Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 35: FEDORA-2022-1176b501f0 Urgent: Risks with NTFS-3G Compression

Rebuild for ntfs-3g CVE. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1176b501f0 2022-06-24 01:25:24.273343 --------------------------------------------------------------------------------Name : ntfs-3g-system-compression Product : Fedora 35 Version : 1.0 Release : 9.fc35 URL : https://github.com/ebiggers/ntfs-3g-system-compression Summary : NTFS-3G plugin for reading "system compressed" files Description : System compression, also known as "Compact OS", is a Windows feature that allows rarely modified files to be compressed using the XPRESS or LZX compression formats. It is not built directly into NTFS but rather is implemented using reparse points. This feature appeared in Windows 10 and it appears that many Windows 10 systems have been using it by default. This RPM contains a plugin which enables the NTFS-3G FUSE driver to transparently read from system-compressed files. Currently, only reading is supported. Compressing an existing file may be done by using the "compact" utility on Windows. --------------------------------------------------------------------------------Update Information: Rebuild for ntfs-3g CVE --------------------------------------------------------------------------------ChangeLog: * Wed Jun 8 2022 Richard W.M. Jones - 1.0-9 - Rebuild for ntfs-3g CVE * Thu Jan 20 2022 Fedora Release Engineering - 1.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2093310 - CVE-2022-30783 ntfs-3g-system-compression: ntfs-3g: invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093310 [ 2 ] Bug #2093319 - CVE-2022-30784 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093319 [ 3 ] Bug #2093325 - CVE-2022-30785 ntfs-3g-system-compression: ntfs-3g: a file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093325 [ 4 ] Bug #2093331 - CVE-2022-30786 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093331 [ 5 ] Bug #2093338 - CVE-2022-30787 ntfs-3g-system-compression: ntfs-3g: integer underflow in fuse_lib_readdir enables arbitrary memory read operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093338 [ 6 ] Bug #2093345 - CVE-2022-30788 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093345 [ 7 ] Bug #2093352 - CVE-2022-30789 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093352 [ 8 ] Bug #2093361 - CVE-2021-46790 ntfs-3g-system-compression: ntfs-3g: heap-based buffer overflow in ntfsck [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093361 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1176b501f0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 35 has issued a vital update to tackle serious NTFS-3G system compression vulnerabilities, enhancing security and protecting against data corruption. ntfs-3g system compression,Fedora update,CVE references. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 23, 2022 Important Fedora
89

Fedora 36: 2022-13bc8c91b0 Critical: ntfs-3g Buffer Overflow

Rebuild for ntfs-3g CVE. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-13bc8c91b0 2022-06-18 00:37:15.099565 --------------------------------------------------------------------------------Name : ntfs-3g-system-compression Product : Fedora 36 Version : 1.0 Release : 9.fc36 URL : https://github.com/ebiggers/ntfs-3g-system-compression Summary : NTFS-3G plugin for reading "system compressed" files Description : System compression, also known as "Compact OS", is a Windows feature that allows rarely modified files to be compressed using the XPRESS or LZX compression formats. It is not built directly into NTFS but rather is implemented using reparse points. This feature appeared in Windows 10 and it appears that many Windows 10 systems have been using it by default. This RPM contains a plugin which enables the NTFS-3G FUSE driver to transparently read from system-compressed files. Currently, only reading is supported. Compressing an existing file may be done by using the "compact" utility on Windows. --------------------------------------------------------------------------------Update Information: Rebuild for ntfs-3g CVE --------------------------------------------------------------------------------ChangeLog: * Wed Jun 8 2022 Richard W.M. Jones - 1.0-9 - Rebuild for ntfs-3g CVE --------------------------------------------------------------------------------References: [ 1 ] Bug #2093310 - CVE-2022-30783 ntfs-3g-system-compression: ntfs-3g: invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093310 [ 2 ] Bug #2093319 - CVE-2022-30784 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093319 [ 3 ] Bug #2093325 - CVE-2022-30785ntfs-3g-system-compression: ntfs-3g: a file handle created in fuse_lib_opendir, and later used in fuse_lib_readdir, enables arbitrary memory read and write operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093325 [ 4 ] Bug #2093331 - CVE-2022-30786 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093331 [ 5 ] Bug #2093338 - CVE-2022-30787 ntfs-3g-system-compression: ntfs-3g: integer underflow in fuse_lib_readdir enables arbitrary memory read operations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093338 [ 6 ] Bug #2093345 - CVE-2022-30788 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093345 [ 7 ] Bug #2093352 - CVE-2022-30789 ntfs-3g-system-compression: ntfs-3g: crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093352 [ 8 ] Bug #2093361 - CVE-2021-46790 ntfs-3g-system-compression: ntfs-3g: heap-based buffer overflow in ntfsck [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2093361 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-13bc8c91b0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Vital patch for Ubuntu 22.04 tackles various vulnerabilities in ext4-file-system-optimizations with guidelines for deployment.. Fedora 36, ntfs-3g, buffer overflow, system compression, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 17, 2022 Critical Fedora
89

