Explore top 10 tips to secure your open-source projects now. Read More
×
Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-04847cb65d 2025-04-20 04:20:54.268638+00:00 -------------------------------------------------------------------------------- Name : rust-icu_properties Product : Fedora 42 Version : 1.5.1 Release : 1.fc42 URL : https://crates.io/crates/icu_properties Summary : Definitions for Unicode properties Description : Definitions for Unicode properties. -------------------------------------------------------------------------------- Update Information: Update uv to 0.6.14, with various bugfixes and new features. Update rust-idna to 1.0.3 (fixing RUSTSEC-2024-0421), rust-url to 2.5.4, rust- adblock to 0.9.6, and rust-cookie_store to 0.21.1; adjust some reverse dependencies of rust-idna. Initial packages for many dependencies. Update rust-ron to 0.9. Update rust-zip to 2.6.1, fixing GHSA-94vh-gphv-8pm8. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 10 2025 Benjamin A. Beasley - 1.5.1-1 - Initial package (close RHBZ#2358527) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2277901 - rust-adblock-0.9.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=2277901 [ 2 ] Bug #2291175 - rust-idna-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2291175 [ 3 ] Bug #2323618 - rust-url-2.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2323618 [ 4 ] Bug #2324926 - rust-cookie_store-0.21.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2324926 [ 5 ]Bug #2352783 - rust-zip-2.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2352783 [ 6 ] Bug #2358015 - Review Request: rust-write16 - UTF-16 analog of the Write trait https://bugzilla.redhat.com/show_bug.cgi?id=2358015 [ 7 ] Bug #2358018 - Review Request: rust-utf16_iter - Iterator by char over potentially-invalid UTF-16 in &[u16] https://bugzilla.redhat.com/show_bug.cgi?id=2358018 [ 8 ] Bug #2358020 - Review Request: rust-icu_locid - API for managing Unicode Language and Locale Identifiers https://bugzilla.redhat.com/show_bug.cgi?id=2358020 [ 9 ] Bug #2358105 - Review Request: rust-icu_provider_macros - Proc macros for ICU data providers https://bugzilla.redhat.com/show_bug.cgi?id=2358105 [ 10 ] Bug #2358290 - Review Request: rust-icu_provider - Trait and struct definitions for the ICU data provider https://bugzilla.redhat.com/show_bug.cgi?id=2358290 [ 11 ] Bug #2358292 - Review Request: rust-icu_locid_transform_data - Data for the icu_locid_transform crate https://bugzilla.redhat.com/show_bug.cgi?id=2358292 [ 12 ] Bug #2358507 - Review Request: rust-icu_locid_transform - API for Unicode Language and Locale Identifiers canonicalization https://bugzilla.redhat.com/show_bug.cgi?id=2358507 [ 13 ] Bug #2358521 - Review Request: rust-icu_properties_data - Data for the icu_properties crate https://bugzilla.redhat.com/show_bug.cgi?id=2358521 [ 14 ] Bug #2358522 - Review Request: rust-icu_normalizer_data - Data for the icu_normalizer crate https://bugzilla.redhat.com/show_bug.cgi?id=2358522 [ 15 ] Bug #2358527 - Review Request: rust-icu_properties - Definitions for Unicode properties https://bugzilla.redhat.com/show_bug.cgi?id=2358527 [ 16 ] Bug #2358606 - Review Request: rust-icu_normalizer - API for normalizing text into Unicode Normalization Forms https://bugzilla.redhat.com/show_bug.cgi?id=2358606 [ 17 ] Bug #2358642 - Review Request: rust-idna_adapter - Backend adapter for idna https://bugzilla.redhat.com/show_bug.cgi?id=2358642 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-04847cb65d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updated to latest upstream (131.0.2). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-d85494e836 2024-10-10 00:15:44.893600 -------------------------------------------------------------------------------- Name : firefox Product : Fedora 41 Version : 131.0.2 Release : 1.fc41 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. -------------------------------------------------------------------------------- Update Information: Updated to latest upstream (131.0.2) -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 9 2024 Martin Stransky - 131.0.2-1 - Updated to 131.0.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d85494e836' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New seamonkey packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] seamonkey (SSA:2024-247-02) New seamonkey packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/seamonkey-2.53.19-i686-1_slack15.0.txz: Upgraded. This update contains security fixes and improvements. For more information, see: https://www.seamonkey-project.org/releases/seamonkey2.53.19 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/seamonkey-2.53.19-i686-1_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/seamonkey-2.53.19-x86_64-1_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/xap/seamonkey-2.53.19-i686-1.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/xap/seamonkey-2.53.19-x86_64-1.txz MD5 signatures: +-------------+ Slackware 15.0 package: 75c0ed299f27b64251ed725ef23da40c seamonkey-2.53.19-i686-1_slack15.0.txz Slackware x86_64 15.0 package: fc8c3a1d94ea6d5050eea997ee495f02 seamonkey-2.53.19-x86_64-1_slack15.0.txz Slackware -current package: 46a63968b7230033aa7a9be6b26374ec xap/seamonkey-2.53.19-i686-1.txz Slackware x86_64 -current package: 18d1e3b43dbdc8b3d606b54535173197 xap/seamonkey-2.53.19-x86_64-1.txz Installationinstructions: +------------------------+ Upgrade the package as root: # upgradepkg seamonkey-2.53.19-i686-1_slack15.0.txz +-----+ . Updated seamonkey versions have been released for Slackware 15.0, tackling significant security vulnerabilities and enhancing overall performance.. Seamonkey Security, Slackware Update, Seamonkey Package Fixes, Linux Security Advisory. . Severity: Critical. LinuxSecurity.com Team
