Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
203

Mageia 7 and 8: 2021-0295 Moderate Vulnerability in Kernel-Linus Detected

This kernel-linus update is based on upstream 5.10.46 and fixes atleast the following security issues: In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an . MGASA-2021-0295 - Updated kernel-linus packages fix security vulnerabilities Publication date: 28 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0295.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-33624, CVE-2021-34693 This kernel-linus update is based on upstream 5.10.46 and fixes atleast the following security issues: In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack (CVE-2021-33624). net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized. (CVE-2021-34693). For other upstream fixes, see the referenced changelog. References: - https://bugs.mageia.org/show_bug.cgi?id=29171 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.46 - https://www.cve.org/CVERecord?id=CVE-2021-33624 - https://www.cve.org/CVERecord?id=CVE-2021-34693 SRPMS: - 7/core/kernel-linus-5.10.46-1.mga7 - 8/core/kernel-linus-5.10.46-1.mga8 . Mageia's kernel-linus release resolves significant problems such as memory leaks and type confusion flaws.. kernel-linus update,mageia security advisory,local exploitation,system vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jun 28, 2021 Mageia
203

Mageia: 2019-0022 moderate: Coreutils Race Condition Exploitation

A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018). . MGASA-2019-0022 - Updated coreutils packages fix security vulnerabilities Publication date: 08 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0022.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-18018, CVE-2018-17942 A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018). A flaw was found in Gnulib before 2018-09-23. The convert_to_decimal function in vasnprintf.c has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing (CVE-2018-17942). References: - https://bugs.mageia.org/show_bug.cgi?id=23825 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/JK2ISMPYUEU3JS3L7AVXEHWCI56INCJJ/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/4ZP6L5HXDOVKYTM5ELLYE64H75MT4LZR/ - https://bugs.mageia.org/show_bug.cgi?id=22495 - https://bugs.mageia.org/show_bug.cgi?id=23825 - https://www.cve.org/CVERecord?id=CVE-2017-18018 - https://www.cve.org/CVERecord?id=CVE-2018-17942 SRPMS: - 6/core/coreutils-8.25-3.1.mga6 . MGASA-2023-0056 concerns significant weaknesses in libjpeg that could allow unauthorized image manipulation.. Coreutils Security Update, Mageia Advisories, Ownership Modification, Race Conditions, Security Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jan 08, 2019 Mageia
172

Ubuntu 10.10: USN-1293-1 Critical: Kernel Denial of Service Issues

Several security issues were fixed in the kernel.. =========================================================================Ubuntu Security Notice USN-1293-1 December 08, 2011 linux vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.10 Summary: Several security issues were fixed in the kernel. Software Description: - linux: Linux kernel Details: A bug was discovered in the XFS filesystem's handling of pathnames. A local attacker could exploit this to crash the system, leading to a denial of service, or gain root privileges. (CVE-2011-4077) Nick Bowler discovered the kernel GHASH message digest algorithm incorrectly handled error conditions. A local attacker could exploit this to cause a kernel oops. (CVE-2011-4081) A flaw was found in the Journaling Block Device (JBD). A local attacker able to mount ext3 or ext4 file systems could exploit this to crash the system, leading to a denial of service. (CVE-2011-4132) A bug was found in the way headroom check was performed in udp6_ufo_fragment() function. A remote attacker could use this flaw to crash the system. (CVE-2011-4326) Clement Lecigne discovered a bug in the HFS file system bounds checking. When a malformed HFS file system is mounted a local user could crash the system or gain root privileges. (CVE-2011-4330) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: linux-image-2.6.35-31-generic 2.6.35-31.63 linux-image-2.6.35-31-generic-pae 2.6.35-31.63 linux-image-2.6.35-31-omap 2.6.35-31.63 linux-image-2.6.35-31-powerpc 2.6.35-31.63 linux-image-2.6.35-31-powerpc-smp 2.6.35-31.63 linux-image-2.6.35-31-powerpc64-smp 2.6.35-31.63 linux-image-2.6.35-31-server 2.6.35-31.63 linux-image-2.6.35-31-versatile 2.6.35-31.63 linux-image-2.6.35-31-virtual 2.6.35-31.63 After astandard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1293-1 CVE-2011-4077, CVE-2011-4081, CVE-2011-4132, CVE-2011-4326, CVE-2011-4330 Package Information: https://launchpad.net/ubuntu/+source/linux/2.6.35-31.63 . =========================================================================Ubuntu Security Notice USN-. security, kernel, ==================================================. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 2011 Critical Ubuntu
200

