Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 python-2.7.5-93.el7_9.x86_64.rpm python-debuginfo-2.7.5-93.el7_9.i686.rpm python-debuginfo-2.7.5-93.el7_9.x86_64.rpm python-libs-2.7.5-93.el7_9.i686.rpm [More...]. Synopsis: Important: python security update Advisory ID: SLSA-2023:3555-1 Issue Date: 2023-06-09 CVE Numbers: CVE-2023-24329 -- Security Fix(es): * python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 python-2.7.5-93.el7_9.x86_64.rpm python-debuginfo-2.7.5-93.el7_9.i686.rpm python-debuginfo-2.7.5-93.el7_9.x86_64.rpm python-libs-2.7.5-93.el7_9.i686.rpm python-libs-2.7.5-93.el7_9.x86_64.rpm python-debug-2.7.5-93.el7_9.x86_64.rpm python-devel-2.7.5-93.el7_9.x86_64.rpm python-test-2.7.5-93.el7_9.x86_64.rpm python-tools-2.7.5-93.el7_9.x86_64.rpm tkinter-2.7.5-93.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical patch released for Python concerning the url blocklisting circumvention vulnerability (CVE-2023-24329) on SL7 x86_64 systems.. Python Security Update, SL7 Security Advisory, Blocklisting Bypass. . Severity: Critical. LinuxSecurity.com Team
systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c (CVE-2022-2526) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 libgudev1-219-78.el7_9.7.i686.rpm libgudev1-219-78.el7_9.7.x86_64.rpm systemd-219-78.el7_9.7.x86_64.rpm systemd-debu [More...]. Synopsis: Important: systemd security update Advisory ID: SLSA-2022:6160-1 Issue Date: 2022-08-25 CVE Numbers: CVE-2022-2526 -- Security Fix(es): * systemd-resolved: use-after-free when dealing with DnsStream in resolved-dns-stream.c (CVE-2022-2526) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 libgudev1-219-78.el7_9.7.i686.rpm libgudev1-219-78.el7_9.7.x86_64.rpm systemd-219-78.el7_9.7.x86_64.rpm systemd-debuginfo-219-78.el7_9.7.i686.rpm systemd-debuginfo-219-78.el7_9.7.x86_64.rpm systemd-libs-219-78.el7_9.7.i686.rpm systemd-libs-219-78.el7_9.7.x86_64.rpm systemd-python-219-78.el7_9.7.x86_64.rpm systemd-sysv-219-78.el7_9.7.x86_64.rpm libgudev1-devel-219-78.el7_9.7.i686.rpm libgudev1-devel-219-78.el7_9.7.x86_64.rpm systemd-devel-219-78.el7_9.7.i686.rpm systemd-devel-219-78.el7_9.7.x86_64.rpm systemd-journal-gateway-219-78.el7_9.7.x86_64.rpm systemd-networkd-219-78.el7_9.7.x86_64.rpm systemd-resolved-219-78.el7_9.7.i686.rpm systemd-resolved-219-78.el7_9.7.x86_64.rpm - Scientific Linux Development Team . A recent security patch identified as SLSA-2022-6160-1 resolves a critical use-after-free vulnerability found in resolved-dns-stream.c, which affects SL7 systems.. Systemd Update, Use-After-Free Threat, SL7 Advisory, Linux Security Fix. . Severity: Critical. LinuxSecurity.com Team
kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) * kernel: buffer overflow in mwifiex_cmd_append_vsie_tlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) * kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) * kernel: use-after-free caused by a malicious U [More...]. Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2020:3220-1 Issue Date: 2020-07-29 CVE Numbers: None -- Security Fix(es): * kernel: kernel: DAX hugepages not considered during mremap (CVE-2020-10757) * kernel: buffer overflow in mwifiex_cmd_append_vsie_tlv function in drivers/net/wireless/marvell/mwifiex/scan.c (CVE-2020-12653) * kernel: heap-based buffer overflow in mwifiex_ret_wmm_get_status function in drivers/net/wireless/marvell/mwifiex/wmm.c (CVE-2020-12654) * kernel: use-after-free caused by a malicious USB device in the drivers/hid/usbhid/hiddev.c driver (CVE-2019-19527) -- SL7 x86_64 bpftool-3.10.0-1127.18.2.el7.x86_64.rpm bpftool-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm kernel-3.10.0-1127.18.2.el7.x86_64.rpm kernel-debug-3.10.0-1127.18.2.