Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
98

Red Hat OpenShift Data Foundation 4.12.1 Security Update RHSA-2023-1170

Red Hat OpenShift Data Foundation 4.12.1 Bug Fix Update Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Data Foundation 4.12.1 security bug fix update Advisory ID: RHSA-2023:1170-01 Product: RHODF Advisory URL: https://access.redhat.com/errata/RHSA-2023:1170 Issue date: 2023-03-08 CVE Names: CVE-2020-10735 CVE-2021-4238 CVE-2021-28861 CVE-2022-3650 CVE-2022-4415 CVE-2022-40897 CVE-2022-45061 CVE-2022-47629 ==================================================================== 1. Summary: Red Hat OpenShift Data Foundation 4.12.1 Bug Fix Update Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Data Foundation. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Data Foundation provisions a multicloud data management service with an S3 compatible API. Security Fix: * goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be (CVE-2021-4238) For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE pages listed in theReferences section. Bug fixes: * Previously, wrong and unclear error messages were displayed on Failover/Relocate modal. With this fix, appropriate error messages with links to documentation is added to most of the error messages. (BZ#2161903) * With this update, the read operations performance of the Multicloud Object Gateway database is improved. To achieve this, a certain regular expressions that are used by some of the queries that run against the database to serve the required data are pre-compiled. This saves time when run in real-time. (BZ#2149861) * Previously, the default container created in Azure was with public access enabled. With this fix, the default container created will not have the public access enabled which means `AllowBlobPublicAccess` is set to false. (BZ#2168838) * With this update, the `multicluster-orchestrator` operator is listed under the operators supporting disconnected mode installations. To list this operator, the disconnected mode support annotation is added to CSV as the user interface (UI) uses this annotation. (BZ#2166223) All users of Red Hat OpenShift Data Foundation are advised to upgrade to these updated images, which provide these bug fixes. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2123501 - [RDR] Pod stuck due to error "applyFSGroup failed for vol" for a PVC that was relocated 2156729 - CVE-2021-4238 goutils: RandomAlphaNumeric and CryptoRandomAlphaNumeric are not as random as they should be 2159466 - [MDR RDR] Application user unable to invoke Failover and Relocate actions 2161652 - Namespace store fails to get created via the ODF UI 2165493 - [MCG] Azure bs/ns creation fails with target bucket does not exists 2165960 - [4.12.z clone] ocs-operator CSV is missing disconnected env annotation. 2166220 - [RFE] ODF bluewash introduction in4.12.x 2166223 - CSV is missing disconnected env annotation and relatedImages spec 2167301 - [RFE] ODF bluewash introduction in 4.12.x 2167950 - CSV is missing disconnected env annotation and relatedImages spec 2168637 - fix redirect link to operator details page (OCS dashboard) 2170106 - Update to RHCS 5.3z1 Ceph container image at ODF-4.12.1 2170449 - Include at ODF 4.12 container images the RHEL8 CVE fix on "libksba" 5. References: https://access.redhat.com/security/cve/CVE-2020-10735 https://access.redhat.com/security/cve/CVE-2021-4238 https://access.redhat.com/security/cve/CVE-2021-28861 https://access.redhat.com/security/cve/CVE-2022-3650 https://access.redhat.com/security/cve/CVE-2022-4415 https://access.redhat.com/security/cve/CVE-2022-40897 https://access.redhat.com/security/cve/CVE-2022-45061 https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZAkjw9zjgjWX9erEAQhvEhAAjCAp2/GQUI0yUkWoltJ1BKFH9lyeceh3 KuH5BTN/05smpatHAzv1FzQDXWDi5FdXw9F/EPGfKMK3V86LydVGMjg0OR+ay9NZ ffx9V8RMpyogLX6/P17xtthp+6JHNAZrkjDgNADByVOQppKqQulMIgzsT4BqvuR7 kP/5PDmHdRv6667rTbJFnYJ/KbWq3Yw5yCfocuSViePFEBHcGKZhA39HSs4hWvVe C7jKaK46AIJ5+mEyHzXHIvjb1VnEYdCHrOrYTf6OIx+TXdGnWi5oOQEFrxe/s7D5 G6mk/PAq42yNds/a7ZKg3kiDQhkjnL+2DejnIils2teLtGTSGSOsyv9qX3v0mAPP SM/18C6zH6J1ZjAEIB6byhsGKPbhyi2CybBvTkoylri5oEnD6UR6Z8tREGNusSB8 aomD4SYAcLTZSE1/8pZzTvPmrsEc+fV8LztDYFOK9nm7BDvFPmtco4bpQPV2gT6H xSYmRMhj5aGkg5YxS08+EvfS78VQqzxV+Jx5Hr0nU1QT5cugTgr+RxfBPEVyyAU6 yGg5+kqSa5jGxEJMlNt5NAAHckP7StDdPnye217S1b0P8oeY8EpYJ7xUjHmRuIHQ Vkhp5LMnZFIJwv+Nh9EywMfhB3I9acMAQvRutW+IlY6L6XqJtenqbuUoWA4MO5vV YImyLRk8vWk=6IQw -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Oracle Cloud Infrastructure 2023.2.1 security patch rated Critical. Addresses majorvulnerabilities, enhances network stability.. Red Hat OpenShift, Data Foundation, security update, bug fix, storage solution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 09, 2023 Important Red Hat
98

