Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
203

Mageia 2025-0099: freetype2 Security Advisory Updates

An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References: . MGASA-2025-0099 - Updated freetype2 packages fix security vulnerability Publication date: 16 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0099.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-27363 An out of bounds write exists in FreeType versions 2.13.0 and below when attempting to parse font subglyph structures related to TrueType GX and variable font files which may result in arbitrary code execution. References: - https://bugs.mageia.org/show_bug.cgi?id=34095 - https://www.openwall.com/lists/oss-security/2025/03/13/1 - https://gitlab.freedesktop.org/freetype/freetype/-/issues/1322 - https://www.cve.org/CVERecord?id=CVE-2025-27363 SRPMS: - 9/core/freetype2-2.13.0-1.2.mga9 - 9/tainted/freetype2-2.13.0-1.2.mga9.tainted . MGASA-2025-0099 updates for freetype2 fix a critical security bug that allows arbitrary code execution on affected versions.. bounds, write, exists, freetype, versions, below, attempting, parse. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 16, 2025 Critical Mageia
89

Fedora 39: FEDORA-2024-1bd7266df0 High: Chromium Out Of Bounds Issue

update to 128.0.6613.119 High CVE-2024-8362: Use after free in WebAudio High CVE-2024-7970: Out of bounds write in V8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-1bd7266df0 2024-09-09 00:44:16.093139 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 39 Version : 128.0.6613.119 Release : 1.fc39 URL : http://www.chromium.org/Home Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 128.0.6613.119 High CVE-2024-8362: Use after free in WebAudio High CVE-2024-7970: Out of bounds write in V8 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 5 2024 Than Ngo - 128.0.6613.119-1 - update to 128.0.6613.119 * High CVE-2024-8362: Use after free in WebAudio * High CVE-2024-7970: Out of bounds write in V8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2303360 - CVE-2024-7536 chromium: Use after free in WebAudio [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303360 [ 2 ] Bug #2303361 - CVE-2024-6994 chromium: Heap buffer overflow in Layout [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303361 [ 3 ] Bug #2303362 - CVE-2024-6994 chromium: Heap buffer overflow in Layout [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303362 [ 4 ] Bug #2303363 - CVE-2024-7003 chromium: Inappropriate implementation in FedCM [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303363 [ 5 ] Bug #2303364 - CVE-2024-7000 chromium: Use after free in CSS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303364 [ 6] Bug #2303365 - CVE-2024-7003 chromium: Inappropriate implementation in FedCM [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303365 [ 7 ] Bug #2303366 - CVE-2024-6999 chromium: Inappropriate implementation in FedCM [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303366 [ 8 ] Bug #2303367 - CVE-2024-6998 chromium: Use after free in User Education [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303367 [ 9 ] Bug #2303368 - CVE-2024-6997 chromium: Use after free in Tabs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303368 [ 10 ] Bug #2303369 - CVE-2024-7000 chromium: Use after free in CSS [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303369 [ 11 ] Bug #2303370 - CVE-2024-6999 chromium: Inappropriate implementation in FedCM [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303370 [ 12 ] Bug #2303371 - CVE-2024-6996 chromium: Race in Frames [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303371 [ 13 ] Bug #2303372 - CVE-2024-6995 chromium: Inappropriate implementation in Fullscreen [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303372 [ 14 ] Bug #2303373 - CVE-2024-6998 chromium: Use after free in User Education [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303373 [ 15 ] Bug #2303374 - CVE-2024-6997 chromium: Use after free in Tabs [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2303374 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-1bd7266df0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Significant security patch for Fedora 39's Firefox tackles major vulnerabilities to bolster overall safety.. Fedora Update,Fedora 39,Chromium Security Update,WebAudio Issue. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2024 Fedora
98

