Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A vulnerability has been discovered in Ubiquiti UniFi, which can lead to local privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Ubiquiti UniFi: Privilege Escalation Date: November 06, 2024 Bugs: #941922 ID: 202411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Ubiquiti UniFi, which can lead to local privilege escalation. Background ========== Ubiquiti UniFi is a Management Controller for Ubiquiti Networks UniFi APs. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------ net-wireless/unifi < 8.5.6 > = 8.5.6 Description =========== A vulnerability has been discovered in Ubiquiti UniFi. Please review the CVE identifier referenced below for details. Impact ====== The vulnerability allows a malicious actor with a local operational system user to execute high privilege actions on UniFi Network Server. Workaround ========== There is no known workaround at this time. Resolution ========== All Ubiquiti UniFi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/unifi-8.5.6" References ========== [ 1 ] CVE-2024-42028 https://nvd.nist.gov/vuln/detail/CVE-2024-42028 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202411-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any securityconcerns should be addressed to
Updated Satellite 6.13 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures:. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: Satellite 6.13.3 Async Security Update Advisory ID: RHSA-2023:4466-01 Product: Red Hat Satellite 6 Advisory URL: https://access.redhat.com/errata/RHSA-2023:4466 Issue date: 2023-08-03 CVE Names: CVE-2022-40899 CVE-2023-0118 ===================================================================== 1. Summary: Updated Satellite 6.13 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.13 for RHEL 8 - noarch 3. Description: Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security fix(es): foreman: Arbitrary code execution through templates. (CVE-2023-0118) python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server (CVE-2022-40899) This update fixes the following bugs: 2159659 - CVE-2023-0118 foreman: Arbitrary code execution through templates [rhn_satellite_6.13] 2211954 -
Updated Satellite 6.13 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.13 for RHEL 8 - noarch. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Satellite 6.13.1 Async Security Update Advisory ID: RHSA-2023:3387-01 Product: Red Hat Satellite 6 Advisory URL: https://access.redhat.com/errata/RHSA-2023:3387 Issue date: 2023-05-31 CVE Names: CVE-2023-0119 ==================================================================== 1. Summary: Updated Satellite 6.13 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.13 for RHEL 8 - noarch 3. Description: Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security fix(es): foreman: Stored cross-site scripting in host tab(CVE-2023-0119) This update fixes the following bugs: 2190469 - CVE-2023-0119 foreman: Stored cross-site scripting in host tab [rhn_satellite_6.13] 2190460 - Navigating to Capsules page on Satellite WebUI displays error "Pulp plugin missing for synchronizable content types: . Repositories containing these content types will not be synced." for few seconds 2190470 - Host Detail button landed to old Host UI page 2190472 - wrong metadata if uploaded rpm have different name than name in rpm 2190473 - Getting "NoMethodError undefined method `get_status' for nil:NilClass" when publishing content view 2190509 - Incremental update of the content view takes long time to complete 2190512 - Errorimporting repositories with GPG key 2190513 - Satellite showing errata from module streams not installed on client as upgradable/installable when content is imported (not synced) 2191657 - Importing Red Hat Repository Import on Disconnected Red Hat Satellite taking huge time around 5 hours2191659 - Misleading job status in the new host UI when running jobs in bulk 2196242 - Upgrade to Satellite 6.13 fails on db:seed step with error GraphQL::InvalidNameError: Names must match /^[_a-zA-Z][_a-zA-Z0-9]*$/ but 'RHEL OpenStack Platform' does not 2208642 - Support satellite-clone with Ansible running on Python 3.11 in RHEL 8.8 Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2159104 - CVE-2023-0119 Foreman: Stored cross-site scripting in host tab 2190460 - Navigating to Capsules page on Satellite WebUI displays error "Pulp plugin missing for synchronizable content types: . Repositories containing these content types will not be synced." for few seconds 2190464 - job invocation shows wrong info after remote execution job (regression from 6.11) 2190470 - Host Detail button landed to old Host UI page 2190472 - wrong metadata if uploaded rpm have different name than name in rpm 2190473 - Getting "NoMethodError undefined method `get_status' for nil:NilClass" when publishing content view 2190509 - Incremental update of the content view takes long time to complete 2190512 - Error importing repositories with GPG key 2190513 - Satellite showing errata from module streams not installed on client as upgradable/installable when content is imported (not synced) 2191657 - Importing Red Hat Repository Import on Disconnected Red Hat Satellite taking huge time around 5 hours2191659 - Misleading job status in the newhost UI when running jobs in bulk 2196242 - Upgrade to Satellite 6.13 fails on db:seed step with error GraphQL::InvalidNameError: Names must match /^[_a-zA-Z][_a-zA-Z0-9]*$/ but 'RHEL OpenStack Platform' does not 2208642 - Support satellite-clone with Ansible running on Python 3.11 in RHEL 8.8 6. Package List: Red Hat Satellite 6.13 for RHEL 8: Source: foreman-3.5.1.17-1.el8sat.src.rpm python-pulp-rpm-3.18.14-1.el8pc.src.rpm rubygem-dynflow-1.6.11-1.el8sat.src.rpm rubygem-foreman_remote_execution-8.3.0-1.el8sat.src.rpm rubygem-katello-4.7.0.25-1.el8sat.src.rpm rubygem-smart_proxy_ansible-3.5.4-1.el8sat.src.rpm satellite-6.13.1-1.el8sat.src.rpm noarch: foreman-3.5.1.17-1.el8sat.noarch.rpm foreman-cli-3.5.1.17-1.el8sat.noarch.rpm foreman-debug-3.5.1.17-1.el8sat.noarch.rpm foreman-dynflow-sidekiq-3.5.1.17-1.el8sat.noarch.rpm foreman-ec2-3.5.1.17-1.el8sat.noarch.rpm foreman-journald-3.5.1.17-1.el8sat.noarch.rpm foreman-libvirt-3.5.1.17-1.el8sat.noarch.rpm foreman-openstack-3.5.1.17-1.el8sat.noarch.rpm foreman-ovirt-3.5.1.17-1.el8sat.noarch.rpm foreman-postgresql-3.5.1.17-1.el8sat.noarch.rpm foreman-service-3.5.1.17-1.el8sat.noarch.rpm foreman-telemetry-3.5.1.17-1.el8sat.noarch.rpm foreman-vmware-3.5.1.17-1.el8sat.noarch.rpm python39-pulp-rpm-3.18.14-1.el8pc.noarch.rpm rubygem-dynflow-1.6.11-1.el8sat.noarch.rpm rubygem-foreman_remote_execution-8.3.0-1.el8sat.noarch.rpm rubygem-foreman_remote_execution-cockpit-8.3.0-1.el8sat.noarch.rpm rubygem-katello-4.7.0.25-1.el8sat.noarch.rpm rubygem-smart_proxy_ansible-3.5.4-1.el8sat.noarch.rpm satellite-6.13.1-1.el8sat.noarch.rpm satellite-cli-6.13.1-1.el8sat.noarch.rpm satellite-common-6.13.1-1.el8sat.noarch.rpm Red Hat Satellite 6.13 for RHEL8: Source: foreman-3.5.1.17-1.el8sat.src.rpm python-pulp-rpm-3.18.14-1.el8pc.src.rpm rubygem-dynflow-1.6.11-1.el8sat.src.rpm rubygem-smart_proxy_ansible-3.5.4-1.el8sat.src.rpm satellite-6.13.1-1.el8sat.src.rpm noarch: foreman-debug-3.5.1.17-1.el8sat.noarch.rpm python39-pulp-rpm-3.18.14-1.el8pc.noarch.rpm rubygem-dynflow-1.6.11-1.el8sat.noarch.rpm rubygem-smart_proxy_ansible-3.5.4-1.el8sat.noarch.rpm satellite-capsule-6.13.1-1.el8sat.noarch.rpm satellite-common-6.13.1-1.el8sat.noarch.rpm Red Hat Satellite 6.13 for RHEL 8: Source: satellite-clone-3.3.0-2.el8sat.src.rpm noarch: satellite-clone-3.3.0-2.el8sat.noarch.rpm Red Hat Satellite 6.13 for RHEL 8: Source: foreman-3.5.1.17-1.el8sat.src.rpm satellite-6.13.1-1.el8sat.src.rpm noarch: foreman-cli-3.5.1.17-1.el8sat.noarch.rpm satellite-cli-6.13.1-1.el8sat.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-0119 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZHeVAtzjgjWX9erEAQgI4Q//X5noheedXgPO/LByWnl87d6+iRD6mEQo Njl8cMYP0CzNz6s4rvZtDssuwe4cPx77i7vydOCuVDxFlqf4j9nHDfHku/66IBkf V0jQ1YU0gpAGxzzdjpsfOcaXLfTkTtE8GMivM+gOcpfwdaMirelH+9EIJ59+q09c 7NSIxvHf+OGW5MeX2H6SUkCvPiy5ttOJu3P/d0nIllUqzFsCnPMhm8s1MZwaK2kI HXwEMzidNeaZqOX0s9NhhPOM2P5kinqtyEZPMvVFuTnq4wbz5YToz6ivMmgVKG5I s9PEFFOzBm8JhEO/CJI8vYMdE6XfMk/sNfZe9nNiGbNfndO+5gJ9ENM4V9DhyJDn qV3qkIa9aT0YK+oGqCcQqZA+UoyIlsX5EaDZH1o9eDGn+AVrGzzRarOCBHcMdckI 1gDgRGLDZmDeJm3VgFGKVgKHPjB6MP5BDb5a0imBWhvRWtSJwSJ5gstYaP7nvUM3 vibjtKnoLakoFDhU55RA01m1Pqo4c+8Ecqhzv6yiVLb7pSYVayRlDn3G1duL+Pju DRaz+Lskua0T6bJXF4efEnOlHsJkQC9yup34JYKLnf+tHi4Tetm/AMsaSnq53WgQ /0mevZ8O1dmkg8IkWypycTstVRkdUacgWhQPx5rbVqQMsOrn3RJCDqSXUgEkkmNf qvU8kOmaSg0=zDsj -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for sudo is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: sudo security update Advisory ID: RHSA-2023:3264-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3264 Issue date: 2023-05-23 CVE Names: CVE-2023-22809 ==================================================================== 1. Summary: An update for sudo is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.4) - x86_64 3. Description: The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: arbitrary file write with privileges of the RunAs user (CVE-2023-22809) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161142 -CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: sudo-1.8.19p2-12.el7_4.3.src.rpm x86_64: sudo-1.8.19p2-12.el7_4.3.x86_64.rpm sudo-debuginfo-1.8.19p2-12.el7_4.3.