Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
* bsc#1237040 Cross-References: * CVE-2025-26465 . # Security update for openssh Announcement ID: SUSE-SU-2025:0605-1 Release Date: 2025-02-20T14:43:40Z Rating: moderate References: * bsc#1237040 Cross-References: * CVE-2025-26465 CVSS scores: * CVE-2025-26465 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-26465 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for openssh fixes the following issues: * CVE-2025-26465: Fixed MitMattack against OpenSSH's VerifyHostKeyDNS-enabled client (bsc#1237040). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-605=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-605=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-605=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-605=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-605=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-605=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-605=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-605=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-605=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-605=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-605=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-605=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-605=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-605=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-605=1 * SUSE Linux Enterprise Server for SAP Applications 15SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-605=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-605=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-605=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-605=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-605=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-605=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-605=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-605=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-605=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-cavs-debuginfo-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-cavs-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 *openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 *openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 *openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 *openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Server for SAPApplications 15 SP5 (ppc64le x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Manager Proxy 4.3 (x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debuginfo-8.4p1-150300.3.42.1 * openssh-helpers-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-askpass-gnome-debugsource-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-askpass-gnome-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-helpers-debuginfo-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 *openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * openssh-debugsource-8.4p1-150300.3.42.1 * openssh-common-debuginfo-8.4p1-150300.3.42.1 * openssh-server-debuginfo-8.4p1-150300.3.42.1 * openssh-fips-8.4p1-150300.3.42.1 * openssh-debuginfo-8.4p1-150300.3.42.1 * openssh-clients-debuginfo-8.4p1-150300.3.42.1 * openssh-8.4p1-150300.3.42.1 * openssh-common-8.4p1-150300.3.42.1 * openssh-server-8.4p1-150300.3.42.1 * openssh-clients-8.4p1-150300.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-26465.html * https://bugzilla.suse.com/show_bug.cgi?id=1237040 . Essential patch for OpenSSH resolves a MitM security flaw. Apply this update to protect your environment from potential risks.. openssh update, SUSE security advisory, Linux security patch. . LinuxSecurity.com Team
