Explore top 10 tips to secure your open-source projects now. Read More
×MGASA-2026-0149 - Updated perl-WWW-Mechanize-Cached, perl-File-XDG & perl-Path-Tiny packages fix security vulnerabilities. MGASA-2026-0149 - Updated perl-WWW-Mechanize-Cached, perl-File-XDG & perl-Path-Tiny packages fix security vulnerabilities Publication date: 18 May 2026 URL: https://advisories.mageia.org/MGASA-2026-0149.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-8612 Description: WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code execution. References: - https://bugs.mageia.org/show_bug.cgi?id=35533 - https://www.openwall.com/lists/oss-security/2026/05/15/1 - https://metacpan.org/release/OALDERS/WWW-Mechanize-Cached-2.00/changes - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-8612 SRPMS: - 9/core/perl-WWW-Mechanize-Cached-2.0.0-1.mga9 - 9/core/perl-Path-Tiny-0.150.0-1.mga9 - 9/core/perl-File-XDG-1.30.0-1.mga9 . Mageia updates perl-WWW-Mechanize-Cached to fix security flaws allowing local response forgery and code execution.. perl WWW Mechanize Cached Mageia security local threat. . Severity: Critical. LinuxSecurity.com Team
Moderate: kernel security update. {"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2024:8162","synopsis":"Moderate: kernel security update","severity":"SEVERITY_MODERATE","topic":"An update is available for kernel.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: Local information disclosure on Intel(R) Atom(R) processors (CVE-2023-28746)\n\n* kernel: netfilter: nft_flow_offload: reset dst in route object after setting up flow (CVE-2024-27403)\n\n* kernel: Revert "net\/mlx5: Block entering switchdev mode with ns inconsistency" (CVE-2023-52658)\n\n* kernel: dmaengine: idxd: Fix oops during rmmod on single-CPU platforms (CVE-2024-35989)\n\n* kernel: hwmon: (w83792d) Fix NULL pointer dereference by removing unnecessary structure field (CVE-2021-47385)\n\n* kernel: mptcp: ensure snd_nxt is properly initialized on connect (CVE-2024-36889)\n\n* kernel: net: sched: sch_multiq: fix possible OOB write in multiq_tune() (CVE-2024-36978)\n\n* kernel: net\/mlx5: Add a timeout to acquire the command queue semaphore (CVE-2024-38556)\n\n* kernel: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked (CVE-2024-39483)\n\n* kernel: ionic: fix use after netif_napi_del() (CVE-2024-39502)\n\n* kernel: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() (CVE-2024-40959)\n\n* kernel: gfs2: Fix NULL pointer dereference in gfs2_log_flush (CVE-2024-42079)\n\n* kernel: sched: act_ct: take care of padding in struct zones_ht_key (CVE-2024-42272)\n\n* kernel: tipc: Return non-zero value from tipc_udp_addr2str() on error (CVE-2024-42284)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Referencessection.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[{"ticket":"2270700","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2270700","description":""},{"ticket":"2281127","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281127","description":""},{"ticket":"2281149","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281149","description":""},{"ticket":"2281847","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2281847","description":""},{"ticket":"2282355","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2282355","description":""},{"ticket":"2284571","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2284571","description":""},{"ticket":"2293078","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293078","description":""},{"ticket":"2293443","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2293443","description":""},{"ticket":"2295921","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2295921","description":""},{"ticket":"2297474","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297474","description":""},{"ticket":"2297543","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2297543","description":""},{"ticket":"2300517","sourceBy":"RedHat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2300517","description":""}],"cves":[{"name":"CVE-2021-47385","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2021-47385","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2023-28746","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-28746","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2023-52658","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-52658","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-27403","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-27403","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-35989","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-35989","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36889","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36889","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-36978","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-36978","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-38556","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-38556","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-39483","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-39483","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-39502","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-39502","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-40959","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-40959","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42079","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42079","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42272","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42272","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"},{"name":"CVE-2024-42284","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-42284","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-10-25T17:17:17.459405Z","rpms":{"Rocky