Explore top 10 tips to secure your open-source projects now. Read More
×Important: pcp security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:6837", "synopsis": "Important: pcp security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pcp.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.\n\nSecurity Fix(es):\n\n* pcp: pmpost symlink attack allows escalating pcp to root user (CVE-2024-45770)\n\n* pcp: pmcd heap corruption through metric pmstore operations (CVE-2024-45769)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2310451", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2310451", "description": ""}, {"ticket": "2310452", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2310452", "description": ""}], "cves": [{"name": "CVE-2024-45769", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-45769", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-45770", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-45770", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-09-30T14:30:36.675668Z", "rpms": {"Rocky Linux 8": {"nvras": ["pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-0:5.3.7-22.el8_10.src.rpm", "pcp-0:5.3.7-22.el8_10.x86_64.rpm","pcp-conf-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-conf-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-debuginfo-0:5.3.7-22.el8_10.i686.rpm", "pcp-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-debugsource-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-debugsource-0:5.3.7-22.el8_10.i686.rpm", "pcp-debugsource-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-devel-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-devel-0:5.3.7-22.el8_10.i686.rpm", "pcp-devel-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-devel-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-devel-debuginfo-0:5.3.7-22.el8_10.i686.rpm", "pcp-devel-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-doc-0:5.3.7-22.el8_10.noarch.rpm", "pcp-export-pcp2elasticsearch-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2elasticsearch-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2graphite-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2graphite-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2influxdb-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2influxdb-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2json-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2json-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2spark-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2spark-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2xml-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2xml-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-pcp2zabbix-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-pcp2zabbix-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-zabbix-agent-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-zabbix-agent-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-export-zabbix-agent-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-export-zabbix-agent-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-gui-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-gui-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-gui-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-gui-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-import-collectl2pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-collectl2pcp-0:5.3.7-22.el8_10.x86_64.rpm","pcp-import-collectl2pcp-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-collectl2pcp-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-import-ganglia2pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-ganglia2pcp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-import-iostat2pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-iostat2pcp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-import-mrtg2pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-mrtg2pcp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-import-sar2pcp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-import-sar2pcp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-libs-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-libs-0:5.3.7-22.el8_10.i686.rpm", "pcp-libs-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-libs-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-libs-debuginfo-0:5.3.7-22.el8_10.i686.rpm", "pcp-libs-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-libs-devel-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-libs-devel-0:5.3.7-22.el8_10.i686.rpm", "pcp-libs-devel-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-activemq-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-activemq-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-apache-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-apache-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-apache-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-apache-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bash-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bash-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bash-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bash-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bcc-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bcc-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bind2-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bind2-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bonding-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bonding-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-bpftrace-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-bpftrace-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-cifs-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-cifs-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-cifs-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm","pcp-pmda-cifs-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-cisco-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-cisco-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-cisco-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-cisco-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-dbping-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-dbping-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-denki-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-denki-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-denki-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-denki-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-dm-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-dm-