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.4): x86_64: sudo-debuginfo-1.8.19p2-12.el7_4.3.i686.rpm sudo-debuginfo-1.8.19p2-12.el7_4.3.x86_64.rpm sudo-devel-1.8.19p2-12.el7_4.3.i686.rpm sudo-devel-1.8.19p2-12.el7_4.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-22809 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZGzKfdzjgjWX9erEAQiBeQ/+PEHn6hqQPc0Lg5ZphXUxckaPoxwJWsYO VxVCY3egY8aGiRWH+YTqjfIvblYlcD1DzD3uLQvqi5fsutSKt85J4RioY4larQ02 rIOG+asAgzhP8DqOAlPzPB40Is8xts+bfh1s7wTm+4U7yGXrEEktyT6S9QAazc82 TEUCRi7rPqmQ/04E8U04NoH/VV2NkiH6rzVAtbkW8Zxu09VH0FXObfyPnpaMrxwY 7oCQJEt2bV17I9ad+W0iHUnZt7vzCK6yT2p8wHx2XIWC7lHRNwQW3iPNl6jMwRjy W9IYe0Fk2wmSDR8mphXhCtEYmAxqLs7kbdjoiRSBSw430HA6WKujVugcbi5Jbmhl 841XDJdWGR3VkN7zaqiyKOReExYVNQQX7LfSAqqAFEVRjz6X42k9hxQax2m23jNS 7YXxZWO8GZj/vGxxOv2AgSMUK1ZIcRlPieJtOg0Ji3SismZxE3crw6ykh9IiqYtz TbzEBdUH7LBVHZAlX/b/jsrriIGzwaK6ChbmQBKZSDKcI10a1YzsBhFlxy1h/ALh wLcW+e+GdU1JB2nDsTSjSyuP/EmEMJ/MIKaS0/03uOj3s66fo8SvMYmG/EYV6jVB VfqQMD6sV/5my7CP3zfAsIwpF4kY0IjG3FJOZvaXaApnxZAP/GSLOiDU+zjM357p bIIk4P/QBmU=zhNV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for sudo is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: sudo security update Advisory ID: RHSA-2023:3262-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3262 Issue date: 2023-05-23 CVE Names: CVE-2023-22809 ==================================================================== 1. Summary: An update for sudo is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.6) - x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 7.6) - x86_64 3. Description: The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are used for system management purposes, without having to log in as root. Security Fix(es): * sudo: arbitrary file write with privileges of the RunAs user (CVE-2023-22809) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161142 -CVE-2023-22809 sudo: arbitrary file write with privileges of the RunAs user 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.6): Source: sudo-1.8.23-3.el7_6.3.src.rpm x86_64: sudo-1.8.23-3.el7_6.3.x86_64.rpm sudo-debuginfo-1.8.23-3.el7_6.3.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v. 7.6): x86_64: sudo-debuginfo-1.8.23-3.el7_6.3.i686.rpm sudo-debuginfo-1.8.23-3.el7_6.3.x86_64.rpm sudo-devel-1.8.23-3.el7_6.3.i686.rpm sudo-devel-1.8.23-3.el7_6.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2023-22809 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZGzKcdzjgjWX9erEAQh40A/8Cia5e74sbfVLsIAZRo1634P2Qki5uRJR 2jApxcWnvl//0E/idDOiWToobWBrgcNoY4/4/y1z1cSNFg4xN+Dwzl1xYML3NwY+ iY+nfWZfo4mFOJkVkf+7CIaZJYGoCRRNKY3x//jB27MyTJpwu17csnuJPuwOAIxC aaeeNDtgMRctGT3VlTQgaj+2u9l/XdUg/fs5URjMOPzzEEbLutOgPTWlhTC4IPh7 tGAObUBbQdJ+N+bA2u1JwKtPfy/4jjha1jZDFTDPIWO5eEUmCWuJ+iixvfFqGw+V +AiOQb+BnbMFHrCPEPyjq5JDEbEDeyQjK1uO5vjWk+p4rVYTDGe7oStyyZetYF/d XIEM9hxs7zRIl1SiUyZ6eAFDtWx8wfn9JEq59ladDwHGuy71BUQlE8LnG5b5hDc+ xo/CZ4ynz+30AThvgXPj/RS9y/LgUq0CxPydnDKzDWEl1QSOz0m2rMHncq2aC9ss 8FgOax+zVUIyX0ihm0A/angOSmwH72Yxp/r1qqlbBcb9aov9SP+SAs5qEaDEXIui hpKugIWJyqCz++VQ0gV2c4EKjBuy1SuRqeWJjc8YgLV/gn+HxELOrVi79PmCEi6r 22XencGIcrWMzy5Ur8H35K62FI1XAnxPOZ+pB9cCo3ji8BjLLd7jLNDTFJdJWRX/ y2W9Y3MTdcs=k4ha -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Satellite 6.13 Release Advisory ID: RHSA-2023:2097-03 Product: Red Hat Satellite 6 Advisory URL: https://access.redhat.com/errata/RHSA-2023:2097 Issue date: 2023-05-03 CVE Names: CVE-2022-1471 CVE-2022-22577 CVE-2022-23514 CVE-2022-23515 CVE-2022-23516 CVE-2022-23517 CVE-2022-23518 CVE-2022-23519 CVE-2022-23520 CVE-2022-25857 CVE-2022-27777 CVE-2022-31163 CVE-2022-32224 CVE-2022-33980 CVE-2022-38749 CVE-2022-38750 CVE-2022-38751 CVE-2022-38752 CVE-2022-41323 CVE-2022-41946 CVE-2022-42003 CVE-2022-42004 CVE-2022-42889 CVE-2023-23969 CVE-2023-24580 ==================================================================== 1. Summary: An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components. 2. Relevant releases/architectures: Red Hat Satellite 6.13 for RHEL 8 - noarch, x86_64 3. Description: Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool. Security Fix(es): * CVE-2022-1471 CVE-2022-25857 CVE-2022-38749 CVE-2022-38750 CVE-2022-38751 CVE-2022-38752 candlepin and puppetserver: various flaws * CVE-2022-22577 tfm-rubygem-actionpack: rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack * CVE-2022-23514 rubygem-loofah: inefficient regular expression leading to denial of service * CVE-2022-23515 rubygem-loofah:rubygem-loofah: Improper neutralization of data URIs leading to Cross Site Scripting * CVE-2022-23516 rubygem-loofah: Uncontrolled Recursion leading to denial of service * CVE-2022-23517 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Inefficient Regular Expression leading to denial of service * CVE-2022-23518 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Improper neutralization of data URIs leading to