Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 39 Firecracker ADVISORY: FEDORA-2024-04877592b7 Critical Update

Update rust-vmm components and their consumers to address CVE-2023-50711. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-04877592b7 2024-02-10 01:24:59.648730 -------------------------------------------------------------------------------- Name : firecracker Product : Fedora 39 Version : 1.6.0 Release : 6.fc39 URL : https://firecracker-microvm.github.io/ Summary : Secure and fast microVMs for serverless computing Description : Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services that provide serverless operational models. Firecracker runs workloads in lightweight virtual machines, called microVMs, which combine the security and isolation properties provided by hardware virtualization technology with the speed and flexibility of containers. This package does not include all of the security features of an official release. It is not production ready without additional sandboxing. -------------------------------------------------------------------------------- Update Information: Update rust-vmm components and their consumers to address CVE-2023-50711 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 28 2024 David Michael - 1.6.0-6 - Sync linux-loader with the upstream version fixing the vmm-sys-util CVE. * Wed Jan 24 2024 Fedora Release Engineering - 1.6.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 David Michael - 1.6.0-4 - Backport the userfaultfd update for its unrecognized ioctl fixes. * Fri Jan 19 2024 Fedora Release Engineering - 1.6.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Thu Jan 11 2024 David Michael - 1.6.0-2 - Backport changes to update vmm-sys-util forCVE-2023-50711. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-04877592b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A critical vulnerability CVE-2023-50711 in Firecracker components affects Fedora 39. All users must update systems to reduce risks of unauthorized access. Fedora Update, Firecracker MicroVM, Serverless Security, Rust-vmm Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 10, 2024 Critical Fedora
98

Red Hat OpenShift 1.30.0 SP1 RHSA-2023:5480-01 Important: HTTP Bypass

Release of OpenShift Serverless Operator 1.30.1 and OpenShift Serverless Logic 1.30.0 SP1 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Release of OpenShift Serverless Logic 1.30.0 SP1 security update Advisory ID: RHSA-2023:5480-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2023:5480 Issue date: 2023-10-05 CVE Names: CVE-2023-2602 CVE-2023-2603 CVE-2023-4853 CVE-2023-22006 CVE-2023-22036 CVE-2023-22041 CVE-2023-22044 CVE-2023-22045 CVE-2023-22049 CVE-2023-25193 CVE-2023-27536 CVE-2023-28321 CVE-2023-28484 CVE-2023-29469 CVE-2023-29491 CVE-2023-34969 ===================================================================== 1. Summary: Release of OpenShift Serverless Operator 1.30.1 and OpenShift Serverless Logic 1.30.0 SP1 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. 2. Description: Red Hat OpenShift Serverless release of OpenShift Serverless Logic. This release includes security fixes. Security Fix(es): * quarkus: HTTP security policy bypass (CVE-2023-4853) For further information about CVE-2023-4853, see the Red Hat Security Bulletin link in the References section. For more details about the security issues, including the impact, a CVSS score, acknowledgements, and other related information, refer to the CVE pages listed in the References section. 3. Solution: Before applying this update, make sure allpreviously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2238034 - CVE-2023-4853 quarkus: HTTP security policy bypass 5. References: https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-4853 https://access.redhat.com/security/cve/CVE-2023-22006 https://access.redhat.com/security/cve/CVE-2023-22036 https://access.redhat.com/security/cve/CVE-2023-22041 https://access.redhat.com/security/cve/CVE-2023-22044 https://access.redhat.com/security/cve/CVE-2023-22045 https://access.redhat.com/security/cve/CVE-2023-22049 https://access.redhat.com/security/cve/CVE-2023-25193 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-29491 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/vulnerabilities/RHSB-2023-002 https://access.redhat.com/security/updates/classification#important https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlHypBAAoJENzjgjWX9erEKGkP/jYGGRUGra0tizCgOISt3wpS YKNeBdag+cSMriReV9XSse2/SYWd0CXtynbDZfQYyP7EmXik03/7Rf/o5h92OJ4c jxrJF4mCmc0dFW31HEefguylonyMKp75XFZb0+hnAaFU4BfjzNIw8DpOcF3JP7Q7 revr5B95oWRHcfG/Wy+9g0texu7ilFlYR5Hp3eYbntkstfpOMIYHjnvYF7fDN9Ty 4AG6aAUnR0UOT5rEZE9GtGaeK+MIMbR8bnjud+NcCuYXktnGNTMhUxEa8uguh7pM Q7hG+n6cAOYKb3kGkhCMwrfRE0TrFgkbQ0r4PoFsWll6TEV5UdBRDE5KCnUxBDjU 9CweYlI1veEx/dfpR17bOgtik6RaRsku3mUp4+3Arp8i5MMUFCWC20oyi382T/NA EpkehRCOJk0PWgYsZ8jvPlJqgitgrpN4rIyljN4utTxFlTyZlVJyYLXPcRg0/N3t 4gFaIFqtrgumLmfgrMe6/PqmA8mRcZENsZiDeoB/zxdOGLZ4lJpgZt2/gOjONWkL A6P+XhzLfp5BVUf4HCua2pQnk/W96ooKabsvhTc1kGb7z8f09JuNxLTIiaj+m7Jt EMwqNxjH3hpoRF2XfOvVR0IM/G26siMpxHkqof9YA8I/St2HDpCKFn7B/ofQRMni 9J9AvIfhEJHOpvztziJH =zYgu -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . OpenShift Serverless Logic has launched an essential security update tackling critical vulnerabilities, enhancing authentication, access controls, and logging features to protect applications. OpenShift Serverless, Red Hat Security, security update, operator release, HTTP bypass. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 05, 2023 Important Red Hat
89

