Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
217

Oracle Linux 8 rsync Important Integer Overflow TOCTOU ELSA-2026-26408

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-26408 http://linux.oracle.com/errata/ELSA-2026-26408.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: rsync-3.1.3-27.el8_10.x86_64.rpm rsync-daemon-3.1.3-27.el8_10.noarch.rpm aarch64: rsync-3.1.3-27.el8_10.aarch64.rpm rsync-daemon-3.1.3-27.el8_10.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/rsync-3.1.3-27.el8_10.src.rpm Related CVEs: CVE-2026-29518 CVE-2026-43618 Description of changes: [3.1.3-27] - Integer overflow in compressed-token decoding (CVE-2026-43618) - Resolves: RHEL-174951 [3.1.3-26] - Resolves: RHEL-174950 - CVE-2026-29518 - TOCTOU symlink race in non-chrooted daemon modules _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 updated rsync packages address important security flaws including integer overflow and symlink race.. Oracle Linux Security Advisory, rsync update, Important security issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Important Oracle
100

SUSE Linux Micro rsync Important Symlink Race Auth Bypass 2026-21739-1

An update that solves eight vulnerabilities can now be installed.. # Security update for rsync Announcement ID: SUSE-SU-2026:21739-1 Release Date: 2026-05-21T11:22:07Z Rating: important References: * bsc#1254441 * bsc#1262223 * bsc#1264511 * bsc#1264512 * bsc#1264513 * bsc#1264514 * bsc#1264515 * bsc#1265296 Cross-References: * CVE-2025-10158 * CVE-2026-29518 * CVE-2026-41035 * CVE-2026-43617 * CVE-2026-43618 * CVE-2026-43619 * CVE-2026-43620 * CVE-2026-45232 CVSS scores: * CVE-2025-10158 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-10158 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-29518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-29518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-29518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41035 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41035 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41035 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41035 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L * CVE-2026-43617 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43617 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43617 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-43617 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43618 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43618 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43618 ( NVD ): 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-43618 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43619 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-43619 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-43619 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-43619 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-43620 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43620 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43620 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-43620 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43620 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-45232 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45232 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-45232 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45232 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45232 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro6.1 An update that solves eight vulnerabilities can now be installed. ## Description: This update for rsync fixes the following issues * CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511). * CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515). * CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512). * CVE-2026-43619: Symlink Race Condition via Path-Based Syscalls (bsc#1264514). * CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513). * CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-539=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * rsync-debugsource-3.3.0-slfo.1.1_6.1 * rsync-debuginfo-3.3.0-slfo.1.1_6.1 * rsync-3.3.0-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10158.html * https://www.suse.com/security/cve/CVE-2026-29518.html * https://www.suse.com/security/cve/CVE-2026-41035.html * https://www.suse.com/security/cve/CVE-2026-43617.html * https://www.suse.com/security/cve/CVE-2026-43618.html * https://www.suse.com/security/cve/CVE-2026-43619.html * https://www.suse.com/security/cve/CVE-2026-43620.html * https://www.suse.com/security/cve/CVE-2026-45232.html * https://bugzilla.suse.com/show_bug.cgi?id=1254441 * https://bugzilla.suse.com/show_bug.cgi?id=1262223 * https://bugzilla.suse.com/show_bug.cgi?id=1264511 * https://bugzilla.suse.com/show_bug.cgi?id=1264512 * https://bugzilla.suse.com/show_bug.cgi?id=1264513 * https://bugzilla.suse.com/show_bug.cgi?id=1264514 * https://bugzilla.suse.com/show_bug.cgi?id=1264515 * https://bugzilla.suse.com/show_bug.cgi?id=1265296 . SUSE updates rsync tofix multiple important issues including symlink race and authorization bypass vulnerabilities.. SUSE Patch, rsync Update, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Important SuSE
87

Debian Bookworm Imagemagick Important Code Execution Risks DSA-6210-1

Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to symlink races, information leaks, denial of service and potentially arbitrary code execution. For the oldstable distribution (bookworm), these problems have been fixed. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6210-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 14, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : imagemagick CVE ID : CVE-2026-25796 CVE-2026-25985 CVE-2026-26284 CVE-2026-26983 CVE-2026-28494 CVE-2026-28686 CVE-2026-28687 CVE-2026-28688 CVE-2026-28689 CVE-2026-28690 CVE-2026-28691 CVE-2026-28692 CVE-2026-28693 CVE-2026-30883 CVE-2026-30936 CVE-2026-30937 CVE-2026-31853 CVE-2026-32259 CVE-2026-32636 CVE-2026-33535 CVE-2026-33536 Multiple security vulnerabilities were discovered in imagemagick, a software suite used for editing and manipulating digital images, which could lead to symlink races, information leaks, denial of service and potentially arbitrary code execution. For the oldstable distribution (bookworm), these problems have been fixed in version 8:6.9.11.60+dfsg-1.6+deb12u8. We recommend that you upgrade your imagemagick packages. For the detailed security status of imagemagick please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/imagemagick Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple vulnerabilities found in imagemagick could lead toinformation leaks, denial of service, and arbitrary code execution.. imagemagick security, Debian advisory, image manipulation risks, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 14, 2026 Important Debian
100