Red Hat Enterprise Linux 9 RHSA-2022-8078-01 Moderate FLAC Security Fix

An update for flac is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: flac security update Advisory ID: RHSA-2022:8078-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:8078 Issue date: 2022-11-15 CVE Names: CVE-2021-0561 ==================================================================== 1. Summary: An update for flac is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: FLAC stands for Free Lossless Audio Codec. FLAC is similar to Ogg Vorbis, but lossless. The FLAC project consists of the stream format, reference encoders and decoders in library form, a command-line program to encode and decode FLAC files, and a command-line metadata editor for FLAC files. Security Fix(es): * flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c (CVE-2021-0561) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the RedHat Enterprise Linux 9.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2057776 - CVE-2021-0561 flac: out of bound write in append_to_verify_fifo_interleaved_ of stream_encoder.c 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: flac-1.3.3-10.el9.src.rpm aarch64: flac-debuginfo-1.3.3-10.el9.aarch64.rpm flac-debugsource-1.3.3-10.el9.aarch64.rpm flac-libs-1.3.3-10.el9.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9.aarch64.rpm ppc64le: flac-debuginfo-1.3.3-10.el9.ppc64le.rpm flac-debugsource-1.3.3-10.el9.ppc64le.rpm flac-libs-1.3.3-10.el9.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9.ppc64le.rpm s390x: flac-debuginfo-1.3.3-10.el9.s390x.rpm flac-debugsource-1.3.3-10.el9.s390x.rpm flac-libs-1.3.3-10.el9.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9.s390x.rpm x86_64: flac-debuginfo-1.3.3-10.el9.i686.rpm flac-debuginfo-1.3.3-10.el9.x86_64.rpm flac-debugsource-1.3.3-10.el9.i686.rpm flac-debugsource-1.3.3-10.el9.x86_64.rpm flac-libs-1.3.3-10.el9.i686.rpm flac-libs-1.3.3-10.el9.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9.i686.rpm flac-libs-debuginfo-1.3.3-10.el9.x86_64.rpm Red Hat CodeReady Linux Builder (v.9): aarch64: flac-1.3.3-10.el9.aarch64.rpm flac-debuginfo-1.3.3-10.el9.aarch64.rpm flac-debugsource-1.3.3-10.el9.aarch64.rpm flac-devel-1.3.3-10.el9.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9.aarch64.rpm ppc64le: flac-1.3.3-10.el9.ppc64le.rpm flac-debuginfo-1.3.3-10.el9.ppc64le.rpm flac-debugsource-1.3.3-10.el9.ppc64le.rpm flac-devel-1.3.3-10.el9.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9.ppc64le.rpm s390x: flac-1.3.3-10.el9.s390x.rpm flac-debuginfo-1.3.3-10.el9.s390x.rpm flac-debugsource-1.3.3-10.el9.s390x.rpm flac-devel-1.3.3-10.el9.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9.s390x.rpm x86_64: flac-1.3.3-10.el9.x86_64.rpm flac-debuginfo-1.3.3-10.el9.i686.rpm flac-debuginfo-1.3.3-10.el9.x86_64.rpm flac-debugsource-1.3.3-10.el9.i686.rpm flac-debugsource-1.3.3-10.el9.x86_64.rpm flac-devel-1.3.3-10.el9.i686.rpm flac-devel-1.3.3-10.el9.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9.i686.rpm flac-libs-debuginfo-1.3.3-10.el9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-0561 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/9.1_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY3OMatzjgjWX9erEAQirQw/+Ogspm4lU4ref0z1XUq1fPAy7tx1uP9+J gtW+XE0edEaRYkQYsBo7jtyVS9YPcSSEN6i+bhCFh8P+5D5vLvps3gUQMf801RQv M40HS+wjwdcO3R9Mg16yi6nArhnmvg19V2pWgUzqjvQdl/EGYxMtfFJC9nZNa2Pi OZe5HsW4KERMhqcSCOd2N25z6Y0PHEAJnBezm4y+pw8AFFPDX/z7sQbvXsxbrBNW uvkDz83IS7GtOMQEKytoVv9VUgM/j/wcoyb+iskkRmQ8EjQbtZYHokVlae/2B87g OC3DXhITbruQpK6WI8iNreoLK7T9wXfFLTvl8UP3nQwIAO30jbMas2ziPkRf6L+h FS8xnytVQ9alL9xxlpwvWly8igs5u/0w3brdSiZXHDz9f+20D7dkkZQhq6dla4XY wpdZbIPutynjguPtIl1TKG/WnUldYYq+7wiS9eT4zJ3ShAsi1/czQz3Mqkwsankn gxEXAV+5aQhX52RJ4fpXV7DKzDZJyCKyS+Hm0/Ne/AuYQjrxOWqVXbSjWYMOExnA oZEKqInTQ3QdrCrPBo+SkZg2P394PmClydlpCYTMExNYKVLTAkbMCKH3BRYF4cnj w3Vejd7Jd2lx2KbWEVR2tl48J4d2vVRHRe66JP1Kq8kU7Sni3WQLvwXFERueFSU6 9+iIbeADsTs=muDp -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu's notice regarding the AV1 codec patch evaluated as moderate, providing a critical remedy. Keep informed to maintain system integrity.. Red Hat Enterprise Security, FLAC Update, Linux Security Advisory, Moderation Rating. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 15, 2022 Important Red Hat
197

Ubuntu 20.04 Focal: USN-4531-2 Severe: VLC Buffer Overflow

In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3094-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta September 04, 2022 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : flac Version : 1.3.2-3+deb10u2 CVE ID : CVE-2021-0561 Debian Bug : 1006339 In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. For Debian 10 buster, this problem has been fixed in version 1.3.2-3+deb10u2. We recommend that you upgrade your flac packages. For the detailed security status of flac please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/flac Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your flac packages using Debian LTS Advisory DLA-3094-1 to resolve a local data exposure vulnerability.. Debian Flac Security Update, Local Information Leak, Out Of Bounds Check. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 03, 2022 Important Debian LTS
200