Scientific Linux 5.x: CVE-2010-3847 Important Glibc Security Update

Important: glibc security update. Date: Thu, 21 Oct 2010 11:35:16 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Important: glibc on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Important: glibc security update Issue date: 2010-10-20 CVE Names: CVE-2010-3847 It was discovered that the glibc dynamic linker/loader did not handle the $ORIGIN dynamic string token set in the LD_AUDIT environment variable securely. A local attacker with write access to a file system containing setuid or setgid binaries could use this flaw to escalate their privileges. (CVE-2010-3847) SL 5.x SRPMS: glibc-2.5-49.el5_5.6.src.rpm i386: glibc-2.5-49.el5_5.6.i386.rpm glibc-2.5-49.el5_5.6.i686.rpm glibc-common-2.5-49.el5_5.6.i386.rpm glibc-devel-2.5-49.el5_5.6.i386.rpm glibc-headers-2.5-49.el5_5.6.i386.rpm glibc-utils-2.5-49.el5_5.6.i386.rpm nscd-2.5-49.el5_5.6.i386.rpm x86_64: glibc-2.5-49.el5_5.6.i686.rpm glibc-2.5-49.el5_5.6.x86_64.rpm glibc-common-2.5-49.el5_5.6.x86_64.rpm glibc-devel-2.5-49.el5_5.6.i386.rpm glibc-devel-2.5-49.el5_5.6.x86_64.rpm glibc-headers-2.5-49.el5_5.6.x86_64.rpm glibc-utils-2.5-49.el5_5.6.x86_64.rpm nscd-2.5-49.el5_5.6.x86_64.rpm -Connie Sieh -Troy Dawson . Essential glibc security patch tackles potential privilege elevation threats on SL5.x environments; prompt upgrade advised.. glibc Update, Scientific Linux Security, Privilege Escalation, Security Errata, Local Exploit Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 21, 2010 Important Scientific Linux
98

Red Hat: RHSA-2009:1672 Important: Kernel Exploit and DoS Fix

Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 5.2 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2009:1672-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1672.html Issue date: 2009-12-15 CVE Names: CVE-2009-2695 CVE-2009-3547 ==================================================================== 1. Summary: Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 5.2 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5.2.z server) - i386, ia64, noarch, ppc, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issues: * a system with SELinux enforced was more permissive in allowing local users in the unconfined_t domain to map low memory areas even if the mmap_min_addr restriction was enabled. This could aid in the local exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important) * a NULL pointer dereference flaw was found in each of the following functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could be released by other processes before it is used to update the pipe's reader and writer counters. This could lead to a local denial of service or privilege escalation. (CVE-2009-3547, Important) This update also fixes the followingbug: * a bug in the IPv6 implementation in the Linux kernel could have caused an unbalanced reference count. When using network bonding, this bug may have caused a hang when shutting the system down via "shutdown -h", or prevented the network service from being stopped via "service network stop". (BZ#538409) Users should upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 517830 - CVE-2009-2695 kernel: SELinux and mmap_min_addr 530490 - CVE-2009-3547 kernel: fs: pipe.c null pointer dereference 538409 - Unbalance reference count in ndisc_recv_ns [rhel-5.2.z] 6. Package List: Red Hat Enterprise Linux (v. 5.2.zserver): Source: kernel-2.6.18-92.1.32.el5.src.rpm i386: kernel-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-devel-2.6.18-92.1.32.el5.i686.rpm kernel-debug-2.6.18-92.1.32.el5.i686.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-debug-devel-2.6.18-92.1.32.el5.i686.rpm kernel-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.i686.rpm kernel-devel-2.6.18-92.1.32.el5.i686.rpm kernel-headers-2.6.18-92.1.32.el5.i386.rpm kernel-xen-2.6.18-92.1.32.el5.i686.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-xen-devel-2.6.18-92.1.32.el5.i686.rpm ia64: kernel-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.ia64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.ia64.rpm kernel-devel-2.6.18-92.1.32.el5.ia64.rpm kernel-headers-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-devel-2.6.18-92.1.32.el5.ia64.rpm noarch: kernel-doc-2.6.18-92.1.32.el5.noarch.rpm ppc: kernel-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.ppc64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.ppc64.rpm kernel-devel-2.6.18-92.1.32.el5.ppc64.rpm kernel-headers-2.6.18-92.1.32.el5.ppc.rpm kernel-headers-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-devel-2.6.18-92.1.32.el5.ppc64.rpm s390x: kernel-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-devel-2.6.18-92.1.32.el5.s390x.rpm kernel-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.s390x.rpm kernel-devel-2.6.18-92.1.32.el5.s390x.rpm kernel-headers-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-devel-2.6.18-92.1.32.el5.s390x.rpm x86_64: kernel-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.x86_64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.x86_64.rpm kernel-devel-2.6.18-92.1.32.el5.x86_64.rpm kernel-headers-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-devel-2.6.18-92.1.32.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2009-2695 https://access.redhat.com/security/cve/CVE-2009-3547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLJ8nSXlSAg2UNWIIRAuGnAJ9efdo7qm9BIyy6BShaIuL/xM/gYQCgmi+Q lJzYPF4hmKplmx4ibhEhB4Y=Q//E -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch and security enhancement update for CentOS Linux to resolve significant vulnerabilities.. Red Hat, Kernel Security, SELinux Fix, Bug Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 15, 2009 Important Red Hat
98

