Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update to 1.28.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-29f4f47ade 2026-04-16 00:53:32.960281+00:00 -------------------------------------------------------------------------------- Name : micropython Product : Fedora 43 Version : 1.28.0 Release : 1.fc43 URL : http://micropython.org/ Summary : Implementation of Python 3 with very low memory footprint Description : Implementation of Python 3 with very low memory footprint -------------------------------------------------------------------------------- Update Information: Update to 1.28.0 -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 6 2026 Lumr Balhar - 1.28.0-1 - Update to 1.28.0 - Security fix for CVE-2026-1998 - Update mbedtls submodule to 3.6.6 - mbedtls security fixes for CVE-2026-25834, CVE-2026-34871, CVE-2026-25833 - CVE-2025-52496, CVE-2025-52497, CVE-2025-49087, CVE-2025-54764, CVE-2025-59438 Resolves: rhbz#2455368, rhbz#2376688, rhbz#2376701, rhbz#2382261, rhbz#2405245, rhbz#2405374, rhbz#2437327, rhbz#2454032, rhbz#2454086, rhbz#2454213 * Fri Jan 16 2026 Fedora Release Engineering - 1.27.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2376688 - CVE-2025-52496 micropython: Mbed TLS AESNI Race Condition Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2376688 [ 2 ] Bug #2376701 - CVE-2025-52497 micropython: Mbed TLS PEM Parsing Buffer Underflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2376701 [ 3 ] Bug #2382261 - CVE-2025-49087 micropython: Mbed TLS PKCS#7 Timing Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2382261 [ 4 ] Bug #2405245 - CVE-2025-54764 micropython: Mbedtls timing attacks in RSA operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2405245 [ 5 ] Bug #2405374 - CVE-2025-59438 micropython: MbedTLS Padding oracle through timing of cipher error reporting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2405374 [ 6 ] Bug #2437327 - CVE-2026-1998 micropython: micropython runtime.c mp_import_all memory corruption [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2437327 [ 7 ] Bug #2454032 - CVE-2026-25833 micropython: buffer underflow in x509_inet_pton_ipv6() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454032 [ 8 ] Bug #2454086 - CVE-2026-34871 micropython: entropy on Linux can fall back to /dev/urandom [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454086 [ 9 ] Bug #2454213 - CVE-2026-25834 micropython: Mbed TLS: Algorithm downgrade vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454213 [ 10 ] Bug #2455368 - micropython-1.28.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455368 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-29f4f47ade' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Update to Micropython 1.28.0 resolves memory corruption and mbedtls issues in Fedora 43. Install via dnf update.. Micropython Update, Fedora 43 Security, Memory Corruption Fix, Mbedtls Vulnerability, Linux Application. . Severity: Important. LinuxSecurity.com Team
* bsc#1198146 Cross-References: * CVE-2022-1210 . # Security update for jbigkit Announcement ID: SUSE-SU-2023:4968-1 Rating: low References: * bsc#1198146 Cross-References: * CVE-2022-1210 CVSS scores: * CVE-2022-1210 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2022-1210 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for jbigkit fixes the following issues: * CVE-2022-1210: Fixed denial of service in TIFF File Handler (bsc#1198146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-4968=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4968=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4968=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4968=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4968=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patchSUSE-SLE-Micro-5.3-2023-4968=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4968=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4968=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4968=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4968=1 * SUSE Linux Enterprise Real Time 15 SP4 zypper in -t patch SUSE-SLE-Product-RT-15-SP4-2023-4968=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4968=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4968=1 ## Package List: * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * jbigkit-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * libjbig-devel-2.1-150000.3.5.1 * libjbig2-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * openSUSE Leap 15.4 (x86_64) * libjbig2-32bit-debuginfo-2.1-150000.3.5.1 * libjbig-devel-32bit-2.1-150000.3.5.1 * libjbig2-32bit-2.1-150000.3.5.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * jbigkit-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * libjbig-devel-2.1-150000.3.5.1 * libjbig2-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * openSUSE Leap 15.5 (x86_64) * libjbig2-32bit-debuginfo-2.1-150000.3.5.1 * libjbig-devel-32bit-2.1-150000.3.5.1 *libjbig2-32bit-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * jbigkit-debuginfo-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * libjbig-devel-2.1-150000.3.5.1 * libjbig2-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * Basesystem Module 15-SP5 (x86_64) * libjbig2-32bit-debuginfo-2.1-150000.3.5.1 * libjbig2-32bit-2.1-150000.3.5.1 * SUSE Linux Enterprise Real Time 15 SP4 (x86_64) * jbigkit-debuginfo-2.1-150000.3.5.1 * libjbig2-32bit-debuginfo-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * libjbig-devel-2.1-150000.3.5.1 * libjbig2-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * libjbig2-32bit-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 *jbigkit-debuginfo-2.1-150000.3.5.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libjbig2-2.1-150000.3.5.1 * libjbig2-debuginfo-2.1-150000.3.5.1 * jbigkit-debugsource-2.1-150000.3.5.1 * jbigkit-debuginfo-2.1-150000.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2022-1210.html * https://bugzilla.suse.com/show_bug.cgi?id=1198146 . Oracle issues a software update for libpng addressing a denial of service flaw marked as minor severity.. jbigkit security update, SUSE Linux patch, low impact update. . Severity: Low. LinuxSecurity.com Team
* bsc#1198146 Cross-References: * CVE-2022-1210 . # Security update for jbigkit Announcement ID: SUSE-SU-2023:4969-1 Rating: low References: * bsc#1198146 Cross-References: * CVE-2022-1210 CVSS scores: * CVE-2022-1210 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2022-1210 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for jbigkit fixes the following issues: * CVE-2022-1210: Fixed denial of service in TIFF File Handler (bsc#1198146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-4969=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4969=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4969=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4969=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * jbigkit-debuginfo-2.0-14.3.1 * jbigkit-debugsource-2.0-14.3.1 * libjbig-devel-2.0-14.3.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * jbigkit-debuginfo-2.0-14.3.1 * jbigkit-debugsource-2.0-14.3.1 * libjbig2-2.0-14.3.1 * libjbig2-debuginfo-2.0-14.3.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libjbig2-debuginfo-32bit-2.0-14.3.1 * libjbig2-32bit-2.0-14.3.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * jbigkit-debuginfo-2.0-14.3.1 * jbigkit-debugsource-2.0-14.3.1 * libjbig2-2.0-14.3.1 * libjbig2-debuginfo-2.0-14.3.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libjbig2-debuginfo-32bit-2.0-14.3.1 * libjbig2-32bit-2.0-14.3.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * jbigkit-debuginfo-2.0-14.3.1 * jbigkit-debugsource-2.0-14.3.1 * libjbig2-2.0-14.3.1 * libjbig2-debuginfo-2.0-14.3.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libjbig2-debuginfo-32bit-2.0-14.3.1 * libjbig2-32bit-2.0-14.3.1 ## References: * https://www.suse.com/security/cve/CVE-2022-1210.html * https://bugzilla.suse.com/show_bug.cgi?id=1198146 . SUSE has issued an update for jbigkit which rectifies a minor denial of service security flaw. Apply the fix immediately.. SUSE Security Update,jbigkit Patch,denial of service fix,12 SP5 software. . Severity: Low. LinuxSecurity.com Team
Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 security update Advisory ID: RHSA-2023:5310-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:5310 Issue date: 2023-09-20 CVE Names: CVE-2023-4853 ===================================================================== 1. Summary: Red Hat Integration Camel Extensions for Quarkus 2.13.3-1 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: A security update for Camel Extensions for Quarkus 2.13.3 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * quarkus-vertx-http: quarkus: HTTP security policy bypass (CVE-2023-4853) Red Hat Product Security has issued a Security Bulletin regarding this flaw. See the RHSB link in the References section. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2238034 -CVE-2023-4853 quarkus: HTTP security policy bypass 5. References: https://access.redhat.com/security/cve/CVE-2023-4853 https://access.redhat.com/security/updates/classification#low https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCrrlAAoJENzjgjWX9erEiNMP/3LaxCkr/bc45RtmAMwoazjD dTZN2XxbYGK+Rk7QGIeaxCHYqPpNvZ218nt+aoK6RD3ZxOxpce0VYphbHLQcmqFg JVezhDGiJfeAPfnwDL2r2ODRdYUzZpe1ZQDcId11MqP53mf6MT3OyjX/8oVDvl5Y 6UWpa1Kgs9iOsdadTes4qbW3DjAxXjNJM/sZLRnCx0GjH1w67xl3qzfmxE5vpkc9 0iBOMoWrqe8qapBFIfA5BkkS5tNZd3tq/muFW9PShZDcVmOLB5SHsyzzOa/68Rk5 knpCKk1wfWINITJf+MZdZ3VgSvQRX3PbXJSZ3OmIAYmnRFQm3IRGUZ5C8+zttkLd J28WI8qNAYLc0cbsgS9UV11PaHnvRfptAD8x7Ux5BomCb60+2E9fFV5ThTHdPEwu b4ZxatnbGxDiWl6FDHFZx32EWPFVR1lSlQVO8NPUoYMLr2kyR3/iSBztOuG8Qz+0 nE8AJQQurAtRXhk4O76beMGAIt42hNfY/Jn/R3wgIxJOoezJJ7QnL3RteokIOC5m Tleuw6XJY2kQgOo8rx/M3Cs36bauSLgFJv5g5etqqTM0K173CT5RD/dVGzVzyfQY s+KqysYZQjrX9Rl+n5v40t/RQgP2pEiCfkzMWXWgjg00ptpo9C74KYqYJ/mYKYDM 2xjcD81yiQtMVf7dELFa =Sq5r -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for open-vm-tools is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: open-vm-tools security update Advisory ID: RHSA-2023:3948-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3948 Issue date: 2023-06-29 CVE Names: CVE-2023-20867 ==================================================================== 1. Summary: An update for open-vm-tools is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, x86_64 3. Description: The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines. Security Fix(es): * open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2213087 - CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module 6. Package List: RedHat Enterprise Linux AppStream (v. 9): Source: open-vm-tools-12.1.5-1.el9_2.1.src.rpm aarch64: open-vm-tools-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-debuginfo-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-debugsource-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-desktop-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-desktop-debuginfo-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-sdmp-debuginfo-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-test-12.1.5-1.el9_2.1.aarch64.rpm open-vm-tools-test-debuginfo-12.1.5-1.el9_2.1.aarch64.rpm x86_64: open-vm-tools-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-debuginfo-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-debugsource-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-desktop-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-desktop-debuginfo-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-salt-minion-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-sdmp-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-sdmp-debuginfo-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-test-12.1.5-1.el9_2.1.x86_64.rpm