Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
217

Oracle Linux 9: ELSA-2024-10939 Moderate: kernel update details

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10939 http://linux.oracle.com/errata/ELSA-2024-10939.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.4.0-503.16.1.el9_5.x86_64.rpm kernel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-abi-stablelists-5.14.0-503.16.1.el9_5.noarch.rpm kernel-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-devel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-devel-matched-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-modules-extra-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-debug-uki-virt-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-devel-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-devel-matched-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-doc-5.14.0-503.16.1.el9_5.noarch.rpm kernel-headers-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-core-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-modules-extra-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-libs-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-uki-virt-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-uki-virt-addons-5.14.0-503.16.1.el9_5.x86_64.rpm perf-5.14.0-503.16.1.el9_5.x86_64.rpm python3-perf-5.14.0-503.16.1.el9_5.x86_64.rpm rtla-5.14.0-503.16.1.el9_5.x86_64.rpm rv-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-cross-headers-5.14.0-503.16.1.el9_5.x86_64.rpm kernel-tools-libs-devel-5.14.0-503.16.1.el9_5.x86_64.rpm libperf-5.14.0-503.16.1.el9_5.x86_64.rpm aarch64: bpftool-7.4.0-503.16.1.el9_5.aarch64.rpm kernel-headers-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-libs-5.14.0-503.16.1.el9_5.aarch64.rpm perf-5.14.0-503.16.1.el9_5.aarch64.rpm python3-perf-5.14.0-503.16.1.el9_5.aarch64.rpm rtla-5.14.0-503.16.1.el9_5.aarch64.rpm rv-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-cross-headers-5.14.0-503.16.1.el9_5.aarch64.rpm kernel-tools-libs-devel-5.14.0-503.16.1.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-5.14.0-503.16.1.el9_5.src.rpm Related CVEs: CVE-2024-26615 CVE-2024-43854 CVE-2024-44994 CVE-2024-45018 CVE-2024-46695 CVE-2024-49949 CVE-2024-50251 Description of changes: [5.14.0-503.16.1.el9_5.OL9] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64

Calendar%202 Dec 13, 2024 Oracle
217

Oracle8 ELSA-2024-8846: Critical Updates for Container Tools

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8846 http://linux.oracle.com/errata/ELSA-2024-8846.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.x86_64.rpm buildah-tests-1.33.8-4.module+el8.10.0+90429+ee702c5c.x86_64.rpm cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm crit-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-devel-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm criu-libs-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90429+ee702c5c.x86_64.rpm netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-catatonit-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-docker-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.noarch.rpm podman-gvproxy-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-plugins-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-remote-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm podman-tests-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.x86_64.rpm python3-criu-3.18-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm python3-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.x86_64.rpm skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.x86_64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90429+ee702c5c.x86_64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.x86_64.rpm aarch64: aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.aarch64.rpm buildah-tests-1.33.8-4.module+el8.10.0+90429+ee702c5c.aarch64.rpm cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.noarch.rpm conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm crit-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-devel-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm criu-libs-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm libslirp-devel-4.4.0-2.module+el8.10.0+90429+ee702c5c.aarch64.rpm netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-catatonit-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-docker-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.noarch.rpm podman-gvproxy-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-plugins-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-remote-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm podman-tests-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.aarch64.rpm python3-criu-3.18-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm python3-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.noarch.rpm runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.aarch64.rpm skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.aarch64.rpm skopeo-tests-1.14.5-3.module+el8.10.0+90429+ee702c5c.aarch64.rpm slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//aardvark-dns-1.10.1-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//buildah-1.33.8-4.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//cockpit-podman-84.1-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//conmon-2.1.10-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containernetworking-plugins-1.4.0-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//containers-common-1-82.0.1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//container-selinux-2.229.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//criu-3.18-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//crun-1.14.3-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//fuse-overlayfs-1.13-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//libslirp-4.4.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//netavark-1.10.3-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//oci-seccomp-bpf-hook-1.2.10-1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//podman-4.9.4-15.0.1.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python-podman-4.9.0-2.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//runc-1.1.12-5.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//skopeo-1.14.5-3.module+el8.10.0+90429+ee702c5c.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//slirp4netns-1.2.3-1.module+el8.10.0+90429+ee702c5c.src.rpm Related CVEs: CVE-2024-9341 CVE-2024-9407 CVE-2024-9675 Description of changes: aardvark-dns buildah cockpit-podman conmon containernetworking-plugins containers-common [1-82.0.1] - Updated removed references [Orabug: 33473101] (Alex Burmashev) - Adjust registries.conf (Nikita Gerasimov) - removereferences to RedHat registry (Nikita Gerasimov) container-selinux criu crun fuse-overlayfs libslirp netavark oci-seccomp-bpf-hook podman [4:4.9.4-15.0.1] - Fixes issue of container created in cgroupv2 not start in cgroupv1 [Orabug: 36136813] - Fixes container memory limit not set after host is rebooted with cgroupv2 [Orabug: 36136802] - Fixes issue of podman execvp error while using podmansh [Orabug: 36756665] [4:4.9.4-15] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/235a22c) - Resolves: RHEL-61837 [4:4.9.4-14] - update to the latest content of https://github.com/containers/podman/tree/v4.9-rhel (https://github.com/containers/podman/commit/6cf9920) - Resolves: RHEL-60962 python-podman runc skopeo slirp4netns _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . The updates for container tools in Oracle Linux introduce critical security enhancements. Delve into the newest RPM updates and understand their implications.. Oracle Linux Updates, Security Patch RPMs, Container Tool Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 08, 2024 Critical Oracle
217

