Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7516-9 May 29, 2025 linux-aws vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - PowerPC architecture; - Block layer subsystem; - Drivers core; - Network block device driver; - Character device driver; - GPU drivers; - HID subsystem; - InfiniBand drivers; - Media drivers; - Network drivers; - PPS (Pulse Per Second) driver; - PTP clock framework; - RapidIO drivers; - Real Time Clock drivers; - SCSI subsystem; - SLIMbus drivers; - QCOM SoC drivers; - Trusted Execution Environment drivers; - USB DSL drivers; - USB Device Class drivers; - USB core drivers; - USB Gadget drivers; - USB Host Controller drivers; - Renesas USBHS Controller drivers; - File systems infrastructure; - BTRFS file system; - NILFS2 file system; - UBI file system; - KVM subsystem; - L3 Master device support module; - Process Accounting mechanism; - printk logging mechanism; - Scheduler infrastructure; - Tracing infrastructure; - Memory management; - 802.1Q VLAN protocol; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - Networking core; - IPv4 networking; - IPv6 networking; - Logical Link layer; - NFC subsystem; - Open vSwitch; - Rose network layer; - Network traffic control; - Wireless networking; - Tomoyo security module; (CVE-2025-21835, CVE-2025-21760, CVE-2025-21914,CVE-2025-21744, CVE-2024-57977, CVE-2024-58001, CVE-2025-21848, CVE-2024-57981, CVE-2024-58055, CVE-2025-21721, CVE-2025-21925, CVE-2025-21764, CVE-2025-21909, CVE-2024-26996, CVE-2024-56599, CVE-2025-21728, CVE-2025-21782, CVE-2025-21866, CVE-2024-58069, CVE-2025-21859, CVE-2024-58007, CVE-2024-58009, CVE-2025-21904, CVE-2024-58085, CVE-2025-21920, CVE-2024-58058, CVE-2025-21811, CVE-2025-21922, CVE-2025-21948, CVE-2024-58090, CVE-2024-57980, CVE-2025-21823, CVE-2024-58052, CVE-2025-21736, CVE-2025-21917, CVE-2021-47191, CVE-2024-58051, CVE-2024-58017, CVE-2025-21846, CVE-2025-21862, CVE-2025-21722, CVE-2024-57986, CVE-2025-21871, CVE-2025-21865, CVE-2023-52741, CVE-2025-21971, CVE-2025-21718, CVE-2025-21814, CVE-2025-21704, CVE-2025-21934, CVE-2025-21781, CVE-2025-21791, CVE-2025-21708, CVE-2025-21935, CVE-2025-21761, CVE-2025-21719, CVE-2025-21763, CVE-2025-21772, CVE-2025-21905, CVE-2025-21731, CVE-2024-58002, CVE-2024-58083, CVE-2025-21858, CVE-2025-21776, CVE-2025-21762, CVE-2025-21928, CVE-2025-21877, CVE-2025-21910, CVE-2024-58010, CVE-2025-21735, CVE-2024-50055, CVE-2025-21785, CVE-2024-57973, CVE-2025-21806, CVE-2025-21749, CVE-2024-58063, CVE-2024-57979, CVE-2025-21753, CVE-2024-26982, CVE-2025-21647, CVE-2025-21898, CVE-2024-58020, CVE-2024-58071, CVE-2025-21926, CVE-2025-21715, CVE-2025-21765, CVE-2025-21787, CVE-2025-21916, CVE-2024-58014, CVE-2024-58072) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1146-aws 5.4.0-1146.156 linux-image-aws-lts-20.04 5.4.0.1146.143 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE,linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7516-9 https://ubuntu.com/security/notices/USN-7516-8 https://ubuntu.com/security/notices/USN-7516-7 https://ubuntu.com/security/notices/USN-7516-6 https://ubuntu.com/security/notices/USN-7516-5 https://ubuntu.com/security/notices/USN-7516-4 https://ubuntu.com/security/notices/USN-7516-3 https://ubuntu.com/security/notices/USN-7516-2 https://ubuntu.com/security/notices/USN-7516-1 CVE-2021-47191, CVE-2023-52741, CVE-2024-26982, CVE-2024-26996, CVE-2024-50055, CVE-2024-56599, CVE-2024-57973, CVE-2024-57977, CVE-2024-57979, CVE-2024-57980, CVE-2024-57981, CVE-2024-57986, CVE-2024-58001, CVE-2024-58002, CVE-2024-58007, CVE-2024-58009, CVE-2024-58010, CVE-2024-58014, CVE-2024-58017, CVE-2024-58020, CVE-2024-58051, CVE-2024-58052, CVE-2024-58055, CVE-2024-58058, CVE-2024-58063, CVE-2024-58069, CVE-2024-58071, CVE-2024-58072, CVE-2024-58083, CVE-2024-58085, CVE-2024-58090, CVE-2025-21647, CVE-2025-21704, CVE-2025-21708, CVE-2025-21715, CVE-2025-21718, CVE-2025-21719, CVE-2025-21721, CVE-2025-21722, CVE-2025-21728, CVE-2025-21731, CVE-2025-21735, CVE-2025-21736, CVE-2025-21744, CVE-2025-21749, CVE-2025-21753, CVE-2025-21760, CVE-2025-21761, CVE-2025-21762, CVE-2025-21763, CVE-2025-21764, CVE-2025-21765, CVE-2025-21772, CVE-2025-21776, CVE-2025-21781, CVE-2025-21782, CVE-2025-21785, CVE-2025-21787, CVE-2025-21791, CVE-2025-21806, CVE-2025-21811, CVE-2025-21814, CVE-2025-21823, CVE-2025-21835, CVE-2025-21846, CVE-2025-21848, CVE-2025-21858, CVE-2025-21859, CVE-2025-21862, CVE-2025-21865, CVE-2025-21866, CVE-2025-21871, CVE-2025-21877, CVE-2025-21898, CVE-2025-21904, CVE-2025-21905, CVE-2025-21909, CVE-2025-21910, CVE-2025-21914, CVE-2025-21916, CVE-2025-21917, CVE-2025-21920, CVE-2025-21922, CVE-2025-21925, CVE-2025-21926, CVE-2025-21928, CVE-2025-21934, CVE-2025-21935, CVE-2025-21948, CVE-2025-21971 