Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
219

Rocky Linux 9 RLSA-2023:1067 Important: Pesign Local Escalation

Important: pesign security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:1067", "synopsis": "Important: pesign security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pesign.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools.\n\nSecurity Fix(es):\n\n* pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2135420", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2135420", "description": ""}], "cves": [{"name": "CVE-2022-3560", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-3560", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-03-08T16:38:25.971989Z", "rpms": {"Rocky Linux 9": {"nvras": ["pesign-0:115-6.el9_1.rocky.2.aarch64.rpm", "pesign-0:115-6.el9_1.rocky.2.src.rpm", "pesign-0:115-6.el9_1.rocky.2.x86_64.rpm", "pesign-debuginfo-0:115-6.el9_1.rocky.2.aarch64.rpm", "pesign-debuginfo-0:115-6.el9_1.rocky.2.x86_64.rpm", "pesign-debugsource-0:115-6.el9_1.rocky.2.aarch64.rpm", "pesign-debugsource-0:115-6.el9_1.rocky.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security patch released for Rocky Linux, targeting local privilege escalation vulnerability in the systemd component.. pesign security, Rocky Linux update, local privilege escalation, UEFI signing. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 08, 2023 Important Rocky Linux
217

Oracle Linux 7 ELSA-2023-1093 Critical: pesign Important Security Patch

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-1093 https://linux.oracle.com/errata/ELSA-2023-1093.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: pesign-0.109-11.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//pesign-0.109-11.el7_9.src.rpm Related CVEs: CVE-2022-3560 Description of changes: [0.109-11.0.1] - RPM macro fix (Petr Benes) - updates for Oracle Linux test certificate (Alexey Petrenko) - update Oracle Linux certificates (Alexey Petrenko) [0.109-11] - Backport newer, deprecated pesign-authorize - Resolves: CVE-2022-3560 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 7 offers critical system enhancements. Refer to ELSA-2023-1094 for more insights.. Oracle Linux Security, aarch64 Linux, pesign Security Update, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 08, 2023 Critical Oracle
98

Red Hat Enterprise Linux 7 RHSA-2023-1093-01 Important Local Escalation Fix

An update for pesign is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1093-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1093 Issue date: 2023-03-07 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux Client Optional (v. 7): Source: pesign-0.109-11.el7_9.src.rpm x86_64: pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): Source: pesign-0.109-11.el7_9.src.rpm x86_64: pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): Source: pesign-0.109-11.el7_9.src.rpm x86_64: pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): Source: pesign-0.109-11.el7_9.src.rpm x86_64: pesign-0.109-11.el7_9.x86_64.rpm pesign-debuginfo-0.109-11.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZAcuBdzjgjWX9erEAQgOHA/7BEHsUb4+utg+YL/EZfFuUqhkHpV3Xk6z i14QR6Hy5kepLhwvGvv37A0U5o8x4rfPYQI+w8vzxliWPY/JXQlawK+qVNcia+xb 1esZBTq7Pn3yfGxbbdA/nW0V0iFdeG/OnTvuyIWZXVe5RpdxMm6y3AB99xY9WM7Z l8QyDNfDQeNRQiZbMupF5Ie8vhnwFEmdNE1rbcBxPInqQ9KJqJNBRqPs/y5fiY9J IDuV/zHFGLAru9zfo0j1YxOV+vKa9FgUkgQwcqT3m39/L1qCY1j2aE0W8C9PFLcN nWu0qO3AChD2qMqTRxUwlag6OU8m99yXeXJD69udM91KBiAT5NwxPFZTwmodNX8p A9VLOuK30khSAjZKaL3jKH9V48WAEXWoIY2ncfFPovw7v7Zyv6bPq2nEIjghvlEf 9ymb60lfH/5wm29OLbmyOGc9eO0FK1qIcarjkI8Tb+PGsLDkocN+vDy7sbr48AlR ZGqLy7awTvdL1G9mFR1S9WMD62jSoHP/wKBwdCHb4cxOXkGjUBMrAnbOXkWU+vkf Q3Pc1a6PFkzgH+TjVNYXy6aOyeHZJxCEj/FDXHo/+QauTxx/xUmryxREFjzand7Z 8TYxpRm78DHmBPmctht+ivZ6thfrcLqtq4xMkCQEUL4PI2pWuL94GiRI3l6e/Iil r77PJEmt1v4=fimS -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Elevate your Red Hat Enterprise experience by applying a critical security patch for pesign that mitigates risks associated with local privilege escalation.. Red Hat Enterprise, Pesign Update, Security Advisory, Local Escalation, Linux Patching. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 07, 2023 Important Red Hat
98

Red Hat Enterprise Linux 9 - RHSA-2023:1067-01 Important Local Escalation

An update for pesign is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pesign security update Advisory ID: RHSA-2023:1067-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:1067 Issue date: 2023-03-06 CVE Names: CVE-2022-3560 ==================================================================== 1. Summary: An update for pesign is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, x86_64 3. Description: The pesign packages provide the pesign utility for signing UEFI binaries as well as other associated tools. Security Fix(es): * pesign: Local privilege escalation on pesign systemd service (CVE-2022-3560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2135420 - CVE-2022-3560 pesign: Local privilege escalation on pesign systemd service 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: pesign-115-6.el9_1.src.rpm aarch64: pesign-115-6.el9_1.aarch64.rpm pesign-debuginfo-115-6.el9_1.aarch64.rpm pesign-debugsource-115-6.el9_1.aarch64.rpm x86_64: pesign-115-6.el9_1.x86_64.rpm pesign-debuginfo-115-6.el9_1.x86_64.rpm pesign-debugsource-115-6.el9_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-3560 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZAXchNzjgjWX9erEAQjveQ//URJ2mVEcGDevTWUkluitSIEOLfu7RheU 0I2BRFgcbnTQEt/BsdDnhZw31HXyqYhDIMgq12Vg70gTSB3mksfY5X5DSrp4NRVE nhNN76qx1egnZqRMC/yJ7tEZY08IO/AN12maZv4spx/B+TsCanw2mymxEYs8Q/Cz zpjN9lJCv/pxLzesQ0hNVFK6pcRbc+sH4xwJ358ZwBRShJYUzTIvxy9/S7t4Y4tD HJRu5UApSMW3wISBvs1gTpBXZ9AhzluwOKtPEas+w4w1cb8fxK32hqBGwaF+BLIW 02Gkl/WZZXTpGL+6cniUviQHf39f5D+XA08OK2SMz2ymwKNM70tWzh7wyfMrCyic EDmLf6Apf8tWzSsDy1UQ2Ley22qWimB+kkS67zwxUKsWOVHantHTOFW4jj+AvQvH Xhxo4A/TYVFVzXrjI/TzDvbSzJDKqgVvMkclyCaUzOP4VrJ51pbqMevX/UPX6LI6 B0TdCI5eHxllAFPmi+6/MHRWo2ZqHBn6p6z/otADg1e9sIA7ZiBCWW2XcDkQCfxD u5sIhGKOgVLsEl1iaoTFp9oYqUsr/sAdssJ1ufrpmxEn2Ck3y75KXisAApOa2xKX mKsYkjKczo1JbRtAi/iSxetplIC92Jr04tGIPpRT0xoFZBwEauSc0BIRmaWTsFBw yvDz0vt28bQ=SvqR -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security patch for pesign in Red Hat Enterprise Linux 9 addresses vulnerabilities that could lead to unauthorized privilege elevation.. Red Hat Enterprise Linux,pesign update,local privilege escalation,security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 06, 2023 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here