Fedora 39: 2023-8e6ae98f81 Critical: Firecracker Memory Access Issue

Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-8e6ae98f81 2023-09-23 00:16:13.955908 -------------------------------------------------------------------------------- Name : firecracker Product : Fedora 39 Version : 1.4.1 Release : 2.fc39 URL : https://firecracker-microvm.github.io/ Summary : Secure and fast microVMs for serverless computing Description : Firecracker is an open source virtualization technology that is purpose-built for creating and managing secure, multi-tenant container and function-based services that provide serverless operational models. Firecracker runs workloads in lightweight virtual machines, called microVMs, which combine the security and isolation properties provided by hardware virtualization technology with the speed and flexibility of containers. This package does not include all of the security features of an official release. It is not production ready without additional sandboxing. -------------------------------------------------------------------------------- Update Information: Rebuild dependent packages for vm-memory v0.12.2 to address CVE-2023-41051 / RUSTSEC-2023-0056. - - bin/cvename.cgi?name=CVE-2023-41051 - https://rustsec.org/advisories/RUSTSEC-2023-0056.html -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 19 2023 Fabio Valentini - 1.4.1-2 - Rebuild for vm-memory v0.12.2 / CVE-2023-41051. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2236894 - CVE-2023-41051 rust-vm-memory: vm-memory: out-of-bounds access in memory functions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236894 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-8e6ae98f81' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . A recent patch for Fedora 39 targets vulnerabilities found in Firecracker, caused by vm-memory v0.12.2, which poses risks for serverless infrastructures.. Fedora 39, Firecracker, Memory Access Error, Serverless Computing. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 23, 2023 Critical Fedora
98

