Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 27 articles for you...
100

SUSE 2025:01990-1 Moderate Security Fix for Golang Prometheus Library

* bsc#1208752 * bsc#1236516 * bsc#1238686 * jsc#MSQA-992 * jsc#PED-11740 . # Security update for golang-github-prometheus-prometheus Announcement ID: SUSE-SU-2025:01990-1 Release Date: 2025-06-18T02:12:03Z Rating: moderate References: * bsc#1208752 * bsc#1236516 * bsc#1238686 * jsc#MSQA-992 * jsc#PED-11740 Cross-References: * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 Module * SUSE Manager Retail Branch Server 4.3 * SUSE Package Hub 15 15-SP6 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities, contains two features and has one security fix can now be installed. ## Description: This update for golang-github-prometheus-prometheus fixes the following issues: * Security issues fixed: * CVE-2023-45288: Require Go > = 1.23 for building (bsc#1236516) * CVE-2025-22870: Bump golang.org/x/net to version 0.39.0 (bsc#1238686) * Version was updated to 2.53.4 with the following bug fixes: * Runtime: fix GOGC is being set to 0 when installed with empty prometheus.yml file resulting high cpu usage * Scrape: fix dropping valid metrics afterprevious scrape failed ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1990=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1990=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2025-1990=1 * SUSE Manager Proxy 4.3 Module zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2025-1990=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.4-150100.4.26.2 * firewalld-prometheus-config-0.1-150100.4.26.2 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.4-150100.4.26.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.4-150100.4.26.2 * golang-github-prometheus-prometheus-debuginfo-2.53.4-150100.4.26.2 * SUSE Manager Proxy 4.3 Module (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.4-150100.4.26.2 ## References: * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1208752 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-992&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11740&page_caps=&user_role= . SUSE's security advisory highlights two critical vulnerabilities in golang-github-prometheus-prometheus, urging users to update for protection and enhanced system integrity. SUSE Update, Prometheus Security, GolangIssues. . LinuxSecurity.com Team

Calendar%202 Jun 18, 2025 SuSE
202

openSUSE Tumbleweed: Update for prometheus-blackbox_exporter 2025:15162-1

An update that solves 2 vulnerabilities can now be installed.. # prometheus-blackbox_exporter-0.24.0-3.1 on GA media Announcement ID: openSUSE-SU-2025:15162-1 Rating: moderate Cross-References: * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the prometheus-blackbox_exporter-0.24.0-3.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * prometheus-blackbox_exporter 0.24.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html . Security advisory for openSUSE Tumbleweed addressing moderate vulnerabilities in prometheus-blackbox_exporter.. openSUSE Tumbleweed, prometheus blackbox_exporter, security advisory, threat mitigation. . LinuxSecurity.com Team

Calendar%202 May 27, 2025 OpenSUSE
89

Fedora 41: FEDORA-2025-b0915f0a19 critical: prometheus-podman-exporter DoS

release v1.16.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b0915f0a19 2025-04-21 16:44:59.680879+00:00 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 41 Version : 1.16.0 Release : 1.fc41 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: release v1.16.0 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 11 2025 Navid Yaghoobi - 1.16.0-1 - release v1.16.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2347472 - CVE-2025-27144 prometheus-podman-exporter: Go JOSE's Parsing Vulnerable to Denial of Service [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2347472 [ 2 ] Bug #2347484 - CVE-2025-27144 prometheus-podman-exporter: Go JOSE's Parsing Vulnerable to Denial of Service [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2347484 [ 3 ] Bug #2350800 - CVE-2025-22869 prometheus-podman-exporter: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2350800 [ 4 ] Bug #2350843 - CVE-2025-22869 prometheus-podman-exporter: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2350843 [ 5 ] Bug #2352105 - CVE-2025-22870 prometheus-podman-exporter: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2352105 [ 6 ] Bug #2352325 -CVE-2025-22870 prometheus-podman-exporter: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2352325 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b0915f0a19' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The Fedora 41 security advisory warns of critical DoS vulnerabilities in prometheus-podman-exporter 1.16.0, urging admins to patch promptly to safeguard services. podman exporter, Fedora security, prometheus update, v1.16.0 advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2025 Critical Fedora
100

