Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update addresses two security issues regarding incorrect handling of malformed IPv6 addresses: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) Reject invalid uncompressed IPv6 (CVE-2026-40198). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0a7ed21996 2026-04-22 07:48:13.354956+00:00 -------------------------------------------------------------------------------- Name : perl-Net-CIDR-Lite Product : Fedora 43 Version : 0.23 Release : 1.fc43 URL : https://metacpan.org/release/Net-CIDR-Lite Summary : Perl extension for merging IPv4 or IPv6 CIDR addresses Description : Faster alternative to Net::CIDR when merging a large number of CIDR address ranges. Works for IPv4 and IPv6 addresses. -------------------------------------------------------------------------------- Update Information: This update addresses two security issues regarding incorrect handling of malformed IPv6 addresses: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) Reject invalid uncompressed IPv6 (CVE-2026-40198) -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Paul Howarth - 0.23-1 - Update to 0.23 - Security: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) - Security: Reject invalid uncompressed IPv6 (CVE-2026-40198) * Sat Jan 17 2026 Fedora Release Engineering - 0.22-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0a7ed21996' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0042-1 Rating: important References: #1257650 Cross-References: CVE-2026-1861 CVE-2026-1862 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for chromium fixes the following issues: - Chromium 144.0.7559.132 (boo#1257650) * CVE-2026-1861: Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. * CVE-2026-1862: Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2026-42=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le x86_64): chromedriver-144.0.7559.132-bp156.2.224.1 chromium-144.0.7559.132-bp156.2.224.1 References: https://www.suse.com/security/cve/CVE-2026-1861.html https://www.suse.com/security/cve/CVE-2026-1862.html https://bugzilla.suse.com/1257650 . Update for openSUSE patches important Chromium vulnerabilities including heap corruption risks from remote attackers.. openSUSE security update, Chromium patch, heap corruption issues, remote attack risk. . Severity: Important. LinuxSecurity.com Team
Moderate: php:8.3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:23309", "synopsis": "Moderate: php:8.3 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.php-pecl-redis6, module.php, php-pecl-redis6, module.php-pecl-apcu, php-pecl-rrd, php-pecl-zip, php, module.php-pecl-zip, module.php-pecl-rrd, php-pecl-apcu, php-pecl-xdebug3, module.php-pecl-xdebug3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Server.\n\nSecurity Fix(es):\n\n* php: pgsql extension does not check for errors during escaping (CVE-2025-1735)\n\n* php: NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix (CVE-2025-6491)\n\n* php: PHP Hostname Null Character Vulnerability (CVE-2025-1220)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2378689", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2378689", "description": ""}, {"ticket": "2378690", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2378690", "description": ""}, {"ticket": "2379792", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2379792", "description": ""}], "cves": [{"name": "CVE-2025-1220", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-1220", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N", "cvss3BaseScore": "3.7", "cwe": "CWE-918"}, {"name": "CVE-2025-1735", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-1735", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-476"}, {"name": "CVE-2025-6491", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-6491", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-476"}], "references": [], "publishedAt": "2025-12-19T09:05:01.645210Z", "rpms": {"Rocky Linux 9": {"nvras": ["apcu-panel-0:5.1.23-1.module+el9.7.0+40004+bf50a568.noarch.rpm", "apcu-panel-0:5.1.23-1.module+el9.7.0+40005+715283ec.noarch.rpm", "php-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.src.rpm", "php-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-bcmath-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-bcmath-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-bcmath-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-bcmath-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-bcmath-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-bcmath-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-bcmath-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-bcmath-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-cli-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-cli-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-cli-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-cli-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-cli-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-cli-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-cli-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-cli-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-common-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm","php-common-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-common-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-common-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-common-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-common-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-common-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-common-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-dba-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-dba-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-dba-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-dba-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-dba-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-dba-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-dba-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-dba-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-dbg-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-dbg-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-dbg-