Oracle Linux 9 ELSA-2024-1310 Moderate: .NET 8.0 Runtime Update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1310 https://linux.oracle.com/errata/ELSA-2024-1310.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm aspnetcore-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm aspnetcore-targeting-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-apphost-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-host-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-hostfxr-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-runtime-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-sdk-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-sdk-dbg-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-targeting-pack-8.0-8.0.3-2.0.1.el9_3.x86_64.rpm dotnet-templates-8.0-8.0.103-2.0.1.el9_3.x86_64.rpm netstandard-targeting-pack-2.1-8.0.103-2.0.1.el9_3.x86_64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.103-2.0.1.el9_3.x86_64.rpm aarch64: aspnetcore-runtime-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm aspnetcore-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm aspnetcore-targeting-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-apphost-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-host-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-hostfxr-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-runtime-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-runtime-dbg-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-sdk-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-sdk-dbg-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-targeting-pack-8.0-8.0.3-2.0.1.el9_3.aarch64.rpm dotnet-templates-8.0-8.0.103-2.0.1.el9_3.aarch64.rpm netstandard-targeting-pack-2.1-8.0.103-2.0.1.el9_3.aarch64.rpm dotnet-sdk-8.0-source-built-artifacts-8.0.103-2.0.1.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//dotnet8.0-8.0.103-2.0.1.el9_3.src.rpm Related CVEs: CVE-2024-21392 Description of changes: [- 8.0.103-2.0.1] - Update to .NET SDK 8.0.103 and Runtime 8.0.3 -Disable checking the signature of the last certificate in a chain if the certificate is supposedly self-signed. - Resolves: RHEL-25254 - Backport MSBuild locale fix - Resolves: RHEL-23936 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Alert ELSA-2024-1310 details essential updates pertaining to .NET 8.0, addressing several issues categorized with moderate severity.. Oracle Linux Updates, .NET Security Fix, Runtime SDK Update. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2024 Oracle
217

Oracle Linux 8 ELSA-2024-12070 Critical: Kernel Vulnerability Patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12069 https://linux.oracle.com/errata/ELSA-2024-12069.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-doc-4.18.0-513.11.0.1.el8_9.noarch.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.x86_64.rpm perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-abi-stablelists-4.18.0-513.11.0.1.el8_9.noarch.rpm aarch64: bpftool-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.aarch64.rpm perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//kernel-4.18.0-513.11.0.1.el8_9.src.rpm Related CVEs: CVE-2023-2162 CVE-2023-4622 CVE-2023-42753 Description of changes: [4.18.0-513.11.1.0.1.el8_9.OL8] - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress{CVE-2023-2162} - af_unix: Fix null-ptr-deref in unix_stream_sendpage() {CVE-2023-4622} - netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet {CVE-2023-42753} _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Bulletin: Urgent kernel patch addresses multiple security flaws. Acquire the latest RPMs now!. Kernel Security, Oracle Linux, Security Advisory, RPM Updates, Access Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 13, 2024 Critical Oracle
217