Red Hat Enterprise Linux 5.2 RHSA-2009:1672-01 Vital Kernel Security Update

Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 5.2 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2009:1672-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1672.html Issue date: 2009-12-15 CVE Names: CVE-2009-2695 CVE-2009-3547 ==================================================================== 1. Summary: Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 5.2 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5.2.z server) - i386, ia64, noarch, ppc, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issues: * a system with SELinux enforced was more permissive in allowing local users in the unconfined_t domain to map low memory areas even if the mmap_min_addr restriction was enabled. This could aid in the local exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important) * a NULL pointer dereference flaw was found in each of the following functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could be released by other processes before it is used to update the pipe's reader and writer counters. This could lead to a local denial of service or privilege escalation. (CVE-2009-3547, Important) This update also fixes the following bug: * a bug in the IPv6 implementation inthe Linux kernel could have caused an unbalanced reference count. When using network bonding, this bug may have caused a hang when shutting the system down via "shutdown -h", or prevented the network service from being stopped via "service network stop". (BZ#538409) Users should upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 517830 - CVE-2009-2695 kernel: SELinux and mmap_min_addr 530490 - CVE-2009-3547 kernel: fs: pipe.c null pointer dereference 538409 - Unbalance reference count in ndisc_recv_ns [rhel-5.2.z] 6. Package List: Red Hat Enterprise Linux (v. 5.2.zserver): Source: kernel-2.6.18-92.1.32.el5.src.rpm i386: kernel-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-PAE-devel-2.6.18-92.1.32.el5.i686.rpm kernel-debug-2.6.18-92.1.32.el5.i686.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-debug-devel-2.6.18-92.1.32.el5.i686.rpm kernel-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.i686.rpm kernel-devel-2.6.18-92.1.32.el5.i686.rpm kernel-headers-2.6.18-92.1.32.el5.i386.rpm kernel-xen-2.6.18-92.1.32.el5.i686.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.i686.rpm kernel-xen-devel-2.6.18-92.1.32.el5.i686.rpm ia64: kernel-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.ia64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.ia64.rpm kernel-devel-2.6.18-92.1.32.el5.ia64.rpm kernel-headers-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.ia64.rpm kernel-xen-devel-2.6.18-92.1.32.el5.ia64.rpm noarch: kernel-doc-2.6.18-92.1.32.el5.noarch.rpm ppc: kernel-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.ppc64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.ppc64.rpm kernel-devel-2.6.18-92.1.32.el5.ppc64.rpm kernel-headers-2.6.18-92.1.32.el5.ppc.rpm kernel-headers-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-debuginfo-2.6.18-92.1.32.el5.ppc64.rpm kernel-kdump-devel-2.6.18-92.1.32.el5.ppc64.rpm s390x: kernel-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-debug-devel-2.6.18-92.1.32.el5.s390x.rpm kernel-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.s390x.rpm kernel-devel-2.6.18-92.1.32.el5.s390x.rpm kernel-headers-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-debuginfo-2.6.18-92.1.32.el5.s390x.rpm kernel-kdump-devel-2.6.18-92.1.32.el5.s390x.rpm x86_64: kernel-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-debug-devel-2.6.18-92.1.32.el5.x86_64.rpm kernel-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-debuginfo-common-2.6.18-92.1.32.el5.x86_64.rpm kernel-devel-2.6.18-92.1.32.el5.x86_64.rpm kernel-headers-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-debuginfo-2.6.18-92.1.32.el5.x86_64.rpm kernel-xen-devel-2.6.18-92.1.32.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2009-2695 https://access.redhat.com/security/cve/CVE-2009-3547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. . Ubuntu announced a significant system patch that resolves vulnerabilities and includes a key bug correction. Update your system immediately!. Red Hat Enterprise Linux, Kernel Update, Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 15, 2009 Important Red Hat
98

