Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
217

Oracle Linux 9 ELSA-2023-12715 Critical: Firmware Update Critical Threat

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12715 https://linux.oracle.com/errata/ELSA-2023-12715.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: iwl1000-firmware-39.31.5.1-999.25.el9.noarch.rpm iwl100-firmware-39.31.5.1-999.25.el9.noarch.rpm iwl105-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl135-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl2000-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl2030-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl3160-firmware-25.30.13.0-999.25.el9.noarch.rpm iwl3945-firmware-15.32.2.9-999.25.el9.noarch.rpm iwl4965-firmware-228.61.2.24-999.25.el9.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.25.el9.noarch.rpm iwl5150-firmware-8.24.2.2-999.25.el9.noarch.rpm iwl6000-firmware-9.221.4.1-999.25.el9.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl6050-firmware-41.28.5.1-999.25.el9.noarch.rpm iwl7260-firmware-25.30.13.0-999.25.el9.noarch.rpm iwlax2xx-firmware-20230516-999.25.el9.noarch.rpm libertas-sd8686-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-sd8787-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-usb8388-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-usb8388-olpc-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-core-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-whence-20230516-999.25.git6c9e0ed5.el9.noarch.rpm liquidio-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm netronome-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm aarch64: iwl1000-firmware-39.31.5.1-999.25.el9.noarch.rpm iwl100-firmware-39.31.5.1-999.25.el9.noarch.rpm iwl105-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl135-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl2000-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl2030-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl3160-firmware-25.30.13.0-999.25.el9.noarch.rpm iwl3945-firmware-15.32.2.9-999.25.el9.noarch.rpm iwl4965-firmware-228.61.2.24-999.25.el9.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.25.el9.noarch.rpm iwl5150-firmware-8.24.2.2-999.25.el9.noarch.rpm iwl6000-firmware-9.221.4.1-999.25.el9.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.25.el9.noarch.rpm iwl6050-firmware-41.28.5.1-999.25.el9.noarch.rpm iwl7260-firmware-25.30.13.0-999.25.el9.noarch.rpm iwlax2xx-firmware-20230516-999.25.el9.noarch.rpm libertas-sd8686-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-sd8787-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-usb8388-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm libertas-usb8388-olpc-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-core-20230516-999.25.git6c9e0ed5.el9.noarch.rpm linux-firmware-whence-20230516-999.25.git6c9e0ed5.el9.noarch.rpm liquidio-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm netronome-firmware-20230516-999.25.git6c9e0ed5.el9.noarch.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//linux-firmware-20230516-999.25.git6c9e0ed5.el9.src.rpm Related CVEs: CVE-2023-20569 Description of changes: [20230516-999.25.git6c9e0ed5.el9] - Add missing amd-ucode/ files to nano and core rpm (Orabug: 35642190) - Add posttrans scriptlet to reload microcode on AMD (Orabug: 35636951) - Recreate initramfs for AMD systems (Orabug: 35636951) [20230516-999.24.git6c9e0ed5.el7] - 8a07fa49 linux-firmware: Update AMD fam19h cpu microcode (Orabug: 35659485) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Enterprise Linux Advisory ELSA-2023-12840 outlines essential security patches and kernel modifications to enhance system integrity and resilience.. Oracle Linux Security,Firmware Updates,Linux Security Patches,Unbreakable Linux Network,Important Linux Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 10, 2023 Critical Oracle
172

