Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 34 articles for you...
217

Oracle Linux 8 ELSA-2024-3267 Moderate: IDM Component Updates

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-3267 http://linux.oracle.com/errata/ELSA-2024-3267.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bind-dyndb-ldap-11.6-5.module+el8.10.0+90339+985471f7.x86_64.rpm custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-client-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.x86_64.rpm ipa-client-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.x86_64.rpm ipa-client-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-client-common-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-client-epn-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.x86_64.rpm ipa-client-epn-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.x86_64.rpm ipa-client-samba-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.x86_64.rpm ipa-client-samba-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.x86_64.rpm ipa-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-common-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-healthcheck-0.12-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-healthcheck-core-0.12-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-healthcheck-core-0.12-3.module+el8.9.0+90095+d672673c.noarch.rpm ipa-python-compat-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-python-compat-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-selinux-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-selinux-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-server-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.x86_64.rpm ipa-server-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-server-dns-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-server-trust-ad-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.x86_64.rpm opendnssec-2.1.7-1.module+el8.9.0+90094+20819f5a.x86_64.rpm python3-custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm python3-ipaclient-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipaclient-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-ipalib-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipalib-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-ipaserver-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipatests-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90339+985471f7.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-kdcproxy-0.4-5.module+el8.9.0+90122+3305dc1d.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90095+d672673c.noarch.rpm python3-qrcode-5.1-12.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-5.1-12.module+el8.9.0+90095+d672673c.noarch.rpm python3-qrcode-core-5.1-12.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-core-5.1-12.module+el8.9.0+90095+d672673c.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90095+d672673c.noarch.rpm slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.x86_64.rpm softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.x86_64.rpm softhsm-devel-2.6.0-5.module+el8.9.0+90094+20819f5a.x86_64.rpm aarch64: bind-dyndb-ldap-11.6-5.module+el8.10.0+90339+985471f7.aarch64.rpm custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-client-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.aarch64.rpm ipa-client-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.aarch64.rpm ipa-client-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-client-common-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-client-epn-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.aarch64.rpm ipa-client-epn-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.aarch64.rpm ipa-client-samba-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.aarch64.rpm ipa-client-samba-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.aarch64.rpm ipa-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-common-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-healthcheck-0.12-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-healthcheck-core-0.12-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-healthcheck-core-0.12-3.module+el8.9.0+90095+d672673c.noarch.rpm ipa-python-compat-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-python-compat-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-selinux-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-selinux-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm ipa-server-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.aarch64.rpm ipa-server-common-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-server-dns-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm ipa-server-trust-ad-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.aarch64.rpm opendnssec-2.1.7-1.module+el8.9.0+90094+20819f5a.aarch64.rpm python3-custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm python3-ipaclient-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipaclient-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-ipalib-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipalib-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-ipaserver-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-ipatests-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90339+985471f7.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90340+9faa45ba.noarch.rpm python3-kdcproxy-0.4-5.module+el8.9.0+90122+3305dc1d.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90095+d672673c.noarch.rpm python3-qrcode-5.1-12.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-5.1-12.module+el8.9.0+90095+d672673c.noarch.rpm python3-qrcode-core-5.1-12.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-core-5.1-12.module+el8.9.0+90095+d672673c.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90095+d672673c.noarch.rpm slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.aarch64.rpm softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.aarch64.rpm softhsm-devel-2.6.0-5.module+el8.9.0+90094+20819f5a.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//bind-dyndb-ldap-11.6-5.module+el8.10.0+90339+985471f7.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//ipa-4.9.13-9.0.1.module+el8.10.0+90339+985471f7.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//ipa-4.9.13-9.0.1.module+el8.10.0+90340+9faa45ba.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//ipa-healthcheck-0.12-3.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//ipa-healthcheck-0.12-3.module+el8.9.0+90095+d672673c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//opendnssec-2.1.7-1.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-jwcrypto-0.5.0-2.module+el8.10.0+90339+985471f7.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-jwcrypto-0.5.0-2.module+el8.10.0+90340+9faa45ba.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-kdcproxy-0.4-5.module+el8.9.0+90122+3305dc1d.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-qrcode-5.1-12.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-qrcode-5.1-12.module+el8.9.0+90095+d672673c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-yubico-1.3.2-9.1.module+el8.9.0+90095+d672673c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pyusb-1.0.0-9.1.module+el8.9.0+90095+d672673c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.src.rpm Related CVEs: CVE-2023-6681 CVE-2024-28102 Description of changes: bind-dyndb-ldap custodia ipa [4.9.13-9.0.1] - Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674] [9.4.13-9] - dcerpc: invalidate forest trust intfo cache when filteringout realm domains Resolves: RHEL-28559 - Backport latests test fixes in python3-tests ipatests: add xfail for autoprivate group test with override ipatests: remove xfail thanks to sssd 2.9.4 ipatests: adapt for new automembership fixup behavior ipatests: Fixes for test_ipahealthcheck_ipansschainvalidation testcases test_xmlrpc: adopt to automember plugin message changes in 389-ds Resolves: RHEL-29908 ipa-healthcheck opendnssec python-jwcrypto [0.5.0-2] - Address potential DoS with high compression ratio Resolves: RHEL-28697 - Limit number of iterations for PBES Resolves: RHEL-23036 RHEL-23037 python-kdcproxy python-qrcode python-qrcode python-yubico python-yubico pyusb pyusb slapi-nis softhsm _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Announcement ELSA-2024-3268 outlines vital enhancements for idm modules essential for safeguarding systems.. Oracle Linux, Moderate Updates, RPM Security, Security Advisory, Unbreakable Linux. . LinuxSecurity.com Team

