Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 62 articles for you...
219

Rocky Linux 9 RLEA-2024:9119 Rhel-System-Roles Bug Fix and Enhancement

rhel-system-roles bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2024:9119","synopsis":"rhel-system-roles bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update is available for rhel-system-roles.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"For detailed information on changes in this release, see the Rocky Linux 9.5 Release Notes linked from the References section.","solution":null,"affectedProducts":["Rocky Linux 9"],"fixes":[],"cves":[],"references":[],"publishedAt":"2025-03-17T20:16:49.937392Z","rpms":{"Rocky Linux 9":{"nvras":["rhel-system-roles-0:1.88.9-0.1.el9_5.noarch.rpm","rhel-system-roles-0:1.88.9-0.1.el9_5.src.rpm"]}},"rebootSuggested":false,"buildReferences":[]}. RockyLinux launches its latest edition of ansible-server-roles, incorporating robustness enhancements and performance improvements.. Rocky Linux,rhel system roles,systems enhancement,update,bug fix. . LinuxSecurity.com Team

Calendar%202 Mar 17, 2025 Rocky Linux
89

Fedora 39: 2024-40ee18b2e7 Moderate Denial of Service for Rust-Diskonaut

This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-40ee18b2e7 2024-06-02 03:36:56.060441 -------------------------------------------------------------------------------- Name : rust-diskonaut Product : Fedora 39 Version : 0.11.0 Release : 18.fc39 URL : Summary : Terminal disk space visual navigator Description : Terminal disk space visual navigator. -------------------------------------------------------------------------------- Update Information: This update contains builds from a mini-mass-rebuild for Rust applications (and some C-style libraries). Rebuilding with the Rust 1.78 toolchain should fix incomplete debug information for the Rust standard library (and the resulting low-quality stack traces). Additionally, builds will have picked up fixes for some minor low-priority security and / or safety fixes in crate dependencies that had not yet been handled via a separate (targeted) rebuild: h2 v0.3.26+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0332.html glib v0.19.4+ and backports (UB): core/pull/1343 hashbrown v0.14.5+ (UB): https://github.com/rust-lang/hashbrown/pull/511 rustls v0.22.4+, v0.21.11+ (denial-of-service): https://rustsec.org/advisories/RUSTSEC-2024-0336.html -------------------------------------------------------------------------------- ChangeLog: * Thu May 23 2024 Fabio Valentini - 0.11.0-18 - Rebuild with Rust 1.78 to fix incomplete debuginfo and backtraces * Fri Jan 26 2024 Fedora Release Engineering - 0.11.0-17 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-40ee18b2e7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . This bulletin outlines the Ubuntu 23.10's python-dataframe update that tackles potential vulnerabilities and improves system performance.. Fedora 39 Update,rust-diskonaut Security Advisory,Dos Risk Mitigation,Rust Applications Update. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2024 Fedora
202

openSUSE 15.5: 2024:1122-1 Important: Go1.21 DoS Issue Resolved

This update for go1.21 fixes the following issues: CVE-2023-45288: Fixed denial of service via HTTP/2 continuation frames (bsc#1221400). # Security update for go1.21 Announcement ID: SUSE-SU-2024:1122-1 Rating: important References: * bsc#1212475 * bsc#1221400 Cross-References: * CVE-2023-45288 CVSS scores: * CVE-2023-45288 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for go1.21 fixes the following issues: * CVE-2023-45288: Fixed denial of service via HTTP/2 continuation frames (bsc#1221400) Other changes: \- go minor release upgrade to 1.21.9 (bsc#1212475) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1122=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-1122=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-1122=1 * SUSE Linux Enterprise HighPerformance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-1122=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-1122=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-1122=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-1122=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-race-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-race-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-race-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-race-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-race-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 x86_64) * go1.21-race-1.21.9-150000.1.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.21-1.21.9-150000.1.30.1 * go1.21-doc-1.21.9-150000.1.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * go1.21-race-1.21.9-150000.1.30.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45288.html *https://bugzilla.suse.com/show_bug.cgi?id=1212475 * https://bugzilla.suse.com/show_bug.cgi?id=1221400 . Important patch for v1.21 addresses denial of service vulnerability through HTTP/2, strengthening overall security. Discover further information.. openSUSE Update, go1.21 Security, Denial of Service Fix, Software Patch, Security Enhancement. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 05, 2024 Important OpenSUSE
89