Fedora 35: FEDORA-2021-4dd269a76c Critical: NTFS-3G System Compression

Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-4dd269a76c 2021-09-07 19:06:12.617794 --------------------------------------------------------------------------------Name : ntfs-3g-system-compression Product : Fedora 35 Version : 1.0 Release : 7.fc35 URL : https://github.com/ebiggers/ntfs-3g-system-compression Summary : NTFS-3G plugin for reading "system compressed" files Description : System compression, also known as "Compact OS", is a Windows feature that allows rarely modified files to be compressed using the XPRESS or LZX compression formats. It is not built directly into NTFS but rather is implemented using reparse points. This feature appeared in Windows 10 and it appears that many Windows 10 systems have been using it by default. This RPM contains a plugin which enables the NTFS-3G FUSE driver to transparently read from system-compressed files. Currently, only reading is supported. Compressing an existing file may be done by using the "compact" utility on Windows. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820) --------------------------------------------------------------------------------ChangeLog: * Tue Aug 31 2021 Richard W.M. Jones - 1.0-7 - Rebuild for updated ntfs-3g CVE (RHBZ#1999788) --------------------------------------------------------------------------------References: [ 1 ] Bug #1998820 - libguestfs breaks with qemu 6.1 with error "Backing file specified without backing format" https://bugzilla.redhat.com/show_bug.cgi?id=1998820 [ 2 ] Bug #1999788 - ntfs-3g: Multiple bufferoverflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 3 ] Bug #1999869 - ntfs-3g-2021.8.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-4dd269a76c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade NTFS-3G to version 2021.8.22, resolving significant problems and improving interoperability with QEMU 6.1.. ntfs-3g,System Compression,Fedora Updates,Bug Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 07, 2021 Critical Fedora
89

Fedora 33 2021-38d1b07839 NTFS-3G Moderate Buffer Overflow Fix

Update NTFS-3G to 2021.8.22 to fix multiple CVEs. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-38d1b07839 2021-09-07 16:26:35.652642 --------------------------------------------------------------------------------Name : ntfs-3g-system-compression Product : Fedora 33 Version : 1.0 Release : 7.fc33 URL : https://github.com/ebiggers/ntfs-3g-system-compression Summary : NTFS-3G plugin for reading "system compressed" files Description : System compression, also known as "Compact OS", is a Windows feature that allows rarely modified files to be compressed using the XPRESS or LZX compression formats. It is not built directly into NTFS but rather is implemented using reparse points. This feature appeared in Windows 10 and it appears that many Windows 10 systems have been using it by default. This RPM contains a plugin which enables the NTFS-3G FUSE driver to transparently read from system-compressed files. Currently, only reading is supported. Compressing an existing file may be done by using the "compact" utility on Windows. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs --------------------------------------------------------------------------------ChangeLog: * Tue Aug 31 2021 Richard W.M. Jones - 1.0-7 - Rebuild for updated ntfs-3g CVE (RHBZ#1999788) * Thu Jul 22 2021 Fedora Release Engineering - 1.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering - 1.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 2 ] Bug #1999869 - ntfs-3g-2021.8.22 isavailable https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-38d1b07839' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade NTFS-3G on Fedora 33 to address various security vulnerabilities and improve support for system-compressed files.. Fedora Updates, NTFS-3G Plugin, System Compression, Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 07, 2021 Important Fedora
89

Fedora 34: 2021-09-04 Moderate Update for NTFS-3G Buffer Overflow

Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c0235d9d79 2021-09-04 19:31:30.714719 --------------------------------------------------------------------------------Name : ntfs-3g-system-compression Product : Fedora 34 Version : 1.0 Release : 7.fc34 URL : https://github.com/ebiggers/ntfs-3g-system-compression Summary : NTFS-3G plugin for reading "system compressed" files Description : System compression, also known as "Compact OS", is a Windows feature that allows rarely modified files to be compressed using the XPRESS or LZX compression formats. It is not built directly into NTFS but rather is implemented using reparse points. This feature appeared in Windows 10 and it appears that many Windows 10 systems have been using it by default. This RPM contains a plugin which enables the NTFS-3G FUSE driver to transparently read from system-compressed files. Currently, only reading is supported. Compressing an existing file may be done by using the "compact" utility on Windows. --------------------------------------------------------------------------------Update Information: Update NTFS-3G to 2021.8.22 to fix multiple CVEs ---- New upstream development version 1.45.7. ---- Upstream patch to work with qemu 6.1 (RHBZ#1998820) --------------------------------------------------------------------------------ChangeLog: * Tue Aug 31 2021 Richard W.M. Jones - 1.0-7 - Rebuild for updated ntfs-3g CVE (RHBZ#1999788) * Thu Jul 22 2021 Fedora Release Engineering - 1.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1998820 - libguestfs breaks with qemu 6.1 with error "Backing file specified without backingformat" https://bugzilla.redhat.com/show_bug.cgi?id=1998820 [ 2 ] Bug #1999788 - ntfs-3g: Multiple buffer overflows in all versions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1999788 [ 3 ] Bug #1999869 - ntfs-3g-2021.8.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1999869 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c0235d9d79' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Patch release for Fedora 34 focusing on resolving various problems related to NTFS-3G compression capabilities and enhancing overall security measures.. Fedora Update, NTFS-3G Fix, System Compression, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 04, 2021 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here