Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora 42 OpenBao 2.5.2 Key Fixes for XSS and User Confirmation Issues

Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fba501f889 2026-04-03 17:03:00.363045+00:00 -------------------------------------------------------------------------------- Name : openbao Product : Fedora 42 Version : 2.5.2 Release : 1.fc42 URL : https://openbao.org Summary : A tool for securely accessing secrets Description : Openbao secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets in modern computing. Openbao handles leasing, key revocation, key rolling, and auditing. Through a unified API, users can access an encrypted Key/Value store and network encryption-as-a-service, or generate AWS IAM/STS credentials, SQL/NoSQL databases, X.509 certificates, SSH credentials, and more. -------------------------------------------------------------------------------- Update Information: Update to upstream 2.5.2, including fixes for CVE-2026-33757 and CVE-2026-33758 -------------------------------------------------------------------------------- ChangeLog: * Wed Mar 25 2026 Dave Dykstra - 2.5.2-1 - update to upstream 2.5.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2452352 - CVE-2026-33757 openbao: lack of user confirmation for OpenBao OIDC direct callback mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452352 [ 2 ] Bug #2452355 - CVE-2026-33758 openbao: reflected XSS in OpenBao OIDC authentication error message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2452355 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fba501f889' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update to openbao 2.5.2 for Fedora 42 addresses CVE-2026-33757 and CVE-2026-33758 vulnerabilities. Recommended updates!. openbao Fedora security update CVE-2026-33757 CVE-2026-33758. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 03, 2026 Important Fedora
89

Fedora 43 WeasyPrint Critical SSRF Issue Fix FEDORA-2026-f59e87ad88

update to new upstream version including a fix for CVE-2025-68616. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f59e87ad88 2026-01-29 00:55:04.138850+00:00 -------------------------------------------------------------------------------- Name : weasyprint Product : Fedora 43 Version : 68.0 Release : 1.fc43 URL : https://weasyprint.org Summary : Utility to render HTML and CSS to PDF Description : WeasyPrint can render HTML and CSS to PDF. It aims to support web standards for printing. -------------------------------------------------------------------------------- Update Information: update to new upstream version including a fix for CVE-2025-68616 -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 20 2026 Felix Schwarz - 68.0-1 - update to 68.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2416619 - python-tinycss2-1.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2416619 [ 2 ] Bug #2430927 - CVE-2025-68616 weasyprint: WeasyPrint Server-Side Request Forgery (SSRF) [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2430927 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f59e87ad88' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Update for weasyprint in Fedora 43 includes critical fix for Server-Side Request Forgery vulnerability identified as CVE-2025-68616.. CVE-2025-68616, weasyprint, Fedora 43, SSRF, update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 29, 2026 Critical Fedora
89

Fedora 43 Forgejo Security Update Released: 2025-35fe65f08c

This is an upstream bug and security fix release. Please view the upstream release notes for more details.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-35fe65f08c 2025-12-03 00:52:00.122545+00:00 -------------------------------------------------------------------------------- Name : forgejo Product : Fedora 43 Version : 13.0.3 Release : 1.fc43 URL : https://forgejo.org Summary : A lightweight software forge Description : Forgejo (pronounced /for\u02c8d\u0361\u0292e.jo/) is a lightweight software forge. Use it to host git repositories, track their issues and allow people to contribute to them! -------------------------------------------------------------------------------- Update Information: This is an upstream bug and security fix release. Please view the upstream release notes for more details. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 24 2025 Nils Philippsen - 13.0.3-1 - Update to 13.0.3 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-35fe65f08c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Forgejo security fix released for Fedora 43. Find details on bug corrections and how to update your system.. Fedora security fixes, Forgejo update, upstream bug fix, lightweight software forge. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Dec 03, 2025 Informational Fedora
89