An update is now available for RHOL-5.5-RHEL-8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Logging Subsystem 5.5.0 - Red Hat OpenShift security update Advisory ID: RHSA-2022:6051-01 Product: RHOL Advisory URL: https://access.redhat.com/errata/RHSA-2022:6051 Issue date: 2022-08-18 CVE Names: CVE-2021-38561 CVE-2022-0759 CVE-2022-1012 CVE-2022-1292 CVE-2022-1586 CVE-2022-1785 CVE-2022-1897 CVE-2022-1927 CVE-2022-2068 CVE-2022-2097 CVE-2022-21698 CVE-2022-30631 CVE-2022-32250 ==================================================================== 1. Summary: An update is now available for RHOL-5.5-RHEL-8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Logging Subsystem 5.5.0 - Red Hat OpenShift Security Fix(es): * kubeclient: kubeconfig parsing error can lead to MITM attacks (CVE-2022-0759) * golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631) * golang: out-of-bounds read in golang.org/x/text/language leads to DoS (CVE-2021-38561) * prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, whichincludes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter 2058404 - CVE-2022-0759 kubeclient: kubeconfig parsing error can lead to MITM attacks 2100495 - CVE-2021-38561 golang: out-of-bounds read in golang.org/x/text/language leads to DoS 2107342 - CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): LOG-1415 - Allow users to tune fluentd LOG-1539 - Events and CLO csv are not collected after running `oc adm must-gather --image=$downstream-clo-image ` LOG-1713 - Reduce Permissions granted for prometheus-k8s service account LOG-2063 - Collector pods fail to start when a Vector only Cluster Logging instance is created. LOG-2134 - The infra logs are sent to app-xx indices LOG-2159 - Cluster Logging Pods in CrashLoopBackOff LOG-2165 - [Vector] Default log level debug makes it hard to find useful error/failure messages. LOG-2167 - [Vector] Collector pods fails to start with configuration error when using Kafka SASL over SSL LOG-2169 - [Vector] Logs not being sent to Kafka with SASL plaintext. LOG-2172 - [vector]The openshift-apiserver and ovn audit logs can not be collected. LOG-2242 - Log file metric exporter is still following /var/log/containers files. LOG-2243 - grafana-dashboard-cluster-logging should be deleted once clusterlogging/instance was removed LOG-2264 - Logging link should contain an icon LOG-2274 - [Logging 5.5] EO doesn't recreate secrets kibana and kibana-proxy after removing them. LOG-2276 - Fluent config format is hard to read via configmap LOG-2290 - ClusterLogging Instance status in not getting updated in UI LOG-2291 - [release-5.5] Events listing out of order in Kibana 6.8.1 LOG-2294 - [Vector] Vector internal metrics are not exposed via HTTPS due to which OpenShift Monitoring Prometheus service cannot scrape the metricsendpoint. LOG-2300 - [Logging 5.5]ES pods can't be ready after removing secret/signing-elasticsearch LOG-2303 - [Logging 5.5] Elasticsearch cluster upgrade stuck LOG-2308 - configmap grafana-dashboard-elasticsearch is being created and deleted continously LOG-2333 - Journal logs not reaching Elasticsearch output LOG-2337 - [Vector] Missing @ prefix from the timestamp field in log record. LOG-2342 - [Logging 5.5] Kibana pod can't connect to ES cluster after removing secret/signing-elasticsearch: "x509: certificate signed by unknown authority" LOG-2384 - Provide a method to get authenticated from GCP LOG-2411 - [Vector] Audit logs forwarding not working. LOG-2412 - CLO's loki output url is parsed wrongly LOG-2413 - PriorityClass cluster-logging is deleted if provide an invalid log type LOG-2418 - EO supported time units don't match the units specified in CRDs. LOG-2439 - Telemetry: the managedStatus&healthStatus&version values are wrong LOG-2440 - [loki-operator] Live tail of logs does not work on OpenShift LOG-2444 - The write index is removed when `the size of the index` > `diskThresholdPercent% * total size`. LOG-2460 - [Vector] Collector pods fail to start on a FIPS enabled cluster. LOG-2461 - [Vector] Vector auth config not generated when user provided bearer token is used in a secret for connecting to LokiStack. LOG-2463 - Elasticsearch operator repeatedly prints error message when checking indices LOG-2474 - EO shouldn't grant cluster-wide permission to system:serviceaccount:openshift-monitoring:prometheus-k8s when ES cluster is deployed. [openshift-logging 5.5] LOG-2522 - CLO supported time units don't match the units specified in CRDs. LOG-2525 - The container's logs are not sent to separate index if the annotation is added after the pod is ready. LOG-2546 - TLS handshake error on loki-gateway for FIPS cluster LOG-2549 - [Vector] [master] Journald logs not sent to the Log store when using Vector as collector. LOG-2554 - [Vector] [master] Fallback index is not used when structuredTypeKey is missingfrom JSON log data LOG-2588 - FluentdQueueLengthIncreasing rule failing to be evaluated. LOG-2596 - [vector]the condition in [transforms.route_container_logs] is inaccurate LOG-2599 - Supported values for level field don't match documentation LOG-2605 - $labels.instance is empty in the message when firing FluentdNodeDown alert LOG-2609 - fluentd and vector are unable to ship logs to elasticsearch when cluster-wide proxy is in effect LOG-2619 - containers violate PodSecurity -- Log Exporation LOG-2627 - containers violate PodSecurity -- Loki LOG-2649 - Level Critical should match the beginning of the line as the other levels LOG-2656 - Logging uses deprecated v1beta1 apis LOG-2664 - Deprecated Feature logs causing too much noise LOG-2665 - [Logging 5.5] Sometimes collector fails to push logs to Elasticsearch cluster LOG-2693 - Integration with Jaeger fails for ServiceMonitor LOG-2700 - [Vector] vector container can't start due to "unknown field `pod_annotation_fields`" . LOG-2703 - Collector DaemonSet is not removed when CLF is deleted for fluentd/vector only CL instance LOG-2725 - Upgrade logging-eventrouter Golang version and tags LOG-2731 - CLO keeps reporting `Reconcile ServiceMonitor retry error` and `Reconcile Service retry error` after creating clusterlogging. LOG-2732 - Prometheus Operator pod throws 'skipping servicemonitor' error on Jaeger integration LOG-2742 - unrecognized outputs when use the sts role secret LOG-2746 - CloudWatch forwarding rejecting large log events, fills tmpfs LOG-2749 - OpenShift Logging Dashboard for Elastic Shards shows "active_primary" instead of "active" shards. LOG-2753 - Update Grafana configuration for LokiStack integration on grafana/loki repo LOG-2763 - [Vector]{Master} Vector's healthcheck fails when forwarding logs to Lokistack. LOG-2764 - ElasticSearch operator does not respect referencePolicy when selecting oauth-proxy image LOG-2765 - ingester pod can not be started in IPv6 cluster LOG-2766 - [vector] failed to parse cluster url: invalid authority IPv6http-proxy LOG-2772 - arn validation failed when role_arn=arn:aws-us-gov:xxx LOG-2773 - No cluster-logging-operator-metrics service in logging 5.5 LOG-2778 - [Vector] [OCP 4.11] SA token not added to Vector config when connecting to LokiStack instance without CLF creds secret required by LokiStack. LOG-2784 - Japanese log messages are garbled at Kibana LOG-2793 - [Vector] OVN audit logs are missing the level field. LOG-2864 - [vector] Can not sent logs to default when loki is the default output in CLF LOG-2867 - [fluentd] All logs are sent to application tenant when loki is used as default logstore in CLF. LOG-2873 - [Vector] Cannot configure CPU/Memory requests/limits when using Vector as collector. LOG-2875 - Seeing a black rectangle box on the graph in Logs view LOG-2876 - The link to the 'Container details' page on the 'Logs' screen throws error LOG-2877 - When there is no query entered, seeing error message on the Logs view LOG-2882 - RefreshIntervalDropdown and TimeRangeDropdown always set back to its original values when switching between pages in 'Logs' screen 6. References: https://access.redhat.com/security/cve/CVE-2021-38561 https://access.redhat.com/security/cve/CVE-2022-0759 https://access.redhat.com/security/cve/CVE-2022-1012 https://access.redhat.com/security/cve/CVE-2022-1292 https://access.redhat.com/security/cve/CVE-2022-1586 https://access.redhat.com/security/cve/CVE-2022-1785 https://access.redhat.com/security/cve/CVE-2022-1897 https://access.redhat.com/security/cve/CVE-2022-1927 https://access.redhat.com/security/cve/CVE-2022-2068 https://access.redhat.com/security/cve/CVE-2022-2097 https://access.redhat.com/security/cve/CVE-2022-21698 https://access.redhat.com/security/cve/CVE-2022-30631 https://access.redhat.com/security/cve/CVE-2022-32250 https://access.redhat.com/security/updates/classification#important 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBYv5/w9zjgjWX9erEAQhRBBAAiZe24VtCQruCG/MvGEOowBvHf/YNANlR N6WAw2VezEfvFkG7z599MWZVWz2jnZO6cn9i+CoNDanAmItPJ8ljK4sitrP2ywrG OKwqIa4DPrywFFTSMxemB604ewE0cvXifuqG5bQDn+GvndiV/u/XaVTYZseY1P5X 8ZIJ20cxROOE9pg0/3eya27edZxDrgWx6BtzSEZw47ReV3Dogqy+KzRCAAoN+pE5 g2t/E0u0Ypmjil9Ttsop/ejUg/iz8UTGtua4m1nzhZrsoE84p5xIgvCEkYlh3OrD tfawpj1r9Avcjk4zbZkAe/enSQZQv0iWD792SoP7/ddX5tIu05ArvPWj/NvN/rI4 