RedHat: RHSA-2022-1051-01 Moderate: OpenShift Serverless 1.21.0

Release of OpenShift Serverless 1.21.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of OpenShift Serverless 1.21.0 Advisory ID: RHSA-2022:1051-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2022:1051 Issue date: 2022-03-24 CVE Names: CVE-2021-3521 CVE-2021-3712 CVE-2021-44716 CVE-2021-44717 CVE-2022-21248 CVE-2022-21277 CVE-2022-21282 CVE-2022-21283 CVE-2022-21291 CVE-2022-21293 CVE-2022-21294 CVE-2022-21296 CVE-2022-21299 CVE-2022-21305 CVE-2022-21340 CVE-2022-21341 CVE-2022-21360 CVE-2022-21365 CVE-2022-21366 CVE-2022-24407 ==================================================================== 1. Summary: Release of OpenShift Serverless 1.21.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6, 4.7, 4.8, 4.9, and 4.10, includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section. Security Fix(es): * golang: syscall: don't close fd 0 on ForkExec error (CVE-2021-44717) * golang: net/http: limit growth of header canonicalization cache (CVE-2021-44716) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to theCVE page(s) listed in the References section. 3. Solution: See the Red Hat OpenShift Container Platform 4.6 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.7 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.8 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.9 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.10 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 4. Bugs fixed (https://bugzilla.redhat.com/): 2030801 - CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache 2030806 - CVE-2021-44717 golang: syscall: don't close fd 0 on ForkExec error 2054720 - Release of OpenShift Serverless Eventing 1.21.0 2054721 - Release of OpenShift Serverless Serving 1.21.0 5.References: https://access.redhat.com/security/cve/CVE-2021-3521 https://access.redhat.com/security/cve/CVE-2021-3712 https://access.redhat.com/security/cve/CVE-2021-44716 https://access.redhat.com/security/cve/CVE-2021-44717 https://access.redhat.com/security/cve/CVE-2022-21248 https://access.redhat.com/security/cve/CVE-2022-21277 https://access.redhat.com/security/cve/CVE-2022-21282 https://access.redhat.com/security/cve/CVE-2022-21283 https://access.redhat.com/security/cve/CVE-2022-21291 https://access.redhat.com/security/cve/CVE-2022-21293 https://access.redhat.com/security/cve/CVE-2022-21294 https://access.redhat.com/security/cve/CVE-2022-21296 https://access.redhat.com/security/cve/CVE-2022-21299 https://access.redhat.com/security/cve/CVE-2022-21305 https://access.redhat.com/security/cve/CVE-2022-21340 https://access.redhat.com/security/cve/CVE-2022-21341 https://access.redhat.com/security/cve/CVE-2022-21360 https://access.redhat.com/security/cve/CVE-2022-21365 https://access.redhat.com/security/cve/CVE-2022-21366 https://access.redhat.com/security/cve/CVE-2022-24407 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYjziz9zjgjWX9erEAQgD/Q//WvOwTsdlMYzQijM4tQukG6MDu+7/4/em zJArZhFg4sN3Gga+574/Pg4FTeTGxxP0B3fkkVeQxC2Eiqkd2JKfJ7LeCSUfgggC qjDQ0o5EeszqO6VIkVhe0RnZuJsXcDbTLTyvu9IUnypZXnQgR5I7q/dMm4A4c4Fh 84rr1oJ0Vb/jJ2+nXzKtaEcauWlMS4RhD90ogYllx6+7Wno1S6uk8xnabu+LEK5b tJa5FfPvGctekmYnSKneBWg+AfmJs0Cr3RT6rwlB1+FBd9Jj/Wh6FaAlxA8zWYOK 8PCImLpCIf67+6RKWRqirskmrzJHlpCX58W0l1XYCQFgI/M0pSlolWVmkYA4IfFS Xd6+dIL91kgh1g9uprqkOpJVZ32EdEpZDPCua9zmiPOI8roTseVpy7k+t68n1seI /hBfOpVst7+lpapitpL0NXh+T+fxEdDKXlTFskYb5Y2VlQWqA7OZgvW+NZWi3G2e /DU8/HRTo9A8u0Um4vtFu5NuXjwXuxT8fvW6UEK+gjGYlzlEhjmLWa1VZU1WVfq9 mZY3Ab1fYLX600qNiP46Jr74rGv6Af3/ivpYSIEKkrvzwmmJ1RUNKiaH+mqw4on7 oz0bIWfvABI7lyVSmSphSIIqGicZCvX+AZoUAW33NUDWk9astcByqnpL3DQqdlef NnncSez0ecE=HxAk -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Red Hat Product Security evaluates OpenShift Serverless 1.21.0 revision as moderate, highlighting vital patches and enhancements.. OpenShift Serverless Update, Red Hat Security Impact, Product Releases. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 24, 2022 Important Red Hat
98

