Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
172

Ubuntu 22.04 LTS USN-7608-5 critical: kernel security flaws

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7608-5 July 08, 2025 linux-ibm-5.15, linux-intel-iotg, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-intel-iotg: Linux kernel for Intel IoT platforms - linux-nvidia-tegra: Linux kernel for NVIDIA Tegra systems - linux-nvidia-tegra-igx: Linux kernel for NVIDIA Tegra IGX systems - linux-ibm-5.15: Linux kernel for IBM cloud systems - linux-nvidia-tegra-5.15: Linux kernel for NVIDIA Tegra systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - SMB network file system; - Memory management; - Netfilter; - Network traffic control; (CVE-2025-37890, CVE-2024-46787, CVE-2025-37798, CVE-2025-38000, CVE-2025-37932, CVE-2025-38001, CVE-2025-37997, CVE-2024-50047, CVE-2024-53051) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1029-nvidia-tegra-igx 5.15.0-1029.29 linux-image-5.15.0-1029-nvidia-tegra-igx-rt 5.15.0-1029.29 linux-image-5.15.0-1040-nvidia-tegra 5.15.0-1040.40 linux-image-5.15.0-1040-nvidia-tegra-rt 5.15.0-1040.40 linux-image-5.15.0-1082-intel-iotg 5.15.0-1082.88 linux-image-intel-iotg 5.15.0.1082.82 linux-image-intel-iotg-5.15 5.15.0.1082.82 linux-image-nvidia-tegra 5.15.0.1040.40 linux-image-nvidia-tegra-5.15 5.15.0.1040.40 linux-image-nvidia-tegra-igx 5.15.0.1029.31 linux-image-nvidia-tegra-igx-5.15 5.15.0.1029.31 linux-image-nvidia-tegra-igx-rt 5.15.0.1029.31 linux-image-nvidia-tegra-igx-rt-5.15 5.15.0.1029.31 linux-image-nvidia-tegra-rt 5.15.0.1040.40 linux-image-nvidia-tegra-rt-5.15 5.15.0.1040.40 Ubuntu 20.04 LTS linux-image-5.15.0-1040-nvidia-tegra 5.15.0-1040.40~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1040-nvidia-tegra-rt 5.15.0-1040.40~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1079-ibm 5.15.0-1079.82~20.04.1 Available with Ubuntu Pro linux-image-ibm 5.15.0.1079.82~20.04.1 Available with Ubuntu Pro linux-image-ibm-5.15 5.15.0.1079.82~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra 5.15.0.1040.40~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-5.15 5.15.0.1040.40~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-rt 5.15.0.1040.40~20.04.1 Available with Ubuntu Pro linux-image-nvidia-tegra-rt-5.15 5.15.0.1040.40~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7608-5 https://ubuntu.com/security/notices/USN-7608-4 https://ubuntu.com/security/notices/USN-7608-3 https://ubuntu.com/security/notices/USN-7608-2 https://ubuntu.com/security/notices/USN-7608-1 CVE-2024-46787, CVE-2024-50047, CVE-2024-53051, CVE-2025-37798, CVE-2025-37890, CVE-2025-37932, CVE-2025-37997, CVE-2025-38000, CVE-2025-38001 Package Information: https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1082.88 https://launchpad.net/ubuntu/+source/linux-nvidia-tegra/5.15.0-1040.40 https://launchpad.net/ubuntu/+source/linux-nvidia-tegra-igx/5.15.0-1029.29 . New revisions in Ubuntu have rectified various security flaws within the Linux kernel, necessitating prompt action and resolution.. Kernel Security, Linux Kernel Flaws, Ubuntu Update 22.04, Security Notice, System Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 08, 2025 Critical Ubuntu
172