openSUSE 15.4: SUSE-SU-2025:0011-1 moderate: pcp security fixes

* bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345 . # Security update for pcp Announcement ID: SUSE-SU-2025:0011-1 Release Date: 2025-01-03T16:49:10Z Rating: moderate References: * bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345 Cross-References: * CVE-2023-6917 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: Upgrade to 6.2.0 (bsc#1217826 / PED#8192): * CVE-2024-45770: Fixed symlink race (bsc#1230552). * CVE-2024-45769: Fixed pmstore corruption (bsc#1230551) * CVE-2023-6917: Fixed local privilege escalation from pcp user to root (bsc#1217826). Bug fixes: * Reintroduce libuv support for SLE > = 15 (bsc#1231345). * move pmlogger_daily into main package (bsc#1222815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-11=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * pcp-pmda-summary-6.2.0-150400.5.9.1 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.9.1 *libpcp_mmv1-6.2.0-150400.5.9.1 * libpcp3-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-debuginfo-6.2.0-150400.5.9.1 * pcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.9.1 * libpcp_trace2-6.2.0-150400.5.9.1 * pcp-devel-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-6.2.0-150400.5.9.1 * pcp-pmda-bind2-6.2.0-150400.5.9.1 * pcp-pmda-smart-6.2.0-150400.5.9.1 * pcp-testsuite-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-6.2.0-150400.5.9.1 * pcp-pmda-docker-6.2.0-150400.5.9.1 * pcp-pmda-cifs-6.2.0-150400.5.9.1 * pcp-testsuite-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-6.2.0-150400.5.9.1 * pcp-pmda-shping-6.2.0-150400.5.9.1 * pcp-6.2.0-150400.5.9.1 * libpcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-6.2.0-150400.5.9.1 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.9.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.9.1 * libpcp_import1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-6.2.0-150400.5.9.1 * pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-6.2.0-150400.5.9.1 * pcp-pmda-bash-6.2.0-150400.5.9.1 * pcp-pmda-mailq-6.2.0-150400.5.9.1 * libpcp_gui2-6.2.0-150400.5.9.1 * pcp-debugsource-6.2.0-150400.5.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-6.2.0-150400.5.9.1 * pcp-pmda-mounts-6.2.0-150400.5.9.1 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-6.2.0-150400.5.9.1 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.9.1 *pcp-pmda-dm-6.2.0-150400.5.9.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-weblog-6.2.0-150400.5.9.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.9.1 * libpcp3-6.2.0-150400.5.9.1 * pcp-pmda-systemd-6.2.0-150400.5.9.1 * perl-PCP-LogImport-6.2.0-150400.5.9.1 * python3-pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-6.2.0-150400.5.9.1 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-6.2.0-150400.5.9.1 * python3-pcp-6.2.0-150400.5.9.1 * pcp-gui-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.9.1 * pcp-gui-6.2.0-150400.5.9.1 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-6.2.0-150400.5.9.1 * perl-PCP-LogSummary-6.2.0-150400.5.9.1 * libpcp_import1-6.2.0-150400.5.9.1 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-cisco-6.2.0-150400.5.9.1 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.9.1 * pcp-pmda-logger-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (noarch) * pcp-pmda-gluster-6.2.0-150400.5.9.1 * pcp-doc-6.2.0-150400.5.9.1 * pcp-pmda-ds389log-6.2.0-150400.5.9.1 * pcp-pmda-elasticsearch-6.2.0-150400.5.9.1 * pcp-pmda-openvswitch-6.2.0-150400.5.9.1 * pcp-pmda-nutcracker-6.2.0-150400.5.9.1 * pcp-pmda-ds389-6.2.0-150400.5.9.1 * pcp-pmda-unbound-6.2.0-150400.5.9.1 * pcp-import-iostat2pcp-6.2.0-150400.5.9.1 * pcp-pmda-postfix-6.2.0-150400.5.9.1 * pcp-pmda-bonding-6.2.0-150400.5.9.1 *pcp-pmda-lustre-6.2.0-150400.5.9.1 * pcp-pmda-news-6.2.0-150400.5.9.1 * pcp-pmda-samba-6.2.0-150400.5.9.1 * pcp-import-sar2pcp-6.2.0-150400.5.9.1 * pcp-pmda-json-6.2.0-150400.5.9.1 * pcp-pmda-mysql-6.2.0-150400.5.9.1 * pcp-pmda-netcheck-6.2.0-150400.5.9.1 * pcp-export-pcp2zabbix-6.2.0-150400.5.9.1 * pcp-pmda-memcache-6.2.0-150400.5.9.1 * pcp-pmda-zswap-6.2.0-150400.5.9.1 * pcp-pmda-oracle-6.2.0-150400.5.9.1 * pcp-import-ganglia2pcp-6.2.0-150400.5.9.1 * pcp-pmda-rsyslog-6.2.0-150400.5.9.1 * pcp-zeroconf-6.2.0-150400.5.9.1 * pcp-pmda-lmsensors-6.2.0-150400.5.9.1 * pcp-pmda-activemq-6.2.0-150400.5.9.1 * pcp-pmda-netfilter-6.2.0-150400.5.9.1 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.9.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.9.1 * pcp-pmda-mic-6.2.0-150400.5.9.1 * pcp-pmda-slurm-6.2.0-150400.5.9.1 * pcp-export-pcp2json-6.2.0-150400.5.9.1 * pcp-export-pcp2graphite-6.2.0-150400.5.9.1 * pcp-pmda-named-6.2.0-150400.5.9.1 * pcp-pmda-gpfs-6.2.0-150400.5.9.1 * pcp-pmda-haproxy-6.2.0-150400.5.9.1 * pcp-export-pcp2influxdb-6.2.0-150400.5.9.1 * pcp-conf-6.2.0-150400.5.9.1 * pcp-pmda-nginx-6.2.0-150400.5.9.1 * pcp-pmda-openmetrics-6.2.0-150400.5.9.1 * pcp-pmda-dbping-6.2.0-150400.5.9.1 * pcp-pmda-pdns-6.2.0-150400.5.9.1 * pcp-pmda-redis-6.2.0-150400.5.9.1 * pcp-pmda-snmp-6.2.0-150400.5.9.1 * pcp-pmda-gpsd-6.2.0-150400.5.9.1 * pcp-pmda-nfsclient-6.2.0-150400.5.9.1 * pcp-export-pcp2spark-6.2.0-150400.5.9.1 * pcp-export-pcp2xml-6.2.0-150400.5.9.1 * pcp-pmda-rabbitmq-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-6.2.0-150400.5.9.1 * pcp-pmda-perfevent-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-resctrl-6.2.0-150400.5.9.1 ## References: *https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 * https://bugzilla.suse.com/show_bug.cgi?id=1231345 . SUSE releases a vital patch for pcp tackling various vulnerabilities. Safeguard your system integrity with this important update.. openSUSE security, pcp vulnerabilities, security updates, moderate advisory. . LinuxSecurity.com Team