dFzMe2UmezuS2EQpzaWOug2xSQUbR1hI+Y4cy0YOHuwzeaMeoHSbNYTJmOxKR0v1 44a9oSBku+Xfk8nUNqS+9oq0z3DlAWt2BjbfrJCbSjZQdOUOIGM95L3ClrXY9LYF PT5v+h2W4myonj6HVhkv+Wy7aRbYQ7Qhk/3AaN7Dz5soBSNK4exvOzWXGuf/BdSf XFef6O87ipZveHQYmTfH+t8aJV1plEVTrm8pyz2EfzCv1Fnhjn0rvbGZAFBlvqW+ vhxoj505RQBBhcno16V1zczdd8KsiqY7aZniTuh2DQAVvNhqsHgn8rvQ7HJlExun eIFVKOxx310=ynB/ -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Logging Subsystem 5.4 - Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Logging Subsystem 5.4 - Red Hat OpenShift Security and Bug update Advisory ID: RHSA-2022:1461-01 Product: Logging Subsystem for Red Hat OpenShift Advisory URL: https://access.redhat.com/errata/RHSA-2022:1461 Issue date: 2022-04-20 CVE Names: CVE-2022-0759 CVE-2022-21698 ==================================================================== 1. Summary: Logging Subsystem 5.4 - Red Hat OpenShift Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Logging Subsystem 5.4 - Red Hat OpenShift Security Fix(es): * kubeclient: kubeconfig parsing error can lead to MITM attacks (CVE-2022-0759) * prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.10 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/release_notes/ocp-4-10-release-notes For Red Hat OpenShift Logging 5.4, see the following instructions to apply thisupdate: https://docs.redhat.com/en/documentation/openshift_container_platform/4.10/html/logging/cluster-logging-upgrading 4. Bugs fixed (https://bugzilla.redhat.com/): 2045880 - CVE-2022-21698 prometheus/client_golang: Denial of service using InstrumentHandlerCounter 2058404 - CVE-2022-0759 kubeclient: kubeconfig parsing error can lead to MITM attacks 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): LOG-1774 - The collector logs should be excluded in fluent.conf LOG-1896 - CLO panic: runtime error: slice bounds out of range [:-1] LOG-1899 - http.max_header_size set to 128kb causes communication with elasticsearch to stop working LOG-1912 - Vector image ref breaks 5.3 build LOG-1918 - Alert `FluentdNodeDown` always firing LOG-1919 - Logging link is not removed when CLO is uninstalled or its instance is removed LOG-2026 - No datapoint for CPU on openshift-logging dashboard LOG-2052 - [vector]Infra logs aren't collected correctly LOG-2056 - Wrong certificates used by fluentd when log forwarding to external Elasticsearch and defined structuredTypeKey LOG-2069 - [release-5.4]Log collected dashboard displays wrong namespace LOG-2070 - [Vector] Collector pods fail to start when a ClusterLogForwarder is created to forward logs to Kafka. LOG-2071 - [release-5.4] The configmap grafana-dashboard-cluster-logging can not be updated LOG-2072 - [Vector] Collector pods fail to start when a ClusterLogForwarder instance is created to forward logs to multiple log stores. LOG-2076 - [Vector] Basic auth credentials are not added to the generated Vector config LOG-2093 - EO Self-generated certificates issue with Kibana when "logging.openshift.io/elasticsearch-cert-management: true" annotation is used LOG-2099 - [release-5.4] Events listing out of order in Kibana 6.8.1 LOG-2107 - CLO instance to deploy Vector not working. LOG-2115 - Incident: Loki Ingester experiencing 50% errors. LOG-2119 - Elasticsearch pod is throwing ElasticsearchSecurityException when running delete by query LOG-2120 - EO becomesCrashLoopBackOff when deploy ES with more than 3 nodes LOG-2121 - LokiStack components/pods are not coming up due to CrashLoopBackOff error LOG-2124 - Binary Manager issue in downstream Loki Operator image LOG-2130 - Vector - Collector pods fails to start when forwarding logs to Loki using tenantKey LOG-2131 - ES Operator Stuck on Quota after Upgrade LOG-2156 - Dashboard for OpenShift Logging in WebConsole shows incorrect number of shards LOG-2157 - Vector: Getting error 'error=unknown field `username`' when forwarding logs to Loki using HTTPS LOG-2160 - [Logging 5.4]Logs under openshift-* projects are sent to app* index when using fluentd as collector LOG-2161 - Cronjob elasticsearch-im-prune-app keeps recreating after enabling delete by query LOG-2163 - Openshift Logging Dashboard is not available in console LOG-2166 - [Vector]CLO doesn't create correct configurations when forwarding different type logs to different log stores. LOG-2171 - [Logging 5.4]ES pods