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-dbg-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-dbg-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-dbg-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-dbg-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-dbg-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-debugsource-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-debugsource-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm","php-debugsource-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-debugsource-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-devel-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-devel-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-devel-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-devel-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-embedded-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-embedded-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-embedded-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-embedded-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-embedded-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-embedded-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-embedded-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-embedded-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-enchant-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-enchant-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-enchant-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-enchant-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-enchant-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-enchant-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-enchant-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-enchant-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-ffi-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-ffi-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-ffi-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-ffi-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-ffi-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-ffi-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-ffi-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm","php-ffi-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-fpm-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-fpm-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-fpm-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-fpm-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-fpm-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-fpm-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-fpm-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-fpm-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-gd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-gd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-gd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-gd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-gd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-gd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-gd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-gd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-gmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-gmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-gmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-gmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-gmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-gmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-gmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-gmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-intl-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-intl-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-intl-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-intl-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-intl-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm","php-intl-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-intl-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-intl-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-ldap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-ldap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-ldap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-ldap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-ldap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-ldap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-ldap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-ldap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-mbstring-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-mbstring-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-mbstring-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-mbstring-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-mbstring-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-mbstring-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-mbstring-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-mbstring-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-mysqlnd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-mysqlnd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-mysqlnd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-mysqlnd-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-mysqlnd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-mysqlnd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-mysqlnd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-mysqlnd-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-odbc-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm","php-odbc-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-odbc-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-odbc-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-odbc-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-odbc-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-odbc-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-odbc-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-opcache-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-opcache-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-opcache-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-opcache-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-opcache-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-opcache-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-opcache-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-opcache-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-pdo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-pdo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-pdo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-pdo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-pdo-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-pdo-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-pdo-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-pdo-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40004+bf50a568.s390x.rpm","php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40004+bf50a568.src.