Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
197

Debian: DLA-3580-1 Critical: Libwebrender Memory Leak And Security Flaws

Multiple flaws were found in libyang, a parser toolkit for IETF YANG data modeling. Double frees, invalid memory access and Null pointer dereferences may cause a denial of service or potentially code execution. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3572-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany September 19, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libyang Version : 0.16.105+really1.0-0+deb10u1 CVE ID : CVE-2019-20391 CVE-2019-20392 CVE-2019-20393 CVE-2019-20394 CVE-2019-20395 CVE-2019-20396 CVE-2019-20397 CVE-2019-20398 Multiple flaws were found in libyang, a parser toolkit for IETF YANG data modeling. Double frees, invalid memory access and Null pointer dereferences may cause a denial of service or potentially code execution. For Debian 10 buster, these problems have been fixed in version 0.16.105+really1.0-0+deb10u1. We recommend that you upgrade your libyang packages. For the detailed security status of libyang please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libyang Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libyang to address several vulnerabilities leading to Denial of Service or arbitrary code execution as outlined in the Debian LTS advisory DLA-3572-1.. libyang security update, Debian LTS, parser toolkit flaws. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 19, 2023 Critical Debian LTS
89

Fedora 38: FEDORA-2023-93d978c182 Moderate libyang Upgrade

Rebase to version 2.1.55. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-93d978c182 2023-04-15 02:01:33.485923 --------------------------------------------------------------------------------Name : libyang Product : Fedora 38 Version : 2.1.55 Release : 1.fc38 URL : https://github.com/CESNET/libyang Summary : YANG data modeling language library Description : Libyang is YANG data modeling language parser and toolkit written (and providing API) in C. --------------------------------------------------------------------------------Update Information: Rebase to version 2.1.55 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 19 2023 Tomas Korbar - 2.1.55-1 - Rebase to version 2.1.55 - Resolves: rhbz#2179481 * Fri Mar 10 2023 Tomas Korbar - 2.1.30-2 - Change the License tag to the SPDX format --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-93d978c182' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do notreply to spam, report it: . Upgrade Your Fedora 38 Journey with libyang 2.1.55 Enhancement for Superior Data Structuring.. libyang, Fedora 38, data modeling update. . LinuxSecurity.com Team

Calendar 2 Apr 15, 2023 Fedora
89

Fedora 36: 2023-17aaa2187f Critical: libyang NULL Pointer Issue

Rebase to version 2.1.55. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-17aaa2187f 2023-04-14 01:30:58.046118 --------------------------------------------------------------------------------Name : libyang Product : Fedora 36 Version : 2.1.55 Release : 1.fc36 URL : https://github.com/CESNET/libyang Summary : YANG data modeling language library Description : Libyang is YANG data modeling language parser and toolkit written (and providing API) in C. --------------------------------------------------------------------------------Update Information: Rebase to version 2.1.55 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 19 2023 Tomas Korbar - 2.1.55-1 - Rebase to version 2.1.55 - Resolves: rhbz#2179481 * Fri Mar 10 2023 Tomas Korbar - 2.1.30-2 - Change the License tag to the SPDX format * Thu Jan 19 2023 Tomas Korbar - 2.1.30-1 - Rebase to version 2.1.30 - Resolves: rhbz#2162362 --------------------------------------------------------------------------------References: [ 1 ] Bug #2184382 - CVE-2023-26916 libyang: NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184382 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-17aaa2187f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The recent libyang update in Fedora 36 addresses a NULL pointer problem and upgrades to version 2.1.55, improving overall security.. libyang update,Fedora 36 advisory,YANG data model,security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 14, 2023 Critical Fedora
89

