Explore top 10 tips to secure your open-source projects now. Read More
×DPDK could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7178-1 December 19, 2024 dpdk vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: DPDK could be made to crash if it received specially crafted network traffic. Software Description: - dpdk: set of libraries for fast packet processing Details: It was discovered that DPDK incorrectly handled the Vhost library checksum offload feature. An malicious guest could possibly use this issue to cause the hypervisor's vSwitch to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 dpdk 23.11.2-0ubuntu1.1 Ubuntu 24.04 LTS dpdk 23.11-1ubuntu0.1 Ubuntu 22.04 LTS dpdk 21.11.6-0ubuntu0.22.04.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7178-1 CVE-2024-11614 Package Information: https://launchpad.net/ubuntu/+source/dpdk/23.11.2-0ubuntu1.1 https://launchpad.net/ubuntu/+source/dpdk/21.11.6-0ubuntu0.22.04.2 . Ubuntu Security Notice USN-7179-1 highlights vulnerabilities in OpenSSL due to specifically designed requests that could lead to service disruptions.. dpdk updates, Ubuntu security patches, network exploit details. . Severity: Critical. LinuxSecurity.com Team
Avahi could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6487-1 November 20, 2023 avahi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Avahi could be made to crash if it received specially crafted input. Software Description: - avahi: IPv4LL network address configuration daemon Details: Evgeny Vereshchagin discovered that Avahi contained several reachable assertions, which could lead to intentional assertion failures when specially crafted user input was given. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: avahi-daemon 0.8-10ubuntu1.1 libavahi-client3 0.8-10ubuntu1.1 libavahi-common3 0.8-10ubuntu1.1 libavahi-core7 0.8-10ubuntu1.1 Ubuntu 23.04: avahi-daemon 0.8-6ubuntu1.23.04.2 libavahi-client3 0.8-6ubuntu1.23.04.2 libavahi-common3 0.8-6ubuntu1.23.04.2 libavahi-core7 0.8-6ubuntu1.23.04.2 Ubuntu 22.04 LTS: avahi-daemon 0.8-5ubuntu5.2 libavahi-client3 0.8-5ubuntu5.2 libavahi-common3 0.8-5ubuntu5.2 libavahi-core7 0.8-5ubuntu5.2 Ubuntu 20.04 LTS: avahi-daemon 0.7-4ubuntu7.3 libavahi-client3 0.7-4ubuntu7.3 libavahi-common3 0.7-4ubuntu7.3 libavahi-core7 0.7-4ubuntu7.3 Ubuntu 18.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.7-3.1ubuntu1.3+esm2 libavahi-client3 0.7-3.1ubuntu1.3+esm2 libavahi-common3 0.7-3.1ubuntu1.3+esm2 libavahi-core7 0.7-3.1ubuntu1.3+esm2 Ubuntu 16.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-client3 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-common3 0.6.32~rc+dfsg-1ubuntu2.3+esm3 libavahi-core7 0.6.32~rc+dfsg-1ubuntu2.3+esm3 Ubuntu 14.04 LTS (Available with Ubuntu Pro): avahi-daemon 0.6.31-4ubuntu1.3+esm3 libavahi-client3 0.6.31-4ubuntu1.3+esm3 libavahi-common3 0.6.31-4ubuntu1.3+esm3 libavahi-core7 0.6.31-4ubuntu1.3+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6487-1 CVE-2023-38469, CVE-2023-38470, CVE-2023-38471, CVE-2023-38472, CVE-2023-38473 Package Information: https://launchpad.net/ubuntu/+source/avahi/0.8-10ubuntu1.1 https://launchpad.net/ubuntu/+source/avahi/0.8-6ubuntu1.23.04.2 https://launchpad.net/ubuntu/+source/avahi/0.8-5ubuntu5.2 https://launchpad.net/ubuntu/+source/avahi/0.7-4ubuntu7.3 . Upgrade your Ubuntu system to resolve serious vulnerabilities in Avahi triggered by specially designed inputs, which may result in possible system failures.. Avahi Vulnerabilities, Denial of Service, Service Crash. . Severity: Critical. LinuxSecurity.com Team