PackageInformation: https://launchpad.net/ubuntu/+source/linux-aws/5.4.0-1146.156 . Uncover vital enhancements for Ubuntu 20.04 LTS targeting various kernel vulnerabilities crucial for safeguarding your system.. Linux Kernel Patches, Ubuntu 20.04 Updates, AWS Security Enhancements, System Update Best Practices. . Severity: Critical. LinuxSecurity.com Team
MariaDB 10.11.8 & Galera 26.4.18 Release notes: https://mariadb.com/docs/release-notes/community-server/10.11/10.11.7 https://mariadb.com/docs/release-notes/community-server/10.11/10.11.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6ea93e629b 2024-06-10 01:27:34.209388 -------------------------------------------------------------------------------- Name : galera Product : Fedora 40 Version : 26.4.18 Release : 1.fc40 URL : https://mariadb.com/products/enterprise/galera-cluster/ Summary : Synchronous multi-master wsrep provider (replication engine) Description : Galera is a fast synchronous multimaster wsrep provider (replication engine) for transactional databases and similar applications. For more information about wsrep API see https://github.com/mariadb-corporation/wsrep-API repository. For a description of Galera replication engine see https://mariadb.com/products/enterprise/galera-cluster/ web. -------------------------------------------------------------------------------- Update Information: MariaDB 10.11.8 & Galera 26.4.18 Release notes: https://mariadb.com/docs/release-notes/community-server/10.11/10.11.7 https://mariadb.com/docs/release-notes/community-server/10.11/10.11.8 -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 7 2024 Michal Schorm - 26.4.18-1 - Rebase to 26.4.18 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2256983 - galera-26.4.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=2256983 [ 2 ] Bug #2282490 - CVE-2024-21096 mariadb10.11: mysql: Client: mysqldump unspecified vulnerability (CPU Apr 2024) [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2282490 [ 3 ] Bug #2283500 - Directories are missing in RPM database. https://bugzilla.redhat.com/show_bug.cgi?id=2283500 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6ea93e629b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
* bsc#1224806 Cross-References: * CVE-2024-4453 . # Security update for gstreamer-plugins-base Announcement ID: SUSE-SU-2024:1882-1 Rating: important References: * bsc#1224806 Cross-References: * CVE-2024-4453 CVSS scores: * CVE-2024-4453 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-base fixes the following issues: * CVE-2024-4453: Fixed lack of proper validation of user-supplied data when parsing EXIF metadata (bsc#1224806) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1882=1 openSUSE-SLE-15.5-2024-1882=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-1882=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1882=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-1882=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.8.2 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-1.22.0-150500.3.8.2 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.8.2 *libgstaudio-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-1.22.0-150500.3.8.2 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstfft-1_0-0-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-devel-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.8.2 * libgstapp-1_0-0-1.22.0-150500.3.8.2 * libgstriff-1_0-0-1.22.0-150500.3.8.2 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.8.2 * libgstrtp-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.8.2 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.8.2 * libgstgl-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.8.2 