RedHat OpenShift Serverless 1.21.0 Update RHSA-2022:1056-01 Moderate Threat

Release of OpenShift Serverless Client kn 1.21.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of OpenShift Serverless Client kn 1.21.0 Advisory ID: RHSA-2022:1056-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2022:1056 Issue date: 2022-03-24 CVE Names: CVE-2021-44716 CVE-2021-44717 ==================================================================== 1. Summary: Release of OpenShift Serverless Client kn 1.21.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Serverless Client kn 1.21.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.21.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms. Security Fix(es): * golang: syscall: don't close fd 0 on ForkExec error (CVE-2021-44717) * golang: net/http: limit growth of header canonicalization cache (CVE-2021-44716) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: See the Red Hat OpenShift Container Platform 4.6 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.7 documentationat: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.8 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.9 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.10 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 5. Bugs fixed (https://bugzilla.redhat.com/): 2030801 - CVE-2021-44716 golang: net/http: limit growth of header canonicalization cache 2030806 - CVE-2021-44717 golang: syscall: don't close fd 0 on ForkExec error 2054716 - Release of Openshift Serverless Client 1.21.0 6. Package List: Openshift Serverless 1 on RHEL 8Base: Source: openshift-serverless-clients-1.0.0-2.el8.src.rpm ppc64le: openshift-serverless-clients-1.0.0-2.el8.ppc64le.rpm s390x: openshift-serverless-clients-1.0.0-2.el8.s390x.rpm x86_64: openshift-serverless-clients-1.0.0-2.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-44716 https://access.redhat.com/security/cve/CVE-2021-44717 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYjziy9zjgjWX9erEAQiXOg/+JBwhDnuT94yLPdg3aoFpTU90KrQZwlEG oLob/u8hWTAd+TuGV7od/ExZg8G7PyhqNamjGBRx+1xdW6Ou+zCoEIefqNqconJJ 6+V/RLZFFi4GV1JRZJi+IHUzUc7+I2trGnM+MTIAJiAz4CGAzcAtyoMlI/GZTEr/ /q9sw4s1jjSSbpQ0UNGDaO/tiRz66hmYJrrXEFpxxzgZWMMPoaUdXdtbNGnFxWBs 9g2hiXk6ThuoFQKT6RiqaNwkBIEbZNBQeZuJY6iRvCMczu8S6+vXI7NvJIjuUmkF M8cqxTdVmgH6ai2LsA9PZRRNgN2Xee2p0VJx7f1hyhT5cYooNF5xc5tu+bIbnzXg xxX1c7d8jCUjAwWAyj0hd+Z6vorLR4OJME9F90Yk0vecNpQrhooEp/PB9RLVKtsA /goPGG2au0WzbqYPl/1wpZuXRDdvki7NeuG36nUVwY3VOBZAYtmFDymTK/1XIJMs 18Ju/peeZBwnKwxnAqC5+wU+Vf8nVE9NiMWAJtQrU4lSmHQb1gh7NbKxCOlkG046 ew5Nyl/1g7NjxHbMReASs2u4oli7H8VAnzzpstDdbtU+Twsp+nZXW4yHfd5E8gP4 saygg+q/sFzNc8IinaXJTPW0mG0NSauPFmBHb9iNFF/gL0hEVAe/LDh9ikvyltf9 DAh6MvQ7G5Q=gg0B -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Stay secure with OpenShift Serverless Client update 1.21.0, addressing security flaws and enhancing functionality for safer deployments and better compliance. Openshift Serverless Client Update, Red Hat Openshift Security, Serverless CVE Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 24, 2022 Important Red Hat
98

