Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 40: 2024-632b468c59 Critical: zlib-rs stack overflow

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-632b468c59 2024-11-29 03:47:35.523146+00:00 -------------------------------------------------------------------------------- Name : rust-rustls Product : Fedora 40 Version : 0.23.17 Release : 1.fc40 URL : https://crates.io/crates/rustls Summary : Modern TLS library written in Rust Description : Rustls is a modern TLS library written in Rust. -------------------------------------------------------------------------------- Update Information: Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and rustls is the only dependent package of zlib-rs. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 20 2024 Benjamin A. Beasley - 0.23.17-1 - Update to version 0.23.17; Fixes RHBZ#2326682 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2326413 - CVE-2024-11249 rust-zlib-rs: zlib-rs stack overflow during decompression with malicious input [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2326413 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-632b468c59' at the command line. For more information,refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The recent update to Fedora's rust-rustls crate resolves significant stack overflow vulnerabilities linked to zlib-rs. Keep up-to-date on essential security patches.. rustls update, Fedora security, zlib-rs stack overflow, software patch, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 29, 2024 Critical Fedora
89

Fedora 41: FEDORA-2024-41e6e2fc74 moderate: zlib-rs stack overflow

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-41e6e2fc74 2024-11-29 03:29:16.747934+00:00 -------------------------------------------------------------------------------- Name : rust-zlib-rs Product : Fedora 41 Version : 0.4.0 Release : 1.fc41 URL : https://crates.io/crates/zlib-rs Summary : Memory-safe zlib implementation written in rust Description : A memory-safe zlib implementation written in rust. -------------------------------------------------------------------------------- Update Information: Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and rustls is the only dependent package of zlib-rs. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 20 2024 Benjamin A. Beasley - 0.4.0-1 - Update to version 0.4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2326414 - CVE-2024-11249 rust-zlib-rs: zlib-rs stack overflow during decompression with malicious input [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2326414 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-41e6e2fc74' at the command line. For more information, refer tothe dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Notice issued for Fedora 41 concerning rust-zlib-rs modifications aimed at reducing the potential for stack overflow vulnerabilities triggered by harmful inputs.. rust-zlib-rs updates, Fedora security, rust crate versioning, memory safety in Rust. . LinuxSecurity.com Team

Calendar 2 Nov 29, 2024 Fedora
89

Fedora 39 FEDORA-2024-ff98facbc6 critical: DoS in rust-hyper-rustls

Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ff98facbc6 2024-10-19 01:18:49.824560 -------------------------------------------------------------------------------- Name : rust-hyper-rustls Product : Fedora 39 Version : 0.27.3 Release : 1.fc39 URL : https://crates.io/crates/hyper-rustls Summary : Rustls+hyper integration for pure rust HTTPS Description : Rustls+hyper integration for pure rust HTTPS. -------------------------------------------------------------------------------- Update Information: Update the hyper-rustls crate to version 0.27.3. Update the reqwest crate to version 0.12.8. Update the rustls-native-certs crate to version 0.8.0 and add a compat package for version 0.7. Update the tonic, tonic-build, and tonic-types crates to version 0.12.3. Update the tower crate to version 0.5.1 and add a compat package for version 0.4. Update the tower-http crate to version 0.6.1 and add a compat package for version 0.5. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 10 2024 Fabio Valentini - 0.27.3-1 - Update to version 0.27.3; Fixes RHBZ#2309673 * Fri Jul 19 2024 Fedora Release Engineering - 0.27.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2316020 - CVE-2024-47609 rust-tonic: Remotely exploitable DoS in Tonic `

Calendar 2 Oct 19, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here