can't be ready after removing secret/signing-elasticsearch LOG-2174 - [vector] ES rejects logs due to MapperParsingException LOG-2210 - Delete by query doesn't delete all the projects' logs defined in retentionPolicy LOG-2211 - [loki-operator]The kube-rbac-proxy is too old ( v4.5.0) LOG-2212 - [loki-operator] Configure Error in ClusterServiceVersion LOG-2218 - support ARM64 for loki-operator images LOG-2220 - Fluentd collector not setting labels from /var/log/pods paths LOG-2221 - The lokistack deployment should continue after the missing secret is created LOG-2224 - LokiStack components are not restarted on ConfigMap change LOG-2226 - [loki-operator] Must use the global namespace openshift-operators or openshift-operators-redhat LOG-2236 - An inner error is swallowed LOG-2246 - [loki-operator] Degraded status immediately reset when no pod actions are pending LOG-2249 - [Vector] Incorrect sinks.loki_server.labels config for kubernetes_host and kubernetes_namespace_name LOG-2250 - [Logging 5.4] EO doesn't recreate secrets kibana and kibana-proxy afterremoving them. LOG-2255 - [Vector] Forwarder does not handle input namespace selectors. LOG-2259 - [Vector] Configuration error ?error=redefinition of table? when forwarding logs from different namespaces. LOG-2278 - [loki-operator] SRV lookup for components fails because of service name mismatch LOG-2286 - Prometheus can't watch pods/endpoints/services in openshift-logging namespace when only the CLO is deployed. LOG-2299 - Loki tenant configuration invalid for fluentd output plugin used LOG-2302 - [Logging 5.4] Elasticsearch cluster upgrade stuck LOG-2327 - [loki-operator] Loki components report connection errors related to kube-probe LOG-2351 - [Logging 5.4] Kibana pod can't connect to ES cluster after removing secret/signing-elasticsearch: "x509: certificate signed by unknown authority" LOG-2352 - loki-operator controller pod in CrashLoopBackOff status LOG-2373 - [release-5.4] Logging link should contain an icon LOG-2375 - Vector preview does not update Status LOG-2379 - [release-5.4] Allow users to tune fluentd LOG-2381 - [Vector] [5.4] Collector pods fail to start with configuration error=unknown variant `internal_metrics` LOG-2383 - The lokistack still bind s3 when secret.type is azure LOG-2392 - CLO's loki output url is parsed wrongly LOG-2397 - Reconcile Error on Loki controller manager after LokiStack size is changed LOG-2398 - [Vector][5.4] Journal logs not reaching Elasticsearch output LOG-2425 - lokistack: Common users can not view their pods logs LOG-2430 - Enable vector functional and e2e tests for preview, or document gaps LOG-2438 - api/logs/v1/audit/loki/api/v1/push 302 Found failed to find token LOG-2441 - Remove OpenShift 4.8 from Logging 5.4 support list LOG-2462 - Fluentd collected metric should track either /var/log/pods or /var/log/containersLOG-2487 - The loki-operator can not be upgraded 6. References: https://access.redhat.com/security/cve/CVE-2022-0759 https://access.redhat.com/security/cve/CVE-2022-21698 https://access.redhat.com/security/updates/classification#important 7.Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYmGDYtzjgjWX9erEAQjESBAAjEvyQPIYiTjNuT+jg44CUTA8WCHTNtqk CQIEO3lu0fA/JGY2gVihGN+CwqM/5NNy/th8fsO11Zu26D5ldIqW6ll82Ms05zpK JHidM+vTuP9fQDXti+rK91k7VusQSFCFyh1zQtqqiyGNKX459o2SKm3LtMGS70l0 qk9wh09qJtXBOV7ibAlB3Gx0qcC7H1bT0U8WzZVWUSpkr77c9UnvF9wntBu/Lsra 9aieeU3LHuy8VYcZ7oovj6t1+2bDTgxFRT7JqlzxlsW4yGm5mAxlQya9y5OC46+8 H7xwK5Qgi7043QWejplJPGuJq79GkYTxdXQE6jLyfRIIzj/Jcl3ViJi7nuCe5mn9 x5EYpiGzqXUh8kPilDUz/I+wGA9AnPV+Wn3v6PkqQ255ngUmOBobhfLLj/v5O74q ukyItuBHllYHhNI71phW0kbrmJV/Q+NlM1IMgdmMJySUMi0FpeKcFg+HumDuiM6E ufs6AHyhEB/kkdQ4OhC6Kcmw+wAxlUEm5Kmhi4Hv+9IzP+bvAz0tNRzoOxnUuC7S dKW0UYVRKDhBnKt5vnuUoJkcVOiRflXia/U4ffQk7KxSFsDO8uT0sqrrE0LHKdzK uKeukACBx62Op/g/kXaX5AuDFDb3T3LLjbGYGyqYvRnCfbV1JUM0pk+9LNw0bhCs f0G9+CqiVLw=Je3i -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Damian Poddebniak and Fabian Ising discovered a response injection vulnerability in Evolution data server, which could enable MITM attacks. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4725-1