Red Hat 5.3 RHSA-2009:1587 Important: Kernel Security Update

Updated kernel packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2009:1587-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1587.html Issue date: 2009-11-17 CVE Names: CVE-2009-2695 CVE-2009-3547 ==================================================================== 1. Summary: Updated kernel packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5.3.z server) - i386, ia64, noarch, ppc, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issues: * a system with SELinux enforced was more permissive in allowing local users in the unconfined_t domain to map low memory areas even if the mmap_min_addr restriction was enabled. This could aid in the local exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important) * a NULL pointer dereference flaw was found in each of the following functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could be released by other processes before it is used to update the pipe's reader and writer counters. This could lead to a local denial of service or privilege escalation. (CVE-2009-3547, Important) This update also fixes thefollowing bugs: * a caching bug in nfs_readdir() has been resolved. This may have caused parts of directory listings to become stale, as they came from cached data when they should not have, possibly causing NFS clients to see duplicate files or not see all files in a directory. (BZ#526959) * a bug prevented the pciehp driver from detecting PCI Express hot plug slots on some systems. (BZ#530381) * when a process attempted to read from a page that had first been accessed by writing to part of it (via write(2)), the NFS client needed to flush the modified portion of the page out to the server, and then read the entire page back in. This flush caused performance issues. (BZ#521243) * a deadlock was found in the cciss driver. In rare cases, this caused an NMI lockup during boot. Messages such as "cciss: controller cciss[x] failed, stopping." and "cciss[x]: controller not responding." may have been displayed on the console. (BZ#525728) Users should upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 517830 - CVE-2009-2695 kernel: SELinux and mmap_min_addr 521243 - Read/Write NFS I/O performance degraded by FLUSH_STABLE page flushing [rhel-5.3.z] 525728 - cciss: spinlock deadlock causes NMI on HP systems [rhel-5.3.z] 526959 - [NetApp 5.5 bug] nfs_readdir() may fail to return all the files in the directory [rhel-5.3.z] 530381 - [5.3] PCIe hotplug slot detection failure [rhel-5.3.z] 530490 - CVE-2009-3547 kernel: fs: pipe.c null pointer dereference 6. Package List: Red Hat Enterprise Linux (v. 5.3.zserver): Source: kernel-2.6.18-128.11.1.el5.src.rpm i386: kernel-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-devel-2.6.18-128.11.1.el5.i686.rpm kernel-debug-2.6.18-128.11.1.el5.i686.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-debug-devel-2.6.18-128.11.1.el5.i686.rpm kernel-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.i686.rpm kernel-devel-2.6.18-128.11.1.el5.i686.rpm kernel-headers-2.6.18-128.11.1.el5.i386.rpm kernel-xen-2.6.18-128.11.1.el5.i686.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-xen-devel-2.6.18-128.11.1.el5.i686.rpm ia64: kernel-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.ia64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.ia64.rpm kernel-devel-2.6.18-128.11.1.el5.ia64.rpm kernel-headers-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-devel-2.6.18-128.11.1.el5.ia64.rpm noarch: kernel-doc-2.6.18-128.11.1.el5.noarch.rpm ppc: kernel-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.ppc64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.ppc64.rpm kernel-devel-2.6.18-128.11.1.el5.ppc64.rpm kernel-headers-2.6.18-128.11.1.el5.ppc.rpm kernel-headers-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-devel-2.6.18-128.11.1.el5.ppc64.rpm s390x: kernel-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-devel-2.6.18-128.11.1.el5.s390x.rpm kernel-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.s390x.rpm kernel-devel-2.6.18-128.11.1.el5.s390x.rpm kernel-headers-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-devel-2.6.18-128.11.1.el5.s390x.rpm x86_64: kernel-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.x86_64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.x86_64.rpm kernel-devel-2.6.18-128.11.1.el5.x86_64.rpm kernel-headers-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-devel-2.6.18-128.11.1.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-2695 https://www.cve.org/CVERecord?id=CVE-2009-3547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLAsF1XlSAg2UNWIIRAn+QAJ9q1QgWep6/0FTG7iUtndIobPJ4JQCfQc5Y w5sHJL3QjRPyUPl6yzMMs08=EUzh -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Revised kernel updates for Red Hat 5.3 tackle critical security vulnerabilities and bugs needing prompt action.. Kernel Update, Red Hat Fixes, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 17, 2009 Important Red Hat
98