Calendar 2 Jun 03, 2024 Oracle
100

SUSE: 2023:3417-1 Important Security Update for Container Environment

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.1/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3416-1 Container Tags : suse/sle-micro/5.1/toolbox:12.1 , suse/sle-micro/5.1/toolbox:12.1-2.2.473 , suse/sle-micro/5.1/toolbox:latest Container Release : 2.2.473 Severity : moderate Type : security References : 1209275 1214806 1215889 CVE-2023-38546 CVE-2023-4641 ----------------------------------------------------------------- The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4027-1 Released: Tue Oct 10 13:59:02 2023 Summary: Security update for shadow Type: security Severity: low References: 1214806,CVE-2023-4641 This update for shadow fixes the following issues: - CVE-2023-4641: Fixed potential password leak (bsc#1214806). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4045-1 Released: Wed Oct 11 09:10:43 2023 Summary: Security update for curl Type: security Severity: moderate References: 1215889,CVE-2023-38546 This update for curl fixes the following issues: - CVE-2023-38546: Fixed a cookie injection with none file (bsc#1215889). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4052-1 Released: Wed Oct 11 14:11:55 2023 Summary: Recommended update for babeltrace Type: recommended Severity: moderate References: 1209275 This update ships missing babeltrace-devel to the Basesystem module to allow building gdb source rpms. (bsc#1209275) The following package changes have been done: - babeltrace-1.5.8-150300.3.2.1 updated - libcurl4-7.66.0-150200.4.60.1 updated -login_defs-4.8.1-150300.4.12.1 updated - shadow-4.8.1-150300.4.12.1 updated - container:sles15-image-15.0.0-17.20.194 updated . Critical security enhancements rolled out for SUSE container toolkit, addressing vulnerabilities related to session hijacking and credential exposure.. SUSE Container Update, toolbox security, SUSE-CU-2023 moderate update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 14, 2023 Important SuSE
98

