Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ba86bed822 2025-06-03 01:26:45.079792+00:00 -------------------------------------------------------------------------------- Name : systemd Product : Fedora 41 Version : 256.15 Release : 1.fc41 URL : https://systemd.io Summary : System and Service Manager Description : systemd is a system and service manager that runs as PID 1 and starts the rest of the system. It provides aggressive parallelization capabilities, uses socket and D-Bus activation for starting services, offers on-demand starting of daemons, keeps track of processes using Linux control groups, maintains mount and automount points, and implements an elaborate transactional dependency-based service control logic. systemd supports SysV and LSB init scripts and works as a replacement for sysvinit. Other parts of this package are a logging daemon, utilities to control basic system configuration like the hostname, date, locale, maintain a list of logged-in users, system accounts, runtime directories and settings, and a logging daemons. This package was built from the v256-stable branch of systemd. -------------------------------------------------------------------------------- Update Information: Fix for local information disclosure in systemd-coredump (CVE-2025-4598) Various other fixes -------------------------------------------------------------------------------- ChangeLog: * Thu May 29 2025 Zbigniew JÄdrzejewski-Szmek - 256.15-1 - Version 257.6 - Fix for local information disclosure in systemd-coredump (CVE-2025-4598) - Various other fixes * Thu May 15 2025 Zbigniew JÄdrzejewski-Szmek - 256.13-1 - Version 256.13 - Various small fixes in multiple components -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369245 - CVE-2025-4598systemd: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2369245 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ba86bed822' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Resolution for exposure of local data in systemd-coredump on Fedora 41, alongside numerous additional enhancements.. systemd security, Fedora update, information disclosure, local attack, systemd-coredump. . Severity: Critical. LinuxSecurity.com Team
- fixed permissions of initramfs file, if microcode is prepended (CVE-2016-8637). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-cc5006bef7 2016-11-19 18:59:18.559792 -------------------------------------------------------------------------------- Name : dracut Product : Fedora 25 Version : 044 Release : 78.fc25 URL : https://github.com/dracutdevs/dracut/wiki/ Summary : Initramfs generator using udev Description : dracut contains tools to create a bootable initramfs for 2.6 Linux kernels. Unlike existing implementations, dracut does hard-code as little as possible into the initramfs. dracut contains various modules which are driven by the event-based udev. Having root on MD, DM, LVM2, LUKS is supported as well as NFS, iSCSI, NBD, FCoE with the dracut-network package. -------------------------------------------------------------------------------- Update Information: - fixed permissions of initramfs file, if microcode is prepended (CVE-2016-8637) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1392435 - CVE-2016-8637 dracut: Local information disclosure of initramfs when early cpio is used [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1392435 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade dracut' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated thermostat1-thermostat packages that fix one security issue are now available for Red Hat Software Collections 1. Red Hat Product Security has rated this update as having Important security [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Important: thermostat1-thermostat security update Advisory ID: RHSA-2014:2000-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2014:2000.html Issue date: 2014-12-16 CVE Names: CVE-2014-8120 ==================================================================== 1. Summary: Updated thermostat1-thermostat packages that fix one security issue are now available for Red Hat Software Collections 1. Red Hat Product Security has rated this update as having Important security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Software Collections 1 for Red Hat Enterprise Linux Server (v. 6) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Server (v. 7) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v. 6.4) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v. 6.5) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v. 6.6) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Workstation (v. 6) - noarch, x86_64 Red Hat Software Collections 1 for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Thermostat is a monitoring and instrumentation tool for the OpenJDK HotSpot Java Virtual Machine (JVM) with support for monitoring multiple JVM instances. It was discovered that, in certain configurations, the Thermostat agent disclosed JMX management URLs of alllocal Java virtual machines to any local user. A local, unprivileged user could use this flaw to escalate their privileges on the system. (CVE-2014-8120) This issue was discovered by Elliott Baron of Red Hat. All thermostat1-thermostat users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1168977 - CVE-2014-8120 thermostat: local JMX URL disclosure 6. Package List: Red Hat Software Collections 1 for Red Hat Enterprise Linux Server (v. 6): Source: thermostat1-thermostat-1.0.4-60.6.el6.