Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 436
Alerts This Week
Warning Icon 1 436

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 25 articles for you...
203

Mageia 8 Advisory: 2021-0509 Moderate OpenAFS Access Control Fix

Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL . MGASA-2021-0509 - Updated openafs packages fix security vulnerability Publication date: 11 Nov 2021 URL: https://advisories.mageia.org/MGASA-2021-0509.html Type: security Affected Mageia releases: 8 CVE: CVE-2018-7168 Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL (opcode 134). These clients add negative access control entries (if any) to the normal rights list. As there is no method by which a fileserver can determine that the ACL is improperly constructed, the only method to defend the storage of broken ACLs is to identify clients that are known to properly construct ACLs by introducing a new RXAFS_StoreACL opcode (164) (CVE-2018-7168). Additionally the CellServDB has been updated to latest version and fixes for suppoorting kernel 5.14 and 5.15 series have been added. References: - https://bugs.mageia.org/show_bug.cgi?id=29639 - https://www.cve.org/CVERecord?id=CVE-2018-7168 SRPMS: - 8/core/openafs-1.9.1-1.mga8 . A significant security enhancement for Mageia has been released, targeting a vital flaw in access permissions within AFS3 client applications.. OpenAFS Security Update,Mageia Access Control Fix,Security Patch Mageia,OpenAFS Version 1.9.1. . LinuxSecurity.com Team

Calendar%202 Nov 11, 2021 Mageia
203

Mageia 7: 2019-0383 Moderate: OpenAFS Server Security Fixes

Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref . MGASA-2019-0383 - Updated openafs packages fix security vulnerabilities Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0383.html Type: security Affected Mageia releases: 7 Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref Update to official version 1.8.4: * support Linux-kernel 5.3 * Avoid non-dir ENOENT errors in afs_lookup * fix parsing of fileservers with -vlruthresh, etc. * other bugfixes References: - https://bugs.mageia.org/show_bug.cgi?id=25816 - https://openafs.org/pages/security/OPENAFS-SA-2019-001.txt - https://openafs.org/pages/security/OPENAFS-SA-2019-002.txt - https://openafs.org/pages/security/OPENAFS-SA-2019-003.txt - - http://openafs.org/dl/openafs/1.8.4/RELNOTES-1.8.4 - http://openafs.org/dl/openafs/1.8.5/RELNOTES-1.8.5 SRPMS: - 7/core/openafs-1.8.5-1.mga7 . OpenAFS security enhancements address vulnerabilities involving RPC configurations and server malfunctions on Mageia 7. Discover more details here.. Mageia Security Updates, OpenAFS Vulnerabilities, Mageia 7 Security. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2019 Mageia
202

openSUSE: 2019:2607-1 Moderate: Openafs Security Fix Instructions

An update that contains security fixes can now be installed.. openSUSE Security Update: Recommended update for openafs ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2607-1 Rating: moderate References: Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for openafs fixes the following issues: Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref update to official version 1.8.4 * support Linux-kernel 5.3 * Avoid non-dir ENOENT errors in afs_lookup * fix parsing of fileservers with -vlruthresh, etc. * other bugfixes update to pre-release 1.8.4pre2 * fix builds for Linux-kernels 5.3 update to 1.8.3 - fix broken directory layout - allow crypt to be set/unset on startup of client update to pre-release 1.8.3pre1 * fix builds for Linux-kernels 4.20 and 5.0 * other fixes, see RELNOTES-1.8.3pre1 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2607=1 Package List: - openSUSE Leap 15.1 (x86_64): openafs-1.8.5-lp151.2.3.1 openafs-authlibs-1.8.5-lp151.2.3.1 openafs-authlibs-debuginfo-1.8.5-lp151.2.3.1 openafs-authlibs-devel-1.8.5-lp151.2.3.1 openafs-client-1.8.5-lp151.2.3.1 openafs-client-debuginfo-1.8.5-lp151.2.3.1 openafs-debuginfo-1.8.5-lp151.2.3.1 openafs-debugsource-1.8.5-lp151.2.3.1 openafs-devel-1.8.5-lp151.2.3.1 openafs-devel-debuginfo-1.8.5-lp151.2.3.1 openafs-fuse_client-1.8.5-lp151.2.3.1 openafs-fuse_client-debuginfo-1.8.5-lp151.2.3.1 openafs-kernel-source-1.8.5-lp151.2.3.1 openafs-kmp-default-1.8.5_k4.12.14_lp151.28.32-lp151.2.3.1 openafs-kmp-default-debuginfo-1.8.5_k4.12.14_lp151.28.32-lp151.2.3.1 openafs-server-1.8.5-lp151.2.3.1 openafs-server-debuginfo-1.8.5-lp151.2.3.1 References: -- . This patch for Fedora addresses vulnerabilities in samba with a moderate impact, promoting better system security.. openSUSE Security Update, openafs, system security fixes, moderate severity updates. . LinuxSecurity.com Team