Red Hat Enterprise Linux 9: RHSA-2023:5146-01 Moderate DoS in .NET 7.0

An update for .NET 7.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: .NET 7.0 security update Advisory ID: RHSA-2023:5146-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5146 Issue date: 2023-09-13 CVE Names: CVE-2023-36799 ===================================================================== 1. Summary: An update for .NET 7.0 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: .NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation. New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 7.0.111 and .NET Runtime 7.0.11. Security Fix(es): * dotnet: Denial of Service with Client Certificates using .NET Kestrel (CVE-2023-36799) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes describedin this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2237317 - CVE-2023-36799 dotnet: Denial of Service with Client Certificates using .NET Kestrel 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: dotnet7.0-7.0.111-1.el9_2.src.rpm aarch64: aspnetcore-runtime-7.0-7.0.11-1.el9_2.aarch64.rpm aspnetcore-targeting-pack-7.0-7.0.11-1.el9_2.aarch64.rpm dotnet-apphost-pack-7.0-7.0.11-1.el9_2.aarch64.rpm dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-host-7.0.11-1.el9_2.aarch64.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-hostfxr-7.0-7.0.11-1.el9_2.aarch64.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-runtime-7.0-7.0.11-1.el9_2.aarch64.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-sdk-7.0-7.0.111-1.el9_2.aarch64.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.aarch64.rpm dotnet-targeting-pack-7.0-7.0.11-1.el9_2.aarch64.rpm dotnet-templates-7.0-7.0.111-1.el9_2.aarch64.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.aarch64.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.aarch64.rpm netstandard-targeting-pack-2.1-7.0.111-1.el9_2.aarch64.rpm ppc64le: aspnetcore-runtime-7.0-7.0.11-1.el9_2.ppc64le.rpm aspnetcore-targeting-pack-7.0-7.0.11-1.el9_2.ppc64le.rpm dotnet-apphost-pack-7.0-7.0.11-1.el9_2.ppc64le.rpm dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-host-7.0.11-1.el9_2.ppc64le.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-hostfxr-7.0-7.0.11-1.el9_2.ppc64le.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-runtime-7.0-7.0.11-1.el9_2.ppc64le.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-sdk-7.0-7.0.111-1.el9_2.ppc64le.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.ppc64le.rpm dotnet-targeting-pack-7.0-7.0.11-1.el9_2.ppc64le.rpm dotnet-templates-7.0-7.0.111-1.el9_2.ppc64le.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.ppc64le.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.ppc64le.rpm netstandard-targeting-pack-2.1-7.0.111-1.el9_2.ppc64le.rpm s390x: aspnetcore-runtime-7.0-7.0.11-1.el9_2.s390x.rpm aspnetcore-targeting-pack-7.0-7.0.11-1.el9_2.s390x.rpm dotnet-apphost-pack-7.0-7.0.11-1.el9_2.s390x.rpm dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-host-7.0.11-1.el9_2.s390x.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-hostfxr-7.0-7.0.11-1.el9_2.s390x.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-runtime-7.0-7.0.11-1.el9_2.s390x.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-sdk-7.0-7.0.111-1.el9_2.s390x.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.s390x.rpm dotnet-targeting-pack-7.0-7.0.11-1.el9_2.s390x.rpm dotnet-templates-7.0-7.0.111-1.el9_2.s390x.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.s390x.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.s390x.rpm netstandard-targeting-pack-2.1-7.0.111-1.el9_2.s390x.rpm x86_64: aspnetcore-runtime-7.0-7.0.11-1.el9_2.x86_64.rpm aspnetcore-targeting-pack-7.0-7.0.11-1.el9_2.x86_64.rpm dotnet-apphost-pack-7.0-7.0.11-1.el9_2.x86_64.rpm dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-host-7.0.11-1.el9_2.x86_64.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-hostfxr-7.0-7.0.11-1.el9_2.x86_64.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-runtime-7.0-7.0.11-1.el9_2.x86_64.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-sdk-7.0-7.0.111-1.el9_2.x86_64.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.x86_64.rpm dotnet-targeting-pack-7.0-7.0.11-1.el9_2.x86_64.rpm dotnet-templates-7.0-7.0.111-1.el9_2.x86_64.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.x86_64.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.x86_64.rpm netstandard-targeting-pack-2.1-7.0.111-1.el9_2.x86_64.rpm Red Hat Enterprise Linux CRB (v.9): aarch64: dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.aarch64.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.aarch64.rpm dotnet-sdk-7.0-source-built-artifacts-7.0.111-1.el9_2.aarch64.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.aarch64.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.aarch64.rpm ppc64le: dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.ppc64le.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.ppc64le.rpm dotnet-sdk-7.0-source-built-artifacts-7.0.111-1.el9_2.ppc64le.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.ppc64le.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.ppc64le.rpm s390x: dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.s390x.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.s390x.rpm dotnet-sdk-7.0-source-built-artifacts-7.0.111-1.el9_2.s390x.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.s390x.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.s390x.rpm x86_64: dotnet-apphost-pack-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-host-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-hostfxr-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-runtime-7.0-debuginfo-7.0.11-1.el9_2.x86_64.rpm dotnet-sdk-7.0-debuginfo-7.0.111-1.el9_2.x86_64.rpm dotnet-sdk-7.0-source-built-artifacts-7.0.111-1.el9_2.x86_64.rpm dotnet7.0-debuginfo-7.0.111-1.el9_2.x86_64.rpm dotnet7.0-debugsource-7.0.111-1.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2023-36799 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlAdTcAAoJENzjgjWX9erE/2wQAICpW9nr+qtR1ZW5ycabviZC /lhTVmRDmy+GdP4PaqIThrfhg/gUk9eXINCmbutdLT6GoS+DDxkFCVOh1VH3CQmu HYrlvqhb67Kaa5G6eR2dVGqbMlFTB1BsOzxZ2kOSKhhJ+9px8je7KIr4X3XKvgbN u8VQgubyMqh51JG5XvbJ5lgr8vK/wP28dyknb6G2Bm1AoKchk+cFQUuPeoNROl29 vUSQBsnD/t3MA/Pj2xqKnmG2HXmbrhJUh6vU8CXMbzO44/tVIBVkDWO0oNP8xnTT z6uTr5GJFabAkbPTVX8eFXkJH0GRUuyUPBenRi2MvG1433pojUcvSrVpOy7Bn+ga cHiU7fVnC+3Ikkap/ynZpMd5iynyUMrc7E3GneZ6L2CfYwHM0wW7Z3b3lH1tJe9i nDRC8cDcmQ7xTUUpgwhfR7Cy2e2P0UK6En86lI7xyohrNmK3DykS8HPwEBq0VK1F JN+rBXT+qGdoEHwhIqPBaE7keWfdp7GB6bsi3QVNIZUqlZEEQMl2cyaWRdeZRzmt 0U6IHUwQLKIZmu8E6sJ4Mp28e4ycqZyJ+YsfWRxhDQjRXTkv0u/4c9f9Mlr+36p7 OpDh/oqbcw89LlVULWKiyPiWa54MCaw9InCo8blGhTfAE0yQUSnTq4q6mhuiYWch CuOy11LY//6y/wN+u3Db =eloI -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An advisory from Red Hat highlights a moderate .NET 7.0 patch aimed at resolving a denial of service vulnerability affecting Linux systems.. Red Hat Linux Security Update, .NET 7.0 Advisory, Moderate Security Patch. . LinuxSecurity.com Team

