The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1147 https://linux.oracle.com/errata/ELSA-2024-1147.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: rear-2.6-21.0.1.el9_3.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//rear-2.6-21.0.1.el9_3.src.rpm Related CVEs: CVE-2024-23301 Description of changes: [2.6-21.0.1] - rear: creates a world-readable initrd (CVE-2024-23301) _______________________________________________ El-errata mailing list
rear is a disaster recovery and system migration framework. It has been discovered that rear creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3733-1
Get the latest Linux and open source security news straight to your inbox.