openSUSE 15.6: 2025:0546-1 moderate: Prometheus error handling fix

* bsc#1232970 * jsc#MSQA-914 * jsc#PED-11649 Cross-References: . # Security update golang-github-prometheus-prometheus Announcement ID: SUSE-SU-2025:0546-1 Release Date: 2025-02-14T07:24:45Z Rating: moderate References: * bsc#1232970 * jsc#MSQA-914 * jsc#PED-11649 Cross-References: * CVE-2024-51744 CVSS scores: * CVE-2024-51744 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-51744 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2024-51744 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 Module * SUSE Manager Retail Branch Server 4.3 * SUSE Package Hub 15 15-SP6 An update that solves one vulnerability and contains two features can now be installed. ## Description: golang-github-prometheus-prometheus was updated from version 2.45.6 to 2.53.3 (jsc#PED-11649): * Security issues fixed: * CVE-2024-51744: Updated golang-jwt to version 5.0 to fix bad error handling (bsc#1232970) * Highlights of other changes: * Performance: * Significant enhancements to PromQL execution speed, TSDB operations (especially querying and compaction) and remote write operations. * Default GOGC value lowered to 75 for better memory management. * Option to limit memory usage from dropped targets added. * New Features: * Experimental OpenTelemetry ingestion. * Automatic memory limit handling. * Native histogram support, including new functions, UI enhancements, and improved scraping. * Improved alerting features, such as relabeling rules for AlertmanagerConfig and a new query_offset option. * Expanded service discovery options with added metadata and support for new services. * New promtoolcommands for PromQL formatting, label manipulation, metric pushing, and OpenMetrics dumping. * Bug Fixes: * Numerous fixes across scraping, API, TSDB, PromQL, and service discovery. * For a detailed list of changes consult the package changelog or https://github.com/prometheus/prometheus/compare/v2.45.6...v2.53.3 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-546=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-546=1 * SUSE Manager Proxy 4.3 Module zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2025-546=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * firewalld-prometheus-config-0.1-150100.4.23.1 * golang-github-prometheus-prometheus-2.53.3-150100.4.23.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.3-150100.4.23.1 * SUSE Manager Proxy 4.3 Module (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.53.3-150100.4.23.1 ## References: * https://www.suse.com/security/cve/CVE-2024-51744.html * https://bugzilla.suse.com/show_bug.cgi?id=1232970 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-914&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-11649&page_caps=&user_role= . The latest security patch for golang-github-prometheus-prometheus addresses CVE-2024-51744, providing important enhancements for SUSE system users.. Golang Security Update, Prometheus Patch, SUSE Linux, Error Handling Fix. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2025 SuSE
89

Fedora 40 - FEDORA-2024-69528c0ba6 moderate: podman file descriptor leak

release 1.13.3. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-69528c0ba6 2024-10-28 03:52:20.506230 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 40 Version : 1.13.3 Release : 1.fc40 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: release 1.13.3 -------------------------------------------------------------------------------- ChangeLog: * Sat Oct 19 2024 Navid Yaghoobi - 1.13.3-1 - release v1.13.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2317466 - CVE-2024-9675 prometheus-podman-exporter: Buildah allows arbitrary directory mount [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2317466 [ 2 ] Bug #2318177 - [Major Incident] CVE-2024-21626 prometheus-podman-exporter: file descriptor leak [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2318177 [ 3 ] Bug #2318188 - [Major Incident] CVE-2024-21626 prometheus-podman-exporter: file descriptor leak [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2318188 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-69528c0ba6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Enhancements for podman-exporter in Fedora boost security, tackling newly identified flaws in version 1.13.3.. prometheus podman exporter, Fedora updates, container security, security patches. . LinuxSecurity.com Team