Ubuntu 22.04 LTS USN-5912-1 Critical Kernel Update: Denial Of Service

Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5912-1 March 02, 2023 linux, linux-aws, linux-aws-5.15, linux-azure, linux-azure-5.15, linux-azure-fde, linux-gcp, linux-gcp-5.15, linux-gke, linux-gke-5.15, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-azure: Linux kernel for Microsoft Azure Cloud systems - linux-azure-fde: Linux kernel for Microsoft Azure CVM cloud systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-lowlatency: Linux low latency kernel - linux-oracle: Linux kernel for Oracle Cloud systems - linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems - linux-azure-5.15: Linux kernel for Microsoft Azure cloud systems - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke-5.15: Linux kernel for Google Container Engine (GKE) systems - linux-hwe-5.15: Linux hardware enablement (HWE) kernel - linux-lowlatency-hwe-5.15: Linux low latency kernel - linux-oracle-5.15: Linux kernel for Oracle Cloud systems Details: It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) Davide Ornaghi discovered that the netfilter subsystemin the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0179) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) Maxim Levitsky discovered that the KVM nested virtualization (SVM) implementation for AMD processors in the Linux kernel did not properly handle nested shutdown execution. An attacker in a guest vm could use this to cause a denial of service (host kernel crash) (CVE-2022-3344) Gwangun Jung discovered a race condition in the IPv4 implementation in the Linux kernel when deleting multipath routes, resulting in an out-of-bounds read. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2022-3435) It was discovered that a race condition existed in the Kernel Connection Multiplexor (KCM) socket implementation in the Linux kernel when releasing sockets in certain situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3521) It was discovered that the Netronome Ethernet driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3545) It was discovered that the Intel i915 graphics driver in the Linux kernel did not perform a GPU TLB flush in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-4139) It was discovered that a race condition existed in the Xen network backend driver in the Linux kernel when handling dropped packets in certain circumstances. An attacker could use this to cause a denial of service (kernel deadlock). (CVE-2022-42328,CVE-2022-42329) It was discovered that the NFSD implementation in the Linux kernel contained a use-after-free vulnerability. A remote attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-4379) It was discovered that a race condition existed in the x86 KVM subsystem implementation in the Linux kernel when nested virtualization and the TDP MMU are enabled. An attacker in a guest vm could use this to cause a denial of service (host OS crash). (CVE-2022-45869) It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate the number of channels, leading to an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47518) It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate specific attributes, leading to an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47519) It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate offsets, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash). (CVE-2022-47520) It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate specific attributes, leading to a heap-based buffer overflow. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47521) Lin Ma discovered a race condition in the io_uring subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-0468) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-5.15.0-1028-gke 5.15.0-1028.33 linux-image-5.15.0-1030-gcp 5.15.0-1030.37 linux-image-5.15.0-1030-oracle 5.15.0-1030.36 linux-image-5.15.0-1031-aws 5.15.0-1031.35 linux-image-5.15.0-1034-azure 5.15.0-1034.41 linux-image-5.15.0-1034-azure-fde 5.15.0-1034.41.1 linux-image-5.15.0-67-generic 5.15.0-67.74 linux-image-5.15.0-67-generic-64k 5.15.0-67.74 linux-image-5.15.0-67-generic-lpae 5.15.0-67.74 linux-image-5.15.0-67-lowlatency 5.15.0-67.74 linux-image-5.15.0-67-lowlatency-64k 5.15.0-67.74 linux-image-aws 5.15.0.1031.29 linux-image-aws-lts-22.04 5.15.0.1031.29 linux-image-azure 5.15.0.1034.30 linux-image-azure-fde 5.15.0.1034.41.11 linux-image-azure-lts-22.04 5.15.0.1034.30 linux-image-gcp 5.15.0.1030.25 linux-image-generic 5.15.0.67.65 linux-image-generic-64k 5.15.0.67.65 linux-image-generic-lpae 5.15.0.67.65 linux-image-gke 5.15.0.1028.27 linux-image-gke-5.15 5.15.0.1028.27 linux-image-lowlatency 5.15.0.67.72 linux-image-lowlatency-64k 5.15.0.67.72 linux-image-oracle 5.15.0.1030.25 linux-image-virtual 5.15.0.67.65 Ubuntu 20.04 LTS: linux-image-5.15.0-1028-gke 5.15.0-1028.33~20.04.1 linux-image-5.15.0-1030-gcp 5.15.0-1030.37~20.04.1 linux-image-5.15.0-1030-oracle 5.15.0-1030.36~20.04.1 linux-image-5.15.0-1031-aws 5.15.0-1031.35~20.04.1 linux-image-5.15.0-1034-azure 5.15.0-1034.41~20.04.1 linux-image-5.15.0-67-generic 5.15.0-67.74~20.04.1 linux-image-5.15.0-67-generic-64k 5.15.0-67.74~20.04.1 linux-image-5.15.0-67-generic-lpae 5.15.0-67.74~20.04.1 linux-image-5.15.0-67-lowlatency 5.15.0-67.74~20.04.1 linux-image-5.15.0-67-lowlatency-64k 5.15.0-67.74~20.04.1 linux-image-aws 5.15.0.1031.35~20.04.20 linux-image-azure 5.15.0.1034.41~20.04.24 linux-image-gcp 5.15.0.1030.37~20.04.1 linux-image-generic-64k-hwe-20.04 5.15.0.67.74~20.04.28 linux-image-generic-hwe-20.04 5.15.0.67.74~20.04.28 linux-image-generic-lpae-hwe-20.04 5.15.0.67.74~20.04.28 linux-image-gke-5.15 5.15.0.1028.33~20.04.1 linux-image-lowlatency-64k-hwe-20.04 5.15.0.67.74~20.04.25 linux-image-lowlatency-hwe-20.04 5.15.0.67.74~20.04.25 linux-image-oracle 5.15.0.1030.36~20.04.1 linux-image-virtual-hwe-20.04 5.15.0.67.74~20.04.28 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5912-1 CVE-2022-3169, CVE-2022-3344, CVE-2022-3435, CVE-2022-3521, CVE-2022-3545, CVE-2022-4139, CVE-2022-42328, CVE-2022-42329, CVE-2022-4379, CVE-2022-45869, CVE-2022-47518, CVE-2022-47519, CVE-2022-47520, CVE-2022-47521, CVE-2023-0179, CVE-2023-0461, CVE-2023-0468 Package Information: https://launchpad.net/ubuntu/+source/linux/5.15.0-67.74 https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1031.35 https://launchpad.net/ubuntu/+source/linux-azure/5.15.0-1034.41 https://launchpad.net/ubuntu/+source/linux-azure-fde/5.15.0-1034.41.1 https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1030.37 https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1028.33 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-67.74 https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1030.36 https://launchpad.net/ubuntu/+source/linux-aws-5.15/5.15.0-1031.35~20.04.1 https://launchpad.net/ubuntu/+source/linux-azure-5.15/5.15.0-1034.41~20.04.1 https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1030.37~20.04.1 https://launchpad.net/ubuntu/+source/linux-gke-5.15/5.15.0-1028.33~20.04.1 https://launchpad.net/ubuntu/+source/linux-hwe-5.15/5.15.0-67.74~20.04.1 https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-67.74~20.04.1 https://launchpad.net/ubuntu/+source/linux-oracle-5.15/5.15.0-1030.36~20.04.1 . Attention Ubuntu 22.04 and 20.04 LTS users! A vital security alert about kernel vulnerabilities has been released. Update your systems now for maximum protection and performance. Kernel Security, Ubuntu 22.04 LTS, Denial Of Service, System Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 03, 2023 Critical Ubuntu
200