Scientific Linux 7.x SLSA-2021-2741-1: firefox Memory Safety Fix

This update upgrades Firefox to version 78.12.0 ESR. * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2021:2741-1 Issue Date: 2021-07-15 CVE Numbers: CVE-2021-30547 CVE-2021-29970 CVE-2021-29976 -- This update upgrades Firefox to version 78.12.0 ESR. Security Fix(es): * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE (CVE-2021-30547) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 - firefox-78.12.0-1.el7_9.x86_64.rpm - firefox-debuginfo-78.12.0-1.el7_9.x86_64.rpm - firefox-78.12.0-1.el7_9.i686.rpm -- - Scientific Linux Development Team . Keep abreast of the significant Firefox enhancement tackling memory security and accessibility challenges within Scientific Linux 7.x.. firefox update, mozilla security, scientific linux, memory safety, accessibility fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2021 Important Scientific Linux
89

Fedora 30: FEDORA-2020-01ed02451f Critical: e2fsprogs Buffer Overflow

Fix a potential out of bounds write when checking a maliciously corrupted file system. This is probably not exploitable on 64-bit platforms, but may be exploitable on 32-bit binaries depending on how the compiler lays out the stack variables. (Addresses CVE-2019-5188) A maliciously corrupted file systems can trigger buffer overruns in the quota code used by e2fsck. (Addresses. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-01ed02451f 2020-02-02 01:53:29.629340 --------------------------------------------------------------------------------Name : e2fsprogs Product : Fedora 30 Version : 1.44.6 Release : 2.fc30 URL : Summary : Utilities for managing ext2, ext3, and ext4 file systems Description : The e2fsprogs package contains a number of utilities for creating, checking, modifying, and correcting any inconsistencies in second, third and fourth extended (ext2/ext3/ext4) file systems. E2fsprogs contains e2fsck (used to repair file system inconsistencies after an unclean shutdown), mke2fs (used to initialize a partition to contain an empty ext2 file system), debugfs (used to examine the internal structure of a file system, to manually repair a corrupted file system, or to create test cases for e2fsck), tune2fs (used to modify file system parameters), and most of the other core ext2fs file system utilities. You should install the e2fsprogs package if you need to manage the performance of an ext2, ext3, or ext4 file system. --------------------------------------------------------------------------------Update Information: Fix a potential out of bounds write when checking a maliciously corrupted file system. This is probably not exploitable on 64-bit platforms, but may be exploitable on 32-bit binaries depending on how the compiler lays out the stack variables. (Addresses CVE-2019-5188) A maliciously corrupted file systems can trigger buffer overruns in the quota code used bye2fsck. (Addresses CVE-2019-5094) Fix potential use after free in calculate_tree() --------------------------------------------------------------------------------ChangeLog: * Thu Jan 16 2020 Lukas Czerner 1.44.6-2 - Prevent buffer overrun bugs in quota code (#1792192) - Fix code execution vulnerability in directory rehashing (#1792193) - Fix use-after-free in calculate_tree --------------------------------------------------------------------------------References: [ 1 ] Bug #1792192 - CVE-2019-5094 e2fsprogs: crafted ext4 partition leads to out-of-bounds write [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1792192 [ 2 ] Bug #1792193 - CVE-2019-5188 e2fsprogs: Out-of-bounds write in e2fsck/rehash.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1792193 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-01ed02451f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Address the buffer overflow and out-of-bounds write vulnerabilities in e2fsprogs for Fedora 30 to maintain system reliability and integrity.. e2fsprogs, Fedoraupdates, buffer overflow fix, out of bounds issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 01, 2020 Critical Fedora
89

