Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for keylime Announcement ID: SUSE-SU-2026:22326-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1264265 Cross-References: * CVE-2026-6420 CVSS scores: * CVE-2026-6420 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-6420 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2026-6420 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for keylime fixes the following issue * CVE-2026-6420: use of hardcoded challenge nonce for TPM quote attestation allows for security bypass (bsc#1264265). Changes for keylime: * Update to version 7.14.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 *keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6420.html * https://bugzilla.suse.com/show_bug.cgi?id=1264265 . Keylime security update on SUSE addresses a security bypass issue with a moderate rating. Install now for enhanced protection.. SUSE Keylime Security Update Moderate Security Bypass Patch. . Severity: moderate. LinuxSecurity.com Team
Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-513c495139 2026-06-07 01:06:43.462201+00:00 -------------------------------------------------------------------------------- Name : keylime Product : Fedora 43 Version : 7.14.2 Release : 1.fc43 URL : https://github.com/keylime/keylime Summary : Open source TPM software for Bootstrapping and Maintaining Trust Description : Keylime is a TPM based highly scalable remote boot attestation and runtime integrity measurement solution. -------------------------------------------------------------------------------- Update Information: Updating for Keylime release v7.14.2: This includes the fix for CVE-2026-6420. Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- ChangeLog: * Wed May 27 2026 Anderson Toshiyuki Sasaki - 7.14.2-1 - Updating for Keylime release v7.14.2 - This includes the fix for CVE-2026-6420. - Update keylime-selinux policy to the latest version 44.1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2467277 - keylime-7.14.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=2467277 [ 2 ] Bug #2467584 - CVE-2026-6420 keylime: Keylime: Security bypass due to hardcoded TPM quote nonce [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2467584 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-513c495139' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: .NET 10.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8467", "synopsis": "Important: .NET 10.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet10.0.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 10.0.106 and .NET Runtime 10.0.6.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}, {"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-18T12:07:14.765683Z", "rpms": {"Rocky Linux 10": {"nvras": ["dotnet-apphost-pack-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el10_1.ppc64le.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-host-0:10.0.6-1.el10_1.aarch64.rpm","dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el10_1.s390x.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el10_1.s390x.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el10_1.s390x.rpm", "dotnet-host-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el10_1.s390x.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet10.0-0:10.0.106-1.el10_1.src.rpm", "aspnetcore-runtime-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el10_1.s390x.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el10_1.s390x.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-host-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-sdk-10.0-source-built-artifacts-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet-runtime-10.0-debuginfo-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-sdk-aot-10.0-debuginfo-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el10_1.aarch64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el10_1.x86_64.rpm","dotnet-hostfxr-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-targeting-pack-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet-apphost-pack-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-runtime-dbg-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el10_1.x86_64.rpm", "dotnet-sdk-dbg-10.0-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el10_1.x86_64.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el10_1.s390x.rpm", "aspnetcore-runtime-dbg-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-hostfxr-10.0-debuginfo-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-host-0:10.0.6-1.el10_1.s390x.rpm", "dotnet-hostfxr-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet10.0-debugsource-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet-sdk-10.0-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-templates-10.0-0:10.0.106-1.el10_1.s390x.rpm", "dotnet-templates-10.0-0:10.0.106-1.el10_1.ppc64le.rpm", "dotnet-sdk-aot-10.0-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-sdk-10.0-debuginfo-0:10.0.106-1.el10_1.aarch64.rpm", "dotnet-apphost-pack-10.0-debuginfo-0:10.0.6-1.el10_1.ppc64le.rpm", "dotnet-runtime-10.0-0:10.0.6-1.el10_1.x86_64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el10_1.aarch64.rpm", "aspnetcore-targeting-pack-10.0-0:10.0.6-1.el10_1.aarch64.rpm", "dotnet-host-debuginfo-0:10.0.6-1.el10_1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Explore the critical .NET 10.0 security update for Rocky Linux, addressing major vulnerabilities and suggested fixes.. Rocky Linux 10, .NET 10.0, Denial of Service, security advisory, vulnerability update. . Severity: Important. LinuxSecurity.com Team
