary: Recommended update for shadow Type: recommended Severity: moderate References: 1205502 This update for shadow fixes the following issues: - Fix issue with user id field that cannot be interpreted (bsc#1205502) The following package changes have been done: - ca-certificates-mozilla-2.60-150200.27.1 updated - libtirpc-netconfig-1.2.6-150300.3.17.1 updated - libtirpc3-1.2.6-150300.3.17.1 updated - login_defs-4.8.1-150400.10.3.1 updated - shadow-4.8.1-150400.10.3.1 updated - container:micro-image-15.4.0-16.3 updated . The container ubuntu/repository has been refreshed with crucial security fixes and advice. Ensure your safety by applying the recent updates.. SUSE Container Update, Security Patches, suse/registry Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 10, 2023 Important SuSE
98

Red Hat Enterprise Linux 9: RHSA-2022-8400-01 Moderate: libtirpc DoS Fix

An update for libtirpc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libtirpc security update Advisory ID: RHSA-2022:8400-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8400 Issue date: 2022-11-15 CVE Names: CVE-2021-46828 ==================================================================== 1. Summary: An update for libtirpc is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: The libtirpc packages contain SunLib's implementation of transport-independent remote procedure call (TI-RPC) documentation, which includes a library required by programs in the nfs-utils and rpcbind packages. Security Fix(es): * libtirpc: DoS vulnerability with lots of connections (CVE-2021-46828) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how toapply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2109352 - CVE-2021-46828 libtirpc: DoS vulnerability with lots of connections 2118157 - CVE-2021-46828 libtirpc: Upgrade to the latest upstream release libtirpc-1.3.3 [rhel-9.1.0] 6. Package List: Red Hat Enterprise Linux BaseOS (v. 9): Source: libtirpc-1.3.3-0.el9.src.rpm aarch64: libtirpc-1.3.3-0.el9.aarch64.rpm libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm ppc64le: libtirpc-1.3.3-0.el9.ppc64le.rpm libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm s390x: libtirpc-1.3.3-0.el9.s390x.rpm libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm libtirpc-debugsource-1.3.3-0.el9.s390x.rpm x86_64: libtirpc-1.3.3-0.el9.i686.rpm libtirpc-1.3.3-0.el9.x86_64.rpm libtirpc-debuginfo-1.3.3-0.el9.i686.rpm libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm libtirpc-debugsource-1.3.3-0.el9.i686.rpm libtirpc-debugsource-1.3.3-0.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v. 9): aarch64: libtirpc-debuginfo-1.3.3-0.el9.aarch64.rpm libtirpc-debugsource-1.3.3-0.el9.aarch64.rpm libtirpc-devel-1.3.3-0.el9.aarch64.rpm ppc64le: libtirpc-debuginfo-1.3.3-0.el9.ppc64le.rpm libtirpc-debugsource-1.3.3-0.el9.ppc64le.rpm libtirpc-devel-1.3.3-0.el9.ppc64le.rpm s390x: libtirpc-debuginfo-1.3.3-0.el9.s390x.rpm libtirpc-debugsource-1.3.3-0.el9.s390x.rpm libtirpc-devel-1.3.3-0.el9.s390x.rpm x86_64: libtirpc-debuginfo-1.3.3-0.el9.i686.rpm libtirpc-debuginfo-1.3.3-0.el9.x86_64.rpm libtirpc-debugsource-1.3.3-0.el9.i686.rpm libtirpc-debugsource-1.3.3-0.el9.x86_64.rpm libtirpc-devel-1.3.3-0.el9.i686.rpm libtirpc-devel-1.3.3-0.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2021-46828 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY3OMRtzjgjWX9erEAQhd+Q//Y1X+e2OsGEBUqBRBDs2msHFginbvg7uZ cbGMYGbb7u16+S0BgZEIUkmtCPSR2Tm2BjLjceTiQSR7rMhpM61O1ab3zPd42NvP BcHnnu5alTi+LfSBippNJjR4TKm1JzON3ny9im6lz/icP14mrVQLpn0JdJNwUCVL FLe8v8ZwSkTSFK6YUIb8QcKVJJH5NgWxQBQ4BK7xgCmx7DCRV97G7Z5a08fZf6Hn BxIio3Jj6AzDAi7Llw+VDb7KI7p918Esq1Sl3w2kwXexmcXda6r5ftG7SjEvf8Sp d4QPEWU9wJrEqx13rYh8g/8xAF1jTzLLBgvfnxnNQupvrgskss5qrDhTps/GaSVg qk7RWyDsURRPTAtCisW+EO3PIXCL9101e+kroLC2w44hqqdTi86X03Fizn3xDuZ1 48YO2sOc6M+ipzA5YUWgMMEmT5YDOQGhflDNf9wbxcLmzFWz5Xa0ui3UWQJ8lrhH 4B4C7SYoHsuNUNUYDzqjnxB8QgpycDuVBHKB/eSqYHXBUOdPixZfrAKLI/h/LRfK LhzogIsCy4tmw4txNcgvb0qhq6ehaU9cRmqlxbtRsvthtANorTrC8Slq1kT51OXJ W5aaFyfGGC/+L8VnB3q0xWx4dzaonEh49aZdTjnqUCfM5ItkqsXE8MwwShn+Rr9W E7LBqCWDqRw=u4dV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A patch for libtirpc enhances safety against denial-of-service threats for Red Hat Enterprise Linux 9, assigned a moderate severity level.. Red Hat Enterprise, libtirpc security, DoS protection, Linux update. . LinuxSecurity.com Team