Fedora 42: cri-o 1.32.9 Important Security Fix 2025-37970906a8

Update to release 1.32.9 Resolves: rhbz#2333357, rhbz#2398407, rhbz#2398662, rhbz#2399064, rhbz#2399338 Upstream fix. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-37970906a8 2025-10-11 00:56:43.169072+00:00 -------------------------------------------------------------------------------- Name : cri-o1.32 Product : Fedora 42 Version : 1.32.9 Release : 1.fc42 URL : https://github.com/cri-o/cri-o Summary : Open Container Initiative-based implementation of Kubernetes Container Runtime Interface Description : Open Container Initiative-based implementation of Kubernetes Container Runtime Interface. -------------------------------------------------------------------------------- Update Information: Update to release 1.32.9 Resolves: rhbz#2333357, rhbz#2398407, rhbz#2398662, rhbz#2399064, rhbz#2399338 Upstream fix -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 2 2025 Bradley G Smith - 1.32.9-1 - Update to release 1.32.9 - Resolves: rhbz#2333357, rhbz#2398407, rhbz#2398662, rhbz#2399064, rhbz#2399338 - Upstream fix -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333357 - cri-o-1.34.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2333357 [ 2 ] Bug #2398407 - CVE-2025-47910 cri-o1.32: CrossOriginProtection bypass in net/http [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2398407 [ 3 ] Bug #2398662 - CVE-2025-47910 cri-o1.32: CrossOriginProtection bypass in net/http [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2398662 [ 4 ] Bug #2399064 - CVE-2025-47906 cri-o1.32: Unexpected paths returned from LookPath in os/exec [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2399064 [ 5 ] Bug #2399338 - CVE-2025-47906 cri-o1.32: Unexpected paths returned from LookPath in os/exec[fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2399338 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-37970906a8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 updates cri-o 1.32.9 to address critical issues impacting Kubernetes with upstream fixes.. Fedora cri-o container runtime update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 11, 2025 Important Fedora
89

Fedora 41: FEDORA-2025-464c59df2a moderate: docker-buildx update

Update package to release v0.24.0 Resolve: rhbz#2366388, rhbz#2360632 Upstream fixes and changes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-464c59df2a 2025-05-30 01:44:07.670119+00:00 -------------------------------------------------------------------------------- Name : docker-buildx Product : Fedora 41 Version : 0.24.0 Release : 1.fc41 URL : https://github.com/docker/buildx Summary : Docker CLI plugin for extended build capabilities with BuildKit Description : Docker CLI plugin for extended build capabilities with BuildKit. -------------------------------------------------------------------------------- Update Information: Update package to release v0.24.0 Resolve: rhbz#2366388, rhbz#2360632 Upstream fixes and changes -------------------------------------------------------------------------------- ChangeLog: * Wed May 21 2025 Bradley G Smith - 0.24.0-1 - Update package to release v0.24.0 - Resolve: rhbz#2366388, rhbz#2360632 - Upstream fixes and changes -------------------------------------------------------------------------------- References: [ 1 ] Bug #2360632 - CVE-2025-22872 docker-buildx: Incorrect Neutralization of Input During Web Page Generation in x/net in golang.org/x/net [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2360632 [ 2 ] Bug #2366388 - docker-buildx-0.24.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2366388 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-464c59df2a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . This post highlights the launch of version 0.24.0 of docker-buildx tailored for Fedora 41, featuring upstream enhancements and modifications. Update today.. docker-buildx, Fedora 41, package update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 30, 2025 Important Fedora
89

Fedora 41: 2025-2fd25cfb83 critical: python-h11 malformed requests

Backport upstream fix for CVE-2025-43859. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-2fd25cfb83 2025-05-11 02:30:35.179655+00:00 -------------------------------------------------------------------------------- Name : python-h11 Product : Fedora 41 Version : 0.14.0 Release : 7.fc41 URL : https://github.com/python-hyper/h11 Summary : A pure-Python, bring-your-own-I/O implementation of HTTP/1.1 Description : This is a little HTTP/1.1 library written from scratch in Python, heavily inspired by hyper-h2. It is a "bring-your-own-I/O" library; h11 contains no IO code whatsoever. This means you can hook h11 up to your favorite network API, and that could be anything you want: synchronous, threaded, asynchronous, or your own implementation of RFC 6214 -- h11 will not judge you. This also means that h11 is not immediately useful out of the box: it is a toolkit for building programs that speak HTTP, not something that could directly replace requests or twisted.web or whatever. But h11 makes it much easier to implement something like requests or twisted.web. -------------------------------------------------------------------------------- Update Information: Backport upstream fix for CVE-2025-43859 -------------------------------------------------------------------------------- ChangeLog: * Fri May 2 2025 Robby Callicotte - 0.14.0-7 - Backport upstream fix for CVE-2025-43859 * Sat Jan 18 2025 Fedora Release Engineering - 0.14.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2362286 - CVE-2025-43859 python-h11: h11 accepts some malformed Chunked-Encoding bodies [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2362286 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-2fd25cfb83' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Implement patch for correcting malformed queries in python-h11 for users on Fedora 41; vital for secure handling of HTTP transactions.. Fedora Updates, python-h11 Security, HTTP Library Fix, Package Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 11, 2025 Critical Fedora
89