Cross site scripting * CVE-2022-23519 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Cross site scripting vulnerability with certain configurations * CVE-2022-23520 tfm-rubygem-rails-html-sanitizer: rubygem-rails-html-sanitizer: Cross site scripting vulnerability with certain configurations * CVE-2022-27777 tfm-rubygem-actionview: Possible cross-site scripting vulnerability in Action View tag helpers* CVE-2022-31163 rubygem-tzinfo: rubygem-tzinfo: arbitrary code execution * CVE-2022-32224 tfm-rubygem-activerecord: activerecord: Possible RCE escalation bug with Serialized Columns in Active Record * CVE-2022-33980 candlepin: apache-commons-configuration2: Apache Commons Configuration insecure interpolation defaults * CVE-2022-41323 satellite-capsule:el8/python-django: Potential denial-of-service vulnerability in internationalized URLs * CVE-2022-41946 candlepin: postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions * CVE-2022-42003 CVE-2022-42004 candlepin: various flaws * CVE-2022-42889 candlepin: apache-commons-text: variable interpolation RCE * CVE-2022-23514 rubygem-loofah: inefficient regular expression leading to denial of service * CVE-2023-23969 python-django: Potential denial-of-service via Accept-Language headers* CVE-2023-24580 python-django: Potential denial-of-service vulnerability in file uploads For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. AdditionalChanges: The items above are not a complete list of changes. This update also fixes several bugs and adds various enhancements. Documentation for these changes is available from the Release Notes document. 4. Solution: For Red Hat Satellite 6.13, see the following documentation for the release. https://docs.redhat.com/en/documentation/red_hat_satellite/6.13 The important instructions on how to upgrade are available below. https://docs.redhat.com/en/documentation/red_hat_satellite/6.13/html/upgrading_and_updating_red_hat_satellite/index 5. Bugs fixed (https://bugzilla.redhat.com/): 1225819 - [RFE] Ability to sync from closest CDN mirror for Capsule 1266407 - IPA (external users) not able to authenticate using hammer CLI: invalid user / SSO failed 1630294 - [RFE] Remote execution overview dashboard should be more interactive like the Monitor Dashboard 1638226 - [RFE] Show difference in errata between ContentViewVersions 1650468 - [RFE] Allow to export Docker images from content views or as repository as part ISS 1761012 - [RFE] Ability to generate a report for ansible/remote execution task result. 1786358 - [RFE] Ability to make persistent changes in "ansible.cfg" on Satellite Server. 1787456 - [RFE] Candlepin log rotation settings should be user-configurable 1813274 - [RFE] Allow customers to be able to add more columns to 'All Hosts' page in Red Hat Satellite 6 webui. 1826648 - [RFE] new report template to list all the installed packages 1837767 - Errata search filtered with ID does not work in Web UI 1841534 - Provide support for "Privileged User" session when host console is being taken via cockpit from Satellite 6.7 UI 1845489 - Audit page shows "auditable id / Host2" for "Host1" but Host2 does not exist or deleted from the all hosts 1880947 - Satellite fails with "HTTP error (500 - Internal Server Error): PG::UniqueViolation: ERROR: duplicate key value violates unique constraint" while running concurrent registrations 1888667 - "Applied Errata" report template does not consider input "Up to" and"Since" in WebUI, hammer works 1895976 - Hammer Allows Invalid Release Version to be Set on Activation Key 1920810 - Error message related to Trend in production log 1931027 - Entitlement certificate is missing content section for a custom product 1931533 - Update foreman-bootloaders-redhat to 202102220000 to add efinet module to Grub2 modules 1950468 - root_pass setting does not enforce minimum length of 8 characters as the host and hostgroups forms do 1952529 - Package and Errata actions on content hosts selected using the "select all hosts" option fails. 1956210 - Health check should use hostname -f 1956985 - [RFE] Capsule Last Sync date and status should not be based on task data. 1963266 - [RFE]: Provide Capsule Load Balancer as an option for Global Registration Feature 1964037 - wrong generation of /etc/tomcat/cert-users.properties 1965871 - Change /var/log/candlepin directory owner/group to candlepin with 750 permission 1978683 - [global registration] - puppet configuration are not inherited to host from host-group while global registration 1978995 - [RFE] The satellite-installer should display the mismatched FQDN additionally rather than just showing the commands to verify the output 1990790 - [RFE] add possibility to resize bookmarks dropdown menu 1990875 - Update the foreman-discovery-image to inject the latest e1000e NIC drivers for I219-LM network cards 1995097 - Tuning profile 'default' requires at least 8 GB of memory and 1 CPU cores 1995470 - Activation key can be deleted, but still shows up in hostgroup configuration 1997186 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans 1997199 - Can't create bookmarks under Lifecyle Environments 2026151 - Can't sync private Azure registry to Satellite 2029402 - [RFE] Add functionality in Hammer to Add/Delete a single Ansible role to Hostgroup without defining every role. 2032040 - Enhance foreman-rake katello:correct_repositories to handle Katello::Errors::CandlepinError: Unable to find content with the ID"xxxxxxxxxxx". 