Linux9":{"nvras":["kernel-doc-0:5.14.0-427.40.1.el9_4.noarch.rpm","bpftool-0:7.3.0-427.40.1.el9_4.aarch64.rpm","bpftool-0:7.3.0-427.40.1.el9_4.ppc64le.rpm","bpftool-0:7.3.0-427.40.1.el9_4.s390x.rpm","bpftool-0:7.3.0-427.40.1.el9_4.x86_64.rpm","bpftool-debuginfo-0:7.3.0-427.40.1.el9_4.aarch64.rpm","bpftool-debuginfo-0:7.3.0-427.40.1.el9_4.ppc64le.rpm","bpftool-debuginfo-0:7.3.0-427.40.1.el9_4.s390x.rpm","bpftool-debuginfo-0:7.3.0-427.40.1.el9_4.x86_64.rpm","kernel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-0:5.14.0-427.40.1.el9_4.src.rpm","kernel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-64k-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-devel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-devel-matched-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-modules-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-modules-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-debug-modules-extra-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-devel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-devel-matched-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-modules-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-modules-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-64k-modules-extra-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-abi-stablelists-0:5.14.0-427.40.1.el9_4.noarch.rpm","kernel-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-core-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-cross-headers-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-cross-headers-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-cross-headers-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-cross-headers-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-core-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-devel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-devel-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-devel-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-devel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-devel-matched-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-devel-matched-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-devel-matched-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-devel-matched-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-modules-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-modules-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-modules-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-modules-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-modules-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-modules-core-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-modules-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-modules-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-modules-extra-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-debug-modules-extra-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-debug-modules-extra-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-debug-modules-extra-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-debug-uki-virt-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-devel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-devel-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-devel-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-devel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-devel-matched-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-devel-matched-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-devel-matched-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-devel-matched-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-headers-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-headers-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-headers-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-headers-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-modules-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-modules-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-modules-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-modules-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-modules-core-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-modules-core-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-modules-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-modules-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-modules-extra-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-modules-extra-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-modules-extra