Calendar 2 Sep 13, 2023 Red Hat
217

Oracle Linux 8 ELSA-2023-4527 Moderate: PostgreSQL Security Issue

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4527 https://linux.oracle.com/errata/ELSA-2023-4527.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pg_repack-1.4.6-3.module+el8.5.0+20353+e924f9ed.x86_64.rpm pgaudit-1.5.0-1.module+el8.4.0+20016+06fd4df3.x86_64.rpm postgres-decoderbufs-0.10.0-2.module+el8.4.0+20016+06fd4df3.x86_64.rpm postgresql-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-contrib-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-docs-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-plperl-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-plpython3-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-pltcl-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-server-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-server-devel-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-static-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-test-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-test-rpm-macros-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.noarch.rpm postgresql-upgrade-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm postgresql-upgrade-devel-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.x86_64.rpm aarch64: pg_repack-1.4.6-3.module+el8.5.0+20353+e924f9ed.aarch64.rpm pgaudit-1.5.0-1.module+el8.4.0+20016+06fd4df3.aarch64.rpm postgres-decoderbufs-0.10.0-2.module+el8.4.0+20016+06fd4df3.aarch64.rpm postgresql-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-contrib-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-docs-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-plperl-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-plpython3-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-pltcl-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-server-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-server-devel-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-static-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-test-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-test-rpm-macros-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.noarch.rpm postgresql-upgrade-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm postgresql-upgrade-devel-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//pgaudit-1.5.0-1.module+el8.4.0+20016+06fd4df3.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//pg_repack-1.4.6-3.module+el8.5.0+20353+e924f9ed.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//postgres-decoderbufs-0.10.0-2.module+el8.4.0+20016+06fd4df3.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//postgresql-13.11-1.0.1.module+el8.8.0+21141+00b1aed9.src.rpm Related CVEs: CVE-2023-2454 CVE-2023-2455 Description of changes: pgaudit pg_repack postgres-decoderbufs postgresql [13.11-1.0.1] - Update to 13.11 - Resolves: #2212815 - Update postgresql-setup to 8.7 (https://github.com/devexp-db/postgresql-setup/pull/35) - Resolves: #2207933 - Update 1001-Fixed-postgresql-service-network-binding-issue.patch for postgresql-setup _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The latest ELSA-2023-4527 update for Oracle Linux introduces crucial security improvements aimed at PostgreSQL 13, bolstering the database's defenses against known vulnerabilities. Oracle Linux Update, PostgreSQL Security Fix, ELSA-2023-4527. . LinuxSecurity.com Team