Ubuntu 22.04 LTS USN-7609-2 critical: Risks in Linux Kernel Architecture

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7608-1 July 01, 2025 linux, linux-aws, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle, linux-oracle-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems - linux-gke: Linux kernel for Google Container Engine (GKE) systems - linux-gkeop: Linux kernel for Google Container Engine (GKE) systems - linux-ibm: Linux kernel for IBM cloud systems - linux-kvm: Linux kernel for cloud environments - linux-lowlatency: Linux low latency kernel - linux-nvidia: Linux kernel for NVIDIA systems - linux-oracle: Linux kernel for Oracle Cloud systems - linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems - linux-hwe-5.15: Linux hardware enablement (HWE) kernel - linux-lowlatency-hwe-5.15: Linux low latency kernel - linux-oracle-5.15: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - SMB network file system; - Memory management; - Netfilter; - Network traffic control; (CVE-2025-37890, CVE-2024-46787, CVE-2025-37798, CVE-2025-38000, CVE-2025-37932, CVE-2025-38001, CVE-2025-37997, CVE-2024-50047, CVE-2024-53051) Update instructions: The problem can be corrected by updating your system to thefollowing package versions: Ubuntu 22.04 LTS linux-image-5.15.0-1069-gkeop 5.15.0-1069.77 linux-image-5.15.0-1079-ibm 5.15.0-1079.82 linux-image-5.15.0-1081-nvidia 5.15.0-1081.82 linux-image-5.15.0-1081-nvidia-lowlatency 5.15.0-1081.82 linux-image-5.15.0-1083-kvm 5.15.0-1083.88 linux-image-5.15.0-1084-gke 5.15.0-1084.90 linux-image-5.15.0-1084-oracle 5.15.0-1084.90 linux-image-5.15.0-1086-gcp 5.15.0-1086.95 linux-image-5.15.0-1087-aws 5.15.0-1087.94 linux-image-5.15.0-1087-aws-64k 5.15.0-1087.94 linux-image-5.15.0-143-generic 5.15.0-143.153 linux-image-5.15.0-143-generic-64k 5.15.0-143.153 linux-image-5.15.0-143-generic-lpae 5.15.0-143.153 linux-image-5.15.0-143-lowlatency 5.15.0-143.153 linux-image-5.15.0-143-lowlatency-64k 5.15.0-143.153 linux-image-aws-5.15 5.15.0.1087.90 linux-image-aws-64k-5.15 5.15.0.1087.90 linux-image-aws-64k-lts-22.04 5.15.0.1087.90 linux-image-aws-lts-22.04 5.15.0.1087.90 linux-image-gcp-5.15 5.15.0.1086.82 linux-image-gcp-lts-22.04 5.15.0.1086.82 linux-image-generic 5.15.0.143.138 linux-image-generic-5.15 5.15.0.143.138 linux-image-generic-64k 5.15.0.143.138 linux-image-generic-64k-5.15 5.15.0.143.138 linux-image-generic-lpae 5.15.0.143.138 linux-image-generic-lpae-5.15 5.15.0.143.138 linux-image-gke 5.15.0.1084.83 linux-image-gke-5.15 5.15.0.1084.83 linux-image-gkeop 5.15.0.1069.68 linux-image-gkeop-5.15 5.15.0.1069.68 linux-image-ibm 5.15.0.1079.75 linux-image-kvm 5.15.0.1083.79 linux-image-kvm-5.15 5.15.0.1083.79 linux-image-lowlatency 5.15.0.143.129 linux-image-lowlatency-5.15 5.15.0.143.129 linux-image-lowlatency-64k 5.15.0.143.129 linux-image-lowlatency-64k-5.15 5.15.0.143.129 linux-image-nvidia 5.15.0.1081.81 linux-image-nvidia-5.15 5.15.0.1081.81 linux-image-nvidia-lowlatency 5.15.0.1081.81 linux-image-nvidia-lowlatency-5.15 5.15.0.1081.81 linux-image-oracle-5.15 5.15.0.1084.80 linux-image-oracle-lts-22.04 5.15.0.1084.80 linux-image-virtual 5.15.0.143.138 linux-image-virtual-5.15 5.15.0.143.138 Ubuntu 20.04 LTS linux-image-5.15.0-1084-oracle 5.15.0-1084.90~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-1086-gcp 5.15.0-1086.95~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-143-generic 5.15.0-143.153~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-143-generic-64k 5.15.0-143.153~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-143-generic-lpae 5.15.0-143.153~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-143-lowlatency 5.15.0-143.153~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-143-lowlatency-64k 5.15.0-143.153~20.04.1 Available with Ubuntu Pro linux-image-gcp 5.15.0.1086.95~20.04.1 Available with Ubuntu Pro linux-image-gcp-5.15 5.15.0.1086.95~20.04.1 Available with Ubuntu Pro linux-image-generic-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-generic-64k-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-generic-64k-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-generic-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-generic-lpae-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-generic-lpae-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04b 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04c 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-oem-20.04d 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-oracle 5.15.0.1084.90~20.04.1 Available with Ubuntu Pro linux-image-oracle-5.15 5.15.0.1084.90~20.04.1 Available with Ubuntu Pro linux-image-virtual-5.15 5.15.0.143.153~20.04.1 Available with Ubuntu Pro linux-image-virtual-hwe-20.04 5.15.0.143.153~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernelmetapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7608-1 CVE-2024-46787, CVE-2024-50047, CVE-2024-53051, CVE-2025-37798, CVE-2025-37890, CVE-2025-37932, CVE-2025-37997, CVE-2025-38000, CVE-2025-38001 Package Information: https://launchpad.net/ubuntu/+source/linux/5.15.0-143.153 https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1087.94 https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1086.95 https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1084.90 https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1069.77 https://launchpad.net/ubuntu/+source/linux-ibm/5.15.0-1079.82 https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1083.88 https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-143.153 https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1081.82 https://launchpad.net/ubuntu/+source/linux-oracle/5.15.0-1084.90 . Essential patches for Ubuntu's kernel address significant vulnerabilities to safeguard systems from potential threats.. Kernel Update, Ubuntu Security Notice, System Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 02, 2025 Critical Ubuntu
100

