strace bug fix and enhancement update. \{'type': 'Enhancement', 'shortCode': 'RL', 'name': 'RLEA-2021:3591', 'synopsis': 'strace bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for strace is now available for Rocky Linux 8.', 'description': 'The strace utility intercepts and records the system calls that are made\nand received by a running process and prints a record of each system call,\nits arguments, and its return value to standard error output or a file. It\nis often used for problem diagnoses, debugging, and for instructional\npurposes.\ne921913eecd5025dae688fdf9c365023fe3b8a0c (SELinux support) (BZ#2000565)', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['2000565'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHEA-2021:3591:::RHEA-2021:3591'], 'references': [], 'publishedAt': '2021-10-01T20:16:06.961220Z', 'rpms': ['strace-5.7-2.1.el8_4.aarch64.rpm', 'strace-5.7-2.1.el8_4.src.rpm', 'strace-5.7-2.1.el8_4.x86_64.rpm', 'strace-debuginfo-5.7-2.1.el8_4.aarch64.rpm', 'strace-debuginfo-5.7-2.1.el8_4.x86_64.rpm', 'strace-debugsource-5.7-2.1.el8_4.aarch64.rpm', 'strace-debugsource-5.7-2.1.el8_4.x86_64.rpm']}\. New version of strace released for Rocky Linux 8, featuring critical bug corrections and improvements in the monitoring of system calls.. strace enhancement, Rocky Linux 8 update, system call utility, software fix. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9730 https://linux.oracle.com/errata/ELSA-2022-9730.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-container-5.4.17-2136.310.7.1.el8.x86_64.rpm kernel-uek-container-debug-5.4.17-2136.310.7.1.el8.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/kernel-uek-container-5.4.17-2136.310.7.1.el8.src.rpm Related CVEs: CVE-2022-21385 Description of changes: [5.4.17-2136.310.7.1] - rds: copy_from_user only once per rds_sendmsg system call (Hans Westgaard Ry) [Orabug: 33981855] {CVE-2022-21385} _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-9726 https://linux.oracle.com/errata/ELSA-2022-9726.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: aarch64: bpftool-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-core-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-debug-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-debug-core-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-debug-devel-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-debug-modules-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-debug-modules-extra-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-devel-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-doc-5.15.0-1.43.4.2.el9uek.noarch.rpm kernel-uek-modules-5.15.0-1.43.4.2.el9uek.aarch64.rpm kernel-uek-modules-extra-5.15.0-1.43.4.2.el9uek.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates/kernel-uek-5.15.0-1.43.4.2.el9uek.src.rpm Related CVEs: CVE-2022-21385 Description of changes: [5.15.0-1.43.4.2.el9uek] - rds: copy_from_user only once per rds_sendmsg system call (Hans Westgaard Ry) [Orabug: 33981854] {CVE-2022-21385} _______________________________________________ El-errata mailing list
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for go1.17 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1862-1 Rating: moderate References: #1190649 #1199413 Cross-References: CVE-2022-29526 CVSS scores: CVE-2022-29526 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for go1.17 fixes the following issues: - CVE-2022-29526: Fixed faccessat() system call operation that checked the wrong group (bsc#1199413). - go1.17.10 (released 2022-05-10) (bsc#1190649). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1862=1 -openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1862=1 - SUSE Linux Enterprise Module for Development Tools 15-SP4: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2022-1862=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2022-1862=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): go1.17-1.17.10-150000.1.34.1 go1.17-doc-1.17.10-150000.1.34.1 - openSUSE Leap 15.4 (aarch64 x86_64): go1.17-race-1.17.10-150000.1.34.1 - openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64): go1.17-1.17.10-150000.1.34.1 go1.17-doc-1.17.10-150000.1.34.1 - openSUSE Leap 15.3 (aarch64 x86_64): go1.17-race-1.17.10-150000.1.34.