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm kernel-debug-devel-3.10.0-1127.18.2.el7.x86_64.rpm kernel-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-1127.18.2.el7.x86_64.rpm kernel-devel-3.10.0-1127.18.2.el7.x86_64.rpm kernel-headers-3.10.0-1127.18.2.el7.x86_64.rpm kernel-tools-3.10.0-1127.18.2.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm kernel-tools-libs-3.10.0-1127.18.2.el7.x86_64.rpm perf-3.10.0-1127.18.2.el7.x86_64.rpm perf-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm python-perf-3.10.0-1127.18.2.el7.x86_64.rpm python-perf-debuginfo-3.10.0-1127.18.2.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-1127.18.2.el7.x86_64.rpm noarch kernel-abi-whitelists-3.10.0-1127.18.2.el7.noarch.rpm kernel-doc-3.10.0-1127.18.2.el7.noarch.rpm - Scientific Linux Development Team . Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2020:3220-1 Issue Date: 20. kernel, hugepages, considered, during, mremap, (cve-2020-10757), buffer, overflo. . Severity: Important. LinuxSecurity.com Team
wireshark: Out-of-bounds read in packet-ldss.c * wireshark: Multiple dissectors could crash (wnpa-sec-2018-36) * wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39) * wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40) * wireshark: SIGCOMP dissector crash in packet-sigcomp.c * wireshark: Radiotap dissector crash * wireshark: Infinite loop in the MM [More...]. Synopsis: Moderate: wireshark security and bug fix update Advisory ID: SLSA-2020:1047-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2018-14368 CVE-2018-7418 CVE-2018-19622 CVE-2018-14341 CVE-2018-16057 CVE-2018-11362 CVE-2018-14340 -- * wireshark: Out-of-bounds read in packet-ldss.c * wireshark: Multiple dissectors could crash (wnpa-sec-2018-36) * wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39) * wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40) * wireshark: SIGCOMP dissector crash in packet-sigcomp.c * wireshark: Radiotap dissector crash * wireshark: Infinite loop in the MMSE dissector -- SL7 x86_64 wireshark-1.10.14-24.el7.x86_64.rpm wireshark-1.10.14-24.el7.i686.rpm wireshark-gnome-1.10.14-24.el7.x86_64.rpm wireshark-debuginfo-1.10.14-24.el7.i686.rpm wireshark-debuginfo-1.10.14-24.el7.x86_64.rpm wireshark-devel-1.10.14-24.el7.i686.rpm wireshark-devel-1.10.14-24.el7.x86_64.rpm - Scientific Linux Development Team . Routine network analyzer security and patch release addressing diverse vulnerabilities and remedies outlined in notice SLSA-2020:1047-1.. wireshark, out-of-bounds, dissectors, crash, bugfix. . LinuxSecurity.com Team
sudo: Stack based buffer overflow when pwfeedback is enabled (CVE-2019-18634) SL7 x86_64 sudo-1.8.23-4.el7_7.2.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.2.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.2.i686.rpm sudo-devel-1.8.23-4.el7_7.2.i686.rpm sudo-devel-1.8.23-4.el7_7.2.x86_64.rpm - Scientific Linux Development Team. Synopsis: Important: sudo security update Advisory ID: SLSA-2020:0540-1 Issue Date: 2020-02-18 CVE Numbers: None -- Security Fix(es): * sudo: Stack based buffer overflow when pwfeedback is enabled (CVE-2019-18634) -- SL7 x86_64 sudo-1.8.23-4.el7_7.2.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.2.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.2.i686.rpm sudo-devel-1.8.23-4.el7_7.2.i686.rpm sudo-devel-1.8.23-4.el7_7.2.x86_64.rpm - Scientific Linux Development Team . Crucial sudo patch resolving a heap overflow vulnerability for SL7 x86_64 platforms.. Sudo Update, Stack Overflow, Security Fix, SL7, Important Advisory. . Severity: Important. LinuxSecurity.com Team
hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm - Scien [More...]. Synopsis: Important: qemu-kvm security, bug fix, and enhancement update Advisory ID: SLSA-2020:0366-1 Issue Date: 2020-02-05 CVE Numbers: None -- Security Fix(es): * hw: TSX Transaction Asynchronous Abort (TAA) (CVE-2019-11135) * QEMU: slirp: heap buffer overflow during packet reassembly (CVE-2019-14378) -- SL7 x86_64 qemu-img-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-common-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-debuginfo-1.5.3-167.el7_7.4.x86_64.rpm qemu-kvm-tools-1.5.3-167.el7_7.4.x86_64.rpm - Scientific Linux Development Team . Critical qemu-kvm security, patch correction, and performance improvement update announcement Advisory ID: SLSA-2020:0456-2.. Queue Management, Asynchronous Transaction, Security Update, Linux Advisory, Kernel Fixes. . Severity: Important. LinuxSecurity.com Team
libX11: Crash on invalid reply in XListExtensions in ListExt.c (CVE-2018-14598) * libX11: Off-by-one error in XListExtensions in ListExt.c (CVE-2018-14599) * libX11: Out of Bounds write in XListExtensions in ListExt.c (CVE-2018-14600) * libxkbcommon: Invalid free in ExprAppendMultiKeysymList resulting in a crash (CVE-2018-15857) * libxkbcommon: Endless recursion in xkbcomp/expr.c resulting [More...]. Synopsis: Moderate: Xorg security and bug fix update Advisory ID: SLSA-2019:2079-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-15856 CVE-2018-15854 CVE-2018-14600 CVE-2018-15859 CVE-2018-14599 CVE-2018-15864 CVE-2018-15862 CVE-2018-15863 CVE-2018-15857 CVE-2018-15861 CVE-2018-14598 CVE-2018-15855 CVE-2018-15853 -- Security Fix(es): * libX11: Crash on invalid reply in XListExtensions in ListExt.c (CVE-2018-14598) * libX11: Off-by-one error in XListExtensions in ListExt.c (CVE-2018-14599) * libX11: Out of Bounds write in XListExtensions in ListExt.c (CVE-2018-14600) * libxkbcommon: Invalid free in ExprAppendMultiKeysymList resulting in a crash (CVE-2018-15857) * libxkbcommon: Endless recursion in xkbcomp/expr.c resulting in a crash (CVE-2018-15853) * libxkbcommon: NULL pointer dereference resulting in a crash (CVE-2018-15854) * libxkbcommon: NULL pointer dereference when handling xkb_geometry (CVE-2018-15855) * libxkbcommon: Infinite loop when reaching EOL unexpectedly resulting in a crash (CVE-2018-15856) * libxkbcommon: NULL pointer dereference when parsing invalid atoms in ExprResolveLhs resulting in a crash (CVE-2018-15859) * libxkbcommon: NULL pointer dereference in ExprResolveLhs resulting in a crash (CVE-2018-15861) * libxkbcommon: NULL pointer dereference in LookupModMask resulting in a crash (CVE-2018-15862) * libxkbcommon: NULL pointer dereference inResolveStateAndPredicate resulting in a crash (CVE-2018-15863) * libxkbcommon: NULL pointer dereference in resolve_keysym resulting in a crash (CVE-2018-15864) -- SL7 x86_64 mesa-libGLw-devel-8.0.0-5.el7.x86_64.rpm mesa-libGLw-devel-8.0.0-5.el7.i686.rpm mesa-libGLw-8.0.0-5.el7.i686.rpm mesa-libGLw-8.0.0-5.el7.x86_64.rpm libxkbcommon-x11-0.7.1-3.el7.x86_64.rpm libX11-devel-1.6.7-2.el7.i686.rpm libxkbcommon-x11-0.7.1-3.el7.i686.rpm gdm-3.28.2-16.el7.i686.rpm libxkbcommon-devel-0.7.1-3.el7.i686.rpm