Red Hat OpenShift Container Storage 4.6 Moderate Advisory: RHSA-2020-5606

An update for mcg is now available for Red Hat OpenShift Container Storage 4.6.0 on RHEL-8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenShift Container Storage 4.6 bug fix and enhancement update Advisory ID: RHSA-2020:5606-01 Product: Red Hat OpenShift Container Storage Advisory URL: https://access.redhat.com/errata/RHSA-2020:5606 Issue date: 2020-12-17 CVE Names: CVE-2020-14040 CVE-2020-15586 CVE-2020-16845 ==================================================================== 1. Summary: An update for mcg is now available for Red Hat OpenShift Container Storage 4.6.0 on RHEL-8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenShift Container Storage 4.6 on RHEL-8 - ppc64le, s390x, x86_64 3. Description: Red Hat OpenShift Container Storage is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Container Storage is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. In addition to persistent storage, Red Hat OpenShift Container Storage provisions a multicloud data management service with an S3 compatible API. These updated packages include numerous security fixes, bug fixes, and enhancements. Security Fix(es): * golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash (CVE-2020-14040) * golang: data race incertain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586) * golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. These updated packages include numerous bug fixes and enhancements. Usersare directed to the Red Hat OpenShift Container Storage Release Notes for information on the most significant of these changes: torage/4.6/html/4.6_release_notes/index All Red Hat OpenShift Container Storage users are advised to upgrade to these updated packages. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1853652 - CVE-2020-14040 golang.org/x/text: possibility to trigger an infinite loop in encoding/unicode could lead to crash 1856953 - CVE-2020-15586 golang: data race in certain net/http servers including ReverseProxy can lead to DoS 1867099 - CVE-2020-16845 golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs 6. Package List: Red Hat OpenShift Container Storage 4.6 on RHEL-8: Source: mcg-5.6.0-39.2279a46.5.6.el8.src.rpm tini-0.18.0-5.el8.src.rpm ppc64le: mcg-5.6.0-39.2279a46.5.6.el8.ppc64le.rpm tini-0.18.0-5.el8.ppc64le.rpm s390x: mcg-5.6.0-39.2279a46.5.6.el8.s390x.rpm tini-0.18.0-5.el8.s390x.rpm x86_64: mcg-5.6.0-39.2279a46.5.6.el8.x86_64.rpm tini-0.18.0-5.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2020-14040 https://access.redhat.com/security/cve/CVE-2020-15586 https://access.redhat.com/security/cve/CVE-2020-16845 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX9rwMdzjgjWX9erEAQi7fhAApBiURbg1SP1Hm0rhMW4gwNnBvjalJfuD 2aPArNfStmGg0TBKOW6H4kkEz+WCdbuq/GcApSDH1r0l33X15zzVCjI0r62bYvo2 coKs5d5MFacRJav9eL7rjksCVvjK0k7ocQ6A9+8/Zh/KiqeM6UVfwS1lmIb7pRKB 0Mzl4M29lbdPHDCcqGEj5Io6P9b9vL3298mUXoMka0LTkSPjwY6mv5JozcrLmp// uqzC+c1wrUtC1XS/gP0w1aIDwiCq4OMEHhbGY/KdIk0jn5UvOmEkHvU5pl611VWK p+H8334tgBclRChjoGF5b4LPvko52XIle7Cjm0u/mEC+3U0vf2gwmcCV6x0GVll7 gN/Wqgm1inX+3dYU+Bk2aV81+5GdrMmGmr+FmIjBwjjFCxKwxRTLPLwGtPVp9M/P Y4JJFI0V+wQAARcO8GckTiXXLjoQtaCjJkByUPwlDpEfnRyPmHwwEqFD3ndslSE1 9xHW34hsklT67V5cnZyNZdGBnLs396UA5T/2sOwTaFMLwwQARA8zTHSg4Sz7Dpbn j/diOK3eby2DG21JH7cVPAuGBfWfAvN9fy/Aaabt7kNkrI8iVT3tciLs3MUBumf4 n3xt9wDekO/zZEuKLdCOekE2nta5K3ygFiyBQRJp1ITqV/m8g9noi4to7OBtJ+Xi 3p1+r4wp/TU=e5tm -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A flaw in Red Hat OpenShift Container Storage 4.6 may permit unauthorized access or data leaks, highlighting the need for configuration reviews and updates to maintain security. Red Hat OpenShift, Storage Solutions, RHEL-8 Update. . LinuxSecurity.com Team