-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-modules-extra-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-devel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-kvm-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-modules-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-modules-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-debug-modules-extra-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-devel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-kvm-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-modules-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-modules-core-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-rt-modules-extra-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-tools-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-tools-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-tools-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-tools-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-tools-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-tools-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-tools-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-tools-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-tools-libs-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-tools-libs-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-tools-libs-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-tools-libs-devel-0:5.14.0-427.40.1.el9_4.aarch64.rpm","kernel-tools-libs-devel-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","kernel-tools-libs-devel-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-uki-virt-0:5.14.0-427.40.1.el9_4.x86_64.rpm","kernel-zfcpdump-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-devel-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-devel-matched-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-modules-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-modules-core-0:5.14.0-427.40.1.el9_4.s390x.rpm","kernel-zfcpdump-modules-extra-0:5.14.0-427.40.1.el9_4.s390x.rpm","libperf-0:5.14.0-427.40.1.el9_4.aarch64.rpm","libperf-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","libperf-0:5.14.0-427.40.1.el9_4.s390x.rpm","libperf-0:5.14.0-427.40.1.el9_4.x86_64.rpm","libperf-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","libperf-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","libperf-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","libperf-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","perf-0:5.14.0-427.40.1.el9_4.aarch64.rpm","perf-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","perf-0:5.14.0-427.40.1.el9_4.s390x.rpm","perf-0:5.14.0-427.40.1.el9_4.x86_64.rpm","perf-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","perf-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","perf-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","perf-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","python3-perf-0:5.14.0-427.40.1.el9_4.aarch64.rpm","python3-perf-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","python3-perf-0:5.14.0-427.40.1.el9_4.s390x.rpm","python3-perf-0:5.14.0-427.40.1.el9_4.x86_64.rpm","python3-perf-debuginfo-0:5.14.0-427.40.1.el9_4.aarch64.rpm","python3-perf-debuginfo-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","python3-perf-debuginfo-0:5.14.0-427.40.1.el9_4.s390x.rpm","python3-perf-debuginfo-0:5.14.0-427.40.1.el9_4.x86_64.rpm","rtla-0:5.14.0-427.40.1.el9_4.aarch64.rpm","rtla-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","rtla-0:5.14.0-427.40.1.el9_4.s390x.rpm","rtla-0:5.14.0-427.40.1.el9_4.x86_64.rpm","rv-0:5.14.0-427.40.1.el9_4.aarch64.rpm","rv-0:5.14.0-427.40.1.el9_4.ppc64le.rpm","rv-0:5.14.0-427.40.1.el9_4.s390x.rpm","rv-0:5.14.0-427.40.1.el9_4.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. A critical system patch has been released for Rocky Linux 9 to address local vulnerabilities, notably those related to potential information leaks.. kernel security update, Rocky Linux patch, moderate security advisory. . LinuxSecurity.com Team
* bsc#1213584 * bsc#1215097 * bsc#1215442 * bsc#1215519 * bsc#1215971 . # Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP5) Announcement ID: SUSE-SU-2023:4848-1 Rating: important References: * bsc#1213584 * bsc#1215097 * bsc#1215442 * bsc#1215519 * bsc#1215971 Cross-References: * CVE-2023-2163 * CVE-2023-3610 * CVE-2023-3777 * CVE-2023-4622 * CVE-2023-5345 CVSS scores: * CVE-2023-2163 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2023-2163 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2023-3610 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3777 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3777 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-4622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-4622 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-5345 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro 6.0 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the Linux Kernel5.14.21-150500_55_19 fixes several issues. The following security issues were fixed: * CVE-2023-3610: Fixed use-after-free vulnerability in nf_tables can be exploited to achieve local privilege escalation (bsc#1213584). * CVE-2023-3777: Fixed a use-after-free vulnerability in netfilter: nf_tables component can be exploited to achieve local privilege escalation. (bsc#1215097) * CVE-2023-5345: Fixed an use-after-free vulnerability in the fs/smb/client component which could be exploited to achieve local privilege escalation. (bsc#1215971) * CVE-2023-4622: Fixed a use-after-free vulnerability in the Unix domain sockets component which could be exploited to achieve local privilege escalation (bsc#1215442). * CVE-2023-2163: Fixed an incorrect verifier pruning in BPF that could lead to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape. (bsc#1215519) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-4857=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2023-4857=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-4848=1 SUSE-SLE- Module-Live-Patching-15-SP4-2023-4851=1 SUSE-SLE-Module-Live- Patching-15-SP4-2023-4858=1 SUSE-SLE-Module-Live-Patching-15-SP4-2023-4859=1 SUSE-SLE-Module-Live-Patching-15-SP4-2023-4865=1 SUSE-SLE-Module-Live- Patching-15-SP4-2023-4856=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4851=1 SUSE-2023-4858=1 SUSE-2023-4859=1 SUSE-2023-4865=1 SUSE-2023-4856=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_19-default-4-150500.2.1 *kernel-livepatch-SLE15-SP5_Update_3-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_55_19-default-debuginfo-4-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_19-default-4-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_3-debugsource-4-150500.2.1 * kernel-livepatch-5_14_21-150500_55_19-default-debuginfo-4-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (x86_64) * kernel-livepatch-SLE15-SP4-RT_Update_1-debugsource-12-150400.2.2 * kernel-livepatch-5_14_21-150400_15_5-rt-debuginfo-12-150400.2.2 * kernel-livepatch-5_14_21-150400_15_5-rt-12-150400.2.2 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_14-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_46-default-10-150400.2.2 * kernel-livepatch-5_14_21-150400_24_38-default-debuginfo-12-150400.2.2 * kernel-livepatch-SLE15-SP4_Update_13-debugsource-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_6-debugsource-12-150400.2.2 * kernel-livepatch-SLE15-SP4_Update_10-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_69-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_66-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_46-default-debuginfo-10-150400.2.2 * kernel-livepatch-5_14_21-150400_24_66-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_38-default-12-150400.2.2 * kernel-livepatch-5_14_21-150400_24_69-default-debuginfo-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_8-debugsource-10-150400.2.2 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_14-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_46-default-10-150400.2.2 *kernel-livepatch-5_14_21-150400_24_38-default-debuginfo-12-150400.2.2 * kernel-livepatch-SLE15-SP4_Update_13-debugsource-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_6-debugsource-12-150400.2.2 * kernel-livepatch-SLE15-SP4_Update_10-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_69-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_66-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_46-default-debuginfo-10-150400.2.2 * kernel-livepatch-5_14_21-150400_24_66-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_55-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_38-default-12-150400.2.2 * kernel-livepatch-5_14_21-150400_24_69-default-debuginfo-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_8-debugsource-10-150400.2.2 ## References: * https://www.suse.com/security/cve/CVE-2023-2163.html * https://www.suse.com/security/cve/CVE-2023-3610.html * https://www.suse.com/security/cve/CVE-2023-3777.html * https://www.suse.com/security/cve/CVE-2023-4622.html * https://www.suse.com/security/cve/CVE-2023-5345.html * https://bugzilla.suse.com/show_bug.cgi?id=1213584 * https://bugzilla.suse.com/show_bug.cgi?id=1215097 * https://bugzilla.suse.com/show_bug.cgi?id=1215442 * https://bugzilla.suse.com/show_bug.cgi?id=1215519 * https://bugzilla.suse.com/show_bug.cgi?id=1215971 . Essential firmware upgrade for Linux Kernel Live Patch 3 resolves various serious security flaws impacting SLE 15.. Linux Kernel Update, SUSE Patching, Privilege Escalation. . Severity: Important. LinuxSecurity.com Team
GNOME Shell could be made to expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-6395-1 September 21, 2023 gnome-shell vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 Summary: GNOME Shell could be made to expose sensitive information. Software Description: - gnome-shell: graphical shell for the GNOME desktop Details: Mickael Karatekin discovered that GNOME Shell incorrectly allowed the screenshot tool to view open windows when a session was locked. A local attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: gnome-shell 44.3-0ubuntu1.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6395-1 CVE-2023-43090 Package Information: https://launchpad.net/ubuntu/+source/gnome-shell/44.3-0ubuntu1.1 . The Ubuntu Security Advisory USN-6396-1 highlights a vulnerability in the GNOME Desktop environment that may lead to unauthorized data exposure, necessitating immediate updates.. GNOME Shell, Security Update, Sensitive Information, Local Attack, Ubuntu Security Notice. . Severity: Low. LinuxSecurity.com Team