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-1.22.0-150500.3.8.2 * openSUSE Leap 15.5 (x86_64) * libgstsdp-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstriff-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-32bit-1.22.0-150500.3.8.2 *libgstapp-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstriff-1_0-0-32bit-1.22.0-150500.3.8.2 * gstreamer-plugins-base-32bit-1.22.0-150500.3.8.2 * libgstrtp-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstfft-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstapp-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstgl-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstrtp-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-32bit-1.22.0-150500.3.8.2 * gstreamer-plugins-base-devel-32bit-1.22.0-150500.3.8.2 * libgsttag-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstgl-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstfft-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-32bit-1.22.0-150500.3.8.2 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.8.2 * openSUSE Leap 15.5 (aarch64_ilp32) * libgstrtsp-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstgl-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstfft-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-64bit-1.22.0-150500.3.8.2 * gstreamer-plugins-base-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstrtp-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstriff-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstfft-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 *libgstrtp-1_0-0-64bit-1.22.0-150500.3.8.2 * gstreamer-plugins-base-devel-64bit-1.22.0-150500.3.8.2 * libgstapp-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-64bit-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-64bit-1.22.0-150500.3.8.2 * libgstgl-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstriff-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgstapp-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-64bit-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-64bit-1.22.0-150500.3.8.2 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstapp-1_0-0-1.22.0-150500.3.8.2 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-1.22.0-150500.3.8.2 * libgstriff-1_0-0-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.8.2 * libgstgl-1_0-0-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-1.22.0-150500.3.8.2 * libgstriff-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-1.22.0-150500.3.8.2 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libgstrtp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstGLX11-1_0-1.22.0-150500.3.8.2 * libgsttag-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-1.22.0-150500.3.8.2 *libgstriff-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstAllocators-1_0-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstTag-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstRtp-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstRtsp-1_0-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-1.22.0-150500.3.8.2 * libgstgl-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstsdp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgstfft-1_0-0-1.22.0-150500.3.8.2 * libgstpbutils-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-devel-1.22.0-150500.3.8.2 * libgstrtsp-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstPbutils-1_0-1.22.0-150500.3.8.2 * libgstapp-1_0-0-1.22.0-150500.3.8.2 * libgstriff-1_0-0-1.22.0-150500.3.8.2 * libgstfft-1_0-0-debuginfo-1.22.0-150500.3.8.2 * libgsttag-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.8.2 * libgstrtp-1_0-0-1.22.0-150500.3.8.2 * typelib-1_0-GstAudio-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstSdp-1_0-1.22.0-150500.3.8.2 * libgstapp-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstVideo-1_0-1.22.0-150500.3.8.2 * libgstgl-1_0-0-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.8.2 * typelib-1_0-GstGLWayland-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstGL-1_0-1.22.0-150500.3.8.2 * libgstallocators-1_0-0-debuginfo-1.22.0-150500.3.8.2 * typelib-1_0-GstApp-1_0-1.22.0-150500.3.8.2 * typelib-1_0-GstGLEGL-1_0-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-1.22.0-150500.3.8.2 * Basesystem Module 15-SP5 (noarch) * gstreamer-plugins-base-lang-1.22.0-150500.3.8.2 * SUSE Package Hub 15 15-SP5 (x86_64) * libgsttag-1_0-0-32bit-1.22.0-150500.3.8.2 *libgsttag-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * libgstaudio-1_0-0-32bit-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-32bit-debuginfo-1.22.0-150500.3.8.2 * gstreamer-plugins-base-debugsource-1.22.0-150500.3.8.2 * libgstvideo-1_0-0-32bit-1.22.0-150500.3.8.2 ## References: * https://www.suse.com/security/cve/CVE-2024-4453.html * https://bugzilla.suse.com/show_bug.cgi?id=1224806 . Essential security patches regarding gstreamer-plugins-base and CVE-2024-4453 are highlighted. System administrators must take immediate steps as outlined.. gstreamer security,recommended updates,SUSE advisory,system administration. . Severity: Important. LinuxSecurity.com Team
Red Hat Advanced Cluster Management for Kubernetes 2.5.3 General Availability release images, which fix security issues and bugs, as well as update container images. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat Advanced Cluster Management 2.5.3 security fixes and bug fixes Advisory ID: RHSA-2022:6954-01 Product: Red Hat ACM Advisory URL: https://access.redhat.com/errata/RHSA-2022:6954 Issue date: 2022-10-13 CVE Names: CVE-2015-20107 CVE-2022-0391 CVE-2022-2238 CVE-2022-21123 CVE-2022-21125 CVE-2022-21166 CVE-2022-34903 ==================================================================== 1. Summary: Red Hat Advanced Cluster Management for Kubernetes 2.5.3 General Availability release images, which fix security issues and bugs, as well as update container images. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE links in the References section. 2. Description: Red Hat Advanced Cluster Management for Kubernetes 2.5.3 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix security issues and several bugs. See the following Release Notes documentation, which will be updated shortly for this release, for additional details aboutthis release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.5/html/release_notes/index Security fix: * search-api-container: search-api: SQL injection leads to remote denial of service (CVE-2022-2238) Bug fixes: * search-aggregator pod is continuously getting OOMkilled on the hub (BZ# 2092863) * ACM 2.5 cannot create known_hosts file when pulling from ssh git repo (BZ# 2105885) * Production RHACM upgrade from v2.4.2 to 2.5.1 (BZ# 2121063) * No errors shown for failed helm deployments (BZ# 2124636) * In topology, cluster deploy status is shown as not deployed however new project is created on the cluster (BZ# 2125441) 3. Solution: For Red Hat Advanced Cluster Management for Kubernetes, see the following documentation, which will be updated shortly for this release, for important instructions about installing this release: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.5/html-single/install/index#installing 4. Bugs fixed (https://bugzilla.redhat.com/): 2092863 - search-aggregator pod is continuously getting OOMkilled on the hub 2101669 - CVE-2022-2238 search-api: SQL injection leads to remote denial of service 2105885 - ACM 2.5 cannot create known_hosts file when pulling from ssh git repo 2121063 - Production RHACM upgrade from v2.4.2 to 2.5.1 2124636 - no errors shown for failed helm deployments 2125441 - In topology, cluster deploy status is shown as not deployed however new project is created on the cluster 5. References: https://access.redhat.com/security/cve/CVE-2015-20107 https://access.redhat.com/security/cve/CVE-2022-0391 https://access.redhat.com/security/cve/CVE-2022-2238 https://access.redhat.com/security/cve/CVE-2022-21123 https://access.redhat.com/security/cve/CVE-2022-21125 https://access.redhat.com/security/cve/CVE-2022-21166 https://access.redhat.com/security/cve/CVE-2022-34903 https://access.redhat.com/security/updates/classification#moderate 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY0h7dtzjgjWX9erEAQj27g//ToLns2TgWThkVxfFX/MbwCmskyu4nChs VsaXJakIawA8wzc1tF8BHJZ3QB1geeM1K+QZZBetghoEHlqO0BB/tosPjdljgRBe VJf8v4RRdPwbp9cRnb5mSoZ7AOlRan64WHZrs5TLm0ruGF4UWgC3PL+eDuWfwEm7 zepKpsV+wAsL1sgxAEQzkL+ICs+9fLQsAJeGR+OwIPVBa7tJ5+OIaj+JzsCTV/Zs 1cvfKPqwV1IDGLm4SaEuUjLRDLlMv0LwoFwCsHrFyRpaEMLvm6o/iGRR6rUtAAQN