Oracle Linux 9 ELSA-2023-7749 critical: kernel security update

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7749 https://linux.oracle.com/errata/ELSA-2023-7749.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bpftool-7.2.0-362.13.1.el9_3.x86_64.rpm kernel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-abi-stablelists-5.14.0-362.13.1.el9_3.noarch.rpm kernel-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-devel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-devel-matched-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-debug-modules-extra-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-devel-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-devel-matched-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-doc-5.14.0-362.13.1.el9_3.noarch.rpm kernel-headers-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-core-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-modules-extra-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-libs-5.14.0-362.13.1.el9_3.x86_64.rpm perf-5.14.0-362.13.1.el9_3.x86_64.rpm python3-perf-5.14.0-362.13.1.el9_3.x86_64.rpm rtla-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-cross-headers-5.14.0-362.13.1.el9_3.x86_64.rpm kernel-tools-libs-devel-5.14.0-362.13.1.el9_3.x86_64.rpm aarch64: bpftool-7.2.0-362.13.1.el9_3.aarch64.rpm kernel-headers-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-libs-5.14.0-362.13.1.el9_3.aarch64.rpm perf-5.14.0-362.13.1.el9_3.aarch64.rpm python3-perf-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-cross-headers-5.14.0-362.13.1.el9_3.aarch64.rpm kernel-tools-libs-devel-5.14.0-362.13.1.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//kernel-5.14.0-362.13.1.el9_3.src.rpm Related CVEs: CVE-2023-1192 CVE-2023-5345 CVE-2023-20569 CVE-2023-45871 Description of changes: [5.14.0-362.13.1.el9_3.OL9] - x86/retpoline: Document some thunk handling aspects (Borislav Petkov) {CVE-2023-20569} - objtool: Fix return thunk patching in retpolines (Josh Poimboeuf){CVE-2023-20569} - x86/srso: Remove unnecessary semicolon (Yang Li) {CVE-2023-20569} - x86/calldepth: Rename __x86_return_skl() to call_depth_return_thunk() (Josh Poimboeuf) {CVE-2023-20569} - x86/nospec: Refactor UNTRAIN_RET[_*] (Josh Poimboeuf) {CVE-2023-20569} - x86/rethunk: Use SYM_CODE_START[_LOCAL]_NOALIGN macros (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Disentangle rethunk-dependent options (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Move retbleed IBPB check into existing 'has_microcode' code block (Josh Poimboeuf) {CVE-2023-20569} - x86/bugs: Remove default case for fully switched enums (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Remove 'pred_cmd' label (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Unexport untraining functions (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Improve i-cache locality for alias mitigation (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix unret validation dependencies (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix vulnerability reporting for missing microcode (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Print mitigation for retbleed IBPB case (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Print actual mitigation if requested mitigation isn't possible (Josh Poimboeuf) [RHEL-8594] {CVE-2023-20569} - x86/srso: Fix SBPB enablement for (possible) future fixed HW (Josh Poimboeuf) {CVE-2023-20569} - x86,static_call: Fix static-call vs return-thunk (Peter Zijlstra) {CVE-2023-20569} - x86/alternatives: Remove faulty optimization (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix SBPB enablement for spec_rstack_overflow=off (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Don't probe microcode in a guest (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Set CPUID feature bits independently of bug or mitigation status (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Fix srso_show_state() side effect (Josh Poimboeuf) {CVE-2023-20569} - x86/cpu: Fix amd_check_microcode() declaration (Arnd Bergmann) {CVE-2023-20569} - x86/srso: Correct the mitigation status when SMT is disabled (BorislavPetkov) {CVE-2023-20569} - x86/static_call: Fix __static_call_fixup() (Peter Zijlstra) {CVE-2023-20569} - objtool/x86: Fixup frame-pointer vs rethunk (Peter Zijlstra) {CVE-2023-20569} - x86/srso: Explain the untraining sequences a bit more (Borislav Petkov) {CVE-2023-20569} - x86/cpu/kvm: Provide UNTRAIN_RET_VM (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Cleanup the untrain mess (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Rename srso_(.