Important: .NET 9.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8472", "synopsis": "Important: .NET 9.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for dotnet9.0.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": ".NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.\n\nNew versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 9.0.116 and .NET Runtime 9.0.15.Security Fix(es):\n\n* dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)\n\n* dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)\n\n* dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)\n\n* dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2457741", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457741", "description": ""}, {"ticket": "2457740", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457740", "description": ""}, {"ticket": "2457781", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457781", "description": ""}, {"ticket": "2457739", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2457739", "description": ""}], "cves": [{"name": "CVE-2026-26171", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2026-26171", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}, {"name": "CVE-2026-32178", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-32178", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "cvss3BaseScore": "7.5", "cwe": null}, {"name": "CVE-2026-32203", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-32203", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-787"}, {"name": "CVE-2026-33116", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-33116", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-776"}], "references": [], "publishedAt": "2026-04-18T12:07:14.765683Z", "rpms": {"Rocky Linux 10": {"nvras": ["dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-templates-9.0-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el10_1.x86_64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el10_1.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el10_1.aarch64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el10_1.x86_64.rpm","dotnet-runtime-dbg-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-templates-9.0-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el10_1.x86_64.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-sdk-dbg-9.0-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet-sdk-aot-9.0-debuginfo-0:9.0.116-1.el10_1.aarch64.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el10_1.s390x.rpm", "aspnetcore-runtime-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-hostfxr-9.0-debuginfo-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-sdk-9.0-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el10_1.ppc64le.rpm","dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-runtime-dbg-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "aspnetcore-runtime-dbg-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-targeting-pack-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "aspnetcore-targeting-pack-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet9.0-0:9.0.116-1.el10_1.src.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-sdk-9.0-debuginfo-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-templates-9.0-0:9.0.116-1.el10_1.ppc64le.rpm", "dotnet-runtime-9.0-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-hostfxr-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el10_1.aarch64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el10_1.s390x.rpm", "netstandard-targeting-pack-2.1-0:9.0.116-1.el10_1.aarch64.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el10_1.ppc64le.rpm", "dotnet-sdk-aot-9.0-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet-apphost-pack-9.0-0:9.0.15-1.el10_1.x86_64.rpm", "dotnet-runtime-9.0-debuginfo-0:9.0.15-1.el10_1.s390x.rpm", "dotnet-sdk-9.0-source-built-artifacts-0:9.0.116-1.el10_1.x86_64.rpm", "dotnet9.0-debugsource-0:9.0.116-1.el10_1.s390x.rpm", "dotnet-apphost-pack-9.0-debuginfo-0:9.0.15-1.el10_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical security advisory for Rocky Linux on .NET 9.0 highlights important updates and fixes against various threats.. Rocky Linux, .NET 9.0, security update, Denial of Service, security fix. . Severity: Important. LinuxSecurity.com Team