Fedora 38: 2024-71f0f16533 Moderate: Kernel Security Updates

The 6.7.6 stable kernel update contains a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-71f0f16533 2024-02-28 01:40:29.293829 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 38 Version : 6.7.6 Release : 100.fc38 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.7.6 stable kernel update contains a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 23 2024 Justin M. Forbes [6.7.6-0] - Add CVE fix for 6.7.6 (Justin M. Forbes) - Linux v6.7.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2265269 - CVE-2023-52437 kernel: Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d" https://bugzilla.redhat.com/show_bug.cgi?id=2265269 [ 2 ] Bug #2265517 - CVE-2024-26585 kernel: tls: race between tx work scheduling and socket close https://bugzilla.redhat.com/show_bug.cgi?id=2265517 [ 3 ] Bug #2265518 - CVE-2024-26582 kernel: tls: use-after-free with partial reads and async decrypt https://bugzilla.redhat.com/show_bug.cgi?id=2265518 [ 4 ] Bug #2265519 - CVE-2024-26584 kernel: tls: handle backlogging of crypto requests https://bugzilla.redhat.com/show_bug.cgi?id=2265519 [ 5 ] Bug #2265520 - CVE-2024-26583 kernel: tls: race between async notify and socket close https://bugzilla.redhat.com/show_bug.cgi?id=2265520 [ 6 ] Bug #2265646 - CVE-2024-26593 kernel: i2c: i801: Fix block process call transactions https://bugzilla.redhat.com/show_bug.cgi?id=2265646 [ 7 ] Bug #2265833 - CVE-2024-26603 kernel: x86/fpu: Stoprelying on userspace for info to fault in xsave buffer https://bugzilla.redhat.com/show_bug.cgi?id=2265833 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-71f0f16533' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest kernel 6.7.6 in Fedora 38 introduces significant updates that encompass critical CVE resolutions alongside major enhancements to system reliability.. Fedora Kernel Update, Security Patch, System Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 28, 2024 Important Fedora
89

Fedora 38: FEDORA-2024-cf47b35a6c Critical Kernel-headers Update

The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-cf47b35a6c 2024-02-06 03:42:03.891066 -------------------------------------------------------------------------------- Name : kernel-headers Product : Fedora 38 Version : 6.7.3 Release : 100.fc38 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. -------------------------------------------------------------------------------- Update Information: The 6.7.3 stable kernel rebase contains new features, improved hardware support, and a number of important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 1 2024 Justin M. Forbes - 6.7.3-1 - Linux v6.7.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2253986 - CVE-2023-6679 kernel: NULL pointer dereference in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c https://bugzilla.redhat.com/show_bug.cgi?id=2253986 [ 2 ] Bug #2260041 - CVE-2024-23849 kernel: off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison, resulting in out-of-bounds access https://bugzilla.redhat.com/show_bug.cgi?id=2260041 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-cf47b35a6c' at the command line. For more information, refer to thednf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The Fedora 38 kernel-headers update brings enhancements, better compatibility with hardware, and resolves multiple reported problems.. Fedora Kernel Update,Kernal Headers,System Support Enhancements. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 06, 2024 Critical Fedora
89