pwWfwWtxnDCe6kIoUiPD5yK4AUNfPcJ3X+8naXRY1eht2sG/i3X7g5sx5j1WD1K8 MnIZdZGnBwLCqCWTg53vjVA6Hp2vIX0vvY5QkEnpmy8x2XsYkPFxl5k5tnfOXD2K GrJPixA2J7v8J/0liL39So4s5vwG8b22Y2X6zg/L1MoMoVO8shbs1TUy4d6mOxRW dYgIBaZrJ1Lld4TjYjIb5pUvo/XvKHAA4yf9gc0N149C45lOJ25ASTmmSNxYBKFu 3JWVrA3ODUAxi8fERU+Ldx086eG8MS2MF5r8lvRLy/x3GySr9coUq7xcQRJJ91sS J+njyeK3JimbZcVKrDiHrHIrx7uUGPF0QRMdEjTdzeRJW02tfM1Z0+5e95R+8ljw kj4vhpMcHXk=r3dk -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves two vulnerabilities and has 11 fixes is now available. . SUSE Security Update: Security update for SUSE Manager Server 4.1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0798-1 Rating: moderate References: #1097531 #1133198 #1190781 #1191360 #1192510 #1192566 #1192822 #1193565 #1194044 #1194363 #1194464 #1195043 #1195282 Cross-References: CVE-2018-20433 CVE-2019-5427 CVSS scores: CVE-2018-20433 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2018-20433 (SUSE): 4.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L CVE-2019-5427 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2019-5427 (SUSE): 5.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Module for SUSE Manager Server 4.1 SUSE Manager Server 4.1 ______________________________________________________________________________ An update that solves two vulnerabilities and has 11 fixes is now available. Description: This update fixes the following issues: c3p0: - Update to version c3p0 0.9.5.5 and mchange-commons-java 0.2.19 * Address CVE-2018-20433 * Address CVE-2019-5427 - XML-config parsing related attacks (bsc#1133198) * Properly implement the JDBC 4.1 abort method - Build with log4j mapper - Enhanced for RHEL8 dhcpd-formula: - Update to version 0.1.1641480250.d5bd14c * make routers option optional - Add arm64 support - Update to version 0.1.1615805990.f15c8d9 hub-xmlrpc-api: - Updated to build on Enterprise Linux 8. py26-compat-msgpack-python: - Adapted to build on OBS for Enterprise Linux. py27-compat-salt: - Fix inspector module export function (bsc#1097531) - Fix possible traceback on ip6_interface grain (bsc#1193565) - Don'tcheck for cached pillar errors on state.apply (bsc#1190781) - Simplify "transactional_update" module to not use SSH wrapper and allow more flexible execution - Add "--no-return-event" option to salt-call to prevent sending return event back to master. - Make "state.highstate" to acts on concurrent flag. - Fix the regression with invalid syntax in test_parse_cpe_name_v23. spacecmd: - Version 4.1.17-1 * Fix interactive mode for "system_applyerrata" and "errata_apply" (bsc#1194363) spacewalk-java: - Version 4.1.44-1 * allow SCC to display the last check-in time for registered systems * Suggest Product Migration when patch for CVE is in a successor Product (bsc#1191360) * Add store info to Equals and hash methods to fix CVE audit process (bsc#1195282) * fix ClassCastException during action processing (bsc#1195043) * Fix disappearing metadata key files after channel change (bsc#1192822) * Pass only selected servers to taskomatic for cancelation (bsc#1194044) spacewalk-web: - Version 4.1.32-1 * Suggest Product Migration when patch for CVE is in a successor Product (bsc#1191360) susemanager: - Version 4.1.33-1 * set default for registration batch size susemanager-doc-indexes: - Added a warning about the origin of the salt-minion package in the Register on the Command Line (Salt) section of the Client Configuration Guide - In the Client Configuration Guide, explain how you find channel names to register older SUSE Linux Enterprise clients. - Added grub.cfg for GRUB 2 in the Upgrade chapter of the Client susemanager-docs_en: - Added a warning about the origin of the salt-minion package in the Register on the Command Line (Salt) section of the Client Configuration Guide - In the Client Configuration Guide, explain how you find channel names to register older SUSE Linux Enterprise clients. - Added grub.cfg for GRUB 2 in the Upgrade chapterof the Client Configuration Guide susemanager-schema: - Version 4.1.25-1 * Continue with index migration when the expected indexes do not exist (bsc#1192566) susemanager-sls: - Version 4.1.34-1 * Improve `pkgset` beacon with using `salt.cache` to notify about the changes made while the minion was stopped. * Align the code of pkgset beacon to prevent warnings (bsc#1194464) - Version 4.1.33-1 * Fix errors on calling sed -E ... by force_restart_minion with action chains * Postgres exporter package was renamed * fix deprecation warnings * enforce correct minion configuration similar to bootstrapping (bsc#1192510) How to apply this update: 1. Log in as root user to the SUSE Manager server. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start` Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.1-2022-798=1 Package List: - SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (ppc64le s390x x86_64): hub-xmlrpc-api-0.7-3.9.2 py26-compat-msgpack-python-0.4.6-3.6.2 py26-compat-msgpack-python-debuginfo-0.4.6-3.6.2 py26-compat-msgpack-python-debugsource-0.4.6-3.6.2 susemanager-4.1.33-3.45.2 susemanager-tools-4.1.33-3.45.2 - SUSE Linux Enterprise Module for SUSE Manager Server 4.1 (noarch): c3p0-0.9.5.5-3.3.2 dhcpd-formula-0.1.1641480250.d5bd14c-3.3.2 py27-compat-salt-3000.3-6.21.2 spacecmd-4.1.17-4.36.2 spacewalk-base-4.1.32-3.42.2 spacewalk-base-minimal-4.1.32-3.42.2 spacewalk-base-minimal-config-4.1.32-3.42.2 spacewalk-html-4.1.32-3.42.2 spacewalk-java-4.1.44-3.66.2 spacewalk-java-config-4.1.44-3.66.2 spacewalk-java-lib-4.1.44-3.66.2 spacewalk-java-postgresql-4.1.44-3.66.2 spacewalk-taskomatic-4.1.44-3.66.2 susemanager-doc-indexes-4.1-11.52.2 susemanager-docs_en-4.1-11.52.2 susemanager-docs_en-pdf-4.1-11.52.2 susemanager-schema-4.1.25-3.42.2 susemanager-sls-4.1.34-3.59.2 susemanager-web-libs-4.1.32-3.42.2 uyuni-config-modules-4.1.34-3.59.2 References: https://www.suse.com/security/cve/CVE-2018-20433.html https://www.suse.com/security/cve/CVE-2019-5427.html https://bugzilla.suse.com/1097531 https://bugzilla.suse.com/1133198 https://bugzilla.suse.com/1190781 https://bugzilla.suse.com/1191360 https://bugzilla.suse.com/1192510 https://bugzilla.suse.com/1192566 https://bugzilla.suse.com/1192822 https://bugzilla.suse.com/1193565 https://bugzilla.suse.com/1194044 https://bugzilla.suse.com/1194363 https://bugzilla.suse.com/1194464 https://bugzilla.suse.com/1195043 https://bugzilla.suse.com/1195282 . The recent update for SUSE Manager Server 4.1 addresses a couple of concerns and introduces ten improvements aimed at boosting both security and overall functionality.. SUSE Manager Server Update, Security Fixes, Vulnerability Management. . LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for fwupdate ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1104-1 Rating: important References: #1182057 Affected Products: SUSE Manager Server 4.0 SUSE Manager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for fwupdate fixes the following issues: - Add SBAT section to EFI images (bsc#1182057) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-1104=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-1104=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-1104=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-1104=1 - SUSE Linux Enterprise Server15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-1104=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-1104=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2021-1104=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-1104=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-1104=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-1104=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-1104=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.0 (x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Manager Retail Branch Server 4.0 (x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Manager Proxy 4.0 (x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise Server for SAP 15-SP1(x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE Enterprise Storage 6 (aarch64 x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 - SUSE CaaS Platform 4.0 (x86_64): fwupdate-12-11.8.2 fwupdate-debuginfo-12-11.8.2 fwupdate-debugsource-12-11.8.2 fwupdate-devel-12-11.8.2 fwupdate-efi-12-11.8.2 fwupdate-efi-debuginfo-12-11.8.2 libfwup1-12-11.8.2 libfwup1-debuginfo-12-11.8.2 References: https://bugzilla.suse.com/1182057 . Crucial SUSE patch for fwupdate launched, including security enhancements outlined for setup and administration.. SUSE Linux, fwupdate, patch instructions, security management, system update. . Severity: Important. LinuxSecurity.com Team
