Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-b268fceaec 2025-02-20 02:26:20.996716+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 40 Version : 6.12.15 Release : 100.fc40 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.12.15 stable kernel update contains a number of important fixes across the tree. The 6.12.14 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 18 2025 Augusto Caringi [6.12.15-100] - Turn off libbpf dynamic for perf (Justin M. Forbes) * Tue Feb 18 2025 Augusto Caringi [6.12.15-0] - Linux v6.12.15 * Mon Feb 17 2025 Augusto Caringi [6.12.14-0] - redhat/configs: automotive: Set CONFIG_FSCACHE=y (Augusto Caringi) - CONFIG_CPUFREQ_DT_PLATDEV is bool now (Justin M. Forbes) - Add some bugs to BugsFixed for the 6.12.14 update (Justin M. Forbes) - efi,lockdown: fix kernel lockdown on Secure Boot (Ondrej Mosnacek) {CVE-2025-1272} - Linux v6.12.14 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333706 - Kernel 6.12.6 kernel lockdown disabled https://bugzilla.redhat.com/show_bug.cgi?id=2333706 [ 2 ] Bug #2345700 - CVE-2025-1272 kernel: Secure Boot does not automatically enable kernel lockdown [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2345700 [ 3 ] Bug #2345701 - CVE-2025-1272 kernel: Secure Boot does not automatically enable kernel lockdown[fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2345701 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-b268fceaec' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-811cffc4ef 2024-12-16 02:29:18.629389+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 40 Version : 6.12.4 Release : 100.fc40 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.12.4 stable kernel rebase contains new features, additional hardware support and a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 9 2024 Justin M. Forbes [6.12.4-0] - Fix up QCOM_EMAC config for Fedora (Justin M. Forbes) - wifi: rtl8xxxu: add more missing rtl8192cu USB IDs (Hans de Goede) - Linux v6.12.4 * Fri Dec 6 2024 Justin M. Forbes [6.12.3-0] - Linux v6.12.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2322092 - CVE-2024-50067 kernel: uprobe: avoid out-of-bounds memory access of fetching args [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2322092 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-811cffc4ef' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12547 http://linux.oracle.com/errata/ELSA-2024-12547.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-debug-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-debug-devel-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-devel-5.4.17-2136.333.5.1.el7uek.x86_64.rpm kernel-uek-doc-5.4.17-2136.333.5.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.333.5.1.el7uek.x86_64.rpm aarch64: kernel-uek-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-debug-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-debug-devel-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-devel-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-doc-5.4.17-2136.333.5.1.el7uek.noarch.rpm kernel-uek-tools-5.4.17-2136.333.5.1.el7uek.aarch64.rpm kernel-uek-tools-libs-5.4.17-2136.333.5.1.el7uek.aarch64.rpm perf-5.4.17-2136.333.5.1.el7uek.aarch64.rpm python-perf-5.4.17-2136.333.5.1.el7uek.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//kernel-uek-5.4.17-2136.333.5.1.el7uek.src.rpm Related CVEs: CVE-2024-41090 CVE-2024-41091 Description of changes: [5.4.17-2136.333.5.1.el7uek] - net/mlx5e: drop shorter ethernet frames (Manjunath Patil) [Orabug: 36660755] - pci: add hotplug patch support for SOLIDIGM Aura10 AIC 0x025e:0x0b60 (Alan Adamson) [Orabug: 36836653] _______________________________________________ El-errata mailing list
The update for composer released as DSA 5715 introduced a regression in the handling of git feature branches. Updated composer packages are now available to address this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5715-2
The 6.8.5 stable kernel update contains a number of important fixes across the tree. . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-33a9ea72d1 2024-04-13 01:13:12.184317 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 39 Version : 6.8.5 Release : 201.fc39 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.8.5 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Justin M. Forbes [6.8.5-201] - Revert "cpupower: Bump soname version" (Justin M. Forbes) - Drop soname for libcpupower.so since we reverted the bump (Justin M. Forbes) - nouveau: fix devinit paths to only handle display on GSP. (Dave Airlie) - Add bluetooth bug to Bugsfixed for 6.8.6 (Justin M. Forbes) - Bluetooth: l2cap: Don't double set the HCI_CONN_MGMT_CONNECTED bit (Archie Pusaka) * Wed Apr 10 2024 Justin M. Forbes [6.8.5-0] - Set configs for SPECTRE_BHI (Justin M. Forbes) - Add AMD PMF bug (Justin M. Forbes) - redhat/configs: Enable CONFIG_AMDTEE for x86 (David Arcari) - Add CVE fix for 6.8.5 (Justin M. Forbes) - Linux v6.8.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273968 - CVE-2024-26811 kernel: ksmbd: validate payload size in ipc response [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2273968 [ 2 ] Bug #2274047 - Bluetooth headset partially connects under some circumstances with blues 5.73-3.fc40.x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=2274047 [ 3 ] Bug #2274069 - AMD-PMF driver fails to load on kernel- 6.8.4-300.fc40.x86_64. Resulting in GPUfailing to use full gpu available watts. https://bugzilla.redhat.com/show_bug.cgi?id=2274069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-33a9ea72d1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 6.5.6 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-830d9ec624 2023-10-10 01:35:39.387189 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.5.6 Release : 200.