Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.. openSUSE security update: security update for libxml2 ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21317-1 Rating: important References: * bsc#1262719 * bsc#1269790 Cross-References: * CVE-2026-11979 * CVE-2026-6732 CVSS scores: * CVE-2026-11979 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6732 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( SUSE ): 6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed. Description: This update for libxml2 fixes the following issues - CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1220=1 Package List: - openSUSE Leap 16.0: libxml2-2-2.13.8-160000.5.1 libxml2-devel-2.13.8-160000.5.1 libxml2-doc-2.13.8-160000.5.1 libxml2-tools-2.13.8-160000.5.1 python313-libxml2-2.13.8-160000.5.1 References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://www.suse.com/security/cve/CVE-2026-6732.html . This openSUSE security update addresses important issues in libxml2, fixing vulnerabilities and bugs that could compromise system stability.. openSUSE security, libxml2 update, denial of service, stackoverflow. . Severity: Important. LinuxSecurity.com Team
Moderate: rrdtool security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:34155", "synopsis": "Moderate: rrdtool security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for rrdtool.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The round robin database (RRD) system stores and displays time-series data, such as network bandwidth, machine-room temperature, and server load average. RRDtool is a high performance data logging and graphing utility, which can be easily integrated with shell scripts, or used to create applications using its Perl, Python, Ruby, Lua, Tcl, and PHP bindings. The data is stored in a compact manner that does not expand over time, and RRDtool provides the user with useful graphs by processing the data to enforce a certain data density.\n\nSecurity Fix(es):\n\n* rrdtool: Stack buffer overflow in rrdcached handle_request_create() allows local privilege escalation via unbounded DS/RRA arguments (CVE-2026-43958)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2460932", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2460932", "description": ""}], "cves": [{"name": "CVE-2026-43958", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43958", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-121"}], "references": [], "publishedAt": "2026-07-04T06:00:26.778042Z", "rpms": {"Rocky Linux 8": {"nvras": ["rrdtool-tcl-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-tcl-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-tcl-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm","rrdtool-tcl-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm", "python3-rrdtool-0:1.7.0-17.el8_10.aarch64.rpm", "python3-rrdtool-0:1.7.0-17.el8_10.x86_64.rpm", "python3-rrdtool-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm", "python3-rrdtool-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-0:1.7.0-17.el8_10.i686.rpm", "rrdtool-0:1.7.0-17.el8_10.src.rpm", "rrdtool-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-debuginfo-0:1.7.0-17.el8_10.i686.rpm", "rrdtool-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-debugsource-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-debugsource-0:1.7.0-17.el8_10.i686.rpm", "rrdtool-debugsource-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-devel-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-devel-0:1.7.0-17.el8_10.i686.rpm", "rrdtool-devel-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-doc-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-doc-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-lua-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-lua-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-lua-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-lua-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-perl-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-perl-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-perl-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-perl-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-ruby-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-ruby-0:1.7.0-17.el8_10.x86_64.rpm", "rrdtool-ruby-debuginfo-0:1.7.0-17.el8_10.aarch64.rpm", "rrdtool-ruby-debuginfo-0:1.7.0-17.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A security update for rrdtool on Rocky Linux addresses a stack buffer overflow issue with moderate severity and potential local access risks.. rrdtool security update, local privilege escalation, moderate severity vulnerability. . Severity: moderate. LinuxSecurity.com Team
An update that solves four vulnerabilities can now be installed.. # Security update for opensc Announcement ID: SUSE-SU-2026:21283-1 Release Date: 2026-04-22T11:13:04Z Rating: low References: * bsc#1261214 * bsc#1261218 * bsc#1261219 * bsc#1261220 Cross-References: * CVE-2025-49010 * CVE-2025-66037 * CVE-2025-66038 * CVE-2025-66215 CVSS scores: * CVE-2025-49010 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-49010 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-49010 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-49010 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66037 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66037 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66037 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66037 ( NVD ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66038 ( SUSE ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( NVD ): 3.9 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-66038 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-66215 ( SUSE ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-66215 ( SUSE ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-66215 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-66215 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for opensc fixes the following issues: * CVE-2025-49010: stack-buffer-overflow via crafted smart card or USB device responses (bsc#1261214). *CVE-2025-66037: crafted input can cause an out-of-bounds read (bsc#1261218). * CVE-2025-66038: improper compact-TLV length validation can lead to crash or unexpected behavior (bsc#1261219). * CVE-2025-66215: crafted smart card or USB device can cause a stack-buffer- overflow write (bsc#1261220). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-501=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * opensc-0.24.0-slfo.1.1_3.1 * opensc-debuginfo-0.24.0-slfo.1.1_3.1 * opensc-debugsource-0.24.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49010.html * https://www.suse.com/security/cve/CVE-2025-66037.html * https://www.suse.com/security/cve/CVE-2025-66038.html * https://www.suse.com/security/cve/CVE-2025-66215.html * https://bugzilla.suse.com/show_bug.cgi?id=1261214 * https://bugzilla.suse.com/show_bug.cgi?id=1261218 * https://bugzilla.suse.com/show_bug.cgi?id=1261219 * https://bugzilla.suse.com/show_bug.cgi?id=1261220 . An essential update for opensc addresses multiple security concerns including low risk vulnerabilities.. opensc security update, SUSE Linux Micro, buffer overflow fix, security vulnerabilities, patch instructions. . Severity: Low. LinuxSecurity.com Team
New upstream release (#2442363) fixing various security issues. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-de85b06438 2026-04-10 01:10:26.730915+00:00 -------------------------------------------------------------------------------- Name : opensc Product : Fedora 42 Version : 0.27.1 Release : 1.fc42 URL : https://github.com/OpenSC/OpenSC/wiki Summary : Smart card library and applications Description : OpenSC provides a set of libraries and utilities to work with smart cards. Its main focus is on cards that support cryptographic operations, and facilitate their use in security applications such as authentication, mail encryption and digital signatures. OpenSC implements the PKCS#11 API so applications supporting this API (such as Mozilla Firefox and Thunderbird) can use it. On the card OpenSC implements the PKCS#15 standard and aims to be compatible with every software/card that does so, too. -------------------------------------------------------------------------------- Update Information: New upstream release (#2442363) fixing various security issues -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 31 2026 Jakub Jelen - 0.27.1-1 - New upstream release (#2442363) fixing various security issues: - CVE-2025-66038 Memory corruption via improper compact-TLV length validation - CVE-2025-66215 Stack-buffer-overflow with physical access via crafted smart card or USB device - CVE-2025-49010 Stack-buffer-overflow via crafted smart card or USB device responses - CVE-2025-66037 Out-of-bounds read via crafted input - CVE-2025-13763 Several uses of potentially uninitialized memory detected by fuzzers * Fri Jan 16 2026 Michael Catanzaro - 0.26.1-6 - Fix crash when loaded by p11-kit - SoftHSM 2.7.0 compatibility * Fri Jan 16 2026 Fedora Release Engineering - 0.26.1-5 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Wed Dec 17 2025 Jakub Jelen - 0.26.1-4 - Avoid const discard to unbreak eln build -------------------------------------------------------------------------------- References: [ 1 ] Bug #2442363 - opensc-0.27.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2442363 [ 2 ] Bug #2453188 - CVE-2025-66037 opensc: OpenSC: Out-of-bounds read via crafted input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453188 [ 3 ] Bug #2453189 - CVE-2025-49010 opensc: OpenSC: Stack-buffer-overflow via crafted smart card or USB device responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453189 [ 4 ] Bug #2453190 - CVE-2025-66215 opensc: OpenSC: Stack-buffer-overflow with physical access via crafted smart card or USB device [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453190 [ 5 ] Bug #2453191 - CVE-2025-66038 opensc: OpenSC: Memory corruption via improper compact-TLV length validation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2453191 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-de85b06438' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # Security update for jq Announcement ID: SUSE-SU-2025:02915-1 Release Date: 2025-08-19T12:57:02Z Rating: moderate References: * bsc#1244116 Cross-References: * CVE-2025-48060 CVSS scores: * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2025-48060: Fixed stack-buffer-overflow in jq_fuzz_execute (bsc#1244116) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patchopenSUSE-SLE-15.6-2025-2915=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2915=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2915=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2915=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2915=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2915=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2915=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2915=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-2915=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2915=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2915=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * libjq-devel-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.4(aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * libjq-devel-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * libjq-devel-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libjq1-debuginfo-1.6-150000.3.9.1 * jq-1.6-150000.3.9.1 * libjq1-1.6-150000.3.9.1 * jq-debugsource-1.6-150000.3.9.1 * jq-debuginfo-1.6-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48060.html * https://bugzilla.suse.com/show_bug.cgi?id=1244116 . Important openSUSE patch for jq addresses a significant stack buffer overflow vulnerability; safeguard your system now.. openSUSE Patch jq Security Fix Stack Buffer. . LinuxSecurity.com Team
Avoid restarting minidlna.service when rotating logs if it's not running. Fix CVE-2023-47430 . . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-9fb8ee63fb 2025-07-18 01:05:30.483965+00:00 -------------------------------------------------------------------------------- Name : minidlna Product : Fedora 42 Version : 1.3.3 Release : 13.fc42 URL : http://sourceforge.net/projects/minidlna/ Summary : Lightweight DLNA/UPnP-AV server targeted at embedded systems Description : MiniDLNA (aka ReadyDLNA) is server software with the aim of being fully compliant with DLNA/UPnP-AV clients. The minidlna daemon serves media files (music, pictures, and video) to clients on your local network. Example clients include applications such as Totem and XBMC, and devices such as portable media players, smartphones, and televisions. -------------------------------------------------------------------------------- Update Information: Avoid restarting minidlna.service when rotating logs if it's not running. Fix CVE-2023-47430 . -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 7 2025 Dominik Mierzejewski - 1.3.3-13 - use systemctl try-restart in postrotate script (resolves rhbz#2372859) - attempt to fix CVE-2023-47430 (resolves rhbz#2271621) * Tue May 27 2025 Jitka Plesnikova - 1.3.3-12 - Rebuilt for flac 1.5.0 * Tue Feb 11 2025 Zbigniew J\u0119drzejewski-Szmek - 1.3.3-11 - Drop call to %sysusers_create_compat -------------------------------------------------------------------------------- References: [ 1 ] Bug #2271621 - CVE-2023-47430 minidlna: Stack-buffer-overflow vulnerability in ReadyMedia [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2271621 [ 2 ] Bug #2372859 - Use `systemctl try-restart` in logrotate postrotate script https://bugzilla.redhat.com/show_bug.cgi?id=2372859 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9fb8ee63fb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Debian 12's rdiff-backup upgrade addresses significant memory-corruption vulnerability CVE-2023-57420 with improved operational safeguards.. Fedora Update,minidlna security,service restart fix,minidlna vulnerability,security patch. . Severity: Important. LinuxSecurity.com Team
An update that solves seven vulnerabilities can now be installed.. # Security update for gstreamer-plugins-base Announcement ID: SUSE-SU-2025:0054-1 Release Date: 2025-01-09T16:36:42Z Rating: important References: * bsc#1234415 * bsc#1234450 * bsc#1234453 * bsc#1234455 * bsc#1234456 * bsc#1234459 * bsc#1234460 Cross-References: * CVE-2024-47538 * CVE-2024-47541 * CVE-2024-47542 * CVE-2024-47600 * CVE-2024-47607 * CVE-2024-47615 * CVE-2024-47835 CVSS scores: * CVE-2024-47538 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47538 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47538 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47541 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47541 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-47541 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47542 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47542 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47542 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47600 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2024-47600 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47600 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-47607 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47607 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47607 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47615 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47615 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47615 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47835 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-47835 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-base fixes the following issues: * CVE-2024-47538: Fixed a stack-buffer overflow in vorbis_handle_identification_packet. (bsc#1234415) * CVE-2024-47835: Fixed a NULL-pointer dereference in LRC subtitle parser. (bsc#1234450) * CVE-2024-47600: Fixed an out-of-bounds read in gst-discoverer-1.0 commandline tool. (bsc#1234453) * CVE-2024-47615: Fixed an out-of-bounds write in Ogg demuxer. (bsc#1234456) * CVE-2024-47541: Fixed an out-of-bounds write in SSA subtitle parser. (bsc#1234459) * CVE-2024-47542: Fixed an ID3v2 parser out-of-bounds read and NULL-pointer dereference. (bsc#1234460) * CVE-2024-47607: Fixed a stack buffer-overflow in Opus decoder. (bsc#1234455) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-54=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-54=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-54=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-54=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-54=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-54=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 *libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.11.