* Ver. 19.3.6.4. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-9e6df1e099 2017-12-12 10:01:38.490997 --------------------------------------------------------------------------------Name : erlang Product : Fedora 27 Version : 19.3.6.4 Release : 1.fc27 URL : https://www.erlang.org Summary : General-purpose programming language and runtime environment Description : Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. --------------------------------------------------------------------------------Update Information: * Ver. 19.3.6.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1520400 - CVE-2017-1000385 erlang: TLS server vulnerable to Adaptive Chosen Ciphertext attack allowing plaintext recovery or MITM attack https://bugzilla.redhat.com/show_bug.cgi?id=1520400 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade erlang' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A certificate authority mis-issued fraudulent certificates.. =========================================================================Ubuntu Security Notice USN-1197-5 September 09, 2011 ca-certificates vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: A certificate authority mis-issued fraudulent certificates. Software Description: - ca-certificates: Common CA certificates Details: USN-1197-1 addressed an issue in Firefox and Xulrunner pertaining to the Dutch Certificate Authority DigiNotar mis-issuing fraudulent certificates. This update provides the corresponding update for ca-certificates. Original advisory details: It was discovered that Dutch Certificate Authority DigiNotar, had mis-issued multiple fraudulent certificates. These certificates could allow an attacker to perform a "man in the middle" (MITM) attack which would make the user believe their connection is secure, but is actually being monitored. For the protection of its users, Mozilla has removed the DigiNotar certificate. Sites using certificates issued by DigiNotar will need to seek another certificate vendor. We are currently aware of a regression that blocks one of two Staat der Nederlanden root certificates which are believed to still be secure. This regression is being tracked at https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/838322. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: ca-certificates 20090814+nmu2ubuntu0.1 Ubuntu 10.10: ca-certificates 20090814ubuntu0.10.10.1 Ubuntu 10.04 LTS: ca-certificates 20090814ubuntu0.10.04.1 After a standard system update you need to restart any application using ca-certificates to make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-1197-1 https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/837557 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates/20090814+nmu2ubuntu0.1 https://launchpad.net/ubuntu/+source/ca-certificates/20090814ubuntu0.10.10.1 https://launchpad.net/ubuntu/+source/ca-certificates/20090814ubuntu0.10.04.1 . Ubuntu's latest update addresses bogus certificates from a wrongly issued authority, boosting security for all user connections on the platform. ca-certificates update, ubuntu security, fraudulent certificates, man-in-the-middle, certificate authority. . Severity: Important. LinuxSecurity.com Team
Critical: java (jdk 1.6.0) security update. Date: Mon, 12 Apr 2010 16:18:58 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: java (jdk 1.6.0) on SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Critical: java (jdk 1.6.0) security update Issue date: 2010-03-31 CVE Names: CVE-2009-3555 CVE-2010-0082 CVE-2010-0084 CVE-2010-0085 CVE-2010-0087 CVE-2010-0088 CVE-2010-0089 CVE-2010-0090 CVE-2010-0091 CVE-2010-0092 CVE-2010-0093 CVE-2010-0094 CVE-2010-0095 CVE-2010-0837 CVE-2010-0838 CVE-2010-0839 CVE-2010-0840 CVE-2010-0841 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 CVE-2010-0845 CVE-2010-0846 CVE-2010-0847 CVE-2010-0848 CVE-2010-0849 CVE-2009-3555 TLS: MITM attacks via session renegotiation CVE-2010-0082 OpenJDK Loader-constraint table allows arrays instead of only the base-classes (6626217) CVE-2010-0084 OpenJDK Policy/PolicyFile leak dynamic ProtectionDomains. (6633872) CVE-2010-0085 OpenJDK File TOCTOU deserialization vulnerability (6736390) CVE-2010-0088 OpenJDK Inflater/Deflater clone issues (6745393) CVE-2010-0091 OpenJDK Unsigned applet can retrieve the dragged information before drop action occurs(6887703) CVE-2010-0092 OpenJDK AtomicReferenceArray causes SIGSEGV -> SEGV_MAPERR error (6888149) CVE-2010-0093 