Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 25: Util-linux Critical Security Advisory for CVE-2017-2616

Security fix for CVE-2017-2616. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-20710607f5 2017-02-24 18:39:45.709858 -------------------------------------------------------------------------------- Name : util-linux Product : Fedora 25 Version : 2.28.2 Release : 2.fc25 URL : https://en.wikipedia.org/wiki/Util-linux Summary : A collection of basic system utilities Description : The util-linux package contains a large variety of low-level system utilities that are necessary for a Linux system to function. Among others, Util-linux contains the fdisk configuration tool and the login program. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2616 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1418710 - CVE-2017-2616 util-linux: Sending SIGKILL to other processes with root privileges via su https://bugzilla.redhat.com/show_bug.cgi?id=1418710 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade util-linux' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . A security patch for util-linux in Fedora 25 resolves a major vulnerability related to administrative rights and process management. Ensure you install the updateimmediately!. Fedora Updates, Util-linux Security, System Utilities Fix, Root Privileges Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 24, 2017 Critical Fedora
200

Critical Vulnerability Found in Scientific Linux 3 Kernel CVE-2007-2172

Important: kernel security and bug fix update. Date: Wed, 5 Dec 2007 17:12:11 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for on SL3,x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Important: kernel security and bug fix update Issue date: 2007-12-03 CVE Names: CVE-2007-2172 CVE-2007-3848 CVE-2006-4538 CVE-2007-3739 CVE-2007-4308 A flaw was found in the handling of process death signals. This allowed a local user to send arbitrary signals to the suid-process executed by that user. A successful exploitation of this flaw depends on the structure of the suid-program and its signal handling. (CVE-2007-3848, Important) A flaw was found in the IPv4 forwarding base. This allowed a local user to cause a denial of service. (CVE-2007-2172, Important) A flaw was found where a corrupted executable file could cause cross-region memory mappings on Itanium systems. This allowed a local user to cause a denial of service. (CVE-2006-4538, Moderate) A flaw was found in the stack expansion when using the hugetlb kernel on PowerPC systems. This allowed a local user to cause a denial of service. (CVE-2007-3739, Moderate) A flaw was found in the aacraid SCSI driver. This allowed a local user to make ioctl calls to the driver that should be restricted to privileged users. (CVE-2007-4308, Moderate) As well, these updated packages fix the following bug: * a bug in the TCP header prediction code may have caused "TCP: Treason uncloaked!" messages to be logged. In certain situations this may have lead to TCP connections hanging or aborting. SL 3.0.x SRPMS: kernel-2.4.21-53.EL.src.rpm i386: kernel-2.4.21-53.EL.athlon.rpm kernel-2.4.21-53.EL.i686.rpm kernel-BOOT-2.4.21-53.EL.i386.rpm kernel-doc-2.4.21-53.EL.i386.rpm kernel-hugemem-2.4.21-53.EL.i686.rpm kernel-hugemem-unsupported-2.4.21-53.EL.i686.rpm kernel-smp-2.4.21-53.EL.athlon.rpm kernel-smp-2.4.21-53.EL.i686.rpm kernel-smp-unsupported-2.4.21-53.EL.athlon.rpm kernel-smp-unsupported-2.4.21-53.EL.i686.rpm kernel-source-2.4.21-53.EL.i386.rpm kernel-unsupported-2.4.21-53.EL.athlon.rpm kernel-unsupported-2.4.21-53.EL.i686.rpm Dependancies: GFS-6.0.2.36-6.i686.rpm GFS-devel-6.0.2.36-6.i686.rpm GFS-modules-6.0.2.36-6.i686.rpm GFS-modules-hugemem-6.0.2.36-6.i686.rpm GFS-modules-smp-6.0.2.36-6.i686.rpm kernel-module-openafs-2.4.21-53.EL-1.2.13-15.17.SL.athlon.rpm kernel-module-openafs-2.4.21-53.EL-1.2.13-15.17.SL.i686.rpm kernel-module-openafs-2.4.21-53.ELsmp-1.2.13-15.17.SL.athlon.rpm kernel-module-openafs-2.4.21-53.ELsmp-1.2.13-15.17.SL.i686.rpm x86_64: kernel-2.4.21-53.EL.ia32e.rpm kernel-2.4.21-53.EL.x86_64.rpm kernel-doc-2.4.21-53.EL.x86_64.rpm kernel-smp-2.4.21-53.EL.x86_64.rpm kernel-smp-unsupported-2.4.21-53.EL.x86_64.rpm kernel-source-2.4.21-53.EL.x86_64.rpm kernel-unsupported-2.4.21-53.EL.ia32e.rpm kernel-unsupported-2.4.21-53.EL.x86_64.rpm Dependancies: GFS-6.0.2.36-6.ia32e.rpm GFS-6.0.2.36-6.x86_64.rpm GFS-devel-6.0.2.36-6.ia32e.rpm GFS-devel-6.0.2.36-6.x86_64.rpm GFS-modules-6.0.2.36-6.ia32e.rpm GFS-modules-6.0.2.36-6.x86_64.rpm GFS-modules-smp-6.0.2.36-6.x86_64.rpm kernel-module-openafs-2.4.21-53.EL-1.2.13-15.17.SL.ia32e.rpm kernel-module-openafs-2.4.21-53.EL-1.2.13-15.17.SL.x86_64.rpm kernel-module-openafs-2.4.21-53.ELsmp-1.2.13-15.17.SL.x86_64.rpm -Connie Sieh -Troy Dawson . The latest kernel revisions in Scientific Linux address critical vulnerabilities, enhancing defense against denial-of-service (DoS) attacks and refining signal management.. kernel update, Scientific Linux, security flaws, process signals, denial of service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 05, 2007 Critical Scientific Linux
200