Calendar%202 Nov 15, 2022 Red Hat
91

Gentoo: GLSA-202210-33 Normal: Libtirpc Service Disruption Due To Denial

A vulnerability has been discovered in Libtirpc which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Libtirpc: Denial of Service Date: October 31, 2022 Bugs: #859634 ID: 202210-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in Libtirpc which could result in denial of service. Background ========= Libtirpc is a port of Sun's Transport-Independent RPC library to Linux. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libtirpc < 1.3.2 > = 1.3.2 Description ========== Currently svc_run does not handle poll timeout and rendezvous_request does not handle EMFILE error returned from accept(2 as it used to. These two missing functionality were removed by commit b2c9430f46c4. The effect of not handling poll timeout allows idle TCP conections to remain ESTABLISHED indefinitely. When the number of connections reaches the limit of the open file descriptors (ulimit -n) then accept(2) fails with EMFILE. Since there is no handling of EMFILE error this causes svc_run() to get in a tight loop calling accept(2). This resulting in the RPC service of svc_run is being down, it's no longer able to service any requests. Due to a lack of handling of certain error cases, connections to Libtirpc could remain ESTABLISHED indefinitely. Impact ===== Denial of service can be achieved via establishing enough connectionsto Libtirpc to reach the limit of open file descriptors for the process. Workaround ========= There is no known workaround at this time. Resolution ========= All Libtirpc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/libtirpc-1.3.2" References ========= [ 1 ] CVE-2021-46828 https://nvd.nist.gov/vuln/detail/CVE-2021-46828 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-33 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Uncover the vulnerability related to DoS in Libtirpc and explore effective strategies for risk alleviation using Gentoo's latest patch.. Gentoo Security,Libtirpc Denial,Service Advisory,GLSA 202210-33,Open File Descriptors. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 Gentoo
100

SUSE: 2022:3791-1 Critical Update: libtirpc Denial of Service Patch

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for libtirpc ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3791-1 Rating: important References: #1200800 #1201680 Cross-References: CVE-2021-46828 CVSS scores: CVE-2021-46828 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-46828 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for libtirpc fixes the following issues: - CVE-2021-46828: Fixed denial of service vulnerability with lots of connections (bsc#1201680). - Exclude ipv6 addresses in client protocol version 2 code (bsc#1200800) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-3791=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-3791=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patchSUSE-SLE-SDK-12-SP5-2022-3791=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2022-3791=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-3791=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2022-3791=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-3791=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-3791=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE OpenStack Cloud 9 (x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-devel-1.0.1-17.24.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libtirpc-debugsource-1.0.1-17.24.1 libtirpc-netconfig-1.0.1-17.24.1 libtirpc3-1.0.1-17.24.1 libtirpc3-32bit-1.0.1-17.24.1 libtirpc3-debuginfo-1.0.1-17.24.1 libtirpc3-debuginfo-32bit-1.0.1-17.24.1 References: https://www.suse.com/security/cve/CVE-2021-46828.html https://bugzilla.suse.com/1200800 https://bugzilla.suse.com/1201680 . The recent libtirpc update addresses a denial of service vulnerability found in SUSE platforms. Please consult Announcement ID: SUSE-SU-2022:3791-1 for further details.. libtirpc Patch, Software Update, SUSE Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 27, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200