Explore top 10 tips to secure your open-source projects now. Read More
×
An update for python3 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: python3 security update Advisory ID: RHSA-2023:5531-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5531 Issue date: 2023-10-09 CVE Names: CVE-2023-40217 ===================================================================== 1. Summary: An update for python3 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: TLS handshake bypass (CVE-2023-40217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2235789 - CVE-2023-40217 python: TLS handshake bypass 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.6): aarch64: platform-python-debug-3.6.8-47.el8_6.2.aarch64.rpm platform-python-devel-3.6.8-47.el8_6.2.aarch64.rpm python3-debuginfo-3.6.8-47.el8_6.2.aarch64.rpm python3-debugsource-3.6.8-47.el8_6.2.aarch64.rpm python3-idle-3.6.8-47.el8_6.2.aarch64.rpm python3-tkinter-3.6.8-47.el8_6.2.aarch64.rpm ppc64le: platform-python-debug-3.6.8-47.el8_6.2.ppc64le.rpm platform-python-devel-3.6.8-47.el8_6.2.ppc64le.rpm python3-debuginfo-3.6.8-47.el8_6.2.ppc64le.rpm python3-debugsource-3.6.8-47.el8_6.2.ppc64le.rpm python3-idle-3.6.8-47.el8_6.2.ppc64le.rpm python3-tkinter-3.6.8-47.el8_6.2.ppc64le.rpm s390x: platform-python-debug-3.6.8-47.el8_6.2.s390x.rpm platform-python-devel-3.6.8-47.el8_6.2.s390x.rpm python3-debuginfo-3.6.8-47.el8_6.2.s390x.rpm python3-debugsource-3.6.8-47.el8_6.2.s390x.rpm python3-idle-3.6.8-47.el8_6.2.s390x.rpm python3-tkinter-3.6.8-47.el8_6.2.s390x.rpm x86_64: platform-python-3.6.8-47.el8_6.2.i686.rpm platform-python-debug-3.6.8-47.el8_6.2.i686.rpm platform-python-debug-3.6.8-47.el8_6.2.x86_64.rpm platform-python-devel-3.6.8-47.el8_6.2.i686.rpm platform-python-devel-3.6.8-47.el8_6.2.x86_64.rpm python3-debuginfo-3.6.8-47.el8_6.2.i686.rpm python3-debuginfo-3.6.8-47.el8_6.2.x86_64.rpm python3-debugsource-3.6.8-47.el8_6.2.i686.rpm python3-debugsource-3.6.8-47.el8_6.2.x86_64.rpm python3-idle-3.6.8-47.el8_6.2.i686.rpm python3-idle-3.6.8-47.el8_6.2.x86_64.rpm python3-test-3.6.8-47.el8_6.2.i686.rpm python3-tkinter-3.6.8-47.el8_6.2.i686.rpm python3-tkinter-3.6.8-47.el8_6.2.x86_64.rpm Red Hat Enterprise Linux BaseOS EUS(v.8.6): Source: python3-3.6.8-47.el8_6.2.src.rpm aarch64: platform-python-3.6.8-47.el8_6.2.aarch64.rpm python3-debuginfo-3.6.8-47.el8_6.2.aarch64.rpm python3-debugsource-3.6.8-47.el8_6.2.aarch64.rpm python3-libs-3.6.8-47.el8_6.2.aarch64.rpm python3-test-3.6.8-47.el8_6.2.aarch64.rpm ppc64le: platform-python-3.6.8-47.el8_6.2.ppc64le.rpm python3-debuginfo-3.6.8-47.el8_6.2.ppc64le.rpm python3-debugsource-3.6.8-47.el8_6.2.ppc64le.rpm python3-libs-3.6.8-47.el8_6.2.ppc64le.rpm python3-test-3.6.8-47.el8_6.2.ppc64le.rpm s390x: platform-python-3.6.8-47.el8_6.2.s390x.rpm python3-debuginfo-3.6.8-47.el8_6.2.s390x.rpm python3-debugsource-3.6.8-47.el8_6.2.s390x.rpm python3-libs-3.6.8-47.el8_6.2.s390x.rpm python3-test-3.6.8-47.el8_6.2.s390x.rpm x86_64: platform-python-3.6.8-47.el8_6.2.x86_64.rpm python3-debuginfo-3.6.8-47.el8_6.2.i686.rpm python3-debuginfo-3.6.8-47.el8_6.2.x86_64.rpm python3-debugsource-3.6.8-47.el8_6.2.i686.rpm python3-debugsource-3.6.8-47.el8_6.2.x86_64.rpm python3-libs-3.6.8-47.el8_6.2.i686.rpm python3-libs-3.6.8-47.el8_6.2.x86_64.rpm python3-test-3.6.8-47.el8_6.