Scientific Linux: 2016:2588-2 Moderate OpenSSH Remote Code Execution Fix

Moderate: openssh security, bug fix, and enhancement update. Date: Wed, 14 Dec 2016 18:15:53 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Scott Reid Subject: Security ERRATA Moderate: openssh on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: openssh security, bug fix, and enhancement update Advisory ID: SLSA-2016:2588-2 Issue Date: 2016-11-03 CVE Numbers: CVE-2015-8325 -- Security Fix(es): * It was discovered that the OpenSSH sshd daemon fetched PAM environment settings before running the login program. In configurations with UseLogin=yes and the pam_env PAM module configured to read user environment settings, a local user could use this flaw to execute arbitrary code as root. (CVE-2015-8325) Additional Changes: -- SL7 x86_64 openssh-6.6.1p1-31.el7.x86_64.rpm openssh-askpass-6.6.1p1-31.el7.x86_64.rpm openssh-clients-6.6.1p1-31.el7.x86_64.rpm openssh-debuginfo-6.6.1p1-31.el7.x86_64.rpm openssh-keycat-6.6.1p1-31.el7.x86_64.rpm openssh-server-6.6.1p1-31.el7.x86_64.rpm openssh-debuginfo-6.6.1p1-31.el7.i686.rpm openssh-ldap-6.6.1p1-31.el7.x86_64.rpm openssh-server-sysvinit-6.6.1p1-31.el7.x86_64.rpm pam_ssh_agent_auth-0.9.3-9.31.el7.i686.rpm pam_ssh_agent_auth-0.9.3-9.31.el7.x86_64.rpm - Scientific Linux Development Team . An update to OpenSSH for Scientific Linux resolves a moderate security vulnerability. Several key improvements and bug fixes have been implemented.. scientific linux, openssh update, security advisory, bug fix. . LinuxSecurity.com Team