Calendar%202 Dec 02, 2019 OpenSUSE
197

Debian 8: DLA-1982-1 Critical OpenAFS Denial Of Service Issue

Several security vulnerabilities were discovered in OpenAFS, a distributed file system. CVE-2019-18601 . Package : openafs Version : 1.6.9-2+deb8u9 CVE ID : CVE-2019-18601 CVE-2019-18602 CVE-2019-18603 Debian Bug : 943587 Several security vulnerabilities were discovered in OpenAFS, a distributed file system. CVE-2019-18601 OpenAFS is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler. CVE-2019-18602 OpenAFS is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer. CVE-2019-18603 OpenAFS is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. For Debian 8 "Jessie", these problems have been fixed in version 1.6.9-2+deb8u9. We recommend that you upgrade your openafs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest OpenAFS update rectifies vulnerabilities related to denial of service and information exposure in Debian 8, incorporating numerous security enhancements.. OpenAFS Security Update, Debian LTS, Denial Of Service, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 05, 2019 Critical Debian LTS
203

Mageia 6: MGASA-2019-0021 Critical: Openafs DoS and Authentication Issues

Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947). . MGASA-2019-0021 - Updated openafs packages fix security vulnerabilities Publication date: 08 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0021.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16947, CVE-2018-16948, CVE-2018-16949 Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947). Mark Vitale reported that several RPC server routines do not fully initialize output variables, leaking memory contents (from both the stack and the heap) to the remote caller for otherwise-successful RPCs (CVE-2018-16948). Mark Vitale reported that an unauthenticated attacker can consume large amounts of server memory and network bandwidth via specially crafted requests, resulting in denial of service to legitimate clients (CVE-2018-16949). References: - https://bugs.mageia.org/show_bug.cgi?id=23663 - https://openafs.org/pages/security/OPENAFS-SA-2018-001.txt - https://openafs.org/pages/security/OPENAFS-SA-2018-002.txt - https://openafs.org/pages/security/OPENAFS-SA-2018-003.txt - http://openafs.org/dl/openafs/1.6.23/RELNOTES-1.6.23 - https://lists.debian.org/debian-security-announce/2018/msg00233.html - https://www.cve.org/CVERecord?id=CVE-2018-16947 - https://www.cve.org/CVERecord?id=CVE-2018-16948 - https://www.cve.org/CVERecord?id=CVE-2018-16949 SRPMS: - 6/core/openafs-1.6.23-1.mga6 . MGASA-2019-0021 - Updated openafs packages fix security vulnerabilities Publication date: 08 Jan 201. jeffrey, altman, reported, backup, controller, (butc), process, accept, incoming. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jan 08, 2019 Critical Mageia
87

Debian 9 DSA-4302-1 Critical: Openafs Denial Of Service Issues

Several vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4302-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 23, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openafs CVE ID : CVE-2018-16947 CVE-2018-16948 CVE-2018-16949 Debian Bug : 908616 Several vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2018-16947 Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials. https://openafs.org/pages/security/OPENAFS-SA-2018-001.txt CVE-2018-16948 Mark Vitale reported that several RPC server routines do not fully initialize output variables, leaking memory contents (from both the stack and the heap) to the remote caller for otherwise-successful RPCs. https://openafs.org/pages/security/OPENAFS-SA-2018-002.txt CVE-2018-16949 Mark Vitale reported that an unauthenticated attacker can consume large amounts of server memory and network bandwidth via specially crafted requests, resulting in denial of service to legitimate clients. https://openafs.org/pages/security/OPENAFS-SA-2018-003.txt For the stable distribution (stretch), these problems have been fixed in version 1.6.20-2+deb9u2. We recommend that you upgrade your openafs packages. For the detailed security status of openafs pleaserefer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openafs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-4302-1 addresses critical vulnerabilities in OpenAFS, stemming from poor input sanitization and access controls, risking unauthorized access and data leakage. openafs security update, debian dsa-4302-1, distributed filesystem fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 23, 2018 Critical Debian
200