Fedora 37 LIBYANG-2023-9887f01975 Critical: NULL Pointer Issue

Rebase to version 2.1.55. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-9887f01975 2023-04-14 01:05:02.596181 --------------------------------------------------------------------------------Name : libyang Product : Fedora 37 Version : 2.1.55 Release : 1.fc37 URL : https://github.com/CESNET/libyang Summary : YANG data modeling language library Description : Libyang is YANG data modeling language parser and toolkit written (and providing API) in C. --------------------------------------------------------------------------------Update Information: Rebase to version 2.1.55 --------------------------------------------------------------------------------ChangeLog: * Sun Mar 19 2023 Tomas Korbar - 2.1.55-1 - Rebase to version 2.1.55 - Resolves: rhbz#2179481 * Fri Mar 10 2023 Tomas Korbar - 2.1.30-2 - Change the License tag to the SPDX format * Thu Jan 19 2023 Tomas Korbar - 2.1.30-1 - Rebase to version 2.1.30 - Resolves: rhbz#2162362 --------------------------------------------------------------------------------References: [ 1 ] Bug #2184382 - CVE-2023-26916 libyang: NULL pointer dereference via the function lys_parse_mem at lys_parse_mem.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184382 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9887f01975' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Updating to version 2.1.55 for libyang incorporates crucial enhancements for Fedora 37, guaranteeing improved efficiency and safety.. libyang updates, Fedora security, data modeling software. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 14, 2023 Critical Fedora
100

SUSE: 2022:3245-1 Critical Update for libyang DoS Issues

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for libyang ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3245-1 Rating: important References: #1186374 #1186375 #1186376 #1186378 Cross-References: CVE-2021-28902 CVE-2021-28903 CVE-2021-28904 CVE-2021-28906 CVSS scores: CVE-2021-28902 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28902 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28903 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28903 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28904 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28904 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28906 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28906 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libyang fixes the following issues: - CVE-2021-28906: Fixed missing check in read_yin_leaf that can lead to DoS (bsc#1186378) - CVE-2021-28904: Fixed missing check in ext_get_plugin that lead to DoS (bsc#1186376). - CVE-2021-28903: Fixed stack overflow in lyxml_parse_mem (bsc#1186375). - CVE-2021-28902: Fixed missing check in read_yin_container that can lead to DoS (bsc#1186374). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-3245=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3245=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-3245=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-3245=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libyang-cpp-devel-1.0.184-150300.3.6.1 libyang-cpp1-1.0.184-150300.3.6.1 libyang-cpp1-debuginfo-1.0.184-150300.3.6.1 libyang-debuginfo-1.0.184-150300.3.6.1 libyang-debugsource-1.0.184-150300.3.6.1 libyang-devel-1.0.184-150300.3.6.1 libyang-extentions-1.0.184-150300.3.6.1 libyang-extentions-debuginfo-1.0.184-150300.3.6.1 libyang1-1.0.184-150300.3.6.1 libyang1-debuginfo-1.0.184-150300.3.6.1 python3-yang-1.0.184-150300.3.6.1 python3-yang-debuginfo-1.0.184-150300.3.6.1 yang-tools-1.0.184-150300.3.6.1 yang-tools-debuginfo-1.0.184-150300.3.6.1 - openSUSE Leap 15.4 (noarch): libyang-doc-1.0.184-150300.3.6.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libyang-cpp-devel-1.0.184-150300.3.6.1 libyang-cpp1-1.0.184-150300.3.6.1 libyang-cpp1-debuginfo-1.0.184-150300.3.6.1 libyang-debuginfo-1.0.184-150300.3.6.1 libyang-debugsource-1.0.184-150300.3.6.1 libyang-devel-1.0.184-150300.3.6.1 libyang-extentions-1.0.184-150300.3.6.1 libyang-extentions-debuginfo-1.0.184-150300.3.6.1 libyang1-1.0.184-150300.3.6.1 libyang1-debuginfo-1.0.184-150300.3.6.1 python3-yang-1.0.184-150300.3.6.1 python3-yang-debuginfo-1.0.184-150300.3.6.1 yang-tools-1.0.184-150300.3.6.1 yang-tools-debuginfo-1.0.184-150300.3.6.1 - openSUSE Leap 15.3 (noarch): libyang-doc-1.0.184-150300.3.6.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (aarch64 ppc64le s390x x86_64): libyang-debuginfo-1.0.184-150300.3.6.1 libyang-debugsource-1.0.184-150300.3.6.1 libyang-extentions-1.0.184-150300.3.6.1 libyang-extentions-debuginfo-1.0.184-150300.3.6.1 libyang1-1.0.184-150300.3.6.1 libyang1-debuginfo-1.0.184-150300.3.6.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 ppc64le s390x x86_64): libyang-debuginfo-1.0.184-150300.3.6.1 libyang-debugsource-1.0.184-150300.3.6.1 libyang-extentions-1.0.184-150300.3.6.1 libyang-extentions-debuginfo-1.0.184-150300.3.6.1 libyang1-1.0.184-150300.3.6.1 libyang1-debuginfo-1.0.184-150300.3.6.1 References: https://www.suse.com/security/cve/CVE-2021-28902.html https://www.suse.com/security/cve/CVE-2021-28903.html https://www.suse.com/security/cve/CVE-2021-28904.html https://www.suse.com/security/cve/CVE-2021-28906.html https://bugzilla.suse.com/1186374 https://bugzilla.suse.com/1186375 https://bugzilla.suse.com/1186376 https://bugzilla.suse.com/1186378 . A crucial patch for libyang resolves several concerns that could potentially result in Denial of Service attacks.. Libyang Update,SUSE Security,Denial of Service,Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 12, 2022 Important SuSE
100