Calendar 2 Dec 17, 2020 Red Hat
98

Red Hat GlusterFS Remote Access Threat RHSA-2018-1955-01 Important

An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: glusterfs security update Advisory ID: RHSA-2018:1955-01 Product: Red Hat Gluster Storage Advisory URL: https://access.redhat.com/errata/RHSA-2018:1955 Issue date: 2018-06-20 CVE Names: CVE-2018-10841 ==================================================================== 1. Summary: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Gluster Storage Server 3.3 on RHEL-6 - noarch, x86_64 Red Hat Storage Native Client for Red Hat Enterprise Linux 6 - noarch, x86_64 3. Description: GlusterFS is a key building block of Red Hat Gluster Storage. It is based on a stackable user-space design and can deliver exceptional performance for diverse workloads. GlusterFS aggregates various storage servers over network interconnections into one large, parallel network file system. Security Fix: * glusterfs: access trusted peer group via remote-host command (CVE-2018-10841) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes thechanges described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1582043 - CVE-2018-10841 glusterfs: access trusted peer group via remote-host command 6. Package List: Red Hat Gluster Storage Server 3.3 on RHEL-6: Source: glusterfs-3.8.4-54.11.el6rhs.src.rpm noarch: python-gluster-3.8.4-54.11.el6rhs.noarch.rpm x86_64: glusterfs-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-api-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-api-devel-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-cli-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-client-xlators-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-debuginfo-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-devel-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-events-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-fuse-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-ganesha-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-geo-replication-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-libs-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-rdma-3.8.4-54.11.el6rhs.x86_64.rpm glusterfs-server-3.8.4-54.11.el6rhs.x86_64.rpm Red Hat Storage Native Client for Red Hat Enterprise Linux 6: Source: glusterfs-3.8.4-54.11.el6.src.rpm noarch: python-gluster-3.8.4-54.11.el6.noarch.rpm x86_64: glusterfs-3.8.4-54.11.el6.x86_64.rpm glusterfs-api-3.8.4-54.11.el6.x86_64.rpm glusterfs-api-devel-3.8.4-54.11.el6.x86_64.rpm glusterfs-cli-3.8.4-54.11.el6.x86_64.rpm glusterfs-client-xlators-3.8.4-54.11.el6.x86_64.rpm glusterfs-debuginfo-3.8.4-54.11.el6.x86_64.rpm glusterfs-devel-3.8.4-54.11.el6.x86_64.rpm glusterfs-fuse-3.8.4-54.11.el6.x86_64.rpm glusterfs-libs-3.8.4-54.11.el6.x86_64.rpm glusterfs-rdma-3.8.4-54.11.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-10841 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBWyos7NzjgjWX9erEAQjSmQ//Qe92hlYel6MZXq3KoSGF5UxPaE6Jl4ok 665vtt4Lw/MRT0vYWQubLi2PIy6hTh8vuB1tSW83eXlfvGOYewkQrrELXny3x27c 7HeSXfWyiKGdV0GIdvzitxm9aITKsuHZ+4UKAC80v49FCP3SHinM0vMbIAgnATVv /hMrO+rKwJoTHg2rIcril7MR9aWRU8LiFeJkFcZ3Wz4RJGNZeOpSChZYzVa4tERK 628m0++kpHAMoQ14Q9eeRnOqmIwlaFv9bHr5R0p8/nyAAXjMNSg7Vl2mx911+om8 DRjKFjsKUfta1ZHXZQWpDkgstBSoggIQxskBkukXa4I9MgaDyjj3vpUxEbPLMVD+ XsdlpUFpoqLXTWjFYBuSGDIeeCF8WhKCKumHsH1R9px2FPQ6N3uY5s4u5TCXQjEQ tlQGLaFtE8lnmWa5eyOQ/VK9bD8LeaiaTd3g2VHMn3DbqJoksTMtbJ8sOnfIKA7m FGA/DU+LE1XcKIXK3/JTV5oO9dQoV4EeY2D4J+uimd1HHt6hJzpXv0Ps/8VBq2q/ c+69yUxyOymW1pY4iWj/BejhipvKWRHdoUgTNjvK7kNrvvt4Hxvsxzg/EW7rArEs yHU460Oh9nNCvAN2UI697LSTX9zj1qyYdrnW/hYcFM26aFSGyb+U3reT9CghOWZu BXi4sTxX78s=3GKa -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance the protection of your CentOS environments by applying the essential samba patch, resolving significant permission vulnerabilities efficiently.. Red Hat Gluster Storage, Security Updates, GlusterFS Access, Linux Storage Solutions. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 20, 2018 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here