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-dm-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-dm-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-docker-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-docker-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-docker-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-docker-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-ds389-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-ds389-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-ds389log-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-ds389log-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-elasticsearch-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-elasticsearch-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-gfs2-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-gfs2-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-gfs2-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-gfs2-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-gluster-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-gluster-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-gpfs-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-gpfs-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-gpsd-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-gpsd-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-hacluster-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-hacluster-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-hacluster-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-hacluster-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm","pcp-pmda-haproxy-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-haproxy-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-infiniband-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-infiniband-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-infiniband-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-infiniband-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-json-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-json-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-libvirt-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-libvirt-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-lio-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-lio-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-lmsensors-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-lmsensors-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-logger-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-logger-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-logger-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-logger-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-lustre-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-lustre-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-lustrecomm-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-lustrecomm-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-lustrecomm-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-lustrecomm-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mailq-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mailq-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mailq-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mailq-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-memcache-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-memcache-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mic-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mic-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mongodb-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mongodb-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mounts-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mounts-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mounts-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mounts-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-mssql-0:5.3.7-22.el8_10.x86_64.rpm","pcp-pmda-mysql-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-mysql-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-named-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-named-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-netcheck-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-netcheck-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-netfilter-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-netfilter-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-news-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-news-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-nfsclient-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-nfsclient-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-nginx-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-nginx-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-nvidia-gpu-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-nvidia-gpu-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-nvidia-gpu-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-nvidia-gpu-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-openmetrics-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-openmetrics-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-openvswitch-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-openvswitch-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-oracle-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-oracle-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-pdns-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-pdns-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-perfevent-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-perfevent-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-perfevent-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-perfevent-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-podman-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-podman-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-podman-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-podman-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-postfix-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-postfix-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-postgresql-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-postgresql-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-rabbitmq-0:5.3.7-22.el8_10.aarch64.rpm","pcp-pmda-rabbitmq-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-redis-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-redis-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-roomtemp