Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-3354 http://linux.oracle.com/errata/ELSA-2026-3354.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: python3-pyasn1-0.6.2-1.el10_1.noarch.rpm python3-pyasn1-modules-0.6.2-1.el10_1.noarch.rpm aarch64: python3-pyasn1-0.6.2-1.el10_1.noarch.rpm python3-pyasn1-modules-0.6.2-1.el10_1.noarch.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/python-pyasn1-0.6.2-1.el10_1.src.rpm Related CVEs: CVE-2026-23490 Description of changes: [0.6.2-1] - Update to 0.6.2 - Update modules to 0.4.2 Resolves: RHEL-148142 _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-2410 http://linux.oracle.com/errata/ELSA-2026-2410.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: libsoup3-3.6.5-3.el10_1.10.x86_64.rpm libsoup3-devel-3.6.5-3.el10_1.10.x86_64.rpm libsoup3-doc-3.6.5-3.el10_1.10.noarch.rpm aarch64: libsoup3-3.6.5-3.el10_1.10.aarch64.rpm libsoup3-devel-3.6.5-3.el10_1.10.aarch64.rpm libsoup3-doc-3.6.5-3.el10_1.10.noarch.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/libsoup3-3.6.5-3.el10_1.10.src.rpm Related CVEs: CVE-2026-1761 Description of changes: [3.6.5-10] - Add patch for CVE-2026-1761 [3.6.5-9] - Fix CVE-2026-0719 [3.6.5-8] - Fix CVE-2025-14523 [3.6.5-7] - Add patch for CVE-2025-12105 [3.6.5-6] - Fix integer overflow in date/time parsing [3.6.5-5] - Bump revision number [3.6.5-4] - Fix several CVEs _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7418 http://linux.oracle.com/errata/ELSA-2025-7418.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: apcu-panel-5.1.23-1.module+el9.6.0+90525+5083e899.noarch.rpm php-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-bcmath-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-cli-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-common-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-dba-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-dbg-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-devel-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-embedded-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-enchant-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-ffi-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-fpm-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-gd-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-gmp-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-intl-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-ldap-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-mbstring-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-mysqlnd-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-odbc-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-opcache-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-pdo-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.x86_64.rpm php-pecl-apcu-devel-5.1.23-1.module+el9.6.0+90525+5083e899.x86_64.rpm php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.x86_64.rpm php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.x86_64.rpm php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.x86_64.rpm php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.x86_64.rpm php-pgsql-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-process-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-snmp-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-soap-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm php-xml-8.3.19-1.module+el9.6.0+90584+da8065b7.x86_64.rpm aarch64: apcu-panel-5.1.23-1.module+el9.6.0+90525+5083e899.noarch.rpm php-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-bcmath-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-cli-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-common-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-dba-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-dbg-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-devel-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-embedded-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-enchant-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-ffi-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-fpm-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-gd-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-gmp-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-intl-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-ldap-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-mbstring-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-mysqlnd-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-odbc-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-opcache-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-pdo-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.aarch64.rpm php-pecl-apcu-devel-5.1.23-1.module+el9.6.0+90525+5083e899.aarch64.rpm php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.aarch64.rpm php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.aarch64.rpm php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.aarch64.rpm php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.aarch64.rpm php-pgsql-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-process-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-snmp-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-soap-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm php-xml-8.3.19-1.module+el9.6.0+90584+da8065b7.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//php-8.3.19-1.module+el9.6.0+90584+da8065b7.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//php-pecl-apcu-5.1.23-1.module+el9.6.0+90525+5083e899.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//php-pecl-redis6-6.1.0-2.module+el9.6.0+90525+5083e899.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//php-pecl-rrd-2.0.3-4.module+el9.6.0+90525+5083e899.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//php-pecl-xdebug3-3.3.1-1.module+el9.6.0+90525+5083e899.