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-40217 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlJBu+AAoJENzjgjWX9erETsAQAKhY4n2S1DHnsBPu5N1gwk21 MsOEGKvSk9fOL8+2T4FZIlqTwakdudj/HfpeD8ieoNI5NGQo0/CdlCUpg3cf2yxK 0UK5FEr/wKwVVKB0tTuwge7PHSuWvqVPKfqxtPdgJZRsXbJ4eNBh65fOFJ7Z7kiY +uKnqy8BnqEGt87uiO8HuphfoN7sLK7aWj6jsXpVm8lyJ3BLNqcxeUgM6iyrJmf6 nKTlKirIrSgKGgPfU6G7+WJGQHWP+gOKqmrnbeu6QwslP21uWsC3DNHLaGDFx5aZ cM4F+wxgZ+S+a4ZTfT2d5XKcdp459gD2IiZ8oAftschQPR9WIdP4kOD2p47qd/3k g9dH5lU+rinhZxLqXUyS5V1kd386p5ZjeUbX9Dv76k7DbGOoDEOlR5mK4ENrDstN WjYV+mREy51UNmrql0G8aZPDVmuIMmjLPq1KUGkW61MIOEaTcaKGxikIN/J2TYxm C5D92+qGV1zvbLHd2Bh7MmvrzC45F8TKIDXAw4x0cNDEF3y/DeiSXrzlBxTNG9KD 3jVnVV1LIu75qp5ZcM7z6y1UC+kSCTif56NWVGN5SDTzlUs6Uhyotw5Q6KSfHQLL EdujROpFBQRi/f0cAQHLFCp453A7Dl9sSkVps8BZJQj2s+1097JG4RYGebnNvK9K 9eFj8JEdpxo7J3c5VZH9 =fmrV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for thunderbird is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2023:5439-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5439 Issue date: 2023-10-04 CVE Names: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.9.0) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.3.1. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4.Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2222652 - CVE-2023-3600 firefox: use-after-free in workers 2240893 - CVE-2023-5169 Mozilla: Out-of-bounds write in PathOps 2240894 - CVE-2023-5171 Mozilla: Use-after-free in Ion Compiler 2240896 - CVE-2023-5176 Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 2241191 - CVE-2023-5217 libvpx: Heap buffer overflow in vp8 encoding in libvpx 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.9.0): Source: thunderbird-115.3.1-1.el9_0.src.rpm aarch64: thunderbird-115.3.1-1.el9_0.aarch64.rpm thunderbird-debuginfo-115.3.1-1.el9_0.aarch64.rpm thunderbird-debugsource-115.3.1-1.el9_0.aarch64.rpm ppc64le: thunderbird-115.3.1-1.el9_0.ppc64le.rpm thunderbird-debuginfo-115.3.1-1.el9_0.ppc64le.rpm thunderbird-debugsource-115.3.1-1.el9_0.ppc64le.rpm s390x: thunderbird-115.3.1-1.el9_0.s390x.rpm thunderbird-debuginfo-115.3.1-1.el9_0.s390x.rpm thunderbird-debugsource-115.3.1-1.el9_0.s390x.rpm x86_64: thunderbird-115.3.1-1.el9_0.x86_64.rpm thunderbird-debuginfo-115.3.1-1.el9_0.x86_64.rpm thunderbird-debugsource-115.3.1-1.el9_0.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-3600 https://access.redhat.com/security/cve/CVE-2023-5169 https://access.redhat.com/security/cve/CVE-2023-5171 https://access.redhat.com/security/cve/CVE-2023-5176 https://access.redhat.com/security/cve/CVE-2023-5217 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 RedHat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlHYRpAAoJENzjgjWX9erEDQgP/0G/EvIj3zBNje0yWbcdD0qC iDBIrI3zoaLx9OsaxbA7pOMkZvd3esHwXRV9rIJs4M2Wuzrok1kHJLP3ix7kYtt7 YXrba5RpkOIfhEQCbneXKL0JM7oCthSMFLUii2dKhjbWRrvee78BSOR+DmqChvv1 0Avef3CRB6n4BEToLHfkPVuKA0+65ABR6gBdggew6JUFntA5DgKv0JDxXBLk05HA g7RkNrip69oBdGtBZAp547HOyz2u+Nb2UxTyJOj8tUsFCCePP7AgV0+5qIhxNja4 PSw68PMJQeTcep00bZwpjmRwm+UqdGlHlz3WPvT/D19YbY5RKcXotNgIV0ATbrBq AFX91T8ckA7mC4qiD2UF4INfcTifhIUejLacdxV/Dl1CJoywUDHcKhzllMC9dSAs