Red Hat: RHSA-2009:1587-01 Important: Kernel Security Update

Updated kernel packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security and bug fix update Advisory ID: RHSA-2009:1587-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1587.html Issue date: 2009-11-17 CVE Names: CVE-2009-2695 CVE-2009-3547 ==================================================================== 1. Summary: Updated kernel packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5.3.z server) - i386, ia64, noarch, ppc, s390x, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issues: * a system with SELinux enforced was more permissive in allowing local users in the unconfined_t domain to map low memory areas even if the mmap_min_addr restriction was enabled. This could aid in the local exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important) * a NULL pointer dereference flaw was found in each of the following functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could be released by other processes before it is used to update the pipe's reader and writer counters. This could lead to a local denial of service or privilege escalation. (CVE-2009-3547, Important) This update also fixes the following bugs: * a caching bug innfs_readdir() has been resolved. This may have caused parts of directory listings to become stale, as they came from cached data when they should not have, possibly causing NFS clients to see duplicate files or not see all files in a directory. (BZ#526959) * a bug prevented the pciehp driver from detecting PCI Express hot plug slots on some systems. (BZ#530381) * when a process attempted to read from a page that had first been accessed by writing to part of it (via write(2)), the NFS client needed to flush the modified portion of the page out to the server, and then read the entire page back in. This flush caused performance issues. (BZ#521243) * a deadlock was found in the cciss driver. In rare cases, this caused an NMI lockup during boot. Messages such as "cciss: controller cciss[x] failed, stopping." and "cciss[x]: controller not responding." may have been displayed on the console. (BZ#525728) Users should upgrade to these updated packages, which contain backported patches to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 517830 - CVE-2009-2695 kernel: SELinux and mmap_min_addr 521243 - Read/Write NFS I/O performance degraded by FLUSH_STABLE page flushing [rhel-5.3.z] 525728 - cciss: spinlock deadlock causes NMI on HP systems [rhel-5.3.z] 526959 - [NetApp 5.5 bug] nfs_readdir() may fail to return all the files in the directory [rhel-5.3.z] 530381 - [5.3] PCIe hotplug slot detection failure [rhel-5.3.z] 530490 - CVE-2009-3547 kernel: fs: pipe.c null pointer dereference 6. Package List: Red Hat Enterprise Linux (v. 5.3.zserver): Source: kernel-2.6.18-128.11.1.el5.src.rpm i386: kernel-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-PAE-devel-2.6.18-128.11.1.el5.i686.rpm kernel-debug-2.6.18-128.11.1.el5.i686.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-debug-devel-2.6.18-128.11.1.el5.i686.rpm kernel-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.i686.rpm kernel-devel-2.6.18-128.11.1.el5.i686.rpm kernel-headers-2.6.18-128.11.1.el5.i386.rpm kernel-xen-2.6.18-128.11.1.el5.i686.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.i686.rpm kernel-xen-devel-2.6.18-128.11.1.el5.i686.rpm ia64: kernel-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.ia64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.ia64.rpm kernel-devel-2.6.18-128.11.1.el5.ia64.rpm kernel-headers-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.ia64.rpm kernel-xen-devel-2.6.18-128.11.1.el5.ia64.rpm noarch: kernel-doc-2.6.18-128.11.1.el5.noarch.rpm ppc: kernel-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.ppc64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.ppc64.rpm kernel-devel-2.6.18-128.11.1.el5.ppc64.rpm kernel-headers-2.6.18-128.11.1.el5.ppc.rpm kernel-headers-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-debuginfo-2.6.18-128.11.1.el5.ppc64.rpm kernel-kdump-devel-2.6.18-128.11.1.el5.ppc64.rpm s390x: kernel-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-debug-devel-2.6.18-128.11.1.el5.s390x.rpm kernel-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.s390x.rpm kernel-devel-2.6.18-128.11.1.el5.s390x.rpm kernel-headers-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-debuginfo-2.6.18-128.11.1.el5.s390x.rpm kernel-kdump-devel-2.6.18-128.11.1.el5.s390x.rpm x86_64: kernel-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-debug-devel-2.6.18-128.11.1.el5.x86_64.rpm kernel-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-debuginfo-common-2.6.18-128.11.1.el5.x86_64.rpm kernel-devel-2.6.18-128.11.1.el5.x86_64.rpm kernel-headers-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-debuginfo-2.6.18-128.11.1.el5.x86_64.rpm kernel-xen-devel-2.6.18-128.11.1.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-2695 https://www.cve.org/CVERecord?id=CVE-2009-3547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. . Latest kernel updates for RHEL address critical vulnerabilities and fix numerous bugs affecting system performance.. Red Hat Kernel Update, Security Fix, SELinux Issue, System Bug, Kernel Package. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 17, 2009 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200