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 ppc64le s390x x86_64): go1.17-1.17.10-150000.1.34.1 go1.17-doc-1.17.10-150000.1.34.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 x86_64): go1.17-race-1.17.10-150000.1.34.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 ppc64le s390x x86_64): go1.17-1.17.10-150000.1.34.1 go1.17-doc-1.17.10-150000.1.34.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 x86_64): go1.17-race-1.17.10-150000.1.34.1 References: https://www.suse.com/security/cve/CVE-2022-29526.html https://bugzilla.suse.com/1190649 https://bugzilla.suse.com/1199413 . SUSE Security Update for node.js version 14.x addresses vulnerability CVE-2021-22918 classified as low severity, including essential patch information.. SUSE Linux Security, Go1.17 Patch, System Call Fix, Security Update. . LinuxSecurity.com Team
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for go1.18 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1829-1 Rating: moderate References: #1193742 #1199413 Cross-References: CVE-2022-29526 CVSS scores: CVE-2022-29526 (SUSE): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Development Tools 15-SP3 SUSE Linux Enterprise Module for Development Tools 15-SP4 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for go1.18 fixes the following issues: - CVE-2022-29526: Fixed faccessat() system call operation that checked the wrong group (bsc#1199413). - go1.18.2 (released 2022-05-10) (bsc#1193742). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-1829=1 -openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-1829=1 - SUSE Linux Enterprise Module for Development Tools 15-SP4: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2022-1829=1 - SUSE Linux Enterprise Module for Development Tools 15-SP3: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP3-2022-1829=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): go1.18-1.18.2-150000.1.17.1 go1.18-doc-1.18.2-150000.1.17.1 - openSUSE Leap 15.4 (aarch64 x86_64): go1.18-race-1.18.2-150000.1.17.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): go1.18-1.18.2-150000.1.17.1 go1.18-doc-1.18.2-150000.1.17.1 - openSUSE Leap 15.3 (aarch64 x86_64): go1.18-race-1.18.2-150000.1.17.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 ppc64le s390x x86_64): go1.18-1.18.2-150000.1.17.1 go1.18-doc-1.18.2-150000.1.17.1 - SUSE Linux Enterprise Module for Development Tools 15-SP4 (aarch64 x86_64): go1.18-race-1.18.2-150000.1.17.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 ppc64le s390x x86_64): go1.18-1.18.2-150000.1.17.1 go1.18-doc-1.18.2-150000.1.17.1 - SUSE Linux Enterprise Module for Development Tools 15-SP3 (aarch64 x86_64): go1.18-race-1.18.2-150000.1.17.1 References: https://www.suse.com/security/cve/CVE-2022-29526.html https://bugzilla.suse.com/1193742 https://bugzilla.suse.com/1199413 . This patch resolves a significant vulnerability in go1.18, providing guidelines specifically for users of SUSE and openSUSE.. SUSE Update, Go1.18 Patch, SUSE Security Fix. . Severity: Important. LinuxSecurity.com Team
net/http: limit growth of header canonicalization cache (CVE-2021-44716) syscall: don't close fd 0 on ForkExec error (CVE-2021-44717) References: - https://bugs.mageia.org/show_bug.cgi?id=29807 . MGASA-2021-0587 - Updated golang packages fix security vulnerability Publication date: 26 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0587.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-44716, CVE-2021-44717 net/http: limit growth of header canonicalization cache (CVE-2021-44716) syscall: don't close fd 0 on ForkExec error (CVE-2021-44717) References: - https://bugs.mageia.org/show_bug.cgi?id=29807 - https://lists.suse.com/pipermail/sle-security-updates/2021-December/009942.html - - https://www.cve.org/CVERecord?id=CVE-2021-44716 - https://www.cve.org/CVERecord?id=CVE-2021-44717 SRPMS: - 8/core/golang-1.17.5-1.mga8 . Revised Go packages address critical vulnerabilities impacting Mageia's safety as highlighted in advisory MGASA-2021-0587.. Golang Update, Mageia Security, Critical Updates, Header Cache, System Call Fix. . Severity: Critical. LinuxSecurity.com Team