open-vm-tools-test-debuginfo-12.1.5-1.el9_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-20867 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZJ2of9zjgjWX9erEAQjZjw//RjyHb5TBQ8PKFI5RUsmniCGENc9FSQe2 lmEWeUsBN1MXvB62o81VkQzXqikBNbRAvvX+uNuAMCEmbgWcpobrVj45kSw+zckT vTe3h58T7/dkftW32eb8U4ZbHn8yF2UxMHPAuzH4ejLxjjK86762re/fm4iPOYSu g5PHx1bHyOt318kRvEk4b9ZI5/aQAJXDNXplCbFiYt66iCkPxZOwxnzhiYncz6TP kz27ikiEHRaBwNcQEIRSGOpH/hQGYCB175gpz8/oxKzn5eO2htaQN8TnDX5RipDF bqIpW1VZB4hk+zKkpcGxt7VCTrb6CooRu21MaZ3Zpiskvn44eDtN+Bu1n8h8hppl KajNdylOBeOgf61HAuhaWL1lauXwks+MZPxCkt+/YKWgVhUtFfqamUVUqtJg8wnJ 2xYuE6cfBwwF7xdYAQEtLzHPlyBEtF7grMUtPQNfyaE7VAxAx56rR8fzKeqh8aG8 t6cx+LuMn/UoPxb94ZRNp2t6Wnx3gAf5LTmC54VoDaIH6jB4ccXea8VNtZPLzPYd 8n1cSYwtT4IADDYj1APix+ihqWxWg5qXCL8zZE/iR1Jja9WI+58AmHCO130pc8Yo toOGpSvZScNvGsspYIyUwOzQ4cQfzx7p9E3pg80/nppRMCSOq6MG7RdTzroqxZSm m8FCwTysfe8=tvNt -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for open-vm-tools is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: open-vm-tools security update Advisory ID: RHSA-2023:3949-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3949 Issue date: 2023-06-29 CVE Names: CVE-2023-20867 ==================================================================== 1. Summary: An update for open-vm-tools is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - x86_64 3. Description: The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines. Security Fix(es): * open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2213087 - CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module 6. Package List: Red HatEnterprise Linux AppStream (v. 8): Source: open-vm-tools-12.1.5-2.el8_8.src.rpm x86_64: open-vm-tools-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-debuginfo-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-debugsource-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-desktop-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-desktop-debuginfo-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-salt-minion-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-sdmp-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-sdmp-debuginfo-12.1.5-2.el8_8.x86_64.rpm open-vm-tools-test-debuginfo-12.1.5-2.el8_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-20867 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJ2oWdzjgjWX9erEAQg1Gg//frRHoVjUFeLBnvZnJORz1MQsroeyiJkw 3FReHbPsbSfT7ryXkw4stnrKl7eiIHrfUvNgMjv0pgvoKjloHRyY0+9KyB0lmEQh eYTeFuE9BTKJ9GUIz6j8p1uYurWJh6Now5uiWh0CgwGDa+6J5Rf95nBQJ3H4wVSk nB5cvXatF/RoebGQHUSVBLZzHfTr8ha3ubWFSW9qMluJdAgA8nBfrh5HtvNsRbHa oSuAV60a0fmc9gYnRUz2HTHyfEqa6/YS/W36AytM6DbATiuqRyUPBA7qtqJ0bxCD xsAf0SZDRR24a5EmlTBlzWBBw9u9qUWzo9NjZvvsEaMY95sETm3KH/lEFf6YzU8u XTmwu72mRFdK8fHSxlEs5Cjf2xxnBtAYCDNmC4TfHMUMlBibAAJQ/h5Oye5YyE5I wdH/glDGty+UD5RmmMrFLhAw65UcpZjdE+0Kxfduk6rj/FKv1mLWatQfk33Ko34N bS5jw+anOq7ivwF4nweWgu8WNFo4g6aSQRnwwtSEtKYXh2xQeY0cIXq+YtPqmMHh p04tlhnqTCe1dx99CWcbwxtqkh3uXzAzjHp4tr1JwwdJrg1fw5rqxSDW2JUbOSKe zzijJiRzt62L5HbS6XltnUj3/oPzJANkGnTVRGZKA+Frl+0j1z4ldkhSztt/3lby qxOeJp637W4=Ck9R -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for openssl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: openssl security and bug fix update Advisory ID: RHSA-2023:2523-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:2523 Issue date: 2023-05-09 CVE Names: CVE-2022-3358 ==================================================================== 1. Summary: An update for openssl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: Using a Custom Cipher with NID_undef may lead to NULL encryption (CVE-2022-3358) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.2 Release Notes linked from the References section. 