Scientific Linux: Kernel Security Advisory for CVE-2006-6921 and Others

Important: kernel security update. Date: Thu, 1 Nov 2007 16:54:53 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kernel on SL4.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: kernel security update Issue date: 2007-11-01 CVE Names: CVE-2006-6921 CVE-2007-2878 CVE-2007-3105 CVE-2007-3739 CVE-2007-3740 CVE-2007-3843 CVE-2007-3848 CVE-2007-4308 CVE-2007-4571 * A flaw was found in the handling of process death signals. This allowed a local user to send arbitrary signals to the suid-process executed by that user. A successful exploitation of this flaw depends on the structure of the suid-program and its signal handling. (CVE-2007-3848, Important) * A flaw was found in the CIFS file system. This could cause the umask values of a process to not be honored on CIFS file systems where UNIX extensions are supported. (CVE-2007-3740, Important) * A flaw was found in the VFAT compat ioctl handling on 64-bit systems. This allowed a local user to corrupt a kernel_dirent struct and cause a denial of service. (CVE-2007-2878, Important) * A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local user who had the ability to read the /proc/driver/snd-page-alloc file could see portions of kernel memory. (CVE-2007-4571, Moderate) * A flaw was found in the aacraid SCSI driver. This allowed a local user to make ioctl calls to the driver that should be restricted to privileged users. (CVE-2007-4308, Moderate) * A flaw was found in the stack expansion when using the hugetlb kernel on PowerPC systems. This allowed a local user to cause a denial of service. (CVE-2007-3739, Moderate) * A flaw was found in the handling of zombie processes. A local user could create processes that would not be properly reaped which could lead to a denial of service. (CVE-2006-6921, Moderate) * A flaw was found in the CIFS file system handling. The mount option "sec=" did not enable integrity checking or produce an errormessage if used. (CVE-2007-3843, Low) * A flaw was found in the random number generator implementation that allowed a local user to cause a denial of service or possibly gain privileges. This flaw could be exploited if the root user raised the default wakeup threshold over the size of the output pool. (CVE-2007-3105, Low) Additionally, the following bugs were fixed: * A flaw was found in the kernel netpoll code, creating a potential deadlock condition. If the xmit_lock for a given network interface is held, and a subsequent netpoll event is generated from within the lock owning context (a console message for example), deadlock on that cpu will result, because the netpoll code will attempt to re-acquire the xmit_lock. The fix is to, in the netpoll code, only attempt to take the lock, and fail if it is already acquired (rather than block on it), and queue the message to be sent for later delivery. Any user of netpoll code in the kernel (netdump or netconsole services), is exposed to this problem, and should resolve the issue by upgrading to this kernel release immediately. * A flaw was found where, under 64-bit mode (x86_64), AMD processors were not able to address greater than a 40-bit physical address space; and Intel processors were only able to address up to a 36-bit physical address space. The fix is to increase the physical addressing for an AMD processor to 48 bits, and an Intel processor to 38 bits. * A flaw was found in the xenU kernel that may prevent a paravirtualized guest with more than one CPU from starting when running under an Scientific Linux 5.1 hypervisor. The fix is to allow your Scientific Linux 4 Xen SMP guests to boot under a 5.1 hypervisor. SL 4.x SRPMS: kernel-2.6.9-55.0.12.EL.src.rpm i386: kernel-2.6.9-55.0.12.EL.i686.rpm kernel-devel-2.6.9-55.0.12.EL.i686.rpm kernel-doc-2.6.9-55.0.12.EL.noarch.rpm kernel-hugemem-2.6.9-55.0.12.EL.i686.rpm kernel-hugemem-devel-2.6.9-55.0.12.EL.i686.rpm kernel-smp-2.6.9-55.0.12.EL.i686.rpm kernel-smp-devel-2.6.9-55.0.12.EL.i686.rpm kernel-xenU-2.6.9-55.0.12.EL.i686.rpm kernel-xenU-devel-2.6.9-55.0.12.EL.i686.rpm Dependancies: kernel-module-fuse-2.6.9-55.0.12.EL-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.12.ELhugemem-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.12.ELsmp-2.5.3-1.SL.i686.rpm kernel-module-fuse-2.6.9-55.0.12.ELxenU-2.5.3-1.SL.i686.rpm kernel-module-ipw3945-2.6.9-55.0.12.EL-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELhugemem-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELsmp-1.1.0-1.SL4.i686.