Calendar%202 Oct 28, 2024 Fedora
100

SUSE: 2024:3288-1 Important: Golang Prometheus Security Updates

* bsc#1204023 * bsc#1208298 * bsc#1227038 * bsc#1228556 * jsc#MSQA-848 . # Security update for golang-github-prometheus-prometheus Announcement ID: SUSE-SU-2024:3288-1 Rating: important References: * bsc#1204023 * bsc#1208298 * bsc#1227038 * bsc#1228556 * jsc#MSQA-848 * jsc#PED-3577 * jsc#PED-5406 Cross-References: * CVE-2022-41715 * CVE-2022-41723 * CVE-2023-45142 * CVE-2024-6104 CVSS scores: * CVE-2022-41715 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41715 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45142 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45142 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-6104 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-6104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 Module 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Package Hub 15 15-SP5 * SUSE Package Hub 15 15-SP6 An update that solves four vulnerabilities and contains three features can now be installed. ## Description: This update for golang-github-prometheus-prometheus fixes the following issues: * Require Go > 1.20 for building * Bump go-retryablehttp to version0.7.7 (CVE-2024-6104, bsc#1227038) * Migrate from `disabled` to `manual` service mode * Add0003-Bump-go-retryablehttp.patch * Update to 2.45.6 (jsc#PED-3577): * Security fixes in dependencies * Update to 2.45.5: * [BUGFIX] tsdb/agent: ensure that new series get written to WAL on rollback. * [BUGFIX] Remote write: Avoid a race condition when applying configuration. * Update to 2.45.4: * [BUGFIX] Remote read: Release querier resources before encoding the results. * Update to 2.45.3: * Security fixes in dependencies * [BUGFIX] TSDB: Remove double memory snapshot on shutdown. * Update to 2.45.2: * Security fixes in dependencies * [SECURITY] Updated otelhttp to version 0.46.1 (CVE-2023-45142, bsc#1228556) * [BUGFIX] TSDB: Fix PostingsForMatchers race with creating new series. * Update to 2.45.1: * [ENHANCEMENT] Hetzner SD: Support larger ID's that will be used by Hetzner in September. * [BUGFIX] Linode SD: Cast InstanceSpec values to int64 to avoid overflows on 386 architecture. * [BUGFIX] TSDB: Handle TOC parsing failures. * update to 2.45.0 (jsc#PED-5406): * [FEATURE] API: New limit parameter to limit the number of items returned by `/api/v1/status/tsdb` endpoint. * [FEATURE] Config: Add limits to global config. * [FEATURE] Consul SD: Added support for `path_prefix`. * [FEATURE] Native histograms: Add option to scrape both classic and native histograms. * [FEATURE] Native histograms: Added support for two more arithmetic operators `avg_over_time` and `sum_over_time`. * [FEATURE] Promtool: When providing the block id, only one block will be loaded and analyzed. * [FEATURE] Remote-write: New Azure ad configuration to support remote writing directly to Azure Monitor workspace. * [FEATURE] TSDB: Samples per chunk are now configurable with flag `storage.tsdb.samples-per-chunk`. By default set to its former value 120. * [ENHANCEMENT] Native histograms: bucket size can now be limited to avoid scrape fails. * [ENHANCEMENT]TSDB: Dropped series are now deleted from the WAL sooner. * [BUGFIX] Native histograms: ChunkSeries iterator now checks if a new sample can be appended to the open chunk. * [BUGFIX] Native histograms: Fix Histogram Appender `Appendable()` segfault. * [BUGFIX] Native histograms: Fix setting reset header to gauge histograms in seriesToChunkEncoder. * [BUGFIX] TSDB: Tombstone intervals are not modified after Get() call. * [BUGFIX] TSDB: Use path/filepath to set the WAL directory. * update to 2.44.0: * [FEATURE] Remote-read: Handle native histograms. * [FEATURE] Promtool: Health and readiness check of prometheus server in CLI. * [FEATURE] PromQL: Add `query_samples_total` metric, the total number of samples loaded by all queries. * [ENHANCEMENT] Storage: Optimise buffer used to iterate through samples. * [ENHANCEMENT] Scrape: Reduce memory allocations on target labels. * [ENHANCEMENT] PromQL: Use faster heap method for `topk()` / `bottomk()`. * [ENHANCEMENT] Rules API: Allow filtering by rule name. * [ENHANCEMENT] Native Histograms: Various fixes and improvements. * [ENHANCEMENT] UI: Search of scraping pools is now case-insensitive. * [ENHANCEMENT] TSDB: Add an affirmative log message for successful WAL repair. * [BUGFIX] TSDB: Block compaction failed when shutting down. * [BUGFIX] TSDB: Out-of-order chunks could be ignored if the write-behind log was deleted. * rebase patch 0001-Do-not-force-the-pure-Go-name-resolver.patch onto v2.44.0 * update to 2.43.1 * [BUGFIX] Labels: Set() after Del() would be ignored, which broke some relabeling rules. * update to 2.43.0: * [FEATURE] Promtool: Add HTTP client configuration to query commands. * [FEATURE] Scrape: Add `include_scrape_configs` to include scrape configs from different files. * [FEATURE] HTTP client: Add `no_proxy` to exclude URLs from proxied requests. * [FEATURE] HTTP client: Add `proxy_from_enviroment` to read proxies from env variables. * [ENHANCEMENT] API: Add support forsetting lookback delta per query via the API. * [ENHANCEMENT] API: Change HTTP status code from 503/422 to 499 if a request is canceled. * [ENHANCEMENT] Scrape: Allow exemplars for all metric types. * [ENHANCEMENT] TSDB: Add metrics for head chunks and WAL folders size. * [ENHANCEMENT] TSDB: Automatically remove incorrect snapshot with index that is ahead of WAL. * [ENHANCEMENT] TSDB: Improve Prometheus parser error outputs to be more comprehensible. * [ENHANCEMENT] UI: Scope `group by` labels to metric in autocompletion. * [BUGFIX] Scrape: Fix `prometheus_target_scrape_pool_target_limit` metric not set before reloading. * [BUGFIX] TSDB: Correctly update `prometheus_tsdb_head_chunks_removed_total` and `prometheus_tsdb_head_chunks` metrics when reading WAL. * [BUGFIX] TSDB: Use the correct unit (seconds) when recording out-of-order append deltas in the `prometheus_tsdb_sample_ooo_delta` metric. * update to 2.42.0: This release comes with a bunch of feature coverage for native histograms and breaking changes. If you are trying native histograms already, we recommend you remove the `wal` directory when upgrading. Because the old WAL record for native histograms is not backward compatible in v2.42.0, this will lead to some data loss for the latest data. Additionally, if you scrape "float histograms" or use recording rules on native histograms in v2.42.0 (which writes float histograms), it is a one-way street since older versions do not support float histograms. * [CHANGE] **breaking** TSDB: Changed WAL record format for the experimental native histograms. * [FEATURE] Add 'keep_firing_for' field to alerting rules. * [FEATURE] Promtool: Add support of selecting timeseries for TSDB dump. * [ENHANCEMENT] Agent: Native histogram support. * [ENHANCEMENT] Rules: Support native histograms in recording rules. * [ENHANCEMENT] SD: Add container ID as a meta label for pod targets for Kubernetes. * [ENHANCEMENT] SD: Add VM sizelabel to azure service discovery. * [ENHANCEMENT] Support native histograms in federation. * [ENHANCEMENT] TSDB: Add gauge histogram support. * [ENHANCEMENT] TSDB/Scrape: Support FloatHistogram that represents buckets as float64 values. * [ENHANCEMENT] UI: Show individual scrape pools on /targets page. * update to 2.41.0: * [FEATURE] Relabeling: Add keepequal and dropequal relabel actions. * [FEATURE] Add support for HTTP proxy headers. * [ENHANCEMENT] Reload private certificates when changed on disk. * [ENHANCEMENT] Add max_version to specify maximum TLS version in tls_config. * [ENHANCEMENT] Add goos and goarch labels to prometheus_build_info. * [ENHANCEMENT] SD: Add proxy support for EC2 and LightSail SDs. * [ENHANCEMENT] SD: Add new metric prometheus_sd_file_watcher_errors_total. * [ENHANCEMENT] Remote Read: Use a pool to speed up marshalling. * [ENHANCEMENT] TSDB: Improve handling of tombstoned chunks in iterators. * [ENHANCEMENT] TSDB: Optimize postings offset table reading. * [BUGFIX] Scrape: Validate the metric name, label names, and label values after relabeling. * [BUGFIX] Remote Write receiver and rule manager: Fix error handling. * update to 2.40.7: * [BUGFIX] TSDB: Fix queries involving negative buckets of native histograms. * update to 2.40.5: * [BUGFIX] TSDB: Fix queries involving native histograms due to improper reset of iterators. * update to 2.40.3: * [BUGFIX] TSDB: Fix compaction after a deletion is called. * update to 2.40.2: * [BUGFIX] UI: Fix black-on-black metric name color in dark mode. * update to 2.40.1: * [BUGFIX] TSDB: Fix alignment for atomic int64 for 32 bit architecture. * [BUGFIX] Scrape: Fix accept headers. * update to 2.40.0: * [FEATURE] Add experimental support for native histograms. Enable with the flag --enable-feature=native-histograms. * [FEATURE] SD: Add service discovery for OVHcloud. * [ENHANCEMENT] Kubernetes SD: Use protobuf encoding. * [ENHANCEMENT] TSDB: Use golang.org/x/exp/slices forimproved sorting speed. * [ENHANCEMENT] Consul SD: Add enterprise admin partitions. Adds __meta_consul_partition label. Adds partition config in consul_sd_config. * [BUGFIX] API: Fix API error codes for /api/v1/labels and /api/v1/series. * update to 2.39.1: * [BUGFIX] Rules: Fix notifier relabel changing