SUSE Linux Enterprise Server 15-SP4 Important: libyang Denial of Service

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libyang ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2922-1 Rating: important References: #1186377 Cross-References: CVE-2021-28905 CVSS scores: CVE-2021-28905 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-28905 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.2 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.2 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.2 SUSE Manager Server 4.3 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libyang fixes the following issues: - CVE-2021-28905: Fixed a reachable assertion which could be exploited by an attacker to cause a denial of service (bsc#1186377). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-2922=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2922=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-2922=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-2922=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): libyang-cpp-devel-1.0.184-150300.3.3.1 libyang-cpp1-1.0.184-150300.3.3.1 libyang-cpp1-debuginfo-1.0.184-150300.3.3.1 libyang-debuginfo-1.0.184-150300.3.3.1 libyang-debugsource-1.0.184-150300.3.3.1 libyang-devel-1.0.184-150300.3.3.1 libyang-extentions-1.0.184-150300.3.3.1 libyang-extentions-debuginfo-1.0.184-150300.3.3.1 libyang1-1.0.184-150300.3.3.1 libyang1-debuginfo-1.0.184-150300.3.3.1 python3-yang-1.0.184-150300.3.3.1 python3-yang-debuginfo-1.0.184-150300.3.3.1 yang-tools-1.0.184-150300.3.3.1 yang-tools-debuginfo-1.0.184-150300.3.3.1 - openSUSE Leap 15.4 (noarch): libyang-doc-1.0.184-150300.3.3.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): libyang-cpp-devel-1.0.184-150300.3.3.1 libyang-cpp1-1.0.184-150300.3.3.1 libyang-cpp1-debuginfo-1.0.184-150300.3.3.1 libyang-debuginfo-1.0.184-150300.3.3.1 libyang-debugsource-1.0.184-150300.3.3.1 libyang-devel-1.0.184-150300.3.3.1 libyang-extentions-1.0.184-150300.3.3.1 libyang-extentions-debuginfo-1.0.184-150300.3.3.1 libyang1-1.0.184-150300.3.3.1 libyang1-debuginfo-1.0.184-150300.3.3.1 python3-yang-1.0.184-150300.3.3.1 python3-yang-debuginfo-1.0.184-150300.3.3.1 yang-tools-1.0.184-150300.3.3.1 yang-tools-debuginfo-1.0.184-150300.3.3.1 - openSUSE Leap 15.3 (noarch): libyang-doc-1.0.184-150300.3.3.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (aarch64 ppc64le s390x x86_64): libyang-debuginfo-1.0.184-150300.3.3.1 libyang-debugsource-1.0.184-150300.3.3.1 libyang-extentions-1.0.184-150300.3.3.1 libyang-extentions-debuginfo-1.0.184-150300.3.3.1 libyang1-1.0.184-150300.3.3.1 libyang1-debuginfo-1.0.184-150300.3.3.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 ppc64le s390x x86_64): libyang-debuginfo-1.0.184-150300.3.3.1 libyang-debugsource-1.0.184-150300.3.3.1 libyang-extentions-1.0.184-150300.3.3.1 libyang-extentions-debuginfo-1.0.184-150300.3.3.1 libyang1-1.0.184-150300.3.3.1 libyang1-debuginfo-1.0.184-150300.3.3.1 References: https://www.suse.com/security/cve/CVE-2021-28905.html https://bugzilla.suse.com/1186377 . SUSE has released a critical security update targeting a libyang vulnerability, providing essential patch guidelines for impacted systems.. SUSE Security Update, libyang Patch, Denial Of Service Fix, SUSE Vulnerability Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 26, 2022 Important SuSE
91