2043600 - consumer certificate is generated with validity after 19th Jan 2038 which is causing 2038 bug on 32bit systems 2050234 - pulp_streamer runs out of file descriptors when upstream server is unavailable 2052904 - [RFE] Prevent the deletion of content credentials when they are in use in Satellite 6.x 2056402 - [RFE] New hosts page doesn't show global and host parameters2057314 - RHEL 9 as Guest OS is not available on Satellite 6.11 2060099 - [RFE] ouia-ID for tile cards in the new host details page 2062526 - Another deadlock issue when syncing repos with high concurrency 2063999 - No profiles are shown for any module streams 2066323 - [RFE] Satellite should use the newer asynchronous endpoint to export manifests 2069438 - [RFE] new host ui details, tracer tab, page reload required after change 2073847 - Restarting postgres just before task finish causes discrepancy between foreman and dynflow task status - forever 2077363 - Fail to sync kickstart repositories with same sub repositories concurrently 2080296 - CVE-2022-27777 tfm-rubygem-actionview: Possible cross-site scripting vulnerability in Action View tag helpers2080302 - CVE-2022-22577 rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack 2088156 - Broken Link in the Realms section of Satellite 2088529 - ForemanCustomScript in Host provisioned on Azure CR fails with `command not found` 2094912 - Unable to search the hosts based on the query "ansible_role", if the roles are inherited from the hostgroup. 2098079 - [RFE] Add an ability to search by Insights status 2101708 - when host is deleted on hypervisor while ansible job is running, hosts gets deleted on hypervisor level 2102078 - podman run returns Error: unexpected end of JSON input on image pulled from satellite 2103936 - Execution of satellite-installer raises multiple "warning: URI.escape is obsolete" messages in Red Hat Satellite 6.11 2104247 - [RFE] version non-specific flag to enable puppet on Red Hat Satellite. 2105067 - CVE-2022-33980apache-commons-configuration: Apache Commons Configuration insecure interpolation defaults 2105441 - RHEL 9 provisioned host goes into emergency mode after initial reboot 2106475 - [RFE] Enhance puppet agent deployment for external puppetserver 2106753 - [RFE] Allow user to choose between Graphical and Text mode anaconda installer during system build via Satellite 6 2107011 - [RFE] Keep notifications from RSS feed in Notifications drawer in Satellite webui for a longer period of time 2107758 - [RFE] Upgrade to Redis 6 2108997 - CVE-2022-32224 activerecord: Possible RCE escalation bug with Serialized Columns in Active Record 2109634 - Add module profile information to modulemd enpoints 2110551 - CVE-2022-31163 rubygem-tzinfo: arbitrary code execution 2111159 - Refreshing Alternate Content Source complains about invalid remote URL 2115970 - Sync container images of existing docker type repositories fail with 404 - Not found 2116375 - Even in 6.11.1, sync summary email notification shows the incorrect summary for newly added errata. 2118651 - pull-provider rex jobs hang if host is not configured correctly 2119053 - [RFE] X509 Certification Authorities" and "Optional HTTP headers as JSON (ERB allowed)" fields need to be included via Hammer CLI for "hammer webhook create" and "hammer webhook update" sub-options 2119155 - With every edit of an exising webhook, the value in password field disappears in Satellite 6.10/6.11/6.12 2119911 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching 2120640 - New host details Insights tab doesn't work with breadcrumb switcher 2121210 - [RFE] Add call-to-action empty states 2121288 - Still getting API request timeout when indexing contents. 