Calendar 2 Aug 10, 2023 Oracle
217

Oracle Linux 8 ELSA-2023-4524 Moderate: Libcap Integer Overflow

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4524 https://linux.oracle.com/errata/ELSA-2023-4524.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libcap-2.48-5.el8_8.i686.rpm libcap-2.48-5.el8_8.x86_64.rpm libcap-devel-2.48-5.el8_8.i686.rpm libcap-devel-2.48-5.el8_8.x86_64.rpm aarch64: libcap-2.48-5.el8_8.aarch64.rpm libcap-devel-2.48-5.el8_8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//libcap-2.48-5.el8_8.src.rpm Related CVEs: CVE-2023-2602 CVE-2023-2603 Description of changes: [2.48-5] - Fix integer overflow in _libcap_strdup() (CVE-2023-2603) Resolves: rhbz#2210637 - Correctly check pthread_create() return value to avoid memory leak (CVE-2023-2602) Resolves: rhbz#2210644 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Announcement ELSA-2023-4524 pertains to enhancements in libcap concerning issues related to integer overflows and memory leak vulnerabilities.. Oracle Linux Security, libcap Update, Moderate Security Advisory, Linux RPMs, ELSA-2023-4524. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 10, 2023 Important Oracle
217

Oracle Linux 9 ELSA-2023-4325 Moderate: Memleak Fix in Samba

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4325 https://linux.oracle.com/errata/ELSA-2023-4325.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: libnetapi-4.17.5-103.0.1.el9_2.i686.rpm libnetapi-4.17.5-103.0.1.el9_2.x86_64.rpm libsmbclient-4.17.5-103.0.1.el9_2.i686.rpm libsmbclient-4.17.5-103.0.1.el9_2.x86_64.rpm libwbclient-4.17.5-103.0.1.el9_2.i686.rpm libwbclient-4.17.5-103.0.1.el9_2.x86_64.rpm python3-samba-4.17.5-103.0.1.el9_2.i686.rpm python3-samba-4.17.5-103.0.1.el9_2.x86_64.rpm python3-samba-dc-4.17.5-103.0.1.el9_2.x86_64.rpm samba-4.17.5-103.0.1.el9_2.x86_64.rpm samba-client-4.17.5-103.0.1.el9_2.x86_64.rpm samba-client-libs-4.17.5-103.0.1.el9_2.i686.rpm samba-client-libs-4.17.5-103.0.1.el9_2.x86_64.rpm samba-common-4.17.5-103.0.1.el9_2.noarch.rpm samba-common-libs-4.17.5-103.0.1.el9_2.i686.rpm samba-common-libs-4.17.5-103.0.1.el9_2.x86_64.rpm samba-common-tools-4.17.5-103.0.1.el9_2.x86_64.rpm samba-dc-libs-4.17.5-103.0.1.el9_2.i686.rpm samba-dc-libs-4.17.5-103.0.1.el9_2.x86_64.rpm samba-dcerpc-4.17.5-103.0.1.el9_2.x86_64.rpm samba-krb5-printing-4.17.5-103.0.1.el9_2.x86_64.rpm samba-ldb-ldap-modules-4.17.5-103.0.1.el9_2.x86_64.rpm samba-libs-4.17.5-103.0.1.el9_2.i686.rpm samba-libs-4.17.5-103.0.1.el9_2.x86_64.rpm samba-tools-4.17.5-103.0.1.el9_2.x86_64.rpm samba-usershares-4.17.5-103.0.1.el9_2.x86_64.rpm samba-vfs-iouring-4.17.5-103.0.1.el9_2.x86_64.rpm samba-winbind-4.17.5-103.0.1.el9_2.x86_64.rpm samba-winbind-clients-4.17.5-103.0.1.el9_2.x86_64.rpm samba-winbind-krb5-locator-4.17.5-103.0.1.el9_2.x86_64.rpm samba-winbind-modules-4.17.5-103.0.1.el9_2.i686.rpm samba-winbind-modules-4.17.5-103.0.1.el9_2.x86_64.rpm