* bsc#1228578 * bsc#1235916 Cross-References: * CVE-2024-41062 . # Security update for the Linux Kernel RT (Live Patch 1 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:1064-1 Release Date: 2025-03-31T13:03:55Z Rating: important References: * bsc#1228578 * bsc#1235916 Cross-References: * CVE-2024-41062 * CVE-2024-57882 CVSS scores: * CVE-2024-41062 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-41062 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-57882 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-57882 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2024-57882 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_10_5 fixes several issues. The following security issues were fixed: * CVE-2024-57882: mptcp: fix TCP options overflow. (bsc#1235916). * CVE-2024-41062: Sync sock recv cb and release (bsc#1228578). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-1064=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * kernel-livepatch-6_4_0-150600_10_5-rt-debuginfo-11-150600.2.1 * kernel-livepatch-SLE15-SP6-RT_Update_1-debugsource-11-150600.2.1 * kernel-livepatch-6_4_0-150600_10_5-rt-11-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-41062.html *https://www.suse.com/security/cve/CVE-2024-57882.html * https://bugzilla.suse.com/show_bug.cgi?id=1228578 * https://bugzilla.suse.com/show_bug.cgi?id=1235916 . Important update for the Linux Kernel RT addressing two critical issues to enhance system stability.. bsc#1228578, bsc#1235916, cross-references, cve-2024-41062, security, update, linux, kerne. . Severity: Important. LinuxSecurity.com Team
**MariaDB 10.5.23 & Galera 26.4.16** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-23-release-notes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-2eca0baace 2023-11-26 01:54:52.536184 -------------------------------------------------------------------------------- Name : galera Product : Fedora 39 Version : 26.4.16 Release : 1.fc39 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multimaster wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://github.com/mariadb-corporation/wsrep-API repository. For a description of Galera replication engine see https://mariadb.com/products/enterprise/galera-cluster/ web. -------------------------------------------------------------------------------- Update Information: **MariaDB 10.5.23 & Galera 26.4.16** Release notes: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-23-release-notes -------------------------------------------------------------------------------- ChangeLog: * Fri Nov 17 2023 Michal Schorm - 26.4.16-1 - Rebase to 26.4.16 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2249665 - CVE-2023-22084 mariadb: mysql: InnoDB unspecified vulnerability (CPU Oct 2023) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2249665 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2eca0baace' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
389-ds-base: SIGSEGV in sync_repl (CVE-2022-2850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Import may break replication because changelog starting csn may not be created SL7 x86_64 389-ds-base-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-debuginfo-1.3.10.2-17.el7_9 [More...]. Synopsis: Moderate: 389-ds-base security and bug fix update Advisory ID: SLSA-2022:7087-1 Issue Date: 2022-10-25 CVE Numbers: CVE-2022-2850 -- Security Fix(es): * 389-ds-base: SIGSEGV in sync_repl (CVE-2022-2850) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Import may break replication because changelog starting csn may not be created -- SL7 x86_64 389-ds-base-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-debuginfo-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-devel-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-libs-1.3.10.2-17.el7_9.x86_64.rpm 389-ds-base-snmp-1.3.10.2-17.el7_9.x86_64.rpm - Scientific Linux Development Team . Alert: Update on moderate 389-ds-base concerning SIGSEGV bug impacting sync_repl security flaw. Further information enclosed.. 389-ds-base Security Update, Scientific Linux Bug Fix, Sync Replication Issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.