SUSE Linux 15 SP2: 2022:1591-1 Important: Kernel Live Patch Security Fix

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP2) ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1591-1 Rating: important References: #1195950 #1198133 Cross-References: CVE-2022-0330 CVE-2022-1158 CVSS scores: CVE-2022-0330 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-0330 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-1158 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise Module for Live Patching 15-SP2 SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 5.3.18-24_64 fixes several issues. The following security issues were fixed: - - CVE-2022-1158: Fixed KVM x86/mmu compare-and-exchange of gPTE via the user address (bsc#1198133) - CVE-2022-0330: A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allowed a local user to crash the system or escalate their privileges on the system. (bsc#1195950) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP2: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2022-1591=1 Package List: - SUSELinux Enterprise Module for Live Patching 15-SP2 (ppc64le s390x x86_64): kernel-livepatch-5_3_18-24_64-default-16-150200.2.1 kernel-livepatch-5_3_18-24_64-default-debuginfo-16-150200.2.1 kernel-livepatch-SLE15-SP2_Update_13-debugsource-16-150200.2.1 References: https://www.suse.com/security/cve/CVE-2022-0330.html https://www.suse.com/security/cve/CVE-2022-1158.html https://bugzilla.suse.com/1195950 https://bugzilla.suse.com/1198133 . SUSE has released a pivotal security update targeting severe vulnerabilities within the Linux Kernel Live Patch for SLE 15 SP2, which significantly improves system robustness.. SUSE Linux Kernel Update, Live Patching Security, System Update Flaws. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 10, 2022 Important SuSE
100