Calendar%202 Jan 03, 2025 SuSE
202

openSUSE Leap 15.4: SUSE-SU-2025:0011-1 moderate: pcp issues

An update that solves three vulnerabilities and has two security fixes can now be installed.. # Security update for pcp Announcement ID: SUSE-SU-2025:0011-1 Release Date: 2025-01-03T16:49:10Z Rating: moderate References: * bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345 Cross-References: * CVE-2023-6917 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: Upgrade to 6.2.0 (bsc#1217826 / PED#8192): * CVE-2024-45770: Fixed symlink race (bsc#1230552). * CVE-2024-45769: Fixed pmstore corruption (bsc#1230551) * CVE-2023-6917: Fixed local privilege escalation from pcp user to root (bsc#1217826). Bug fixes: * Reintroduce libuv support for SLE > = 15 (bsc#1231345). * move pmlogger_daily into main package (bsc#1222815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-11=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * pcp-pmda-summary-6.2.0-150400.5.9.1 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.9.1 *libpcp_mmv1-6.2.0-150400.5.9.1 * libpcp3-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-debuginfo-6.2.0-150400.5.9.1 * pcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.9.1 * libpcp_trace2-6.2.0-150400.5.9.1 * pcp-devel-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-6.2.0-150400.5.9.1 * pcp-pmda-bind2-6.2.0-150400.5.9.1 * pcp-pmda-smart-6.2.0-150400.5.9.1 * pcp-testsuite-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-6.2.0-150400.5.9.1 * pcp-pmda-docker-6.2.0-150400.5.9.1 * pcp-pmda-cifs-6.2.0-150400.5.9.1 * pcp-testsuite-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-6.2.0-150400.5.9.1 * pcp-pmda-shping-6.2.0-150400.5.9.1 * pcp-6.2.0-150400.5.9.1 * libpcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-6.2.0-150400.5.9.1 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.9.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.9.1 * libpcp_import1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-6.2.0-150400.5.9.1 * pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-6.2.0-150400.5.9.1 * pcp-pmda-bash-6.2.0-150400.5.9.1 * pcp-pmda-mailq-6.2.0-150400.5.9.1 * libpcp_gui2-6.2.0-150400.5.9.1 * pcp-debugsource-6.2.0-150400.5.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-6.2.0-150400.5.9.1 * pcp-pmda-mounts-6.2.0-150400.5.9.1 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-6.2.0-150400.5.9.1 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.9.1 *pcp-pmda-dm-6.2.0-150400.5.9.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-weblog-6.2.0-150400.5.9.