Scientific Linux: OPENAFS-SA-2016-003 Moderate: Directory Leak Fix

Moderate: openafs security and enhancement update . Date: Tue, 13 Dec 2016 16:02:09 +0000 Reply-To: Scott Reid Sender: Security Errata for Scientific Linux From: Scott Reid Subject: FASTBUGS for SL 6x i386, x86_64 now available Comments: To: scientific-linux-errata MIME-Version: 1.0 Message-ID: --_000_D475779F33B8Csvreidfnalgov_ The following FASTBUGS have been uploaded to i386: 6x/i386/chrony-2.1.1-2.el6_8.i686.rpm x86_64: 6x/x86_64/chrony-2.1.1-2.el6_8.x86_64.rpm --_000_D475779F33B8Csvreidfnalgov_ 6x/i386/chrony-2.1.1-2.el6_8.i686.rpm 6x/x86_64/chrony-2.1.1-2.el6_8.x86_64.rpm --_000_D475779F33B8Csvreidfnalgov_-- Date: Wed, 14 Dec 2016 17:38:25 +0000 Reply-To: Scott Reid Sender: Security Errata for Scientific Linux From: Scott Reid Subject: Security ERRATA Moderate: OpenAFS on SL5.x, SL6.x, SL7.x i386/x86_64 Comments: To: scientific-linux-errata MIME-Version: 1.0 Message-ID: --_000_D476DFB033EA1svreidfnalgov_ Synopsis: Moderate: openafs security and enhancement update Advisory ID: OPENAFS-SA-2016-003 Issue Date: 2016-12-14 -- Security Fix(es): There are three different kinds of "dead" residual directory entry leaks, each with a different cause: 1. There may be partial name data after the null terminator in a live directory entry. This happens when a previously used directory entry becomes free, then is reused for a directory entry with a shorter name. 2. "Dead" directory entries are left uncleared after an object is deleted or renamed. 3. Residual directory entries may be inadvertently picked up when a new directory is created or an existing directory is extended by a 2kiB page. This happens because the fileserver shares a buffer pool for directories of all AFS users, but does not clear each buffer upon reuse. This is the most severe problembecause the leaked information may be from other directories or volumes for which the AFS user is not authorized. SL5 packages feature a backported patch to the vulnerable code. Enhancement(s): * OpenAFS on SL6 and SL7 has been rebased to1.6.20 -- SL5 x86_64 kernel-module-openafs-2.6.18-416.el5-1.4.15-90.sl5.x86_64.rpm kernel-module-openafs-2.6.18-416.el5xen-1.4.15-90.sl5.x86_64.rpm openafs-1.4.15-90.sl5.x86_64.rpm openafs-authlibs-1.4.15-90.sl5.x86_64.rpm openafs-authlibs-devel-1.4.15-90.sl5.x86_64.rpm openafs-client-1.4.15-90.sl5.x86_64.rpm openafs-compat-1.4.15-90.sl5.x86_64.rpm openafs-debug-1.4.15-90.sl5.x86_64.rpm openafs-devel-1.4.15-90.sl5.x86_64.rpm openafs-kernel-source-1.4.15-90.sl5.x86_64.rpm openafs-kpasswd-1.4.15-90.sl5.x86_64.rpm openafs-krb5-1.4.15-90.sl5.x86_64.rpm openafs-server-1.4.15-90.sl5.x86_64.rpm i386 kernel-module-openafs-2.6.18-416.el5-1.4.15-90.sl5.i686.rpm kernel-module-openafs-2.6.18-416.el5PAE-1.4.15-90.sl5.i686.rpm kernel-module-openafs-2.6.18-416.el5xen-1.4.15-90.sl5.i686.rpm openafs-1.4.15-90.sl5.i386.rpm openafs-authlibs-1.4.15-90.sl5.i386.rpm openafs-authlibs-devel-1.4.15-90.sl5.i386.rpm openafs-client-1.4.15-90.sl5.i386.rpm openafs-compat-1.4.15-90.sl5.i386.rpm openafs-debug-1.4.15-90.sl5.i386.rpm openafs-devel-1.4.15-90.sl5.i386.rpm openafs-kernel-source-1.4.15-90.sl5.i386.rpm openafs-kpasswd-1.4.15-90.sl5.i386.rpm openafs-krb5-1.4.15-90.sl5.i386.rpm openafs-server-1.4.15-90.sl5.i386.rpm SL6 x86_64 kmod-openafs-642-1.6.20-256.sl6.642.6.2.x86_64.rpm