An issue has been found in libuev, a lightweight event loop library for Linux. The issue is related to a possible buffer overrun in uev_run(). For Debian 11 bullseye, this problem has been fixed in version 2.3.1-1+deb11u1. We recommend that you upgrade your libuev packages.. Debian LTS Advisory DLA-4454-1
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libuev ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0023-1 Rating: moderate References: #1218749 Cross-References: CVE-2022-48620 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libuev fixes the following issues: - Update to 2.4.1: * Update README with list of moden Linux APIs used * Fix #27: possible buffer overrun in uev_run() boo#1218749 CVE-2022-48620 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-23=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libuev-devel-2.4.1-bp155.3.3.1 libuev3-2.4.1-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2022-48620.html https://bugzilla.suse.com/1218749 . An update for libuv has been released, mitigating moderate security flaws within openSUSE Backports. Apply this enhancement to ensure increased safety.. openSUSE Security, libuev Update, Buffer Overrun Fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.