Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 36: FEDORA-2022-d5eefdbf2d Major Upgrade: LibTPMS Performance Boost

tpm2: Marshal event sequence objects' hash state ---- Build of libtpms 0.8.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-c4edcdbf1c 2021-09-24 20:04:10.616639 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 35 Version : 0.8.6 Release : 0.20210910git7a4d46a119.fc35.0 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: Marshal event sequence objects' hash state ---- Build of libtpms 0.8.5 --------------------------------------------------------------------------------ChangeLog: * Fri Sep 10 2021 Stefan Berger - 0.8.6-1.20210910git7a4d46a119 - tpm2: Marshal event sequence objects' hash state * Wed Sep 1 2021 Stefan Berger - 0.8.5-1.20210901git18ba4c0206 - Build of libtpms 0.8.5 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-c4edcdbf1c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ ListGuidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The release of LibTPM 0.8.6 for Fedora 35 introduces a range of improvements and modifications to enhance TPM capabilities.. LibTPM,Fedora 35,TPM update. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Sep 24, 2021 Informational Fedora
91

Gentoo: GLSA 202107-10 Normal: TCG TPM2 Information Leak

A bug in TCG TPM2 Software Stack may result in information disclosure to a local attacker.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TCG TPM2 Software Stack: Information disclosure Date: July 07, 2021 Bugs: #746563 ID: 202107-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A bug in TCG TPM2 Software Stack may result in information disclosure to a local attacker. Background ========= TCG TPM2 Software Stack is a library to interface with trusted platform modules. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-crypt/tpm2-tss < 2.4.3 > = 2.4.3 Description ========== TCG TPM2 Software Stack did not appropriately apply FAPI policies to protect data encrypted with the trusted platform module. Impact ===== Data encrypted using TCG TPM2 Software Stack (tpm2-tss) may not be protected from an attacker. Workaround ========= There is no known workaround at this time. Resolution ========= All tpm2-tss users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-crypt/tpm2-tss-2.4.3" References ========= [ 1 ] CVE-2020-24455 https://nvd.nist.gov/vuln/detail/CVE-2020-24455 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentialityand security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202112-15 resolves a vulnerability in the XYZ package leading to remote privilege escalation. Update promptly to safeguard your environment.. TCG TPM2, Information Disclosure, Linux Security, Gentoo Advisory. . LinuxSecurity.com Team

Calendar 2 Jul 07, 2021 Gentoo
89

Fedora 33: FEDORA-2021-caf9e04ef1 Critical: LibTPMS AES IV Fix

tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-caf9e04ef1 2021-03-10 00:41:43.224986 --------------------------------------------------------------------------------Name : libtpms Product : Fedora 33 Version : 0.7.7 Release : 0.20210302gitfd5bd3fb1d.fc33 URL : https://github.com/stefanberger/libtpms Summary : Library providing Trusted Platform Module (TPM) functionality Description : A library providing TPM functionality for VMs. Targeted for integration into Qemu. --------------------------------------------------------------------------------Update Information: tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue --------------------------------------------------------------------------------ChangeLog: * Tue Mar 2 2021 Stefan Breger - 0.7.7-0.20210302gitfd5bd3fb1d - tpm2: CryptSym: fix AES output IV; a CVE has been filed for this issue - tpm2: fixes a suspend/resume problem when public keys are loaded --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-caf9e04ef1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Essential patch addressing concerns with AES initialization vector in libtpms on Fedora 33; detailed upgrade guidance included.. libtpms, Fedora 33, AES, TPM, update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 09, 2021 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here