2122617 - Kerberos authentication fails for POST, PUT and DELETE api calls 2123593 - Satellite should be able to process (and publish) compressed comps.xml / groups metadata 2123696 - The Value of "Allowed bootdisk types" shows up as subnetfull_host where as it is set assubnet,full_host in Satellite 6.12 2123835 - System build based on "PXELess Discovery" will always fail if the "Installation token lifetime" has been disabled in Satellite 6.12 2123932 - Unable to "Remove" a repository directly if the repo is part of a CV as well as CCV in Satellite 6.12 2124419 - Jobs pushed in MQTT queue is not delivered if yggdrasild was not running and communicating with the right broker before the jobs were pushed 2124520 - Changing the Capsule parameter post the curl command generated in Global Registration template failed with error "There was an error while generating the command, see the logs for more information." 2125424 - Mismatched files between stage 1 and stage 2 kernel images during kickstart provisioning 2125444 - Syncable exports across partitions causes ' Invalid cross-device link' error 2126200 - CV version details repository tab links to library_instance_inverse version and lets you use it like a regular library repo 2126349 - Missing cron job for ACS refresh in /etc/cron.d/katello 2126372 - Refreshing ACS with --name instead of --id fails with "Error: Found more than one alternate_content_source." 2126695 - Wrong Ansible documentation links 2126789 - CVE-2022-25857 snakeyaml: Denial of Service due to missing nested depth limitation for collections 2126905 - Packages tab - Add dropdown to select upgrade version 2127180 - random failure of Inventory Sync 2127470 - Content view publish fails when the content view and repository both have a large name with : Error message: the server returns an error HTTP status code: 500 2127998 - RHEL 9 appstream and baseos kickstart repositories not showing as recommended repositories 2128038 - [RFE] Add Templates tab in the new UI, under (Hosts > All Hosts > Host ) 2128256 - Insights recommendation sync failing in Satelliite 2128864 - Repo Deletion with no feed url causes a `ArgumentError` 2128894 - [RFE] Need syncable yum-format repository imports 2129706 - CVE-2022-38749 snakeyaml: Uncaught exception inorg.yaml.snakeyaml.composer.Composer.composeSequenceNode 2129707 - CVE-2022-38750 snakeyaml: Uncaught exception in org.yaml.snakeyaml.constructor.BaseConstructor.constructObject 2129709 - CVE-2022-38751 snakeyaml: Uncaught exception in java.base/java.util.regex.Pattern$Ques.match 2129710 - CVE-2022-38752 snakeyaml: Uncaught exception in java.base/java.util.ArrayList.hashCode 2129950 - ISE when creating a CV with org_id specified as array 2130596 - insights-client --register --verbose throwing error UnicodeEncodeError: 'ascii' codec can't encode character '\ufffd' in position 94: ordinal not in range(128) 2130698 - New Host UI: Toggle group is hidden when host has no installable errata 2131312 - Satellite 6.9\6.10\6.11 suddenly cannot enable or sync satellite-tools repo for rhel 8 but the same works for rhel 7 2131369 - Updating subscription attributes of a host, such as CV and LCE fails with "Katello::Resources::Candlepin::Consumer: 400 Bad Request" and "Cannot construct instance of `org.candlepin.dto.api.v1.GuestIdDTO`" error 2131839 - re-enabling sync plans [FAIL] Could not update the sync plan: ERF28-1357 [ForemanTasks::RecurringLogicCancelledException]: Cannot update a cancelled Recurring Logic. 2132452 - Missing ouia-id for content view 2133343 - Content view filter will include module streams of other repos/arches if the errata contain rpms in different repos/arches. 2133615 - Content view filter included errata not in the filter date range 2134283 - SSH key passphrase is not working if password was set previously 2134682 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io 2135244 - CVE-2022-42003 jackson-databind: deep wrapper array nesting wrt UNWRAP_SINGLE_VALUE_ARRAYS 2135247 - CVE-2022-42004 jackson-databind: use of deeply nested arrays 2135418 - rubygem-foreman_hooks scriptlet issues an error message 2135435 - CVE-2022-42889 apache-commons-text: variable interpolation RCE 2136130 - CVE-2022-41323 python-django:Potential denial-of-service vulnerability in internationalized URLs 2137318 - hammer content-view purge only deletes up to "Entries per page" versions 2137350 - hammer repository types command is missing options 2137539 - mosquitto service is missing in `satellite-maintain service status -b` output 2138887 - [RFE] Add content export to FAM 2139209 - Don't use the term 'Subscription Watch' anymore 2139418 - MQTT ReX mode makes it too easy to to DDOS Satellite 2139441 - Improve empty state design when a host has applicable errata but no installable errata 2139545 - Registration error: PG::UniqueViolation: ERROR: duplicate key value violates unique constraint "katello_available_module_streams_name_stream_context" 2140628 - Preupgrade and upgrade jobs should not mention RHEL 7 2140807 - Show include all RPM without errata and the 3 other checkboxes for rpm and module stream filters outside table so they don't get hidden by empty state. 