An update that contains security fixes can now be installed. . SUSE Security Update: Security update for man ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0102-1 Rating: moderate References: #1159105 Affected Products: SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Desktop 12-SP4 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for man fixes the following issues: - Skip using 'safe-rm' in cron job below cache directory (bsc#1159105). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-102=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2020-102=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2020-102=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): man-2.6.6-4.3.1 man-debuginfo-2.6.6-4.3.1 man-debugsource-2.6.6-4.3.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): man-2.6.6-4.3.1 man-debuginfo-2.6.6-4.3.1 man-debugsource-2.6.6-4.3.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): man-2.6.6-4.3.1 man-debuginfo-2.6.6-4.3.1 man-debugsource-2.6.6-4.3.1 References: https://bugzilla.suse.com/1159105 _______________________________________________ sle-security-updates mailing list
An update for sudo is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: sudo security update Advisory ID: RHSA-2019:3209-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3209 Issue date: 2019-10-28 CVE Names: CVE-2019-14287 ==================================================================== 1. Summary: An update for sudo is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server Optional E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server TUS (v. 7.4) - x86_64 3. Description: The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: Privilege escalation via 'Runas' specification with 'ALL'keyword (CVE-2019-14287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1760531 - CVE-2019-14287 sudo: Privilege escalation via 'Runas' specification with 'ALL' keyword 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: sudo-1.8.19p2-12.el7_4.1.src.rpm x86_64: sudo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.4): Source: sudo-1.8.19p2-12.el7_4.1.src.rpm ppc64le: sudo-1.8.19p2-12.el7_4.1.ppc64le.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.ppc64le.rpm x86_64: sudo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.4): Source: sudo-1.8.19p2-12.el7_4.1.src.rpm x86_64: sudo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.4): x86_64: sudo-debuginfo-1.8.19p2-12.el7_4.1.i686.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-devel-1.8.19p2-12.el7_4.1.i686.rpm sudo-devel-1.8.19p2-12.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server Optional E4S (v. 7.4): ppc64le: sudo-debuginfo-1.8.19p2-12.el7_4.1.ppc64le.rpm sudo-devel-1.8.19p2-12.el7_4.1.ppc64le.rpm x86_64: sudo-debuginfo-1.8.19p2-12.el7_4.1.i686.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-devel-1.8.19p2-12.el7_4.1.i686.rpm sudo-devel-1.8.19p2-12.el7_4.1.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v.7.4): x86_64: sudo-debuginfo-1.8.19p2-12.el7_4.1.i686.rpm sudo-debuginfo-1.8.19p2-12.el7_4.1.x86_64.rpm sudo-devel-1.8.19p2-12.el7_4.1.i686.rpm sudo-devel-1.8.19p2-12.el7_4.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-14287 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPG v1 iQIVAwUBXbctW9zjgjWX9erEAQjCKw/+LWewWJhZk11++W5jN6Z4j0zbmUqu8M9r Y8kD8lb1h3XfsTs+YzWoOqp0miWRhLbC99tKXwMntyB2lujRdxFF+BdaR4xGrUfS v1eMSYqVIunFF9BYmk9RxQ58rXOu9JF0qLt+CXiupLF3ZsaXElcLPH73vdFw8F5M B2gYVmVr0GE5OS1UA/DTHMa6bIgKUlSqUEC5XoeL4QatGa5F5A3leoilhdsiLJyC c62QGc2vzvpt4le+zEq5TinqRqWaVJZvVfLOUZ4Ko5lxi8/mebKNK1xbM4RYhdmS xuFhN1YZKQ4ixK4IbiNoAXWs74XZrU5VU8TMgg8yatVKeNgbNQde1C5QRYiF+1Rd KOXyf5YMU9zQYnmfHQCLL+ZBT9TTYy6DudPjO2XJjQFeG8GfbBfvzkCip/EKkZW2 kK77Sty0NQD85lkwjL95T33u/cJstCsdfT7qbTDC/Kd0/o+0QfZaZfAxai1DEAvB dv6u3e+Grz0xKOw5gn9uGq0BTkgnnLgZjMW4JH+NA6U/Y6TwBAB/PB1tBNTDlahM 6AP1PEF6jLaBBIrqtvt1x8AGUYmxn8oj3IDCL8c3u01ebDq3POfZcchJksqgWED+ ++wBCmP/90E3xqZOdYqhUdwFCuiUFqTxPXLzLv0Pjj71kmF1DK5f3dAHeF0B2N/d UV8bhGLL46Q=DSE/ -----END PGP SIGNATURE-------RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.