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-60.6.el6.noarch.rpm thermostat1-thermostat-webapp-1.0.4-60.6.el6.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-60.6.el6.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-60.6.el6.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v. 6.4): Source: thermostat1-thermostat-1.0.4-60.6.el6.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-60.6.el6.noarch.rpm thermostat1-thermostat-webapp-1.0.4-60.6.el6.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-60.6.el6.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-60.6.el6.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v. 6.5): Source: thermostat1-thermostat-1.0.4-60.6.el6.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-60.6.el6.noarch.rpm thermostat1-thermostat-webapp-1.0.4-60.6.el6.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-60.6.el6.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-60.6.el6.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Server EUS (v.6.6): Source: thermostat1-thermostat-1.0.4-60.6.el6.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-60.6.el6.noarch.rpm thermostat1-thermostat-webapp-1.0.4-60.6.el6.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-60.6.el6.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-60.6.el6.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Workstation (v. 6): Source: thermostat1-thermostat-1.0.4-60.6.el6.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-60.6.el6.noarch.rpm thermostat1-thermostat-webapp-1.0.4-60.6.el6.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-60.6.el6.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-60.6.el6.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Server (v. 7): Source: thermostat1-thermostat-1.0.4-70.6.el7.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-70.6.el7.noarch.rpm thermostat1-thermostat-webapp-1.0.4-70.6.el7.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-70.6.el7.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-70.6.el7.x86_64.rpm Red Hat Software Collections 1 for Red Hat Enterprise Linux Workstation (v. 7): Source: thermostat1-thermostat-1.0.4-70.6.el7.src.rpm noarch: thermostat1-thermostat-javadoc-1.0.4-70.6.el7.noarch.rpm thermostat1-thermostat-webapp-1.0.4-70.6.el7.noarch.rpm x86_64: thermostat1-thermostat-1.0.4-70.6.el7.x86_64.rpm thermostat1-thermostat-debuginfo-1.0.4-70.6.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2014-8120 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2014 Red Hat, Inc. . Red Hat has released a critical advisory regarding an update for thermostat2-thermostat that tackles the issue of exposing local JMX URLs.. Thermostat SecurityUpdate, Red Hat Advisory, JMX Issue, System Security, Software Update. . Severity: Important. LinuxSecurity.com Team
Low: ecryptfs-utils security, bug fix, and enhancement update. Date: Wed, 11 Nov 2009 15:41:40 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Low: ecryptfs-utils on SL5.x i386/x86_64 Comments: To: "
New wicd packages are available for Slackware 12.2 and -current to fix a security issue with the D-Bus configuration file that could allow local information disclosure (such as network credentials). More details about this issue may be found in the Common . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] wicd (SSA:2009-040-01) New wicd packages are available for Slackware 12.2 and -current to fix a security issue with the D-Bus configuration file that could allow local information disclosure (such as network credentials). More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2009-0489 Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/wicd/wicd-1.5.9-noarch-1.tgz: Upgraded to wicd-1.5.9. This fixes a security problem with the D-Bus configuration file that allows local users to intercept D-Bus messages, possibly including wireless network credentials. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0489 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 12.2: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 12.2 package: 503d6dd8cce8fe148d6799727a51f5a6 wicd-1.5.9-noarch-1_slack12.2.tgz Slackware -current package: f98aab4483d4aa1f6c16c4517e560b81 wicd-1.5.9-noarch-1.tgz Installationinstructions: +------------------------+ Kill any instances of wicd-client: # killall wicd-client Upgrade the package as root: # upgradepkg wicd-1.5.9-noarch-1_slack12.2.tgz Reload D-Bus: # /etc/rc.d/rc.messagebus reload Restart wicd: # /etc/rc.d/rc.wicd restart Finally, restart any stopped instances of wicd-client as the normal user(s). Alternate approach: Upgrade the wicd package and reboot. +-----+ . Patch issued for sensitive data exposure in wicd D-Bus setup, applicable for Slackware 12.2 and rolling updates.. wicd Update, Slackware Security, D-Bus Vulnerability, Software Patch. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.