openafs-1.6.20-256.sl6.x86_64.rpm openafs-authlibs-1.6.20-256.sl6.x86_64.rpm openafs-authlibs-devel-1.6.20-256.sl6.x86_64.rpm openafs-client-1.6.20-256.sl6.x86_64.rpm openafs-compat-1.6.20-256.sl6.x86_64.rpm openafs-devel-1.6.20-256.sl6.x86_64.rpm openafs-kernel-source-1.6.20-256.sl6.x86_64.rpm openafs-kpasswd-1.6.20-256.sl6.x86_64.rpm openafs-krb5-1.6.20-256.sl6.x86_64.rpm openafs-module-tools-1.6.20-256.sl6.x86_64.rpm openafs-plumbing-tools-1.6.20-256.sl6.x86_64.rpm openafs-server-1.6.20-256.sl6.x86_64.rpm i386 kmod-openafs-642-1.6.20-256.sl6.642.6.2.i686.rpm openafs-1.6.20-256.sl6.i686.rpm openafs-authlibs-1.6.20-256.sl6.i686.rpm openafs-authlibs-devel-1.6.20-256.sl6.i686.rpm openafs-client-1.6.20-256.sl6.i686.rpm openafs-compat-1.6.20-256.sl6.i686.rpm openafs-devel-1.6.20-256.sl6.i686.rpm openafs-kernel-source-1.6.20-256.sl6.i686.rpm openafs-kpasswd-1.6.20-256.sl6.i686.rpm openafs-krb5-1.6.20-256.sl6.i686.rpm openafs-module-tools-1.6.20-256.sl6.i686.rpm openafs-plumbing-tools-1.6.20-256.sl6.i686.rpm openafs-server-1.6.20-256.sl6.i686.rpm SL7 x86_64 kmod-openafs-1.6-sl-514-1.6.20-256.7.514.x86_64.rpm openafs-1.6-sl-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-authlibs-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-authlibs-devel-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-client-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-compat-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-devel-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-kernel-source-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-kpasswd-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-krb5-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-module-tools-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-plumbing-tools-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-server-1.6.20-256.7.x86_64.rpm - Scientific Linux Development Team --_000_D476DFB033EA1svreidfnalgov_ Issue Date: 2016-12-14 There are three different kinds of "dead" residual directory entry

Calendar%202 Dec 14, 2016 Scientific Linux
87

Debian 8 DSA-3569-1 Moderate: OpenAFS DoS and Group Management Issues

Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3569-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 05, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openafs CVE ID : CVE-2015-8312 CVE-2016-2860 Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8312 Potential denial of service caused by a bug in the pioctl logic allowing a local user to overrun a kernel buffer with a single NUL byte. CVE-2016-2860 Peter Iannucci discovered that users from foreign Kerberos realms can create groups as if they were administrators. For the stable distribution (jessie), these problems have been fixed in version 1.6.9-2+deb8u5. For the testing distribution (stretch), these problems have been fixed in version 1.6.17-1. For the unstable distribution (sid), these problems have been fixed in version 1.6.17-1. We recommend that you upgrade your openafs packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover the latest about two OpenAFS vulnerabilities in Debian Security Advisory DSA-3569-1, detailing critical flaws and essential updates for user protection. Debian Security, OpenAFS Patch, Filesystem Security. . LinuxSecurity.com Team

Calendar%202 May 05, 2016 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200