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//php-pecl-zip-1.22.3-1.module+el9.6.0+90525+5083e899.src.rpm Related CVEs: CVE-2024-11235 CVE-2025-1217 CVE-2025-1219 CVE-2025-1734 CVE-2025-1736 CVE-2025-1861 Description of changes: php [8.3.19-1] - rebase to 8.3.19 [8.3.15-1] - rebase to 8.3.15 [8.3.12-1] - rebase to 8.3.12 RHEL-62189 - enable command history in phpdbg - backport Argon2 password hashing in OpenSSL ext - build sockets extension statically - switch to nikic/php-parser version 5 - openssl: always warn about missing curve_name [8.2.13-1] - rebase to 8.2.13 RHEL-14699 - add %__phpize and %__phpconfig macros - move httpd/nginx wants directives to config files in /etc - php-fpm.conf: move include directive after [global] section following upstream example, allowing overriding - use SPDX license IDs php-pecl-apcu php-pecl-redis6 [6.1.0-2] - ignore 1 ONLINE test [6.1.0-1] - RHEL build [6.1.0-1] - update to 6.1.0 - drop patch merged upstream [6.1.0~RC2-1] - update to 6.1.0RC2 - fix test suite with redis 6.2 using patch from https://github.com/phpredis/phpredis/pull/2555 [6.0.2-3] - cleanup and modernize spec file [6.0.2-2] - use valkey on Fedora 41 - add upstream patch for PHP 8.4 [6.0.2-1] - update to 6.0.2 [6.0.1-1] - update to 6.0.1 [6.0.0-1] - cleanup SCL stuff for Fedora review [6.0.0-1] php-pecl-rrd php-pecl-xdebug3 [3.3.1-1] - update to 3.3.1 for PHP 8.3 php-pecl-zip _______________________________________________ El-errata mailing list
This release fixes CVE-2024-13939 (leaking the length of a secret string). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ce51c124a5 2025-04-17 18:59:47.310408+00:00 -------------------------------------------------------------------------------- Name : perl-String-Compare-ConstantTime Product : Fedora 42 Version : 0.321 Release : 22.fc42 URL : https://metacpan.org/dist/String-Compare-ConstantTime Summary : Timing side-channel protected string compare Description : This module provides one function, "equals", which works like perl's "eq", but which does not provide a timing side-channel. Such comparison is useful when matching against a secret string. -------------------------------------------------------------------------------- Update Information: This release fixes CVE-2024-13939 (leaking the length of a secret string) -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 1 2025 Petr Pisar - 0.321-22 - Fix CVE-2024-13939 (leaking the length of a secret string) (bug #2355705) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2355663 - CVE-2024-13939 String-Compare-ConstantTime: String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the length of a secret string https://bugzilla.redhat.com/show_bug.cgi?id=2355663 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ce51c124a5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1740 http://linux.oracle.com/errata/ELSA-2025-1740.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: pgaudit-16.0-1.module+el8.10.0+90275+c15b12cb.x86_64.rpm pg_repack-1.5.1-1.module+el8.10.0+90451+109c7b24.x86_64.rpm postgres-decoderbufs-2.4.0-1.Final.module+el8.10.0+90275+c15b12cb.x86_64.rpm postgresql-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-contrib-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-docs-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-plperl-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-plpython3-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-pltcl-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-private-devel-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-private-libs-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-server-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-server-devel-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-static-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-test-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-test-rpm-macros-16.8-1.module+el8.10.0+90530+9eb57222.noarch.rpm postgresql-upgrade-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm postgresql-upgrade-devel-16.8-1.module+el8.10.0+90530+9eb57222.x86_64.rpm aarch64: pgaudit-16.0-1.module+el8.10.0+90275+c15b12cb.aarch64.rpm pg_repack-1.5.1-1.module+el8.10.0+90451+109c7b24.aarch64.rpm postgres-decoderbufs-2.4.0-1.Final.module+el8.10.0+90275+c15b12cb.aarch64.rpm postgresql-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-contrib-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-docs-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-plperl-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-plpython3-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-pltcl-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-private-devel-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-private-libs-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-server-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-server-devel-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-static-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-test-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-test-rpm-macros-16.8-1.module+el8.10.0+90530+9eb57222.noarch.rpm postgresql-upgrade-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm postgresql-upgrade-devel-16.8-1.module+el8.10.0+90530+9eb57222.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//pgaudit-16.0-1.module+el8.10.0+90275+c15b12cb.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pg_repack-1.5.1-1.module+el8.10.0+90451+109c7b24.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgres-decoderbufs-2.4.0-1.Final.module+el8.10.0+90275+c15b12cb.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//postgresql-16.8-1.module+el8.10.0+90530+9eb57222.src.rpm Related CVEs: CVE-2025-1094 Description of changes: pgaudit [16.0-1] - Update to 16.0 - Support postgresql 16 - Initial import for PG 16 module - Resolves: RHEL-3636 pg_repack [1.5.1-1] - Update to 1.5.1 postgres-decoderbufs [2.4.0-1.Final] - Initial import for postgresql 16 stream - Related: RHEL-3636 postgresql [16.8-1] - Update to 16.8 - Fix CVE-2025-1094 _______________________________________________ El-errata mailing list