AccountsService could be made to crash or run programs if it received specially crafted messages.. ========================================================================== Ubuntu Security Notice USN-6190-2 September 25, 2023 accountsservice vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: AccountsService could be made to crash or run programs if it received specially crafted messages. Software Description: - accountsservice: query and manipulate user account information Details: USN-6190-1 fixed a vulnerability in AccountsService. This update provides the corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: Kevin Backhouse discovered that AccountsService incorrectly handled certain D-Bus messages. A local attacker could use this issue to cause AccountsService to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.45-1ubuntu1.3+esm1 libaccountsservice0 0.6.45-1ubuntu1.3+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.40-2ubuntu11.6+esm1 libaccountsservice0 0.6.40-2ubuntu11.6+esm1 Ubuntu 14.04 LTS (Available with Ubuntu Pro): accountsservice 0.6.35-0ubuntu7.3+esm3 libaccountsservice0 0.6.35-0ubuntu7.3+esm3 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6190-2 https://ubuntu.com/security/notices/USN-6190-1 CVE-2023-3297 . The vulnerability present in the AccountsService could enable local attackers tocompromise services or run unrestricted code on Ubuntu machines.. AccountsService Exploit, Ubuntu Security, Denial of Service Risk, Software Update, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for freeradius-server ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4621-1 Rating: important References: #1206204 #1206205 #1206206 Cross-References: CVE-2022-41859 CVE-2022-41860 CVE-2022-41861 CVSS scores: CVE-2022-41859 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2022-41860 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-41861 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for freeradius-server fixes the following issues: - CVE-2022-41859: Fixes an information leakage in EAP-PWD (bsc#1206204). - CVE-2022-41860: Fixes a crash on unknown option in EAP-SIM (bsc#1206205). - CVE-2022-41861: Fixes a crash on invalid abinary data (bsc#1206206). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4621=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-4621=1 Package List: - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): freeradius-server-debuginfo-3.0.19-3.12.1 freeradius-server-debugsource-3.0.19-3.12.1 freeradius-server-devel-3.0.19-3.12.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): freeradius-server-3.0.19-3.12.1 freeradius-server-debuginfo-3.0.19-3.12.1 freeradius-server-debugsource-3.0.19-3.12.1 freeradius-server-doc-3.0.19-3.12.1 freeradius-server-krb5-3.0.19-3.12.1 freeradius-server-krb5-debuginfo-3.0.19-3.12.1 freeradius-server-ldap-3.0.19-3.12.1 freeradius-server-ldap-debuginfo-3.0.19-3.12.1 freeradius-server-libs-3.0.19-3.12.1 freeradius-server-libs-debuginfo-3.0.19-3.12.1 freeradius-server-mysql-3.0.19-3.12.1 freeradius-server-mysql-debuginfo-3.0.19-3.12.1 freeradius-server-perl-3.0.19-3.12.1 freeradius-server-perl-debuginfo-3.0.19-3.12.1 freeradius-server-postgresql-3.0.19-3.12.1 freeradius-server-postgresql-debuginfo-3.0.19-3.12.1 freeradius-server-python-3.0.19-3.12.1 freeradius-server-python-debuginfo-3.0.19-3.12.1 freeradius-server-sqlite-3.0.19-3.12.1 freeradius-server-sqlite-debuginfo-3.0.19-3.12.1 freeradius-server-utils-3.0.19-3.12.1 freeradius-server-utils-debuginfo-3.0.19-3.12.1 References: https://www.suse.com/security/cve/CVE-2022-41859.html https://www.suse.com/security/cve/CVE-2022-41860.html https://www.suse.com/security/cve/CVE-2022-41861.html https://bugzilla.suse.com/1206204 https://bugzilla.suse.com/1206205 https://bugzilla.suse.com/1206206 . New release for freeradius-server tackles three significant vulnerabilities. Check out the specifics regarding the security flaws and the implemented corrections.. FreeRADIUS Server Fixes,SUSE Patch Instructions,Enterprise Security Updates. . Severity: Important. LinuxSecurity.com Team