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.5.6 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 6 2023 Augusto Caringi [6.5.6-0] - power: supply: core: Use blocking_notifier_call_chain to avoid RCU complaint (Kai-Heng Feng) - Revert "Add linux-next specific files for 20231004" (Justin M. Forbes) - redhat/configs: enable missing Kconfig options for Qualcomm RideSX4 (Brian Masney) - add a couple of CVEs to BugsFixed (Justin M. Forbes) - Add another F39 FE bug to BugsFixed (Justin M. Forbes) - Add linux-next specific files for 20231004 (Stephen Rothwell) - common: aarch64: enable NXP Flex SPI (Peter Robinson) - fedora: Switch TI_SCI_CLK and TI_SCI_PM_DOMAINS symbols to built-in (Javier Martinez Canillas) - Add bug for amdgpu to BugsFixed for 6.5.6 (Justin M. Forbes) - drm/amdgpu: set completion status as preempted for the resubmission (Jiadong Zhu) - Add CVE-2023-42756 to BugsFixed for 6.5.6 (Justin M. Forbes) - Linux v6.5.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2239845 - CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach() https://bugzilla.redhat.com/show_bug.cgi?id=2239845 [ 2 ] Bug #2239848 - CVE-2023-42756 kernel: netfilter: race condition betweenIPSET_CMD_ADD and IPSET_CMD_SWAP https://bugzilla.redhat.com/show_bug.cgi?id=2239848 [ 3 ] Bug #2242172 - CVE-2023-5345 kernel: use-after-free vulnerability in the smb client component https://bugzilla.redhat.com/show_bug.cgi?id=2242172 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-830d9ec624' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to the latest stable bugfix release. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-39533c087f 2022-04-26 06:56:41.093963 --------------------------------------------------------------------------------Name : htmldoc Product : Fedora 34 Version : 1.9.15 Release : 1.fc34 URL : https://www.msweet.org/htmldoc/ Summary : Converter from HTML into indexed HTML, PostScript, or PDF Description : HTMLDOC converts HTML source files into indexed HTML, PostScript, or Portable Document Format (PDF) files that can be viewed online or printed. With no options a HTML document is produced on stdout. The second form of HTMLDOC reads HTML source from stdin, which allows you to use HTMLDOC as a filter. The third form of HTMLDOC launches a graphical interface that allows you to change options and generate documents interactively. --------------------------------------------------------------------------------Update Information: Update to the latest stable bugfix release --------------------------------------------------------------------------------ChangeLog: * Fri Mar 4 2022 Rex Dieter - 1.9.15-1 - 1.9.15 * Tue Jun 22 2021 Rex Dieter - 1.9.7-5 - hack/workaround FTBFS (#1923557) * Tue Jan 26 2021 Fedora Release Engineering - 1.9.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2074393 - CVE-2022-24191 htmldoc: infinite loop in the gif_read_lzw function can lead to a buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074393 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-39533c087f' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The 5.17.2 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-af492757d9 2022-04-11 03:33:14.178560 --------------------------------------------------------------------------------Name : kernel Product : Fedora 36 Version : 5.17.2 Release : 300.fc36 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.17.2 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Fri Apr 8 2022 Justin M. Forbes [5.17.2-0] - Move the patch to the redhat directory so it doesn't end up as an applied patch (Justin M. Forbes) - Config updates for 5.17.2 (Justin M. Forbes) - Fedora: arm: Updates for QCom devices (Peter Robinson) - Fedora arm and generic updates for 5.17 (Peter Robinson) - enable COMMON_CLK_SI5341 for Xilinx ZYNQ-MP (Peter Robinson) - Update Fix 'mem_section' will never be NULL gcc 12 warning to V4 (Justin M. Forbes) - NFSv4.1 provide mount option to toggle trunking discovery (Olga Kornievskaia) - Add the Revert patch so that it can be applied when building dist-git for F34 and F35 (Justin M. Forbes) - redhat/configs/process_configs.sh: Avoid race with find (Prarit Bhargava) - redhat/configs/process_configs.sh: Remove CONTINUEONERROR (Prarit Bhargava) - redhat/configs/process_configs.sh: Fix race with tools generation (Prarit Bhargava) - Bluetooth: hci_core: Rate limit the logging of invalid SCO handle (Luiz Augusto von Dentz) - Bluetooth: hci_event: Fix HCI_EV_VENDOR max_len (Luiz Augusto von Dentz) - Update mm/sparsemem: Fix 'mem_section' will never be NULL gcc 12 (Justin M. Forbes) - net: bcmgenet: Use stronger register read/writes to assure ordering(Jeremy Linton) - We actually needed the previous patch from os-build (Justin M. Forbes) - redhat: Fix release tagging (Prarit Bhargava) - Fix up changelog generation for stable releases (Justin M. Forbes) - Remove i686 configs and filters (Justin M. Forbes) - redhat/self-test: Fix shellcheck test (Prarit Bhargava) - redhat/configs: Set CONFIG_X86_AMD_PSTATE built-in on Fedora (Prarit Bhargava) --------------------------------------------------------------------------------References: [ 1 ] Bug #2071047 - CVE-2022-1205 kernel: Null pointer dereference and use after free in net/ax25/ax25_timer.c https://bugzilla.redhat.com/show_bug.cgi?id=2071047 [ 2 ] Bug #2073064 - CVE-2022-28390 kernel: a double free in ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c https://bugzilla.redhat.com/show_bug.cgi?id=2073064 [ 3 ] Bug #2073086 - CVE-2022-28389 kernel: a double free in mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c https://bugzilla.redhat.com/show_bug.cgi?id=2073086 [ 4 ] Bug #2073091 - CVE-2022-28388 kernel: a double free in usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c https://bugzilla.redhat.com/show_bug.cgi?id=2073091 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-af492757d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.