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.9.1 * libpcp3-6.2.0-150400.5.9.1 * pcp-pmda-systemd-6.2.0-150400.5.9.1 * perl-PCP-LogImport-6.2.0-150400.5.9.1 * python3-pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-6.2.0-150400.5.9.1 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-6.2.0-150400.5.9.1 * python3-pcp-6.2.0-150400.5.9.1 * pcp-gui-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.9.1 * pcp-gui-6.2.0-150400.5.9.1 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-6.2.0-150400.5.9.1 * perl-PCP-LogSummary-6.2.0-150400.5.9.1 * libpcp_import1-6.2.0-150400.5.9.1 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-cisco-6.2.0-150400.5.9.1 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.9.1 * pcp-pmda-logger-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (noarch) * pcp-pmda-gluster-6.2.0-150400.5.9.1 * pcp-doc-6.2.0-150400.5.9.1 * pcp-pmda-ds389log-6.2.0-150400.5.9.1 * pcp-pmda-elasticsearch-6.2.0-150400.5.9.1 * pcp-pmda-openvswitch-6.2.0-150400.5.9.1 * pcp-pmda-nutcracker-6.2.0-150400.5.9.1 * pcp-pmda-ds389-6.2.0-150400.5.9.1 * pcp-pmda-unbound-6.2.0-150400.5.9.1 * pcp-import-iostat2pcp-6.2.0-150400.5.9.1 * pcp-pmda-postfix-6.2.0-150400.5.9.1 * pcp-pmda-bonding-6.2.0-150400.5.9.1 *pcp-pmda-lustre-6.2.0-150400.5.9.1 * pcp-pmda-news-6.2.0-150400.5.9.1 * pcp-pmda-samba-6.2.0-150400.5.9.1 * pcp-import-sar2pcp-6.2.0-150400.5.9.1 * pcp-pmda-json-6.2.0-150400.5.9.1 * pcp-pmda-mysql-6.2.0-150400.5.9.1 * pcp-pmda-netcheck-6.2.0-150400.5.9.1 * pcp-export-pcp2zabbix-6.2.0-150400.5.9.1 * pcp-pmda-memcache-6.2.0-150400.5.9.1 * pcp-pmda-zswap-6.2.0-150400.5.9.1 * pcp-pmda-oracle-6.2.0-150400.5.9.1 * pcp-import-ganglia2pcp-6.2.0-150400.5.9.1 * pcp-pmda-rsyslog-6.2.0-150400.5.9.1 * pcp-zeroconf-6.2.0-150400.5.9.1 * pcp-pmda-lmsensors-6.2.0-150400.5.9.1 * pcp-pmda-activemq-6.2.0-150400.5.9.1 * pcp-pmda-netfilter-6.2.0-150400.5.9.1 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.9.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.9.1 * pcp-pmda-mic-6.2.0-150400.5.9.1 * pcp-pmda-slurm-6.2.0-150400.5.9.1 * pcp-export-pcp2json-6.2.0-150400.5.9.1 * pcp-export-pcp2graphite-6.2.0-150400.5.9.1 * pcp-pmda-named-6.2.0-150400.5.9.1 * pcp-pmda-gpfs-6.2.0-150400.5.9.1 * pcp-pmda-haproxy-6.2.0-150400.5.9.1 * pcp-export-pcp2influxdb-6.2.0-150400.5.9.1 * pcp-conf-6.2.0-150400.5.9.1 * pcp-pmda-nginx-6.2.0-150400.5.9.1 * pcp-pmda-openmetrics-6.2.0-150400.5.9.1 * pcp-pmda-dbping-6.2.0-150400.5.9.1 * pcp-pmda-pdns-6.2.0-150400.5.9.1 * pcp-pmda-redis-6.2.0-150400.5.9.1 * pcp-pmda-snmp-6.2.0-150400.5.9.1 * pcp-pmda-gpsd-6.2.0-150400.5.9.1 * pcp-pmda-nfsclient-6.2.0-150400.5.9.1 * pcp-export-pcp2spark-6.2.0-150400.5.9.1 * pcp-export-pcp2xml-6.2.0-150400.5.9.1 * pcp-pmda-rabbitmq-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-6.2.0-150400.5.9.1 * pcp-pmda-perfevent-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-resctrl-6.2.0-150400.5.9.1 ## References: *https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 * https://bugzilla.suse.com/show_bug.cgi?id=1231345 . A revision for openSUSE addresses several significant security flaws in pcp, including potential local privilege escalation and data integrity issues.. openSUSE, pcp security fix, security update 2025, Linux update, local privilege escalation. . LinuxSecurity.com Team