samba-winexe-4.17.5-103.0.1.el9_2.x86_64.rpm libnetapi-devel-4.17.5-103.0.1.el9_2.i686.rpm libnetapi-devel-4.17.5-103.0.1.el9_2.x86_64.rpm libsmbclient-devel-4.17.5-103.0.1.el9_2.i686.rpm libsmbclient-devel-4.17.5-103.0.1.el9_2.x86_64.rpm libwbclient-devel-4.17.5-103.0.1.el9_2.i686.rpm libwbclient-devel-4.17.5-103.0.1.el9_2.x86_64.rpm python3-samba-devel-4.17.5-103.0.1.el9_2.i686.rpm python3-samba-devel-4.17.5-103.0.1.el9_2.x86_64.rpm python3-samba-test-4.17.5-103.0.1.el9_2.x86_64.rpm samba-devel-4.17.5-103.0.1.el9_2.i686.rpm samba-devel-4.17.5-103.0.1.el9_2.x86_64.rpm samba-pidl-4.17.5-103.0.1.el9_2.noarch.rpm samba-test-4.17.5-103.0.1.el9_2.x86_64.rpm samba-test-libs-4.17.5-103.0.1.el9_2.x86_64.rpm aarch64: libnetapi-4.17.5-103.0.1.el9_2.aarch64.rpm libsmbclient-4.17.5-103.0.1.el9_2.aarch64.rpm libwbclient-4.17.5-103.0.1.el9_2.aarch64.rpm python3-samba-4.17.5-103.0.1.el9_2.aarch64.rpm python3-samba-dc-4.17.5-103.0.1.el9_2.aarch64.rpm samba-4.17.5-103.0.1.el9_2.aarch64.rpm samba-client-4.17.5-103.0.1.el9_2.aarch64.rpm samba-client-libs-4.17.5-103.0.1.el9_2.aarch64.rpm samba-common-4.17.5-103.0.1.el9_2.noarch.rpm samba-common-libs-4.17.5-103.0.1.el9_2.aarch64.rpm samba-common-tools-4.17.5-103.0.1.el9_2.aarch64.rpm samba-dc-libs-4.17.5-103.0.1.el9_2.aarch64.rpm samba-dcerpc-4.17.5-103.0.1.el9_2.aarch64.rpm samba-krb5-printing-4.17.5-103.0.1.el9_2.aarch64.rpm samba-ldb-ldap-modules-4.17.5-103.0.1.el9_2.aarch64.rpm samba-libs-4.17.5-103.0.1.el9_2.aarch64.rpm samba-tools-4.17.5-103.0.1.el9_2.aarch64.rpm samba-usershares-4.17.5-103.0.1.el9_2.aarch64.rpm samba-vfs-iouring-4.17.5-103.0.1.el9_2.aarch64.rpm samba-winbind-4.17.5-103.0.1.el9_2.aarch64.rpm samba-winbind-clients-4.17.5-103.0.1.el9_2.aarch64.rpm samba-winbind-krb5-locator-4.17.5-103.0.1.el9_2.aarch64.rpm samba-winbind-modules-4.17.5-103.0.1.el9_2.aarch64.rpm libnetapi-devel-4.17.5-103.0.1.el9_2.aarch64.rpm libsmbclient-devel-4.17.5-103.0.1.el9_2.aarch64.rpm libwbclient-devel-4.17.5-103.0.1.el9_2.aarch64.rpm python3-samba-devel-4.17.5-103.0.1.el9_2.aarch64.rpm python3-samba-test-4.17.5-103.0.1.el9_2.aarch64.rpm samba-devel-4.17.5-103.0.1.el9_2.aarch64.rpm samba-pidl-4.17.5-103.0.1.el9_2.noarch.rpm samba-test-4.17.5-103.0.1.el9_2.aarch64.rpm samba-test-libs-4.17.5-103.0.1.el9_2.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//samba-4.17.5-103.0.1.el9_2.src.rpm Related CVEs: CVE-2023-3347 Description of changes: [4.17.5-103.0.1] - Fix memleak in _nss_winbind_initgroups_dyn [Orabug: 34994509] [4.17.5-103] - resolves: rhbz#2223600 - Fix trustrelationship between workstation and DC - resolves: rhbz#2222895 - Fix CVE-2023-3347 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 has rolled out ELSA-2023-4325 for samba, targeting memory leak and trust concerns. For further information, explore the complete update.. Oracle Linux, Samba Update, Security Advisory, ELSA-2023-4325. . LinuxSecurity.com Team