Heimdal could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-5766-1 December 07, 2022 heimdal vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM - Ubuntu 14.04 ESM Summary: Heimdal could be made to crash if it received specially crafted network traffic. Software Description: - heimdal: Heimdal Kerberos Network Authentication Protocol Details: It was discovered that Heimdal did not properly manage memory when normalizing Unicode. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libwind0-heimdal 7.7.0+dfsg-1ubuntu1.2 Ubuntu 18.04 LTS: libwind0-heimdal 7.5.0+dfsg-1ubuntu0.2 Ubuntu 16.04 ESM: libwind0-heimdal 1.7~git20150920+dfsg-4ubuntu1.16.04.1+esm2 Ubuntu 14.04 ESM: libwind0-heimdal 1.6~git20131207+dfsg-1ubuntu1.2+esm2 After a standard system update you need to restart any application using Heimdal libraries to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5766-1 CVE-2022-41916 Package Information: https://launchpad.net/ubuntu/+source/heimdal/7.7.0+dfsg-1ubuntu1.2 https://launchpad.net/ubuntu/+source/heimdal/7.5.0+dfsg-1ubuntu0.2 . The Heimdal flaw impacts various Debian releases. Ensure updates are applied quickly to avoid system failures triggered by specific network requests.. Heimdal Vulnerability, Ubuntu Security, Service Crash Risk. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-6763 https://linux.oracle.com/errata/ELSA-2022-6763.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bind-9.16.23-1.el9_0.1.x86_64.rpm bind-chroot-9.16.23-1.el9_0.1.x86_64.rpm bind-dnssec-doc-9.16.23-1.el9_0.1.noarch.rpm bind-dnssec-utils-9.16.23-1.el9_0.1.x86_64.rpm bind-libs-9.16.23-1.el9_0.1.x86_64.rpm bind-license-9.16.23-1.el9_0.1.noarch.rpm bind-utils-9.16.23-1.el9_0.1.x86_64.rpm python3-bind-9.16.23-1.el9_0.1.noarch.rpm bind-devel-9.16.23-1.el9_0.1.i686.rpm bind-devel-9.16.23-1.el9_0.1.x86_64.rpm bind-libs-9.16.23-1.el9_0.1.i686.rpm aarch64: bind-9.16.23-1.el9_0.1.aarch64.rpm bind-chroot-9.16.23-1.el9_0.1.aarch64.rpm bind-dnssec-doc-9.16.23-1.el9_0.1.noarch.rpm bind-dnssec-utils-9.16.23-1.el9_0.1.aarch64.rpm bind-libs-9.16.23-1.el9_0.1.aarch64.rpm bind-license-9.16.23-1.el9_0.1.noarch.rpm bind-utils-9.16.23-1.el9_0.1.aarch64.rpm python3-bind-9.16.23-1.el9_0.1.noarch.rpm bind-devel-9.16.23-1.el9_0.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates/bind-9.16.23-1.el9_0.1.src.rpm Related CVEs: CVE-2022-3080 CVE-2022-38177 CVE-2022-38178 Description of changes: [32:9.16.23-1.1] - Fix possible serve-stale related crash (CVE-2022-3080) - Fix memory leak in ECDSA verify processing (CVE-2022-38177) - Fix memory leak in EdDSA verify processing (CVE-2022-38178) _______________________________________________ El-errata mailing list
Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : grpcurl Product : Fedora 35 Version : 1.8.6 Release : 2.fc35 URL : https://github.com/fullstorydev/grpcurl Summary : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers Description : Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati 1.8.6-2 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several issues were found in ConnMan, a connection manager for embedded devices, that could cause denial of service via service crash or excessive CPU usage. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2915-1
Get the latest Linux and open source security news straight to your inbox.