4. Solution: For details on how to apply thisupdate, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. 5. Bugs fixed (https://bugzilla.redhat.com/): 2060044 - PSK ciphersuites at SECLEVEL=3 2083879 - -Wimplicit-function-declaration when compiling FIPS_mode() function with clang 2094956 - Overriding default property query settings doesn't work for some operations (FIPS mode) 2128412 - stunnel consumes high amount of memory when pestered with TCP connections without a TLS handshake 2129063 - Rebase to the latest openssl 3.0.x series 2133809 - OPENSSL_strcasecmp versioning 2134740 - CVE-2022-3358 openssl: Using a Custom Cipher with NID_undef may lead to NULL encryption 2136250 - HMAC generation should reject key lengths < 112 bits or provide an indicator in FIPS mode 2137557 - In FIPS mode, openssl should set a minimum length for passwords in PBKDF2 2141597 - FIPS self-test data for RSA-CRT contains incorrect parameters2141695 - In FIPS mode, openssl should reject KDF input and output key lengths < 112 bits or provide an indicator 2141748 - In FIPS mode, openssl should reject SHA-224, SHA-384, SHA-512-224, and SHA-512-256 as hashes for hash-based DRBGs, or provide an indicator after 2023-05-16 2142087 - In FIPS mode, openssl should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator 2142121 - In FIPS mode, openssl should reject SHAKE as digest for RSA-OAEP or provide an indicator 2142131 - In FIPS mode, openssl should reject RSA signatures with X9.31 padding, or provide an indicator 2142517 - OpenSSL PKCS#11 provider compatibility 2144561 - In FIPS mode, openssl should reject RSA keys < 2048 bits when using EVP_PKEY_decapsulate, or provide an indicator 2157965 - OpenSSL FIPS checksum code needs update 2168224 - OpenSSL - Significant performance drop for getrandom system call when FIPS is enabled (compared to RHEL 8) 6. PackageList: Red Hat Enterprise Linux AppStream (v. 9): aarch64: openssl-debuginfo-3.0.7-6.el9_2.aarch64.rpm openssl-debugsource-3.0.7-6.el9_2.aarch64.rpm openssl-devel-3.0.7-6.el9_2.aarch64.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.aarch64.rpm openssl-perl-3.0.7-6.el9_2.aarch64.rpm ppc64le: openssl-debuginfo-3.0.7-6.el9_2.ppc64le.rpm openssl-debugsource-3.0.7-6.el9_2.ppc64le.rpm openssl-devel-3.0.7-6.el9_2.ppc64le.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.ppc64le.rpm openssl-perl-3.0.7-6.el9_2.ppc64le.rpm s390x: openssl-debuginfo-3.0.7-6.el9_2.s390x.rpm openssl-debugsource-3.0.7-6.el9_2.s390x.rpm openssl-devel-3.0.7-6.el9_2.s390x.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.s390x.rpm openssl-perl-3.0.7-6.el9_2.s390x.rpm x86_64: openssl-debuginfo-3.0.7-6.el9_2.i686.rpm openssl-debuginfo-3.0.7-6.el9_2.x86_64.rpm openssl-debugsource-3.0.7-6.el9_2.i686.rpm openssl-debugsource-3.0.7-6.el9_2.x86_64.rpm openssl-devel-3.0.7-6.el9_2.i686.rpm openssl-devel-3.0.7-6.el9_2.x86_64.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.i686.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.x86_64.rpm openssl-perl-3.0.7-6.el9_2.x86_64.rpm Red Hat Enterprise Linux BaseOS (v.9): Source: openssl-3.0.7-6.el9_2.src.rpm aarch64: openssl-3.0.7-6.el9_2.aarch64.rpm openssl-debuginfo-3.0.7-6.el9_2.aarch64.rpm openssl-debugsource-3.0.7-6.el9_2.aarch64.rpm openssl-libs-3.0.7-6.el9_2.aarch64.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.aarch64.rpm ppc64le: openssl-3.0.7-6.el9_2.ppc64le.rpm openssl-debuginfo-3.0.7-6.el9_2.ppc64le.rpm openssl-debugsource-3.0.7-6.el9_2.ppc64le.rpm openssl-libs-3.0.7-6.el9_2.ppc64le.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.ppc64le.rpm s390x: openssl-3.0.7-6.el9_2.s390x.rpm openssl-debuginfo-3.0.7-6.el9_2.s390x.rpm openssl-debugsource-3.0.7-6.el9_2.s390x.rpm openssl-libs-3.0.7-6.el9_2.s390x.