Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 455
Alerts This Week
Warning Icon 1 455

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 39: 2023-9adf4a31cc Critical: Netconsole Buffer Overrun Fix

Update to prevent invalid fragment values from leading to a buffer overrun. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-9adf4a31cc 2023-09-07 22:59:29.614770 -------------------------------------------------------------------------------- Name : netconsd Product : Fedora 39 Version : 0.3 Release : 1.fc39 URL : Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. -------------------------------------------------------------------------------- Update Information: Update to prevent invalid fragment values from leading to a buffer overrun -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 6 2023 Michel Lind - 0.3-1 - Update to 0.3 - Prevent invalid fragment values from leading to a buffer overrun - Use SPDX license identifier -------------------------------------------------------------------------------- References: [ 1 ] Bug #2237785 - netconsd prior to v0.3 susceptible to buffer overrun when processing invalid fragment values https://bugzilla.redhat.com/show_bug.cgi?id=2237785 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-9adf4a31cc' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . This patch addresses memory overflow vulnerabilities in the netconsole service for Fedora 39. Urgent installation advised.. Fedora Update, Software Security, Netconsole Daemon. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 07, 2023 Critical Fedora
89

Fedora 36: FEDORA-2023-80b2470d3c Critical Netconsole Service Update

Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-80b2470d3c 2023-04-02 01:33:23.803455 --------------------------------------------------------------------------------Name : netconsd Product : Fedora 36 Version : 0.2 Release : 1.fc36 URL : Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. --------------------------------------------------------------------------------Update Information: Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 24 2023 Davide Cavalca - 0.2-1 - Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 * Fri Jan 27 2023 Davide Cavalca - 0.1-5 - Backport upstream PR to fix FTBFS * Thu Jan 19 2023 Fedora Release Engineering - 0.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jul 22 2022 Fedora Release Engineering - 0.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2181655 - netconsd-0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2181655 --------------------------------------------------------------------------------This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-80b2470d3c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The netconsd 0.2 release addresses the security vulnerability identified as CVE-2023-28753. This update brings crucial enhancements to the network logging service available in Fedora.. Fedora Update, Netconsd, Security Fix, Remote Logging Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2023 Critical Fedora
89

Fedora 38: 2023-f25098f499 Critical Update for Netconsole Daemon

Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-f25098f499 2023-04-02 00:15:32.501413 --------------------------------------------------------------------------------Name : netconsd Product : Fedora 38 Version : 0.2 Release : 1.fc38 URL : https://facebookmicrosites.github.io/netconsd/ Summary : The Netconsole Daemon Description : This is a daemon for receiving and processing logs from the Linux Kernel, as emitted over a network by the kernel's netconsole module. It supports both the old "legacy" text-only format, and the new extended format added in v4.4. The core of the daemon does nothing but process messages and drop them: in order to make the daemon useful, the user must supply one or more "output modules". These modules are shared object files which expose a small ABI that is called by netconsd with the content and metadata for netconsole messages it receives. --------------------------------------------------------------------------------Update Information: Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 24 2023 Davide Cavalca - 0.2-1 - Update to 0.2 to address CVE-2023-28753; Fixes: RHBZ#2181655 --------------------------------------------------------------------------------References: [ 1 ] Bug #2181655 - netconsd-0.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2181655 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f25098f499' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . In response to CVE-2023-28753, the update refines netconsd, boosting log management functionality and resolving urgent vulnerabilities.. netconsole Daemon Update,Fedora Security Notification,CVE-2023-28753 Fix,Log Processing Daemon. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2023 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200