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40005+715283ec.src.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-apcu-0:5.1.23-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-apcu-debuginfo-0:5.1.23-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-apcu-debugsource-0:5.1.23-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40005+715283ec.s390x.rpm","php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-apcu-devel-0:5.1.23-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-redis6-0:6.1.0-2.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-redis6-0:6.1.0-2.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-redis6-0:6.1.0-2.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-redis6-0:6.1.0-2.module+el9.7.0+40005+715283ec.src.rpm", "php-pecl-redis6-0:6.1.0-2.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-redis6-debuginfo-0:6.1.0-2.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-redis6-debuginfo-0:6.1.0-2.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-redis6-debuginfo-0:6.1.0-2.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-redis6-debuginfo-0:6.1.0-2.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-redis6-debugsource-0:6.1.0-2.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-redis6-debugsource-0:6.1.0-2.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-redis6-debugsource-0:6.1.0-2.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-redis6-debugsource-0:6.1.0-2.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.aarch64.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.ppc64le.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.s390x.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.src.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40005+715283ec.src.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40004+bf50a568.src.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40004+bf50a568.x86_64.rpm","php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.x86_64.rpm", "php-pecl-rrd-0:2.0.3-4.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.aarch64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.ppc64le.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.s390x.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.x86_64.rpm", "php-pecl-rrd-debuginfo-0:2.0.3-4.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.aarch64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.ppc64le.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.s390x.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-rrd-debugsource-0:2.0.3-4.module+el9.7.0+40003+454ed3c4.x86_64.rpm","php-pecl-xdebug3-0:3.3.1-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-xdebug3-0:3.3.1-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-xdebug3-0:3.3.1-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-xdebug3-0:3.3.1-1.module+el9.7.0+40005+715283ec.src.rpm", "php-pecl-xdebug3-0:3.3.1-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-xdebug3-debuginfo-0:3.3.1-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-xdebug3-debuginfo-0:3.3.1-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-xdebug3-debuginfo-0:3.3.1-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-xdebug3-debuginfo-0:3.3.1-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-xdebug3-debugsource-0:3.3.1-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-xdebug3-debugsource-0:3.3.1-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-xdebug3-debugsource-0:3.3.1-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-xdebug3-debugsource-0:3.3.1-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40005+715283ec.src.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40004+bf50a568.src.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-zip-0:1.22.3-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm","php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pecl-zip-debuginfo-0:1.22.3-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40004+bf50a568.aarch64.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40005+715283ec.aarch64.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40005+715283ec.ppc64le.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40004+bf50a568.ppc64le.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40004+bf50a568.s390x.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40005+715283ec.s390x.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40004+bf50a568.x86_64.rpm", "php-pecl-zip-debugsource-0:1.22.3-1.module+el9.7.0+40005+715283ec.x86_64.rpm", "php-pgsql-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-pgsql-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-pgsql-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-pgsql-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-pgsql-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-pgsql-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-pgsql-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-pgsql-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-process-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-process-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-process-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-process-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-process-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-process-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-process-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm","php