Fedora 37: 2023-ceaa6b19c1 high: Chromium memory access issues

update to 119.0.6045.199, upstream security release * High CVE-2023-6345: Integer overflow in Skia * High CVE-2023-6346: Use after free in WebAudio * High CVE-2023-6347: Use after free in Mojo * High CVE-2023-6348: Type Confusion in Spellcheck * High CVE-2023-6350: Out of bounds memory access in libavif * High CVE-2023-6351: Use after free in libavif. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ceaa6b19c1 2023-12-05 16:27:20.051939 -------------------------------------------------------------------------------- Name : chromium Product : Fedora 37 Version : 119.0.6045.199 Release : 1.fc37 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser that Google doesn't want you to use Description : Chromium is an open-source web browser, powered by WebKit (Blink). -------------------------------------------------------------------------------- Update Information: update to 119.0.6045.199, upstream security release * High CVE-2023-6345: Integer overflow in Skia * High CVE-2023-6346: Use after free in WebAudio * High CVE-2023-6347: Use after free in Mojo * High CVE-2023-6348: Type Confusion in Spellcheck * High CVE-2023-6350: Out of bounds memory access in libavif * High CVE-2023-6351: Use after free in libavif -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 29 2023 Than Ngo - 119.0.6045.199-1 - update to 119.0.6045.199 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ceaa6b19c1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Severe memory access issues fixed in Fedora 37's Chromium update to 119.0.6045.199, addressing multiple high risks.. Fedora Chromium Security Update, Memory Access Issues, High Severity Fixes. . LinuxSecurity.com Team