ijLzXupu7Ttkbsl0Sv0wq6fDqbK7ROxm6v/x97vonK51Y+i7dr+/yjbyK5IhimQd JErtvZj1KFkU4gsWE6yudCRRS0fmyG5FfOjARYhKaV0JsFHLm6K8wBjdceScxOWq FAz/ZcXzIfkVqc2gc9eAOFDM0lvzpEcy6LzvqKA1oShKuiCdVXdepNtmxiSWVzj0 opG7A5ICjtxBC5YS4A1Djqvz0QyF0hLUpQphSfAovf5RDLmEnW3cE8UhVrfO9Vq8 MVtr73ByYuii+31SU4MX =Nbe8 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for thunderbird is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2023:5224-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5224 Issue date: 2023-09-19 CVE Names: CVE-2023-4863 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.15.1. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2238431 - CVE-2023-4863 libwebp: Heap buffer overflow in WebPCodec 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: thunderbird-102.15.1-1.el9_2.src.rpm aarch64: thunderbird-102.15.1-1.el9_2.aarch64.rpm thunderbird-debuginfo-102.15.1-1.el9_2.aarch64.rpm thunderbird-debugsource-102.15.1-1.el9_2.aarch64.rpm ppc64le: thunderbird-102.15.1-1.el9_2.ppc64le.rpm thunderbird-debuginfo-102.15.1-1.el9_2.ppc64le.rpm thunderbird-debugsource-102.15.1-1.el9_2.ppc64le.rpm s390x: thunderbird-102.15.1-1.el9_2.s390x.rpm thunderbird-debuginfo-102.15.1-1.el9_2.s390x.rpm thunderbird-debugsource-102.15.1-1.el9_2.s390x.rpm x86_64: thunderbird-102.15.1-1.el9_2.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el9_2.x86_64.rpm thunderbird-debugsource-102.15.1-1.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-4863 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCWl+AAoJENzjgjWX9erE1bUP/i6j7UACBljwknEWUY6oASPc fp8l3BtUrtoMMIpLYwpuwEHgNM86BNStsVMzRSMT7XPkK3dRLBk4326OLm/2yEZJ B/wliTO+neP7PRkOPmaHjJg3O0hsZTJHSUFryg8bbteIteJiCFVifBamNpaR2GeR 3oYexrVyOvOTjSdueJSore645jOcyhsQaMc+mNA5fbAy0bVL2D3E8A7iIbntwaBz No6Q4/zwMEakm3qEXSd8Xc9bpvaLZr8Z7g0Pd7uijMZAJKdKx8UyCA0y/NeWi6Y/ A5btMjnKIxB1VYJxAgwxMYy/MdU2FTwfjBZ61V0e+a+OrrGKBIBYbIHZczKohfsF +MZyg229LFxsq80WbP/z9CsuNT8AtsJt286feQqdFz5/WAMiXgLgFMhZNFmYTJoW kLBvZvbLpwy4itC44BJST9JfNFWlmofg948Hdu5ChAwS00LjM0PIok0JF9Ol5Zu0 +znDFbckz8yzwjS5hATH/JUmT9T9TKFmCatt2JNKwjF1lle7bCeYQgXf7uNc2UO2 cIR9rH9KJwIxKfXBB3nD38TnNRvh0imp5XtvHh1tpoXPv6pZCBwGFo27eKN4NyR3 0cpaM8ZXouhEEmYacKBf6p/P3K4qKXn5jcsvuNTUWbSqbnt4Vhb9MNdLfgESA1lA jGVfJt/jJ12JpT+DeQSD =fYw8 -----END PGP SIGNATURE----- -- RHSA-announce mailinglist
An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2023:5185-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5185 Issue date: 2023-09-18 CVE Names: CVE-2023-4863 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Telecommunications Update Service, and Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream AUS (v.8.4) - x86_64 Red Hat Enterprise Linux AppStream E4S (v.8.4) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux AppStream TUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.15.1. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2238431 - CVE-2023-4863 libwebp: Heap buffer overflow in WebP Codec 6. Package List: Red Hat Enterprise Linux AppStream AUS (v.8.4): Source: thunderbird-102.15.1-1.el8_4.src.rpm x86_64: thunderbird-102.15.1-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el8_4.x86_64.rpm thunderbird-debugsource-102.15.1-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream E4S (v.8.4): Source: thunderbird-102.15.1-1.el8_4.src.rpm aarch64: thunderbird-102.15.1-1.el8_4.aarch64.rpm thunderbird-debuginfo-102.15.1-1.el8_4.aarch64.rpm thunderbird-debugsource-102.15.1-1.el8_4.aarch64.rpm ppc64le: thunderbird-102.15.1-1.el8_4.ppc64le.rpm thunderbird-debuginfo-102.15.1-1.el8_4.ppc64le.rpm thunderbird-debugsource-102.15.1-1.el8_4.ppc64le.rpm s390x: thunderbird-102.15.1-1.el8_4.s390x.rpm thunderbird-debuginfo-102.15.1-1.el8_4.s390x.rpm thunderbird-debugsource-102.15.1-1.el8_4.s390x.rpm x86_64: thunderbird-102.15.1-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el8_4.x86_64.rpm thunderbird-debugsource-102.15.1-1.el8_4.x86_64.rpm Red Hat Enterprise Linux AppStream TUS (v.8.4): Source: thunderbird-102.15.1-1.el8_4.src.rpm aarch64: thunderbird-102.15.1-1.el8_4.aarch64.rpm thunderbird-debuginfo-102.15.1-1.el8_4.aarch64.rpm thunderbird-debugsource-102.15.1-1.el8_4.aarch64.rpm ppc64le: thunderbird-102.15.1-1.el8_4.ppc64le.rpm thunderbird-debuginfo-102.15.1-1.el8_4.ppc64le.rpm thunderbird-debugsource-102.15.1-1.el8_4.ppc64le.rpm s390x: thunderbird-102.15.1-1.el8_4.s390x.rpm thunderbird-debuginfo-102.15.1-1.el8_4.s390x.rpm thunderbird-debugsource-102.15.1-1.el8_4.s390x.rpm x86_64: thunderbird-102.15.1-1.el8_4.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el8_4.x86_64.rpm thunderbird-debugsource-102.15.1-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how toverify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-4863 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCGyAAAoJENzjgjWX9erEgE0QAJbYx8JAaavwCRAdFKUXagSU CYpNZjfZNpLa4PplP87my4UHhvbZTFv6v/QviYwjf36GdqsP9BK/aAa2zM25HSCO FNgT4e+2X67EakkN2JcPjVwWMt+jqzCE+CyV4AS/TfYXVvUEDGUIx00TMXpn73Pv nOzqyoYEnaNXsJ1cpE/gxM/Er3vxNpPK2+HAwHRssCB0bJVsGj+/QV9F3ZSlZyc5 OmVvl5f29yhqRqp32vUyMEW1xqhB9TdRABYUZ+AnW0KJnYIqXnvDj8bfDSbId7aL xLRMHO/UI+/zG0iJDi34Bga63IwBt+N3QF1E8OVCtRFoq6khZ/x7pMlzbxjzIpTe x7/lpXvfNXR+aUvv2kv0me90BD0pwia2JkyKM3Ttmjrn8AjZv3DzCbRrzu5jWnTI LE4xPSq3Ur+thOOS5EAKFJO7qebNjY+sQp/9fQpIvrG9hqKGylkuACQfwdic7FQx RolRYOa3ZJt6sG8I02QKL7hRxFHAJAe9xCfDx6TPL9fdu2GjWh4jYEOUeJfbE6a9 Tr0ki2oLF9eFMbtxRyzgdcaalzGmPY7pJ2Gu8keX+x2AwMOLhjtX/OqTvfs5hqGb v2Kn3G2U3TPY0u6BJ8p4rdiMl0a8VznfAc+T/EXLT7fHo4pj3KbshSJfANicnr7v t8O4TgcGxxXBGcJpKjzE =hH95 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: firefox security update Advisory ID: RHSA-2023:5184-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5184 Issue date: 2023-09-18 CVE Names: CVE-2023-4863 ===================================================================== 1. Summary: An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 102.15.1 ESR. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Firefox must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2238431 - CVE-2023-4863libwebp: Heap buffer overflow in WebP Codec 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: firefox-102.15.1-1.el8_8.src.rpm aarch64: firefox-102.15.1-1.el8_8.aarch64.rpm firefox-debuginfo-102.15.1-1.el8_8.aarch64.rpm firefox-debugsource-102.15.1-1.el8_8.aarch64.rpm ppc64le: firefox-102.15.1-1.el8_8.ppc64le.rpm firefox-debuginfo-102.15.1-1.el8_8.ppc64le.rpm firefox-debugsource-102.15.1-1.el8_8.ppc64le.rpm s390x: firefox-102.15.1-1.el8_8.s390x.rpm firefox-debuginfo-102.15.1-1.el8_8.s390x.rpm firefox-debugsource-102.15.1-1.el8_8.s390x.rpm x86_64: firefox-102.15.1-1.el8_8.x86_64.rpm firefox-debuginfo-102.15.1-1.el8_8.x86_64.rpm firefox-debugsource-102.15.1-1.el8_8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-4863 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCGxhAAoJENzjgjWX9erEU7sQAIgT8DLlIJnQOsUKnK+/zNjs QTPHAWa9HyE4LaEwjWP9uanGJVj75BeaaOAdDiw3jeZdRasriy7QneA2X3yGLg/+ HugGhSd3kxtXF48SgwjH78otwInmcXKGVH0rQwnauoPcAhspJ23vCtMHdjl41znd aLgLOyDlTE3lH/ajf1wNX/OVGYsIIdR0A4AIRjSd7Neb9vudWxWSkeqiZngfls+2 1llrxas82nlS6wMqOtlgm18j8rd+aaiEC1CD7aFc+jMbt7onhnP+eZcDEcamuu2X g0QAqt5pQ9jK3eCjxsitKnAuU0ZDURRPZiAELx2D/SUOlPnVH8h54g8i/slCwJcf 1QjYdpjKGc2HAqKApMqK0zu6lLEbh76AIR/rBkPQsqNZjj5pB7RmQgE+NLG38M7+ hwju2gPIOJNP4g3LDzFS4mIJYFKJeD+93ad6KEOAToEiCVHsWyMAhSwJzoIBcxqq PYz4a+ZbsIDVaG+xBDxhf/ZC93GBB7SxFRsULWKzlXYPtDWK0bFPV/I6P88zcFab QTxdVgVM+LGKLc+tNg6yU5W28BXCR0GwoCITlzQWisOAjy/xxyS1iuVcNCGfu4fo sx/c53DI501ObzV2Y+VzvS+vnzzID1McJAdPskecv6GijRq4LZrlH64GD2ZscsDq 1Cg6jF6BfeI/H0yojYr7 =cOkm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: thunderbird security update Advisory ID: RHSA-2023:5191-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5191 Issue date: 2023-09-18 CVE Names: CVE-2023-4863 ===================================================================== 1. Summary: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 3. Description: Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 102.15.1. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 All running instances of Thunderbird must be restarted for the update to take effect. 5. Bugs fixed(https://bugzilla.redhat.com/): 2238431 - CVE-2023-4863 libwebp: Heap buffer overflow in WebP Codec 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: thunderbird-102.15.1-1.el7_9.src.rpm x86_64: thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): Source: thunderbird-102.15.1-1.el7_9.src.rpm ppc64le: thunderbird-102.15.1-1.el7_9.ppc64le.rpm thunderbird-debuginfo-102.15.1-1.el7_9.ppc64le.rpm x86_64: thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: thunderbird-102.15.1-1.el7_9.src.rpm x86_64: thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-4863 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlCGxbAAoJENzjgjWX9erEpbcQAINL2TWNvzuU5VCq05fsFfdN XCoVVnT82e+MLgu9072rROeEbKOoCtRUqPEN4YOmbIu9JXGXZOI7oE9fy/bwGbck QfLDiCHBoZMbJs9+q2LJ70o4kJel9HESxQOXeWrJE9OhpaI4dIuy11r7hvuSC/jK hcKP2zLdiFMKjd2ZLtZmQZt5wiykQZQvgnGjK7MhaL1lxrvTFKacAxqDOcIAvbXc gSpNc1qgJxaPKQLWZpcTshQkAqxK5vA3lWxhx7/flmRVFkAm+yXRL3S0xy1Qo8+x xQt8fZmWz0/ZSxU+Fx7LSRrdEc+WL8SKD2/s5eJWus553LAGS7VlDCzeJy1XuzmR 1oSiuhvGsauTW9cHQF7I37RrF2m1itl6Z/EoNi0AfmMP8LG1ABL9tR5cOINp2H3z PLoH8W0DyvQkQdZNeAYXlkDskX+6NgMTKJ4YeLJST+Xj933gjbBPeIT9NSBtJWXp Fw5GLe5FOMc+9jC/Q8RR407AK6D7a/0Y2haM4utpF8MxA7kj1743rcX3CssPsOkB 17xh5SKaeePHcz278uyRKW3Iv6NTGqWYsmeA7MoK6IVDuioj3ymmRuNj30ZZ8vUj 7FlQ20wigs3oUixS8AKiJqaKNFuZsqRRvkTPcI3k3nNUMaMLxmvaLMa03IlDOlW1 nY5EuVf3/QlMRXY48rmh =seGu -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for flac is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: flac security update Advisory ID: RHSA-2023:5048-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5048 