-process-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-snmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-snmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-snmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-snmp-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-snmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-snmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-snmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-snmp-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-soap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-soap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-soap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-soap-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-soap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-soap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-soap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-soap-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-xml-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-xml-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-xml-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-xml-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm", "php-xml-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.aarch64.rpm", "php-xml-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.ppc64le.rpm", "php-xml-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.s390x.rpm", "php-xml-debuginfo-0:8.3.26-1.module+el9.7.0+40049+21bbec6b.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux php update addresses multiple security issues including NULL Pointer Dereference vulnerabilities and more. Stay secured!. Rocky Linux PHP update. . LinuxSecurity.com Team
Several security issues were fixed in PHP.. =========================================================================Ubuntu Security Notice USN-5902-1 February 28, 2023 php7.2, php7.4, php8.1 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php8.1: HTML-embedded scripting language interpreter - php7.4: HTML-embedded scripting language interpreter - php7.2: HTML-embedded scripting language interpreter Details: It was discovered that PHP incorrectly handled certain invalid Blowfish password hashes. An invalid password hash could possibly allow applications to accept any password as valid, contrary to expectations. (CVE-2023-0567) It was discovered that PHP incorrectly handled resolving long paths. A remote attacker could possibly use this issue to obtain or modify sensitive information. (CVE-2023-0568) It was discovered that PHP incorrectly handled a large number of parts in HTTP form uploads. A remote attacker could possibly use this issue to cause PHP to consume resources, leading to a denial of service. (CVE-2023-0662) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libapache2-mod-php8.1 8.1.7-1ubuntu3.3 php8.1 8.1.7-1ubuntu3.3 php8.1-cgi 8.1.7-1ubuntu3.3 php8.1-cli 8.1.7-1ubuntu3.3 php8.1-fpm 8.1.7-1ubuntu3.3 Ubuntu 22.04 LTS: libapache2-mod-php8.1 8.1.2-1ubuntu2.11 php8.1 8.1.2-1ubuntu2.11 php8.1-cgi 8.1.2-1ubuntu2.11 php8.1-cli 8.1.2-1ubuntu2.11 php8.1-fpm 8.1.2-1ubuntu2.11 Ubuntu 20.04LTS: libapache2-mod-php7.4 7.4.3-4ubuntu2.18 php7.4 7.4.3-4ubuntu2.18 php7.4-cgi 7.4.3-4ubuntu2.18 php7.4-cli 7.4.3-4ubuntu2.18 php7.4-fpm 7.4.3-4ubuntu2.18 Ubuntu 18.04 LTS: libapache2-mod-php7.2 7.2.24-0ubuntu0.18.04.17 php7.2 7.2.24-0ubuntu0.18.04.17 php7.2-cgi 7.2.24-0ubuntu0.18.04.17 php7.2-cli 7.2.24-0ubuntu0.18.04.17 php7.2-fpm 7.2.24-0ubuntu0.18.04.17 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5902-1 CVE-2023-0567, CVE-2023-0568, CVE-2023-0662 Package Information: https://launchpad.net/ubuntu/+source/php8.1/8.1.7-1ubuntu3.3 https://launchpad.net/ubuntu/+source/php8.1/8.1.2-1ubuntu2.11 https://launchpad.net/ubuntu/+source/php7.4/7.4.3-4ubuntu2.18 https://launchpad.net/ubuntu/+source/php7.2/7.2.24-0ubuntu0.18.04.17 . Latest patches for PHP on Ubuntu tackle severe vulnerabilities impacting various versions, safeguarding system reliability and protection.. PHP Security Update, PHP Vulnerabilities, Ubuntu Security Notice. . Severity: Critical. LinuxSecurity.com Team
A remote information leak vulnerability and a remote buffer overflow vulnerability were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4847-1
An information disclosure vulnerability in libjpeg-turbo allow remote attackers to obtain sensitive information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202010-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: libjpeg-turbo: Information disclosure Date: October 20, 2020 Bugs: #727010 ID: 202010-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An information disclosure vulnerability in libjpeg-turbo allow remote attackers to obtain sensitive information. Background ========= libjpeg-turbo is a MMX, SSE, and SSE2 SIMD accelerated JPEG library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libjpeg-turbo < 2.0.4-r1 > = 1.5.3-r3:0/0.1 > = 2.0.4-r1:0/0.2 Description ========== It was discovered that libjpeg-turbo incorrectly handled certain PPM files. Impact ===== A remote attacker could entice a user to open a specially crafted PPM file using an application linked against libjpeg-turbo, possibly allowing attacker to obtain sensitive information. Workaround ========= There is no known workaround at this time. Resolution ========= All libjpeg-turbo 1.x users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v "> =media-libs/libjpeg-turbo-1.5.3-r3:0/0.1" All libjpeg-turbo 2.x users should upgrade to the latest version: # emerge --sync # emerge -a --oneshot -v ">=media-libs/libjpeg-turbo-2.0.4-r1:0/0.2" References ========= [ 1 ] CVE-2020-13790 https://nvd.nist.gov/vuln/detail/CVE-2020-13790 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202010-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2284-1