RedHat: RHSA-2021-4765 Moderate: OpenShift Serverless Client 1.19.0 Release

Release of OpenShift Serverless Client kn 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of OpenShift Serverless Client kn 1.19.0 Advisory ID: RHSA-2021:4765-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2021:4765 Issue date: 2021-11-23 CVE Names: CVE-2021-36221 ==================================================================== 1. Summary: Release of OpenShift Serverless Client kn 1.19.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Openshift Serverless 1 on RHEL 8Base - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Serverless Client kn 1.19.0 provides a CLI to interact with Red Hat OpenShift Serverless 1.19.0. The kn CLI is delivered as an RPM package for installation on RHEL platforms, and as binaries for non-Linux platforms. Security Fix(es): * golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: See the Red Hat OpenShift Container Platform 4.6 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.7 documentationat: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.8 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 See the Red Hat OpenShift Container Platform 4.9 documentation at: https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 5. Bugs fixed (https://bugzilla.redhat.com/): 1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic 2016255 - Release of Openshift Serverless Client 1.19.0 6. Package List: Openshift Serverless 1 on RHEL 8Base: Source: openshift-serverless-clients-0.25.1-1.el8.src.rpm ppc64le: openshift-serverless-clients-0.25.1-1.el8.ppc64le.rpm s390x: openshift-serverless-clients-0.25.1-1.el8.s390x.rpm x86_64: openshift-serverless-clients-0.25.1-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-36221 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 https://docs.redhat.com/en/documentation/red_hat_openshift_serverless/1.33 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYZz9oNzjgjWX9erEAQhjew/9EeAac0uiyEFP58IN3qHHpbt0x3iv2Sc8 dI5/d9sh1KZ9H7VEm00eSnDkeCofUzP7cseTAOcpk5cQ/22hO3yfDZqnZE6ORNYw VwVreCFcsMfDhnEPsanEaT1395dH8o3uFqx9o9C+qedhJFabfYNN7CVtVRW1H6xg NOqAhjv56YJh9bLkdytwzOsDfb7eU8WLoNusqKZCVJixFbBdTSMkyCAETVyDhl8p 8dSUDNHIhK+o7QwUScPzrAH5jiT4VKQgZVaVAH4NDtcYHaoG2pcdqCHIuTY49N7R ZZo3mEZBxaeuZXchJ2CxGPLqanOXn78TdILVHbZ5inbXaZ9aMDjfzEZkVRCNssBW d7Nxl5bRAqzgNwjbrKHls2ssBxe1F8X6t/5yOtBdZGVmDgXZGSl2/U2yaO9kA2Qv 7GRagWTKJAv9APoaj2ILarUO+Gf410G4Cpc0OEN45Glp7tqW/PpI65B4fEZGnhFH 37kLzeTHm+aOpLcxyCc3I3uVrTtD23mf7vwUj3O8AURQRng8WwymWxOuza7Eo2iz rX46zJF9TOxeGcHJ3Ykl9BDR3gQh6pQ9ccTjFFz0vrev8X7YHbhUvDDgGmK/5xya voswqaVuwD37RjzmF7t65PC+XOyt9A++Vo2/XfbUfkRLIgytx+UkQa7CjGDd8nvu /YGicfc9BgQ=TWiE -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the details regarding the release of OpenShift Serverless Client kn 1.19.0 with a moderate security impact rating.. OpenShift Serverless, Client Update, Red Hat Advisory, Security Impact, Serverless Client Release. . LinuxSecurity.com Team

Calendar 2 Nov 23, 2021 Red Hat
98

Red Hat OpenShift 1.14.1 RHSA-2021:2093-01 Moderate Risks in Serverless Ops