nodejs:18 bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:0890","synopsis":"nodejs:18 bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for nodejs-nodemon, module.nodejs, nodejs, module.nodejs-nodemon, module.nodejs-packaging, nodejs-packaging.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Node.js is a software development platform for building fast and scalable\nnetwork applications in the JavaScript programming language.\n\nBug Fix(es) and Enhancement(s):\n\n* nodejs:18\/nodejs: Rebase to latest upstream version (JIRA:Rocky Linux-21439)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2024-03-12T15:42:26.241001Z","rpms":{"Rocky Linux 8":{"nvras":["nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.src.rpm","nodejs-debuginfo-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-debugsource-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-devel-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-docs-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.noarch.rpm","nodejs-full-i18n-1:18.19.0-1.module+el8.9.0+1727+17e65eb5.aarch64.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.noarch.rpm","nodejs-nodemon-0:3.0.1-1.module+el8.8.0+1459+02651ab6.src.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","nodejs-packaging-0:2021.06-4.module+el8.7.0+1072+5b168780.src.rpm","nodejs-packaging-bundler-0:2021.06-4.module+el8.7.0+1072+5b168780.noarch.rpm","npm-1:10.2.3-1.18.19.0.1.module+el8.9.0+1727+17e65eb5.aarch64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. Elevate your Rocky Linux 8 environment by incorporating the updated nodejs:18, featuring essential bug resolutions and enhancements to maximizeefficiency.. Rocky Linux Update, Node.js Enhancements, Software Development Platform. . Severity: Critical. LinuxSecurity.com Team
This is the February 2024 update for .NET 7. Release Notes: - Runtime: notes/7.0/7.0.16/7.0.16.md - SDK: . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-a66f05d20f 2024-03-01 01:07:58.185744 -------------------------------------------------------------------------------- Name : dotnet7.0 Product : Fedora 39 Version : 7.0.116 Release : 1.fc39 URL : https://github.com/dotnet/ Summary : .NET Runtime and SDK Description : .NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything. -------------------------------------------------------------------------------- Update Information: This is the February 2024 update for .NET 7. Release Notes: - Runtime: notes/7.0/7.0.16/7.0.16.md - SDK: notes/7.0/7.0.16/7.0.116.md -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 14 2024 Omair Majid - 7.0.116-1 - Update to .NET SDK 7.0.116 and Runtime 7.0.16 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-a66f05d20f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announcemailing list --
The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2116a8468b 2024-02-06 01:17:01.499269 -------------------------------------------------------------------------------- Name : kernel-headers Product : Fedora 39 Version : 6.7.3 Release : 200.fc39 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. -------------------------------------------------------------------------------- Update Information: The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 1 2024 Justin M. Forbes - 6.7.3-1 - Linux v6.7.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253986 - CVE-2023-6679 kernel: NULL pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c https://bugzilla.redhat.com/show_bug.cgi?id=2253986 [ 2 ] Bug #2260041 - CVE-2024-23849 kernel: off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access https://bugzilla.redhat.com/show_bug.cgi?id=2260041 [ 3 ] Bug #2262126 - CVE-2024-1086 kernel: nf_tables: use-after-free vulnerability in the nft_verdict_init() function https://bugzilla.redhat.com/show_bug.cgi?id=2262126 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2116a8468b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
microcode_ctl bug fix and enhancement update . {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2023:4995","synopsis":"microcode_ctl bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for microcode_ctl.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"The microcode_ctl packages provide microcode updates for Intel processors.\n\nBug Fix(es) and Enhancement(s):\n\n* Update Intel CPU microcode to microcode-20230214 release, which addresses CVE-2022-40982, CVE-2022-41804, and CVE-2023-23908. (BZ#2229733)","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[],"cves":[],"references":[],"publishedAt":"2023-09-19T12:08:46.496613Z","rpms":{"Rocky Linux 8":{"nvras":["microcode_ctl-4:20220809-2.20230808.2.el8_8.src.rpm","microcode_ctl-4:20220809-2.20230808.2.el8_8.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]} . Rocky Linux 8 has introduced a microcode_ctl patch and improvement release that tackles vital updates for Intel processors.. Rocky Linux, Microcode Update, Intel Processor, Bug Fix, Enhancement. . Severity: Informational. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-4645 https://linux.oracle.com/errata/ELSA-2023-4645.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: aspnetcore-runtime-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm aspnetcore-targeting-pack-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm dotnet-apphost-pack-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm dotnet-hostfxr-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm dotnet-runtime-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm dotnet-sdk-6.0-6.0.121-1.0.1.el8_8.x86_64.rpm dotnet-targeting-pack-6.0-6.0.21-1.0.1.el8_8.x86_64.rpm dotnet-templates-6.0-6.0.121-1.0.1.el8_8.x86_64.rpm dotnet-sdk-6.0-source-built-artifacts-6.0.121-1.0.1.el8_8.x86_64.rpm aarch64: aspnetcore-runtime-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm aspnetcore-targeting-pack-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm dotnet-apphost-pack-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm dotnet-hostfxr-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm dotnet-runtime-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm dotnet-sdk-6.0-6.0.121-1.0.1.el8_8.aarch64.rpm dotnet-targeting-pack-6.0-6.0.21-1.0.1.el8_8.aarch64.rpm dotnet-templates-6.0-6.0.121-1.0.1.el8_8.aarch64.rpm dotnet-sdk-6.0-source-built-artifacts-6.0.121-1.0.1.el8_8.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//dotnet6.0-6.0.121-1.0.1.el8_8.src.rpm Related CVEs: CVE-2023-35390 CVE-2023-38180 Description of changes: [6.0.121-1.0.1] - Update to .NET SDK 6.0.121 and Runtime 6.0.21 - Resolves: RHBZ#2228567 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.