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-roomtemp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-roomtemp-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-roomtemp-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-rsyslog-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-rsyslog-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-samba-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-samba-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-sendmail-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-sendmail-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-sendmail-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-sendmail-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-shping-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-shping-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-shping-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-shping-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-slurm-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-slurm-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-smart-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-smart-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-smart-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-smart-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-snmp-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-snmp-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-sockets-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-sockets-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-sockets-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-sockets-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-statsd-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-statsd-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-statsd-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-statsd-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-summary-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-summary-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-summary-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-summary-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm","pcp-pmda-systemd-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-systemd-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-systemd-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-systemd-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-trace-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-trace-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-trace-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-trace-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-unbound-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-unbound-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-weblog-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-weblog-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-weblog-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-weblog-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-zimbra-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-zimbra-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-pmda-zswap-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-pmda-zswap-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-selinux-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-selinux-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-system-tools-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-system-tools-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-system-tools-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-system-tools-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-testsuite-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-testsuite-0:5.3.7-22.el8_10.i686.rpm", "pcp-testsuite-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-testsuite-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-testsuite-debuginfo-0:5.3.7-22.el8_10.i686.rpm", "pcp-testsuite-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "pcp-zeroconf-0:5.3.7-22.el8_10.aarch64.rpm", "pcp-zeroconf-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-LogImport-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-LogImport-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-LogImport-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-LogImport-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-LogSummary-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-LogSummary-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-MMV-0:5.3.7-22.el8_10.aarch64.rpm","perl-PCP-MMV-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-MMV-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-MMV-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-PMDA-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-PMDA-0:5.3.7-22.el8_10.x86_64.rpm", "perl-PCP-PMDA-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "perl-PCP-PMDA-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm", "python3-pcp-0:5.3.7-22.el8_10.aarch64.rpm", "python3-pcp-0:5.3.7-22.el8_10.x86_64.rpm", "python3-pcp-debuginfo-0:5.3.7-22.el8_10.aarch64.rpm", "python3-pcp-debuginfo-0:5.3.7-22.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Essential pcp security patch for Rocky Linux boosts system efficiency and resolves significant bugs.. Rocky Linux Security, pcp Update, Performance Co-Pilot. . Severity: Important. LinuxSecurity.com Team
* bsc#1219276 Cross-References: * CVE-2022-48622 . # Security update for gdk-pixbuf Announcement ID: SUSE-SU-2024:1842-1 Rating: important References: * bsc#1219276 Cross-References: * CVE-2022-48622 CVSS scores: * CVE-2022-48622 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2022-48622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for gdk-pixbuf fixes the following issues: * CVE-2022-48622: Fixed files rejection with multiple anih chunks (bsc#1219276). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-1842=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-1842=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-1842=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patchSUSE-SLE-Product-SLES-15-SP3-LTSS-2024-1842=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-1842=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-1842=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-1842=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1842=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-1842=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (x86_64) * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 *gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (x86_64) * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 *typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (x86_64) * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (x86_64) * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux EnterpriseServer for SAP Applications 15 SP3 (ppc64le x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * gdk-pixbuf-thumbnailer-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-thumbnailer-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * typelib-1_0-GdkPixdata-2_0-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * gdk-pixbuf-devel-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Enterprise Storage 7.1 (noarch) * gdk-pixbuf-lang-2.40.0-150200.3.12.1 * SUSE Enterprise Storage 7.1 (x86_64) * gdk-pixbuf-query-loaders-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-32bit-2.40.0-150200.3.12.1 *gdk-pixbuf-query-loaders-32bit-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * typelib-1_0-GdkPixbuf-2_0-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-2.40.0-150200.3.12.1 * gdk-pixbuf-debugsource-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-2.40.0-150200.3.12.1 * gdk-pixbuf-query-loaders-debuginfo-2.40.0-150200.3.12.1 * libgdk_pixbuf-2_0-0-debuginfo-2.40.0-150200.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48622.html * https://bugzilla.suse.com/show_bug.cgi?id=1219276 . Significant revision for gdk-pixbuf tackling serious security vulnerabilities found across several SUSE versions.. gdk-pixbuf Update,SUSE Security Advisory,Vulnerability Fix,SUSE Linux Updates,Gdk-Pixbuf Security. . Severity: Critical. LinuxSecurity.com Team
Update to uriparser-0.9.8.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a7b8b6bfe2 2024-05-21 01:17:25.932122 -------------------------------------------------------------------------------- Name : uriparser Product : Fedora 40 Version : 0.9.8 Release : 1.fc40 URL : https://uriparser.github.io/ Summary : URI parsing library - RFC 3986 Description : Uriparser is a strictly RFC 3986 compliant URI parsing library written in C. uriparser is cross-platform, fast, supports Unicode and is licensed under the New BSD license. -------------------------------------------------------------------------------- Update Information: Update to uriparser-0.9.8. -------------------------------------------------------------------------------- ChangeLog: * Sun May 5 2024 Sandro Mani - 0.9.8-1 - Update to 0.9.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278811 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2278811 [ 2 ] Bug #2278812 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2278812 [ 3 ] Bug #2278813 - CVE-2024-34402 CVE-2024-34403 uriparser: various flaws [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2278813 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a7b8b6bfe2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A flaw was found in the tpm2-tss package, where there was no check that the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote. . MGASA-2024-0171 - Updated tpm2-tss packages fix security vulnerabilities Publication date: 09 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0171.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-29040 A flaw was found in the tpm2-tss package, where there was no check that the magic number in the attest is equal to the TPM2_GENERATED_VALUE. This flaw allows an attacker to generate arbitrary quote data, which may not be detected by Fapi_VerifyQuote. References: - https://bugs.mageia.org/show_bug.cgi?id=33176 - https://access.redhat.com/security/cve/CVE-2024-29040 - https://www.cve.org/CVERecord?id=CVE-2024-29040 SRPMS: - 9/core/tpm2-tss-4.0.2-1.mga9 . Vulnerability in tpm2-tss module enables adversaries to produce unverified quote information, threatening system integrity. Stay informed for further details.. Mageia 9 updates,tpm2-tss security flaw,security advisory,Mageia vulnerabilities. . LinuxSecurity.com Team
This update for python311 fixes the following issues: python was updated to version 3.11.4:. # Security update for python311 Announcement ID: SUSE-SU-2023:2937-1 Rating: important References: * bsc#1203750 * bsc#1208471 Cross-References: * CVE-2007-4559 * CVE-2023-24329 CVSS scores: * CVE-2007-4559 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2023-24329 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2023-24329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP4 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: python was updated to version 3.11.4: * CVE-2023-24329: Fixed blocklist bypass via the urllib.parse component when supplying a URL that starts with blank characters (bsc#1208471). * CVE-2007-4559: Fixed python tarfile module directory traversal (bsc#1203750). * Fixed a security in flaw in uu.decode() that could allow for directory traversal based on the input if no out_file was specified. * Do not expose the local on-disk location in directory indexes produced by http.client.SimpleHTTPRequestHandler. Bugfixes: * trace. **main** now uses io.open_code() for files to be executed instead of raw open(). ## Patch Instructions: To install this SUSE update use the SUSE recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-2937=1 openSUSE-SLE-15.4-2023-2937=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-2937=1 * Python 3 Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Python3-15-SP4-2023-2937=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2023-2937=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libpython3_11-1_0-debuginfo-3.11.4-150400.9.15.3 * python311-3.11.4-150400.9.15.1 * python311-base-3.11.4-150400.9.15.3 * python311-curses-3.11.4-150400.9.15.1 * python311-devel-3.11.4-150400.9.15.3 * python311-testsuite-debuginfo-3.11.4-150400.9.15.3 * python311-doc-3.11.4-150400.9.15.2 * python311-testsuite-3.11.4-150400.9.15.3 * python311-doc-devhelp-3.11.4-150400.9.15.2 * python311-debuginfo-3.11.4-150400.9.15.1 * python311-dbm-3.11.4-150400.9.15.1 * libpython3_11-1_0-3.11.4-150400.9.15.3 * python311-core-debugsource-3.11.4-150400.9.15.3 * python311-tk-3.11.4-150400.9.15.1 * python311-idle-3.11.4-150400.9.15.1 * python311-tk-debuginfo-3.11.4-150400.9.15.1 * python311-debugsource-3.11.4-150400.9.15.1 * python311-dbm-debuginfo-3.11.4-150400.9.15.1 * python311-base-debuginfo-3.11.4-150400.9.15.3 * python311-tools-3.11.4-150400.9.15.3 * python311-curses-debuginfo-3.11.4-150400.9.15.1 * openSUSE Leap 15.4 (x86_64) * python311-base-32bit-debuginfo-3.11.4-150400.9.15.3 * libpython3_11-1_0-32bit-debuginfo-3.11.4-150400.9.15.3 * python311-base-32bit-3.11.4-150400.9.15.3 * python311-32bit-3.11.4-150400.9.15.1 * python311-32bit-debuginfo-3.11.4-150400.9.15.1 * libpython3_11-1_0-32bit-3.11.4-150400.9.15.3 * openSUSE Leap 15.4 (aarch64_ilp32) * python311-base-64bit-debuginfo-3.11.4-150400.9.15.3 * python311-64bit-3.11.4-150400.9.15.1 *python311-base-64bit-3.11.4-150400.9.15.3 * libpython3_11-1_0-64bit-3.11.4-150400.9.15.3 * python311-64bit-debuginfo-3.11.4-150400.9.15.1 * libpython3_11-1_0-64bit-debuginfo-3.11.4-150400.9.15.3 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-debuginfo-3.11.4-150400.9.15.3 * python311-3.11.4-150400.9.15.1 * python311-base-3.11.4-150400.9.15.3 * python311-curses-3.11.4-150400.9.15.1 * python311-devel-3.11.4-150400.9.15.3 * python311-testsuite-debuginfo-3.11.4-150400.9.15.3 * python311-doc-3.11.4-150400.9.15.2 * python311-testsuite-3.11.4-150400.9.15.3 * python311-doc-devhelp-3.11.4-150400.9.15.2 * python311-debuginfo-3.11.4-150400.9.15.1 * python311-dbm-3.11.4-150400.9.15.1 * libpython3_11-1_0-3.11.4-150400.9.15.3 * python311-core-debugsource-3.11.4-150400.9.15.3 * python311-tk-3.11.4-150400.9.15.1 * python311-idle-3.11.4-150400.9.15.1 * python311-tk-debuginfo-3.11.4-150400.9.15.1 * python311-debugsource-3.11.4-150400.9.15.1 * python311-base-debuginfo-3.11.4-150400.9.15.3 * python311-dbm-debuginfo-3.11.4-150400.9.15.1 * python311-tools-3.11.4-150400.9.15.3 * python311-curses-debuginfo-3.11.4-150400.9.15.1 * openSUSE Leap 15.5 (x86_64) * python311-base-32bit-debuginfo-3.11.4-150400.9.15.3 * libpython3_11-1_0-32bit-debuginfo-3.11.4-150400.9.15.3 * python311-base-32bit-3.11.4-150400.9.15.3 * python311-32bit-3.11.4-150400.9.15.1 * python311-32bit-debuginfo-3.11.4-150400.9.15.1 * libpython3_11-1_0-32bit-3.11.4-150400.9.15.3 * Python 3 Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-tk-3.11.4-150400.9.15.1 * python311-doc-3.11.4-150400.9.15.2 * python311-idle-3.11.4-150400.9.15.1 * python311-tk-debuginfo-3.11.4-150400.9.15.1 * python311-dbm-3.11.4-150400.9.15.1 * libpython3_11-1_0-debuginfo-3.11.4-150400.9.15.3 * python311-3.11.4-150400.9.15.1 * python311-debugsource-3.11.4-150400.9.15.1 * python311-base-3.11.4-150400.9.15.3 * libpython3_11-1_0-3.11.4-150400.9.15.3 * python311-base-debuginfo-3.11.4-150400.9.15.3 * python311-dbm-debuginfo-3.11.4-150400.9.15.1 * python311-curses-3.11.4-150400.9.15.1 * python311-debuginfo-3.11.4-150400.9.15.1 * python311-tools-3.11.4-150400.9.15.3 * python311-doc-devhelp-3.11.4-150400.9.15.2 * python311-devel-3.11.4-150400.9.15.3 * python311-curses-debuginfo-3.11.4-150400.9.15.1 * python311-core-debugsource-3.11.4-150400.9.15.3 * Python 3 Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python311-tk-3.11.4-150400.9.15.1 * python311-doc-3.11.4-150400.9.15.2 * python311-idle-3.11.4-150400.9.15.1 * python311-tk-debuginfo-3.11.4-150400.9.15.1 * python311-dbm-3.11.4-150400.9.15.1 * libpython3_11-1_0-debuginfo-3.11.4-150400.9.15.3 * python311-3.11.4-150400.9.15.1 * python311-debugsource-3.11.4-150400.9.15.1 * python311-base-3.11.4-150400.9.15.3 * libpython3_11-1_0-3.11.4-150400.9.15.3 * python311-base-debuginfo-3.11.4-150400.9.15.3 * python311-dbm-debuginfo-3.11.4-150400.9.15.1 * python311-curses-3.11.4-150400.9.15.1 * python311-debuginfo-3.11.4-150400.9.15.1 * python311-tools-3.11.4-150400.9.15.3 * python311-doc-devhelp-3.11.4-150400.9.15.2 * python311-devel-3.11.4-150400.9.15.3 * python311-curses-debuginfo-3.11.4-150400.9.15.1 * python311-core-debugsource-3.11.4-150400.9.15.3 ## References: * https://www.suse.com/security/cve/CVE-2007-4559.html * https://www.suse.com/security/cve/CVE-2023-24329.html * https://bugzilla.suse.com/show_bug.cgi?id=1203750 * https://bugzilla.suse.com/show_bug.cgi?id=1208471 . Upgrade your framework with the vital security patch for python311. This update tackles significant vulnerabilities and enhances overall stability.. openSUSE Security, Python Patch, Important Update, System Security, Python 3 Module. . Severity: Important. LinuxSecurity.com Team
Update golang-x-crypto to v0.18.0, fix for CVE-2023-48795. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2705241461 2024-01-18 01:24:42.646417 -------------------------------------------------------------------------------- Name : golang-x-crypto Product : Fedora 38 Version : 0.18.0 Release : 1.fc38 URL : https://github.com/golang/crypto Summary : Go supplementary cryptography libraries Description : Go supplementary cryptography libraries. -------------------------------------------------------------------------------- Update Information: Update golang-x-crypto to v0.18.0, fix for CVE-2023-48795 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 9 2024 Mark E. Fuller - 0.18.0-1 - update to v0.18.0, close rhbz#2255095 - CVE-2023-48795 golang-x-crypto: ssh: Prefix truncation attack on Binary Packet Protocol * Tue Dec 19 2023 Mark E. Fuller - 0.17.0-1 - update to v0.17.0, close rhbz#2255153 * Tue Nov 28 2023 Mark E. Fuller - 0.16.0-1 - update to v0.16.0, close rhbz#2251962 * Mon Nov 20 2023 Mark E. Fuller - 0.15.0-1 - update to 0.15.0, close rhbz#2248796 * Mon Oct 9 2023 Mark E. Fuller - 0.14.0-1 - update to v0.14.0, close rhbz#2242424 * Wed Sep 6 2023 Mark E. Fuller - 0.13.0-1 - update to v0.13.0, close rhbz#2237488 * Sat Aug 12 2023 Mark E. Fuller - 0.12.0-1 - update to v0.12.0 * Thu Jul 20 2023 Fedora Release Engineering - 0.11.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Fri Jul 14 2023 Mark E. Fuller - 0.11.0-1 - update to v0.11.0, close rhbz#2214859 * Thu Jun 22 2023 Mark E. Fuller - 0.10.0-1 - update to v0.10.0, close rhbz#2214859 * Sun Jun 11 2023 Mark E. Fuller - 0.9.0-1 - bump to v0.9.0, close rhbz#2175556 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2254210 - CVE-2023-48795 ssh:Prefix truncation attack on Binary Packet Protocol (BPP) https://bugzilla.redhat.com/show_bug.cgi?id=2254210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2705241461' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-13044 https://linux.oracle.com/errata/ELSA-2023-13044.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.326.6.el8uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.326.6.el8uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.326.6.el8uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.326.6.el8uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.326.6.el8uek.