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.s390x.rpm x86_64: openssl-3.0.7-6.el9_2.x86_64.rpm openssl-debuginfo-3.0.7-6.el9_2.i686.rpm openssl-debuginfo-3.0.7-6.el9_2.x86_64.rpm openssl-debugsource-3.0.7-6.el9_2.i686.rpm openssl-debugsource-3.0.7-6.el9_2.x86_64.rpm openssl-libs-3.0.7-6.el9_2.i686.rpm openssl-libs-3.0.7-6.el9_2.x86_64.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.i686.rpm openssl-libs-debuginfo-3.0.7-6.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-3358 https://access.redhat.com/security/updates/classification#low https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZFo1dNzjgjWX9erEAQgzIA//Umqqwi/EqZCm5Ji+lBfbBR39gqJdGRQB 5jxLU/+A1TCTNUT/x+j420fnigF4MDIhh/H0QfK+72Fld2m+CreIqZW+7Xsh0RtN WSGZaf4irML80WhRjSHgsIipN7Nji4tl0xbGmF0uchDdJU84D7xcF8qbzyVXpNeu GBczcwUIqCS7A/1cMQLTmeQPlP1IRs3QMs5d5a3Ao5VrzeLctTt9I5Q2LFnzdqAp WhHNBsQye+510/8ORfVaavUVFM47WhR7rBxW2M/dVnYj51ak85Dk1VIZN5WFXHq+ ZPg6EXXlyXagYKZwYtJEC32v6xd2rjDjrfsbKuT90yH9nkGJ0YcjI6FKOg8K0NcI qs1NNGGzI5ZOAPbTTYENYOiFhKyI0wv8K+GWwzWjTysR6lAhH0WSVEffjAWAY17S 94uSgAGtDu/sVZz5Qxj64352RDtpsigrdg5dbhzkl8eVXjBJ7fi5ynANIMqts0xc KmrbOycn9gfNp6w98qO3/PD+ppADa/BxETbjg8CHlgD0AX92SNOQuI3x62g45iPo 1UrZ07kpLaZPmSJaWGvdSD7jfRq/cxtSB5UAfsXf6Ot++hDvwICDIVAbjW7RCXXZ WbUE1dI4rARGSW8G3DANl5fQrnYh8yqf1mIbCEl38NInWWescvTyB8i1zDWyKrjX AFWo0WjKSQw=naov -----END PGP SIGNATURE----- -- RHSA-announce mailing list
A security update for Debezium is now available for Red Hat Integration. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: Red Hat Integration Debezium 2.1.4 security update Advisory ID: RHSA-2023:1815-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:1815 Issue date: 2023-04-17 CVE Names: CVE-2022-41946 ==================================================================== 1. Summary: A security update for Debezium is now available for Red Hat Integration. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Debezium is a distributed platform that turns your existing databases into event streams, so applications can see and respond immediately to each row-level change in the databases. Debezium is built on top of Apache Kafka and provides Kafka Connect compatible connectors that monitor specific database management systems. Debezium records the history of data changes in Kafka logs, from where your application consumes them. This makes it possible for your application to easily consume all of the events correctly and completely. Even if your application stops unexpectedly, it will not miss anything: when the application restarts, it will resume consuming the events where it left off. Security Fix(es): * jdbc-postgresql: postgresql-jdbc: PreparedStatement.setText(int, InputStream) will create a temporary file if the InputStream is larger than 2k(CVE-2022-41946) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2153399 - CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions 5. References: https://access.redhat.com/security/cve/CVE-2022-41946 https://access.redhat.com/security/updates/classification/#low 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZD10m9zjgjWX9erEAQh9dBAAhmVuToNCVu4H3LeIOBsGsl1jEcIfJCqt F0p6MpfVHhEpCtql9ArPqXqDD4wBlzybN6taF8UCMinqxSunYbGhLiErEwS8iQ/7 UZTPw4KntC5AKWYzgUfHiPzyvPNPU+oXRfCCGQZPE+WTAS7E3bdV94nshKYI5gSS fWK7Bp/zXqIaLadipUmweuyg/nm7aE2qbDjJORxnHxn83mbxnASSrOxfR3ihofTy XpoFvOWJnUUS4MdEfC4+fyxLRNKwaU4mEIdTJTmLOs8Y0uoWMUuGZyRq2soWG6yG DleEJbr+73as1XGWXIcQTFfSGe7sL4BXVILxczUwNn5ONCGvgueLZnOlA/hs3P4V UdkRfHZNFZ6vvB4bv2CTY9557icaa/MUiWYNujcuOBognotRaVMMySrQ34AMWS0o x2o5EVHkcaHG4RlsfH0VIPSscembWypQ6uDzVBUswPBeKKVd8z9r90dwqjL+HIxE zuu4zVRFbEMxdiLvXWqhYF1CKgiVGUVz+AqgVnGGzpN6GzLzAsuHM6tldTsBrutJ Bl1v9n0wEOpSe6T/4eNAPTQl1aXqkfbCZIGWqhnJ4FwYgJqx4xS1R4nhvd+hhYcQ tsYTQKFM7FznoSDKUBHsnmsV7P6IkO5SN6RjUh9JnuxYmMgDIliLTaIptkUDj3VT Gg4i7hw8Jjo=Usvm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.