Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 40: Critical libcoap Update Addressing CVE-2024-31031 Released

Patch to fix CVE-2024-31031. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-75863445ff 2024-05-03 01:40:26.180521 -------------------------------------------------------------------------------- Name : libcoap Product : Fedora 40 Version : 4.3.4a Release : 2.fc40 URL : https://libcoap.net/ Summary : C library implementation of CoAP Description : The Constrained Application Protocol (CoAP) is a specialized web transfer protocol for use with constrained nodes and constrained networks in the Internet of Things. The protocol is designed for machine-to-machine (M2M) applications such as smart energy and building automation. libcoap implements a lightweight application-protocol for devices with constrained resources such as computing power, RF range, memory, bandwidth, or network packet sizes. This protocol, CoAP, was standardized in the IETF working group "CoRE" as RFC 7252. -------------------------------------------------------------------------------- Update Information: Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 24 2024 Peter Robinson - 4.3.4a-2 - Patch to fix CVE-2024-31031 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2275804 - CVE-2024-31031 libcoap: unsigned integer overflow vulnerability in coap_pdu.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2275804 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-75863445ff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Update released for CVE-2024-31031 affecting Fedora 40's libcoap library, aimed at improving both security measures and overall system efficiency.. libcoap updates, security patches, Fedora software updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 03, 2024 Critical Fedora
89

Fedora 36: FEDORA-2023-8b0938312e Important Security Update for Libsignal

Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-8b0938312e 2023-04-29 05:12:00.194966 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 36 Version : 2.3.3 Release : 7.fc36 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-7 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-8b0938312e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important announcement for libsignal-protocol-c: a crucial update is now available addressing an unsigned integer overflow issue in protobuf-c, vital for Fedora users. libsignal-protocol-c, update notification, critical fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 29, 2023 Important Fedora
89

Fedora 38: FEDORA-2023-7cfe245fa7 Critical: Memory Leak Vulnerability

Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6cfe134db6 2023-04-29 04:41:45.954640 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 37 Version : 2.3.3 Release : 8.fc37 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-8 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6cfe134db6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 37 patch resolves a critical unsigned integer overflow in libsignal-protocol-c via a retrofitted solution.. libsignal-protocol-c, unsigned integer overflow, backport fix, Fedora Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 29, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-4e094d5297 critical: libsignal-protocol-c overflow

Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-4e094d5297 2023-04-29 02:52:14.059040 --------------------------------------------------------------------------------Name : libsignal-protocol-c Product : Fedora 38 Version : 2.3.3 Release : 9.fc38 URL : https://github.com/signalapp/libsignal-protocol-c Summary : Signal Protocol C library Description : This is a ratcheting forward secrecy protocol that works in synchronous and asynchronous messaging environments. --------------------------------------------------------------------------------Update Information: Backport a fix for [CVE-2022-48468](https://www.cve.org/CVERecord?id=CVE-2022-48468) for [protobuf-c](https://github.com/protobuf-c/protobuf-c), which is bundled in `libsignal-protocol-c`. https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217 https://github.com/protobuf-c/protobuf-c/issues/499 https://github.com/protobuf-c/protobuf-c/pull/513 https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 19 2023 Randy Barlow - 2.3.3-9 - Fix CVE-2022-48468: unsigned integer overflow (#2186673). --------------------------------------------------------------------------------References: [ 1 ] Bug #2186674 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2186674 [ 2 ] Bug #2186675 - CVE-2022-48468 libsignal-protocol-c: protobuf-c: an unsigned integer overflow in parse_required_member [fedora-36] https://bugzilla.redhat.com/show_bug.cgi?id=2186675 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4e094d5297' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Implement backport solution for integer overflow issue in libsignal-protocol-c for Fedora 38. Additional information on the modification is provided.. Libsignal-Protocol-C, Protobuf-C, Fedora Update, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 29, 2023 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here