An update for pesign is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1829-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1829 Issue date: 2023-04-18 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux AppStream EUS(v.8.6): Source: pesign-0.112-27.el8_6.src.rpm aarch64: pesign-0.112-27.el8_6.aarch64.rpm pesign-debuginfo-0.112-27.el8_6.aarch64.rpm pesign-debugsource-0.112-27.el8_6.aarch64.rpm x86_64: pesign-0.112-27.el8_6.x86_64.rpm pesign-debuginfo-0.112-27.el8_6.x86_64.rpm pesign-debugsource-0.112-27.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZEgrgdzjgjWX9erEAQjRGBAApP7z+kBk0EXV5sgqVCP7eLjK39Qdrk/i 3Xi4nUdVf6swVbB5o/ycmI1X+DDKDzo0/c9sr9YRLpC2IrlqWJWPtYVtivdSAB7L kwfAzeHY6YhI8TfnASaeLtO3DjOXSjUJ81Pozu+FPAVjiat0pOsHFs1nVUUE9tx9 g523aKkKNZpiZzgrxr8rogp8667L18w5Jq4W0QZi2iYs8m/IrTo9GczhmJsyU76p vmW0wY7ebSx77kjA0ZrUVf2ESOVb2t+jBMusvRxA1g70Dmol4TzllNJvWD1UqOyh sFWLFV+y+dEGiWB9uLgzfShgyny55VGmYV5TEuEV65TMVg6DLKA9v7dq5Rk+XLhK 1v7gvubzFM3GojR9EJ0silADNDa2yEjjrlQcUuiiXOVx5B0Iw06X5mDF9ViDMUCn EM/vNw5aaVTN87AO3+XsTPN1tToHSASO60DGRpJZBFc3uASV40cg/vHSAN/iucNp OBFrrUwHiGQcQ2DfvQm27IKBCUscL9aassYZ2sgHyuVQel998Wo/2xfLitD5abJ8 7BU3R7UvXr2ZRt5i77XjjTe/Gv5PB/avza9O/+ZWHdfVZLmQIVRrFfgLzt3V5Jj9 3A7nuxP380ewcH27ROWwKRHgDnQ+bTCfz0OQ36xCPUrzbhm83Pj64NuUxyiABBDp SyrtI0hs9DA=my1q -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-1572 https://linux.oracle.com/errata/ELSA-2023-1572.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: pesign-0.112-27.0.1.el8_7.x86_64.rpm aarch64: pesign-0.112-27.0.1.el8_7.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//pesign-0.112-27.0.1.el8_7.src.rpm Related CVEs: CVE-2022-3560 Description of changes: [0.112-27.0.1] - Update Oracle Linux test certificates [Orabug: 31928433] - Apply pesigcheck-Mark-the-imported-certificate-as-trusted.patch [Orabug: 31928433] - update Oracle Linux certificates (Alexey Petrenko) - remove obsoletes of pesign-rh-test-certs [Orabug 29222572] [0.112-27] - Deprecate pesign-authorize and drop ACL - Resolves: CVE-2022-3560 _______________________________________________ El-errata mailing list
An update for pesign is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1572-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1572 Issue date: 2023-04-04 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux AppStream (v.8): Source: pesign-0.112-27.el8_7.src.rpm aarch64: pesign-0.112-27.el8_7.aarch64.rpm pesign-debuginfo-0.112-27.el8_7.aarch64.rpm pesign-debugsource-0.112-27.el8_7.aarch64.rpm x86_64: pesign-0.112-27.el8_7.x86_64.rpm pesign-debuginfo-0.112-27.el8_7.x86_64.rpm pesign-debugsource-0.112-27.el8_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCw/BdzjgjWX9erEAQjA5w//X/sGFb60k93GURFP2926E34jFkhfKHr3 VxWgcjVcSJJpiV+zvPSOmP1c/BIeETKSk02bEqBKdkskrfTVXYrHGWbh6u+5fGZk 7SuIwEP2FththWejXuL6CHMWF2gnXCvOja+8ucQstJlwJ2IwIiWhHjmLbbGvZP5A 8uTBKORsoIpVmIXCiJKBaJj4/Sbf6b3GemdEKQYldTriA0r7ZJnSAeFkPqg12KXe