Local users can destroy the contents of any file on any mounted filesystem. . -----BEGIN PGP SIGNED MESSAGE------ --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: New openldap packages. Advisory ID: RHSA-2000:012-05 Issue date: 2000-04-13 Updated on: 2000-04-21 Product: Red Hat Linux Keywords: openldap startup symlink overwrite denial Cross references: N/A - ---------------------------------------------------------------------1. Topic: New openldap packages are available which fix a security vulnerability in Red Hat Linux 6.1 and 6.2. 2. Relevant releases/architectures: Red Hat Linux 6.1 - i386 alpha sparc Red Hat Linux 6.2 - i386 alpha sparc 3. Problem description: OpenLDAP follows symbolic links when creating files. The default location for these files is /usr/tmp, which is a symlink to /tmp, which in turn is a world-writable directory. Local users can destroy the contents of any file on any mounted filesystem. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. Administrators with existing databases should also move their NEXTID and *.dbb files from /usr/tmp to /var/lib/ldap, and verify that the 'directory' setting in /etc/openldap/slapd.conf is changed accordingly. 5. Bug IDs fixed ( for more info): 10714 - Insecure file creation using static files which follow symlinks. 6. Obsoleted by: N/A 7. Conflicts with: N/A 8. RPMs required: Red Hat Linux 6.1: intel: alpha: sparc: sources: Red Hat Linux 6.2: intel: alpha: sparc: sources: 9. Verification: MD5 sum Package Name - --------------------------------------------------------------------------fa79c61565a72407db4695ef8468a482 6.1/alpha/openldap-1.2.9-6.alpha.rpm 058c4aa63710da7490f98da4b3cad53d 6.1/i386/openldap-1.2.9-6.i386.rpm 17fbdb33172a7884f56b4fc746b1b763 6.1/SRPMS/openldap-1.2.9-6.src.rpm 816fccd85990833f7c5dfb7f2dc6e0a1 6.1/sparc/openldap-1.2.9-6.sparc.rpm fa79c61565a72407db4695ef8468a482 6.2/alpha/openldap-1.2.9-6.alpha.rpm 816fccd85990833f7c5dfb7f2dc6e0a1 6.2/sparc/openldap-1.2.9-6.sparc.rpm 17fbdb33172a7884f56b4fc746b1b763 6.2/SRPMS/openldap-1.2.9-6.src.rpm 058c4aa63710da7490f98da4b3cad53d 6.2/i386/openldap-1.2.9-6.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 10. References: Thanks also go to Stan Bubrouski for reporting this problem. Cristian - --- ----------------------------------------------------------------------Cristian Gafton --
Two vulnerabilities have been fixed in sqlite (V2) which which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3431-1
A security issue was fixed in Intel Microcode.. =========================================================================Ubuntu Security Notice USN-5612-1 September 15, 2022 intel-microcode vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: A security issue was fixed in Intel Microcode. Software Description: - intel-microcode: Processor microcode for Intel CPUs Details: Pietro Borrello, Andreas Kogler, Martin Schwarzl, Daniel Gruss, Michael Schwarz and Moritz Lipp discovered that some Intel processors did not properly clear data between subsequent xAPIC MMIO reads. This could allow a local attacker to compromise SGX enclaves. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: intel-microcode 3.20220809.0ubuntu0.22.04.1 Ubuntu 20.04 LTS: intel-microcode 3.20220809.0ubuntu0.20.04.1 Ubuntu 18.04 LTS: intel-microcode 3.20220809.0ubuntu0.18.04.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5612-1 CVE-2022-21233 Package Information: https://launchpad.net/ubuntu/+source/intel-microcode/3.20220809.0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/intel-microcode/3.20220809.0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/intel-microcode/3.20220809.0ubuntu0.18.04.1 . A critical vulnerability in Intel microcode has been patched for Ubuntu versions. Make sure your devices are current and protected.. Intel Microcode Update, Ubuntu Security Advisory, Intel Processor Issue. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for canna ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10090-1 Rating: important References: #1199280 Cross-References: CVE-2022-21950 CVSS scores: CVE-2022-21950 (SUSE): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for canna fixes the following issues: - CVE-2022-21950: move UNIX socket dir from /tmp to /run to avoid local attackers being able to place bogus directories in its stead. Use systemd-tmpfiles for cleaning old sockets (boo#1199280). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10090=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): canna-3.7p3-bp153.2.3.1 canna-devel-3.7p3-bp153.2.3.1 canna-libs-3.7p3-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (aarch64_ilp32): canna-libs-64bit-3.7p3-bp153.2.3.1 - openSUSE Backports SLE-15-SP3 (x86_64): canna-libs-32bit-3.7p3-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-21950.html https://bugzilla.suse.com/1199280 . Critical patch released for canna service addressing socket directory flaw affecting openSUSE installations.. openSUSE Backports, canna issue, socket vulnerability, systemd-tmpfiles. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.