2141136 - Orphaned ACSs should be cleaned from smart proxies 2141187 - Searchbar disappears when trying to select a bookmark as user without bookmark permissions 2141455 - New host details - Move Details tab out of experimental labs 2141719 - While selecting "Enable debugging output" option, Satellite generates ahv virt-who confirguration with "internal_debug=true" which is not recognized by virt-who 2141810 - When working with CCV, include and exclude filters, eventually the number of packages in the CCV will not be as expected, causing problems to the customer 2142514 - Satellite-clone not working if ansible-core 2.13 is installed 2142555 - import puppet classes permission filter does not work 2143451 - Satellite upgrades should not require enabling the next versions Satellite repository, and should rely only on the Maintenance repository 2143497 - Can't perform incremental content exports in syncable format 2143515 - ERROR -- /parallel-executor-core: no manager for Dynflow::Director::Event for event: #
Updated Satellite 6.12 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures:. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Satellite 6.12.3 Async Security Update Advisory ID: RHSA-2023:1630-01 Product: Red Hat Satellite 6 Advisory URL: https://access.redhat.com/errata/RHSA-2023:1630 Issue date: 2023-04-04 CVE Names: CVE-2022-41946 ==================================================================== 1. Summary: Updated Satellite 6.12 packages that fixes important security bugs and several regular bugs are now available for Red Hat Satellite. 2. Relevant releases/architectures: Red Hat Satellite 6.12 for RHEL 8 - noarch 3. Description: Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security fix(es): * Candlepin: PreparedStatement.setText(int, InputStream) will create a temporary file if the InputStream is larger than 2k (CVE-2022-41946) This update fixes the following bugs: 2163538 - Pages Blank 2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos 2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions 2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching 2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails. 2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong todifferent organizations 2175002 - Getting "undefined method `schema_version' for nil:NilClass" while syncing from quay.io 2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static 2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11 2174995 - Health check should use hostname -f 2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans 2176272 - new wait task introduced by rh_cloud 6.0.44 is not recognized by maintain as OK to interrupt 2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11 2176922 - [RFE] Need syncable yum-format repository imports 2175003 - Can't perform incremental content exports in syncable format Users of Red Hat Satellite are advised to upgrade to these updated packages, which fix these bugs. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2153399 - CVE-2022-41946 postgresql-jdbc: Information leak of prepared statement data due to insecure temporary file permissions 2163538 - Pages Blank 2174984 - Getting 'null value in column \"image_manifest_id\" violates not-null constraint' when syncing openstack container repos 2174987 - (Regression of 2033940) Error: AttributeError: 'NoneType' object has no attribute 'cast' thrown while listing repository versions 2174994 - VMware Image based Provisioning fails with error- : Could not find virtual machine network interface matching 2174995 - Health check should use hostname -f 2174997 - Package and Errata actions on content hosts selected using the "select all hosts" option fails. 2174998 - Subscription can't be blank, A Pool and its Subscription cannot belong to different organizations 2175002 - Getting "undefined method`schema_version' for nil:NilClass" while syncing from quay.io 2175003 - Can't perform incremental content exports in syncable format 2175005 - New kickstart_kernel_options snippet breaks UEFI (Grub2) PXE provisioning when boot_mode is static 2175007 - [regression] data.yml is referring to old sync plain id which does not exist in katello_sync_plans 2175008 - RHEL 9 as Guest OS is not available on Satellite 6.11 2175010 - Some custom repositories are failing to synchorize with error "This field may not be blank" after upgrading to Red Hat Satellite 6.11 2176272 - new wait task introduced by rh_cloud 6.0.44 is not recognized by maintain as OK to interrupt 2176922 - [RFE] Need syncable yum-format repository imports 6. Package List: Red Hat Satellite 6.12 for RHEL8: Source: candlepin-4.1.20-1.el8sat.src.rpm foreman-3.3.0.21-2.el8sat.src.rpm python-django-3.2.16-1.el8pc.src.rpm python-pulp-container-2.10.12-1.el8pc.src.rpm