Calendar 2 Dec 14, 2016 Scientific Linux
98

Red Hat Enterprise Linux 6: RHSA-2015:0863-01 Moderate Glibc Overflow

Updated glibc packages that fix two security issues and one bug are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: glibc security and bug fix update Advisory ID: RHSA-2015:0863-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:0863.html Issue date: 2015-04-21 CVE Names: CVE-2013-7423 CVE-2015-1781 ==================================================================== 1. Summary: Updated glibc packages that fix two security issues and one bug are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The glibc packages provide the standard C libraries (libc), POSIX thread libraries (libpthread), standard math libraries (libm), and the Name Server Caching Daemon (nscd) used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. A buffer overflow flaw was found in the way glibc's gethostbyname_r() and other related functions computed the size of a buffer when passeda misaligned buffer as input. An attacker able to make an application call any of these functions with a misaligned buffer could use this flaw to crash the application or, potentially, execute arbitrary code with the permissions of the user running the application. (CVE-2015-1781) It was discovered that, under certain circumstances, glibc's getaddrinfo() function would send DNS queries to random file descriptors. An attacker could potentially use this flaw to send DNS queries to unintended recipients, resulting in information disclosure or data loss due to the application encountering corrupted data. (CVE-2013-7423) The CVE-2015-1781 issue was discovered by Arjun Shankar of Red Hat. This update also fixes the following bug: * Previously, the nscd daemon did not properly reload modified data when the user edited monitored nscd configuration files. As a consequence, nscd returned stale data to system processes. This update adds a system of inotify-based monitoring and stat-based backup monitoring for nscd configuration files. As a result, nscd now detects changes to its configuration files and reloads the data properly, which prevents it from returning stale data. (BZ#1194149) All glibc users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1187109 - CVE-2013-7423 glibc: getaddrinfo() writes DNS queries to random file descriptors under high load 1199525 - CVE-2015-1781 glibc: buffer overflow in gethostbyname_r() and related functions with misaligned buffer 6. Package List: Red Hat Enterprise Linux Desktop (v.6): Source: glibc-2.12-1.149.el6_6.7.src.rpm i386: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-headers-2.12-1.149.el6_6.7.i686.rpm glibc-utils-2.12-1.149.el6_6.7.i686.rpm nscd-2.12-1.149.el6_6.7.i686.rpm x86_64: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-2.12-1.149.el6_6.7.x86_64.rpm glibc-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.x86_64.rpm glibc-headers-2.12-1.149.el6_6.7.x86_64.rpm glibc-utils-2.12-1.149.el6_6.7.x86_64.rpm nscd-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: glibc-2.12-1.149.el6_6.7.src.rpm x86_64: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-2.12-1.149.el6_6.7.x86_64.rpm glibc-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.x86_64.rpm glibc-headers-2.12-1.149.el6_6.7.x86_64.rpm glibc-utils-2.12-1.149.el6_6.7.x86_64.rpm nscd-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v.6): x86_64: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: glibc-2.12-1.149.el6_6.7.src.rpm i386: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-headers-2.12-1.149.el6_6.7.i686.rpm glibc-utils-2.12-1.149.el6_6.7.i686.rpm nscd-2.12-1.149.el6_6.7.i686.rpm ppc64: glibc-2.12-1.149.el6_6.7.ppc.rpm glibc-2.12-1.149.el6_6.7.ppc64.rpm glibc-common-2.12-1.149.el6_6.7.ppc64.rpm glibc-debuginfo-2.12-1.149.el6_6.7.ppc.rpm glibc-debuginfo-2.12-1.149.el6_6.7.ppc64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.ppc.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.ppc64.rpm glibc-devel-2.12-1.149.el6_6.7.ppc.rpm glibc-devel-2.12-1.149.el6_6.7.ppc64.rpm glibc-headers-2.12-1.149.el6_6.7.ppc64.rpm glibc-utils-2.12-1.149.el6_6.7.ppc64.rpm nscd-2.12-1.149.el6_6.7.ppc64.rpm s390x: glibc-2.12-1.149.el6_6.7.s390.rpm glibc-2.12-1.149.el6_6.7.s390x.rpm glibc-common-2.12-1.149.el6_6.7.s390x.rpm glibc-debuginfo-2.12-1.149.el6_6.7.s390.rpm glibc-debuginfo-2.12-1.149.el6_6.7.s390x.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.s390.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.s390x.rpm glibc-devel-2.12-1.149.el6_6.7.s390.rpm glibc-devel-2.12-1.149.el6_6.7.s390x.rpm glibc-headers-2.12-1.149.el6_6.7.s390x.rpm glibc-utils-2.12-1.149.el6_6.7.s390x.rpm nscd-2.12-1.149.el6_6.7.s390x.rpm x86_64: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-2.12-1.149.el6_6.7.x86_64.rpm glibc-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.x86_64.rpm glibc-headers-2.12-1.149.el6_6.7.x86_64.rpm glibc-utils-2.12-1.149.el6_6.7.x86_64.rpm nscd-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm ppc64: glibc-debuginfo-2.12-1.149.el6_6.7.ppc.rpm glibc-debuginfo-2.12-1.149.el6_6.7.ppc64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.ppc.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.ppc64.rpm glibc-static-2.12-1.149.el6_6.7.ppc.rpm glibc-static-2.12-1.149.el6_6.7.ppc64.rpm s390x: glibc-debuginfo-2.12-1.149.el6_6.7.s390.rpm glibc-debuginfo-2.12-1.149.el6_6.7.s390x.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.s390.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.s390x.rpm glibc-static-2.12-1.149.el6_6.7.s390.rpm glibc-static-2.12-1.149.el6_6.7.s390x.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: glibc-2.12-1.149.el6_6.7.src.rpm i386: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-headers-2.12-1.149.el6_6.7.i686.rpm glibc-utils-2.12-1.149.el6_6.7.i686.rpm nscd-2.12-1.149.el6_6.7.i686.rpm x86_64: glibc-2.12-1.149.el6_6.7.i686.rpm glibc-2.12-1.149.el6_6.7.x86_64.rpm glibc-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-devel-2.12-1.149.el6_6.7.i686.rpm glibc-devel-2.12-1.149.el6_6.7.x86_64.rpm glibc-headers-2.12-1.149.el6_6.7.x86_64.rpm glibc-utils-2.12-1.149.el6_6.7.x86_64.rpm nscd-2.12-1.149.el6_6.7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.6): i386: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm x86_64: glibc-debuginfo-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-2.12-1.149.el6_6.7.x86_64.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.i686.rpm glibc-debuginfo-common-2.12-1.149.el6_6.7.x86_64.rpm glibc-static-2.12-1.149.el6_6.7.i686.rpm glibc-static-2.12-1.149.el6_6.7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2013-7423 https://access.redhat.com/security/cve/CVE-2015-1781 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. . Cautious notice regarding glibc updates addressing vulnerabilities and errors, along with recommendations for Red Hat systems.. Glibc Update, Red Hat Security, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar 2 Apr 21, 2015 Red Hat
172