An update that solves 9 vulnerabilities and has 7 fixes is now available. . SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1533-1 Rating: important References: #1104367 #1110785 #1113769 #1120843 #1120885 #1125580 #1125931 #1131543 #1131587 #1132374 #1132472 #1134848 #1135281 #1136424 #1136446 #1137586 Cross-References: CVE-2018-17972 CVE-2019-11190 CVE-2019-11477 CVE-2019-11478 CVE-2019-11479 CVE-2019-11833 CVE-2019-11884 CVE-2019-3846 CVE-2019-5489 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Module for Public Cloud 12 ______________________________________________________________________________ An update that solves 9 vulnerabilities and has 7 fixes is now available. Description: The SUSE Linux Enterprise 12 SP1 kernel version 3.12.74 was updated to to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-11477: A sequence of SACKs may have been crafted by a remote attacker such that one can trigger an integer overflow, leading to a kernel panic. (bsc#1137586). - CVE-2019-11478: It is possible to send a crafted sequence of SACKs which will fragment the TCP retransmission queue. A remote attacker may be able to further exploit the fragmented queue to cause an expensive linked-list walk for subsequent SACKs received for that same TCP connection. - CVE-2019-11479: It was possible to send a crafted sequence of SACKs which will fragment the RACK send map. A remote attacker may be able to further exploit the fragmented send map to cause an expensive linked-list walk for subsequent SACKsreceived for that same TCP connection. This would have resulted in excess resource consumption due to low mss values. - CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. (bnc#1136424) - CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server. (bnc#1120843) - CVE-2019-11833: fs/ext4/extents.c in the Linux kernel did not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem. (bnc#1135281) - CVE-2019-11190: The Linux kernel allowed local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading /proc/pid/stat. (bnc#1131543) - CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel allowed a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character. (bnc#1134848) - CVE-2018-17972: An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel It did not ensure that only root may inspect the kernel stack of an arbitrary task, allowing a local attacker to exploit racy stack unwinding and leak kernel task stack contents.(bnc#1110785) The following non-security bugs were fixed: - kabi: drop LINUX_MIB_TCPWQUEUETOOBIG snmp counter (bsc#1137586). - kvm: x86: Fix the duplicated failure path handling in vmx_init (bsc#1104367). - lib: add "on"/"off" support to strtobool (bsc#1125931). - powerpc/tm: Add commandline option to disable hardware transactional memory (bsc#1125580). - powerpc/tm: Add TM Unavailable Exception (bsc#1125580). - powerpc/tm: Flip the HTM switch default to disabled (bsc#1125580). - powerpc/vdso32: fix CLOCK_MONOTONIC on PPC64 (bsc#1131587). - powerpc/vdso64: Fix CLOCK_MONOTONIC inconsistencies across Y2038 (bsc#1131587). - tcp: add tcp_min_snd_mss sysctl (bsc#1137586). - tcp: enforce tcp_min_snd_mss in tcp_mtu_probing() (bsc#1137586). - tcp: limit payload size of sacked skbs (bsc#1137586). - tcp: tcp_fragment() should apply sane memory limits (bsc#1137586). Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-1533=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1533=1 - SUSE Linux Enterprise Module for Public Cloud 12: zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2019-1533=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): kernel-devel-3.12.74-60.64.115.1 kernel-macros-3.12.74-60.64.115.1 kernel-source-3.12.74-60.64.115.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kernel-default-3.12.74-60.64.115.1 kernel-default-base-3.12.74-60.64.115.1 kernel-default-base-debuginfo-3.12.74-60.64.115.1 kernel-default-debuginfo-3.12.74-60.64.115.1 kernel-default-debugsource-3.12.74-60.64.115.1 kernel-default-devel-3.12.74-60.64.115.1 kernel-syms-3.12.74-60.64.115.1 kernel-xen-3.12.74-60.64.115.1 kernel-xen-base-3.12.74-60.64.115.1 kernel-xen-base-debuginfo-3.12.74-60.64.115.1 kernel-xen-debuginfo-3.12.74-60.64.115.1 kernel-xen-debugsource-3.12.74-60.64.115.1 kernel-xen-devel-3.12.74-60.64.115.1 kgraft-patch-3_12_74-60_64_115-default-1-2.5.1 kgraft-patch-3_12_74-60_64_115-xen-1-2.5.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): kernel-default-3.12.74-60.64.115.1 kernel-default-base-3.12.74-60.64.115.1 kernel-default-base-debuginfo-3.12.74-60.64.115.1 kernel-default-debuginfo-3.12.74-60.64.115.1 kernel-default-debugsource-3.12.74-60.64.115.1 kernel-default-devel-3.12.74-60.64.115.1 kernel-syms-3.12.74-60.64.115.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kernel-xen-3.12.74-60.64.115.1 kernel-xen-base-3.12.74-60.64.115.1 kernel-xen-base-debuginfo-3.12.74-60.64.115.1 kernel-xen-debuginfo-3.12.74-60.64.115.1 kernel-xen-debugsource-3.12.74-60.64.115.1 kernel-xen-devel-3.12.74-60.64.115.1 kgraft-patch-3_12_74-60_64_115-default-1-2.5.1 kgraft-patch-3_12_74-60_64_115-xen-1-2.5.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): kernel-devel-3.12.74-60.64.115.1 kernel-macros-3.12.74-60.64.115.1 kernel-source-3.12.74-60.64.115.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x): kernel-default-man-3.12.74-60.64.115.1 - SUSE Linux Enterprise Module for Public Cloud 12 (x86_64): kernel-ec2-3.12.74-60.64.115.1 kernel-ec2-debuginfo-3.12.74-60.64.115.1 kernel-ec2-debugsource-3.12.74-60.64.115.1 kernel-ec2-devel-3.12.74-60.64.115.1 kernel-ec2-extra-3.12.74-60.64.115.1 kernel-ec2-extra-debuginfo-3.12.74-60.64.115.1 References: https://www.suse.com/security/cve/CVE-2018-17972.html https://www.suse.com/security/cve/CVE-2019-11190.html https://www.suse.com/security/cve/CVE-2019-11477.html https://www.suse.com/security/cve/CVE-2019-11478.html https://www.suse.com/security/cve/CVE-2019-11479.html https://www.suse.com/security/cve/CVE-2019-11833.html https://www.suse.com/security/cve/CVE-2019-11884.html https://www.suse.com/security/cve/CVE-2019-3846.html https://www.suse.com/security/cve/CVE-2019-5489.html https://bugzilla.suse.com/1104367 https://bugzilla.suse.com/1110785 https://bugzilla.suse.com/1113769 https://bugzilla.suse.com/1120843 https://bugzilla.suse.com/1120885 https://bugzilla.suse.com/1125580 https://bugzilla.suse.com/1125931 https://bugzilla.suse.com/1131543 https://bugzilla.suse.com/1131587 https://bugzilla.suse.com/1132374 https://bugzilla.suse.com/1132472 https://bugzilla.suse.com/1134848 https://bugzilla.suse.com/1135281 https://bugzilla.suse.com/1136424 https://bugzilla.suse.com/1136446 https://bugzilla.suse.com/1137586 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.