Fix crash in event loop (CVE-2024-4418) Fix leak of GSource object Fix leak of udev object reference. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ee96e0c470 2024-06-11 01:48:54.482850 -------------------------------------------------------------------------------- Name : libvirt Product : Fedora 40 Version : 10.1.0 Release : 2.fc40 URL : https://libvirt.org/ Summary : Library providing a simple virtualization API Description : Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support. -------------------------------------------------------------------------------- Update Information: Fix crash in event loop (CVE-2024-4418) Fix leak of GSource object Fix leak of udev object reference -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278616 - CVE-2024-4418 libvirt: stack use-after-free in virNetClientIOEventLoop() https://bugzilla.redhat.com/show_bug.cgi?id=2278616 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ee96e0c470' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Security fix for CVE-2015-7581 Security fix for CVE-2016-0751 Security fix for CVE-2015-7576. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f486068393 2016-02-28 08:31:31.054902 -------------------------------------------------------------------------------- Name : rubygem-actionpack Product : Fedora 23 Version : 4.2.3 Release : 4.fc23 URL : https://rubyonrails.org/ Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn't require a browser. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7581 Security fix for CVE-2016-0751 Security fix for CVE-2015-7576 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1301933 - CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller https://bugzilla.redhat.com/show_bug.cgi?id=1301933 [ 2 ] Bug #1301946 - CVE-2016-0751 rubygem-actionpack: possible object leak and denial of service attack in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301946 [ 3 ] Bug #1301981 - CVE-2015-7581 rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301981 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionpack' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Security fix for CVE-2015-7581 CVE-2015-7576 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-94e71ee673 2016-02-28 04:00:02.128575 -------------------------------------------------------------------------------- Name : rubygem-activemodel Product : Fedora 22 Version : 4.2.0 Release : 2.fc22 URL : https://rubyonrails.org/ Summary : A toolkit for building modeling frameworks Description : Rich support for attributes, callbacks, validations, observers, serialization, internationalization, and testing. It provides a known set of interfaces for usage in model classes. It also helps building custom ORMs for use outside of the Rails framework. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7581 CVE-2015-7576 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1301973 - CVE-2016-0753 rubygem-activemodel, rubygem-activerecord: possible input validation circumvention in Active Model https://bugzilla.redhat.com/show_bug.cgi?id=1301973 [ 2 ] Bug #1301933 - CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller https://bugzilla.redhat.com/show_bug.cgi?id=1301933 [ 3 ] Bug #1301946 - CVE-2016-0751 rubygem-actionpack: possible object leak and denial of service attack in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301946 [ 4 ] Bug #1301981 - CVE-2015-7581 rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301981 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activemodel' at the command line. Formore information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.