Seccomp jail improvements (CVE-2023-43641). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-40044895ce 2023-10-11 01:33:15.490419 -------------------------------------------------------------------------------- Name : tracker-miners Product : Fedora 37 Version : 3.4.5 Release : 1.fc37 URL : Summary : Tracker miners and metadata extractors Description : Tracker is a powerful desktop-neutral first class object database, tag/metadata database and search tool. This package contains various miners and metadata extractors for tracker. -------------------------------------------------------------------------------- Update Information: Seccomp jail improvements (CVE-2023-43641) -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Kalev Lember - 3.4.5-1 - Update to 3.4.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2243096 - tracker-miners: sandbox escape https://bugzilla.redhat.com/show_bug.cgi?id=2243096 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-40044895ce' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for webkit2gtk3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3768-1 Rating: important References: #1191937 Cross-References: CVE-2021-42762 CVSS scores: CVE-2021-42762 (NVD) : 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVE-2021-42762 (SUSE): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for webkit2gtk3 fixes the following issues: - CVE-2021-42762: Updated seccomp rules with latest changes from flatpak (bsc#1191937). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-3768=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-3768=1 - SUSEOpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-3768=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-3768=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3768=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-3768=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-3768=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-3768=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-3768=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-3768=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-3768=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-3768=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-3768=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE OpenStack Cloud Crowbar 9 (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE OpenStack Cloud Crowbar 8 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE OpenStack Cloud 9 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE OpenStack Cloud 9 (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE OpenStack Cloud 8 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE OpenStack Cloud 8 (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 webkit2gtk3-devel-2.32.4-2.74.5 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server for SAP 12-SP4 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP5 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 webkit2gtk3-devel-2.32.4-2.74.5 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 - HPE Helion Openstack 8 (x86_64): libjavascriptcoregtk-4_0-18-2.32.4-2.74.5 libjavascriptcoregtk-4_0-18-debuginfo-2.32.4-2.74.5 libwebkit2gtk-4_0-37-2.32.4-2.74.5 libwebkit2gtk-4_0-37-debuginfo-2.32.4-2.74.5 typelib-1_0-JavaScriptCore-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2-4_0-2.32.4-2.74.5 typelib-1_0-WebKit2WebExtension-4_0-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-2.32.4-2.74.5 webkit2gtk-4_0-injected-bundles-debuginfo-2.32.4-2.74.5 webkit2gtk3-debugsource-2.32.4-2.74.5 - HPE Helion Openstack 8 (noarch): libwebkit2gtk3-lang-2.32.4-2.74.5 References: https://www.suse.com/security/cve/CVE-2021-42762.html https://bugzilla.suse.com/1191937 . SUSE Security Alert: Urgent webkit2gtk3 patch released for various distributions and versions. Take action now!. SUSE Update, Webkit2gtk3, Security Fix, Linux Patches. . Severity: Important. LinuxSecurity.com Team
A process running under a restrictive seccomp filter that specified multiple syscall arguments could bypass intended access restrictions by specifying a single matching argument. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2320-1
Updated firejail package fixes security vulnerabilities: Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions . MGASA-2020-0115 - Updated firejail packages fix security vulnerabilities Publication date: 06 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0115.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12499, CVE-2019-12589 Updated firejail package fixes security vulnerabilities: Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also needs to be terminated as root from the host (either by stopping it ungracefully (e.g., SIGKILL), or by using the --shutdown control command) (CVE-2019-12499). In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker (CVE-2019-12589). References: - https://bugs.mageia.org/show_bug.cgi?id=26013 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.