Ubuntu 12.04 LTS USN-1941-1 Moderate: Kernel Issues Addressed

Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1941-1 September 06, 2013 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client. A remote attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2013-1059) Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that allows for privilege escalation. A local user could exploit this flaw to run commands as root when using the perf tool. (CVE-2013-1060) Jonathan Salwan discovered an information leak in the Linux kernel's cdrom driver. A local user can exploit this leak to obtain sensitive information from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164) A flaw was discovered in the Linux kernel when an IPv6 socket is used to connect to an IPv4 destination. An unprivileged local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-2232) An information leak was discovered in the IPSec key_socket implementation in the Linux kernel. An local user could exploit this flaw to examine potentially sensitive information in kernel memory. (CVE-2013-2234) Kees Cook discovered a format string vulnerability in the Linux kernel's disk block layer. A local user with administrator privileges could exploit this flaw to gain kernel privileges. (CVE-2013-2851) Hannes Frederic Sowa discovered a flaw in setsockopt UDP_CORK option in the Linux kernel's IPv6 stack. A local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-4162) Hannes Frederic Sowa discovered a flaw in the IPv6 subsystem of theLinux kernel when the IPV6_MTU setsockopt option has been specified in combination with the UDP_CORK option. A local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-4163) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: linux-image-3.2.0-53-generic 3.2.0-53.81 linux-image-3.2.0-53-generic-pae 3.2.0-53.81 linux-image-3.2.0-53-highbank 3.2.0-53.81 linux-image-3.2.0-53-omap 3.2.0-53.81 linux-image-3.2.0-53-powerpc-smp 3.2.0-53.81 linux-image-3.2.0-53-powerpc64-smp 3.2.0-53.81 linux-image-3.2.0-53-virtual 3.2.0-53.81 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. If you use linux-restricted-modules, you have to update that package as well to get modules which work with the new kernel version. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-server, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-1941-1 CVE-2013-1059, CVE-2013-1060, CVE-2013-2164, CVE-2013-2232, CVE-2013-2234, CVE-2013-2851, CVE-2013-4162, CVE-2013-4163 Package Information: https://launchpad.net/ubuntu/+source/linux/3.2.0-53.81 . Multiple vulnerabilities were addressed in the Linux kernel impacting Ubuntu 12.04 LTS users. It's crucial to update your system for enhanced security.. Linux Kernel, Ubuntu Security, Security Issues, System Update. . LinuxSecurity.com Team

Calendar 2 Sep 06, 2013 Ubuntu
172

Ubuntu 12.04 LTS: USN-1676-1 Critical AppArmor Chromium Profile Escape

A weakness was discovered in the example AppArmor profile for chromium-browser.. =========================================================================Ubuntu Security Notice USN-1676-1 December 19, 2012 AppArmor update ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: A weakness was discovered in the example AppArmor profile for chromium-browser. Software Description: - apparmor: Linux security system Details: Dan Rosenberg discovered that the example AppArmor profile for chromium-browser could be escaped by calling xdg-settings with a crafted environment. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: apparmor-profiles 2.7.102-0ubuntu3.7 Ubuntu 11.10: apparmor-profiles 2.7.0~beta1+bzr1774-1ubuntu2.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1676-1 https://bugs.launchpad.net/ubuntu/+source/apparmor/+bug/1045986 Package Information: https://launchpad.net/ubuntu/+source/apparmor/2.7.102-0ubuntu3.7 https://launchpad.net/ubuntu/+source/apparmor/2.7.0~beta1+bzr1774-1ubuntu2.2 . An identified vulnerability in the Chromium browser's AppArmor configuration affects various Ubuntu releases. Please update immediately.. AppArmor Security Update, Chromium Escape Issue, Critical Linux Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 19, 2012 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here