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//kernel-uek-5.4.17-2136.326.6.el8uek.src.rpm Related CVEs: CVE-2023-5178 Description of changes: [5.4.17-2136.326.6.el8uek] - Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" (Junxiao Bi) [Orabug: 35914789] - md: bypass block throttle for superblock update (Junxiao Bi) [Orabug: 35914789] [5.4.17-2136.326.5.el8uek] - Revert "tracing: Increase trace array ref count on enable and filter files" (Sherry Yang) [Orabug: 36059945] - xen/blkback: Force flush and secure discard support flags (Boris Ostrovsky) [Orabug: 36050498] - Revert "PCI: acpiphp: Reassign resources on bridge if necessary" (Dongli Zhang) [Orabug: 36049644] - Revert "PCI: acpiphp: Use pci_assign_unassigned_bridge_resources() only for non-root bus" (Dongli Zhang) [Orabug: 36049644] [5.4.17-2136.326.4.el8uek] - Revert "mmc: core: Capture correct oemid-bits for eMMC cards" (Dominique Martinet) - media: dvb-usb-v2: af9035: fix missing unlock (Hans Verkuil) - perf/core: Fix potential NULL deref (Peter Zijlstra) - i2c: aspeed: Fix i2c bus hang in slave read (Jian Zhang) - virtio-mmio: fix memory leak of vm_dev (Maximilian Heyne) - net/rds: Use proper peer port number even when not connected (Greg Jumper) [Orabug: 35065319] - Use inflight IO in io acct of high latency devices (Gulam Mohamed) [Orabug: 35475691] - nvmet-tcp: Fix a possible UAF in queue intialization setup (Sagi Grimberg) [Orabug: 36028026] {CVE-2023-5178} [5.4.17-2136.326.3.el8uek] - LTS tag: v5.4.259 (Sherry Yang) - xfrm6: fix inet6_dev refcount underflow problem (Zhang Changzhong) - Bluetooth: hci_sock: Correctly bounds check and pad HCI_MON_NEW_INDEX name (Kees Cook) - Bluetooth: hci_sock: fix slab oob read in create_monitor_event (Edward AD) - phy: mapphone-mdm6600: Fix pinctrl_pm handling for sleep pins (Tony Lindgren) - phy: mapphone-mdm6600: Fix runtime PM for remove (Tony Lindgren) - phy: mapphone-mdm6600: Fix runtime disable on probe (Tony Lindgren) - ASoC: pxa: fix a memory leak in probe() (Dan Carpenter) - gpio: vf610: set value before the direction to avoid a glitch (Haibo Chen) - s390/pci: fix iommu bitmap allocation (Niklas Schnelle) - perf: Disallow mis-matched inherited group reads (Peter Zijlstra) - USB: serial: option: add Fibocom to DELL custom modem FM101R-GL (Puliang Lu) - USB: serial: option: add entry for Sierra EM9191 with new firmware (Benoît Monin) - USB: serial: option: add Telit LE910C4-WWX 0x1035 composition (Fabio Porcedda) - ACPI: irq: Fix incorrect return value in acpi_register_gsi() (Sunil V L) - Revert "pinctrl: avoid unsafe code pattern in find_pinctrl()" (Andy Shevchenko) - mmc: core: Capture correct oemid-bits for eMMC cards (Avri Altman) - mmc: core: sdio: hold retuning if sdio in 1-bit mode (Haibo Chen) - mtd: physmap-core: Restore map_rom fallback (Geert Uytterhoeven) - mtd: spinand: micron: correct bitmask for ecc status (Martin Kurbanov) - mtd: rawnand: qcom: Unmap the right resource upon probe failure (Bibek Kumar Patro) - Bluetooth: hci_event: Fix using memcmp when comparing keys (Luiz Augusto von Dentz) - HID: multitouch: Add required quirk for Synaptics 0xcd7e device (Rahul Rameshbabu) - btrfs: fix some -Wmaybe-uninitialized warnings in ioctl.c (Josef Bacik) - drm: panel-orientation-quirks: Add quirk for One Mix 2S (Kai Uwe Broulik) - sky2: Make sure there is at least one frag_addr available (Kees Cook) - regulator/core: Revert "fix kobject release warning and memory leakin regulator_register()" (MichaÅ MirosÅaw) - wifi: cfg80211: avoid leaking stack data into trace (Benjamin Berg) - wifi: mac80211: allow transmitting EAPOL frames with tainted key (Wen Gong) - Bluetooth: hci_core: Fix build warnings (Luiz Augusto von Dentz) - Bluetooth: Avoid redundant authentication (Ying Hsu) - HID: holtek: fix slab-out-of-bounds Write in holtek_kbd_input_event (Ma Ke) - tracing: relax trace_event_eval_update() execution with cond_resched() (Clément Léger) - ata: libata-eh: Fix compilation warning in ata_eh_link_report() (Damien Le Moal) - gpio: timberdale: Fix potential deadlock on &tgpio-> lock (Chengfeng Ye) - overlayfs: set ctime when setting mtime and atime (Jeff Layton) - i2c: mux: Avoid potential false error message in i2c_mux_add_adapter (Heiner Kallweit) - btrfs: initialize start_slot in btrfs_log_prealloc_extents (Josef Bacik) - btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to 1 (Filipe Manana) - ARM: dts: ti: omap: Fix noisy serial with overrun-throttle-ms for mapphone (Tony Lindgren) - ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CBA (Hans de Goede) - ACPI: resource: Skip IRQ override on ASUS ExpertBook B1502CBA (Paul Menzel) - ACPI: resource: Skip IRQ override on Asus Expertbook B2402CBA (Tamim Khan) - ACPI: resource: Add Asus ExpertBook B2502 to Asus quirks (Hans de Goede) - ACPI: resource: Skip IRQ override on Asus Vivobook S5602ZA (Tamim Khan) - ACPI: resource: Add ASUS model S5402ZA to quirks (Kellen Renshaw) - ACPI: resource: Skip IRQ override on Asus Vivobook K3402ZA/K3502ZA (Tamim Khan) - ACPI: resources: Add DMI-based legacy IRQ override quirk (Hui Wang) - ACPI: Drop acpi_dev_irqresource_disabled() (John Garry) - resource: Add irqresource_disabled() (John Garry) - net: pktgen: Fix interface flags printing (Gavrilov Ilia) - netfilter: nft_set_rbtree: .deactivate fails if element has expired (Pablo Neira Ayuso) - neighbor: tracing: Move pin6 inside CONFIG_IPV6=y section (Geert Uytterhoeven) -net/sched: sch_hfsc: upgrade 'rt' to 'sc' when it becomes a inner curve (Pedro Tammela) - i40e: prevent crash on probe if hw registers have invalid values (Michal Schmidt) - net: usb: smsc95xx: Fix an error code in smsc95xx_reset() (Dan Carpenter) - ipv4: fib: annotate races around nh-> nh_saddr_genid and nh-> nh_saddr (Eric Dumazet) - tun: prevent negative ifindex (Eric Dumazet) - tcp: tsq: relax tcp_small_queue_check() when rtx queue contains a single skb (Eric Dumazet) - tcp: fix excessive TLP and RACK timeouts from HZ rounding (Neal Cardwell) - net: rfkill: gpio: prevent value glitch during probe (Josua Mayer) - net: ipv6: fix return value check in esp_remove_trailer (Ma Ke) - net: ipv4: fix return value check in esp_remove_trailer (Ma Ke) - xfrm: interface: use DEV_STATS_INC() (Eric Dumazet) - xfrm: fix a data-race in xfrm_gen_index() (Eric Dumazet) - qed: fix LL2 RX buffer allocation (Manish Chopra) - netfilter: nft_payload: fix wrong mac header matching (Florian Westphal) - KVM: x86: Mask LVTPC when handling a PMI (Jim Mattson) - regmap: fix NULL deref on lookup (Johan Hovold) - nfc: nci: fix possible NULL pointer dereference in send_acknowledge() (Krzysztof Kozlowski) - ice: fix over-shifted variable (Jesse Brandeburg) - Bluetooth: avoid memcmp() out of bounds warning (Arnd Bergmann) - Bluetooth: hci_event: Fix coding style (Luiz Augusto von Dentz) - Bluetooth: vhci: Fix race when opening vhci device (Arkadiusz Bokowy) - Bluetooth: Fix a refcnt underflow problem for hci_conn (Ziyang Xuan) - Bluetooth: Reject connection with the device which has same BD_ADDR (Lee, Chun-Yi) - Bluetooth: hci_event: Ignore NULL link key (Lee, Chun-Yi) - usb: hub: Guard against accesses to uninitialized BOS descriptors (Ricardo Cañuelo) - Documentation: sysctl: align cells in second content column (Bagas Sanjaya) - dev_forward_skb: do not scrub skb mark within the same name space (Nicolas Dichtel) - ravb: Fix use-after-free issue in ravb_tx_timeout_work() (Yoshihiro Shimoda) - powerpc/64e: Fixwrong test in __ptep_test_and_clear_young() (Christophe Leroy) - powerpc/8xx: Fix pte_access_permitted() for PAGE_NONE (Christophe Leroy) - dmaengine: mediatek: Fix deadlock caused by synchronize_irq() (Duoming Zhou) - x86/cpu: Fix AMD erratum #1485 on Zen4-based CPUs (Borislav Petkov (AMD)) - usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call (Krishna Kurapati) - usb: gadget: udc-xilinx: replace memcpy with memcpy_toio (Piyush Mehta) - pinctrl: avoid unsafe code pattern in find_pinctrl() (Dmitry Torokhov) - cgroup: Remove duplicates in cgroup v1 tasks file (Michal Koutný) - Input: xpad - add PXN V900 support (Matthias Berndt) - Input: psmouse - fix fast_reconnect function for PS/2 mode (Jeffery Miller) - Input: powermate - fix use-after-free in powermate_config_complete (Javier Carrasco) - ceph: fix incorrect revoked caps assert in ceph_fill_file_size() (Xiubo Li) - libceph: use kernel_connect() (Jordan Rife) - mcb: remove is_added flag from mcb_device struct (Jorge Sanjuan Garcia) - iio: pressure: ms5611: ms5611_prom_is_valid false negative bug (Alexander Zangerl) - iio: pressure: dps310: Adjust Timeout Settings (Lakshmi Yadlapati) - iio: pressure: bmp280: Fix NULL pointer exception (Phil Elwell) - usb: musb: Modify the "HWVers" register address (Xingxing Luo) - usb: musb: Get the musb_qh poniter after musb_giveback (Xingxing Luo) - usb: dwc3: Soft reset phy on probe for host (Thinh Nguyen) - net: usb: dm9601: fix uninitialized variable use in dm9601_mdio_read (Javier Carrasco) - usb: xhci: xhci-ring: Use sysdev for mapping bounce buffer (Wesley Cheng) - dmaengine: stm32-mdma: abort resume if no ongoing transfer (Amelie Delaunay) - workqueue: Override implicit ordered attribute in workqueue_apply_unbound_cpumask() (Waiman Long) - nfc: nci: assert requested protocol is valid (Jeremy Cline) - net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn() (Eric Dumazet) - ixgbe: fix crash with empty VF macvlan list (Dan Carpenter) - drm/vmwgfx: fix typo ofsizeof argument (Konstantin Meskhidze) - xen-netback: use default TX queue size for vifs (Roger Pau Monne) - mlxsw: fix mlxsw_sp2_nve_vxlan_learning_set() return type (Dan Carpenter) - ieee802154: ca8210: Fix a potential UAF in ca8210_probe (Dinghao Liu) - ravb: Fix up dma_free_coherent() call in ravb_remove() (Yoshihiro Shimoda) - drm/msm/dsi: skip the wait for video mode done if not applicable (Abhinav Kumar) - drm: etvnaviv: fix bad backport leading to warning (Martin Fuzzey) - quota: Fix slow quotaoff (Jan Kara) - HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect (Hans de Goede) - pwm: hibvt: Explicitly set .polarity in .get_state() (Uwe Kleine-König) - lib/test_meminit: fix off-by-one error in test_pages() (Greg Kroah-Hartman) - RDMA/cxgb4: Check skb value for failure to allocate (Artem Chernyshev) - LTS tag: v5.4.258 (Sherry Yang) - xen/events: replace evtchn_rwlock with RCU (Juergen Gross) - ima: rework CONFIG_IMA dependency block (Arnd Bergmann) - NFS: Fix a race in __nfs_list_for_each_server() (Trond Myklebust) - parisc: Restore __ldcw_align for PA-RISC 2.0 processors (John David Anglin) - RDMA/mlx5: Fix NULL string error (Shay Drory) - RDMA/siw: Fix connection failure handling (Bernard Metzler) - RDMA/uverbs: Fix typo of sizeof argument (Konstantin Meskhidze) - RDMA/cma: Fix truncation compilation warning in make_cma_ports (Leon Romanovsky) - gpio: pxa: disable pinctrl calls for MMP_GPIO (Duje MihanoviÄ) - gpio: aspeed: fix the GPIO number passed to pinctrl_gpio_set_config() (Bartosz Golaszewski) - IB/mlx4: Fix the size of a buffer in add_port_entries() (Christophe JAILLET) - RDMA/core: Require admin capabilities to set system parameters (Leon Romanovsky) - cpupower: add Makefile dependencies for install targets (Ivan Babrou) - sctp: update hb timer immediately after users change hb_interval (Xin Long) - sctp: update transport state when processing a dupcook packet (Xin Long) - tcp: fix delayed ACKs for MSS boundary condition (Neal Cardwell) - tcp: fixquick-ack counting to count actual ACKs of new data (Neal Cardwell) - net: stmmac: dwmac-stm32: fix resume on STM32 MCU (Ben Wolsieffer) - netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp (Xin Long) - net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg (Shigeru Yoshida) - ipv4, ipv6: Fix handling of transhdrlen in __ip{,6}_append_data() (David Howells) - net: fix possible store tearing in neigh_periodic_work() (Eric Dumazet) - modpost: add missing else to the "of" check (Mauricio Faria de Oliveira) - NFSv4: Fix a nfs4_state_manager() race (Trond Myklebust) - NFS: Add a helper nfs_client_for_each_server() (Trond Myklebust) - NFS4: Trace state recovery operation (Chuck Lever) - regmap: rbtree: Fix wrong register marked as in-cache when creating new node (Richard Fitzgerald) - wifi: mt76: mt76x02: fix MT76x0 external LNA gain handling (Felix Fietkau) - drivers/net: process the result of hdlc_open() and add call of hdlc_close() in uhdlc_close() (Alexandra Diupina) - wifi: iwlwifi: dbg_ini: fix structure packing (Arnd Bergmann) - ubi: Refuse attaching if mtd's erasesize is 0 (Zhihao Cheng) - net: prevent rewrite of msg_name in sock_sendmsg() (Jordan Rife) - wifi: mwifiex: Fix tlv_buf_left calculation (Gustavo A. R. Silva) - qed/red_ll2: Fix undefined behavior bug in struct qed_ll2_info (Gustavo A. R. Silva) - scsi: zfcp: Fix a double put in zfcp_port_enqueue() (Dinghao Liu) - fs: binfmt_elf_efpic: fix personality for ELF-FDPIC (Greg Ungerer) - ata: libata-sata: increase PMP SRST timeout to 10s (Matthias Schiffer) - ata: libata-core: Do not register PM operations for SAS ports (Damien Le Moal) - ata: libata-core: Fix port and device removal (Damien Le Moal) - ata: libata-core: Fix ata_port_request_pm() locking (Damien Le Moal) - net: thunderbolt: Fix TCPv6 GSO checksum calculation (Mika Westerberg) - btrfs: properly report 0 avail for very full file systems (Josef Bacik) - i2c: i801: unregister tco_pdev in i801_probe() error path (Heiner Kallweit) - ata: libata-scsi: ignore reserved bits for REPORT SUPPORTED OPERATION CODES (Niklas Cassel) - ALSA: hda: Disable power save for solving pop issue on Lenovo ThinkCentre M70q (Kailang Yang) - nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() (Pan