Issue date: 2023-09-11 CVE Names: CVE-2020-22219 ===================================================================== 1. Summary: An update for flac is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 9) - aarch64, ppc64le, s390x, x86_64 3. Description: FLAC stands for Free Lossless Audio Codec. FLAC is similar to Ogg Vorbis, but lossless. The FLAC project consists of the stream format, reference encoders and decoders in library form, a command-line program to encode and decode FLAC files, and a command-line metadata editor for FLAC files. Security Fix(es): * flac: Remote Code Execution (RCE) via the bitwriter_grow_ function, by supplying crafted input to the encoder (CVE-2020-22219) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, whichincludes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2235489 - CVE-2020-22219 flac: Remote Code Execution (RCE) via the bitwriter_grow_ function, by supplying crafted input to the encoder 6. Package List: Red Hat Enterprise Linux AppStream (v. 9): Source: flac-1.3.3-10.el9_2.1.src.rpm aarch64: flac-debuginfo-1.3.3-10.el9_2.1.aarch64.rpm flac-debugsource-1.3.3-10.el9_2.1.aarch64.rpm flac-libs-1.3.3-10.el9_2.1.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.aarch64.rpm ppc64le: flac-debuginfo-1.3.3-10.el9_2.1.ppc64le.rpm flac-debugsource-1.3.3-10.el9_2.1.ppc64le.rpm flac-libs-1.3.3-10.el9_2.1.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.ppc64le.rpm s390x: flac-debuginfo-1.3.3-10.el9_2.1.s390x.rpm flac-debugsource-1.3.3-10.el9_2.1.s390x.rpm flac-libs-1.3.3-10.el9_2.1.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.s390x.rpm x86_64: flac-debuginfo-1.3.3-10.el9_2.1.i686.rpm flac-debuginfo-1.3.3-10.el9_2.1.x86_64.rpm flac-debugsource-1.3.3-10.el9_2.1.i686.rpm flac-debugsource-1.3.3-10.el9_2.1.x86_64.rpm flac-libs-1.3.3-10.el9_2.1.i686.rpm flac-libs-1.3.3-10.el9_2.1.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.i686.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.x86_64.rpm Red Hat Enterprise Linux CRB (v.9): aarch64: flac-1.3.3-10.el9_2.1.aarch64.rpm flac-debuginfo-1.3.3-10.el9_2.1.aarch64.rpm flac-debugsource-1.3.3-10.el9_2.1.aarch64.rpm flac-devel-1.3.3-10.el9_2.1.aarch64.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.aarch64.rpm ppc64le: flac-1.3.3-10.el9_2.1.ppc64le.rpm flac-debuginfo-1.3.3-10.el9_2.1.ppc64le.rpm flac-debugsource-1.3.3-10.el9_2.1.ppc64le.rpm flac-devel-1.3.3-10.el9_2.1.ppc64le.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.ppc64le.rpm s390x: flac-1.3.3-10.el9_2.1.s390x.rpm flac-debuginfo-1.3.3-10.el9_2.1.s390x.rpm flac-debugsource-1.3.3-10.el9_2.1.s390x.rpm flac-devel-1.3.3-10.el9_2.1.s390x.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.s390x.rpm x86_64: flac-1.3.3-10.el9_2.1.x86_64.rpm flac-debuginfo-1.3.3-10.el9_2.1.i686.rpm flac-debuginfo-1.3.3-10.el9_2.1.x86_64.rpm flac-debugsource-1.3.3-10.el9_2.1.i686.rpm flac-debugsource-1.3.3-10.el9_2.1.x86_64.rpm flac-devel-1.3.3-10.el9_2.1.i686.rpm flac-devel-1.3.3-10.el9_2.1.x86_64.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.i686.rpm flac-libs-debuginfo-1.3.3-10.el9_2.