Calendar%202 Jan 03, 2025 OpenSUSE
202

openSUSE Leap 42.3: 2017:0955-1 Critical: Samba Symlink Vulnerability

An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.. openSUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0944-1 Rating: important References: #1012092 #1019416 #1023847 #1024416 #1027147 #993692 #993707 Cross-References: CVE-2017-2619 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that solves one vulnerability and has 6 fixes is now available. Description: This update for samba fixes the following issues: Security issues fixed: - CVE-2017-2619: Symlink race permits opening files outside share directory (bsc#1027147). Bugfixes: - Force usage of ncurses6-config thru NCURSES_CONFIG env var (bsc#1023847). - Add missing ldb module directory (bsc#1012092). - Don't package man pages for VFS modules that aren't built (bsc#993707). - sync_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416). - Document "winbind: ignore domains" parameter; (bsc#1019416). - Prevent core, make sure response-> extra_data.data is always cleared out; (bsc#993692). This update was imported from the SUSE:SLE-12-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-437=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (i586 x86_64): ctdb-4.4.2-11.3.1 ctdb-debuginfo-4.4.2-11.3.1 ctdb-tests-4.4.2-11.3.1 ctdb-tests-debuginfo-4.4.2-11.3.1 libdcerpc-binding0-4.4.2-11.3.1 libdcerpc-binding0-debuginfo-4.4.2-11.3.1 libdcerpc-devel-4.4.2-11.3.1 libdcerpc-samr-devel-4.4.2-11.3.1 libdcerpc-samr0-4.4.2-11.3.1 libdcerpc-samr0-debuginfo-4.4.2-11.3.1 libdcerpc0-4.4.2-11.3.1 libdcerpc0-debuginfo-4.4.2-11.3.1 libndr-devel-4.4.2-11.3.1 libndr-krb5pac-devel-4.4.2-11.3.1 libndr-krb5pac0-4.4.2-11.3.1 libndr-krb5pac0-debuginfo-4.4.2-11.3.1 libndr-nbt-devel-4.4.2-11.3.1 libndr-nbt0-4.4.2-11.3.1 libndr-nbt0-debuginfo-4.4.2-11.3.1 libndr-standard-devel-4.4.2-11.3.1 libndr-standard0-4.4.2-11.3.1 libndr-standard0-debuginfo-4.4.2-11.3.1 libndr0-4.4.2-11.3.1 libndr0-debuginfo-4.4.2-11.3.1 libnetapi-devel-4.4.2-11.3.1 libnetapi0-4.4.2-11.3.1 libnetapi0-debuginfo-4.4.2-11.3.1 libsamba-credentials-devel-4.4.2-11.3.1 libsamba-credentials0-4.4.2-11.3.1 libsamba-credentials0-debuginfo-4.4.2-11.3.1 libsamba-errors-devel-4.4.2-11.3.1 libsamba-errors0-4.4.2-11.3.1 libsamba-errors0-debuginfo-4.4.2-11.3.1 libsamba-hostconfig-devel-4.4.2-11.3.1 libsamba-hostconfig0-4.4.2-11.3.1 libsamba-hostconfig0-debuginfo-4.4.2-11.3.1 libsamba-passdb-devel-4.4.2-11.3.1 libsamba-passdb0-4.4.2-11.3.1 libsamba-passdb0-debuginfo-4.4.2-11.3.1 libsamba-policy-devel-4.4.2-11.3.1 libsamba-policy0-4.4.2-11.3.1 libsamba-policy0-debuginfo-4.4.2-11.3.1 libsamba-util-devel-4.4.2-11.3.1 libsamba-util0-4.4.2-11.3.1 libsamba-util0-debuginfo-4.4.2-11.3.1 libsamdb-devel-4.4.2-11.3.1 libsamdb0-4.4.2-11.3.1 libsamdb0-debuginfo-4.4.2-11.3.1 libsmbclient-devel-4.4.2-11.3.1 libsmbclient0-4.4.2-11.3.1 libsmbclient0-debuginfo-4.4.2-11.3.1 libsmbconf-devel-4.4.2-11.3.1 libsmbconf0-4.4.2-11.3.1 libsmbconf0-debuginfo-4.4.2-11.3.1 libsmbldap-devel-4.4.2-11.3.1 libsmbldap0-4.4.2-11.3.1 libsmbldap0-debuginfo-4.4.2-11.3.1 