Gentoo GLSA-202108-32: Minor libxml2 Vulnerabilities May Disrupt Services

Multiple vulnerabilities have been found in libyang, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: libyang: Multiple vulnerabilities Date: July 24, 2021 Bugs: #791373 ID: 202107-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libyang, the worst of which could result in a Denial of Service condition. Background ========= YANG data modeling language library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/libyang < 1.0.236 > = 1.0.236 Description ========== Multiple vulnerabilities have been discovered in libyang. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libyang users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/libyang-1.0.236" References ========= [ 1 ] CVE-2021-28902 https://nvd.nist.gov/vuln/detail/CVE-2021-28902 [ 2 ] CVE-2021-28903 https://nvd.nist.gov/vuln/detail/CVE-2021-28903 [ 3 ] CVE-2021-28904 https://nvd.nist.gov/vuln/detail/CVE-2021-28904 [ 4 ] CVE-2021-28905 https://nvd.nist.gov/vuln/detail/CVE-2021-28905 [ 5 ] CVE-2021-28906 https://nvd.nist.gov/vuln/detail/CVE-2021-28906 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-54 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Serious security issues found in libyang; it is recommended to upgrade to prevent potential service interruptions on Gentoo platforms.. libyang vulnerabilities,Gentoo security,software update,denial of service,security advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jul 23, 2021 Low Gentoo
98

