Moderate: glib2 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:6464", "synopsis": "Moderate: glib2 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for glib2.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "GLib provides the core application building blocks for libraries and applications written in C. It provides the core object system used in GNOME, the main loop implementation, and a large set of utility functions for strings and common data structures.\n\nSecurity Fix(es):\n\n* glib2: Signal subscription vulnerabilities (CVE-2024-34397)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2279632", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2279632", "description": ""}], "cves": [{"name": "CVE-2024-34397", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-34397", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-09-17T00:55:53.927829Z", "rpms": {"Rocky Linux 9": {"nvras": ["glib2-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-0:2.68.4-14.el9_4.1.i686.rpm", "glib2-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-0:2.68.4-14.el9_4.1.src.rpm", "glib2-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-debuginfo-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-debuginfo-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-debuginfo-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-debuginfo-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-debugsource-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-debugsource-0:2.68.4-14.el9_4.1.ppc64le.rpm","glib2-debugsource-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-debugsource-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-devel-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-devel-0:2.68.4-14.el9_4.1.i686.rpm", "glib2-devel-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-devel-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-devel-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-devel-debuginfo-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-devel-debuginfo-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-devel-debuginfo-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-devel-debuginfo-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-doc-0:2.68.4-14.el9_4.1.noarch.rpm", "glib2-static-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-static-0:2.68.4-14.el9_4.1.i686.rpm", "glib2-static-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-static-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-static-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-tests-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-tests-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-tests-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-tests-0:2.68.4-14.el9_4.1.x86_64.rpm", "glib2-tests-debuginfo-0:2.68.4-14.el9_4.1.aarch64.rpm", "glib2-tests-debuginfo-0:2.68.4-14.el9_4.1.ppc64le.rpm", "glib2-tests-debuginfo-0:2.68.4-14.el9_4.1.s390x.rpm", "glib2-tests-debuginfo-0:2.68.4-14.el9_4.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Recent glib2 security patch made available for Rocky Linux 9. Stay updated on specifics and resolutions to safeguard your environment.. glib2 Security Update, Rocky Linux Advisory, Moderate Vulnerability Fix, Security Update Notification. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-6464 http://linux.oracle.com/errata/ELSA-2024-6464.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: glib2-2.68.4-14.el9_4.1.i686.rpm glib2-2.68.4-14.el9_4.1.x86_64.rpm glib2-devel-2.68.4-14.el9_4.1.i686.rpm glib2-devel-2.68.4-14.el9_4.1.x86_64.rpm glib2-doc-2.68.4-14.el9_4.1.noarch.rpm glib2-tests-2.68.4-14.el9_4.1.x86_64.rpm glib2-static-2.68.4-14.el9_4.1.i686.rpm glib2-static-2.68.4-14.el9_4.1.x86_64.rpm aarch64: glib2-2.68.4-14.el9_4.1.aarch64.rpm glib2-devel-2.68.4-14.el9_4.1.aarch64.rpm glib2-doc-2.68.4-14.el9_4.1.noarch.rpm glib2-tests-2.68.4-14.el9_4.1.aarch64.rpm glib2-static-2.68.4-14.el9_4.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//glib2-2.68.4-14.el9_4.1.src.rpm Related CVEs: CVE-2024-34397 Description of changes: [2.68.4-14.1] - Fix CVE-2024-34397, signal subscription vulnerabilities - Resolves: RHEL-56979 _______________________________________________ El-errata mailing list
Update glib2 to fix CVE-2024-34397.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2ce1c754f7 2024-05-16 01:50:39.118643 -------------------------------------------------------------------------------- Name : mingw-glib2 Product : Fedora 40 Version : 2.80.1 Release : 1.fc40 URL : http://www.gtk.org Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. -------------------------------------------------------------------------------- Update Information: Update glib2 to fix CVE-2024-34397. -------------------------------------------------------------------------------- ChangeLog: * Tue May 7 2024 Sandro Mani - 2.80.1-1 - Update to 2.80.1 * Sat Mar 23 2024 Sandro Mani - 2.80.0-1 - Update to 2.80.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2279641 - CVE-2024-34397 mingw-glib2: glib2: Signal subscription vulnerabilities [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2279641 [ 2 ] Bug #2279642 - CVE-2024-34397 mingw-glib2: glib2: Signal subscription vulnerabilities [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2279642 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2ce1c754f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update glib2 to fix CVE-2024-34397.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-be032e564d 2024-05-16 01:08:08.062527 -------------------------------------------------------------------------------- Name : mingw-glib2 Product : Fedora 39 Version : 2.78.5 Release : 1.fc39 URL : http://www.gtk.org Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. -------------------------------------------------------------------------------- Update Information: Update glib2 to fix CVE-2024-34397. -------------------------------------------------------------------------------- ChangeLog: * Tue May 7 2024 Sandro Mani - 2.78.5-1 - Update to 2.78.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2279641 - CVE-2024-34397 mingw-glib2: glib2: Signal subscription vulnerabilities [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2279641 [ 2 ] Bug #2279642 - CVE-2024-34397 mingw-glib2: glib2: Signal subscription vulnerabilities [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2279642 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-be032e564d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.