OpenJDK System.arraycopy unable to reference elements beyond Integer.MAX_VALUE bytes (6892265) CVE-2010-0094 OpenJDK Deserialization of RMIConnectionImpl objects should enforce stricter checks (6893947) CVE-2010-0095 OpenJDK Subclasses of InetAddress may incorrectly interpret network addresses (6893954) CVE-2010-0845 OpenJDK No ClassCastException for HashAttributeSet constructors if run with -Xcomp (6894807) CVE-2010-0838 OpenJDK CMM readMabCurveData Buffer Overflow Vulnerability (6899653) CVE-2010-0837 OpenJDK JAR "unpack200" must verify input parameters (6902299) CVE-2010-0840 OpenJDK Applet Trusted Methods Chaining Privilege Escalation Vulnerability(6904691) CVE-2010-0841 OpenJDK JPEGImageReader stepX Integer Overflow Vulnerability (6909597) CVE-2010-0848 OpenJDK AWT Library Invalid Index Vulnerability (6914823) CVE-2010-0847 OpenJDK ImagingLib arbitrary code execution vulnerability (6914866) CVE-2010-0846 JDK unspecified vulnerability in ImageIO component CVE-2010-0849 JDK unspecified vulnerability in Java2D component CVE-2010-0087 JDK unspecified vulnerability in JWS/Plugin component CVE-2010-0839 CVE-2010-0842 CVE-2010-0843 CVE-2010-0844 JDK multiple unspecified vulnerabilities CVE-2010-0090 JDK unspecified vulnerability in JavaWS/Plugin component CVE-2010-0089 JDK unspecified vulnerability in JavaWS/Plugin component This update fixes several vulnerabilities in the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. Further information about these flaws can be found on the "Oracle Java SE and Java for Business Critical Patch Update Advisory" page, listed in the References section. (CVE-2009-3555, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085, CVE-2010-0087, CVE-2010-0088, CVE-2010-0089, CVE-2010-0090, CVE-2010-0091, CVE-2010-0092, CVE-2010-0093, CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838, CVE-2010-0839, CVE-2010-0840, CVE-2010-0841, CVE-2010-0842, CVE-2010-0843, CVE-2010-0844, CVE-2010-0845, CVE-2010-0846, CVE-2010-0847, CVE-2010-0848, CVE-2010-0849) For the CVE-2009-3555 issue, this update disables renegotiation in the Java Secure Socket Extension (JSSE) component. Unsafe renegotiation can be re-enabled using the sun.security.ssl.allowUnsafeRenegotiation property. All running instances of Sun Java must be restarted for the update to take effect. SL 4.x SRPMS: java-1.6.0-sun-compat-1.6.0.19-1.sl4.jpp.src.rpm i386: java-1.6.0-sun-compat-1.6.0.19-1.sl4.jpp.i586.rpm jdk-1.6.0_19-fcs.i586.rpm x86_64: java-1.6.0-sun-compat-1.6.0.19-1.sl4.jpp.i586.rpm jdk-1.6.0_19-fcs.i586.rpm SL 5.x SRPMS: java-1.6.0-sun-compat-1.6.0.19-1.sl5.jpp.src.rpm i386: java-1.6.0-sun-compat-1.6.0.19-1.sl5.jpp.i586.rpm jdk-1.6.0_19-fcs.i586.rpm x86_64: java-1.6.0-sun-compat-1.6.0.19-1.sl5.jpp.i586.rpm java-1.6.0-sun-compat-1.6.0.19-1.sl5.jpp.x86_64.rpm jdk-1.6.0_19-fcs.i586.rpm jdk-1.6.0_19-fcs.x86_64.rpm -Connie Sieh -Troy Dawson . Urgent patch release for Java (jdk 1.6.0) on Scientific Linux tackling several security flaws proficiently.. Java Security Fix, Scientific Linux Advisory, JDK Update, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Update to 3.12.5 This update fixes the following security flaw: CVE-2009-3555 TLS: MITM attacks via session renegotiation. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-12968 2009-12-10 03:28:57 -------------------------------------------------------------------------------- Name : nss-util Product : Fedora 12 Version : 3.12.5 Release : 1.fc12.1 URL : https://firefox-source-docs.mozilla.org/security/nss/index.html Summary : Network Security Services Utilities Library Description : Utilities for Network Security Services and the Softoken module -------------------------------------------------------------------------------- Update Information: Update to 3.12.5 This update fixes the following security flaw: CVE-2009-3555 TLS: MITM attacks via session renegotiation -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 3 2009 Elio Maldonado - 3.12.5-1.1 - Update to 3.12.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #533125 - CVE-2009-3555 TLS: MITM attacks via session renegotiation https://bugzilla.redhat.com/show_bug.cgi?id=533125 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update nss-util' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.