An update for openshift-serverless-1-kn-cli-artifacts-rhel8-container, openshift-serverless-1-knative-rhel8-operator-container, and openshift-serverless-1-serverless-operator-bundle-container is now available for Openshift Serveless 1.14.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of OpenShift Serverless 1.14.1 security update Advisory ID: RHSA-2021:2093-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2021:2093 Issue date: 2021-05-24 CVE Names: CVE-2021-3114 CVE-2021-3115 ==================================================================== 1. Summary: An update for openshift-serverless-1-kn-cli-artifacts-rhel8-container, openshift-serverless-1-knative-rhel8-operator-container, and openshift-serverless-1-serverless-operator-bundle-container is now available for Openshift Serveless 1.14. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Serverless 1.14.1 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6 and 4.7, and includes security and bug fixes and enhancements. For more information, see the documentation listed in the References section. Security Fix(es): * golang: crypto/elliptic: incorrect operations on the P-224 curve (CVE-2021-3114) * golang: cmd/go: packages using cgo can cause arbitrary code execution at build time (CVE-2021-3115) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to theCVE page(s) listed in the References section. 3. Solution: See the Red Hat OpenShift Container Platform 4.6 documentation at: https://access.redhat.com/documentation/en-us/openshift_container_platform/ 4.6/html/serverless/index See the Red Hat OpenShift Container Platform 4.7 documentation at: https://access.redhat.com/documentation/en-us/openshift_container_platform/ 4.7/html/serverless/index 4. Bugs fixed (https://bugzilla.redhat.com/): 1918750 - CVE-2021-3114 golang: crypto/elliptic: incorrect operations on the P-224 curve 1918761 - CVE-2021-3115 golang: cmd/go: packages using cgo can cause arbitrary code execution at build time 5. References: https://access.redhat.com/security/cve/CVE-2021-3114 https://access.redhat.com/security/cve/CVE-2021-3115 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYKulBtzjgjWX9erEAQjm/hAAlFWbvMzsbylfgz8oXCZ5BBNoUDCNDRFB AVu5C41w03Mi8pdur/xiGE1Vj64Hd/ldcbIgpqTqPyAVWV33/YRdN/Rt6y4LIqDm Dcp0YH8ADA7CMicXZEo2VZyoIm9F2f1NpX7zNF3AWJ6hqUEdabPKZTVj12XK+uNw spD6PhTlskKDImSIuM8oZvEPiVTlSNrOxVyN21m70NsLOb4fLJI3OLKaj/N3oJ9Z 8mJnPvgkketwshSgsAmXowMmWJ+/3FCBctvZyR9iPpY0l4dpItsNonHYOP5Qzhpr 8/J+atCEMgK3WXJxgZ+aq5osPgI7pIqfoVBy3iv87YjMoEAUX0/y5JCHhzhq13mC LtF3LLSVb7BQzMZuPJmGN3sjG5Ep7LDyl030TuAb/phpggucJ3ZAzrB77mMK5+il AaaW/v4wtWdcXMCezz8dQr2iWrHd2zdSf94UgOgSHXvw0RluXhFalqJKhtzQ2q+V 6ykKF4LOCPf7Cl0BD1SOi5KuAj2CK22rf4SLq5EvZ02JJPieYQQxiKnJ53Ucfo1b sH8q59wpM9UjktBWs8GK1iPdfcfVyuCF61bCgH/AZHv1m+7NeFSmjPSkO5vWFwhE 6r28oEn2zyOJNjhI4cPlyuN1JckgGJhTkyF8YtHxiSSgE2gM2kl2oXOPmeFWmabO btflHE/tbT4=9XfM -----END PGP SIGNATURE----- -- RHSA-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . Uncover vital security improvements in Red Hat OpenShift Serverless 1.14.1 that bolster important container infrastructure.. OpenShift Serverless, Red Hat Advisory, Container Security, Serverless Threats. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 24, 2021 Important Red Hat
98