nodejs:22 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2025:0734","synopsis":"nodejs:22 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for module.nodejs-packaging, nodejs-nodemon, nodejs-packaging, module.nodejs-nodemon, nodejs, module.nodejs.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nBug Fix(es) and Enhancement(s):\n\n* Add Node.js v22 to Rocky Linux8 AppStream (JIRA:Rocky Linux-35991)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-02-13T20:34:26.141542Z","rpms":{"Rocky Linux8":{"nvras":["nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.src.rpm","nodejs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-debugsource-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-devel-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-docs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.noarch.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-full-i18n-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.aarch64.rpm","nodejs-libs-debuginfo-1:22.11.0-1.module+el8.10.0+1924+614dc87f.x86_64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.10.0+1666+930e28e8.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.10.0+1667+4a788d89.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.10.0+1667+4a788d89.noarch.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","npm-1:10.9.0-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.aarch64.rpm","v8-12.4-devel-3:12.4.254.21-1.22.11.0.1.module+el8.10.0+1924+614dc87f.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 setup by integrating the latest Node.js v22 enhancements, featuring essential bug resolutions and performance improvements.. Node.js Update, Rocky Linux Security Fix, Bug Fixes,Enhancements. . LinuxSecurity.com Team
Important: postgresql:12 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:10785", "synopsis": "Important: postgresql:12 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pgaudit, postgresql, module.pgaudit, pg_repack, module.postgres-decoderbufs, module.pg_repack, postgres-decoderbufs, module.postgresql.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PostgreSQL is an advanced object-relational database management system (DBMS).\n\nSecurity Fix(es):\n\n* postgresql: PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID (CVE-2024-10978)\n\n* postgresql: PostgreSQL PL/Perl environment variable changes execute arbitrary code (CVE-2024-10979)\n\n* postgresql: PostgreSQL row security below e.g. subqueries disregards user ID changes (CVE-2024-10976)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2326251", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326251", "description": ""}, {"ticket": "2326253", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326253", "description": ""}, {"ticket": "2326263", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2326263", "description": ""}], "cves": [{"name": "CVE-2024-10976", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10976", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-10978", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10978", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe":"UNKNOWN"}, {"name": "CVE-2024-10979", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-10979", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-12-19T04:18:05.672002Z", "rpms": {"Rocky Linux 8": {"nvras": ["pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.src.rpm", "pgaudit-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pgaudit-debuginfo-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-debuginfo-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pgaudit-debugsource-0:1.4.0-7.module+el8.9.0+1735+a332307b.aarch64.rpm", "pgaudit-debugsource-0:1.4.0-7.module+el8.9.0+1735+a332307b.x86_64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.src.rpm", "pg_repack-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-debuginfo-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+1862+29bef648.aarch64.rpm", "pg_repack-debugsource-0:1.4.6-3.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.src.rpm", "postgres-decoderbufs-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-debuginfo-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+1862+29bef648.aarch64.rpm", "postgres-decoderbufs-debugsource-0:0.10.0-2.module+el8.10.0+1862+29bef648.x86_64.rpm", "postgresql-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-0:12.22-1.module+el8.10.0+1897+c7883fde.src.rpm", "postgresql-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm","postgresql-contrib-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-contrib-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-contrib-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-contrib-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-debugsource-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-debugsource-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-docs-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-docs-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-docs-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-docs-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-plperl-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-plperl-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-plperl-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-plperl-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-plpython3-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-plpython3-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-plpython3-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-plpython3-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-pltcl-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-pltcl-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-pltcl-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-pltcl-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-server-