Fedora 29: 2019-44a9d99647 Critical: elfutils Buffer Over-Read

New upstream release 0.176. Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149, CVE-2019-7150, CVE-2019-7664 and CVE-2019-7665.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-44a9d99647 2019-02-18 02:03:22.662227 --------------------------------------------------------------------------------Name : elfutils Product : Fedora 29 Version : 0.176 Release : 1.fc29 URL : https://sourceware.org/elfutils/ Summary : A collection of utilities and DSOs to handle ELF files and DWARF data Description : Elfutils is a collection of utilities, including stack (to show backtraces), nm (for listing symbols from object files), size (for listing the section sizes of an object or archive file), strip (for discarding symbols), readelf (to see the raw ELF file structures), elflint (to check for well-formed ELF files) and elfcompress (to compress or decompress ELF sections). --------------------------------------------------------------------------------Update Information: New upstream release 0.176. Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149, CVE-2019-7150, CVE-2019-7664 and CVE-2019-7665. --------------------------------------------------------------------------------ChangeLog: * Fri Feb 15 2019 Mark Wielaard - 0.176-1 - New upstream release. - backends: riscv improved core file and return value location support. - Fixes CVE-2019-7146, CVE-2019-7148, CVE-2019-7149, CVE-2019-7150, CVE-2019-7664, CVE-2019-7665. * Thu Jan 31 2019 Fedora Release Engineering - 0.175-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Dec 3 2018 Mark Wielaard - 0.175-2 - Add elfutils-0.175-gnu-props-32.patch. * Fri Nov 16 2018 Mark Wielaard - 0.175-1 - New upstream release. - readelf: Handle multiple .debug_macro sections. - strip: Add strip --reloc-debug-sections-only option. Handle relocations against GNU compressed sections. - libdwelf: Newfunction dwelf_elf_begin. - libcpu: Recognize bpf jump variants BPF_JLT, BPF_JLE, BPF_JSLT and BPF_JSLE. - backends: RISCV handles ADD/SUB relocations. - Remove all patches. * Wed Nov 14 2018 Mark Wielaard - 0.174-5 - Add elfutils-0.174-x86_64_unwind.patch. - Add elfutils-0.174-gnu-property-note.patch. - Add elfutils-0.174-version-note.patch. - Add elfutils-0.174-gnu-attribute-note.patch * Tue Nov 6 2018 Mark Wielaard - 0.174-4 - Add elfutils-0.174-size-rec-ar.patch CVE-2018-18520 (#1646478) - Add elfutils-0.174-ar-sh_entsize-zero.patch CVE-2018-18521 (#1646483) * Fri Nov 2 2018 Mark Wielaard - 0.174-3 - Add elfutils-0.174-libdwfl-sanity-check-core-reads.patch CVE-2018-18310 (#1642605) * Wed Oct 17 2018 Mark Wielaard - 0.174-2 - Add elfutils-0.174-strip-unstrip-group.patch. --------------------------------------------------------------------------------References: [ 1 ] Bug #1671433 - CVE-2019-7146 elfutils: buffer over-read in the ebl_object_note function in eblobjnote.c in libebl [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1671433 [ 2 ] Bug #1671444 - CVE-2019-7149 elfutils: heap-based buffer over-read in read_srclines in dwarf_getsrclines.c in libdw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1671444 [ 3 ] Bug #1677537 - CVE-2019-7664 elfutils: Out of bound write in elf_cvt_note in libelf/note_xlate.h [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1677537 [ 4 ] Bug #1677539 - CVE-2019-7665 elfutils: heap-based buffer over-read in function elf32_xlatetom in elf32_xlatetom.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1677539 [ 5 ] Bug #1677717 - elfutils-0.176 is available https://bugzilla.redhat.com/show_bug.cgi?id=1677717 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-44a9d99647' at the command line. For moreinformation, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. . An important patch for Fedora 29 tackles various elfutils vulnerabilities, enhancing the overall security and reliability of the system.. Fedora Update, elfutils Security, Buffer Over-read, Out of Bounds Write, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 18, 2019 Critical Fedora
202

openSUSE Leap 15.0: openSUSE-SU-2019:0082-1 Important ntpsec Update

An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for ntpsec ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:0082-1 Rating: important References: #1122131 #1122132 #1122134 #1122144 Cross-References: CVE-2019-6442 CVE-2019-6443 CVE-2019-6444 CVE-2019-6445 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for ntpsec to version 1.1.3 fixes the following issues: Security issues fixed: - CVE-2019-6442: Fixed a out of bounds write via a malformed config request (boo#1122132) - CVE-2019-6443: Fixed a stack-based buffer over-read in the ctl_getitem function (boo#1122144) - CVE-2019-6444: Fixed a stack-based buffer over-read in the process_control function (boo#1122134) - CVE-2019-6445: Fixed a NULL pointer dereference in the ctl_getitem function (boo#1122131) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-82=1 Package List: - openSUSE Leap 15.0 (x86_64): ntpsec-1.1.3-lp150.2.3.1 ntpsec-debuginfo-1.1.3-lp150.2.3.1 ntpsec-debugsource-1.1.3-lp150.2.3.1 ntpsec-utils-1.1.3-lp150.2.3.1 python3-ntp-1.1.3-lp150.2.3.1 python3-ntp-debuginfo-1.1.3-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-6442.html https://www.suse.com/security/cve/CVE-2019-6443.html https://www.suse.com/security/cve/CVE-2019-6444.html https://www.suse.com/security/cve/CVE-2019-6445.html https://bugzilla.suse.com/1122131 https://bugzilla.suse.com/1122132 https://bugzilla.suse.com/1122134 https://bugzilla.suse.com/1122144 -- . openSUSE Security Update: Security update for ntpsec _______________________________________________. update, security, fixes, vulnerabilities, opensuse, updat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 23, 2019 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200