SUSE: 2018:1005-1 Important Kernel Patch for SLE 12 SP1 - DoS Flaws

An update that fixes four vulnerabilities is now available.. SUSE Security Update: Security update for the Linux Kernel (Live Patch 20 for SLE 12 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1005-1 Rating: important References: #1076017 #1083488 #1085114 #1085447 Cross-References: CVE-2017-13166 CVE-2018-1000004 CVE-2018-1068 CVE-2018-7566 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_57 fixes several issues. The following security issues were fixed: - CVE-2017-13166: An elevation of privilege vulnerability was fixed in the kernel v4l2 video driver. (bsc#1085447). - CVE-2018-1068: A flaw was found in the Linux kernels implementation of 32-bit syscall interface for bridging. This allowed a privileged user to arbitrarily write to a limited range of kernel memory (bsc#1085114). - CVE-2018-1000004: A race condition vulnerability existed in the sound system, which could lead to a deadlock and denial of service condition (bsc#1076017) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2018-690=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2018-690=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_74-60_64_57-default-7-2.1 kgraft-patch-3_12_74-60_64_57-xen-7-2.1 - SUSE LinuxEnterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_74-60_64_57-default-7-2.1 kgraft-patch-3_12_74-60_64_57-xen-7-2.1 References: https://www.suse.com/security/cve/CVE-2017-13166.html https://www.suse.com/security/cve/CVE-2018-1000004.html https://www.suse.com/security/cve/CVE-2018-1068.html https://www.suse.com/security/cve/CVE-2018-7566.html https://bugzilla.suse.com/1076017 https://bugzilla.suse.com/1083488 https://bugzilla.suse.com/1085114 https://bugzilla.suse.com/1085447 -- . Essential SUSE kernel updates target four significant vulnerabilities. Ensure you upgrade promptly for maximum security and enhanced system performance.. SUSE Linux Enterprise, Kernel Patch Update, System Flaws, Security Patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 20, 2018 Important SuSE
89

Fedora 25: 2017-ae7a707032 Moderate: Moodle System Flaws Update

3.1.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-ae7a707032 2017-02-06 20:31:36.912335 -------------------------------------------------------------------------------- Name : moodle Product : Fedora 25 Version : 3.1.4 Release : 1.fc25 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. -------------------------------------------------------------------------------- Update Information: 3.1.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1401065 - CVE-2016-8642 CVE-2016-8643 CVE-2016-8644 CVE-2017-2576 CVE-2017-2578 moodle: various flaws [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1401065 [ 2 ] Bug #1401064 - CVE-2016-8642 CVE-2016-8643 CVE-2016-8644 CVE-2017-2576 CVE-2017-2578 moodle: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1401064 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade moodle' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This Fedora release specifically attends to vulnerabilities found in Moodle 3.1.4,improving overall system resilience and trustworthiness.. Moodle Security Update,Fedora 25,Software Flaws,Open Source Education. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 07, 2017 Important Fedora
98