python-pulpcore-3.18.16-1.el8pc.src.rpm rubygem-fog-vsphere-3.6.0-1.el8sat.src.rpm rubygem-foreman_maintain-1.1.12-1.el8sat.src.rpm rubygem-hammer_cli_katello-1.6.0.2-1.el8sat.src.rpm rubygem-katello-4.5.0.32-1.el8sat.src.rpm rubygem-optimist-3.0.1-1.el8sat.src.rpm rubygem-rbvmomi2-3.6.0-2.el8sat.src.rpm satellite-6.12.3-1.el8sat.src.rpm noarch: candlepin-4.1.20-1.el8sat.noarch.rpm candlepin-selinux-4.1.20-1.el8sat.noarch.rpm foreman-3.3.0.21-2.el8sat.noarch.rpm foreman-cli-3.3.0.21-2.el8sat.noarch.rpm foreman-debug-3.3.0.21-2.el8sat.noarch.rpm foreman-dynflow-sidekiq-3.3.0.21-2.el8sat.noarch.rpm foreman-ec2-3.3.0.21-2.el8sat.noarch.rpm foreman-gce-3.3.0.21-2.el8sat.noarch.rpm foreman-journald-3.3.0.21-2.el8sat.noarch.rpm foreman-libvirt-3.3.0.21-2.el8sat.noarch.rpm foreman-openstack-3.3.0.21-2.el8sat.noarch.rpm foreman-ovirt-3.3.0.21-2.el8sat.noarch.rpm foreman-postgresql-3.3.0.21-2.el8sat.noarch.rpm foreman-service-3.3.0.21-2.el8sat.noarch.rpm foreman-telemetry-3.3.0.21-2.el8sat.noarch.rpm foreman-vmware-3.3.0.21-2.el8sat.noarch.rpm python39-django-3.2.16-1.el8pc.noarch.rpm python39-pulp-container-2.10.12-1.el8pc.noarch.rpm python39-pulpcore-3.18.16-1.el8pc.noarch.rpm rubygem-fog-vsphere-3.6.0-1.el8sat.noarch.rpm rubygem-foreman_maintain-1.1.12-1.el8sat.noarch.rpm rubygem-hammer_cli_katello-1.6.0.2-1.el8sat.noarch.rpm rubygem-katello-4.5.0.32-1.el8sat.noarch.rpm rubygem-optimist-3.0.1-1.el8sat.noarch.rpm rubygem-rbvmomi2-3.6.0-2.el8sat.noarch.rpm satellite-6.12.3-1.el8sat.noarch.rpm satellite-cli-6.12.3-1.el8sat.noarch.rpm satellite-common-6.12.3-1.el8sat.noarch.rpm Red Hat Satellite 6.12 for RHEL8: Source: foreman-3.3.0.21-2.el8sat.src.rpm python-django-3.2.16-1.el8pc.src.rpm python-pulp-container-2.10.12-1.el8pc.src.rpm python-pulpcore-3.18.16-1.el8pc.src.rpm rubygem-foreman_maintain-1.1.12-1.el8sat.src.rpm satellite-6.12.3-1.el8sat.src.rpm noarch: foreman-debug-3.3.0.21-2.el8sat.noarch.rpm python39-django-3.2.16-1.el8pc.noarch.rpm python39-pulp-container-2.10.12-1.el8pc.noarch.rpm python39-pulpcore-3.18.16-1.el8pc.noarch.rpm rubygem-foreman_maintain-1.1.12-1.el8sat.noarch.rpm satellite-capsule-6.12.3-1.el8sat.noarch.rpm satellite-common-6.12.3-1.el8sat.noarch.rpm Red Hat Satellite 6.12 for RHEL 8: Source: rubygem-foreman_maintain-1.1.12-1.el8sat.src.rpm noarch: rubygem-foreman_maintain-1.1.12-1.el8sat.noarch.rpm Red Hat Satellite 6.12 for RHEL 8: Source: foreman-3.3.0.21-2.el8sat.src.rpm rubygem-hammer_cli_katello-1.6.0.2-1.el8sat.src.rpm satellite-6.12.3-1.el8sat.src.rpm noarch: foreman-cli-3.3.0.21-2.el8sat.noarch.rpm rubygem-hammer_cli_katello-1.6.0.2-1.el8sat.noarch.rpm satellite-cli-6.12.3-1.el8sat.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-41946 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZCyTXNzjgjWX9erEAQh57hAAknElDhu4y424D1I96zILtTXiJrw+50LC xD4Vj3M7gY44/6QgBg8H4YzfKZjdWGAX1byaDC6Wzb6RqtSnU7LCGI3PwA4+N3SY a0AidcKXV0LccwTDQcykzNC47KABGDShLFmXx5jGKn7LNWxrZRpSPk9G/jJ2tD4T /TaZQT20pxFXKs4vZvqXkjBDk0NXMT60fv128iXsloriajum1g3IcmJoB5R4tHFF bKp+sTWBVlOBwjN1qvXZ/A8JkvzKiyeMeVRM/sAoiFHNdaKFiUAsafebXTJJ55YC 7zHqsAIO1MznhhHuW7xqE4cJb58HBYDA/Q7xD5NONFYJn+nMWe6wNgB7GOL2vNOR 18wT35+BOjUnY0N1Ew9EllAeNOP2rHn9Rknvr9N3Z3WVzUU6Jsn4JyicdVi96xj7 1G/Mwu2/I4fZE0SkLF3YUI1eB0akNa9lASZ/i29XbyL3HuYhDLkdQ2qrRrCWOHf3 MxkYFoBaQlKLnWI21B1AkqIcxiqfQQ9CRECTTl86R3IZRnnV49IXrowSIAZJQy0r hY6n+5BcvGLpqDkyYelp4zaoCwnlSJRsXOJMBW5shF/9QfB1eWT7dU3bxnl+MPUO tZ0iUmZjbzBsjvgiQ22377jDuhdMk95lRgaRF8kdy13cavaykF5MA2hitfIiucL7 pG8zVEKEY3A=vuaR -----END PGP SIGNATURE----- -- RHSA-announce mailing list
gnome-settings-daemon bug fix and enhancement update. {"type":"TYPE_ENHANCEMENT","shortCode":"RL","name":"RLEA-2022:6456","synopsis":"gnome-settings-daemon bug fix and enhancement update","severity":"SEVERITY_UNKNOWN","topic":"An update for gnome-settings-daemon is now available for Rocky Linux 8.","description":"The gnome-settings-daemon packages contain a daemon to share settings from GNOME to other applications. It also handles global key bindings, as well as a number of desktop-wide settings.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"2122964","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2122964","description":"Automatic logout function logs out of GDM session, causing GUI to fail [rhel-8.6.0.z]"}],"cves":[{"name":"RHEA-2022:6456","sourceBy":"Red Hat","sourceLink":"https:\/\/access.redhat.com\/errata\/RHEA-2022:6456","cvss3ScoringVector":"","cvss3BaseScore":"","cwe":""}],"references":[],"publishedAt":"2023-01-30T05:24:11.760119Z","rpms":{},"rebootSuggested":false,"buildReferences":[]}. Fedora Core unveils a new kernel patch that rectifies errors and enhances system performance and security features.. Rocky Linux, gnome-settings-daemon, bug fix, system enhancements. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.