Red Hat Enterprise Linux 8 RHSA-2019-4360-01 Important Buffer Overflow Fix

An update for libyang is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libyang security update Advisory ID: RHSA-2019:4360-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:4360 Issue date: 2019-12-23 CVE Names: CVE-2019-19333 CVE-2019-19334 ==================================================================== 1. Summary: An update for libyang is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libyang package provides a library for YANG data modeling language. libyang is a YANG data modelling language parser and toolkit written (and providing API) in C. The library is used e.g. in libnetconf2, Netopeer2, sysrepo and FRRouting projects. Security Fix(es): * libyang: stack-based buffer overflow in make_canonical when bits leaf type is used (CVE-2019-19333) * libyang: stack-based buffer overflow in make_canonical when identityref leaf type is used (CVE-2019-19334) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. IMPORTANT: The libyang-devel sub-package has recently been removed from theAppStream repository. If you have previously installed libyang-devel, remove it prior to applying this advisory to make the update successful. 4. Solution: If you have previously installed libyang-devel, remove it prior to applying this advisory to make the update successful. For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1779573 - CVE-2019-19333 libyang: stack-based buffer overflow in make_canonical when bits leaf type is used 1779576 - CVE-2019-19334 libyang: stack-based buffer overflow in make_canonical when identityref leaf type is used 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: libyang-0.16.105-3.el8_1.2.src.rpm aarch64: libyang-0.16.105-3.el8_1.2.aarch64.rpm libyang-cpp-debuginfo-0.16.105-3.el8_1.2.aarch64.rpm libyang-debuginfo-0.16.105-3.el8_1.2.aarch64.rpm libyang-debugsource-0.16.105-3.el8_1.2.aarch64.rpm python3-libyang-debuginfo-0.16.105-3.el8_1.2.aarch64.rpm ppc64le: libyang-0.16.105-3.el8_1.2.ppc64le.rpm libyang-cpp-debuginfo-0.16.105-3.el8_1.2.ppc64le.rpm libyang-debuginfo-0.16.105-3.el8_1.2.ppc64le.rpm libyang-debugsource-0.16.105-3.el8_1.2.ppc64le.rpm python3-libyang-debuginfo-0.16.105-3.el8_1.2.ppc64le.rpm s390x: libyang-0.16.105-3.el8_1.2.s390x.rpm libyang-cpp-debuginfo-0.16.105-3.el8_1.2.s390x.rpm libyang-debuginfo-0.16.105-3.el8_1.2.s390x.rpm libyang-debugsource-0.16.105-3.el8_1.2.s390x.rpm python3-libyang-debuginfo-0.16.105-3.el8_1.2.s390x.rpm x86_64: libyang-0.16.105-3.el8_1.2.i686.rpm libyang-0.16.105-3.el8_1.2.x86_64.rpm libyang-cpp-debuginfo-0.16.105-3.el8_1.2.i686.rpm libyang-cpp-debuginfo-0.16.105-3.el8_1.2.x86_64.rpm libyang-debuginfo-0.16.105-3.el8_1.2.i686.rpm libyang-debuginfo-0.16.105-3.el8_1.2.x86_64.rpm libyang-debugsource-0.16.105-3.el8_1.2.i686.rpm libyang-debugsource-0.16.105-3.el8_1.2.x86_64.rpm python3-libyang-debuginfo-0.16.105-3.el8_1.2.i686.rpm python3-libyang-debuginfo-0.16.105-3.el8_1.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-19333 https://access.redhat.com/security/cve/CVE-2019-19334 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXgA7EtzjgjWX9erEAQj7KBAAjEUWsYnU3jHCJQFV8Uxwc/GqKDQBJG1z eA3NrdDTA639M9CCCRnorfgErKpmlU8qJahmyuUm2VdazfmC95K/ZOce/BdD3FxO b/aRvjRG/fmMuiFC1bbg5KGRq27ZAyIZrRCTi1bHqbuVULufZUBX2mUxd5cR4L2m /tfq86ckNeA6x9fZ9YotztOrTgJL7D4Ujxe6VE//BflFI4f7ouwQyLP556Q3vHI3 +litpxcY9yuWuKcblvC6Jm6W/7rluzVUd8d7l9/FI5bJdIinO57g6hrO3mbEUmgn YeoFfjs+HI+kWTniZqJC+CUEBhY3Z3V+dKh2eiwKAEcerh8bi1CtXkTgoomJzef6 fU1A0arfPCNApyYTWGAMenHJvbZMASbwOw4YQoioN/m5C1Y6EGFs/JVx2Cg+MGCE zTD6xGwi9Fhj2k1K5r70l/OtJpxLT3Hs5oGqlnu3BTLyIX4nNleVLgHPeScAttXf mnE+/Mebm462qg/H/MiShxqevOg+ioieRwO3Z+PnzmYUqfBYx2Jc8l4282zhhFJy hJNLU9s49TAdQgLIBoa3thPLgxeaQM+NhHpOsI6AD31JEKCPNWLZoC7hqsQeZbKs ETP0upGdGvo0xrByp0JDVu6H/FoY6UL1087TfcUQX+blTKawNRZaZB+OVqDlvM7k n2AioaFDJb4=cgM6 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical libyang security patch now released for Red Hat Enterprise Linux 8. Refer to the advisory for more information.. libyang security, Red Hat update, buffer overflow fix, Red Hat security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 22, 2019 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here