*)_alias to srso_alias_\1 (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Rename original retbleed methods (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Clean up SRSO return thunk mess (Peter Zijlstra) {CVE-2023-20569} - x86/alternative: Make custom return thunk unconditional (Peter Zijlstra) {CVE-2023-20569} - objtool/x86: Fix SRSO mess (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Fix up srso_safe_ret() and __x86_return_thunk() (Peter Zijlstra) {CVE-2023-20569} - x86/cpu: Fix __x86_return_thunk symbol type (Peter Zijlstra) {CVE-2023-20569} - x86/retpoline,kprobes: Skip optprobe check for indirect jumps with retpolines and IBT (Petr Pavlu) {CVE-2023-20569} - x86/retpoline,kprobes: Fix position of thunk sections with CONFIG_LTO_CLANG (Petr Pavlu) {CVE-2023-20569} - x86/srso: Disable the mitigation on unaffected configurations (Borislav Petkov) {CVE-2023-20569} - x86/CPU/AMD: Fix the DIV(0) initial fix attempt (Borislav Petkov) {CVE-2023-20588} - x86/retpoline: Don't clobber RFLAGS during srso_safe_ret() (Sean Christopherson) {CVE-2023-20569} - x86/cpu/amd: Enable Zenbleed fix for AMD Custom APU 0405 (Cristian Ciocaltea) {CVE-2023-20593} - driver core: cpu: Fix the fallback cpu_show_gds() name (Borislav Petkov) {CVE-2023-20569} - x86: Move gds_ucode_mitigated() declaration to header (Arnd Bergmann) {CVE-2023-20569} - x86/speculation: Add cpu_show_gds() prototype (Arnd Bergmann) {CVE-2023-20569} - driver core: cpu: Make cpu_show_not_affected() static (Borislav Petkov) {CVE-2023-20569} - x86/srso: Fix build breakage with the LLVM linker (Nick Desaulniers) {CVE-2023-20569} -Documentation/srso: Document IBPB aspect and fix formatting (Borislav Petkov) {CVE-2023-20569} - driver core: cpu: Unify redundant silly stubs (Borislav Petkov) {CVE-2023-20569} - Documentation/hw-vuln: Unify filename specification in index (Borislav Petkov) {CVE-2023-20569} - x86/CPU/AMD: Do not leak quotient data after a division by 0 (Borislav Petkov) {CVE-2023-20588} - x86/srso: Tie SBPB bit setting to microcode patch detection (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add a forgotten NOENDBR annotation (Borislav Petkov) {CVE-2023-20569} - x86/srso: Fix return thunks in generated code (Josh Poimboeuf) {CVE-2023-20569} - x86/srso: Add IBPB on VMEXIT (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add IBPB (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add SRSO_NO support (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add IBPB_BRTYPE support (Borislav Petkov) {CVE-2023-20569} - redhat/configs/x86: Enable CONFIG_CPU_SRSO (Borislav Petkov) {CVE-2023-20569} - x86/srso: Add a Speculative RAS Overflow mitigation (Borislav Petkov) {CVE-2023-20569} - x86/retbleed: Add __x86_return_thunk alignment checks (Borislav Petkov) {CVE-2023-20569} - x86/retbleed: Fix return thunk alignment (Borislav Petkov) {CVE-2023-20569} - x86/alternative: Optimize returns patching (Borislav Petkov) {CVE-2023-20569} - x86,objtool: Separate unret validation from unwind hints (Josh Poimboeuf) {CVE-2023-20569} - objtool: Add objtool_types.h (Josh Poimboeuf) {CVE-2023-20569} - objtool: Union instruction::{call_dest,jump_table} (Peter Zijlstra) {CVE-2023-20569} - x86/kprobes: Fix optprobe optimization check with CONFIG_RETHUNK (Peter Zijlstra) {CVE-2023-20569} - objtool: Fix SEGFAULT (Christophe Leroy) {CVE-2023-20569} - vmlinux.lds.h: add BOUNDED_SECTION* macros (Jim Cromie) {CVE-2023-20569} _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Important Oracle Linux 9 kernel security patch addresses several vulnerabilities, introducesenhancements to RPM, and provides detailed severity information.. Oracle Linux Security, Kernel Update, RPM Package, Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 02, 2024 Critical Oracle
217