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-server-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm","postgresql-server-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-server-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-server-devel-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-server-devel-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-server-devel-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-server-devel-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-static-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-static-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-test-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-test-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-test-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-test-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-test-rpm-macros-0:12.22-1.module+el8.10.0+1897+c7883fde.noarch.rpm", "postgresql-upgrade-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-upgrade-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-upgrade-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-upgrade-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-upgrade-devel-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-upgrade-devel-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm", "postgresql-upgrade-devel-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.aarch64.rpm", "postgresql-upgrade-devel-debuginfo-0:12.22-1.module+el8.10.0+1897+c7883fde.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 8 introduces a critical update for PostgreSQL, targeting several security vulnerabilities. Explore the specifics regarding impacted components and available patches.. PostgreSQL Update, Rocky Linux 8, Security Fix. . Severity: Important. LinuxSecurity.com Team
Important: httpd:2.4 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:5193", "synopsis": "Important: httpd:2.4 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for module.mod_md, module.mod_http2, mod_http2, httpd, mod_md, module.httpd.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.\n\nSecurity Fix(es):\n\n* httpd: Security issues via?backend applications whose response headers are malicious or exploitable (CVE-2024-38476)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2295015", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2295015", "description": ""}], "cves": [{"name": "CVE-2024-38476", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-38476", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-21T14:52:31.100489Z", "rpms": {"Rocky Linux 8": {"nvras": ["httpd-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "httpd-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.src.rpm", "httpd-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "httpd-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "httpd-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "httpd-debugsource-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "httpd-debugsource-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "httpd-devel-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm","httpd-devel-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "httpd-filesystem-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.noarch.rpm", "httpd-manual-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.noarch.rpm", "httpd-tools-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "httpd-tools-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "httpd-tools-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "httpd-tools-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_http2-0:1.15.7-10.module+el8.10.0+1775+6b057638.aarch64.rpm", "mod_http2-0:1.15.7-10.module+el8.10.0+1775+6b057638.src.rpm", "mod_http2-0:1.15.7-10.module+el8.10.0+1775+6b057638.x86_64.rpm", "mod_http2-debuginfo-0:1.15.7-10.module+el8.10.0+1775+6b057638.aarch64.rpm", "mod_http2-debuginfo-0:1.15.7-10.module+el8.10.0+1775+6b057638.x86_64.rpm", "mod_http2-debugsource-0:1.15.7-10.module+el8.10.0+1775+6b057638.aarch64.rpm", "mod_http2-debugsource-0:1.15.7-10.module+el8.10.0+1775+6b057638.x86_64.rpm", "mod_ldap-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_ldap-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_ldap-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_ldap-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_md-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.aarch64.rpm", "mod_md-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.src.rpm", "mod_md-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.x86_64.rpm", "mod_md-debuginfo-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.aarch64.rpm", "mod_md-debuginfo-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.x86_64.rpm", "mod_md-debugsource-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.aarch64.rpm", "mod_md-debugsource-1:2.0.8-8.module+el8.9.0+1370+89cc8ad5.x86_64.rpm", "mod_proxy_html-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_proxy_html-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_proxy_html-debuginfo-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm","mod_proxy_html-debuginfo-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_session-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_session-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_session-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_session-debuginfo-0:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_ssl-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_ssl-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm", "mod_ssl-debuginfo-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm", "mod_ssl-debuginfo-1:2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Essential patches released for httpd:2.4 to mitigate significant security vulnerabilities affecting Rocky Linux.. httpd security update, Rocky Linux patch, Apache HTTP fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.