Fedora: 2024-2fb8991c68 critical: sos 4.6.1 troubleshooting enhancement

Rebase on upstream 4.6.1: see https://github.com/sosreport/sos/releases/tag/4.6.1 for full changelog.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2fb8991c68 2024-01-20 03:24:12.788932 -------------------------------------------------------------------------------- Name : sos Product : Fedora 38 Version : 4.6.1 Release : 1.fc38 URL : https://github.com/sosreport/sos Summary : A set of tools to gather troubleshooting information from a system Description : Sos is a set of tools that gathers information about system hardware and configuration. The information can then be used for diagnostic purposes and debugging. Sos is commonly used to help support technicians and developers. -------------------------------------------------------------------------------- Update Information: Rebase on upstream 4.6.1: see https://github.com/sosreport/sos/releases/tag/4.6.1 for full changelog. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 11 2024 Sandro Bonazzola - 4.6.1-1 - Update to 4.6.1 - Resolves: fedora#2257777 - Resolves: fedora#2244214 * Mon Aug 21 2023 Sandro Bonazzola - 4.6.0-1 - Update to 4.6.0 - Resolves: fedora#2232710 * Mon Jul 24 2023 Sandro Bonazzola - 4.5.6-1 - Update to 4.5.6 - Resolves: fedora#2224676 - Resolves: fedora#2223526 * Sat Jul 22 2023 Fedora Release Engineering - 4.5.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jun 27 2023 Python Maint - 4.5.5-2 - Rebuilt for Python 3.12 * Tue Jun 27 2023 Sandro Bonazzola - 4.5.5-1 - Update to 4.5.5 - Resolves: rhbz#2217163 * Wed Jun 14 2023 Python Maint - 4.5.4-4 - Rebuilt for Python 3.12 * Thu Jun 1 2023 Sandro Bonazzola - 4.5.4-3 - Adapt to new Fedora packaging guidelines * Mon May 29 2023 Sandro Bonazzola - 4.5.4-2 - Remove unneeded requirements * Mon May 29 2023 Sandro Bonazzola - 4.5.4-1 -Update to 4.5.4 - Resolves: rhbz#2210423 * Tue May 2 2023 Sandro Bonazzola - 4.5.3-1 - Update to 4.5.3 - Resolves: rhbz#2192086 * Mon Apr 3 2023 Sandro Bonazzola - 4.5.2-1 - Update to 4.5.2 - Resolves: rhbz#2183722 * Fri Mar 17 2023 Sandro Bonazzola - 4.5.1-2 - migrated to SPDX license -------------------------------------------------------------------------------- References: [ 1 ] Bug #2244214 - sos: Ansible Automation Platform collects customer passwords and tokens via sosreport [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2244214 [ 2 ] Bug #2257777 - sos-4.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2257777 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2fb8991c68' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 38's sos package 4.6.1 brings advancements in system diagnostics through enhanced efficiency, new features, and resolved issues.. Fedora 38, sos report, software enhancements, troubleshooting updates. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jan 20, 2024 Critical Fedora
89

Fedora 39: FEDORA-2023-43ef9f5376 Critical: Curl HTTP Memory Problem

- fix HTTP headers eat all memory (CVE-2023-38039). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-43ef9f5376 2023-09-26 00:17:00.225467 -------------------------------------------------------------------------------- Name : curl Product : Fedora 39 Version : 8.2.1 Release : 2.fc39 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. -------------------------------------------------------------------------------- Update Information: - fix HTTP headers eat all memory (CVE-2023-38039) -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 13 2023 Jan Macku - 8.2.1-2 - fix HTTP headers eat all memory (CVE-2023-38039) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2239136 - CVE-2023-38039 curl: out of heap memory issue due to missing limit on header quntity [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2239136 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-43ef9f5376' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Fedora 39 patch resolves a memory leak in curl related to HTTP headers, significantly improving overall system security.. Curl Update, Memory Fix, Fedora Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 26, 2023 Critical Fedora
217

