Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u5.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6213-1
Two security issues were discovered in Incus, a system container and virtual machine manager, which could result in restriction bypass or privilege escalation. For the stable distribution (trixie), these problems have been fixed in version 6.0.4-2+deb13u6.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6212-1
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, cross-site scripting or restriction bypass. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5901-1
AppArmor restrictions could be bypassed for rules allowing mount operations. ========================================================================== Ubuntu Security Notice USN-7035-1 September 25, 2024 apparmor vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: AppArmor restrictions could be bypassed for rules allowing mount operations Software Description: - apparmor: Linux security system Details: It was discovered that the AppArmor policy compiler incorrectly generated looser restrictions than expected for rules allowing mount operations. A local attacker could possibly use this to bypass AppArmor restrictions in applications where some mount operations were permitted. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS apparmor 3.0.4-2ubuntu2.4 Ubuntu 20.04 LTS apparmor 2.13.3-7ubuntu5.4 In general, a standard system update will make all the necessary changes. After this update, applications confined by policies with mount operations restrictions may need to have the rules updated. References: https://ubuntu.com/security/notices/USN-7035-1 https://bugs.launchpad.net/apparmor/+bug/1597017 CVE-2016-1585 Package Information: https://launchpad.net/ubuntu/+source/apparmor/3.0.4-2ubuntu2.4 . Ubuntu Security Update USN-7036-1 addresses a potential kernel flaw and outlines critical measures for safeguarding system integrity.. apparmor update, ubuntu advisory, apparmor restrictions, security instructions. . Severity: Critical. LinuxSecurity.com Team
Three security issues were discovered in php-svg-lib, a PHP library to read, parse and export to PDF SVG files, which could result in denial of service, restriction bypass or the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5642-1
This update for xrdp fixes the following issues: CVE-2023-40184: Fixed restriction bypass via improper session handling (bsc#1214805).. # Security update for xrdp Announcement ID: SUSE-SU-2023:3830-1 Rating: moderate References: * #1214805 Cross-References: * CVE-2023-40184 CVSS scores: * CVE-2023-40184 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2023-40184 ( NVD ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for xrdp fixes the following issues: * CVE-2023-40184: Fixed restriction bypass via improper session handling (bsc#1214805). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3830=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3830=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3830=1 * Basesystem Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Basesystem-15-SP5-2023-3830=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3830=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3830=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3830=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 *librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Proxy 4.2 (x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * xrdp-debugsource-0.9.13.1-150200.4.24.1 * libpainter0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-devel-0.9.13.1-150200.4.24.1 * libpainter0-0.9.13.1-150200.4.24.1 * librfxencode0-debuginfo-0.9.13.1-150200.4.24.1 * xrdp-0.9.13.1-150200.4.24.1 * librfxencode0-0.9.13.1-150200.4.24.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40184.html * https://bugzilla.suse.com/show_bug.cgi?id=1214805 . A critical patch for xrdp focusing on mitigating security loopholes related to access control on openSUSE platforms. Discover further details now!. xrdp Security Update, openSUSE Advisory, restriction bypass fix. . Severity: Important. LinuxSecurity.com Team
runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3322-1
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 30 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1949-1 Rating: important References: #1199602 #1199834 Cross-References: CVE-2022-30594 CVSS scores: CVE-2022-30594 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-30594 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP1 SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Server 15-SP1 SUSE Linux Enterprise Server for SAP Applications 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for the Linux Kernel 4.12.14-150100_197_111 fixes several issues. The following security issue was fixed: - CVE-2022-30594: Fixed restriction bypass on setting the PT_SUSPEND_SECCOMP flag (bnc#1199602). - Add missing module_mutex lock to module notifier for previous live patches (bsc#1199834). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2022-1949=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-150100_197_111-default-3-150100.2.2 References: https://www.suse.com/security/cve/CVE-2022-30594.html https://bugzilla.suse.com/1199602 https://bugzilla.suse.com/1199834 . SUSE Security Update for Linux Kernel tackles urgent vulnerabilities in Live Patch 30 for SLE 15 SP2 alongside suggested actions.. Linux Kernel, SUSE Security Update, Live Patching, Kernel Security. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.