Updated libseccomp packages fix security vulnerability: Jann Horn discovered that libseccomp did not correctly generate 64-bit syscall argument comparisons with arithmetic operators (LT, GT, LE, GE). An attacker could use this to bypass intended access restrictions for . MGASA-2020-0136 - Updated libseccomp packages fix security vulnerability Publication date: 10 Mar 2020 URL: https://advisories.mageia.org/MGASA-2020-0136.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-9893 Updated libseccomp packages fix security vulnerability: Jann Horn discovered that libseccomp did not correctly generate 64-bit syscall argument comparisons with arithmetic operators (LT, GT, LE, GE). An attacker could use this to bypass intended access restrictions for argument-filtered system calls (CVE-2019-9893). References: - https://bugs.mageia.org/show_bug.cgi?id=24523 - https://ubuntu.com/security/notices/USN-4001-1 - https://www.cve.org/CVERecord?id=CVE-2019-9893 SRPMS: - 7/core/libseccomp-2.4.2-1.mga7 . Recent updates to libseccomp packages deliver essential security improvements for Mageia users. Review the specifics regarding access restrictions.. libseccomp, Mageia, security update, syscall, software vulnerability. . LinuxSecurity.com Team
An update that solves one vulnerability and has two fixes is now available. . SUSE Security Update: Security update for libseccomp ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2517-1 Rating: moderate References: #1082318 #1128828 #1142614 Cross-References: CVE-2019-9893 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for libseccomp fixes the following issues: Security issues fixed: - CVE-2019-9893: An incorrect generation of syscall filters in libseccomp was fixed (bsc#1128828) libseccomp was updated to new upstream release 2.4.1: - Fix a BPF generation bug where the optimizer mistakenly identified duplicate BPF code blocks. libseccomp was updated to 2.4.0 (bsc#1128828 CVE-2019-9893): - Update the syscall table for Linux v5.0-rc5 - Added support for the SCMP_ACT_KILL_PROCESS action - Added support for the SCMP_ACT_LOG action and SCMP_FLTATR_CTL_LOG attribute - Added explicit 32-bit (SCMP_AX_32(...)) and 64-bit (SCMP_AX_64(...)) argument comparison macros to help protect against unexpected sign extension - Added support for the parisc and parisc64 architectures - Added the ability to query and set the libseccomp API level via seccomp_api_get(3) and seccomp_api_set(3) - Return -EDOM on an endian mismatch when adding an architecture to a filter - Renumber the pseudo syscall number for subpage_prot() so it no longer conflicts with spu_run() - Fix PFCgeneration when a syscall is prioritized, but no rule exists - Numerous fixes to the seccomp-bpf filter generation code - Switch our internal hashing function to jhash/Lookup3 to MurmurHash3 - Numerous tests added to the included test suite, coverage now at ~92% - Update our Travis CI configuration to use Ubuntu 16.04 - Numerous documentation fixes and updates libseccomp was updated to release 2.3.3: - Updated the syscall table for Linux v4.15-rc7 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2517=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2517=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-2517=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-2517=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): libseccomp-debugsource-2.4.1-3.3.1 libseccomp-tools-2.4.1-3.3.1 libseccomp-tools-debuginfo-2.4.1-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libseccomp-debugsource-2.4.1-3.3.1 libseccomp-tools-2.4.1-3.3.1 libseccomp-tools-debuginfo-2.4.1-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libseccomp-debugsource-2.4.1-3.3.1 libseccomp-devel-2.4.1-3.3.1 libseccomp2-2.4.1-3.3.1 libseccomp2-debuginfo-2.4.1-3.3.1 - SUSE Linux Enterprise Module for Basesystem15-SP1 (x86_64): libseccomp2-32bit-2.4.1-3.3.1 libseccomp2-32bit-debuginfo-2.4.1-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libseccomp-debugsource-2.4.1-3.3.1 libseccomp-devel-2.4.1-3.3.1 libseccomp2-2.4.1-3.3.1 libseccomp2-debuginfo-2.4.1-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (x86_64): libseccomp2-32bit-2.4.1-3.3.1 libseccomp2-32bit-debuginfo-2.4.1-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-9893.html https://bugzilla.suse.com/1082318 https://bugzilla.suse.com/1128828 https://bugzilla.suse.com/1142614 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.