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-22219 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk/2WhAAoJENzjgjWX9erE3DYP+wS27lw358et2AX5osfA6VS8 E/1q3v2t/JoCafeDq18wz0scuio5KLVdzxxxv+LJy/bozmkLhyKXIEqj2tTrQF4p /m27rDypksancVGZClu8GhO1fexyzzywhPO1jVdRRzbvL2cbDLoSy1aUL09m8fyf bQCSMtIUIi2GB0j/o2ANU6kGZNeVLIZzN3sBeh+UPCRRWKeazPt1aIgw/X7Lp9Fj HWY2lpSz11SHNYfi+w8zueDREcRrK27K9+IEEtZmYntWJ1HIHucGTFmo3phM80fL RPFeUDQTc9/T+opHXaXgqwXGm2F9h1+UCNhXn8Ce81diTOthGQqA7hn1o1AfPJEw CAcyYZC6koez06KkX8MC4nTpSSBaGZg3qQawYEd/Fvv8AKyrqdQ8j+SW91rro87i BV8unUKfk/85ae/4z+zxDGAEwKqGF1Oq0IkZNPHGw6pyRXXtn8y2zpTGROd6Ovce nVLVr1OP9rUdPJ5LQkr6AC0avwRNakOTaoqxrIrS8ZWho436w44+Q2ba3uHbP/t+ 1JG2w+ckAw8eU9bzY5k9i0yjeTYBDJfAC9FLSjc+MkzbUh+jtS+ODIOch6Ef0zqY nVjvrOI4a9p/giLKEnJJA851tQ4Pik7/KtJx0mE81I4ibBNOYbqHtWEDQA42tDPN 1c72yatovuF8qIjLkBbY =s/9A -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: kpatch-patch security update Advisory ID: RHSA-2023:4967-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4967 Issue date: 2023-09-05 CVE Names: CVE-2023-1829 CVE-2023-3090 CVE-2023-3390 CVE-2023-4004 CVE-2023-35001 CVE-2023-35788 ===================================================================== 1. Summary: An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS E4S (v.8.4) - ppc64le, x86_64 3. Description: This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Security Fix(es): * kernel: Use-after-free vulnerability in the Linux Kernel traffic control index filter (CVE-2023-1829) * kernel: ipvlan: out-of-bounds write caused by unclear skb-> cb (CVE-2023-3090) * kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests (CVE-2023-3390) * kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() (CVE-2023-4004) * kernel: nf_tables: stack-out-of-bounds-read innft_byteorder_eval() (CVE-2023-35001) * kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt() (CVE-2023-35788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2188470 - CVE-2023-1829 kernel: Use-after-free vulnerability in the Linux Kernel traffic control index filter 2213260 - CVE-2023-3390 kernel: UAF in nftables when nft_set_lookup_global triggered after handling named and anonymous sets in batch requests 2215768 - CVE-2023-35788 kernel: cls_flower: out-of-bounds write in fl_set_geneve_opt() 2218672 - CVE-2023-3090 kernel: ipvlan: out-of-bounds write caused by unclear skb-> cb 2220892 - CVE-2023-35001 kernel: nf_tables: stack-out-of-bounds-read in nft_byteorder_eval() 2225275 - CVE-2023-4004 kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() 6. Package List: Red Hat Enterprise Linux BaseOS E4S(v.8.4): Source: kpatch-patch-4_18_0-305_76_1-1-5.el8_4.src.rpm kpatch-patch-4_18_0-305_82_1-1-4.el8_4.src.rpm kpatch-patch-4_18_0-305_86_2-1-3.el8_4.src.rpm kpatch-patch-4_18_0-305_88_1-1-3.el8_4.src.rpm kpatch-patch-4_18_0-305_91_1-1-2.el8_4.src.rpm kpatch-patch-4_18_0-305_97_1-1-1.el8_4.src.rpm ppc64le: kpatch-patch-4_18_0-305_76_1-1-5.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_76_1-debuginfo-1-5.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_76_1-debugsource-1-5.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_82_1-1-4.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_82_1-debuginfo-1-4.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_82_1-debugsource-1-4.