libtevent-util-devel-4.4.2-11.3.1 libtevent-util0-4.4.2-11.3.1 libtevent-util0-debuginfo-4.4.2-11.3.1 libwbclient-devel-4.4.2-11.3.1 libwbclient0-4.4.2-11.3.1 libwbclient0-debuginfo-4.4.2-11.3.1 samba-4.4.2-11.3.1 samba-client-4.4.2-11.3.1 samba-client-debuginfo-4.4.2-11.3.1 samba-core-devel-4.4.2-11.3.1 samba-debuginfo-4.4.2-11.3.1 samba-debugsource-4.4.2-11.3.1 samba-libs-4.4.2-11.3.1 samba-libs-debuginfo-4.4.2-11.3.1 samba-pidl-4.4.2-11.3.1 samba-python-4.4.2-11.3.1 samba-python-debuginfo-4.4.2-11.3.1 samba-test-4.4.2-11.3.1 samba-test-debuginfo-4.4.2-11.3.1 samba-winbind-4.4.2-11.3.1 samba-winbind-debuginfo-4.4.2-11.3.1 - openSUSE Leap 42.2 (x86_64): libdcerpc-binding0-32bit-4.4.2-11.3.1 libdcerpc-binding0-debuginfo-32bit-4.4.2-11.3.1 libdcerpc-samr0-32bit-4.4.2-11.3.1 libdcerpc-samr0-debuginfo-32bit-4.4.2-11.3.1 libdcerpc0-32bit-4.4.2-11.3.1 libdcerpc0-debuginfo-32bit-4.4.2-11.3.1 libndr-krb5pac0-32bit-4.4.2-11.3.1 libndr-krb5pac0-debuginfo-32bit-4.4.2-11.3.1 libndr-nbt0-32bit-4.4.2-11.3.1 libndr-nbt0-debuginfo-32bit-4.4.2-11.3.1 libndr-standard0-32bit-4.4.2-11.3.1 libndr-standard0-debuginfo-32bit-4.4.2-11.3.1 libndr0-32bit-4.4.2-11.3.1 libndr0-debuginfo-32bit-4.4.2-11.3.1 libnetapi0-32bit-4.4.2-11.3.1 libnetapi0-debuginfo-32bit-4.4.2-11.3.1 libsamba-credentials0-32bit-4.4.2-11.3.1 libsamba-credentials0-debuginfo-32bit-4.4.2-11.3.1 libsamba-errors0-32bit-4.4.2-11.3.1 libsamba-errors0-debuginfo-32bit-4.4.2-11.3.1 libsamba-hostconfig0-32bit-4.4.2-11.3.1 libsamba-hostconfig0-debuginfo-32bit-4.4.2-11.3.1 libsamba-passdb0-32bit-4.4.2-11.3.1 libsamba-passdb0-debuginfo-32bit-4.4.2-11.3.1 libsamba-policy0-32bit-4.4.2-11.3.1 libsamba-policy0-debuginfo-32bit-4.4.2-11.3.1 libsamba-util0-32bit-4.4.2-11.3.1 libsamba-util0-debuginfo-32bit-4.4.2-11.3.1 libsamdb0-32bit-4.4.2-11.3.1 libsamdb0-debuginfo-32bit-4.4.2-11.3.1 libsmbclient0-32bit-4.4.2-11.3.1 libsmbclient0-debuginfo-32bit-4.4.2-11.3.1 libsmbconf0-32bit-4.4.2-11.3.1 libsmbconf0-debuginfo-32bit-4.4.2-11.3.1 libsmbldap0-32bit-4.4.2-11.3.1 libsmbldap0-debuginfo-32bit-4.4.2-11.3.1 libtevent-util0-32bit-4.4.2-11.3.1 libtevent-util0-debuginfo-32bit-4.4.2-11.3.1 libwbclient0-32bit-4.4.2-11.3.1 libwbclient0-debuginfo-32bit-4.4.2-11.3.1 samba-client-32bit-4.4.2-11.3.1 samba-client-debuginfo-32bit-4.4.2-11.3.1 samba-libs-32bit-4.4.2-11.3.1 samba-libs-debuginfo-32bit-4.4.2-11.3.1 samba-winbind-32bit-4.4.2-11.3.1 samba-winbind-debuginfo-32bit-4.4.2-11.3.1 - openSUSE Leap 42.2 (noarch): samba-doc-4.4.2-11.3.1 References: https://www.suse.com/security/cve/CVE-2017-2619.html https://bugzilla.suse.com/1012092 https://bugzilla.suse.com/1019416 https://bugzilla.suse.com/1023847 https://bugzilla.suse.com/1024416 https://bugzilla.suse.com/1027147 https://bugzilla.suse.com/993692 https://bugzilla.suse.com/993707 . The latest release for openSUSE addresses a critical flaw in Samba linked to a symlink race security risk. Discover further details within.. openSUSE, samba security, important update, symlink race. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2017 Important OpenSUSE
202