the labels on active alerts. * update to 2.39.0: * [FEATURE] experimental TSDB: Add support for ingesting out-of-order samples. This is configured via out_of_order_time_window field in the config file; check config file docs for more info. * [ENHANCEMENT] API: /-/healthy and /-/ready API calls now also respond to a HEAD request on top of existing GET support. * [ENHANCEMENT] PuppetDB SD: Add __meta_puppetdb_query label. * [ENHANCEMENT] AWS EC2 SD: Add __meta_ec2_region label. * [ENHANCEMENT] AWS Lightsail SD: Add __meta_lightsail_region label. * [ENHANCEMENT] Scrape: Optimise relabeling by re-using memory. * [ENHANCEMENT] TSDB: Improve WAL replay timings. * [ENHANCEMENT] TSDB: Optimise memory by not storing unnecessary data in the memory. * [ENHANCEMENT] TSDB: Allow overlapping blocks by default. \--storage.tsdb.allow-overlapping-blocks now has no effect. * [ENHANCEMENT] UI: Click to copy label-value pair from query result to clipboard. * [BUGFIX] TSDB: Turn off isolation for Head compaction to fix a memory leak. * [BUGFIX] TSDB: Fix 'invalid magic number 0' error on Prometheus startup. * [BUGFIX] PromQL: Properly close file descriptor when logging unfinished queries. * [BUGFIX] Agent: Fix validation of flag options and prevent WAL from growing more than desired. * update to 2.38.0: * [FEATURE]: Web: Add a /api/v1/format_query HTTP API endpoint that allows pretty-formatting PromQL expressions. * [FEATURE]: UI: Add support for formatting PromQL expressions in the UI. * [FEATURE]: DNS SD: Support MX records for discovering targets. * [FEATURE]: Templates: Add toTime() template function that allows converting sampletimestamps to Go time.Time values. * [ENHANCEMENT]: Kubernetes SD: Add __meta_kubernetes_service_port_number meta label indicating the service port number. * [ENHANCEMENT]: Kubernetes SD: Add __meta_kubernetes_pod_container_image meta label indicating the container image. * [ENHANCEMENT]: PromQL: When a query panics, also log the query itself alongside the panic message. * [ENHANCEMENT]: UI: Tweak colors in the dark theme to improve the contrast ratio. * [ENHANCEMENT]: Web: Speed up calls to /api/v1/rules by avoiding locks and using atomic types instead. * [ENHANCEMENT]: Scrape: Add a no-default-scrape-port feature flag, which omits or removes any default HTTP (:80) or HTTPS (:443) ports in the target's scrape address. * [BUGFIX]: TSDB: In the WAL watcher metrics, expose the type="exemplar" label instead of type="unknown" for exemplar records. * [BUGFIX]: TSDB: Fix race condition around allocating series IDs during chunk snapshot loading. * Remove npm_licenses.tar.bz2 during "make clean" * Remove web-ui archives during "make clean". * [SECURITY] CVE-2022-41715: Limit memory used by parsing regexps (bsc#1204023). * Fix uncontrolled resource consumption by updating Go to version 1.20.1 (CVE-2022-41723, bsc#1208298) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3288=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3288=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-3288=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-3288=1 * SUSE Manager Proxy 4.3 Module 4.3 zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Proxy-4.3-2024-3288=1 ## Package List: * openSUSELeap 15.5 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.45.6-150100.4.20.1 * firewalld-prometheus-config-0.1-150100.4.20.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.45.6-150100.4.20.1 * firewalld-prometheus-config-0.1-150100.4.20.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.45.6-150100.4.20.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.45.6-150100.4.20.1 * SUSE Manager Proxy 4.3 Module 4.3 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-prometheus-2.45.6-150100.4.20.1 ## References: * https://www.suse.com/security/cve/CVE-2022-41715.html * https://www.suse.com/security/cve/CVE-2022-41723.html * https://www.suse.com/security/cve/CVE-2023-45142.html * https://www.suse.com/security/cve/CVE-2024-6104.html * https://bugzilla.suse.com/show_bug.cgi?id=1204023 * https://bugzilla.suse.com/show_bug.cgi?id=1208298 * https://bugzilla.suse.com/show_bug.cgi?id=1227038 * https://bugzilla.suse.com/show_bug.cgi?id=1228556 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FMSQA-848&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-3577&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-5406&page_caps=&user_role= . SUSE reveals significant patches for golang-github-prometheus-prometheus, targeting severe vulnerabilities.. SUSE Security Updates,golang-github-prometheus-prometheus,SUSE Linux Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 17, 2024 Important SuSE
89