qFZzvJt5CeYSOu2PcC1GVvbOboe99rvtjdJfiFgQAfKnLrUAmu2bSReCnRVT4NhD 0joaJYJP9aK76Dg++oM8hOPyClNT4txbg/RWtVq05GANT03pzmRb1wND8JLomI/q RjdsyzDIcuEkZ7y81QO3d08U3TLQAw6Ry5+v6ZiK8GvlplI/WpcDL5+/aNfqPTG3 uHbyKD1HP65zUsBrQNUqZL2V8ZZ92ZSVbTr0gkdWMmrS8ZhLuE7pm+zoJehSXkLM HG5OrOTJlVQp1D+zK4MEp+lB2CSYkiYvfvL7sWNOv8oDfBPafLrz1DiCv8IkhnU8 +OWy2tW6HOMuoNfeApaSpY1VlOjGHWWTMRcLQUajM5ZaqsNG+Y4iyc0xfzyWeQvA 6Bw2LCa86tbyyue6J7AWDUCV3cCbWDgD0Zm6P4qdtV4qi4re953VboWSNCBerWkP wsKrRVkU0QM=n3cv -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for pesign is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1586-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1586 Issue date: 2023-04-04 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux AppStream E4S (v.8.1): Source: pesign-0.112-25.el8_1.1.src.rpm aarch64: pesign-0.112-25.el8_1.1.aarch64.rpm pesign-debuginfo-0.112-25.el8_1.1.aarch64.rpm pesign-debugsource-0.112-25.el8_1.1.aarch64.rpm x86_64: pesign-0.112-25.el8_1.1.x86_64.rpm pesign-debuginfo-0.112-25.el8_1.1.x86_64.rpm pesign-debugsource-0.112-25.el8_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZCvqnNzjgjWX9erEAQiWzA/+OfCZ8FqHTlCqshqwNyOQsZXODIZaJ27z Z9l2yvVBtOQ1YuH8g5DiQnqSpQzzn8mLMLi5tNnLMnvAq9AvtVUIVQVM55CoXXkJ I234s7rk3zPy0XZseb0BJGw2Zw/bbSSNFY65dVeAsPZwYYNxfCB5v0/3pOxdOezN GpsusEpyYSEAuLTN2WSAUywndsUPHHUQ7cV4YaM51IJmUu6VWCvEmawi3jqXpptT lNVys6F/pmypMwwshb9d3Q3V8qph6v1PnGwRzuiYqvB3MHdAYff7XWvNmwU1Mskn 1sPN9Ot642t4hhPLWWVqj4oMz3RElFT594oKU3HG2GeWo4yQq5vmgXmrKRGxT6cy 3Aqa1VOgjRRtL7xsA96PmC7mniqX1+7wKHYRz1gDPMiOQ9n+iwi37NBwUZjRCAZd N6Fn8+RkE7aFYx07PlET9apLhAMO6RvEKopE/Kx4iv9+sMWwjIvbgpCA3b8dKugO xn7tN20wYO3hUjgnFhdiNHiYuLT8Y3QW4wjhRvgdYX98L5pmeFvOiqzU7qIX32Dt Ow0R3MiN0qC4kd0ecgiNfRd3BAwGlu6lo16d34awUCBh9EX0Y4oXGWXzu4A1V/27 w98c3GMAw5VC8rklDk+qiVgctbBknr7Y+Lm8rhfwN4lBziO2oZGhZaR/7T4f1olx t0peXK3PCkg=+vZz -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Upstream details at : https://access.redhat.com/errata/RHSA-2023:1093. CentOS Errata and Security Advisory 2023:1093 Important Upstream details at : https://access.redhat.com/errata/RHSA-2023:1093 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: c041cb0f7c5becd34a9fa8c2693fe7723c0e561a13cee7ae61287bfc4ff2eb4d pesign-0.109-11.el7_9.x86_64.rpm Source: 90f1b952b1c14d738c75cf8cc3841c86f38dca07a9010e872e1772ac2c3fdc5c pesign-0.109-11.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
An update for pesign is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1107-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1107 Issue date: 2023-03-07 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream AUS (v. 8.2) - aarch64, x86_64 Red Hat Enterprise Linux AppStream E4S (v. 8.2) - aarch64, x86_64 Red Hat Enterprise Linux AppStream TUS (v. 8.2) - aarch64, x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux AppStream AUS (v. 8.2): Source: pesign-0.112-25.el8_2.1.src.rpm aarch64: pesign-0.112-25.el8_2.1.aarch64.rpm pesign-debuginfo-0.112-25.el8_2.1.aarch64.rpm pesign-debugsource-0.112-25.el8_2.1.aarch64.rpm x86_64: pesign-0.112-25.el8_2.1.x86_64.rpm pesign-debuginfo-0.112-25.el8_2.1.x86_64.rpm pesign-debugsource-0.112-25.el8_2.1.x86_64.rpm Red Hat Enterprise Linux AppStream E4S (v. 8.2): Source: pesign-0.112-25.el8_2.1.src.rpm aarch64: pesign-0.112-25.el8_2.1.aarch64.rpm pesign-debuginfo-0.112-25.el8_2.1.aarch64.rpm pesign-debugsource-0.112-25.el8_2.1.aarch64.rpm x86_64: pesign-0.112-25.el8_2.1.x86_64.rpm pesign-debuginfo-0.112-25.el8_2.1.x86_64.rpm pesign-debugsource-0.112-25.el8_2.1.x86_64.rpm Red Hat Enterprise Linux AppStream TUS (v. 8.2): Source: pesign-0.112-25.el8_2.1.src.rpm aarch64: pesign-0.112-25.el8_2.1.aarch64.rpm pesign-debuginfo-0.112-25.el8_2.1.aarch64.rpm pesign-debugsource-0.112-25.el8_2.1.aarch64.rpm x86_64: pesign-0.112-25.el8_2.1.x86_64.rpm pesign-debuginfo-0.112-25.el8_2.1.x86_64.rpm pesign-debugsource-0.112-25.el8_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZAiXLdzjgjWX9erEAQhQsA//RLv4H10wZJTWZnezz9KMapHUwJ6iPQP6 NnuWs26Q3scr0Y10dgVqNm+g9oHGvsLrqm+fZK0dgK4PhYoWsAlXrfyCcAGPoCqo 2LEXeZD0HPQ5icixfrbhlxwsNnGdM/+H1LFgsrc6G5B5FVtkaJmr4GMK7hWxhF+/ FUfa+eMGSAZL3n1ZsQ8VWGIOb1IEhUXfsWrv1XWlZY55buQn7/3MfjA4tb8Au9zc 0GCnl2iz0NGyF7so/mSi2+KYsodp7CwZ7ZseJgrLtA/MbVww/lxW5X2rMV2UHjgF Joh5krhdHUbVAArYVPyRsrzTm6Ijim+Ww3axMOXglttPHDcpL2Wwg6X3E+mJmEhp zdXHvhwW2/7prhMnXzjuzmKq07s6jCAnAtFSI8fWmT9BRixPF0WbVFDriIRU8Tgq nCLuDQa58oXIkb11tQ4WMUFcu6PqadYBa0EvWGgQeqrbcMVXlpVaXylzwoUO55P3 yC2ws9tMvoN4PBcICBlASAngQMbOxCtSb7wnDi4rl3kqFdafmTzIk3+cs1OkqNjC H1h/UJoroqAS977s3HSNfZQJ+sw7RQ7Grz3RovV7g88tUV87F1Vv5QRwbBWMdVVN OINoZBTMdXcD0qegq1+TjHl6+bMdn0XshC6g7wM2RyiMdw5fXeP6+QjRvDtnWWDc kbgX2OTcUho=HPJq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-1093 https://linux.oracle.com/errata/ELSA-2023-1093.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: pesign-0.109-11.el7_9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//pesign-0.109-11.el7_9.src.rpm Related CVEs: CVE-2022-3560 Description of changes: [0.109-11.0.1] - RPM macro fix (Petr Benes) - updates for Oracle Linux test certificate (Alexey Petrenko) - update Oracle Linux certificates (Alexey Petrenko) [0.109-11] - Backport newer, deprecated pesign-authorize - Resolves: CVE-2022-3560 _______________________________________________ El-errata mailing list
pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm - Scientific Linux Development Team. Synopsis: Important: pesign security update Advisory ID: SLSA-2023:1093-1 Issue Date: 2023-03-07 CVE Numbers: CVE-2022-3560 -- Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm - Scientific Linux Development Team . Important security patch released for pesign on Scientific Linux to fix local privilege escalation vulnerability.. Pesign Security Update, Local Escalation Issue, Scientific Linux. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.