Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Ruby.. ========================================================================== Ubuntu Security Notice USN-8556-1 July 16, 2026 ruby2.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Ruby. Software Description: - ruby2.3: Object-oriented scripting language Details: It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject arbitrary IMAP commands via CRLF sequences. (CVE-2026-42258) It was discovered that the Zlib::GzipReader in Ruby did not correctly ensure sufficient buffer capacity in the zstream_buffer_ungets function. An attacker could use this to craft a gzip stream that, when processed, could cause a buffer overflow, resulting in memory corruption and possibly arbitrary code execution. (CVE-2026-27820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8556-1 CVE-2026-27820, CVE-2026-42258 . Security issues in Ruby for Ubuntu 16.04 LTS addressed with recommended updates to prevent exploitation.. Ruby security patch, Ubuntu system update, buffer overflow fix, command injection vulnerability. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0083 http://linux.oracle.com/errata/ELSA-2025-0083.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: cups-2.2.6-62.el8_10.x86_64.rpm cups-client-2.2.6-62.el8_10.x86_64.rpm cups-devel-2.2.6-62.el8_10.i686.rpm cups-devel-2.2.6-62.el8_10.x86_64.rpm cups-filesystem-2.2.6-62.el8_10.noarch.rpm cups-ipptool-2.2.6-62.el8_10.x86_64.rpm cups-libs-2.2.6-62.el8_10.i686.rpm cups-libs-2.2.6-62.el8_10.x86_64.rpm cups-lpd-2.2.6-62.el8_10.x86_64.rpm aarch64: cups-2.2.6-62.el8_10.aarch64.rpm cups-client-2.2.6-62.el8_10.aarch64.rpm cups-devel-2.2.6-62.el8_10.aarch64.rpm cups-filesystem-2.2.6-62.el8_10.noarch.rpm cups-ipptool-2.2.6-62.el8_10.aarch64.rpm cups-libs-2.2.6-62.el8_10.aarch64.rpm cups-lpd-2.2.6-62.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//cups-2.2.6-62.el8_10.src.rpm Related CVEs: CVE-2024-47175 Description of changes: [1:2.2.6-62] - RHEL-60338 CVE-2024-47175 cups: remote command injection via attacker controlled data in PPD file _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-9470 http://linux.oracle.com/errata/ELSA-2024-9470.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cups-2.3.3op2-31.el9_5.x86_64.rpm cups-client-2.3.3op2-31.el9_5.x86_64.rpm cups-devel-2.3.3op2-31.el9_5.i686.rpm cups-devel-2.3.3op2-31.el9_5.x86_64.rpm cups-filesystem-2.3.3op2-31.el9_5.noarch.rpm cups-ipptool-2.3.3op2-31.el9_5.x86_64.rpm cups-libs-2.3.3op2-31.el9_5.i686.rpm cups-libs-2.3.3op2-31.el9_5.x86_64.rpm cups-lpd-2.3.3op2-31.el9_5.x86_64.rpm cups-printerapp-2.3.3op2-31.el9_5.x86_64.rpm aarch64: cups-2.3.3op2-31.el9_5.aarch64.rpm cups-client-2.3.3op2-31.el9_5.aarch64.rpm cups-devel-2.3.3op2-31.el9_5.aarch64.rpm cups-filesystem-2.3.3op2-31.el9_5.noarch.rpm cups-ipptool-2.3.3op2-31.el9_5.aarch64.rpm cups-libs-2.3.3op2-31.el9_5.aarch64.rpm cups-lpd-2.3.3op2-31.el9_5.aarch64.rpm cups-printerapp-2.3.3op2-31.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//cups-2.3.3op2-31.el9_5.src.rpm Related CVEs: CVE-2024-47175 Description of changes: [1:2.3.3op2-31] - RHEL-60343 CVE-2024-47175 cups: remote command injection via attacker controlled data in PPD file _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7463 http://linux.oracle.com/errata/ELSA-2024-7463.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: cups-filters-1.20.0-35.0.1.el8_10.x86_64.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.i686.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.x86_64.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.i686.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.x86_64.rpm aarch64: cups-filters-1.20.0-35.0.1.el8_10.aarch64.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.aarch64.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//cups-filters-1.20.0-35.0.1.el8_10.src.rpm Related CVEs: CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 Description of changes: [1.20.0-35.0.1] - header/footer not being printed in banner page. [Orabug: 28265099] (
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7346 http://linux.oracle.com/errata/ELSA-2024-7346.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cups-filters-1.28.7-17.0.1.el9_4.x86_64.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.i686.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.x86_64.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.i686.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.x86_64.rpm aarch64: cups-filters-1.28.7-17.0.1.el9_4.aarch64.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.aarch64.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//cups-filters-1.28.7-17.0.1.el9_4.src.rpm Related CVEs: CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 Description of changes: [1.28.7-17.0.1] - header/footer not being printed in banner page. [Orabug: 28265099] (
Important: cups-filters security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:7346", "synopsis": "Important: cups-filters security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for cups-filters.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The cups-filters package contains back ends, filters, and other software that was once part of the core Common UNIX Printing System (CUPS) distribution but is now maintained independently. \n\nSecurity Fix(es):\n\n* cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source ()\n\n* cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes (CVE-2024-47076)\n\n* cups: libppd: remote command injection via attacker controlled data in PPD file ()\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2314252", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314252", "description": ""}, {"ticket": "2314253", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314253", "description": ""}, {"ticket": "2314256", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314256", "description": ""}], "cves": [{"name": "CVE-2024-47076", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47076", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-47175", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47175", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe":"UNKNOWN"}, {"name": "CVE-2024-47176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47176", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-09-30T14:31:39.795853Z", "rpms": {"Rocky Linux 9": {"nvras": ["cups-filters-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-0:1.28.7-17.el9_4.src.rpm", "cups-filters-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.i686.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.i686.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Significant cups-filters enhancement for Rocky Linux 9 resolves various security vulnerabilities, bolstering overall system protection.. cups filters update, rocky linux security, 2024 security advisories. . Severity: Important. LinuxSecurity.com Team
# Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ca5321b5ff 2018-05-15 20:03:56.912735 --------------------------------------------------------------------------------Name : mysql-mmm Product : Fedora 28 Version : 2.2.1 Release : 20.fc28 URL : https://mysql-mmm.org/ Summary : Multi-Master Replication Manager for MySQL Description : MMM (MySQL Master-Master Replication Manager) is a set of flexible scripts to perform monitoring/failover and management of MySQL Master-Master replication configurations (with only one node writable at any time). The toolset also has the ability to read balance standard master/slave configurations with any number of slaves, so you can use it to move virtual IP addresses around a group of servers depending on whether they are behind in replication. In addition to that, it also has scripts for data backups, resynchronization between nodes etc. --------------------------------------------------------------------------------Update Information: # Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by default. A specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privilegesof the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger these vulnerabilities. The impact of these vulnerabilities can be lessened by configuring mmm_agentd to require TLS mutual authentication and by using network ACLs to prevent hosts other than legitimate mmm_mond hosts from accessing mmm_agentd. For example on Linux iptables rules can be used to block access to the port mmm_agent is listening on from all hosts except the mmm_monitor. The configuration of ssl can be used where firewall rules are not practical. See Socket Documentation https://mysql-mmm.org/mysql-mmm.html Add to mmm_common.conf type ssl cert_file /etc/ssl/certs/www..bundle.crt key_file /etc/ssl/certs/www..key ca_file /etc/ssl/certs/ca-bundle.crt # or ca-certificates.crt Now only those with access to the private key can send commands. Whilst your web server certificate will do the job, you may consider registering a dedicated certificate just for this task. NOTE: By now there are a some good alternatives to MySQL-MMM. Maybe you want to check out Galera Cluster which is part of MariaDB Galera Cluster and Percona XtraDB Cluster. - https://mysql-mmm.org/ - https://galeracluster.com/ - https://mariadb.com/kb/en/what-is-mariadb-galera-cluster/ ---------------------------------------------------------------------------------ChangeLog: * Wed May 2 2018 David Beveridge 2.2.1-20 - Patch for mmm_agentd Remote Command Injection Vulnerabilities - TALOS-2017-0501, CVE-2017-14474 - CVE-2017-14481 * Thu Feb 8 2018 Fedora Release Engineering - 2.2.1-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1575161 https://bugzilla.redhat.com/show_bug.cgi?id=1575161 --------------------------------------------------------------------------------This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2018-ca5321b5ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
# Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-e31f52c5ee 2018-05-15 19:52:12.739386 --------------------------------------------------------------------------------Name : mysql-mmm Product : Fedora 27 Version : 2.2.1 Release : 20.fc27 URL : https://mysql-mmm.org/ Summary : Multi-Master Replication Manager for MySQL Description : MMM (MySQL Master-Master Replication Manager) is a set of flexible scripts to perform monitoring/failover and management of MySQL Master-Master replication configurations (with only one node writable at any time). The toolset also has the ability to read balance standard master/slave configurations with any number of slaves, so you can use it to move virtual IP addresses around a group of servers depending on whether they are behind in replication. In addition to that, it also has scripts for data backups, resynchronization between nodes etc. --------------------------------------------------------------------------------Update Information: # Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by default. A specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privilegesof the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger these vulnerabilities. The impact of these vulnerabilities can be lessened by configuring mmm_agentd to require TLS mutual authentication and by using network ACLs to prevent hosts other than legitimate mmm_mond hosts from accessing mmm_agentd. For example on Linux iptables rules can be used to block access to the port mmm_agent is listening on from all hosts except the mmm_monitor. The configuration of ssl can be used where firewall rules are not practical. See Socket Documentation https://mysql-mmm.org/mysql-mmm.html Add to mmm_common.conf type ssl cert_file /etc/ssl/certs/www..bundle.crt key_file /etc/ssl/certs/www..key ca_file /etc/ssl/certs/ca-bundle.crt # or ca-certificates.crt Now only those with access to the private key can send commands. Whilst your web server certificate will do the job, you may consider registering a dedicated certificate just for this task. NOTE: By now there are a some good alternatives to MySQL-MMM. Maybe you want to check out Galera Cluster which is part of MariaDB Galera Cluster and Percona XtraDB Cluster. - https://mysql-mmm.org/ - https://galeracluster.com/ - https://mariadb.com/kb/en/what-is-mariadb-galera-cluster/ ---------------------------------------------------------------------------------ChangeLog: * Wed May 2 2018 David Beveridge 2.2.1-20 - Patch for mmm_agentd Remote Command Injection Vulnerabilities - TALOS-2017-0501, CVE-2017-14474 - CVE-2017-14481 * Thu Feb 8 2018 Fedora Release Engineering - 2.2.1-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Wed Dec 20 2017 Ruben Kerkhof - 2.2.1-18 - Correct permissions for systemd units (#1527992) --------------------------------------------------------------------------------References: [ 1 ] Bug #1575161 https://bugzilla.redhat.com/show_bug.cgi?id=1575161 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-e31f52c5ee' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.