Calendar 2 Aug 10, 2023 Oracle
98

Red Hat Enterprise Linux 9 RHSA-2023-4350-01 Moderate: Proxy Leak Fix

An update for python-requests is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python-requests security update Advisory ID: RHSA-2023:4350-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4350 Issue date: 2023-08-01 CVE Names: CVE-2023-32681 ===================================================================== 1. Summary: An update for python-requests is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - noarch Red Hat Enterprise Linux BaseOS (v. 9) - noarch 3. Description: The python-requests package contains a library designed to make HTTP requests easy for developers. Security Fix(es): * python-requests: Unintended leak of Proxy-Authorization header (CVE-2023-32681) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2209469 - CVE-2023-32681 python-requests: Unintended leak of Proxy-Authorization header 6. Package List: Red Hat Enterprise Linux AppStream (v.9): noarch: python3-requests+security-2.25.1-7.el9_2.noarch.rpm python3-requests+socks-2.25.1-7.el9_2.noarch.rpm Red Hat Enterprise Linux BaseOS (v. 9): Source: python-requests-2.25.1-7.el9_2.src.rpm noarch: python3-requests-2.25.1-7.el9_2.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkyRTsAAoJENzjgjWX9erEU4AP/16Fa0Oaj9KCTbQr/zNZ+s3I okLWs8KH6W2eiF8NqeeKPf7/R0uCDjl+dgNMHR4ZSQzfmKsY1HQe0Uq8CHevAWJL 66PDIyxpJZZZ/vzMx5lmSZbnAcrwjA9pumboa9YqRkPCAZf59Af9SuythGKxdv4q ltmwaVpXiEpZ7MimSc5oqfea+3gAQgePppQB7jg3lIdXgl8YGf8pnHFUjsICVveJ YZ/XGDRkG0tJx+AhNlkRwEEZUuMWDEeIdv32l43PkxR7i0UbBYgEC3hZdP2J4wLo MfP9QrEj1W+LhYluhLNe3Yj7iHOVSYfzf4SQkqeRCv3AadeNRQlfxBE/s+WlG6xE wQlKhiD+s0Y3XQfQwSIY+qB7aVEWYhyReUmL6kehmFUxW0WSHHEGbq6AAAyTjC2Y Tj2NCKLcTqkwCg+iUVzkjG5JwvWNjspN9FkAIY0plbHogWgfNFJ1arzBQghW3a3O fD8IeWxNSigo8yXirKPfH4x7WHXEWnW2ISGgamCsI1FxC9GZe49WGnxerD4YosIw RuwsRNknqCe6xara0NLhHJj+IA4V1ldIenNJC4LvvVGruxGzUhyigzbu3NMjJDxP O/hP0rz+DLU1MKdQSoyNYzIGq3R8mqeBu0efoWx7z2E8E2tgKbujSgfFx0QP5ztY bm+MjCCftFTN2LfNf1Ff =q/ez -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat introduces a significant patch for python-requests, fixing a proxy information exposure issue in Enterprise Linux 9.. Red Hat Enterprise Linux 9, python-requests update, HTTP requests security, moderate security fix, proxy authorization leak. . LinuxSecurity.com Team