Bian) - serial: 8250_port: Check IRQ data before use (Andy Shevchenko) - Smack:- Use overlay inode label in smack_inode_copy_up() (Vishal Goel) - smack: Retrieve transmuting information in smack_inode_getsecurity() (Roberto Sassu) - smack: Record transmuting in smk_transmuted (Roberto Sassu) - i40e: fix return of uninitialized aq_ret in i40e_set_vsi_promisc (Stefan Assmann) - i40e: always propagate error value in i40e_set_vsi_promisc() (Stefan Assmann) - i40e: improve locking of mac_filter_hash (Stefan Assmann) - watchdog: iTCO_wdt: Set NO_REBOOT if the watchdog is not already running (Mika Westerberg) - watchdog: iTCO_wdt: No need to stop the timer in probe (Mika Westerberg) - nvme-pci: do not set the NUMA node of device if it has none (Pratyush Yadav) - fbdev/sh7760fb: Depend on FB=y (Thomas Zimmermann) - ncsi: Propagate carrier gain/loss events to the NCSI controller (Johnathan Mantey) - powerpc/watchpoints: Annotate atomic context in more places (Benjamin Gray) - bpf: Clarify error expectations from bpf_clone_redirect (Stanislav Fomichev) - spi: nxp-fspi: reset the FLSHxCR1 registers (Han Xu) - ata: libata-eh: do not clear ATA_PFLAG_EH_PENDING in ata_eh_reset() (Niklas Cassel) - ring-buffer: Avoid softlockup in ring_buffer_resize() (Zheng Yejian) - selftests/ftrace: Correctly enable event in instance-event.tc (Zheng Yejian) - parisc: irq: Make irq_stack_union static to avoid sparse warning (Helge Deller) - parisc: drivers: Fix sparse warning (Helge Deller) - parisc: iosapic.c: Fix sparse warnings (Helge Deller) - parisc: sba: Fix compile warning wrt list of SBA devices (Helge Deller) - gpio: pmic-eic-sprd: Add can_sleep flag for PMIC EIC chip (Wenhua Lin) - xtensa: boot/lib: fix function prototypes (Max Filippov) -xtensa: boot: don't add include-dirs (Randy Dunlap) - xtensa: iss/network: make functions static (Randy Dunlap) - xtensa: add default definition for XCHAL_HAVE_DIV32 (Max Filippov) - bus: ti-sysc: Fix SYSC_QUIRK_SWSUP_SIDLE_ACT handling for uart wake-up (Tony Lindgren) - ARM: dts: ti: omap: motorola-mapphone: Fix abe_clkctrl warning on boot (Tony Lindgren) - clk: tegra: fix error return case for recalc_rate (Timo Alho) - ata: libata: disallow dev-initiated LPM transitions to unsupported states (Niklas Cassel) - drm/amd/display: prevent potential division by zero errors (Hamza Mahfooz) - drm/amd/display: Fix LFC multiplier changing erratically (Anthony Koo) - drm/amd/display: Reinstate LFC optimization (Amanda Liu) - scsi: qla2xxx: Fix deletion race condition (Quinn Tran) - Input: i8042 - add quirk for TUXEDO Gemini 17 Gen1/Clevo PD70PN (Werner Sembach) - i2c: mux: demux-pinctrl: check the return value of devm_kstrdup() (Xiaoke Wang) - gpio: tb10x: Fix an error handling path in tb10x_gpio_probe() (Christophe JAILLET) - team: fix null-ptr-deref when team device type is changed (Ziyang Xuan) - net: bridge: use DEV_STATS_INC() (Eric Dumazet) - net: hns3: add 5ms delay before clear firmware reset irq source (Jie Wang) - powerpc/perf/hv-24x7: Update domain value check (Kajol Jain) - ipv4: fix null-deref in ipv4_link_failure (Kyle Zeng) - i40e: Fix VF VLAN offloading when port VLAN is configured (Ivan Vecera) - i40e: Fix warning message and call stack during rmmod i40e driver (Karen Sornek) - ASoC: imx-audmix: Fix return error with devm_clk_get() (Shengjiu Wang) - selftests: tls: swap the TX and RX sockets in some tests (Sabrina Dubroca) - selftests/tls: Add {} to avoid static checker warning (Kees Cook) - bpf: Avoid deadlock when using queue and stack maps from NMI (Toke Høiland-Jørgensen) - netfilter: nf_tables: disallow element removal on anonymous sets (Pablo Neira Ayuso) - ASoC: meson: spdifin: start hw on dai probe (Jerome Brunet) - ext4: do not let fstrim block system suspend(Jan Kara) - ext4: move setting of trimmed bit into ext4_try_to_trim_range() (Jan Kara) - ext4: replace the traditional ternary conditional operator with with max()/min() (Kemeng Shi) - ext4: mark group as trimmed only if it was fully scanned (Dmitry Monakhov) - ext4: change s_last_trim_minblks type to unsigned long (Lukas Czerner) - ext4: scope ret locally in ext4_try_to_trim_range() (Lukas Bulwahn) - ext4: add new helper interface ext4_try_to_trim_range() (Wang Jianchao) - ext4: remove the 'group' parameter of ext4_trim_extent (Wang Jianchao) - ata: libahci: clear pending interrupt status (Szuying Chen) - tracing: Increase trace array ref count on enable and filter files (Steven Rostedt (Google)) - SUNRPC: Mark the cred for revalidation if the server rejects it (Trond Myklebust) - NFS/pNFS: Report EINVAL errors from connect() to the server (Trond Myklebust) [5.4.17-2136.326.2.el8uek] - mm/memcg: optimize memory.numa_stat like memory.stat (Shakeel Butt) [Orabug: 35879962] [5.4.17-2136.326.1.el8uek] - mm: fix munmap() of reserved va ranges (Anthony Yznaga) [Orabug: 35843809] - mm: fix mmap() of reserved va ranges (Anthony Yznaga) [Orabug: 35843809] - mm: reinstall placeholder mappings before downgrading mmap lock (Anthony Yznaga) [Orabug: 35843809] - mm: mapping over a reserved va range may unmap twice (Anthony Yznaga) [Orabug: 35843809] - mm: fix update of total_vm for reserved va placeholders (Anthony Yznaga) [Orabug: 35843809] - mm: enable merging of reserved va placeholders (Anthony Yznaga) [Orabug: 35843809] - rds: Provision to allow all trace points at module load time (Arumugam Kolappan) [Orabug: 35916078] - rds/ib: Preserve dest qp num in the connect request (Arumugam Kolappan) [Orabug: 35926165] _______________________________________________ El-errata mailing list
CREATE SCHEMA ... schema_element defeats protective search_path changes. (CVE-2023-2454) Row security policies disregard user ID changes after inlining. (CVE-2023-2455) . MGASA-2023-0187 - Updated postgresql packages fix security vulnerability Publication date: 31 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0187.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-2454, CVE-2023-2455 CREATE SCHEMA ... schema_element defeats protective search_path changes. (CVE-2023-2454) Row security policies disregard user ID changes after inlining. (CVE-2023-2455) References: - https://bugs.mageia.org/show_bug.cgi?id=31912 - https://www.postgresql.org/about/news/postgresql-153-148-1311-1215-and-1120-released-2637/ - https://www.cve.org/CVERecord?id=CVE-2023-2454 - https://www.cve.org/CVERecord?id=CVE-2023-2455 SRPMS: - 8/core/postgresql11-11.20-1.mga8 - 8/core/postgresql13-13.11-1.mga8 . On June 15, 2023, Mageia issued a patch for MySQL that fixes significant vulnerabilities.. PostgreSQL Security Update,Mageia 8,Security Flaw Fixes. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.