Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12069 https://linux.oracle.com/errata/ELSA-2024-12069.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-core-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-debug-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-doc-4.18.0-513.11.0.1.el8_9.noarch.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-modules-extra-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.x86_64.rpm perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.x86_64.rpm kernel-abi-stablelists-4.18.0-513.11.0.1.el8_9.noarch.rpm aarch64: bpftool-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-cross-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-headers-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-4.18.0-513.11.0.1.el8_9.aarch64.rpm perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm python3-perf-4.18.0-513.11.0.1.el8_9.aarch64.rpm kernel-tools-libs-devel-4.18.0-513.11.0.1.el8_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//kernel-4.18.0-513.11.0.1.el8_9.src.rpm Related CVEs: CVE-2023-2162 CVE-2023-4622 CVE-2023-42753 Description of changes: [4.18.0-513.11.1.0.1.el8_9.OL8] - scsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress{CVE-2023-2162} - af_unix: Fix null-ptr-deref in unix_stream_sendpage() {CVE-2023-4622} - netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet {CVE-2023-42753} _______________________________________________ El-errata mailing list
This kernel-linus update is based on upstream 5.15.122 and fixes atleast the following security issues: Under specific microarchitectural circumstances, a register in "Zen 2" CPUs may not be written to 0 correctly. This may cause data from another . MGASA-2023-0243 - Updated kernel-linus packages fix security vulnerabilities Publication date: 26 Jul 2023 URL: https://advisories.mageia.org/MGASA-2023-0243.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-20593, CVE-2023-31248, CVE-2023-35001 This kernel-linus update is based on upstream 5.15.122 and fixes atleast the following security issues: Under specific microarchitectural circumstances, a register in "Zen 2" CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information (CVE-2023-20593, also known as Zenbleed). This update adds a kernel-side mitigation for this issue to protect users until Amd gets their fixed microcode / AGESA updates out for all affected CPUs. The fixed microcode for Amd EPYC gen2 is available in the microcode-0.20230613-2.mga8.nonfree package. For other affected CPUs, see the referenced amd.com url that has info about estimated microcode update timelines for various CPUs. Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; nft_chain_lookup_byid() failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace (CVE-2023-31248). Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace (CVE-2023-35001). For other upstream fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=32140 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.121 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.122 -https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html - https://www.cve.org/CVERecord?id=CVE-2023-20593 - https://www.cve.org/CVERecord?id=CVE-2023-31248 - https://www.cve.org/CVERecord?id=CVE-2023-35001 SRPMS: - 8/core/kernel-linus-5.15.122-1.mga8 . The recent kernel-linus patch in Mageia tackles critical vulnerabilities that could lead to serious data leaks and unauthorized privilege elevation.. Mageia Security Update,Kernels,Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in tcpdump.. =========================================================================Ubuntu Security Notice USN-5331-1 March 16, 2022 tcpdump vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in tcpdump. Software Description: - tcpdump: command-line network traffic analyzer Details: It was discovered that tcpdump incorrectly handled certain inputs. An attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary code. (CVE-2018-16301) It was discovered that tcpdump incorrectly handled certain captured data. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-8037) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: tcpdump 4.9.3-0ubuntu0.16.04.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5331-1 CVE-2018-16301, CVE-2020-8037 . Numerous vulnerabilities in tcpdump have been patched in Ubuntu 16.04 ESM. Ensure your system is updated to safeguard against possible threats.. Ubuntu Security, Tcpdump Update, Network Analyzer Threats. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-5094-2 September 30, 2021 linux-raspi2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi2: Linux kernel for Raspberry Pi systems Details: It was discovered that the KVM hypervisor implementation in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. An attacker who could start and control a VM could possibly use this to expose sensitive information or execute arbitrary code. (CVE-2021-22543) It was discovered that the tracing subsystem in the Linux kernel did not properly keep track of per-cpu ring buffer state. A privileged attacker could use this to cause a denial of service. (CVE-2021-3679) Alois Wohlschlager discovered that the overlay file system in the Linux kernel did not restrict private clones in some situations. An attacker could use this to expose sensitive information. (CVE-2021-3732) It was discovered that the MAX-3421 host USB device driver in the Linux kernel did not properly handle device removal events. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-38204) It was discovered that the Xilinx 10/100 Ethernet Lite device driver in the Linux kernel could report pointer addresses in some situations. An attacker could use this information to ease the exploitation of another vulnerability. (CVE-2021-38205) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1096-raspi2 4.15.0-1096.102 linux-image-raspi2 4.15.0.1096.94 After a standard system update you need to reboot yourcomputer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-5094-2 https://ubuntu.com/security/notices/USN-5094-1 CVE-2021-22543, CVE-2021-3679, CVE-2021-3732, CVE-2021-38204, CVE-2021-38205 Package Information: https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1096.102 . Essential patches address kernel flaws in Ubuntu 18.04 LTS. Update immediately to avert service disruptions and safeguard data breaches.. Kernel Security Issues, Ubuntu 18.04 LTS, Linux Raspberry Pi. . Severity: Important. LinuxSecurity.com Team
Update to Samba 4.13.8 - Security fixes for CVE-2021-20254. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1d0807008b 2021-05-07 00:47:07.535360 --------------------------------------------------------------------------------Name : samba Product : Fedora 33 Version : 4.13.8 Release : 0.fc33 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. --------------------------------------------------------------------------------Update Information: Update to Samba 4.13.8 - Security fixes for CVE-2021-20254 --------------------------------------------------------------------------------ChangeLog: * Thu Apr 29 2021 Guenther Deschner - 4.13.8-0 - Update to Samba 4.13.8 - resolves: #1949442, #1955027 - Security fixes for CVE-2021-20254 --------------------------------------------------------------------------------References: [ 1 ] Bug #1949442 - CVE-2021-20254 samba: Negative idmap cache entries can cause incorrect group entries in the Samba file server process token https://bugzilla.redhat.com/show_bug.cgi?id=1949442 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1d0807008b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Latest upstream.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-7aba37f66a 2020-05-20 03:48:04.197873 --------------------------------------------------------------------------------Name : moodle Product : Fedora 30 Version : 3.6.10 Release : 1.fc30 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Latest upstream. --------------------------------------------------------------------------------ChangeLog: * Mon May 11 2020 Gwyn Ciesla - 3.6.10-1 - 3.6.10 --------------------------------------------------------------------------------References: [ 1 ] Bug #1837582 - CVE-2020-10738 moodle: remote code execution possible via SCORM packages (MSA-20-0006) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1837582 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-7aba37f66a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4411-1
Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-3174-1 January 19, 2017 mysql-5.5, mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database - mysql-5.5: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. Ubuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html https://www.oracle.com/security-alerts/cpujan2017.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: mysql-server-5.7 5.7.17-0ubuntu0.16.10.1 Ubuntu 16.04 LTS: mysql-server-5.7 5.7.17-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.12.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2016-8318, CVE-2016-8327, CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3251, CVE-2017-3256, CVE-2017-3258, CVE-2017-3265, CVE-2017-3273, CVE-2017-3291, CVE-2017-3312, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3319, CVE-2017-3320 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.12.04.1 . Several problems addressed in MySQL for Ubuntu versions 16.10, 16.04, 14.04, and 12.04, with crucial patches detailed for every iteration.. MySQL Security Issues, Ubuntu Updates, Database Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.