Calendar 2 Aug 01, 2023 Red Hat
98

Red Hat OpenShift 4.11.42 Moderate: RHSA-2023:3309-01 DoS Security Threat

Red Hat OpenShift Container Platform release 4.11.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: OpenShift Container Platform 4.11.42 bug fix and security update Advisory ID: RHSA-2023:3309-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2023:3309 Issue date: 2023-05-31 CVE Names: CVE-2018-17419 CVE-2022-25147 CVE-2023-25652 CVE-2023-25815 CVE-2023-28617 CVE-2023-29007 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.11.42 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11. Red Hat Product Security has rated this update as having a security impact of [impact]. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.11.42. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHBA-2023:3308 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about thesechanges: https://docs.redhat.com/en/documentation/openshift_container_platform/4.11/html/release_notes/ocp-4-11-release-notes Security Fix(es): * dns: Denial of Service (DoS) (CVE-2018-17419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.11/html/updating_clusters/updating-cluster-cli 3. Solution: For OpenShift Container Platform 4.11 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.11/html/release_notes/ocp-4-11-release-notes You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are: (For x86_64 architecture) The image digest is sha256:518177a34452837920f1e77944f6afa08864537260c9f742b8c88b6157e4f901 (For s390x architecture) The image digest is sha256:c8f1891f3d4a93104a209b96987e07e2077b685238a246da12a656bf69be88c3 (For ppc64le architecture) The image digest is sha256:19ad52422acbd24dde71ae5089471c541004e1c0bf4e13e081e5b65220600c15 (For aarch64 architecture) The image digest is sha256:d87fcd39ad6fad29454ff9137ce521d7049cda2b391ccbdd34554427d60bd27b All OpenShift Container Platform 4.11 users are advised to upgrade to these updated packages and images when they are available in theappropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.11/html/updating_clusters/updating-cluster-cli 4. Bugs fixed (https://bugzilla.redhat.com/): 2188523 - CVE-2018-17419 dns: Denial of Service (DoS) 5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects): OCPBUGS-10276 - [4.11] Lazily unmount /proc/cmdline OCPBUGS-12231 - Pipeline Repository (Pipeline-as-Code) list page shows an empty Event type column OCPBUGS-12254 - MetalLB operator 4.11 update fails with addressPool apiVersion conversion OCPBUGS-12263 - opm fails to serve FBC if cachedir not provided OCPBUGS-12279 - Developer catalog shows ImageStreams as samples which has no sampleRepo OCPBUGS-12284 - 'gitlab.secretReference' disappears when the buildconfig is edited on ?From View? OCPBUGS-12959 - update the default pipelineRun template name OCPBUGS-13730 - Show type of sample on the samples view OCPBUGS-13746 - PipelineRun templates must be fetched from OpenShift namespace OCPBUGS-13792 - Failed to create STS resources on AWS GovCloud regions using ccoctl OCPBUGS-13822 - Yum Config Manager Not Found OCPBUGS-13864 - Pipeline is not removed when Deployment/DC/Knative Service or Application is deleted 6. References: https://access.redhat.com/security/cve/CVE-2018-17419 https://access.redhat.com/security/cve/CVE-2022-25147 https://access.redhat.com/security/cve/CVE-2023-25652 https://access.redhat.com/security/cve/CVE-2023-25815 https://access.redhat.com/security/cve/CVE-2023-28617 https://access.redhat.com/security/cve/CVE-2023-29007 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/openshift_container_platform/4.11/html/release_notes/ocp-4-11-release-notes 7. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat,Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZHsDvNzjgjWX9erEAQiTFA/+IpKH8pbUZ2wQuRL930DfIKjSsF7TslNk CXUm++vIXt7/dw0y0UWnEMElhnzJAdQKYSSYFdC+L/jaVIzCgP8TlihWkEP7RRe8 RZNY9J9q5M8nNealWsP09LYjHvsPS4FvZtWvWQsvyikTzo/4/B7NQtoAwr0G/ZoR 2oTnh0SCZaST/5PeKGFf2IiQ+wUmHhrOpgvwe+oX+dQvSHjLtstp991EF8YDX4Hf 14+wY5uARNcZ38ds0ut5VJZFb5LMxQRdLW+h89EKwj76XD/mF8b67gqBzsSCK+bT X6mh2VS3vVrpEOGpAi09wGsoAjbLd1Xq8aVhgDa1vyPSDms63YNPMsJLTjCXsKF1 cn3zrHW3uJZr0touwVvuH8IWwo2Uk1kUJaZp37ORIeF6pc7AD8IsZRSZBzJPC1zG m0LHJNxwctIxQQJTsb/XosAz8GvbqyVdoO4IAWUlZbYD4MBDSK42ae1lxzulmeZa p652arSzOAveE4rUbUG7WAG96AEpEWFR1ZKFer1FJpAljMDIeOy9r1/T8+XWHZL7 TRWq6bh9RSewS3wl2gT/rxhcx5B+2Wx2A6pSEdYYnJMY2I9DIxPmOLBJjRw3jqJ+ sCM6xwIh6Db2TCyKzIOefUO4VoBDuQGtgsWHcz/sxxar/mOFCxYg0JOXtB7rGmbL 8whGNsEZG+s=yccR -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Red Hat OpenShift Container Platform version 4.11.42 releases fix multiple issues and includes a significant security enhancement for its users.. OpenShift Updates, Security Fixes, Container Management. . LinuxSecurity.com Team

Calendar 2 Jun 03, 2023 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here