OpenShift Security Advisory RHSA-2021:0146-01 for Serverless 1.12.0

Release of OpenShift Serverless 1.12.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Release of OpenShift Serverless 1.12.0 Advisory ID: RHSA-2021:0146-01 Product: Red Hat OpenShift Serverless Advisory URL: https://access.redhat.com/errata/RHSA-2021:0146 Issue date: 2021-01-14 CVE Names: CVE-2018-20843 CVE-2019-5018 CVE-2019-13050 CVE-2019-13627 CVE-2019-14889 CVE-2019-15903 CVE-2019-16168 CVE-2019-19221 CVE-2019-19906 CVE-2019-19956 CVE-2019-20218 CVE-2019-20387 CVE-2019-20388 CVE-2019-20454 CVE-2020-1730 CVE-2020-1751 CVE-2020-1752 CVE-2020-1971 CVE-2020-6405 CVE-2020-7595 CVE-2020-9327 CVE-2020-10029 CVE-2020-13630 CVE-2020-13631 CVE-2020-13632 CVE-2020-24553 CVE-2020-24659 CVE-2020-28362 CVE-2020-28366 CVE-2020-28367 ==================================================================== 1. Summary: Release of OpenShift Serverless 1.12.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. For more information, see the CVE links in the References section. 2. Description: Red Hat OpenShift Serverless 1.12.0 is a generally available release of the OpenShift Serverless Operator. This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform version 4.6, and includes security and bug fixes and enhancements. For more information, see thedocumentation listed in the References section. Security Fix(es): * golang: default Content-Type setting in net/http/cgi and net/http/fcgi could cause XSS (CVE-2020-24553) * golang: math/big: panic during recursive division of very large numbers(CVE-2020-28362) * golang: malicious symbol names can lead to code execution at build time (CVE-2020-28366) * golang: improper validation of cgo flags can lead to code execution at build time (CVE-2020-28367) For more details about the security issues and their impact, the CVSS score, acknowledgements, and other related information, see the CVE pages listed in the References section. 3. Solution: See the documentation at: https://docs.redhat.com/en/documentation/openshift_container_platform/4.21 4.6/html/serverless_applications/index 4. Bugs fixed (https://bugzilla.redhat.com/): 1874857 - CVE-2020-24553 golang: default Content-Type setting in net/http/cgi and net/http/fcgi could cause XSS 1897635 - CVE-2020-28362 golang: math/big: panic during recursive division of very large numbers1897643 - CVE-2020-28366 golang: malicious symbol names can lead to code execution at build time 1897646 - CVE-2020-28367 golang: improper validation of cgo flags can lead to code execution at build time 1906381 - Release of OpenShift Serverless Serving 1.12.0 1906382 - Release of OpenShift Serverless Eventing 1.12.0 5.References: https://access.redhat.com/security/cve/CVE-2018-20843 https://access.redhat.com/security/cve/CVE-2019-5018 https://access.redhat.com/security/cve/CVE-2019-13050 https://access.redhat.com/security/cve/CVE-2019-13627 https://access.redhat.com/security/cve/CVE-2019-14889 https://access.redhat.com/security/cve/CVE-2019-15903 https://access.redhat.com/security/cve/CVE-2019-16168 https://access.redhat.com/security/cve/CVE-2019-19221 https://access.redhat.com/security/cve/CVE-2019-19906 https://access.redhat.com/security/cve/CVE-2019-19956 https://access.redhat.com/security/cve/CVE-2019-20218 https://access.redhat.com/security/cve/CVE-2019-20387 https://access.redhat.com/security/cve/CVE-2019-20388 https://access.redhat.com/security/cve/CVE-2019-20454 https://access.redhat.com/security/cve/CVE-2020-1730 https://access.redhat.com/security/cve/CVE-2020-1751 https://access.redhat.com/security/cve/CVE-2020-1752 https://access.redhat.com/security/cve/CVE-2020-1971 https://access.redhat.com/security/cve/CVE-2020-6405 https://access.redhat.com/security/cve/CVE-2020-7595 https://access.redhat.com/security/cve/CVE-2020-9327 https://access.redhat.com/security/cve/CVE-2020-10029 https://access.redhat.com/security/cve/CVE-2020-13630 https://access.redhat.com/security/cve/CVE-2020-13631 https://access.redhat.com/security/cve/CVE-2020-13632 https://access.redhat.com/security/cve/CVE-2020-24553 https://access.redhat.com/security/cve/CVE-2020-24659 https://access.redhat.com/security/cve/CVE-2020-28362 https://access.redhat.com/security/cve/CVE-2020-28366 https://access.redhat.com/security/cve/CVE-2020-28367 https://access.redhat.com/security/updates/classification#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYAB9FtzjgjWX9erEAQhy4w/8DkWBfDN8NTwDn5G3DQm7avlhwkCoRMUQ Vt2xCRU6oj06m1xmmixHjbXldN9E8xmJCA9MPfRolKfqFvgxgLs0ZfQNo51qZu2B IlnB/flgg2xT6j5LRSB6gUILkgeKnnTQOoldrc6W4snz+TwPxVUDGLWx4UlaO2n1 giniC6RESaACoMBZYijKjaM/PAo665Fajfs91bgcg7YnnYtu6Zbs561CoRDg7rR1 nC9zqJDfPQXj01GhKqkscVxDjhWRxo9Dvk7bdT9fSMK9o6EZiRnE4HXNm4FjzLIw FXQ1Pd7T6Car3iwN0ZMRLn/aEYPzc3h4d3tAMQj+NwHLX0MnXB61+e2bkoFGEluF PCTis0uhfQaL9unbrQ1NVKMMcbbztlGh9hjY//RLX/aTvYrGqi2sBlnA6n14dRPy rc6fdK3GdVI4doC1SnIMI7ZvWv3Jt5Wq5l/AnxWm/+pn68ibIMPyC0vU82bffUtA aiei6JPY7u3O+JqrlQYVQ2tICySnM2bEbP98emg0bedzkD9JfFOQpg8sxkm+V1qm Tu2xl/v5jHr70nICzVUF3paztwCvMyeD63pYbtWXPqQmc1IIpCUgTQQwpC+G93Uf wu2FJ4Vqb2tiqRkI4Ju3WJd1qKyTz+83pkuKHwe845n7D8kRFxEYpmE50lT7eAab A3H5xDIIYLk=2gLp -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security notice regarding the launch of OpenShift Serverless version 1.12.0. Significant updates enhance the security of applications overall.. OpenShift Serverless, Red Hat Update, Application Security, Golang Fixes, Moderate Rating. . LinuxSecurity.com Team

Calendar 2 Jan 14, 2021 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here