Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 37: FEDORA-2023-9d84f4b8a1 Critical: ntfs-3g Security Flaw

New upstream version 2022.5.17. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8f775872c9 2022-06-17 01:12:46.340907 --------------------------------------------------------------------------------Name : ntfs-3g Product : Fedora 36 Version : 2022.5.17 Release : 1.fc36 URL : https://www.tuxera.com/about-tuxera/ Summary : Linux NTFS userspace driver Description : NTFS-3G is a stable, open source, GPL licensed, POSIX, read/write NTFS driver for Linux and many other operating systems. It provides safe handling of the Windows XP, Windows Server 2003, Windows 2000, Windows Vista, Windows Server 2008 and Windows 7 NTFS file systems. NTFS-3G can create, remove, rename, move files, directories, hard links, and streams; it can read and write normal and transparently compressed files, including streams and sparse files; it can handle special files like symbolic links, devices, and FIFOs, ACL, extended attributes; moreover it provides full file access right and ownership support. --------------------------------------------------------------------------------Update Information: New upstream version 2022.5.17 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 8 2022 Richard W.M. Jones - 2:2022.5.17-1 - New upstream version 2022.5.17 - Fixes: CVE-2021-46790, CVE-2022-30783, CVE-2022-30784, CVE-2022-30785, CVE-2022-30786, CVE-2022-30787, CVE-2022-30788, CVE-2022-30789 --------------------------------------------------------------------------------References: [ 1 ] Bug #2093306 - CVE-2022-30783 ntfs-3g: invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093306 [ 2 ] Bug #2093316 - CVE-2022-30784 ntfs-3g: crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093316 [ 3 ] Bug #2093321 - CVE-2022-30785 ntfs-3g: a file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093321 [ 4 ] Bug #2093328 - CVE-2022-30786 ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093328 [ 5 ] Bug #2093334 - CVE-2022-30787 ntfs-3g: integer underflow in fuse_lib_readdir enables arbitrary memory read operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093334 [ 6 ] Bug #2093341 - CVE-2022-30788 ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093341 [ 7 ] Bug #2093349 - CVE-2022-30789 ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093349 [ 8 ] Bug #2093360 - CVE-2021-46790 ntfs-3g: heap-based buffer overflow in ntfsck [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093360 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8f775872c9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important Fedora ntfs-3g upgrade issued to resolve major problems. Ensure your systems are protected with this vital update.. ntfs-3g Update Notification, Fedora Security Fix, Linux NTFS Driver. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 16, 2022 Critical Fedora
172

Ubuntu 16.04 LTS: USN-4163-1 Critical: Kernel Denial Of Service Risks

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4163-1 October 22, 2019 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-snapdragon: Linux kernel for Snapdragon processors Details: It was discovered that a race condition existed in the ARC EMAC ethernet driver for the Linux kernel, resulting in a use-after-free vulnerability. An attacker could use this to cause a denial of service (system crash). (CVE-2016-10906) It was discovered that a race condition existed in the Serial Attached SCSI (SAS) implementation in the Linux kernel when handling certain error conditions. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2017-18232) It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not did not handle detach operations correctly, leading to a use-after-free vulnerability. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-21008) Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux kernel did not properly perform bounds checking, leading to a heap overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-14814, CVE-2019-14816) Matt Delco discovered that the KVM hypervisor implementation in the Linux kernel did not properly perform bounds checking when handling coalesced MMIO write operations. A local attackerwith write access to /dev/kvm could use this to cause a denial of service (system crash). (CVE-2019-14821) Hui Peng and Mathias Payer discovered that the USB audio driver for the Linux kernel did not properly validate device meta data. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2019-15117) Hui Peng and Mathias Payer discovered that the USB audio driver for the Linux kernel improperly performed recursion while handling device meta data. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2019-15118) It was discovered that the Technisat DVB-S/S2 USB device driver in the Linux kernel contained a buffer overread. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2019-15505) Brad Spengler discovered that a Spectre mitigation was improperly implemented in the ptrace susbsystem of the Linux kernel. A local attacker could possibly use this to expose sensitive information. (CVE-2019-15902) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-1060-kvm 4.4.0-1060.67 linux-image-4.4.0-1096-aws 4.4.0-1096.107 linux-image-4.4.0-1124-raspi2 4.4.0-1124.133 linux-image-4.4.0-1128-snapdragon 4.4.0-1128.136 linux-image-4.4.0-166-generic 4.4.0-166.195 linux-image-4.4.0-166-generic-lpae 4.4.0-166.195 linux-image-4.4.0-166-lowlatency 4.4.0-166.195 linux-image-4.4.0-166-powerpc-e500mc 4.4.0-166.195 linux-image-4.4.0-166-powerpc-smp 4.4.0-166.195 linux-image-4.4.0-166-powerpc64-emb 4.4.0-166.195 linux-image-4.4.0-166-powerpc64-smp 4.4.0-166.195 linux-image-aws 4.4.0.1096.100 linux-image-generic 4.4.0.166.174 linux-image-generic-lpae 4.4.0.166.174 linux-image-kvm 4.4.0.1060.60 linux-image-lowlatency 4.4.0.166.174 linux-image-powerpc-e500mc 4.4.0.166.174 linux-image-powerpc-smp 4.4.0.166.174 linux-image-powerpc64-emb 4.4.0.166.174 linux-image-powerpc64-smp 4.4.0.166.174 linux-image-raspi2 4.4.0.1124.124 linux-image-snapdragon 4.4.0.1128.120 linux-image-virtual 4.4.0.166.174 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4163-1 CVE-2016-10906, CVE-2017-18232, CVE-2018-21008, CVE-2019-14814, CVE-2019-14816, CVE-2019-14821, CVE-2019-15117, CVE-2019-15118, CVE-2019-15505, CVE-2019-15902 Package Information: https://launchpad.net/ubuntu/+source/linux/4.4.0-166.195 https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1096.107 https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1060.67 https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1124.133 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1128.136 . Critical news for Ubuntu 16.04 LTS concerning Linux kernel vulnerabilities, highlighting potential denial of service threats and the corresponding fixes.. ubuntu security, linux kernel patch, denial of service issues, system stability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 21, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here