openSUSE Leap 42.1: SUSE-SU-2017:0935-1 Important Samba Symlink Race

An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.. openSUSE Security Update: Security update for samba ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0935-1 Rating: important References: #1019416 #1024416 #1027147 #993692 #993707 Cross-References: CVE-2017-2619 Affected Products: openSUSE Leap 42.1 ______________________________________________________________________________ An update that solves one vulnerability and has four fixes is now available. Description: This update for samba fixes the following issues: Security issues fixed: - CVE-2017-2619: Symlink race permits opening files outside share directory (bsc#1027147). Bugfixes: - Don't package man pages for VFS modules that aren't built (bsc#993707). - sync_req: make async_connect_send() "reentrant"; (bso#12105); (bsc#1024416). - Document "winbind: ignore domains" parameter; (bsc#1019416). - Prevent core, make sure response-> extra_data.data is always cleared out; (bsc#993692). This update was imported from the SUSE:SLE-12-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.1: zypper in -t patch openSUSE-2017-439=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.1 (i586 x86_64): ctdb-4.2.4-27.1 ctdb-debuginfo-4.2.4-27.1 ctdb-devel-4.2.4-27.1 ctdb-tests-4.2.4-27.1 ctdb-tests-debuginfo-4.2.4-27.1 libdcerpc-atsvc-devel-4.2.4-27.1 libdcerpc-atsvc0-4.2.4-27.1 libdcerpc-atsvc0-debuginfo-4.2.4-27.1 libdcerpc-binding0-4.2.4-27.1 libdcerpc-binding0-debuginfo-4.2.4-27.1 libdcerpc-devel-4.2.4-27.1 libdcerpc-samr-devel-4.2.4-27.1 libdcerpc-samr0-4.2.4-27.1 libdcerpc-samr0-debuginfo-4.2.4-27.1 libdcerpc0-4.2.4-27.1 libdcerpc0-debuginfo-4.2.4-27.1 libgensec-devel-4.2.4-27.1 libgensec0-4.2.4-27.1 libgensec0-debuginfo-4.2.4-27.1 libndr-devel-4.2.4-27.1 libndr-krb5pac-devel-4.2.4-27.1 libndr-krb5pac0-4.2.4-27.1 libndr-krb5pac0-debuginfo-4.2.4-27.1 libndr-nbt-devel-4.2.4-27.1 libndr-nbt0-4.2.4-27.1 libndr-nbt0-debuginfo-4.2.4-27.1 libndr-standard-devel-4.2.4-27.1 libndr-standard0-4.2.4-27.1 libndr-standard0-debuginfo-4.2.4-27.1 libndr0-4.2.4-27.1 libndr0-debuginfo-4.2.4-27.1 libnetapi-devel-4.2.4-27.1 libnetapi0-4.2.4-27.1 libnetapi0-debuginfo-4.2.4-27.1 libregistry-devel-4.2.4-27.1 libregistry0-4.2.4-27.1 libregistry0-debuginfo-4.2.4-27.1 libsamba-credentials-devel-4.2.4-27.1 libsamba-credentials0-4.2.4-27.1 libsamba-credentials0-debuginfo-4.2.4-27.1 libsamba-hostconfig-devel-4.2.4-27.1 libsamba-hostconfig0-4.2.4-27.1 libsamba-hostconfig0-debuginfo-4.2.4-27.1 libsamba-passdb-devel-4.2.4-27.1 libsamba-passdb0-4.2.4-27.1 libsamba-passdb0-debuginfo-4.2.4-27.1 libsamba-policy-devel-4.2.4-27.1 libsamba-policy0-4.2.4-27.1 libsamba-policy0-debuginfo-4.2.4-27.1 libsamba-util-devel-4.2.4-27.1 libsamba-util0-4.2.4-27.1 libsamba-util0-debuginfo-4.2.4-27.1 libsamdb-devel-4.2.4-27.1 libsamdb0-4.2.4-27.1 libsamdb0-debuginfo-4.2.4-27.1 libsmbclient-devel-4.2.4-27.1 libsmbclient-raw-devel-4.2.4-27.1 libsmbclient-raw0-4.2.4-27.1 libsmbclient-raw0-debuginfo-4.2.4-27.1 libsmbclient0-4.2.4-27.1 libsmbclient0-debuginfo-4.2.4-27.1 libsmbconf-devel-4.2.4-27.1 libsmbconf0-4.2.4-27.1 libsmbconf0-debuginfo-4.2.4-27.1 libsmbldap-devel-4.2.4-27.1 libsmbldap0-4.2.4-27.1 libsmbldap0-debuginfo-4.2.4-27.1 libtevent-util-devel-4.2.4-27.1 libtevent-util0-4.2.4-27.1 libtevent-util0-debuginfo-4.2.4-27.1 libwbclient-devel-4.2.4-27.1 libwbclient0-4.2.4-27.1 libwbclient0-debuginfo-4.2.4-27.1 samba-4.2.4-27.1 samba-client-4.2.4-27.1 samba-client-debuginfo-4.2.4-27.1 samba-core-devel-4.2.4-27.1 samba-debuginfo-4.2.4-27.1 samba-debugsource-4.2.4-27.1 samba-libs-4.2.4-27.1 samba-libs-debuginfo-4.2.4-27.1 samba-pidl-4.2.4-27.1 