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELxenU-1.1.0-1.SL4.i686.rpm kernel-module-madwifi-2.6.9-55.0.12.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.0.12.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-2.6.9-55.0.12.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.EL-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.ELhugemem-0.9.3.1-10.sl4.i686.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.ELsmp-0.9.3.1-10.sl4.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.EL-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELhugemem-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELsmp-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELxenU-1.41-1.SL.i686.rpm kernel-module-openafs-2.6.9-55.0.12.EL-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.12.ELhugemem-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.12.ELsmp-1.4.4-46.SL4.i686.rpm kernel-module-openafs-2.6.9-55.0.12.ELxenU-1.4.4-46.SL4.i686.rpm kernel-module-r1000-2.6.9-55.0.12.EL-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.12.ELhugemem-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.12.ELsmp-2.2-2.SL4x.i686.rpm kernel-module-r1000-2.6.9-55.0.12.ELxenU-2.2-2.SL4x.i686.rpm x86_64: kernel-2.6.9-55.0.12.EL.x86_64.rpm kernel-devel-2.6.9-55.0.12.EL.x86_64.rpm kernel-doc-2.6.9-55.0.12.EL.noarch.rpm kernel-largesmp-2.6.9-55.0.12.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-55.0.12.EL.x86_64.rpm kernel-smp-2.6.9-55.0.12.EL.x86_64.rpm kernel-smp-devel-2.6.9-55.0.12.EL.x86_64.rpm kernel-xenU-2.6.9-55.0.12.EL.x86_64.rpm kernel-xenU-devel-2.6.9-55.0.12.EL.x86_64.rpm Dependancies: kernel-module-fuse-2.6.9-55.0.12.EL-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.12.ELlargesmp-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.12.ELsmp-2.5.3-1.SL.x86_64.rpm kernel-module-fuse-2.6.9-55.0.12.ELxenU-2.5.3-1.SL.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.12.EL-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELlargesmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELsmp-1.1.0-1.SL4.x86_64.rpm kernel-module-ipw3945-2.6.9-55.0.12.ELxenU-1.1.0-1.SL4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.12.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.12.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-2.6.9-55.0.12.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.EL-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.ELlargesmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-madwifi-hal-2.6.9-55.0.12.ELsmp-0.9.3.1-10.sl4.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.EL-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELlargesmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELsmp-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.9-55.0.12.ELxenU-1.41-1.SL.x86_64.rpm kernel-module-openafs-2.6.9-55.0.12.EL-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.12.ELlargesmp-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.12.ELsmp-1.4.4-46.SL4.x86_64.rpm kernel-module-openafs-2.6.9-55.0.12.ELxenU-1.4.4-46.SL4.x86_64.rpm kernel-module-r1000-2.6.9-55.0.12.EL-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.12.ELlargesmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.12.ELsmp-2.2-2.SL4x.x86_64.rpm kernel-module-r1000-2.6.9-55.0.12.ELxenU-2.2-2.SL4x.x86_64.rpm NOTE: At the time of this writting, The Upstream Vendor had not released the source rpm's for the GFS kernel modules. When they do, we will recompile them and push them out. But we felt it was better to get the kernel out as soon as possible. -Connie Sieh -Troy Dawson . Core system enhancement patch forScientific Linux SL4.x, resolving multiple vulnerabilities to fortify overall security.. Kernel Security Update, Scientific Linux, Process Handling, CIFS Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 01, 2007 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here