RedHat 6: RHSA-2014-0557-01 Important Kernel-RT Updates: System Crash Risks

Updated kernel-rt packages that fix multiple security issues are now available for Red Hat Enterprise MRG 2.5. The Red Hat Security Response Team has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel-rt security update Advisory ID: RHSA-2014:0557-01 Product: Red Hat Enterprise MRG for RHEL-6 Advisory URL: https://access.redhat.com/errata/RHSA-2014:0557.html Issue date: 2014-05-27 CVE Names: CVE-2014-0100 CVE-2014-0196 CVE-2014-1737 CVE-2014-1738 CVE-2014-2672 CVE-2014-2678 CVE-2014-2706 CVE-2014-2851 CVE-2014-3122 ==================================================================== 1. Summary: Updated kernel-rt packages that fix multiple security issues are now available for Red Hat Enterprise MRG 2.5. The Red Hat Security Response Team has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: MRG Realtime for RHEL 6 Server v.2 - noarch, x86_64 3. Description: The kernel-rt packages contain the Linux kernel, the core of any Linux operating system. * A race condition leading to a use-after-free flaw was found in the way the Linux kernel's TCP/IP protocol suite implementation handled the addition of fragments to the LRU (Last-Recently Used) list under certain conditions. A remote attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system by sending a large amount of specially crafted fragmented packets to that system. (CVE-2014-0100, Important) * A race condition flaw, leading to heap-based buffer overflows, was found in theway the Linux kernel's N_TTY line discipline (LDISC) implementation handled concurrent processing of echo output and TTY write operations originating from user space when the underlying TTY driver was PTY. An unprivileged, local user could use this flaw to crash the system or, potentially, escalate their privileges on the system. (CVE-2014-0196, Important) * A flaw was found in the way the Linux kernel's floppy driver handled user space provided data in certain error code paths while processing FDRAWCMD IOCTL commands. A local user with write access to /dev/fdX could use this flaw to free (using the kfree() function) arbitrary kernel memory. (CVE-2014-1737, Important) * It was found that the Linux kernel's floppy driver leaked internal kernel memory addresses to user space during the processing of the FDRAWCMD IOCTL command. A local user with write access to /dev/fdX could use this flaw to obtain information about the kernel heap arrangement. (CVE-2014-1738, Low) Note: A local user with write access to /dev/fdX could use these two flaws (CVE-2014-1737 in combination with CVE-2014-1738) to escalate their privileges on the system. * A use-after-free flaw was found in the way the ping_init_sock() function of the Linux kernel handled the group_info reference counter. A local, unprivileged user could use this flaw to crash the system or, potentially, escalate their privileges on the system. (CVE-2014-2851, Important) * It was found that a remote attacker could use a race condition flaw in the ath_tx_aggr_sleep() function to crash the system by creating large network traffic on the system's Atheros 9k wireless network adapter. (CVE-2014-2672, Moderate) * A NULL pointer dereference flaw was found in the rds_iw_laddr_check() function in the Linux kernel's implementation of Reliable Datagram Sockets (RDS). A local, unprivileged user could use this flaw to crash the system. (CVE-2014-2678, Moderate) * A race condition flaw was found in the way the Linux kernel's mac80211 subsystem implementation handledsynchronization between TX and STA wake-up code paths. A remote attacker could use this flaw to crash the system. (CVE-2014-2706, Moderate) * It was found that the try_to_unmap_cluster() function in the Linux kernel's Memory Managment subsystem did not properly handle page locking in certain cases, which could potentially trigger the BUG_ON() macro in the mlock_vma_page() function. A local, unprivileged user could use this flaw to crash the system. (CVE-2014-3122, Moderate) Red Hat would like to thank Matthew Daley for reporting CVE-2014-1737 and CVE-2014-1738. The CVE-2014-0100 issue was discovered by Nikolay Aleksandrov of Red Hat. Users are advised to upgrade to these updated packages, which upgrade the kernel-rt kernel to version kernel-rt-3.10.33-rt32.34 and correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 To install kernel packages manually, use "rpm -ivh [package]". Do not use "rpm -Uvh" as that will remove the running kernel binaries from your system. You may use "rpm -e" to remove old kernels after determining that the new kernel functions properly on your system. 5. Bugs fixed (https://bugzilla.redhat.com/): 1070618 - CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free 1083246 - CVE-2014-2672 kernel: ath9k: tid-> sched race in ath_tx_aggr_sleep() 1083274 - CVE-2014-2678 kernel: net: rds: dereference of a NULL device in rds_iw_laddr_check() 1083512 - CVE-2014-2706 Kernel: net: mac80211: crash dues to AP powersave TX vs. wakeup race 1086730 - CVE-2014-2851 kernel: net: ping: refcount issue in ping_init_sock() function 1093076 - CVE-2014-3122 Kernel: mm: try_to_unmap_cluster() should lock_page() before mlocking 1094232 - CVE-2014-0196kernel: pty layer race condition leading to memory corruption 1094299 - CVE-2014-1737 CVE-2014-1738 kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command 6. Package List: MRG Realtime for RHEL 6 Server v.2: Source: noarch: kernel-rt-doc-3.10.33-rt32.34.el6rt.noarch.rpm kernel-rt-firmware-3.10.33-rt32.34.el6rt.noarch.rpm x86_64: kernel-rt-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-debug-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-debug-debuginfo-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-debug-devel-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-debuginfo-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-debuginfo-common-x86_64-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-devel-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-trace-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-trace-debuginfo-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-trace-devel-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-vanilla-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-vanilla-debuginfo-3.10.33-rt32.34.el6rt.x86_64.rpm kernel-rt-vanilla-devel-3.10.33-rt32.34.el6rt.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-0100 https://access.redhat.com/security/cve/CVE-2014-0196 https://access.redhat.com/security/cve/CVE-2014-1737 https://access.redhat.com/security/cve/CVE-2014-1738 https://access.redhat.com/security/cve/CVE-2014-2672 https://access.redhat.com/security/cve/CVE-2014-2678 https://access.redhat.com/security/cve/CVE-2014-2706 https://access.redhat.com/security/cve/CVE-2014-2851 https://access.redhat.com/security/cve/CVE-2014-3122 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4(GNU/Linux) iD8DBQFThL2GXlSAg2UNWIIRAnKNAKC8L7AEZsVfN3SDIRby/ZWJeNGsfACePcvG f8gO1I7yuxLQ1jWWp5abYcQ=WQJC -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical kernel-rt security patch for Red Hat Enterprise MRG, addressing various vulnerabilities impacting functionality and access rights.. RedHat Security Update, Kernel-RT Packages, Important Security Patch, Privilege Escalation Fix, System Stability Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 27, 2014 Important Red Hat
98