Fedora 39: FEDORA-2024-a8a4ce2864 Critical: Compressed Data Handling Issue

release v1.11.0 release v1.10.1 release v1.10.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a8a4ce2864 2024-03-31 01:12:46.078654 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 39 Version : 1.11.0 Release : 1.fc39 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: release v1.11.0 release v1.10.1 release v1.10.0 -------------------------------------------------------------------------------- ChangeLog: * Fri Mar 22 2024 Navid Yaghoobi - 1.11.0-1 - release v1.11.0 * Sun Mar 17 2024 Navid Yaghoobi - 1.10.1-1 - release v1.10.1 * Sat Mar 16 2024 Navid Yaghoobi - 1.10.0-1 - release v1.10.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2268896 - CVE-2024-28180 prometheus-podman-exporter: jose-go: improper handling of highly compressed data [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2268896 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a8a4ce2864' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest update for the prometheus-podman-exporter in Fedora 39 addresses a problem associated with the management of compressed data. Discover more details!. Prometheus Exporter,Fedora 39,Software Update,Podman,Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 31, 2024 Critical Fedora
89

Fedora 39: FEDORA-2024-a53b24023d Critical: Prometheus Exporter SSH Attack

Security fix for CVE-2023-48795. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a53b24023d 2024-01-29 06:23:44.937502 -------------------------------------------------------------------------------- Name : prometheus-podman-exporter Product : Fedora 39 Version : 1.7.0 Release : 1.fc39 URL : https://github.com/containers/prometheus-podman-exporter Summary : Prometheus exporter for podman environment Description : Prometheus exporter for podman environments exposing containers, pods, images, volumes and networks information. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-48795 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 21 2024 Navid Yaghoobi - 1.7.0-1 - release v1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255105 - CVE-2023-48795 prometheus-podman-exporter: ssh: Prefix truncation attack on Binary Packet Protocol (BPP) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255105 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a53b24023d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A patch for the prometheus-podman-exporter in Fedora 39 resolves CVE-2023-48795 to improve system security.. Fedora 39 Prometheus Exporter, CVE-2023-48795 Fix, Podman Security Update, SSH Attack Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 29, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200