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 *libgstrtsp-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.11.1 * openSUSE Leap 15.5 (x86_64) * libgstgl-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-32bit-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-32bit-1.22.0-150500.3.11.1 * libgstapp-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstapp-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-32bit-1.22.0-150500.3.11.1 * gstreamer-plugins-base-32bit-1.22.0-150500.3.11.1 * libgstfft-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-32bit-1.22.0-150500.3.11.1 * libgsttag-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-32bit-1.22.0-150500.3.11.1 * gstreamer-plugins-base-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstriff-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * libgstriff-1_0-0-32bit-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-32bit-debuginfo-1.22.0-150500.3.11.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.11.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libgstvideo-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstfft-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstriff-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstapp-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstgl-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-64bit-1.22.0-150500.3.11.1 * gstreamer-plugins-base-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-64bit-1.22.0-150500.3.11.1 *libgstapp-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstfft-1_0-0-64bit-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-64bit-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-64bit-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-64bit-debuginfo-1.22.0-150500.3.11.1 * libgstriff-1_0-0-64bit-1.22.0-150500.3.11.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15SP5 (aarch64 x86_64) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.11.1 *libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-devel-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 *libgstallocators-1_0-0-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libgstvideo-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-1.22.0-150500.3.11.1 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgsttag-1_0-0-1.22.0-150500.3.11.1 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstfft-1_0-0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-1.22.0-150500.3.11.1 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.11.1 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.11.1 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.11.1 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.11.1 *gstreamer-plugins-base-devel-1.22.0-150500.3.11.1 * libgstapp-1_0-0-1.22.0-150500.3.11.1 * libgstsdp-1_0-0-1.22.0-150500.3.11.1 * gstreamer-plugins-base-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-1.22.0-150500.3.11.1 * libgstallocators-1_0-0-1.22.0-150500.3.11.1 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstpbutils-1_0-0-1.22.0-150500.3.11.1 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.11.1 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.11.1 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47538.html * https://www.suse.com/security/cve/CVE-2024-47541.html * https://www.suse.com/security/cve/CVE-2024-47542.html * https://www.suse.com/security/cve/CVE-2024-47600.html * https://www.suse.com/security/cve/CVE-2024-47607.html * https://www.suse.com/security/cve/CVE-2024-47615.html * https://www.suse.com/security/cve/CVE-2024-47835.html * https://bugzilla.suse.com/show_bug.cgi?id=1234415 * https://bugzilla.suse.com/show_bug.cgi?id=1234450 * https://bugzilla.suse.com/show_bug.cgi?id=1234453 * https://bugzilla.suse.com/show_bug.cgi?id=1234455 * https://bugzilla.suse.com/show_bug.cgi?id=1234456 * https://bugzilla.suse.com/show_bug.cgi?id=1234459 * https://bugzilla.suse.com/show_bug.cgi?id=1234460 . The gstreamer-plugins-base upgrade addresses significant security vulnerabilities in openSUSE. Ensure you install the newest patch promptly for your protection.. gstreamer plugins base security, openSUSE patches, security updates, SUSE vulnerabilities, important security advisory. . Severity: Important. LinuxSecurity.com Team
A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c. (CVE-2024-39134) References: . MGASA-2024-0289 - Updated zziplib packages fix security vulnerability Publication date: 10 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0289.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-39134 A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c. (CVE-2024-39134) References: - https://bugs.mageia.org/show_bug.cgi?id=33527 - https://lists.suse.com/pipermail/sle-security-updates/2024-August/019205.html - https://www.cve.org/CVERecord?id=CVE-2024-39134 SRPMS: - 9/core/zziplib-0.13.72-2.2.mga9 . The Mageia security advisory MGASA-2024-0290 tackles a critical vulnerability in zziplib, which involves a stack buffer overflow, aiming to prevent potential denial of service incidents.. zziplib security, buffer overflow fix, mageia advisory, dos threat, security update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.