samba-python-4.2.4-27.1 samba-python-debuginfo-4.2.4-27.1 samba-test-4.2.4-27.1 samba-test-debuginfo-4.2.4-27.1 samba-test-devel-4.2.4-27.1 samba-winbind-4.2.4-27.1 samba-winbind-debuginfo-4.2.4-27.1 - openSUSE Leap 42.1 (x86_64): libdcerpc-atsvc0-32bit-4.2.4-27.1 libdcerpc-atsvc0-debuginfo-32bit-4.2.4-27.1 libdcerpc-binding0-32bit-4.2.4-27.1 libdcerpc-binding0-debuginfo-32bit-4.2.4-27.1 libdcerpc-samr0-32bit-4.2.4-27.1 libdcerpc-samr0-debuginfo-32bit-4.2.4-27.1 libdcerpc0-32bit-4.2.4-27.1 libdcerpc0-debuginfo-32bit-4.2.4-27.1 libgensec0-32bit-4.2.4-27.1 libgensec0-debuginfo-32bit-4.2.4-27.1 libndr-krb5pac0-32bit-4.2.4-27.1 libndr-krb5pac0-debuginfo-32bit-4.2.4-27.1 libndr-nbt0-32bit-4.2.4-27.1 libndr-nbt0-debuginfo-32bit-4.2.4-27.1 libndr-standard0-32bit-4.2.4-27.1 libndr-standard0-debuginfo-32bit-4.2.4-27.1 libndr0-32bit-4.2.4-27.1 libndr0-debuginfo-32bit-4.2.4-27.1 libnetapi0-32bit-4.2.4-27.1 libnetapi0-debuginfo-32bit-4.2.4-27.1 libregistry0-32bit-4.2.4-27.1 libregistry0-debuginfo-32bit-4.2.4-27.1 libsamba-credentials0-32bit-4.2.4-27.1 libsamba-credentials0-debuginfo-32bit-4.2.4-27.1 libsamba-hostconfig0-32bit-4.2.4-27.1 libsamba-hostconfig0-debuginfo-32bit-4.2.4-27.1 libsamba-passdb0-32bit-4.2.4-27.1 libsamba-passdb0-debuginfo-32bit-4.2.4-27.1 libsamba-policy0-32bit-4.2.4-27.1 libsamba-policy0-debuginfo-32bit-4.2.4-27.1 libsamba-util0-32bit-4.2.4-27.1 libsamba-util0-debuginfo-32bit-4.2.4-27.1 libsamdb0-32bit-4.2.4-27.1 libsamdb0-debuginfo-32bit-4.2.4-27.1 libsmbclient-raw0-32bit-4.2.4-27.1 libsmbclient-raw0-debuginfo-32bit-4.2.4-27.1 libsmbclient0-32bit-4.2.4-27.1 libsmbclient0-debuginfo-32bit-4.2.4-27.1 libsmbconf0-32bit-4.2.4-27.1 libsmbconf0-debuginfo-32bit-4.2.4-27.1 libsmbldap0-32bit-4.2.4-27.1 libsmbldap0-debuginfo-32bit-4.2.4-27.1 libtevent-util0-32bit-4.2.4-27.1 libtevent-util0-debuginfo-32bit-4.2.4-27.1 libwbclient0-32bit-4.2.4-27.1 libwbclient0-debuginfo-32bit-4.2.4-27.1 samba-32bit-4.2.4-27.1 samba-client-32bit-4.2.4-27.1 samba-client-debuginfo-32bit-4.2.4-27.1 samba-debuginfo-32bit-4.2.4-27.1 samba-libs-32bit-4.2.4-27.1 samba-libs-debuginfo-32bit-4.2.4-27.1 samba-winbind-32bit-4.2.4-27.1 samba-winbind-debuginfo-32bit-4.2.4-27.1 - openSUSE Leap 42.1 (noarch): samba-doc-4.2.4-27.1 References: https://www.suse.com/security/cve/CVE-2017-2619.html https://bugzilla.suse.com/1019416 https://bugzilla.suse.com/1024416 https://bugzilla.suse.com/1027147 https://bugzilla.suse.com/993692 https://bugzilla.suse.com/993707 . Security enhancement for samba addresses vulnerabilities in openSUSE Leap 42.1. Priority: high, patches implemented where necessary.. openSUSE,samba,security update,symlink race,software fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2017 Important OpenSUSE
89

Fedora 25 Samba Update: CVE-2017-2619 Critical Symlink Race Issue

Security fix for CVE-2017-2619. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-c22a1dbe8b 2017-04-02 15:51:56.518239 -------------------------------------------------------------------------------- Name : samba Product : Fedora 25 Version : 4.5.8 Release : 0.fc25 URL : / Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2619 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1429472 - CVE-2017-2619 samba: symlink race permits opening files outside share directory https://bugzilla.redhat.com/show_bug.cgi?id=1429472 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade samba' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent security patch for Samba pertains to CVE-2023-1234, with the advisory outlining essential modifications to enhance system integrity.. Fedora Update,Samba Software,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200