Calendar 2 Dec 05, 2023 Fedora
89

Fedora 33 Microcode_ctl Update: Addresses System Hangs and Security Issues

- Update to upstream 2.1-31. 20201118 - Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-2c8824c6b1 2020-11-22 01:24:25.184398 --------------------------------------------------------------------------------Name : microcode_ctl Product : Fedora 33 Version : 2.1 Release : 43.fc33 URL : https://pagure.io/microcode_ctl Summary : Tool to transform and deploy CPU microcode update for x86 Description : The microcode_ctl utility is a companion to the microcode driver written by Tigran Aivazian . The microcode update is volatile and needs to be uploaded on each system boot i.e. it doesn't reflash your cpu permanently, reboot and it reverts back to the old microcode. --------------------------------------------------------------------------------Update Information: - Update to upstream 2.1-31. 20201118 - Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68[1]; - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34[2]. [1] The microcode has been removed after reports of system hangs: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/issues/44 [2] Addresses CVE-2020-8695 for this platform. ---- - Update to upstream 2.1-30. 20201110 - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e; - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28; - Addition of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68; - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0; - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0; -Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0; - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision 0xe0; - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode from revision 0x43 up to 0x44; - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode from revision 0xd6 up to 0xe2; - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157 up to 0x1000159; - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode from revision 0x2006906 up to 0x2006a08; - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01 up to 0x4003003; - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5002f01 up to 0x5003003; - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up to 0x40; - Update of 06-5c-0a/0x03 (APL B1/F1) microcode from revision 0x16 up to 0x1e; - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode from revision 0xd6 up to 0xe2; - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up to 0x18; - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78 up to 0xa0; -Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from revision 0xd6 up to 0xe0; - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0) microcode from revision 0xd6 up to 0xde; -Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision 0xd6 up to0xde; - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision 0xd6 up to 0xde; - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca up to 0xe0. - Addresses CVE-2020-8695, CVE-2020-8696, CVE-2020-8698 --------------------------------------------------------------------------------ChangeLog: * Fri Nov 20 2020 Eugene Syromiatnikov 2:2.1-43 - Update to upstream 2.1-31. 20201118 - Removal of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68; - Update of 06-7a-01/0x01 (GLK B0) microcode from revision 0x32 up to 0x34. * Wed Nov 11 2020 Eugene Syromiatnikov 2:2.1-42 - Fix incorrect CVE numbers in the previous changelog entry * Wed Nov 11 2020 Eugene Syromiatnikov 2:2.1-41 - Update to upstream 2.1-30. 20201110 - Addition of 06-55-0b/0xbf (CPX-SP A1) microcode at revision 0x700001e; - Addition of 06-8a-01/0x10 (LKF B2/B3) microcode at revision 0x28; - Addition of 06-8c-01/0x80 (TGL-UP3/UP4 B1) microcode at revision 0x68; - Addition of 06-a5-02/0x20 (CML-H R1) microcode at revision 0xe0; - Addition of 06-a5-03/0x22 (CML-S 6+2 G1) microcode at revision 0xe0; - Addition of 06-a5-05/0x22 (CML-S 10+2 Q0) microcode at revision 0xe0; - Addition of 06-a6-01/0x80 (CML-U 6+2 v2 K0) microcode at revision 0xe0; - Update of 06-3f-02/0x6f (HSX-E/EN/EP/EP 4S C0/C1/M1/R2) microcode from revision 0x43 up to 0x44; - Update of 06-4e-03/0xc0 (SKL-U/U 2+3e/Y D0/K1) microcode from revision 0xd6 up to 0xe2; - Update of 06-55-03/0x97 (SKX-SP B1) microcode from revision 0x1000157 up to 0x1000159; - Update of 06-55-04/0xb7 (SKX-D/SP/W/X H0/M0/M1/U0) microcode from revision 0x2006906 up to 0x2006a08; - Update of 06-55-06/0xbf (CLX-SP B0) microcode from revision 0x4002f01 up to 0x4003003; - Update of 06-55-07/0xbf (CLX-SP/W/X B1/L1) microcode from revision 0x5002f01 up to 0x5003003; - Update of 06-5c-09/0x03 (APL D0) microcode from revision 0x38 up to 0x40; - Update of 06-5c-0a/0x03 (APLB1/F1) microcode from revision 0x16 up to 0x1e; - Update of 06-5e-03/0x36 (SKL-H/S/Xeon E3 N0/R0/S0) microcode from revision 0xd6 up to 0xe2; - Update of 06-7a-08/0x01 (GLK-R R0) microcode from revision 0x16 up to 0x18; - Update of 06-7e-05/0x80 (ICL-U/Y D1) microcode from revision 0x78 up to 0xa0; - Update of 06-8e-09/0x10 (AML-Y 2+2 H0) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-09/0xc0 (KBL-U/U 2+3e/Y H0/J1) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-0a/0xc0 (CFL-U 4+3e D0, KBL-R Y0) microcode from revision 0xd6 up to 0xe0; - Update of 06-8e-0b/0xd0 (WHL-U W0) microcode from revision 0xd6 up to 0xde; - Update of 06-8e-0c/0x94 (AML-Y 4+2 V0, CML-U 4+2 V0, WHL-U V0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-09/0x2a (KBL-G/H/S/X/Xeon E3 B0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0a/0x22 (CFL-H/S/Xeon E U0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0b/0x02 (CFL-E/H/S B0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0c/0x22 (CFL-H/S/Xeon E P0) microcode from revision 0xd6 up to 0xde; - Update of 06-9e-0d/0x22 (CFL-H/S/Xeon E R0) microcode from revision 0xd6 up to 0xde; - Update of 06-a6-00/0x80 (CML-U 6+2 A0) microcode from revision 0xca up to 0xe0. - Addresses CVE-2020-8695, CVE-2020-8696, CVE-2020-8698 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-2c8824c6b1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important microcode_ctl revisions for Fedora 33 tackle issues of system freezes and significant stability concerns on x86 architectures.. Fedora Update, Microcode Control, System Hangs, X86 Microcode Update, Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 21, 2020 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here