Various security, performance, accuracy, and stability issues have been fixed.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e24171db6d 2025-01-12 01:37:12.378708+00:00 -------------------------------------------------------------------------------- Name : suricata Product : Fedora 41 Version : 7.0.8 Release : 1.fc41 URL : / Summary : Intrusion Detection System Description : The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field. This new Engine supports Multi-threading, Automatic Protocol Detection (IP, TCP, UDP, ICMP, HTTP, TLS, FTP and SMB! ), Gzip Decompression, Fast IP Matching, and GeoIP identification. -------------------------------------------------------------------------------- Update Information: Various security, performance, accuracy, and stability issues have been fixed. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 3 2025 Steve Grubb 7.0.8-1 - New security and bugfix release * Tue Oct 22 2024 Richard W.M. Jones - 7.0.7-2 - Rebuild for Jansson 2.14 (https://lists.fedoraproject.org/archives/list/
This update fixes several security issues and also improves stability. References: - https://bugs.mageia.org/show_bug.cgi?id=32332 - https://xenbits.xen.org/xsa/advisory-431.html . MGASA-2024-0047 - Updated xen, qemu and libvirt packages fix security vulnerabilities Publication date: 24 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0047.html Type: security Affected Mageia releases: 9 CVE: CVE-2022-42336, CVE-2023-2861, CVE-2023-46839, CVE-2023-46840 This update fixes several security issues and also improves stability. References: - https://bugs.mageia.org/show_bug.cgi?id=32332 - https://xenbits.xen.org/xsa/advisory-431.html - https://xenbits.xen.org/xsa/advisory-449.html - https://xenbits.xen.org/xsa/advisory-450.html - https://www.cve.org/CVERecord?id=CVE-2022-42336 - https://www.cve.org/CVERecord?id=CVE-2023-2861 - https://www.cve.org/CVERecord?id=CVE-2023-46839 - https://www.cve.org/CVERecord?id=CVE-2023-46840 SRPMS: - 9/core/qemu-7.2.9-1.mga9 - 9/core/libvirt-9.6.0-1.mga9 - 9/core/xen-4.17.3-1.mga9 . Addresses various vulnerabilities in Xen, QEMU, and Libvirt to improve the security and reliability for Mageia users.. Mageia Security Update,QEMU Patches,Libvirt Fixes,Xen Advisory. . LinuxSecurity.com Team
The 6.6.14 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0f89e13079 2024-02-02 02:22:05.328451 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.6.14 Release : 100.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.6.14 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 26 2024 Augusto Caringi [6.6.14-0] - Add some CVE fixes staged for 6.6.14 (Justin M. Forbes) - Linux v6.6.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2254052 - CVE-2023-6536 kernel: NULL pointer dereference in __nvmet_req_complete https://bugzilla.redhat.com/show_bug.cgi?id=2254052 [ 2 ] Bug #2254053 - CVE-2023-6535 kernel: NULL pointer dereference in nvmet_tcp_execute_request https://bugzilla.redhat.com/show_bug.cgi?id=2254053 [ 3 ] Bug #2254054 - CVE-2023-6356 kernel: NULL pointer dereference in nvmet_tcp_build_iovec https://bugzilla.redhat.com/show_bug.cgi?id=2254054 [ 4 ] Bug #2259701 - CVE-2023-46838 xen: netback processing of zero-length transmit fragment https://bugzilla.redhat.com/show_bug.cgi?id=2259701 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0f89e13079' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update for conmon fixes the following issues: conmon is rebuild with go1.21 to capture current stability, bug and security fixes. (bsc#1215806). # Security update for conmon Announcement ID: SUSE-SU-2023:4022-1 Rating: important References: * #1215806 Affected Products: * Containers Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one security fix can now be installed. ## Description: This update for conmon fixes the following issues: conmon is rebuild with go1.21 to capture current stability, bug and security fixes. (bsc#1215806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2023-4022=1 openSUSE-SLE-15.5-2023-4022=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2023-4022=1 * Containers Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Containers-15-SP5-2023-4022=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * conmon-2.1.7-150500.9.6.1 * conmon-debuginfo-2.1.7-150500.9.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * conmon-2.1.7-150500.9.6.1 * conmon-debuginfo-2.1.7-150500.9.6.1 * Containers Module 15-SP5 (aarch64 ppc64le s390x x86_64) * conmon-2.1.7-150500.9.6.1 * conmon-debuginfo-2.1.7-150500.9.6.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1215806 . Address critical vulnerabilities with this security notice for openSUSE and associated systems.. conmon Security Update, openSUSE Advisory, bug fixes Conmon, security patch. . Severity: Important. LinuxSecurity.com Team
Update to 102.12.0 ; https://www.thunderbird.net/en-US/thunderbird/102.12.0/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.2/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.1/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-edb2509e26 2023-06-11 02:01:36.946210 --------------------------------------------------------------------------------Name : thunderbird Product : Fedora 38 Version : 102.12.0 Release : 1.fc38 URL : https://wiki.mozilla.org/Thunderbird:Home_Page Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. --------------------------------------------------------------------------------Update Information: Update to 102.12.0 ; https://www.thunderbird.net/en-US/thunderbird/102.12.0/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.2/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.1/releasenotes/ ; https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes/ --------------------------------------------------------------------------------ChangeLog: * Wed Jun 7 2023 Eike Rathke - 102.12.0-1 - Update to 102.12.0 * Thu May 25 2023 Eike Rathke - 102.11.1-1 - Update to 102.11.1 - Change %patchN ... to %patch -P N ... * Wed May 10 2023 Eike Rathke - 102.11.0-1 - Update to 102.11.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-edb2509e26' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Various security, performance, accuracy and stability issues. See referenced package announcements for details. References: - https://bugs.mageia.org/show_bug.cgi?id=30375 . MGASA-2023-0174 - Updated suricata packages fix security vulnerability Publication date: 21 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0174.html Type: security Affected Mageia releases: 8 Various security, performance, accuracy and stability issues. See referenced package announcements for details. References: - https://bugs.mageia.org/show_bug.cgi?id=30375 - https://lists.fedoraproject.org/archives/list/
Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-gopkg-src-d-git-4 Product : Fedora 36 Version : 4.13.1 Release : 9.fc36 URL : https://github.com/src-d/go-git Summary : A highly extensible git implementation in pure go Description : A highly extensible git implementation in pure go. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G - 4.13.1-9 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The ffmpeg project released the new version 3.2.18 with fixes for various issues found by the OSS-Fuzz project. For Debian 9 stretch, this release is packaged in version 7:3.2.18-0+deb9u1. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3010-1
Get the latest Linux and open source security news straight to your inbox.