Oracle Linux 8: ELSA-2023-3821 Moderate: Ruby 2.7 HTTP Response Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3821 https://linux.oracle.com/errata/ELSA-2023-3821.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: ruby-2.7.8-139.module+el8.8.0+21111+2e34bf27.i686.rpm ruby-2.7.8-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm ruby-default-gems-2.7.8-139.module+el8.8.0+21111+2e34bf27.noarch.rpm ruby-devel-2.7.8-139.module+el8.8.0+21111+2e34bf27.i686.rpm ruby-devel-2.7.8-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm ruby-doc-2.7.8-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-abrt-0.4.0-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-abrt-doc-0.4.0-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-bigdecimal-2.0.0-139.module+el8.8.0+21111+2e34bf27.i686.rpm rubygem-bigdecimal-2.0.0-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm rubygem-bson-4.8.1-1.module+el8.4.0+20239+cbf59dc8.x86_64.rpm rubygem-bson-doc-4.8.1-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-bundler-2.2.24-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-io-console-0.5.6-139.module+el8.8.0+21111+2e34bf27.i686.rpm rubygem-io-console-0.5.6-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm rubygem-irb-1.2.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-json-2.3.0-139.module+el8.8.0+21111+2e34bf27.i686.rpm rubygem-json-2.3.0-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm rubygem-minitest-5.13.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-mongo-2.11.3-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-mongo-doc-2.11.3-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-mysql2-0.5.3-1.module+el8.4.0+20239+cbf59dc8.x86_64.rpm rubygem-mysql2-doc-0.5.3-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-net-telnet-0.2.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-openssl-2.1.4-139.module+el8.8.0+21111+2e34bf27.i686.rpm rubygem-openssl-2.1.4-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm rubygem-pg-1.2.3-1.module+el8.4.0+20239+cbf59dc8.x86_64.rpm rubygem-pg-doc-1.2.3-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-power_assert-1.1.7-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-psych-3.1.0-139.module+el8.8.0+21111+2e34bf27.i686.rpm rubygem-psych-3.1.0-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm rubygem-rake-13.0.1-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-rdoc-6.2.1.1-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygems-3.1.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygems-devel-3.1.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-test-unit-3.3.4-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-xmlrpc-0.3.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm ruby-libs-2.7.8-139.module+el8.8.0+21111+2e34bf27.i686.rpm ruby-libs-2.7.8-139.module+el8.8.0+21111+2e34bf27.x86_64.rpm aarch64: ruby-2.7.8-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm ruby-default-gems-2.7.8-139.module+el8.8.0+21111+2e34bf27.noarch.rpm ruby-devel-2.7.8-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm ruby-doc-2.7.8-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-abrt-0.4.0-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-abrt-doc-0.4.0-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-bigdecimal-2.0.0-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm rubygem-bson-4.8.1-1.module+el8.4.0+20239+cbf59dc8.aarch64.rpm rubygem-bson-doc-4.8.1-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-bundler-2.2.24-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-io-console-0.5.6-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm rubygem-irb-1.2.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-json-2.3.0-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm rubygem-minitest-5.13.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-mongo-2.11.3-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-mongo-doc-2.11.3-1.module+el8.3.0+7760+537395ec.noarch.rpm rubygem-mysql2-0.5.3-1.module+el8.4.0+20239+cbf59dc8.aarch64.rpm rubygem-mysql2-doc-0.5.3-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-net-telnet-0.2.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-openssl-2.1.4-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm rubygem-pg-1.2.3-1.module+el8.4.0+20239+cbf59dc8.aarch64.rpm rubygem-pg-doc-1.2.3-1.module+el8.4.0+20239+cbf59dc8.noarch.rpm rubygem-power_assert-1.1.7-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-psych-3.1.0-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm rubygem-rake-13.0.1-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-rdoc-6.2.1.1-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygems-3.1.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygems-devel-3.1.6-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-test-unit-3.3.4-139.module+el8.8.0+21111+2e34bf27.noarch.rpm rubygem-xmlrpc-0.3.0-139.module+el8.8.0+21111+2e34bf27.noarch.rpm ruby-libs-2.7.8-139.module+el8.8.0+21111+2e34bf27.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//ruby-2.7.8-139.module+el8.8.0+21111+2e34bf27.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-abrt-0.4.0-1.module+el8.3.0+7760+537395ec.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-bson-4.8.1-1.module+el8.4.0+20239+cbf59dc8.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-mongo-2.11.3-1.module+el8.3.0+7760+537395ec.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-mysql2-0.5.3-1.module+el8.4.0+20239+cbf59dc8.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-pg-1.2.3-1.module+el8.4.0+20239+cbf59dc8.src.rpm Related CVEs: CVE-2021-33621 CVE-2023-28755 CVE-2023-28756 Description of changes: ruby [2.7.8-139] - Upgrade to Ruby 2.7.8. Resolves: rhbz#2149262 - Fix HTTP response splitting in CGI. Resolves: CVE-2021-33621 - Fix ReDoS vulnerability in URI. Resolves: CVE-2023-28755 - Fix ReDoS vulnerability in Time. Resolves: CVE-2023-28756 rubygem-abrt [0.4.0-1] - Update to abrt 0.4.0. Resolves: rhbz#1842476 rubygem-bson [4.8.1-1] - Update to bson 4.8.1 by merging Fedora master branch (commit: 0741dbc) Resolves: rhbz#1817135 rubygem-mongo [2.11.3-1] - Update to mongo 2.11.3 by merging Fedora master branch (commit: c3f83c2) Resolves: rhbz#1817135 rubygem-mysql2 [0.5.3-2] - Update by merging Fedora rawhide branch (commit: 81e2cc9) - Fix Mysql2::Result test for Ruby 3.1. - Remove gem_make.out and mkmf.log files from the binary RPM package. - Fix test assertion for mariadb-connector-c. Related:rhbz#2063772 [0.5.3-1] - New upstream release 0.5.3 by merging Fedora master branch (commit: 674d475) Resolves: rhbz#1817135 [0.5.2-1] - New upstream release 0.5.2 by merging Fedora master branch (commit: cc15309) Resolves: rhbz#1672575 rubygem-pg [1.2.3-1] - Update to pg 1.2.3 by merging Fedora master branch (commit: 5db4d26) Resolves: rhbz#1817135 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2023-3821 enhances Ruby 2.7, addressing issues and significantly improving overall system security measures.. Oracle Linux Security,Ruby Updates,ELSA-2023-3821,Bug Fix,System Enhancements. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 10, 2023 Important Oracle
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200