xorg-x11-drv-wacom-0.36.1-3.el7.x86_64.rpm xorg-x11-server-Xorg-1.20.4-7.el7.x86_64.rpm libxkbcommon-0.7.1-3.el7.i686.rpm libX11-1.6.7-2.el7.x86_64.rpm xorg-x11-server-common-1.20.4-7.el7.x86_64.rpm libxkbcommon-devel-0.7.1-3.el7.x86_64.rpm libX11-1.6.7-2.el7.i686.rpm libX11-common-1.6.7-2.el7.noarch.rpm xorg-x11-drv-ati-19.0.1-2.el7.x86_64.rpm xorg-x11-server-Xephyr-1.20.4-7.el7.x86_64.rpm libxkbcommon-0.7.1-3.el7.x86_64.rpm xorg-x11-drv-vesa-2.4.0-3.el7.x86_64.rpm gdm-3.28.2-16.el7.x86_64.rpm libX11-devel-1.6.7-2.el7.x86_64.rpm gdm-pam-extensions-devel-3.28.2-16.el7.x86_64.rpm xorg-x11-drv-wacom-devel-0.36.1-3.el7.x86_64.rpm gdm-pam-extensions-devel-3.28.2-16.el7.i686.rpm xorg-x11-server-devel-1.20.4-7.el7.i686.rpm xorg-x11-server-Xvfb-1.20.4-7.el7.x86_64.rpm gdm-devel-3.28.2-16.el7.i686.rpm xorg-x11-server-Xdmx-1.20.4-7.el7.x86_64.rpm xorg-x11-server-Xwayland-1.20.4-7.el7.x86_64.rpm xorg-x11-server-Xnest-1.20.4-7.el7.x86_64.rpm xorg-x11-server-devel-1.20.4-7.el7.x86_64.rpm xorg-x11-drv-wacom-devel-0.36.1-3.el7.i686.rpm xorg-x11-server-source-1.20.4-7.el7.noarch.rpm gdm-devel-3.28.2-16.el7.x86_64.rpm libxkbcommon-x11-devel-0.7.1-3.el7.i686.rpm libxkbcommon-x11-devel-0.7.1-3.el7.x86_64.rpm gdm-debuginfo-3.28.2-16.el7.i686.rpm gdm-debuginfo-3.28.2-16.el7.x86_64.rpm libX11-debuginfo-1.6.7-2.el7.i686.rpm libX11-debuginfo-1.6.7-2.el7.x86_64.rpm libxkbcommon-debuginfo-0.7.1-3.el7.i686.rpm libxkbcommon-debuginfo-0.7.1-3.el7.x86_64.rpm xorg-x11-drv-ati-debuginfo-19.0.1-2.el7.x86_64.rpm xorg-x11-drv-vesa-debuginfo-2.4.0-3.el7.x86_64.rpm xorg-x11-drv-wacom-debuginfo-0.36.1-3.el7.x86_64.rpm xorg-x11-server-debuginfo-1.20.4-7.el7.x86_64.rpm xorg-x11-drv-wacom-debuginfo-0.36.1-3.el7.i686.rpm xorg-x11-server-debuginfo-1.20.4-7.el7.i686.rpm mesa-libGLw-debuginfo-8.0.0-5.el7.i686.rpm mesa-libGLw-debuginfo-8.0.0-5.el7.x86_64.rpm noarch libX11-common-1.6.7-2.el7.noarch.rpm xorg-x11-server-source-1.20.4-7.el7.noarch.rpm - Scientific Linux Development Team . Critical security patch released for SL7.x focusing on Xorg, resolving significant stability issues and vulnerabilities found in libX11 and libxkbcommon components.. Xorg Security Update, SL7 x86_64, libX11 Crash Fix, libxkbcommon Patch. . LinuxSecurity.com Team
libmspack: Out-of-bounds write in mspack/cab.h (CVE-2018-18584) * libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes (CVE-2018-18585) SL7 x86_64 libmspack-0.5-0.7.alpha.el7.i686.rpm libmspack-0.5-0.7.alpha.el7.x86_64.rpm libmspack-devel-0.5-0.7.alpha.el7.x86_64.rpm libmspack-devel-0.5-0.7.alpha.el7.i686.rpm libmspack-debuginfo-0.5-0.7.alpha.e [More...]. Synopsis: Moderate: libmspack security update Advisory ID: SLSA-2019:2049-1 Issue Date: 2019-08-06 CVE Numbers: CVE-2018-18584 CVE-2018-18585 -- Security Fix(es): * libmspack: Out-of-bounds write in mspack/cab.h (CVE-2018-18584) * libmspack: chmd_read_headers() fails to reject filenames containing NULL bytes (CVE-2018-18585) -- SL7 x86_64 libmspack-0.5-0.7.alpha.el7.i686.rpm libmspack-0.5-0.7.alpha.el7.x86_64.rpm libmspack-devel-0.5-0.7.alpha.el7.x86_64.rpm libmspack-devel-0.5-0.7.alpha.el7.i686.rpm libmspack-debuginfo-0.5-0.7.alpha.el7.i686.rpm libmspack-debuginfo-0.5-0.7.alpha.el7.x86_64.rpm - Scientific Linux Development Team . A substantial security patch for libmspack has been implemented to rectify issues related to out-of-bounds writing and the management of NULL bytes within the SL7 x86_64 environment.. libmspack, security update, out-of-bounds write. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.