Red Hat Integration Camel for Spring Boot 3.20.2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update Advisory ID: RHSA-2023:5148-01 Product: Red Hat Integration Advisory URL: https://access.redhat.com/errata/RHSA-2023:5148 Issue date: 2023-09-13 CVE Names: CVE-2023-20873 CVE-2023-34455 ===================================================================== 1. Summary: Red Hat Integration Camel for Spring Boot 3.20.2 release and security update is now available. Red Hat Product Security has rated this update as having an impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat Integration Camel for Spring Boot 3.20.2 is now available. The purpose of this text-only errata is to inform you about the security issues fixed. Security Fix(es): * spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry (CVE-2023-20873) * snappy-java: Unchecked chunk length leads to DoS (CVE-2023-34455) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2215445 - CVE-2023-34455 snappy-java: Uncheckedchunk length leads to DoS 2231491 - CVE-2023-20873 spring-boot: Security Bypass With Wildcard Pattern Matching on Cloud Foundry 5. References: https://access.redhat.com/security/cve/CVE-2023-20873 https://access.redhat.com/security/cve/CVE-2023-34455 https://access.redhat.com/security/updates/classification#important https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=red.hat.integration&version=2023-Q3 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlAikfAAoJENzjgjWX9erE99YP/i5C3Va6yTCslqiNPOj8cOhy OC1tdof6RVbOxWysA+u4mOSHLQGCO3WJC5ujoTjBLwnyiW0jsQNZywc6MxvFZVi2 cpd6ZUc6GcOEgXppKmB6kOKckTjK9x2J1Pp99sBaUu1JjjsPHKtiIU7UpxDfbj0x l8LKCbFnjvzEc9iLiORTMrR0x+Di72v1g+pDppkF6cLPISQjmaoy2fFPGOk+QNir OyR6ftdOUwouMpwoeBYA9LNUtj4L4LIwNo7/XUAM37KpgsDjrIugI03BW55WZetu U4fJ2iiCnNRNi7RbQgBoBsAk84wDvZ3CUlsObuJzUnbZO8AHwtTKNLDCXBDXV39N qDhN6Qsf+ODX4XRy92Q7e734bLyKBCdo0JoOq6b3bVP0AxDNnM+vf+1WAD2dnU0F mVEswKVJ3pex7jgw7tsVeGG7QtDLUD3JC1Sg9/wxXZfjmYxr//5e+BPqb0DY3CQ1 VK+Ctx/ovR0sHqmTUFMTgupaVqn/6h9nl16QUpDBY3BiP6QOcgBIAMdZoWDzkdOv Tg/GiEeofpISrxAVtxJXMAcnJA7XmyfaEa6Ks4kqFM5Jd5q+z8tKsePB+SYprL0K 9DLXWQpud7FydFnjzS2HtE85md/LCxBiuGhX8LTqAd0S/n/snKTU3vf7rbDs0uYq +au4fOPXeWAsGf5whih/ =jfNi -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Memory leak. (CVE-2022-23471) Denial of service with maliciously crafted image with a large file (CVE-2023-25153) Security bypass due to improper supplementary group handling. (CVE-2023-25173) . MGASA-2023-0245 - Updated docker-containerd packages fix security vulnerability Publication date: 23 Aug 2023 URL: https://advisories.mageia.org/MGASA-2023-0245.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-23471, CVE-2023-25153, CVE-2023-25173 Memory leak. (CVE-2022-23471) Denial of service with maliciously crafted image with a large file (CVE-2023-25153) Security bypass due to improper supplementary group handling. (CVE-2023-25173) References: - https://bugs.mageia.org/show_bug.cgi?id=31268 - https://lists.suse.com/pipermail/sle-security-updates/2022-December/013215.html - https://ubuntu.com/security/notices/USN-5776-1 - https://lists.fedoraproject.org/archives/list/
Latest upstream 0.2.8. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b25dd670a4 2019-09-04 03:10:52.819337 --------------------------------------------------------------------------------Name : python-mitogen Product : Fedora 30 Version : 0.2.8 Release : 1.fc30 URL : https://github.com/mitogen-hq/mitogen Summary : Distributed self-replicating programs in Python Description : Mitogen is a Python library for writing distributed self-replicating programs. There is no requirement for installing packages, copying files around, writing shell snippets, upfront configuration, or providing any secondary link to a remote machine aside from an SSH connection. Due to its origins for use in managing potentially damaged infrastructure, the remote machine need not even have free disk space or a writeable filesystem. It is not intended as a generic RPC framework; the goal is to provide a robust and efficient low-level API on which tools like Salt, Ansible, or Fabric can be built, and while the API is quite friendly and comparable to Fabric, ultimately it is not intended for direct use by consumer software. The focus is to centralize and perfect the intricate dance required to run Python code safely and efficiently on a remote machine, while avoiding temporary files or large chunks of error-prone shell scripts, and supporting common privilege escalation techniques like sudo, potentially in combination with exotic connection methods such as WMI, telnet, or console-over-IPMI. --------------------------------------------------------------------------------Update Information: Latest upstream 0.2.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #1743124 - CVE-2019-15149 python-mitogen: mitogen: security bypass in core.py [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1743124 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b25dd670a4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNOME desktop library: Security bypass Date: August 31, 2019 Bugs: #692782 ID: 201908-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in the GNOME desktop library may allow attackers to escape the sandbox. Background ========= Library with common API for various GNOME modules. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 gnome-base/gnome-desktop < 3.30.2.3 > = 3.30.2.3 Description ========== A vulnerability was discovered in the GNOME desktop library which allows an attacker to escape the sandbox. Impact ===== A local attacker could possibly bypass sandbox protection. Workaround ========= There is no known workaround at this time. Resolution ========= All GNOME desktop library users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =gnome-base/gnome-desktop-3.30.2.3" References ========= [ 1 ] CVE-2019-11460 https://nvd.nist.gov/vuln/detail/CVE-2019-11460 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201908-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.