Red Hat Enterprise Linux 5 RHSA-2009-1585-01 Moderate: Samba3x Flaws

Updated samba3x packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: samba3x security and bug fix update Advisory ID: RHSA-2009:1585-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2009:1585.html Issue date: 2009-11-16 CVE Names: CVE-2009-1888 CVE-2009-2813 CVE-2009-2906 CVE-2009-2948 ==================================================================== 1. Summary: Updated samba3x packages that fix multiple security issues and various bugs are now available for Red Hat Enterprise Linux 5 Supplementary. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Supplementary (v. 5 client) - x86_64 RHEL Supplementary (v. 5 server) - x86_64 3. Description: Samba is a suite of programs used by machines to share files, printers, and other information. These samba3x packages provide Samba 3.3, which is a Technology Preview for Red Hat Enterprise Linux 5. These packages cannot be installed in parallel with the samba packages. Note: Technology Previews are not intended for production use. A denial of service flaw was found in the Samba smbd daemon. An authenticated, remote user could send a specially-crafted response that would cause an smbd child process to enter an infinite loop. An authenticated, remote user could use this flaw to exhaust system resources by opening multiple CIFS sessions. (CVE-2009-2906) An uninitialized data access flaw was discovered in the smbd daemon when using the non-default "dos filemode" configuration option in "smb.conf".An authenticated, remote user with write access to a file could possibly use this flaw to change an access control list for that file, even when such access should have been denied. (CVE-2009-1888) A flaw was discovered in the way Samba handled users without a home directory set in the back-end password database (e.g. "/etc/passwd"). If a share for the home directory of such a user was created (e.g. using the automated "[homes]" share), any user able to access that share could see the whole file system, possibly bypassing intended access restrictions. (CVE-2009-2813) The mount.cifs program printed CIFS passwords as part of its debug output when running in verbose mode. When mount.cifs had the setuid bit set, a local, unprivileged user could use this flaw to disclose passwords from a file that would otherwise be inaccessible to that user. Note: mount.cifs from the samba3x packages distributed by Red Hat does not have the setuid bit set. This flaw only affected systems where the setuid bit was manually set by an administrator. (CVE-2009-2948) This update also fixes the following bugs: * the samba3x packages contained missing and conflicting license information. License information was missing for the libtalloc, libtdb, and tdb-tools packages. The samba3x-common package provided a COPYING file; however, it stated the license was GPLv2, while RPM metadata stated the licenses were either GPLv3 or LGPLv3. This update adds the correct licensing information to the samba3x-common, libsmbclient, libtalloc, libtdb, and tdb-tools packages. (BZ#528633) * the upstream Samba version in the samba3x packages distributed with the RHEA-2009:1399 update contained broken implementations of the Netlogon credential chain and SAMR access checks security subsystems. This prevented Samba from acting as a domain controller: Client systems could not join the domain; users could not authenticate; and systems could not access the user and group list. (BZ#524551) * this update resolves interoperability issues with Windows 7 andWindows Server 2008 R2. (BZ#529022) These packages upgrade Samba from version 3.3.5 to version 3.3.8. Refer to the Samba Release Notes for a list of changes between versions: Users of samba3x should upgrade to these updated packages, which resolve these issues. After installing this update, the smb service will be restarted automatically. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 506996 - CVE-2009-1888 Samba improper file access 523752 - CVE-2009-2813 Samba: Share restriction bypass via home-less directory user account(s) 524551 - samba3x 3.3.4 is broken as domain controller 526074 - CVE-2009-2948 samba: information disclosure in suid mount.cifs 526645 - CVE-2009-2906 samba: infinite loop flaw in smbd on unexpected oplock break notification reply 528633 - License problem for Samba3X in x86_64 supplementary image 529022 - Interoperation with Windows 7 and Windows 2008 (R2) broken 6. Package List: RHEL Desktop Supplementary (v. 5 client): Source: samba3x-3.3.8-0.46.el5.src.rpm x86_64: libsmbclient-3.0.34-46.el5.x86_64.rpm libsmbclient-devel-3.0.34-46.el5.x86_64.rpm libtalloc-1.2.0-46.el5.x86_64.rpm libtalloc-devel-1.2.0-46.el5.x86_64.rpm libtdb-1.1.2-46.el5.x86_64.rpm libtdb-devel-1.1.2-46.el5.x86_64.rpm samba3x-3.3.8-0.46.el5.x86_64.rpm samba3x-client-3.3.8-0.46.el5.x86_64.rpm samba3x-common-3.3.8-0.46.el5.x86_64.rpm samba3x-debuginfo-3.3.8-0.46.el5.x86_64.rpm samba3x-doc-3.3.8-0.46.el5.x86_64.rpm samba3x-domainjoin-gui-3.3.8-0.46.el5.x86_64.rpm samba3x-swat-3.3.8-0.46.el5.x86_64.rpm samba3x-winbind-3.3.8-0.46.el5.x86_64.rpm samba3x-winbind-devel-3.3.8-0.46.el5.x86_64.rpm tdb-tools-1.1.2-46.el5.x86_64.rpm RHEL Supplementary (v. 5server): Source: samba3x-3.3.8-0.46.el5.src.rpm x86_64: libsmbclient-3.0.34-46.el5.x86_64.rpm libsmbclient-devel-3.0.34-46.el5.x86_64.rpm libtalloc-1.2.0-46.el5.x86_64.rpm libtalloc-devel-1.2.0-46.el5.x86_64.rpm libtdb-1.1.2-46.el5.x86_64.rpm libtdb-devel-1.1.2-46.el5.x86_64.rpm samba3x-3.3.8-0.46.el5.x86_64.rpm samba3x-client-3.3.8-0.46.el5.x86_64.rpm samba3x-common-3.3.8-0.46.el5.x86_64.rpm samba3x-debuginfo-3.3.8-0.46.el5.x86_64.rpm samba3x-doc-3.3.8-0.46.el5.x86_64.rpm samba3x-domainjoin-gui-3.3.8-0.46.el5.x86_64.rpm samba3x-swat-3.3.8-0.46.el5.x86_64.rpm samba3x-winbind-3.3.8-0.46.el5.x86_64.rpm samba3x-winbind-devel-3.3.8-0.46.el5.x86_64.rpm tdb-tools-1.1.2-46.el5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-1888 https://www.cve.org/CVERecord?id=CVE-2009-2813 https://www.cve.org/CVERecord?id=CVE-2009-2906 https://www.cve.org/CVERecord?id=CVE-2009-2948 https://access.redhat.com/security/updates/classification#moderate https://www.redhat.com/en/services/support 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLAXVEXlSAg2UNWIIRAjWRAJ4nUZBFKne6TS8w/O2yv8VHUaCuYACgr8u/ 7etek5nMkxXoqWDRfT10wbw=yoNV -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent samba3x security bulletin featuring numerous patches for Red Hat Enterprise Linux, resolving significant vulnerabilities.. Samba3x Updates, Red Hat Security, Bug Fixes, Samba Flaws, System Security. . LinuxSecurity.com Team

Calendar%202 Nov 16, 2009 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200