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_86_2-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_86_2-debuginfo-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_86_2-debugsource-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_88_1-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_88_1-debuginfo-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_88_1-debugsource-1-3.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_91_1-1-2.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_91_1-debuginfo-1-2.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_91_1-debugsource-1-2.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_97_1-1-1.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_97_1-debuginfo-1-1.el8_4.ppc64le.rpm kpatch-patch-4_18_0-305_97_1-debugsource-1-1.el8_4.ppc64le.rpm x86_64: kpatch-patch-4_18_0-305_76_1-1-5.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_76_1-debuginfo-1-5.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_76_1-debugsource-1-5.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_82_1-1-4.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_82_1-debuginfo-1-4.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_82_1-debugsource-1-4.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_86_2-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_86_2-debuginfo-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_86_2-debugsource-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_88_1-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_88_1-debuginfo-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_88_1-debugsource-1-3.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_91_1-1-2.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_91_1-debuginfo-1-2.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_91_1-debugsource-1-2.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_97_1-1-1.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_97_1-debuginfo-1-1.el8_4.x86_64.rpm kpatch-patch-4_18_0-305_97_1-debugsource-1-1.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-1829 https://access.redhat.com/security/cve/CVE-2023-3090 https://access.redhat.com/security/cve/CVE-2023-3390 https://access.redhat.com/security/cve/CVE-2023-4004 https://access.redhat.com/security/cve/CVE-2023-35001 https://access.redhat.com/security/cve/CVE-2023-35788 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJk9yhYAAoJENzjgjWX9erEtTIP/0EruC40gi4fT3+YLIxrNIgS Bl7SK1GQ+KMtIn/5+IEqJPg57qIJpNESofG9gjVww7lXoyc8SPmU9NIDoEA25gK0 im5GujEq4c+c07RR9gadfpcDVP61gayDlsxK//LeF2SQ34mZep2KSeDbHeR3uDgN zbP1slHBN0pD2PGiqnTu5MlYya6cbnonsaBxMYIWbkTrKpBSpz4tXUZSVwWeAytq Iqobzcd1RDBlkdX7IR53A6RI7g2MGYjgD+rK3WX3F/b4pnAD+M0IEzx4HTC+5IeI oDtUjyI/qsJKfKHPaK/N/9AmWprReoYfPw3uPcg+NEYcQl3Iwsn1skPM2kU0UzBA LJSi/3caU32+atAB4OxCotNpjX4XUuf1o06p5J5tN8h5BWx7gw1Ce+CBLvfylqg3 z1TroQ6aBBkyxADt/ACOghbDaqOS0S5YboJYEfxnyEcEwwYXS4xFY8ZNl4UcOBt7 VklDpo8g9k3tB8gLN/FEFsNEd0lAkTPqcSNup8+pB799BZgJ9ALhwhIUe+VD5beM bT3mmJodsRDO/f/UYqtbFlQxsy9m/NVhfEZ+9tL3Od29v3pCJNj2A0lMpDjHBt2+ 7iX5lfH0M16S6AGMh+xm/llAY9eFLZl+9THUzrHGtZBnnfOt4fhJ++nfhXJ1uXoj +ANDl9NZ1qMdTVVv6goN =O4mq -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.