Oracle Linux 8 ELSA-2023-0113 Moderate: PostgreSQL CVE-2022-2625 Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-0113 https://linux.oracle.com/errata/ELSA-2023-0113.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: postgresql-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-contrib-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-docs-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-plperl-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-plpython3-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-pltcl-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-server-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-server-devel-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-static-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-test-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-test-rpm-macros-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-upgrade-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm postgresql-upgrade-devel-10.23-1.module+el8.7.0+20896+16771be9.x86_64.rpm aarch64: postgresql-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-contrib-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-docs-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-plperl-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-plpython3-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-pltcl-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-server-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-server-devel-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-static-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-test-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-test-rpm-macros-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-upgrade-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm postgresql-upgrade-devel-10.23-1.module+el8.7.0+20896+16771be9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/postgresql-10.23-1.module+el8.7.0+20896+16771be9.src.rpm Related CVEs: CVE-2022-2625 Description of changes: [10.23-1] - Fix CVE-2022-2625 - Resolves: #2143167 - Rebase to10.23 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Enterprise Linux 8 rolls out an important security patch for MariaDB addressing CVE-2022-2676 through updated RPM distributions.. PostgreSQL Update, Oracle Linux, Security Advisory, RPM Packages. . LinuxSecurity.com Team

Calendar%202 Jan 17, 2023 Oracle
217

Oracle Linux 7 ELSA-2022-9469 Important Grub2 Security Update

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9469 https://linux.oracle.com/errata/ELSA-2022-9469.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: grub2-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-common-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-efi-ia32-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-ia32-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-efi-x64-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-x64-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-pc-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-pc-modules-2.02-0.87.0.21.el7_9.9.noarch.rpm grub2-tools-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-tools-extra-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-tools-minimal-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-ia32-cdboot-2.02-0.87.0.21.el7_9.9.x86_64.rpm grub2-efi-x64-cdboot-2.02-0.87.0.21.el7_9.9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/grub2-2.02-0.87.0.21.el7_9.9.src.rpm Related CVEs: CVE-2021-3695 CVE-2021-3696 CVE-2021-3697 CVE-2022-28733 CVE-2022-28734 CVE-2022-28735 CVE-2022-28736 Description of changes: [2.02-0.87.0.21.el7_9.9] - Add CVE-2022-28736 to the list [JIRA: OLDIS-16371] [2.02-0.87.0.19.el7_9.9] - Fix: CVE-2021-3695, CVE-2021-3696, CVE-2021-3697, CVE-2022-28733, CVE-2022-28734, CVE-2022-28735 [JIRA: OLDIS-16371] - Various coverity fixes [JIRA: OLDIS-16371] - bump SBAT generation [JIRA: OLDIS-16371] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Fedora Linux 35 Grub2 Critical Vulnerability Patch for ELSA-2022-9480 aimed at enhancing system protection and robustness.. Oracle Linux, Grub2 Update, Security Advisory, System Security, RPM Packages. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 07, 2022 Important Oracle
217

Oracle Linux 5: ELSA-2013-2542 Critical Kernel Security Fixes

The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2013-2542 The following updated rpms for Oracle Linux 5 have been uploaded to the Unbreakable Linux Network: i386: kernel-uek-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-debug-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-debug-devel-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-headers-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-devel-2.6.32-400.29.3.el5uek.i686.rpm kernel-uek-doc-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-firmware-2.6.32-400.29.3.el5uek.noarch.rpm ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.i686.rpm ofa-2.6.32-400.29.3.el5uekdebug-1.5.1-4.0.58.i686.rpm mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.i686.rpm mlnx_en-2.6.32-400.29.3.el5uekdebug-1.5.7-2.i686.rpm x86_64: kernel-uek-firmware-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-doc-2.6.32-400.29.3.el5uek.noarch.rpm kernel-uek-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-headers-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-devel-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-debug-devel-2.6.32-400.29.3.el5uek.x86_64.rpm kernel-uek-debug-2.6.32-400.29.3.el5uek.x86_64.rpm ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.x86_64.rpm ofa-2.6.32-400.29.3.el5uekdebug-1.5.1-4.0.58.x86_64.rpm mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.x86_64.rpm mlnx_en-2.6.32-400.29.3.el5uekdebug-1.5.7-2.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol5/SRPMS-updates/kernel-uek-2.6.32-400.29.3.el5uek.src.rpm https://oss.oracle.com:443/ol5/SRPMS-updates/ofa-2.6.32-400.29.3.el5uek-1.5.1-4.0.58.src.rpm https://oss.oracle.com:443/ol5/SRPMS-updates/mlnx_en-2.6.32-400.29.3.el5uek-1.5.7-2.src.rpm Description of changes: kernel-uek [2.6.32-400.29.3.el5uek] - block: do not pass disk names as format strings (Jerry Snitselaar) [Orabug: 17230124] {CVE-2013-2851} - af_key: initialize satype in key_notify_policy_flush() (Nicolas Dichtel) [Orabug: 17370765] {CVE-2013-2237} - Bluetooth: L2CAP - Fix info leak via getsockname() (Mathias Krause) [Orabug: 17371054]{CVE-2012-6544} - Bluetooth: HCI - Fix info leak in getsockopt(HCI_FILTER) (Mathias Krause) [Orabug: 17371072] {CVE-2012-6544} - ipv6: ip6_sk_dst_check() must not assume ipv6 dst (Eric Dumazet) [Orabug: 17371079] {CVE-2013-2232} - sctp: Use correct sideffect command in duplicate cookie handling (Vlad Yasevich) [Orabug: 17371121] {CVE-2013-2206} - sctp: deal with multiple COOKIE_ECHO chunks (Max Matveev) [Orabug: 17372129] {CVE-2013-2206} . Key revisions for Oracle Linux 5 rpms tackling major security vulnerabilities. Vital kernel improvements incorporated.. Oracle Linux, Kernel Updates, Security Issues, RPM Packages. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 29, 2013 Critical Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200